vbs/click.a zerstört mein pc! |
||
---|---|---|
#0
| ||
11.01.2008, 14:33
...neu hier
Beiträge: 2 |
||
|
||
11.01.2008, 15:08
Member
Beiträge: 33 |
#2
Du hast erste Infektionen auf dem Rechner! Würde mich freuen, wenn altgediente Boardies noch was dazu schreiben.
Sophos Anti-RootKit - Gehe zu Sophos http://www.sophos.de/products/free-tools/sophos-anti-rootkit/download - (Die Anleitung) http://www.sophos.com/sophos/docs/eng/manuals/rk_13_men.pdf] und lade dir ihren Rootkitescanner herunter. Du bekommst eine Installationsdatei sarsfx.exe. - Starte diese, akzeptiere die Lizenz und lass das Programm installieren, ändere den Pfad C:\SOPHTEMP [color=red]nicht.[/color] - Gehe mit dem Explorer in diesen Ordner und starte sargui.exe, schließe danach alle anderen Programme. - Lass unter Area alles angehalt und starte den Scan mit "Start scan". Der Scan dauert einige Zeit, wenn er fertig ist poppt ein Fenster auf mit einer Zusammenfassung, klicke dort "Ok". Beende den Sophos Rootkitscanner, dieser Scan dient nur der Analyse. - Starte den Explorer und gib in der Adresszeile "%temp%" ein (ohne Anführungsstriche), dort gibt es eine Datei sarscan.log, deren Inhalt bitte posten. [size=7](Thx to Argos)[/size] Combofix Download ComboFix von [url=http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe]hier[/url] oder [url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe]hier[/url] auf Deinen Desktop. Mache einen Doppelklick auf combofix.exe Wenn combofix fertig ist, legt es ein Logfile an. Poste dieses Logfile und ein neues HJT Logfile als nächste Antwort Achtung: Während Combofix läuft klicke nichts an, und benutze den Rechner nicht. Schon jetzt solltest Du alle Passwörter, Zugangsdaten etc ändern und ggf. Deine Kotobewegungen prüfen. Der Befall (hier ntos.exe) steht oft im Zusammenhang mit Kontoproblemen. Dieser Beitrag wurde am 11.01.2008 um 15:54 Uhr von BataAlexander editiert.
|
|
|
||
11.01.2008, 15:45
Moderator
Beiträge: 5694 |
#3
«
wende combofix an + poste das Log hier http://www.virus-protect.org/artikel/tools/combofix.html « wende sdfix im abgesichrten modus an - scane und poste dann hier den Report http://www.virus-protect.org/artikel/tools/sdfix.html$ Dazu noch folgendes: http://www.data-travelers.de/2007/07/02/ntosexe-ein-virus-ein-tag.html Dieser Beitrag wurde am 11.01.2008 um 16:36 Uhr von Tonstudio editiert.
|
|
|
||
11.01.2008, 18:56
...neu hier
Themenstarter Beiträge: 2 |
#4
habs gemacht...
wie bekomme ich jetzt den virus weg? System Report ************* Run on 2008-01-11 at 18:15 Microsoft Windows XP [Version 5.1.2600] Current user is an administrator Running Processes: \SystemRoot\System32\smss.exe [768] \??\C:\WINDOWS\system32\csrss.exe [824] \??\C:\WINDOWS\system32\winlogon.exe [856] C:\WINDOWS\system32\services.exe [900] C:\WINDOWS\system32\lsass.exe [920] C:\WINDOWS\system32\Ati2evxx.exe [1060] C:\WINDOWS\system32\svchost.exe [1112] C:\WINDOWS\system32\svchost.exe [1200] C:\WINDOWS\System32\svchost.exe [1308] C:\Programme\TGTSoft\StyleXP\StyleXPService.exe [1344] C:\WINDOWS\system32\Ati2evxx.exe [1364] C:\WINDOWS\system32\svchost.exe [1476] C:\WINDOWS\system32\svchost.exe [1616] C:\WINDOWS\system32\spoolsv.exe [1756] C:\WINDOWS\Explorer.EXE [196] C:\Programme\Acer\Acer eConsole\MediaServerService.exe [500] C:\Acer\Empowering Technology\ePerformance\MemCheck.exe [560] C:\Programme\AntiVir PersonalEdition Classic\sched.exe [720] C:\Programme\AntiVir PersonalEdition Classic\avguard.exe [796] C:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe [876] C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe [1164] C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe [1256] c:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe [1360] C:\WINDOWS\system32\svchost.exe [1560] C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe [1788] C:\WINDOWS\system32\SearchIndexer.exe [1900] C:\WINDOWS\System32\alg.exe [2944] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe [3740] C:\Programme\CyberLink\PowerDVD\PDVDServ.exe [3832] C:\Programme\QuickTime\qttask.exe [2084] C:\Programme\Java\jre1.6.0_03\bin\jusched.exe [1648] C:\WINDOWS\system32\SysMonitor.exe [464] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe [2820] C:\Programme\Acer\Acer eMode Management\AspireService.exe [2824] C:\Programme\Acer\Acer eConsole\MediaSync.exe [1244] C:\Program Files\CyberLink\PowerCinema\PCMService.exe [2872] C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe [2888] C:\WINDOWS\system32\LVCOMSX.EXE [2992] C:\Programme\Logitech\Video\LogiTray.exe [3592] C:\Programme\Logitech\Video\FxSvr2.exe [264] C:\WINDOWS\system32\wscntfy.exe [1252] C:\WINDOWS\RTHDCPL.EXE [2800] C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe [2900] C:\Programme\Winamp\winampa.exe [2912] C:\Programme\Gemeinsame Dateien\Ulead Systems\AutoDetector\monitor.exe [3100] C:\Programme\Grisoft\AVG Anti-Spyware 7.5\avgas.exe [3552] C:\WINDOWS\system32\ctfmon.exe [3668] C:\Programme\Windows Live\Messenger\MsnMsgr.Exe [3700] C:\Programme\TGTSoft\StyleXP\StyleXP.exe [3720] C:\Programme\Microsoft ActiveSync\wcescomm.exe [3728] C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2976] C:\Programme\Acer WLAN 11g USB Dongle\ZDWlan.exe [3924] C:\Programme\AOL 9.0\aoltray.exe [3780] C:\Programme\Windows Desktop Search\WindowsSearch.exe [812] C:\PROGRA~1\MI3AA1~1\rapimgr.exe [672] C:\Programme\Windows Live\Messenger\usnsvc.exe [3980] C:\Programme\Internet Explorer\iexplore.exe [3108] C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WLLoginProxy.exe [4160] C:\WINDOWS\system32\msiexec.exe [5244] C:\WINDOWS\system32\SearchProtocolHost.exe [4968] C:\WINDOWS\system32\SearchFilterHost.exe [5224] Drivers - Running: SERVICE_NAME: ACPI SERVICE_NAME: Afc SERVICE_NAME: AFD SERVICE_NAME: Arp1394 SERVICE_NAME: atapi SERVICE_NAME: ati2mtag SERVICE_NAME: atksgt SERVICE_NAME: audstub SERVICE_NAME: AVG Anti-Spyware Driver SERVICE_NAME: AvgAsCln SERVICE_NAME: avgio SERVICE_NAME: avgntflt SERVICE_NAME: avipbb SERVICE_NAME: Beep SERVICE_NAME: catchme SERVICE_NAME: Cdfs SERVICE_NAME: Cdrom SERVICE_NAME: Disk SERVICE_NAME: Fastfat SERVICE_NAME: Fdc SERVICE_NAME: Fips SERVICE_NAME: FltMgr SERVICE_NAME: Ftdisk SERVICE_NAME: fwdrv SERVICE_NAME: Gpc SERVICE_NAME: HDAudBus SERVICE_NAME: HidUsb SERVICE_NAME: HTTP SERVICE_NAME: i8042prt SERVICE_NAME: Imapi SERVICE_NAME: int15.sys SERVICE_NAME: IntcAzAudAddService SERVICE_NAME: intelppm SERVICE_NAME: IpNat SERVICE_NAME: IPSec SERVICE_NAME: isapnp SERVICE_NAME: Kbdclass SERVICE_NAME: khips SERVICE_NAME: kmixer SERVICE_NAME: KSecDD SERVICE_NAME: lirsgt SERVICE_NAME: LVUSBSta SERVICE_NAME: mnmdd SERVICE_NAME: Mouclass SERVICE_NAME: mouhid SERVICE_NAME: MountMgr SERVICE_NAME: MRxDAV SERVICE_NAME: MRxSmb SERVICE_NAME: Msfs SERVICE_NAME: mssmbios SERVICE_NAME: Mup SERVICE_NAME: NDIS SERVICE_NAME: NdisTapi SERVICE_NAME: Ndisuio SERVICE_NAME: NdisWan SERVICE_NAME: NDProxy SERVICE_NAME: NetBIOS SERVICE_NAME: NetBT SERVICE_NAME: NIC1394 SERVICE_NAME: Npfs SERVICE_NAME: Ntfs SERVICE_NAME: NTIDrvr SERVICE_NAME: Null SERVICE_NAME: ohci1394 SERVICE_NAME: Parport SERVICE_NAME: PartMgr SERVICE_NAME: PCI SERVICE_NAME: PCIIde SERVICE_NAME: pfc SERVICE_NAME: PID_0928 SERVICE_NAME: PptpMiniport SERVICE_NAME: PSched SERVICE_NAME: psdfilter SERVICE_NAME: psdvdisk SERVICE_NAME: Ptilink SERVICE_NAME: PxHelp20 SERVICE_NAME: RasAcd SERVICE_NAME: Rasl2tp SERVICE_NAME: RasPppoe SERVICE_NAME: Raspti SERVICE_NAME: Rdbss SERVICE_NAME: RDPCDD SERVICE_NAME: redbook SERVICE_NAME: serenum SERVICE_NAME: Serial SERVICE_NAME: sptd SERVICE_NAME: sr SERVICE_NAME: Srv SERVICE_NAME: StyleXPHelper SERVICE_NAME: swenum SERVICE_NAME: sysaudio SERVICE_NAME: Tcpip SERVICE_NAME: TermDD SERVICE_NAME: UBHelper SERVICE_NAME: Update SERVICE_NAME: usbehci SERVICE_NAME: usbhub SERVICE_NAME: usbohci SERVICE_NAME: USBSTOR SERVICE_NAME: VgaSave SERVICE_NAME: VolSnap SERVICE_NAME: Wanarp SERVICE_NAME: wdmaud SERVICE_NAME: yukonwxp SERVICE_NAME: ZDPSp50 Drivers - Stopped: SERVICE_NAME: Abiosdsk SERVICE_NAME: abp480n5 SERVICE_NAME: ACPIEC