einmalige und abgewürgte drive cleaner meldung, hijack + clean up log

#0
26.09.2007, 20:05
...neu hier

Beiträge: 3
#1 hi

habe beim klicken auf paidbanner auf einer paidmailsseite die übliche meldung von drive cleaner bekommen und dann nach ner schrecksekunde den pc manuell ausgeschaltet.. unten im browser stand schon "übertrage (oder lade?) daten von drive cleaner" aber wie gesagt habe ihn ausgeschaltet
papierkorb funktioniert noch, sonst habe ich auch noch keine nebenwirkungen, aber ich mache mir sorgen..

habe cleanup durchlaufen lassen

habe eben hijackthis installiert
während des logs lief antivir und fprot, falls das störend ist könnte ich nochmal einen neuen log kopieren

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:52:20, on 26.09.2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Programme\FSI\F-Prot\F-StopW.EXE
C:\Programme\QuickTime\qttask.exe
C:\Programme\Java\jre1.6.0_02\bin\jusched.exe
C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\FSI\F-Prot\fpavupdm.exe
C:\Programme\PeerGuardian2\pg2.exe
C:\Programme\ATI Technologies\ATI.ACE\CLI.exe
C:\Programme\FSI\F-Prot\FP-Win.exe
c:\programme\avira\antivir personaledition classic\avscan.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
D:\Programme\unlöschbar\ICQLite.exe
C:\Programme\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATICCC] "C:\Programme\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [F-StopW] C:\Programme\FSI\F-Prot\F-StopW.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Programme\TimeSink\AdGateway\TSAdBot.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Programme\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [Skype] "D:\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\RunOnce: [ICQ Lite] D:\Programme\unlöschbar\ICQLite.exe -trayboot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Wecarelife-TrinkButler.lnk = C:\Programme\TrinkButler\TrinkButler.exe
O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST-Infobereich.lnk = C:\Programme\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\PROGRA~1\UNLSCH~1\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\PROGRA~1\UNLSCH~1\ICQLite.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: F-Prot Antivirus Update Monitor - FRISK Software - C:\Programme\FSI\F-Prot\fpavupdm.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Programme\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