SERVICE_NAME: adpu160m SERVICE_NAME: aec SERVICE_NAME: Aha154x SERVICE_NAME: aic78u2 SERVICE_NAME: aic78xx SERVICE_NAME: AliIde SERVICE_NAME: amsint SERVICE_NAME: asc SERVICE_NAME: asc3350p SERVICE_NAME: asc3550 SERVICE_NAME: AsyncMac SERVICE_NAME: Atdisk SERVICE_NAME: Atmarpc SERVICE_NAME: BVRPMPR5 SERVICE_NAME: cbidf2k SERVICE_NAME: CCDECODE SERVICE_NAME: cd20xrnt SERVICE_NAME: Cdaudio SERVICE_NAME: Changer SERVICE_NAME: CmdIde SERVICE_NAME: Cpqarray SERVICE_NAME: dac960nt SERVICE_NAME: dmboot SERVICE_NAME: dmio SERVICE_NAME: dmload SERVICE_NAME: DMusic SERVICE_NAME: dpti2o SERVICE_NAME: drmkaud SERVICE_NAME: Flpydisk SERVICE_NAME: hpn SERVICE_NAME: i2omgmt SERVICE_NAME: i2omp SERVICE_NAME: ini910u SERVICE_NAME: IntelIde SERVICE_NAME: Ip6Fw SERVICE_NAME: IpFilterDriver SERVICE_NAME: IpInIp SERVICE_NAME: IRENUM SERVICE_NAME: lbrtfdc SERVICE_NAME: Modem SERVICE_NAME: mraid35x SERVICE_NAME: MSKSSRV SERVICE_NAME: MSPCLOCK SERVICE_NAME: MSPQM SERVICE_NAME: MSTEE SERVICE_NAME: NABTSFEC SERVICE_NAME: NdisIP SERVICE_NAME: nsysaudm SERVICE_NAME: NwlnkFlt SERVICE_NAME: NwlnkFwd SERVICE_NAME: ParVdm SERVICE_NAME: PCIDump SERVICE_NAME: Pcmcia SERVICE_NAME: PDCOMP SERVICE_NAME: PDFRAME SERVICE_NAME: PDRELI SERVICE_NAME: PDRFRAME SERVICE_NAME: perc2 SERVICE_NAME: perc2hib SERVICE_NAME: ql1080 SERVICE_NAME: Ql10wnt SERVICE_NAME: ql12160 SERVICE_NAME: ql1240 SERVICE_NAME: ql1280 SERVICE_NAME: RDPWD SERVICE_NAME: Secdrv SERVICE_NAME: Sfloppy SERVICE_NAME: Simbad SERVICE_NAME: SLIP SERVICE_NAME: Sparrow SERVICE_NAME: splitter SERVICE_NAME: ssmdrv SERVICE_NAME: streamip SERVICE_NAME: swmidi SERVICE_NAME: symc810 SERVICE_NAME: symc8xx SERVICE_NAME: sym_hi SERVICE_NAME: sym_u3 SERVICE_NAME: TDPIPE SERVICE_NAME: TDTCP SERVICE_NAME: TosIde SERVICE_NAME: Udfs SERVICE_NAME: ultra SERVICE_NAME: usbccgp SERVICE_NAME: usbser SERVICE_NAME: usbsermptxp SERVICE_NAME: VClone SERVICE_NAME: ViaIde SERVICE_NAME: wanatw SERVICE_NAME: wceusbsh SERVICE_NAME: WDICA SERVICE_NAME: WS2IFSL SERVICE_NAME: WSTCODEC SERVICE_NAME: WudfPf SERVICE_NAME: WudfRd SERVICE_NAME: ZD1211BU(ZyDAS) SERVICE_NAME: ZD1211U(ZyDAS) Services - Running: SERVICE_NAME: Acer Media Server SERVICE_NAME: AcerMemUsageCheckService SERVICE_NAME: ALG SERVICE_NAME: AntiVirScheduler SERVICE_NAME: AntiVirService SERVICE_NAME: Ati HotKey Poller SERVICE_NAME: AudioSrv SERVICE_NAME: AVG Anti-Spyware Guard SERVICE_NAME: BITS SERVICE_NAME: Browser SERVICE_NAME: CLCapSvc SERVICE_NAME: CLSched SERVICE_NAME: CryptSvc SERVICE_NAME: CyberLink Media Library Service SERVICE_NAME: DcomLaunch SERVICE_NAME: Dhcp SERVICE_NAME: Dnscache SERVICE_NAME: ERSvc SERVICE_NAME: Eventlog SERVICE_NAME: EventSystem SERVICE_NAME: FastUserSwitchingCompatibility SERVICE_NAME: helpsvc SERVICE_NAME: lanmanserver SERVICE_NAME: lanmanworkstation SERVICE_NAME: LightScribeService SERVICE_NAME: LmHosts SERVICE_NAME: MSIServer SERVICE_NAME: Netman SERVICE_NAME: Nla SERVICE_NAME: PlugPlay SERVICE_NAME: PolicyAgent SERVICE_NAME: ProtectedStorage SERVICE_NAME: RasMan SERVICE_NAME: RpcSs SERVICE_NAME: SamSs SERVICE_NAME: Schedule SERVICE_NAME: seclogon SERVICE_NAME: SENS SERVICE_NAME: SharedAccess SERVICE_NAME: ShellHWDetection SERVICE_NAME: Spooler SERVICE_NAME: srservice SERVICE_NAME: SSDPSRV SERVICE_NAME: stisvc SERVICE_NAME: StyleXPService SERVICE_NAME: TapiSrv SERVICE_NAME: TermService SERVICE_NAME: Themes SERVICE_NAME: TrkWks SERVICE_NAME: usnjsvc SERVICE_NAME: W32Time SERVICE_NAME: WebClient SERVICE_NAME: winmgmt SERVICE_NAME: wscsvc SERVICE_NAME: WSearch SERVICE_NAME: wuauserv SERVICE_NAME: WZCSVC Services - Stopped: SERVICE_NAME: Alerter SERVICE_NAME: AppMgmt SERVICE_NAME: aspnet_state SERVICE_NAME: Automatisches LiveUpdate - Scheduler SERVICE_NAME: CiSvc SERVICE_NAME: ClipSrv SERVICE_NAME: clr_optimization_v2.0.50727_32 SERVICE_NAME: CLTNetCnService SERVICE_NAME: COMSysApp SERVICE_NAME: dmadmin SERVICE_NAME: dmserver SERVICE_NAME: Fax SERVICE_NAME: gusvc SERVICE_NAME: HidServ SERVICE_NAME: HTTPFilter SERVICE_NAME: IDriverT SERVICE_NAME: ImapiService SERVICE_NAME: Messenger SERVICE_NAME: mnmsrvc SERVICE_NAME: MSDTC SERVICE_NAME: NetDDE SERVICE_NAME: NetDDEdsdm SERVICE_NAME: Netlogon SERVICE_NAME: NtLmSsp SERVICE_NAME: NtmsSvc SERVICE_NAME: RasAuto SERVICE_NAME: RDSessMgr SERVICE_NAME: RemoteAccess SERVICE_NAME: RpcLocator SERVICE_NAME: RSVP SERVICE_NAME: SCardSvr SERVICE_NAME: SPF4 SERVICE_NAME: SwPrv SERVICE_NAME: SysmonLog SERVICE_NAME: upnphost SERVICE_NAME: UPS SERVICE_NAME: VSS SERVICE_NAME: WLSetupSvc SERVICE_NAME: WmdmPmSN SERVICE_NAME: WmiApSrv SERVICE_NAME: WMPNetworkSvc SERVICE_NAME: WudfSvc SERVICE_NAME: xmlprov Files Created/Modified - 60 Days : C:\ Æ0Ÿ €>*œ té™ è¦èÿu€>Ñž u€> œ ºöuéÆ,Ÿ¸ l¾ž»! 3ɺ€ - 1252, 6 Jan 2008 3:00:28 211 A.SH. "C:\BOOT.BKK" 6 Jan 2008 3:00:28 211 A.SH. "C:\boot.ini" 11 Jan 2008 17:55:50 1.073.074.176 A.SH. "C:\hiberfil.sys" 14 Dec 2007 21:49:26 176 A.... "C:\out.txt" 11 Jan 2008 17:55:48 1.610.612.736 A.SH. "C:\pagefile.sys" 6 Jan 2008 21:03:44 5.681 A.... "C:\rapport.txt" 10 Jan 2008 14:33:52 45 A.... "C:\TEST.XML" C:\WINDOWS\ 11 Jan 2008 17:56:20 0 A.... "C:\WINDOWS\0.log" 11 Jan 2008 17:55:56 2.048 A.S.. "C:\WINDOWS\bootstat.dat" 9 Jan 2008 23:02:48 561.403 A.... "C:\WINDOWS\comsetup.log" 15 Dec 2007 22:08:54 438.485 A.... "C:\WINDOWS\DirectX.log" 3 Dec 2007 19:31:20 886 A.... "C:\WINDOWS\EReg.dat" 9 Jan 2008 23:02:48 1.709.824 A.... "C:\WINDOWS\FaxSetup.log" 9 Jan 2008 23:02:48 264.460 A.... "C:\WINDOWS\iis6.log" 9 Jan 2008 23:02:42 1.355 A.... "C:\WINDOWS\imsins.BAK" 9 Jan 2008 23:02:48 1.355 A.... "C:\WINDOWS\imsins.log" 18 Dec 2007 19:12:22 286.720 A.... "C:\WINDOWS\iun507.exe" 7 Jan 2008 18:20:30 19.847 A.... "C:\WINDOWS\KB909394.log" 12 Dec 2007 15:44:20 12.697 A.... "C:\WINDOWS\KB941568.log" 12 Dec 2007 15:45:14 16.024 A.... "C:\WINDOWS\KB941569.log" 9 Jan 2008 23:02:48 13.854 A.... "C:\WINDOWS\KB941644.log" 12 Dec 2007 15:44:40 24.310 A.... "C:\WINDOWS\KB942615-IE7.log" 12 Dec 2007 15:45:28 30.537 A.... "C:\WINDOWS\KB942763.log" 14 Nov 2007 22:36:06 8.633 A.... "C:\WINDOWS\KB943460.log" 9 Jan 2008 23:02:42 17.141 A.... "C:\WINDOWS\KB943485.log" 12 Dec 2007 15:44:16 12.429 A.... "C:\WINDOWS\KB944653.log" 30 Nov 2007 19:10:34 1.073.115.136 A.... "C:\WINDOWS\MEMORY.DMP" 12 Dec 2007 15:49:04 4.422 A.... "C:\WINDOWS\ModemLog_Motorola USB Modem.txt" 21 Dec 2007 23:44:04 2.496 A.... "C:\WINDOWS\mozver.dat" 9 Jan 2008 23:02:48 84.332 A.... "C:\WINDOWS\msgsocm.log" 11 Jan 2008 17:40:42 512.076 A.... "C:\WINDOWS\ntbtlog.txt" 9 Jan 2008 23:02:48 337.744 A.... "C:\WINDOWS\ntdtcsetup.log" 9 Jan 2008 23:02:48 810.780 A.... "C:\WINDOWS\ocgen.log" 9 Jan 2008 23:02:48 89.576 A.... "C:\WINDOWS\ocmsn.log" 26 Dec 2007 17:38:04 1.962 A.... "C:\WINDOWS\OEWABLog.txt" 11 Jan 2008 17:55:06 32.540 A.... "C:\WINDOWS\SchedLgU.Txt" 8 Jan 2008 13:00:56 320.493 A.... "C:\WINDOWS\setupact.log" 9 Jan 2008 23:02:48 499.548 A.... "C:\WINDOWS\setupapi.log" 11 Jan 2008 17:57:14 255 A.... "C:\WINDOWS\system.ini" 9 Jan 2008 23:02:48 649.777 A.... "C:\WINDOWS\tsoc.log" 2 Dec 2007 19:24:36 1.302 A.... "C:\WINDOWS\unins000.dat" 2 Dec 2007 19:24:36 72.748 A.... "C:\WINDOWS\unins000.exe" 12 Dec 2007 15:44:34 123.259 A.... "C:\WINDOWS\updspapi.log" 11 Jan 2008 17:56:26 159 A.... "C:\WINDOWS\wiadebug.log" 11 Jan 2008 17:56:22 50 A.... "C:\WINDOWS\wiaservc.log" 11 Jan 2008 17:59:36 742 A.... "C:\WINDOWS\win.ini" 11 Jan 2008 17:56:26 1.487.652 A.... "C:\WINDOWS\WindowsUpdate.log" 7 Jan 2008 23:21:00 159.907 A.... "C:\WINDOWS\wmsetup.log" 9 Jan 2008 23:41:26 11.580 A.... "C:\WINDOWS\Debug\mrt.log" 9 Jan 2008 23:41:26 4.082 A.... "C:\WINDOWS\Debug\mrteng.log" 11 Jan 2008 17:55:56 0 A.... "C:\WINDOWS\Debug\PASSWD.LOG" 11 Jan 2008 17:54:48 110 A.... "C:\WINDOWS\erdnt\CFrecovery.bat" 7 Jan 2008 18:22:14 4.100 A.... "C:\WINDOWS\inf\branches.PNF" 15 Dec 2007 22:08:46 4.860 A.... "C:\WINDOWS\inf\d3dx9_31_x86.PNF" 7 Jan 2008 18:22:14 1.464.168 A.... "C:\WINDOWS\inf\INFCACHE.1" 7 Jan 2008 18:20:32 8.258 A.... "C:\WINDOWS\inf\oem33.PNF" 7 Jan 2008 18:20:32 8.172 A.... "C:\WINDOWS\inf\oem34.PNF" 