--
End of file - 5046 bytes


_________________________________________________

cleanup
CleanUp! started on 09/26/07 20:20:42.
...
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aab\xtras\SWADCmpr.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aab\xtras\Text Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aab\xtras\TextXtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aab\xtras\TxtCrnch.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aab\xtras\xtraydlx.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aab\xtras\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aab\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\dirapi.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\iml32.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\Macromedia.lok - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\msvcrt.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\proj.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\budapi.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\DirectSound.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\FileIo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\Flash Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\Font Xtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\INetURL.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\MacroMix.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\NetFile.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\NetLingo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\pregex.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\Sound Control.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\SWADCmpr.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\Text Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\TextXtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\TxtCrnch.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\xtraydlx.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\xtras\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aac\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\dirapi.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\iml32.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\Macromedia.lok - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\msvcrt.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\proj.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\budapi.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\DirectSound.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\FileIo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\Flash Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\Font Xtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\INetURL.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\MacroMix.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\NetFile.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\NetLingo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\pregex.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\Sound Control.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\SWADCmpr.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\Text Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\TextXtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\TxtCrnch.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\xtraydlx.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\xtras\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aad\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\dirapi.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\iml32.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\Macromedia.lok - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\msvcrt.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\proj.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\budapi.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\DirectSound.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\FileIo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\Flash Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\Font Xtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\INetURL.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\MacroMix.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\NetFile.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\NetLingo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\pregex.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\Sound Control.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\SWADCmpr.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\Text Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\TextXtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\TxtCrnch.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\xtraydlx.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\xtras\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aae\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\dirapi.