7 Jan 2008 18:21:22 127.698 A.... "C:\WINDOWS\inf\oem36.PNF" 15 Dec 2007 22:08:48 5.196 A.... "C:\WINDOWS\inf\xact2_5_x86.PNF" 15 Dec 2007 22:08:48 5.196 A.... "C:\WINDOWS\inf\xact2_6_x86.PNF" 15 Dec 2007 22:08:46 5.196 A.... "C:\WINDOWS\inf\xact2_4_x86.PNF" 26 Dec 2007 18:43:26 43.520 A.... "C:\WINDOWS\system32\CmdLineExt03.dll" 4 Dec 2007 12:30:14 291.680 A.... "C:\WINDOWS\system32\FNTCACHE.DAT" 20 Dec 2007 23:11:52 81.920 A.... "C:\WINDOWS\system32\IEDFix.exe" 6 Jan 2008 12:34:02 5.628 A.... "C:\WINDOWS\system32\jupdate-1.6.0_03-b05.log" 11 Dec 2007 23:34:44 1.044.480 A.... "C:\WINDOWS\system32\libdivx.dll" 2 Jan 2008 19:21:36 17.642.616 A.... "C:\WINDOWS\system32\MRT.exe" 9 Jan 2008 23:04:14 118 A.... "C:\WINDOWS\system32\MRT.INI" 22 Nov 2007 9:50:50 1.193.952 A.... "C:\WINDOWS\system32\NpFv41629.dll" 11 Dec 2007 23:34:44 200.704 A.... "C:\WINDOWS\system32\ssldivx.dll" 6 Jan 2008 21:03:04 3.676 A.... "C:\WINDOWS\system32\tmp.reg" 6 Jan 2008 21:03:04 0 A.... "C:\WINDOWS\system32\tmp.txt" 13 Nov 2007 12:31:12 60.416 ..... "C:\WINDOWS\system32\tzchange.exe" 12 Dec 2007 15:45:26 387.268 A.... "C:\WINDOWS\system32\TZLog.log" 9 Jan 2008 14:09:30 12.720 A.... "C:\WINDOWS\system32\wpa.dbl" 11 Jan 2008 17:25:02 248 A.... "C:\WINDOWS\Tasks\Auf Updates fr Windows Live Toolbar prfen.job" 11 Jan 2008 18:00:02 268 A..H. "C:\WINDOWS\Tasks\B9D4CCF590BB4549.job" 11 Jan 2008 17:56:00 6 A..H. "C:\WINDOWS\Tasks\SA.DAT" 11 Jan 2008 17:56:18 0 A.... "C:\WINDOWS\temp\CLML_AGENT_LOG1.txt" 11 Jan 2008 17:56:12 0 A.... "C:\WINDOWS\temp\JET8387.tmp" 11 Jan 2008 18:10:36 2.977 A.... "C:\WINDOWS\temp\scsE.tmp" 11 Jan 2008 17:56:18 0 A.... "C:\WINDOWS\temp\sqlite_Aas2bxZnmO7wtit" 14 Nov 2007 22:36:06 13.516 A.... "C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.inf" 14 Nov 2007 22:36:00 400 A.... "C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.txt" 7 Jan 2008 18:20:30 13.175 A.... "C:\WINDOWS\$NtUninstallKB909394$\spuninst\spuninst.inf" 9 Jan 2008 23:02:48 12.805 A.... "C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.inf" 9 Jan 2008 23:02:46 363 A.... "C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.txt" 12 Dec 2007 15:44:16 11.946 A.... "C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.inf" 12 Dec 2007 15:44:10 272 A.... "C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.txt" 12 Dec 2007 15:45:28 13.099 A.... "C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.inf" 12 Dec 2007 15:45:28 270 A.... "C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.txt" 9 Jan 2008 23:02:42 12.411 A.... "C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.inf" 9 Jan 2008 23:02:38 305 A.... "C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.txt" 12 Dec 2007 15:45:08 11.993 A.... "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.inf" 12 Dec 2007 15:45:08 254 A.... "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.txt" 12 Dec 2007 15:44:20 12.205 A.... "C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.inf" 12 Dec 2007 15:44:20 312 A.... "C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.txt" 7 Jan 2008 18:19:04 6.841.856 A.... "C:\WINDOWS\Downloaded Installations\{D15E9D8A-3726-4446-BB42-7EBB70A609B7}\Microsoft ActiveSync 4.0.msi" 11 Jan 2008 17:06:34 303.104 A.... "C:\WINDOWS\erdnt\Hiv-backup\default" 11 Jan 2008 17:06:34 673 A.... "C:\WINDOWS\erdnt\Hiv-backup\ERDNT.CON" 11 Jan 2008 17:06:34 1.241 A.... "C:\WINDOWS\erdnt\Hiv-backup\ERDNT.INF" 11 Jan 2008 17:06:34 24.576 A.... "C:\WINDOWS\erdnt\Hiv-backup\SAM" 11 Jan 2008 17:06:32 57.344 A.... "C:\WINDOWS\erdnt\Hiv-backup\SECURITY" 11 Jan 2008 17:06:32 25.522.176 A.... "C:\WINDOWS\erdnt\Hiv-backup\software" 11 Jan 2008 17:06:34 6.856.704 A.... "C:\WINDOWS\erdnt\Hiv-backup\system" 11 Jan 2008 17:13:16 303.104 A.... "C:\WINDOWS\erdnt\subs\default" 11 Jan 2008 17:13:16 673 A.... "C:\WINDOWS\erdnt\subs\ERDNT.CON" 11 Jan 2008 17:13:16 460 A.... "C:\WINDOWS\erdnt\subs\ERDNT.INF" 11 Jan 2008 17:13:16 24.576 A.... "C:\WINDOWS\erdnt\subs\SAM" 11 Jan 2008 17:13:16 57.344 A.... "C:\WINDOWS\erdnt\subs\SECURITY" 11 Jan 2008 17:13:16 25.522.176 A.... "C:\WINDOWS\erdnt\subs\software" 11 Jan 2008 17:13:16 25.522.176 A.... "C:\WINDOWS\erdnt\subs\software.bak" 11 Jan 2008 17:13:20 1.024 A..H. "C:\WINDOWS\erdnt\subs\software.LOG" 11 Jan 2008 17:13:16 6.856.704 A.... "C:\WINDOWS\erdnt\subs\system" 11 Jan 2008 17:13:16 6.856.704 A.... "C:\WINDOWS\erdnt\subs\system.bak" 11 Jan 2008 17:13:20 1.024 A..H. "C:\WINDOWS\erdnt\subs\system.LOG" 12 Dec 2007 15:44:30 8.192 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00002" 12 Dec 2007 15:44:30 90.112 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00003" 12 Dec 2007 15:44:30 8.192 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00004" 12 Dec 2007 15:44:30 8.192 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00005" 12 Dec 2007 15:44:30 8.192 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00006" 12 Dec 2007 15:44:30 8.192 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00007" 12 Dec 2007 15:44:30 8.192 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00008" 12 Dec 2007 15:44:30 8.192 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00009" 12 Dec 2007 15:44:30 8.192 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00010" 12 Dec 2007 15:44:30 8.192 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00011" 12 Dec 2007 15:44:30 8.192 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00012" 12 Dec 2007 15:44:30 8.192 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00013" 12 Dec 2007 15:44:30 8.192 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00014" 12 Dec 2007 15:44:30 12.288 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\reg00015" 15 Dec 2007 22:08:02 278.728 A.... "C:\WINDOWS\system32\drivers\atksgt.sys" 18 Nov 2007 22:51:46 61.632 A.... "C:\WINDOWS\system32\drivers\avipbb.sys" 11 Jan 2008 18:02:58 324 A.... "C:\WINDOWS\system32\drivers\fwdrv.err" 15 Dec 2007 22:08:00 25.416 A.... "C:\WINDOWS\system32\drivers\lirsgt.sys" 13 Nov 2007 11:25:54 20.480 A.... "C:\WINDOWS\system32\drivers\secdrv.sys" 6 Jan 2008 3:12:52 135.168 A.... "C:\WINDOWS\system32\NtmsData\NTMSDATA" 6 Jan 2008 3:12:52 135.168 A.... "C:\WINDOWS\system32\NtmsData\NTMSDATA.BAK" 6 Jan 2008 3:12:52 90.920 A.... "C:\WINDOWS\system32\NtmsData\NTMSIDX" 6 Jan 2008 3:12:16 816 A.... "C:\WINDOWS\system32\NtmsData\NTMSREG" 13 Nov 2007 12:02:46 60.416 A.... "C:\WINDOWS\$hf_mig$\KB942763\SP2QFE\tzchange.exe" 14 Nov 2007 10:57:30 705 A.... "C:\WINDOWS\$hf_mig$\KB942763\update\branches.inf" 14 Nov 2007 11:21:10 11.284 A.... "C:\WINDOWS\$hf_mig$\KB942763\update\KB942763.CAT" 14 Nov 2007 11:26:34 204 A.... "C:\WINDOWS\$hf_mig$\KB942763\update\update.ver" 14 Nov 2007 10:57:30 496 A.... "C:\WINDOWS\$hf_mig$\KB942763\update\updatebr.inf" 14 Nov 2007 11:14:14 54.030 A.... "C:\WINDOWS\$hf_mig$\KB942763\update\update_SP2QFE.inf" 13 Nov 2007 9:47:44 20.480 A.... "C:\WINDOWS\$hf_mig$\KB944653\SP2QFE\secdrv.sys" 13 Nov 2007 18:33:56 705 A.... "C:\WINDOWS\$hf_mig$\KB944653\update\branches.inf" 13 Nov 2007 18:47:50 10.876 A.... "C:\WINDOWS\$hf_mig$\KB944653\update\KB944653.CAT" 13 Nov 2007 18:53:58 188 A.... "C:\WINDOWS\$hf_mig$\KB944653\update\update.ver" 13 Nov 2007 18:33:56 496 A.... "C:\WINDOWS\$hf_mig$\KB944653\update\updatebr.inf" 13 Nov 2007 18:44:14 23.556 A.... "C:\WINDOWS\$hf_mig$\KB944653\update\update_SP2QFE.inf" 12 Dec 2007 15:44:40 23.431 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.inf" 12 Dec 2007 15:44:30 7.305 A.... "C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.txt" 12 Dec 2007 15:46:50 102.864 A.... "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.log" 29 Nov 2007 14:59:26 589.946 A.... "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen_service.log" 14 Nov 2007 11:21:10 11.284 ..S.. "C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB942763.cat" 13 Nov 2007 18:47:50 10.876 ..S.. "C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB944653.cat" 9 Jan 2008 23:02:48 8 A.... "C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\TimeStamp" 11 Jan 2008 17:56:38 27 A.... "C:\WINDOWS\system32\drivers\etc\hosts" 11 Jan 2008 17:06:34 233.472 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT" 11 Jan 2008 17:06:34 8.192 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat" 11 Jan 2008 17:06:34 237.568 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT" 11 Jan 2008 17:06:34 8.192 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat" 11 Jan 2008 17:06:34 11.452.416 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT" 11 Jan 2008 17:06:34 151.552 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat" C:\Programme\ 22 Nov 2007 21:11:04 675.880 A.... "C:\Programme\AntiVir PersonalEdition Classic\avcenter.exe" 6 Jan 2008 2:48:40 3.084.800 A.... "C:\Programme\AntiVir PersonalEdition Classic\avewin32.dll" 18 Nov 2007 22:51:44 249.896 A.... "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" 18 Nov 2007 22:51:44 214.056 A.... "C:\Programme\AntiVir PersonalEdition Classic\avguard.exe" 6 Jan 2008 2:48:44 360.488 A.... "C:\Programme\AntiVir PersonalEdition Classic\avpack32.dll" 18 Nov 2007 22:51:44 241.704 A.... "C:\Programme\AntiVir PersonalEdition Classic\ccguard.dll" 6 Jan 2008 2:48:34 77.864 A.... "C:\Programme\AntiVir PersonalEdition Classic\preupd.exe" 18 Nov 2007 22:51:42 426.024 A.... "C:\Programme\AntiVir PersonalEdition Classic\updlib.dll" 15 Nov 2007 20:38:34 55.415 A.... "C:\Programme\Azureus\Uninstall.exe" 15 Dec 2007 22:07:56 51.587 A.... "C:\Programme\Cobra 11 - Crash Time Demo\Uninstall.exe" 21 Dec 2007 23:43:48 95.905 A.... "C:\Programme\DivX\DivXContentUploaderUninstall.exe" 21 Dec 2007 23:43:48 95.905 A.... "C:\Programme\DivX\DivXWebPlayerUninstall.exe" 18 Dec 2007 19:12:22 100.418 A.... "C:\Programme\FILERECOVERY PRO DEMO\irunin.dat" 19 Nov 2007 20:39:06 6.428 A.... "C:\Programme\Free Internet TV\unins000.dat" 19 Nov 2007 20:38:56 694.041 A.... "C:\Programme\Free Internet TV\unins000.exe" 2 Dec 2007 11:36:14 13.952 A.... "C:\Programme\Mozilla Firefox\AccessibleMarshal.dll" 2 Dec 2007 11:36:16 7.650.416 A.... "C:\Programme\Mozilla Firefox\firefox.exe" 2 Dec 2007 11:36:16 200.829 A.... "C:\Programme\Mozilla Firefox\freebl3.dll" 2 Dec 2007 11:36:16 456.296 A.... "C:\Programme\Mozilla Firefox\js3250.dll" 2 Dec 2007 11:36:16 161.392 A.... "C:\Programme\Mozilla Firefox\nspr4.dll" 2 Dec 2007 11:36:16 378.472 A.... "C:\Programme\Mozilla Firefox\nss3.dll" 2 Dec 2007 11:36:16 271.984 A.... "C:\Programme\Mozilla Firefox\nssckbi.dll" 2 Dec 2007 11:36:16 34.424 A.... "C:\Programme\Mozilla Firefox\plc4.dll" 2 Dec 2007 11:36:16 30.320 A.... "C:\Programme\Mozilla Firefox\plds4.dll" 2 Dec 2007 11:36:16 112.232 A.... "C:\Programme\Mozilla Firefox\smime3.dll" 2 Dec 2007 11:36:16 254.060 A.... "C:\Programme\Mozilla Firefox\softokn3.dll" 2 Dec 2007 11:36:16 132.712 A.... "C:\Programme\Mozilla Firefox\ssl3.dll" 2 Dec 2007 11:36:18 132.232 A.... "C:\Programme\Mozilla Firefox\updater.exe" 2 Dec 2007 11:36:18 13.416 A.... "C:\Programme\Mozilla Firefox\xpcom.dll" 2 Dec 2007 11:36:18 73.848 A.... "C:\Programme\Mozilla Firefox\xpcom_compat.dll" 2 Dec 2007 11:36:18 422.000 A.... "C:\Programme\Mozilla Firefox\xpcom_core.dll" 2 Dec 2007 11:36:18 73.336 A.... "C:\Programme\Mozilla Firefox\xpicleanup.exe" 2 Dec 2007 11:36:18 12.400 A.... "C:\Programme\Mozilla Firefox\xpistub.dll" 19 Nov 2007 20:39:36 22.055 A.... "C:\Programme\concept design\onlineTV 3\unins000.dat" 19 Nov 2007 20:39:10 688.133 A.... "C:\Programme\concept design\onlineTV 3\unins000.exe" 11 Dec 2007 23:32:48 1.933.312 A.... "C:\Programme\DivX\DivX Content Uploader\ContentUploadCheck.dll" 11 Dec 2007 23:32:48 845.824 A.... "C:\Programme\DivX\DivX Content Uploader\libxml2.dll" 11 Dec 2007 23:32:48 1.359.872 A.... "C:\Programme\DivX\DivX Content Uploader\npUpload.dll" 11 Dec 2007 23:33:02 1.335.600 A.... "C:\Programme\DivX\DivX Web Player\npdivx32.dll" 22 Dec 2007 13:59:00 18.681 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\heuristic.dat" 6 Jan 2008 21:07:28 475.893 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe" 14 Nov 2007 20:55:12 107.512 A.... "C:\Programme\InstallShield Installation Information\{11AFE21E-B193-430D-B57A-DFF7815BB962}\setup.exe" 14 Nov 2007 20:55:14 155.648 A.... "C:\Programme\InstallShield Installation Information\{11AFE21E-B193-430D-B57A-DFF7815BB962}\_setup.dll" 22 Nov 2007 9:50:50 1.193.952 A.... "C:\Programme\Internet Explorer\PLUGINS\NpFv41629.dll" 9 Jan 2008 16:54:42 1.244.712 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SetupOneCare.exe" 26 Dec 2007 17:48:26 147.015 A.... "C:\Programme\Mozilla Firefox\components\compreg.dat" 2 Dec 2007 11:36:14 67.696 A.... "C:\Programme\Mozilla Firefox\components\jar50.dll" 2 Dec 2007 11:36:14 54.376 A.... "C:\Programme\Mozilla Firefox\components\jsd3250.dll" 2 Dec 2007 11:36:14 34.952 A.... "C:\Programme\Mozilla Firefox\components\myspell.dll" 2 Dec 2007 11:36:14 46.720 A.... "C:\Programme\Mozilla Firefox\components\spellchk.dll" 2 Dec 2007 11:36:14 172.144 A.... "C:\Programme\Mozilla Firefox\components\xpinstal.dll" 26 Dec 2007 17:48:26 94.676 A.... "C:\Programme\Mozilla Firefox\components\xpti.dat" 11 Dec 2007 23:33:02 1.335.600 A.... "C:\Programme\Mozilla Firefox\plugins\npdivx32.dll" 22 Nov 2007 9:50:50 1.193.952 A.... "C:\Programme\Mozilla Firefox\plugins\NpFv41629.dll" 2 Dec 2007 11:36:16 22.664 A.... "C:\Programme\Mozilla Firefox\plugins\npnul32.dll" 2 Dec 2007 11:36:16 451.928 A.... "C:\Programme\Mozilla Firefox\uninstall\helper.exe" 7 Jan 2008 17:44:38 186 A.... "C:\Programme\TGTSoft\StyleXP\Preview.html" 7 Jan 2008 0:05:18 173.267 A.... "C:\Programme\TGTSoft\StyleXP\StyleXP-uninstall.exe" 28 Nov 2007 11:49:38 70.672 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Client.dll" 28 Nov 2007 11:52:42 898.064 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.CoreServices.dll" 28 Nov 2007 11:49:54 82.960 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.FileDestinations.dll" 28 Nov 2007 11:49:38 74.768 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.HtmlParser.dll" 28 Nov 2007 11:52:34 447.504 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.Localization.dll" 28 Nov 2007 11:52:22 263.184 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.HtmlEditor.dll" 28 Nov 2007 11:52:22 283.664 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.Controls.dll" 28 Nov 2007 11:50:10 140.304 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.Interop.dll" 28 Nov 2007 11:49:22 62.480 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.Passport.dll" 28 Nov 2007 11:51:44 168.976 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.Interop.Mshtml.dll" 28 Nov 2007 11:52:34 377.872 A.... "C:\Programme\Windows Live\Writer\WindowsLiveLocal.WriterPlugin.dll" 28 Nov 2007 11:49:56 119.824 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.Mshtml.dll" 28 Nov 2007 11:49:20 54.288 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.Extensibility.dll" 28 Nov 2007 11:49:54 111.632 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.SpellChecker.dll" 28 Nov 2007 11:52:46 2.909.200 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.PostEditor.dll" 28 Nov 2007 11:49:22 54.288 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.Api.dll" 28 Nov 2007 11:49:36 62.480 A.... "C:\Programme\Windows Live\Writer\WindowsLiveWriter.exe" 28 Nov 2007 11:52:42 594.960 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.ApplicationFramework.dll" 28 Nov 2007 11:52:30 336.912 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.BlogClient.dll" 28 Nov 2007 11:49:40 78.864 A.... "C:\Programme\Windows Live\Writer\WindowsLive.Writer.BrowserControl.dll" 15 Dec 2007 13:52:14 2.738 A.... "C:\Programme\Winamp\Plugins\vis_avs.dat" 11 Dec 2007 23:33:58 479.232 A.... "C:\Programme\DivX\DivX Web Player\Microsoft.VC80.CRT\msvcm80.dll" 11 Dec 2007 23:33:58 548.864 A.... "C:\Programme\DivX\DivX Web Player\Microsoft.VC80.CRT\msvcp80.dll" 11 Dec 2007 23:33:58 626.688 A.... "C:\Programme\DivX\DivX Web Player\Microsoft.VC80.CRT\msvcr80.dll" 