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\iml32.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\Macromedia.lok - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\msvcrt.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\proj.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\budapi.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\DirectSound.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\FileIo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\Flash Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\Font Xtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\INetURL.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\MacroMix.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\NetFile.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\NetLingo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\pregex.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\Sound Control.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\SWADCmpr.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\Text Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\TextXtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\TxtCrnch.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\xtraydlx.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\xtras\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aaf\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\dirapi.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\iml32.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\Macromedia.lok - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\msvcrt.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\proj.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\budapi.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\DirectSound.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\FileIo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\Flash Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\Font Xtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\INetURL.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\MacroMix.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\NetFile.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\NetLingo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\pregex.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\Sound Control.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\SWADCmpr.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\Text Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\TextXtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\TxtCrnch.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\xtraydlx.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\xtras\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aag\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\dirapi.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\iml32.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\Macromedia.lok - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\msvcrt.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\proj.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\budapi.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\DirectSound.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\FileIo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\Flash Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\Font Xtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\INetURL.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\MacroMix.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\NetFile.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\NetLingo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\pregex.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\Sound Control.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\SWADCmpr.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\Text Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\TextXtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\TxtCrnch.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\xtraydlx.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\xtras\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aah\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\dirapi.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\iml32.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\Macromedia.lok - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\msvcrt.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\proj.dll - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\budapi.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\DirectSound.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\FileIo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\Flash Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\Font Xtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\INetURL.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\MacroMix.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\NetFile.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\NetLingo.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\pregex.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\Sound Control.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\SWADCmpr.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\Text Asset.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\TextXtra.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\TxtCrnch.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\xtraydlx.x32 - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\xtras\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\TempFolder.aai\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\Temporary Internet Files\Content.IE5\index.dat - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\Temporary Internet Files\Content.IE5\GXA781QZ\bg_menu[1].jpg - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\VBE\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\Verlauf\History.IE5\index.dat - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\WER2D.tmp.dir00\appcompat.txt - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\WER2D.tmp.dir00\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\WER5.tmp.dir00\appcompat.txt - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\WER5.tmp.dir00\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\WER9.tmp.dir00\appcompat.txt - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\WER9.tmp.dir00\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\WER9C.tmp.dir00\appcompat.txt - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\WER9C.tmp.dir00\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\WERC.tmp.dir00\appcompat.txt - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\WERC.tmp.dir00\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\WERD.tmp.dir00\appcompat.txt - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\WERD.tmp.dir00\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\Word8.0\MSForms.exd - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\Word8.0\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\~nsu.tmp\ - deleted
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\Perflib_Perfdata_6a0.dat currently in use. Will be deleted when Windows is restarted.
C:\DOKUME~1\SE1022~1\LOKALE~1\Temp\Perflib_Perfdata_c8.dat currently in use. Will be deleted when Windows is restarted.
C:\WINDOWS\SET3.tmp - deleted
C:\WINDOWS\SETA.tmp - deleted
C:\WINDOWS\temp\EXEBUILD.EXE - deleted
C:\WINDOWS\temp\EXTSTUB.EXE - deleted
C:\WINDOWS\temp\SETUP.EXE - deleted
C:\WINDOWS\temp\SPL5.tmp - deleted
C:\WINDOWS\temp\SPLA.tmp - deleted
C:\WINDOWS\temp\UNINSTAL.INS - deleted
C:\WINDOWS\temp\Upd1.tmp - deleted
C:\WINDOWS\temp\Upd10.tmp - deleted
C:\WINDOWS\temp\Upd11.tmp - deleted
C:\WINDOWS\temp\Upd12.tmp - deleted
C:\WINDOWS\temp\Upd13.tmp - deleted
C:\WINDOWS\temp\Upd14.tmp - deleted
C:\WINDOWS\temp\Upd15.tmp - deleted
C:\WINDOWS\temp\Upd16.tmp - deleted
C:\WINDOWS\temp\Upd17.tmp - deleted
C:\WINDOWS\temp\Upd18.tmp - deleted
C:\WINDOWS\temp\Upd19.tmp - deleted
C:\WINDOWS\temp\Upd1A.tmp - deleted
C:\WINDOWS\temp\Upd1B.tmp - deleted
C:\WINDOWS\temp\Upd1C.tmp - deleted
C:\WINDOWS\temp\Upd1D.tmp - deleted
C:\WINDOWS\temp\Upd1E.tmp - deleted
C:\WINDOWS\temp\Upd1F.tmp - deleted
C:\WINDOWS\temp\Upd20.tmp - deleted
C:\WINDOWS\temp\Upd21.tmp - deleted
C:\WINDOWS\temp\Upd22.tmp - deleted
C:\WINDOWS\temp\Upd23.tmp - deleted
C:\WINDOWS\temp\Upd24.tmp - deleted
C:\WINDOWS\temp\Upd25.tmp - deleted
C:\WINDOWS\temp\Upd26.tmp - deleted
C:\WINDOWS\temp\Upd27.tmp - deleted
C:\WINDOWS\temp\Upd28.tmp - deleted
C:\WINDOWS\temp\Upd29.tmp - deleted
C:\WINDOWS\temp\Upd2A.tmp - deleted
C:\WINDOWS\temp\Upd2B.tmp - deleted
C:\WINDOWS\temp\Upd2C.tmp - deleted
C:\WINDOWS\temp\Upd2D.tmp - deleted
C:\WINDOWS\temp\Upd2E.tmp - deleted
C:\WINDOWS\temp\Upd2F.tmp - deleted
C:\WINDOWS\temp\Upd3.tmp - deleted
C:\WINDOWS\temp\Upd30.tmp - deleted
C:\WINDOWS\temp\Upd31.tmp - deleted
C:\WINDOWS\temp\Upd32.tmp - deleted
C:\WINDOWS\temp\Upd33.tmp - deleted
C:\WINDOWS\temp\Upd34.tmp - deleted
C:\WINDOWS\temp\Upd35.tmp - deleted
C:\WINDOWS\temp\Upd36.tmp - deleted
C:\WINDOWS\temp\Upd37.tmp - deleted
C:\WINDOWS\temp\Upd38.tmp - deleted
C:\WINDOWS\temp\Upd39.tmp - deleted
C:\WINDOWS\temp\Upd3A.tmp - deleted
C:\WINDOWS\temp\Upd3B.tmp - deleted
C:\WINDOWS\temp\Upd3C.tmp - deleted
C:\WINDOWS\temp\Upd3D.tmp - deleted
C:\WINDOWS\temp\Upd3E.tmp - deleted
C:\WINDOWS\temp\Upd3F.tmp - deleted
C:\WINDOWS\temp\Upd4.tmp - deleted
C:\WINDOWS\temp\Upd40.tmp - deleted
C:\WINDOWS\temp\Upd41.tmp - deleted
C:\WINDOWS\temp\Upd42.tmp - deleted