14 Nov 2007 20:55:12 618.496 A.... "C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\agent.exe" 14 Nov 2007 20:55:12 278.528 A.... "C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\ISDM.exe" 14 Nov 2007 20:55:12 81.920 A.... "C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe" 14 Nov 2007 20:55:12 368.640 A.... "C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\_isusres.dll" 18 Dec 2007 0:56:14 28.479 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3117.dat" 18 Dec 2007 0:56:14 12.893 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3118.dat" 18 Dec 2007 0:56:14 17.778 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3119.dat" 18 Dec 2007 0:56:16 11.152 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3120.dat" 18 Dec 2007 0:56:16 14.218 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3121.dat" 18 Dec 2007 0:56:16 23.827 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3122.dat" 18 Dec 2007 0:56:16 21.071 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3123.dat" 18 Dec 2007 0:56:16 80 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3124.dat" 18 Dec 2007 0:56:16 662 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3125.dat" 18 Dec 2007 0:56:16 22.551 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3126.dat" 18 Dec 2007 0:56:16 34.616 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3127.dat" 18 Dec 2007 0:56:16 137 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3128.dat" 18 Dec 2007 0:56:16 18.280 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3129.dat" 18 Dec 2007 0:56:16 77 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3130.dat" 18 Dec 2007 0:56:16 79 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3131.dat" 18 Dec 2007 0:56:16 20.834 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3132.dat" 18 Dec 2007 0:56:16 15.534 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3133.dat" 18 Dec 2007 0:56:16 10.115 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3134.dat" 18 Dec 2007 0:56:16 76 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3135.dat" 18 Dec 2007 0:56:16 16.658 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3136.dat" 18 Dec 2007 0:56:16 19.392 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3137.dat" 18 Dec 2007 0:56:16 251 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3138.dat" 18 Dec 2007 0:56:16 61 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3139.dat" 18 Dec 2007 0:56:16 8.027 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3140.dat" 18 Dec 2007 0:56:16 2.187 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3141.dat" 18 Dec 2007 0:56:16 5.025 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3142.dat" 18 Dec 2007 0:56:16 3.358 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3143.dat" 18 Dec 2007 0:56:16 193 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3144.dat" 18 Dec 2007 0:56:16 2.209 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3145.dat" 18 Dec 2007 0:56:16 1.074 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3146.dat" 18 Dec 2007 0:56:16 25.174 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3147.dat" 18 Dec 2007 0:56:16 48.732 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3148.dat" 18 Dec 2007 0:56:16 3.416 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3149.dat" 18 Dec 2007 0:56:16 2.463 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3150.dat" 18 Dec 2007 0:56:16 2.378 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3151.dat" 18 Dec 2007 0:56:16 241 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3152.dat" 18 Dec 2007 0:56:16 64.904 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3153.dat" 18 Dec 2007 0:56:16 14.997 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3154.dat" 18 Dec 2007 0:56:16 2.579 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3155.dat" 18 Dec 2007 0:56:16 4.384 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3156.dat" 18 Dec 2007 0:56:16 2.410 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3157.dat" 18 Dec 2007 0:56:18 71.617 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3158.dat" 18 Dec 2007 0:56:18 190 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3159.dat" 18 Dec 2007 0:56:18 3.331 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3160.dat" 18 Dec 2007 0:56:18 3.509 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3161.dat" 18 Dec 2007 0:56:18 1.897 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3162.dat" 18 Dec 2007 0:56:18 1.931 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3163.dat" 18 Dec 2007 0:56:18 2.098 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3164.dat" 18 Dec 2007 0:56:18 1.292 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3165.dat" 18 Dec 2007 0:56:18 1.919 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3166.dat" 18 Dec 2007 0:56:18 1.777 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3167.dat" 18 Dec 2007 0:56:18 1.918 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3168.dat" 18 Dec 2007 0:56:18 1.973 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3169.dat" 18 Dec 2007 0:56:18 2.089 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3170.dat" 18 Dec 2007 0:56:18 1.906 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3171.dat" 18 Dec 2007 0:56:18 77 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3172.dat" 18 Dec 2007 0:56:18 1.247 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3173.dat" 18 Dec 2007 0:56:18 1.966 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3174.dat" 18 Dec 2007 0:56:18 2.157 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3175.dat" 18 Dec 2007 0:56:18 1.737 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3176.dat" 18 Dec 2007 0:56:18 1.908 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3177.dat" 18 Dec 2007 0:56:18 2.245 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3178.dat" 18 Dec 2007 0:56:18 1.954 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3179.dat" 18 Dec 2007 0:56:18 2.002 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3180.dat" 18 Dec 2007 0:56:18 2.311 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3181.dat" 18 Dec 2007 0:56:18 1.718 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3182.dat" 18 Dec 2007 0:56:18 1.904 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3183.dat" 18 Dec 2007 0:56:18 2.367 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3184.dat" 18 Dec 2007 0:56:18 1.724 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3185.dat" 18 Dec 2007 0:56:18 2.203 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3186.dat" 18 Dec 2007 0:56:18 2.162 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3187.dat" 18 Dec 2007 0:56:18 1.565 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3188.dat" 18 Dec 2007 0:56:18 1.806 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3189.dat" 18 Dec 2007 0:56:18 1.961 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3190.dat" 18 Dec 2007 0:56:18 2.207 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3191.dat" 18 Dec 2007 0:56:18 2.152 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3192.dat" 18 Dec 2007 0:56:18 1.993 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3193.dat" 18 Dec 2007 0:56:18 1.403 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3194.dat" 18 Dec 2007 0:56:18 1.445 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3195.dat" 18 Dec 2007 0:56:18 2.422 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3196.dat" 18 Dec 2007 0:56:18 2.388 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3197.dat" 18 Dec 2007 0:56:18 2.807 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3198.dat" 18 Dec 2007 0:56:18 79 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3199.dat" 18 Dec 2007 0:56:18 2.244 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3200.dat" 18 Dec 2007 0:56:18 2.081 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3201.dat" 18 Dec 2007 0:56:18 2.044 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3202.dat" 