C:\WINDOWS\temp\Upd43.tmp - deleted
C:\WINDOWS\temp\Upd44.tmp - deleted
C:\WINDOWS\temp\Upd45.tmp - deleted
C:\WINDOWS\temp\Upd46.tmp - deleted
C:\WINDOWS\temp\Upd47.tmp - deleted
C:\WINDOWS\temp\Upd4D.tmp - deleted
C:\WINDOWS\temp\Upd5.tmp - deleted
C:\WINDOWS\temp\Upd50.tmp - deleted
C:\WINDOWS\temp\Upd58.tmp - deleted
C:\WINDOWS\temp\Upd5E.tmp - deleted
C:\WINDOWS\temp\Upd6.tmp - deleted
C:\WINDOWS\temp\Upd6C.tmp - deleted
C:\WINDOWS\temp\Upd7.tmp - deleted
C:\WINDOWS\temp\Upd73.tmp - deleted
C:\WINDOWS\temp\Upd8.tmp - deleted
C:\WINDOWS\temp\Upd9.tmp - deleted
C:\WINDOWS\temp\UpdA.tmp - deleted
C:\WINDOWS\temp\UpdA0.tmp - deleted
C:\WINDOWS\temp\UpdB.tmp - deleted
C:\WINDOWS\temp\UpdC.tmp - deleted
C:\WINDOWS\temp\UpdD.tmp - deleted
C:\WINDOWS\temp\UpdE.tmp - deleted
C:\WINDOWS\temp\UpdF.tmp - deleted
C:\WINDOWS\temp\WER1.tmp - deleted
C:\WINDOWS\temp\WER2.tmp - deleted
C:\WINDOWS\temp\WER3.tmp - deleted
C:\WINDOWS\temp\WER4.tmp - deleted
C:\WINDOWS\temp\WER5.tmp - deleted
C:\WINDOWS\temp\_INST32I.EX_ - deleted
C:\WINDOWS\temp\_SETUP.DLL - deleted
C:\WINDOWS\temp\_SETUP.LIB - deleted
C:\WINDOWS\temp\~ABC0923.TMP - deleted
C:\WINDOWS\temp\~ABC0924.TMP - deleted
C:\WINDOWS\temp\~ABC092E.TMP - deleted
C:\WINDOWS\temp\~ABC092F.TMP - deleted
C:\WINDOWS\temp\~ABC0E39.TMP - deleted
C:\WINDOWS\temp\~ABC0E3A.TMP - deleted
C:\WINDOWS\temp\~ABC0E3B.TMP - deleted
C:\WINDOWS\temp\~ABC0E3C.TMP - deleted
C:\WINDOWS\temp\WER1.tmp.dir00\manifest.txt - deleted
C:\WINDOWS\temp\WER1.tmp.dir00\ - deleted
C:\WINDOWS\temp\WER2.tmp.dir00\manifest.txt - deleted
C:\WINDOWS\temp\WER2.tmp.dir00\ - deleted
C:\WINDOWS\temp\WER3.tmp.dir00\manifest.txt - deleted
C:\WINDOWS\temp\WER3.tmp.dir00\ - deleted
C:\WINDOWS\temp\WER4.tmp.dir00\manifest.txt - deleted
C:\WINDOWS\temp\WER4.tmp.dir00\ - deleted
C:\WINDOWS\temp\WER5.tmp.dir00\manifest.txt - deleted
C:\WINDOWS\temp\WER5.tmp.dir00\ - deleted
C:\WINDOWS\temp\_ISTMP0.DIR\infolist.txt - deleted
C:\WINDOWS\temp\_ISTMP0.DIR\ - deleted
C:\WINDOWS\temp\_ISTMP1.DIR\ - deleted
C:\Dokumente und Einstellungen\Süüüüüüüße\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Dokumente und Einstellungen\Süüüüüüüße\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Dokumente und Einstellungen\Default User\Cookies\index.dat - deleted
C:\WINDOWS\Prefetch\0004F3A3._MP-01D941E2.pf - deleted
C:\WINDOWS\Prefetch\4IN1449V.EXE-18F3EBF4.pf - deleted
C:\WINDOWS\Prefetch\AGENTSVR.EXE-002E45AB.pf - deleted
C:\WINDOWS\Prefetch\ASPNET_REGIIS.EXE-38397C30.pf - deleted
C:\WINDOWS\Prefetch\ASSETUP.EXE-36D9FE2D.pf - deleted
C:\WINDOWS\Prefetch\ATI2SGAG.EXE-034D00DE.pf - deleted
C:\WINDOWS\Prefetch\ATICIM.BIN-23C0100D.pf - deleted
C:\WINDOWS\Prefetch\ATISETUP.EXE-026C9C2B.pf - deleted
C:\WINDOWS\Prefetch\ATISHLX.EXE-06C8C52F.pf - deleted
C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf - deleted
C:\WINDOWS\Prefetch\CMIBACKWORK.EXE-2CB7574E.pf - deleted
C:\WINDOWS\Prefetch\CMICHIPDETECT.EXE-271D8CCB.pf - deleted
C:\WINDOWS\Prefetch\CMISCREEN.EXE-0C86F711.pf - deleted
C:\WINDOWS\Prefetch\CMISYSTEMINFO.EXE-2342114F.pf - deleted
C:\WINDOWS\Prefetch\CTFMON.EXE-0E17969B.pf - deleted
C:\WINDOWS\Prefetch\DEFRAG.EXE-273F131E.pf - deleted
C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf - deleted
C:\WINDOWS\Prefetch\DLLHOST.EXE-1ECB6754.pf - deleted
C:\WINDOWS\Prefetch\DOTNETFX.EXE-08E4F22C.pf - deleted
C:\WINDOWS\Prefetch\EDONKEY2000.EXE-3009EF7E.pf - deleted
C:\WINDOWS\Prefetch\EXPLODER.EXE-33BC1B55.pf - deleted
C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf - deleted
C:\WINDOWS\Prefetch\F-STOPW.EXE-18E09C20.pf - deleted
C:\WINDOWS\Prefetch\FP-WIN.EXE-23436390.pf - deleted
C:\WINDOWS\Prefetch\FP-WIN_316B_M.EXE-19822CB7.pf - deleted
C:\WINDOWS\Prefetch\FPAVUPDM.EXE-318307C7.pf - deleted
C:\WINDOWS\Prefetch\GLB1.TMP-1B821B7F.pf - deleted
C:\WINDOWS\Prefetch\GLJ3.TMP-000B026D.pf - deleted
C:\WINDOWS\Prefetch\ICQ5_1_GERMAN_SETUP.EXE-0497323F.pf - deleted
C:\WINDOWS\Prefetch\ICQINS~1.EXE-193CAA03.pf - deleted
C:\WINDOWS\Prefetch\ICQLITE.EXE-31DF6EE8.pf - deleted
C:\WINDOWS\Prefetch\ICQLIT~2.EXE-176F103E.pf - deleted
C:\WINDOWS\Prefetch\ICQTOOLBARPATCH.EXE-31D6C6FE.pf - deleted
C:\WINDOWS\Prefetch\IDRIVER.EXE-2E776D3F.pf - deleted
C:\WINDOWS\Prefetch\IE4UINIT.EXE-169A5A39.pf - deleted
C:\WINDOWS\Prefetch\IEXPLORE.EXE-2CA9778D.pf - deleted
C:\WINDOWS\Prefetch\IKERNEL.EXE-092EF074.pf - deleted
C:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf - deleted
C:\WINDOWS\Prefetch\INSTALL.EXE-297C8ACF.pf - deleted
C:\WINDOWS\Prefetch\IS-M6M2L.TMP-0CEB347F.pf - deleted
C:\WINDOWS\Prefetch\ISSETUP.EXE-07529B1A.pf - deleted
C:\WINDOWS\Prefetch\Layout.ini - deleted
C:\WINDOWS\Prefetch\LODCTR.EXE-1009C3B4.pf - deleted
C:\WINDOWS\Prefetch\LOGON.SCR-151EFAEA.pf - deleted
C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf - deleted
C:\WINDOWS\Prefetch\LSASS.EXE-20DB6D1B.pf - deleted
C:\WINDOWS\Prefetch\MIGPOLWIN.EXE-1EFB7D70.pf - deleted
C:\WINDOWS\Prefetch\MOFCOMP.EXE-01718E95.pf - deleted
C:\WINDOWS\Prefetch\MSDTC.EXE-0E6E4AF7.pf - deleted
C:\WINDOWS\Prefetch\MSI9A.TMP-2379EA42.pf - deleted
C:\WINDOWS\Prefetch\MSIEXEC.EXE-2F8A8CAE.pf - deleted
C:\WINDOWS\Prefetch\MSOOBE.EXE-30411B02.pf - deleted
C:\WINDOWS\Prefetch\MSTINIT.EXE-39813B24.pf - deleted
C:\WINDOWS\Prefetch\NGEN.EXE-171CDCC6.pf - deleted
C:\WINDOWS\Prefetch\NOTEPAD.EXE-336351A9.pf - deleted
C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf - deleted
C:\WINDOWS\Prefetch\NTVDM.EXE-1A10A423.pf - deleted
C:\WINDOWS\Prefetch\PG2-050918-NT.EXE-00406AB5.pf - deleted
C:\WINDOWS\Prefetch\PG2.EXE-100DE05D.pf - deleted
C:\WINDOWS\Prefetch\REGEDIT.EXE-1B606482.pf - deleted
C:\WINDOWS\Prefetch\REGSVCS.EXE-077D24C2.pf - deleted
C:\WINDOWS\Prefetch\REGSVR32.EXE-25EEFE2F.pf - deleted
C:\WINDOWS\Prefetch\REGTLIB.EXE-0CCB81E6.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-1197B7C6.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-1245AEEA.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-128CE2BB.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-18E3301D.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-19076CE2.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-1940EEC4.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-19F57947.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-1A0D4B6C.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-25DB3D71.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-271001B4.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-28033D36.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-287A0F19.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-2A59AA93.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-2F8AC90D.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-2F982821.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-2FFA77CA.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-304A2AEA.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-327D1112.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-32EF5B7A.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-33D7466C.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-33F6DC04.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-35AE65C8.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-35FEF084.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-37E068C5.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-40419843.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-451FC2C0.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-4688242C.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-48233408.pf - deleted
C:\WINDOWS\Prefetch\RUNONCE.EXE-2803F297.pf - deleted
C:\WINDOWS\Prefetch\SELECT.EXE-101692F1.pf - deleted
C:\WINDOWS\Prefetch\SETUP.EXE-02C67653.pf - deleted
C:\WINDOWS\Prefetch\SETUP.EXE-094C9B6F.pf - deleted
C:\WINDOWS\Prefetch\SETUP.EXE-15167083.pf - deleted
C:\WINDOWS\Prefetch\SETUP.EXE-17992F3B.pf - deleted
C:\WINDOWS\Prefetch\SETUP.EXE-1E42F7B3.pf - deleted
C:\WINDOWS\Prefetch\SETUP.EXE-265AF91A.pf - deleted
C:\WINDOWS\Prefetch\SETUP50.EXE-0CDEF78F.pf - deleted
C:\WINDOWS\Prefetch\SETUPDX.EXE-0D77DFC6.pf - deleted
C:\WINDOWS\Prefetch\SETUPNET.EXE-071F1490.pf - deleted
C:\WINDOWS\Prefetch\SHMGRATE.EXE-1BA69E68.pf - deleted
C:\WINDOWS\Prefetch\SPOOLSV.EXE-282F76A7.pf - deleted
C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf - deleted
C:\WINDOWS\Prefetch\SYSTRAY.EXE-345DCC1C.pf - deleted
C:\WINDOWS\Prefetch\TASKMGR.EXE-20256C55.pf - deleted
C:\WINDOWS\Prefetch\THUNK.EXE-2E91162B.pf - deleted
C:\WINDOWS\Prefetch\UNINSTALL.EXE-15278D8E.pf - deleted
C:\WINDOWS\Prefetch\UNREGMP2.EXE-07CACB61.pf - deleted
C:\WINDOWS\Prefetch\UPDATER.EXE-2F27DCD9.pf - deleted
C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf - deleted
C:\WINDOWS\Prefetch\W2KSETUP.DAT-1EE008C1.pf - deleted
C:\WINDOWS\Prefetch\W2KSETUP.EXE-27C7EF2E.pf - deleted
C:\WINDOWS\Prefetch\WINLOGON.EXE-32C57D49.pf - deleted
C:\WINDOWS\Prefetch\WINRAR.V.3.51.GERMAN.GEAR.FOR-0D96DE8D.pf - deleted
C:\WINDOWS\Prefetch\WINSETUP.EXE-30D2A11C.pf - deleted
C:\WINDOWS\Prefetch\WMIADAP.EXE-2DF425B2.pf - deleted
C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf - deleted
C:\WINDOWS\Prefetch\XP-ANTISPY.EXE-0A1E13AC.pf - deleted
C:\WINDOWS\Prefetch\XP-ANTISPY_SETUP-DEUTSCH.EXE-1D7E7C9A.pf - deleted
'Run MRU' list - removed from the registry.
Search Assistant MRU list - removed from the registry.
Explorer Open/Save MRU list - removed from the registry.
Explorer Last Visited MRU list - removed from the registry.
Paint Recent File List - removed from the registry.
WordPad Recent File List - removed from the registry.
Telnet's MRU list - removed from the registry.
CleanUp! 4.5.2 recovered 230.5 MB of disk space from 2501 files.
CleanUp! finished on 09/26/07 20:21:44.