18 Dec 2007 0:56:18 1.662 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3203.dat" 18 Dec 2007 0:56:18 1.860 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3204.dat" 18 Dec 2007 0:56:18 1.861 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3205.dat" 18 Dec 2007 0:56:18 2.184 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3206.dat" 18 Dec 2007 0:56:18 2.038 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3207.dat" 18 Dec 2007 0:56:18 1.971 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3208.dat" 18 Dec 2007 0:56:18 2.051 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3209.dat" 18 Dec 2007 0:56:18 1.969 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3210.dat" 18 Dec 2007 0:56:18 2.047 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3211.dat" 18 Dec 2007 0:56:18 2.645 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3212.dat" 18 Dec 2007 0:56:18 3.880 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3213.dat" 18 Dec 2007 0:56:18 2.107 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3214.dat" 18 Dec 2007 0:56:18 2.070 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3215.dat" 18 Dec 2007 0:56:18 1.897 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3216.dat" 18 Dec 2007 0:56:20 84 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3217.dat" 18 Dec 2007 0:56:20 3.495 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3218.dat" 18 Dec 2007 0:56:20 2.230 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3219.dat" 18 Dec 2007 0:56:20 2.251 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3220.dat" 18 Dec 2007 0:56:20 1.875 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3221.dat" 18 Dec 2007 0:56:20 1.819 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3222.dat" 18 Dec 2007 0:56:20 1.968 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3223.dat" 18 Dec 2007 0:56:20 4.960 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3224.dat" 18 Dec 2007 0:56:20 1.860 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3225.dat" 18 Dec 2007 0:56:20 2.301 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3226.dat" 18 Dec 2007 0:56:20 2.359 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3227.dat" 18 Dec 2007 0:56:20 2.448 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3228.dat" 18 Dec 2007 0:56:20 2.291 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3229.dat" 18 Dec 2007 0:56:20 3.402 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3230.dat" 18 Dec 2007 0:56:20 2.205 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3231.dat" 18 Dec 2007 0:56:20 2.981 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3232.dat" 18 Dec 2007 0:56:20 2.800 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3233.dat" 18 Dec 2007 0:56:20 2.037 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3234.dat" 18 Dec 2007 0:56:20 2.040 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3235.dat" 18 Dec 2007 0:56:20 1.719 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3236.dat" 18 Dec 2007 0:56:20 3.391 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3237.dat" 18 Dec 2007 0:56:20 376 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3238.dat" 18 Dec 2007 0:56:20 14.703 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3239.dat" 18 Dec 2007 0:56:20 16.969 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3240.dat" 18 Dec 2007 0:56:20 2.394 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3241.dat" 18 Dec 2007 0:56:20 1.901 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3242.dat" 18 Dec 2007 0:56:20 1.746 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3243.dat" 18 Dec 2007 0:56:20 1.449 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3244.dat" 18 Dec 2007 0:56:20 5.157 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3245.dat" 18 Dec 2007 0:56:20 3.044 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3246.dat" 18 Dec 2007 0:56:20 3.023 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3247.dat" 18 Dec 2007 0:56:20 134 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3248.dat" 18 Dec 2007 0:56:20 3.235 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3249.dat" 18 Dec 2007 0:56:20 3.937 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3250.dat" 18 Dec 2007 0:56:20 3.736 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3251.dat" 18 Dec 2007 0:56:20 3.976 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3252.dat" 18 Dec 2007 0:56:20 22.639 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3253.dat" 18 Dec 2007 0:56:20 3.250 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3254.dat" 18 Dec 2007 0:56:20 3.427 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3255.dat" 18 Dec 2007 0:56:20 4.132 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3256.dat" 18 Dec 2007 0:56:20 4.328 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3257.dat" 18 Dec 2007 0:56:20 2.666 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3258.dat" 18 Dec 2007 0:56:20 3.093 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3259.dat" 18 Dec 2007 0:56:20 2.371 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3260.dat" 18 Dec 2007 0:56:20 2.725 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3261.dat" 18 Dec 2007 0:56:20 2.055 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3262.dat" 18 Dec 2007 0:56:20 2.432 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3263.dat" 18 Dec 2007 0:56:20 2.573 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3264.dat" 18 Dec 2007 0:56:20 1.866 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3265.dat" 18 Dec 2007 0:56:20 2.320 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3266.dat" 18 Dec 2007 0:56:20 1.995 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3267.dat" 18 Dec 2007 0:56:20 2.190 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3268.dat" 18 Dec 2007 0:56:20 2.700 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3269.dat" 18 Dec 2007 0:56:20 2.377 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3270.dat" 18 Dec 2007 0:56:20 2.515 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3271.dat" 18 Dec 2007 0:56:20 2.064 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3272.dat" 18 Dec 2007 0:56:20 2.245 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3273.dat" 18 Dec 2007 0:56:22 31.081 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3274.dat" 18 Dec 2007 0:56:22 26.365 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3275.dat" 18 Dec 2007 0:56:22 35.143 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3276.dat" 18 Dec 2007 0:56:22 30.763 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3277.dat" 18 Dec 2007 0:56:22 138 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3278.dat" 18 Dec 2007 0:56:22 26.633 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3279.dat" 18 Dec 2007 0:56:22 26.311 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3280.dat" 18 Dec 2007 0:56:22 27.912 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3281.dat" 18 Dec 2007 0:56:22 4.146 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3282.dat" 18 Dec 2007 0:56:22 4.058 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3283.dat" 18 Dec 2007 0:56:22 3.880 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3284.dat" 18 Dec 2007 0:56:22 4.092 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3285.dat" 18 Dec 2007 0:56:22 3.281 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3286.dat" 18 Dec 2007 0:56:22 3.322 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3287.dat" 18 Dec 2007 0:56:22 77 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3288.dat" 18 Dec 2007 0:56:22 4.252 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3289.dat" 18 Dec 2007 0:56:22 4.308 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3290.dat" 18 Dec 2007 0:56:22 5.830 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3291.dat" 18 Dec 2007 0:56:22 4.734 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3292.dat" 18 Dec 2007 0:56:22 5.067 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3293.dat" 18 Dec 2007 0:56:22 4.195 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3294.dat" 18 Dec 2007 0:56:22 4.722 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3295.dat" 18 Dec 2007 0:56:22 4.078 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3296.dat" 18 Dec 2007 0:56:22 7.978 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3297.dat" 18 Dec 2007 0:56:22 7.216 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3298.dat" 18 Dec 2007 0:56:22 7.250 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3299.dat" 18 Dec 2007 0:56:22 6.750 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3300.dat" 18 Dec 2007 0:56:22 87 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3301.dat" 18 Dec 2007 0:56:22 3.749 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3302.dat" 18 Dec 2007 0:56:22 6.787 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3303.dat" 18 Dec 2007 0:56:22 6.267 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3304.dat" 18 Dec 2007 0:56:22 48.698 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3305.dat" 18 Dec 2007 0:56:22 43.441 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3306.dat" 18 Dec 2007 0:56:22 157 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3307.dat" 18 Dec 2007 0:56:22 36.397 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3308.dat" 18 Dec 2007 0:56:22 78 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3309.dat" 18 Dec 2007 0:56:22 38.639 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3310.dat" 18 Dec 2007 0:56:22 39.403 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3311.dat" 18 Dec 2007 0:56:24 42.473 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3312.dat" 18 Dec 2007 0:56:24 46.849 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3313.dat" 18 Dec 2007 0:56:24 5.659 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3314.dat" 18 Dec 2007 0:56:24 2.343 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3315.dat" 18 Dec 2007 0:56:24 4.890 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3316.dat" 18 Dec 2007 0:56:24 5.367 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3317.dat" 18 Dec 2007 0:56:24 222 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3318.dat" 18 Dec 2007 0:56:24 4.639 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3319.dat" 18 Dec 2007 0:56:24 4.295 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3320.dat" 18 Dec 2007 0:56:24 4.779 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3321.dat" 18 Dec 2007 0:56:24 4.916 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3322.dat" 18 Dec 2007 12:59:14 5.158 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3323.dat" 19 Dec 2007 13:05:22 4.569 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3324.dat" 20 Dec 2007 13:46:56 5.161 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3325.dat" 21 Dec 2007 13:52:56 4.159 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3326.dat" 22 Dec 2007 13:59:00 4.511 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3327.dat" 23 Dec 2007 14:04:56 4.260 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3328.dat" 24 Dec 2007 12:10:30 3.372 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3329.dat" 25 Dec 2007 12:16:22 3.069 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3330.dat" 26 Dec 2007 12:22:28 2.797 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3331.dat" 27 Dec 2007 14:28:34 3.043 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3332.dat" 28 Dec 2007 14:34:28 3.044 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3333.dat" 29 Dec 2007 12:39:30 2.959 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3334.dat" 30 Dec 2007 14:45:30 2.869 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3335.dat" 31 Dec 2007 14:51:34 39.337 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3336.dat" 1 Jan 2008 16:56:52 39.620 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3337.dat" 2 Jan 2008 13:01:54 42.354 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3338.dat" 2 Jan 2008 17:02:52 83 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3339.dat" 6 Jan 2008 21:07:50 36.314 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3340.dat" 6 Jan 2008 21:07:50 32.546 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3341.dat" 6 Jan 2008 21:07:50 40.864 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3342.dat" 6 Jan 2008 21:07:50 39.969 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3343.dat" 7 Jan 2008 14:02:02 7.807 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3344.dat" 8 Jan 2008 19:00:36 8.086 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3345.dat" 9 Jan 2008 15:24:56 7.611 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3346.dat" 10 Jan 2008 14:34:40 8.923 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3347.dat" 11 Jan 2008 12:55:06 4.614 A.... "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\Signatures\3348.dat" 11 Dec 2007 11:18:34 95.744 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\atl80.dll" 11 Dec 2007 11:18:34 56.872 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\cert.dll" 11 Dec 2007 11:18:34 58.408 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\conflictingappmodule.dll" 11 Dec 2007 11:18:34 548.864 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\msvcp80.dll" 11 Dec 2007 11:18:34 626.688 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\msvcr80.dll" 11 Dec 2007 11:18:34 69.160 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\ochelpagent.dll" 11 Dec 2007 11:18:32 339.496 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\ocsetup.exe" 11 Dec 2007 11:18:34 122.920 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\ocsetupro.dll" 11 Dec 2007 11:18:34 210.472 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\winsscommon.dll" 11 Dec 2007 11:18:34 551.464 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\winssplatform.dll" 11 Dec 2007 23:33:58 479.232 A.... "C:\Programme\Mozilla Firefox\plugins\Microsoft.VC80.CRT\msvcm80.dll" 11 Dec 2007 23:33:58 548.864 A.... "C:\Programme\Mozilla Firefox\plugins\Microsoft.VC80.CRT\msvcp80.dll" 11 Dec 2007 23:33:58 626.688 A.... "C:\Programme\Mozilla Firefox\plugins\Microsoft.VC80.CRT\msvcr80.dll" 11 Jan 2008 17:57:46 4.864 A.... "C:\Programme\Sunbelt Software\Personal Firewall\Config\charts.dat" 7 Jan 2008 17:44:38 244 A.... "C:\Programme\TGTSoft\StyleXP\Boot\BootPreview.html" 7 Jan 2008 17:43:46 2.499.584 A.... "C:\Programme\TGTSoft\StyleXP\Logon\CurrentLogon.EXE" 7 Jan 2008 17:43:52 3.942 A.... "C:\Programme\TGTSoft\StyleXP\Logon\LogonPreview.html" 28 Nov 2007 11:51:26 164.880 A.... "C:\Programme\Windows Live\Writer\de\WindowsLive.Writer.Localization.resources.dll" 11 Jan 2008 15:13:24 728 A.... "C:\Programme\Winamp\Plugins\ml\main.dat" 11 Jan 2008 15:13:28 224.478 A.... "C:\Programme\Winamp\Plugins\ml\recent.dat" 11 Dec 2007 11:18:32 132.648 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\de-at\ocsetupro.dll" 11 Dec 2007 11:18:32 132.648 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\de-ch\ocsetupro.dll" 11 Dec 2007 11:18:32 132.648 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\de-de\ocsetupro.dll" 11 Dec 2007 11:18:32 122.920 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\en-au\ocsetupro.dll" 11 Dec 2007 11:18:32 122.920 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\en-ca\ocsetupro.dll" 11 Dec 2007 11:18:32 122.920 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\en-gb\ocsetupro.dll" 11 Dec 2007 11:18:32 122.920 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\en-ie\ocsetupro.dll" 11 Dec 2007 11:18:32 122.920 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\en-nz\ocsetupro.dll" 11 Dec 2007 11:18:32 122.920 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\en-sg\ocsetupro.dll" 11 Dec 2007 11:18:32 127.016 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\es-es\ocsetupro.dll" 11 Dec 2007 11:18:32 127.016 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\es-mx\ocsetupro.dll" 11 Dec 2007 11:18:32 127.016 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\es-us\ocsetupro.dll" 11 Dec 2007 11:18:32 121.896 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\fr-be\ocsetupro.dll" 11 Dec 2007 11:18:32 121.896 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\fr-ca\ocsetupro.dll" 11 Dec 2007 11:18:32 121.896 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\fr-ch\ocsetupro.dll" 11 Dec 2007 11:18:32 121.896 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\fr-fr\ocsetupro.dll" 11 Dec 2007 11:18:32 120.360 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\it-it\ocsetupro.dll" 11 Dec 2007 11:18:32 103.976 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\ja-jp\ocsetupro.dll" 11 Dec 2007 11:18:32 105.000 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\ja-jp-psloc\ocsetupro.dll" 11 Dec 2007 11:18:32 114.728 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\ko-kr\ocsetupro.dll" 11 Dec 2007 11:18:32 129.576 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\nl-be\ocsetupro.dll" 11 Dec 2007 11:18:32 129.576 ..... "C:\Programme\Microsoft Windows OneCare Live\Staging\SEA1\nl-nl\ocsetupro.dll" 2 Dec 2007 11:36:14 99.840 A.... "C:\Programme\Mozilla Firefox\extensions\talkback@mozilla.org\components\BrandRes.dll" 2 Dec 2007 11:36:14 156.544 A.... "C:\Programme\Mozilla Firefox\extensions\talkback@mozilla.org\components\fullsoft.dll" 2 Dec 2007 11:36:14 14.456 A.... "C:\Programme\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll" 2 Dec 2007 11:36:16 407.040 A.... "C:\Programme\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback.exe" Files with hidden attributes: Wed 25 Feb 2004 54,384 A..H. --- "C:\Programme\AOL 9.0\aolphx.exe" Wed 25 Feb 2004 156,784 A..H. --- "C:\Programme\AOL 9.0\aoltray.exe" Wed 25 Feb 2004 31,344 A..H. --- "C:\Programme\AOL 9.0\RBM.exe" Mon 19 Jan 2004 428,544 A..H. --- "C:\Programme\AOL 9.0\StartSM.exe" Sun 28 Oct 2007 5,903,928 A..H. --- "C:\Programme\Picasa2\setup.exe" Fri 19 Nov 2004 26,112 A..H. --- "C:\WINDOWS\AcerDRV\InsD1211.exe" Tue 15 Nov 2005 26,112 A..H. --- "C:\WINDOWS\AcerDRV\InsD1215.exe" Mon 30 Aug 2004 44,032 A..H. --- "C:\WINDOWS\AcerDRV\rescan.exe" Fri 19 Nov 2004 26,112 A..H. --- "C:\WINDOWS\system32\InsD1211.exe" Tue 15 Nov 2005 26,112 A..H. --- "C:\WINDOWS\system32\InsD1215.exe" Wed 6 Aug 2003 24,576 A..H. --- "C:\WINDOWS\system32\KCMDNIns.exe" Wed 16 Nov 2005 24,576 A..HR --- "C:\WINDOWS\system32\Kill1211.exe" Tue 8 Aug 2006 1,024 ...HR --- "C:\WINDOWS\system32\NTIBUN4.dll" Tue 8 Aug 2006 1,024 ...HR --- "C:\ |
|
|
||
11.01.2008, 21:26
Ehrenmitglied
Beiträge: 1441 |
#5
tothebairo
« wende combofix an + poste das Log hier http://www.virus-protect.org/artikel/tools/combofix.html __________ Gruss Pinguin bin dabei, meine Seite + Proggies zu aktualisieren: http://www.virus-protect.org/ |
|
|
||
Ich hab ein acer aspire t660 und hab keine recovery cd erstellt also ist somit die formatierung auch ausgeschlossen..
was soll ich jetzt machen?! kann mir jemand helfen bitte
hier ist ein logfile von hijackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:28:52, on 09.01.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Acer\Acer eConsole\MediaServerService.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Programme\QuickTime\qttask.exe
C:\Programme\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Programme\Acer\Acer eMode Management\AspireService.exe
C:\Programme\Acer\Acer eConsole\MediaSync.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
c:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
C:\Programme\Logitech\Video\LogiTray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programme\Winamp\winampa.exe
C:\Programme\Gemeinsame Dateien\Ulead Systems\AutoDetector\monitor.exe
C:\Programme\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Logitech\Video\FxSvr2.exe
C:\Programme\Microsoft ActiveSync\wcescomm.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Acer WLAN 11g USB Dongle\ZDWlan.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
C:\Programme\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Dokumente und Einstellungen\Baris\Desktop\SetupOneCare.exe
d:\a2563bf773d2c6e7ae7f12\ocsetup.exe
C:\WINDOWS\explorer.exe
C:\Programme\Windows Live\Messenger\usnsvc.exe
C:\Programme\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Dokumente und Einstellungen\Baris\Desktop\HiJackThis202.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.markamp3.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.de/0SEDEDE/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Programme\BearShare applications\BearShare MediaBar\MediaBar.dll (file missing)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {1268EAE4-E423-4980-9995-E89410FA909C} - C:\WINDOWS\system32\pxsfs32.dll (file missing)
O2 - BHO: BDEX System - {5085333B-FD15-4754-A571-852F7077C5F2} - C:\WINDOWS\dxpvqlmqng.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programme\Windows Live Toolbar\msntb.dll (file missing)
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Programme\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: XBTP02634 - {F97DA966-F09D-4cab-BF29-75A0026986EA} - C:\PROGRA~1\BEARSH~3\BEARSH~2\MediaBar.dll (file missing)
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Programme\BearShare applications\BearShare MediaBar\MediaBar.dll (file missing)
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Programme\MegauploadToolbar\megauploadtoolbar.dll (file missing)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ntiMUI] c:\Programme\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 1
O4 - HKLM\..\Run: [AspireService] C:\Programme\Acer\Acer eMode Management\AspireService.exe
O4 - HKLM\..\Run: [MediaSync] C:\Programme\Acer\Acer eConsole\MediaSync.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programme\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programme\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [nvchost] C:\WINDOWS\winlogon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Programme\Gemeinsame Dateien\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Programme\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [castarmy] C:\DOKUME~1\Baris\ANWEND~1\INTERN~1\DRAWDOWNLOAD.exe
O4 - HKCU\..\Run: [updateMgr] c:\Programme\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [STYLEXP] C:\Programme\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programme\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ImageItEncrypt] C:\WINDOWS\system32\ImageItEncrypt.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Programme\Acer WLAN 11g USB Dongle\ZDWlan.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 9.0 Tray-Symbol.lnk = C:\Programme\AOL 9.0\aoltray.exe
O4 - Global Startup: Windows-Desktopsuche.lnk = C:\Programme\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Programme\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.schuelervz.net/photouploader/ImageUploader4.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://bmm.imgag.com/imgag/cp/install/crusher-de.cab
O16 - DPF: {E55FD215-A32E-43FE-A777-A7E8F165F551} (Flatcast Viewer 4.15) - http://www.flatcast.com/de/download/NpFv415.dll
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.dat
O21 - SSODL: ampkfst - {DEA32835-14E2-4D59-941B-7E0ED5E8A239} - C:\WINDOWS\ampkfst.dll
O21 - SSODL: bklgvsf - {7172D386-A3E1-4219-BA9E-C2135E1AA011} - C:\WINDOWS\bklgvsf.dll (file missing)
O23 - Service: Acer Media Server - Acer Inc. - C:\Programme\Acer\Acer eConsole\MediaServerService.exe
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatisches LiveUpdate - Scheduler - Unknown owner - C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Programme\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: StyleXPService - Unknown owner - C:\Programme\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Programme\Windows Live\installer\WLSetupSvc.exe
--
End of file - 13185 bytes
danke schon mal im voraus..