vielen vielen dank für hilfe!


(ist paidmail prinzipiell gefährlich? mussich damit rechnen dass ein dritter alle privaten daten etc lesen kann?)
Dieser Beitrag wurde am 26.09.2007 um 20:37 Uhr von amyleinchen editiert.
Seitenanfang Seitenende
26.09.2007, 22:07
Ehrenmitglied
Avatar Argus

Beiträge: 6028
#2 Entferne einer der beiden Virenscanner!

Download ComboFix und speichert es auf den Desktop!
Alle Fenster schliessen und combofix.exe starten
Folge den Instruktionen in das Fenster
Waehrend Combofix lauft NICHT ins Fenster klicken sonst erfriert dein Rechner
Wenn das Tool fertig ist,oeffnet sich ein logfile(combofix.txt )
nun das KOMPLETTE Log mit rechtem Mausklick abkopieren und ins Forum mit rechtem Mausklick "einfügen"

zusammen mit ein neuen log von HijackThis
__________
MfG Argus
Seitenanfang Seitenende
26.09.2007, 23:57
...neu hier

Themenstarter

Beiträge: 3
#3 du meinst antivir oder fprot löschen? oO
warum das? wenn die antwort net zu kompliziert ist
Seitenanfang Seitenende
27.09.2007, 00:04
Ehrenmitglied
Avatar Argus

Beiträge: 6028
#4 Auf ein Rechner ist nur ein Virenscanner erlaubt,mehrere verursachen Konflikte
__________
MfG Argus
Seitenanfang Seitenende
27.09.2007, 11:30
...neu hier

Themenstarter

Beiträge: 3
#5 hmmz ich hab schon gestern versucht combofix hier aus dem forum zu laden, in dem download fenster das erscheint kann man aber immer nur "abbrechen" anklicken "auf Datenträger speichern" ist hellgrau und nicht anklickbar
ich habs mit 2 downloadlinks aus anderen foren versucht da kam dann immer not found 404 oder so in meinem browser -.-
wisst ihr noch andere links oder ne lösung wie mein pc das downloaden könnte?
Seitenanfang Seitenende
27.09.2007, 12:19
Ehrenmitglied
Avatar Argus

Beiträge: 6028
#6 Schliesse alle Fenster und starte Hijack This
Klicke: Do a Systemscan only
Setze ein Häckchen in das Kästchen vor den genannten Eintrag bei

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 –k
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Programme\TimeSink\AdGateway\TSAdBot.exe"
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

klicke: Fix checked
Dein Internet Explorer muss geschlossen wenn Du Fix Checked klickst


Entferne auf C:\Programme\TimeSink Papierkorb leeren

Installiere AVG Anti Spyware 7.5
http://board.protecus.de/t29853.htm

Note:Wenn man CleanUp weiter benutzen will das haeckchen bei Delete Prefetch files entfernen!
__________
MfG Argus
Seitenanfang Seitenende
Um auf dieses Thema zu ANTWORTEN
bitte erst » hier kostenlos registrieren!!

Folgende Themen könnten Dich auch interessieren: