Langsame Browser unter Vista ...

#0
18.07.2008, 17:38
...neu hier

Beiträge: 4
#1 => mein problem:

hallo, meine browser (unter vista) sind immer nach ca. 0,5h in benutzung sehr langsam (andere programme aber noch aufs web zugreifen konnten). wär echt super, wenn jemand mal drüberschauen könnte - danke!!


=> malwarebytes: keine fehler gefunden

=> combofix:

ComboFix 08-07-17.4 - Toby 2008-07-18 16:53:35.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1031.18.1201 [GMT 2:00]
ausgeführt von:: C:\Users\Toby\Desktop\ComboFix.exe
* Neuer Wiederherstellungspunkt wurde erstellt
.

((((((((((((((((((((((( Dateien erstellt von 2008-06-18 bis 2008-07-18 ))))))))))))))))))))))))))))))
.

2008-07-18 15:16 . 2008-07-18 15:16 <DIR> d-------- C:\Users\Toby\AppData\Roaming\Malwarebytes
2008-07-18 15:16 . 2008-07-18 15:16 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-07-18 15:16 . 2008-07-18 15:16 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-07-18 15:16 . 2008-07-18 15:16 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-18 15:16 . 2008-07-07 17:35 34,296 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
2008-07-18 15:16 . 2008-07-07 17:35 17,144 --a------ C:\Windows\System32\drivers\mbam.sys
2008-07-17 20:43 . 2008-07-17 20:43 26 --a------ C:\23990098.$$$
2008-07-17 17:47 . 2008-07-17 17:47 26 --a------ C:\Windows\Lic.xxx
2008-07-14 13:08 . 2008-07-14 13:08 <DIR> d-------- C:\fsaua.data
2008-07-14 12:38 . 2008-07-14 12:39 <DIR> d-------- C:\Program Files\MP3Gain
2008-07-12 17:22 . 2008-07-12 17:22 <DIR> d-------- C:\Program Files\VS Revo Group
2008-07-12 17:17 . 2008-07-12 17:17 <DIR> d-------- C:\Program Files\help
2008-07-12 16:51 . 2008-07-12 16:51 <DIR> d-------- C:\Program Files\Avira
2008-07-12 15:02 . 2008-07-12 15:02 <DIR> dr------- C:\Windows\System32\config\systemprofile\Music
2008-07-12 15:02 . 2008-04-23 06:42 428,544 --a------ C:\Windows\System32\EncDec.dll
2008-07-12 15:02 . 2008-04-23 06:42 293,376 --a------ C:\Windows\System32\psisdecd.dll
2008-07-12 15:02 . 2008-04-23 06:41 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-07-12 15:02 . 2008-04-23 06:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-07-11 21:46 . 2008-04-26 10:25 3,600,952 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-07-11 21:46 . 2008-04-26 10:25 3,549,240 --a------ C:\Windows\System32\ntoskrnl.exe
2008-07-11 21:46 . 2008-04-26 10:26 891,448 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-07-11 21:46 . 2008-04-12 05:32 784,896 --a------ C:\Windows\System32\rpcrt4.dll
2008-07-11 21:46 . 2008-05-10 05:35 564,736 --a------ C:\Windows\System32\emdmgmt.dll
2008-07-11 21:46 . 2008-04-05 03:21 72,192 --a------ C:\Windows\System32\drivers\pacer.sys
2008-07-11 21:46 . 2008-04-05 05:34 15,360 --a------ C:\Windows\System32\pacerprf.dll
2008-07-11 21:42 . 2008-06-26 03:45 12,240,896 --a------ C:\Windows\System32\NlsLexicons0007.dll
2008-07-11 21:42 . 2008-06-26 03:45 2,644,480 --a------ C:\Windows\System32\NlsLexicons0009.dll
2008-07-11 21:41 . 2008-06-26 05:29 801,280 --a------ C:\Windows\System32\NaturalLanguage6.dll
2008-07-11 21:37 . 2008-05-08 23:59 430,080 --a------ C:\Windows\System32\vbscript.dll
2008-07-11 21:37 . 2008-05-08 23:59 180,224 --a------ C:\Windows\System32\scrobj.dll
2008-07-11 21:37 . 2008-05-08 23:59 172,032 --a------ C:\Windows\System32\scrrun.dll
2008-07-11 21:37 . 2008-05-08 23:59 155,648 --a------ C:\Windows\System32\wscript.exe
2008-07-11 21:37 . 2008-05-08 23:58 135,168 --a------ C:\Windows\System32\wshom.ocx
2008-07-11 21:37 . 2008-05-08 23:58 135,168 --a------ C:\Windows\System32\cscript.exe
2008-07-11 21:37 . 2008-05-08 23:59 90,112 --a------ C:\Windows\System32\wshext.dll
2008-07-11 14:03 . 2008-07-11 14:05 <DIR> d-------- C:\Users\Toby\Pavark
2008-07-08 13:45 . 2008-07-10 22:17 <DIR> d-------- C:\Program Files\TrayBackup
2008-07-05 18:23 . 2008-07-10 22:16 <DIR> d-------- C:\Program Files\Multimedia Bibel
2008-06-29 15:24 . 2008-06-29 15:24 <DIR> d-------- C:\Users\All Users\WindowsSearch
2008-06-29 15:24 . 2008-06-29 15:24 <DIR> d-------- C:\ProgramData\WindowsSearch
2008-06-28 23:00 . 2008-07-02 17:02 <DIR> d-------- C:\Program Files\Java(17)
2008-06-28 23:00 . 2008-06-28 23:00 <DIR> d-------- C:\Program Files\Common Files\Java(15)
2008-06-22 20:18 . 2008-06-22 20:18 <DIR> d-------- C:\Users\Toby\AppData\Roaming\vlc
2008-06-22 19:35 . 2008-07-11 21:38 <DIR> d-------- C:\Program Files\Runtime Software
2008-06-22 19:12 . 2008-06-22 19:15 <DIR> d-a------ C:\Users\All Users\TEMP
2008-06-22 19:12 . 2008-06-22 19:15 <DIR> d-a------ C:\ProgramData\TEMP
2008-06-20 21:18 . 2008-06-29 00:37 <DIR> d-------- C:\Program Files\Blue Coat K9 Web Protection

.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-18 14:41 352,615 ---ha-w C:\Windows\system32\drivers\vsconfig.xml
2008-07-17 13:46 --------- d-----w C:\Users\Toby\AppData\Roaming\OpenOffice.org2
2008-07-12 15:47 --------- d-----w C:\Users\Toby\AppData\Roaming\phonostar-Player
2008-07-12 15:39 --------- d-----w C:\Program Files\Sauber
2008-07-12 15:36 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-07-12 15:17 2,629 ----a-w C:\Program Files\traybackup.ini
2008-07-12 14:51 --------- d-----w C:\ProgramData\Avira
2008-07-11 19:53 --------- d-----w C:\Program Files\Windows Mail
2008-07-11 19:22 --------- d-----w C:\Users\Toby\AppData\Roaming\Winamp
2008-07-11 19:22 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-07-11 19:22 --------- d-----w C:\Program Files\Zone Labs
2008-07-11 19:22 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-07-11 19:22 --------- d-----w C:\Program Files\Java
2008-07-11 19:22 --------- d-----w C:\Program Files\IrfanView
2008-07-11 19:22 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-11 19:22 --------- d-----w C:\Program Files\Common Files\Java
2008-07-11 19:22 --------- d-----w C:\Program Files\Audiograbber
2008-07-11 15:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-10 07:01 --------- d-----w C:\Program Files\Common Files\LightScribe
2008-07-10 06:26 --------- d-----w C:\Users\Toby\AppData\Roaming\CyberLink
2008-06-20 23:28 --------- d-----w C:\Program Files\Zattoo
2008-06-13 06:52 --------- d-----w C:\Program Files\Google
2008-06-08 18:00 355,584 ----a-w C:\Windows\System32\TuneUpDefragService.exe
2008-05-10 18:44 73,216 ----a-w C:\Windows\cadkasdeinst01.exe
2008-04-26 08:08 1,314,816 ----a-w C:\Windows\System32\quartz.dll
2008-04-25 16:27 942,080 ---ha-w C:\Windows\System32\svchospt.exe
2008-04-25 04:35 826,880 ----a-w C:\Windows\System32\wininet.dll
2008-04-21 18:35 174 --sha-w C:\Program Files\desktop.ini
2008-04-21 18:10 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-04-21 18:10 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-04-21 17:36 47,560 ----a-w C:\Windows\System32\SPReview.exe
2008-04-21 17:36 152,576 ----a-w C:\Windows\System32\SPWizUI.dll
2008-03-14 22:51 217 ----a-w C:\Program Files\setup.ini
2006-02-07 01:42 5,518 ----a-w C:\Program Files\lizenz.txt
2006-02-07 01:42 316,416 ----a-w C:\Program Files\traybackup.exe
2006-02-07 01:42 152 ----a-w C:\Program Files\traybackup.md5
2006-02-07 01:42 10,504 ----a-w C:\Program Files\history.txt
2005-03-03 01:30 8,829 ----a-w C:\Program Files\readme.txt
2003-08-17 01:13 1,896 ----a-w C:\Program Files\register.txt
2002-07-02 01:10 5,587 ----a-w C:\Program Files\update.txt
2002-07-02 01:10 2,485 ----a-w C:\Program Files\winsave.bpr
2002-03-11 09:06 1,822,520 ----a-w C:\Program Files\instmsiw.exe
2002-03-11 08:45 1,708,856 ----a-w C:\Program Files\instmsia.exe
2001-11-27 15:30 384,512 ----a-w C:\Users\Toby\Sound7-Eurorechner.exe
.

(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-06-12 13:26 171448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-23 08:40 857648]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-18 08:33 266497]
"RtHDVCpl"="RtHDVCpl.exe" [2007-06-13 06:11 4489216 C:\Windows\RtHDVCpl.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"NoHotStart"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
--a------ 2008-01-18 23:33 125952 C:\Windows\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 2007-01-08 22:17 52256 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhonostarTimer]
--a------ 2007-12-05 16:14 126976 C:\Program Files\phonostar\ps_timer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2007-01-08 22:26 68640 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-18 23:38 1008184 C:\Program Files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1582639531-4105982936-1949279621-1001]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1FB8C62B-3FA5-484C-8D6E-A2CB7AA97DD3}"= Profile=Private|C:\Program Files\CyberLink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{904243F3-B473-4FA9-9955-0A62D2241DF5}"= Profile=Private|C:\Program Files\CyberLink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{D612F391-34FA-45AA-B7FB-7D65D188B6B0}"= Disabled:C:\Program Files\CyberLink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{A03EF0E7-DC8C-4922-92ED-7F08803055F3}"= Disabled:C:\Program Files\CyberLink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"TCP Query User{B01D2B75-7126-4159-AF60-AC693A20E1C8}C:\\program files\\icq6\\icq.exe"= Disabled:UDP:C:\program files\icq6\icq.exe:ICQ Library
"UDP Query User{C99A78F1-296A-47DE-817F-78D07974749D}C:\\program files\\icq6\\icq.exe"= Disabled:TCP:C:\program files\icq6\icq.exe:ICQ Library
"{EA36E931-35D8-43C1-960A-1FA74D81B167}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{D43F01D7-5291-4AA3-A3A1-892756B33BDA}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{B2DF83D6-3EF6-44EE-805D-27EEFE7B9BC8}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{3213862B-2B31-4647-B078-F40A45CCF999}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{2713AE1E-EE08-4EAF-A4CA-D37BFB1F2663}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{EE0B3049-DDC3-4FC1-AE91-30E6D3496144}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{3EB2E7AA-D896-47F8-BE77-7BE8D5B43512}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{5E1B36A4-726F-4CFE-B843-2D310526A125}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2007-04-26 03:15]
R1 cwmtdi;cwmtdi;C:\Windows\system32\drivers\cwmtdi.sys [2007-05-15 01:04]
R2 KMDFMEMIO;SAMSUNG Kernel Driver;C:\Windows\system32\DRIVERS\kmdfmemio.sys [2006-11-14 09:11]
R2 UxTuneUp;TuneUp Designerweiterung;C:\Windows\System32\svchost.exe [2008-01-18 23:33]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-06-13 16:21]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-06 09:51]
S3 TuneUp.Defrag;TuneUp Drive Defrag-Dienst;C:\Windows\System32\TuneUpDefragService.exe [2008-06-08 20:00]
S4 AAV UpdateService;AAV UpdateService;C:\Program Files\Common Files\AAV\aavus.exe [2007-10-04 15:32]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Inhalt des "geplante Tasks" Ordners
"2008-07-18 12:55:06 C:\Windows\Tasks\User_Feed_Synchronization-{711CE9C2-4023-452A-BC10-87E4023FB939}.job"
- C:\Windows\system32\msfeedssync.exe
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Orb - C:\Program Files\Winamp Remote\bin\OrbTray.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-18 16:56:08
Windows 6.0.6001 Service Pack 1 NTFS

Scanne versteckte Prozesse...

Scanne versteckte Autostart Einträge...

Scanne versteckte Dateien...

Scan erfolgreich abgeschlossen
versteckte Dateien: 0

**************************************************************************
.
Zeit der Fertigstellung: 2008-07-18 16:57:19
ComboFix-quarantined-files.txt 2008-07-18 14:57:09

Pre-Run: 89,869,520,896 Bytes frei
Post-Run: 89,935,097,856 Bytes frei

191 --- E O F --- 2008-07-12 13:03:49


=> hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 17:17:49, on 18.07.2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Windows\system32\taskeng.exe
C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Sauber\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: Blue Coat K9 Web Protection (WebFilter) - Unknown owner - C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)


=> hijackthis uninstall-list:

Adobe Flash Player 9 ActiveX
Adobe Flash Player Plugin
Adobe Reader 8.1.2 - Deutsch
Agere Systems HDA Modem
Atheros WLAN Client
Audiograbber 1.83 SE
Avira AntiVir Personal - Free Antivirus
AVStation Now
Blue Coat® K9 Web Protection
Canon Inkjet Printer Driver Add-On Module
Canon MP360
Canon MP-Toolbox 4.1.1.0.mp10
CCleaner (remove only)
DVD Suite
Easy Battery Manager
Easy Display Manager
Easy Network Manager 3.0
Easy SpeedUp Manager
FLV Player 2.0, build 24
Google Toolbar for Internet Explorer
HijackThis 1.99.1
ICQ6
imagine digital freedom - Samsung
IrfanView (remove only)
Java(TM) 6 Update 5
LabelPrint 2.0
MediaShow
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proof (Italian) 2007
Microsoft Office Proofing (German) 2007
Microsoft Office Publisher 2007
Microsoft Office Publisher 2007 Trial
Microsoft Office Publisher MUI (German) 2007
Microsoft Office Shared MUI (German) 2007
Microsoft SOAP Toolkit 2.0 SP2
Microsoft Visual C++ 2005 Redistributable
OpenOffice.org 2.4
Passwort.Tresor
phonostar-Player Version 2.01.2
PhotoNow! 1.0
Play AVStation
Power2Go 5.0
PowerDirector
PowerDVD
PowerProducer
RealPlayer
Realtek High Definition Audio Driver
Revo Uninstaller 1.71
Samsung Magic Doctor
Samsung Recovery Solution II
Samsung Update Plus
SopCast 3.0.1
Spelling Dictionaries Support For Adobe Reader 8
Spybot - Search & Destroy
Steuer-Spar-Erklärung 2008
Synaptics Pointing Device Driver
User Guide
VideoLAN VLC media player 0.8.6h
Winamp
WinRAR
Zattoo 3.2.1 Beta
ZoneAlarm

=> datfind.bat:

.
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: AA75-E4D0

Verzeichnis von C:\Windows\system32

18.07.2008 16:47 3.664 7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
18.07.2008 16:47 3.664 7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
18.07.2008 08:46 587.178 perfh009.dat
18.07.2008 08:46 618.430 perfh007.dat
18.07.2008 08:46 101.250 perfc009.dat
18.07.2008 08:46 122.648 perfc007.dat
18.07.2008 08:46 1.418.600 PerfStringBackup.INI
02.07.2008 17:02 6.082 jupdate-1.6.0_04-b12.log
28.06.2008 23:01 6.634 jupdate-1.6.0_06-b02.log
26.06.2008 05:29 801.280 NaturalLanguage6.dll
26.06.2008 03:45 2.644.480 NlsLexicons0009.dll
26.06.2008 03:45 12.240.896 NlsLexicons0007.dll
25.06.2008 18:15 17.972.344 mrt.exe
08.06.2008 20:00 355.584 TuneUpDefragService.exe
15.05.2008 07:55 394.200 FNTCACHE.DAT
10.05.2008 05:35 564.736 emdmgmt.dll
08.05.2008 23:59 90.112 wshext.dll
08.05.2008 23:59 430.080 vbscript.dll
08.05.2008 23:59 172.032 scrrun.dll
08.05.2008 23:59 180.224 scrobj.dll
08.05.2008 23:59 512.000 jscript.dll
08.05.2008 23:59 155.648 wscript.exe
08.05.2008 23:58 135.168 cscript.exe
08.05.2008 23:58 135.168 wshom.ocx
26.04.2008 10:25 3.549.240 ntoskrnl.exe
26.04.2008 10:25 3.600.952 ntkrnlpa.exe
26.04.2008 10:08 1.314.816 quartz.dll
25.04.2008 18:27 942.080 svchospt.exe
25.04.2008 06:35 826.880 wininet.dll
25.04.2008 06:35 1.166.336 urlmon.dll
25.04.2008 06:35 671.232 mstime.dll
25.04.2008 06:35 3.578.368 mshtml.dll
25.04.2008 06:35 28.160 jsproxy.dll
25.04.2008 04:12 1.383.424 mshtml.tlb
24.04.2008 06:58 11.580.416 shell32.dll
23.04.2008 06:42 293.376 psisdecd.dll
23.04.2008 06:42 428.544 EncDec.dll
23.04.2008 06:41 57.856 MSDvbNP.ax
23.04.2008 06:41 218.624 psisrndr.ax
21.04.2008 20:10 101.888 ifxcardm.dll
21.04.2008 20:10 82.432 axaltocm.dll
21.04.2008 19:36 152.576 SPWizUI.dll
21.04.2008 19:36 47.560 SPReview.exe
19.04.2008 19:37 185.944 rmoc3260.dll
19.04.2008 19:36 5.632 pndx5032.dll
19.04.2008 19:36 6.656 pndx5016.dll
19.04.2008 19:36 278.528 pncrt.dll
13.04.2008 16:35 6.591 jupdate-1.6.0_05-b13.log
12.04.2008 05:32 784.896 rpcrt4.dll
08.04.2008 21:44 6.656 kbd106n.dll
08.04.2008 21:44 927.288 winresume.exe
08.04.2008 21:44 988.216 winload.exe
08.04.2008 21:44 40.960 srclient.dll
08.04.2008 21:44 318.464 rstrui.exe
08.04.2008 21:44 378.368 srcore.dll
08.04.2008 21:44 14.848 srdelayed.exe
08.04.2008 21:44 19.000 kd1394.dll
08.04.2008 21:44 46.592 setbcdlocale.dll
08.04.2008 21:44 615.992 ci.dll
08.04.2008 21:42 2.032.128 win32k.sys
08.04.2008 21:41 295.936 gdi32.dll
08.04.2008 18:05 5.571 vsconfig.xml
07.04.2008 21:34 1.820 rasctrnm.h
07.04.2008 21:09 2.455.488 ieapfltr.dat
07.04.2008 20:10 23.220 emptyregdb.dat
05.04.2008 05:34 15.360 pacerprf.dll
04.04.2008 14:51 28.416 uxtuneup.dll
04.04.2008 14:51 16.640 authuitu.dll
.
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: AA75-E4D0

Verzeichnis von C:\Users\Toby\AppData\Local\Temp

18.07.2008 17:22 124.712 datfind.txt
18.07.2008 17:12 311.296 ~DF4059.tmp
18.07.2008 15:14 688.760 _iu14D2N.tmp
4 Datei(en), 1.378.984 Bytes
0 Verzeichnis(se), 89.790.595.072 Bytes frei
.
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: AA75-E4D0

Verzeichnis von C:\Windows

18.07.2008 16:56 215 system.ini
18.07.2008 16:47 516.837 WindowsUpdate.log
18.07.2008 16:41 67.584 bootstat.dat
17.07.2008 17:47 26 Lic.xxx
14.07.2008 11:15 34 cdplayer.ini
05.07.2008 18:25 327.680 SPInstall.etl
10.05.2008 20:44 73.216 cadkasdeinst01.exe
21.04.2008 20:35 749 WindowsShell.Manifest
.
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: AA75-E4D0

Verzeichnis von C:\Windows\temp

18.07.2008 16:41 256 ZLT02ff8.TMP
18.07.2008 16:41 256 ZLT0570a.TMP
2 Datei(en), 512 Bytes
0 Verzeichnis(se), 89.790.590.976 Bytes frei
Seitenanfang Seitenende
18.07.2008, 17:50
Moderator

Beiträge: 7805
#2 Pruefe bitte C:\Windows\System32\svchospt.exe bei Virustotal, poste das komplette Ergebniss und erstelle mit Hijackthis 2.02 einen neuen Report.

Hat der Scan mit Mbam etwas ergeben?
__________
MfG Ralf
SEO-Spam Hunter
Seitenanfang Seitenende
18.07.2008, 18:17
...neu hier

Themenstarter

Beiträge: 4
#3 => virustotal von "svchospt.exe"

Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.7.17.0 2008.07.18 -
AntiVir 7.8.1.11 2008.07.18 -
Authentium 5.1.0.4 2008.07.18 -
Avast 4.8.1195.0 2008.07.18 Win32:Trojan-gen {Other}
AVG 8.0.0.130 2008.07.18 Generic10.ABWC
BitDefender 7.2 2008.07.18 -
CAT-QuickHeal 9.50 2008.07.17 -
ClamAV 0.93.1 2008.07.18 -
DrWeb 4.44.0.09170 2008.07.18 -
eSafe 7.0.17.0 2008.07.17 -
eTrust-Vet 31.6.5965 2008.07.18 -
Ewido 4.0 2008.07.18 -
F-Prot 4.4.4.56 2008.07.18 -
F-Secure 7.60.13501.0 2008.07.18 -
Fortinet 3.14.0.0 2008.07.18 -
GData 2.0.7306.1023 2008.07.18 Win32:Trojan-gen
Ikarus T3.1.1.34.0 2008.07.18 -
Kaspersky 7.0.0.125 2008.07.18 -
McAfee 5341 2008.07.18 -
Microsoft 1.3704 2008.07.18 -
NOD32v2 3280 2008.07.18 probably unknown NewHeur_PE virus
Norman 5.80.02 2008.07.18 -
Panda 9.0.0.4 2008.07.18 -
Prevx1 V2 2008.07.18 -
Rising 20.53.42.00 2008.07.18 -
Sophos 4.31.0 2008.07.18 -
Sunbelt 3.1.1536.1 2008.07.17 -
Symantec 10 2008.07.18 -
TheHacker 6.2.96.381 2008.07.16 -
TrendMicro 8.700.0.1004 2008.07.18 -
VBA32 3.12.8.0 2008.07.17 -
VirusBuster 4.5.11.0 2008.07.18 -
Webwasher-Gateway 6.6.2 2008.07.18 -
weitere Informationen
File size: 942080 bytes
MD5...: 586a1e862e3f15f44e56ec311deee9f5
SHA1..: b43b416ea407098c3403b8f2852dfca497556757
SHA256: 4535c0fcf8afc4471d1f756b99be0ba7564f06f991187b59e6ddc599ebfa2888
SHA512: 9c26b9b8740cdb1aecbc6636b0314cf5dd8e7e23b50244f2b77fa40f9b6fb67e
1d388d810bf1a6d93b2b05405cb321c7eb1f4e303a6453c36c443e06121582e3
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x404f78
timedatestamp.....: 0x4812068e (Fri Apr 25 16:27:58 2008)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xe190c 0xe2000 5.71 0e809f1d9c822f2ce07394cdc1f4326e
.data 0xe3000 0x63c0 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110
.rsrc 0xea000 0x1cfe 0x2000 2.80 60e7b4d53177154c5cdb2ba520cea297

( 1 imports )
> MSVBVM60.DLL: EVENT_SINK_GetIDsOfNames, __vbaVarSub, __vbaVarTstGt, -, __vbaStrI2, _CIcos, _adj_fptan, __vbaStrI4, __vbaVarMove, __vbaVarVargNofree, -, __vbaAryMove, __vbaFreeVar, -, __vbaLateIdCall, __vbaStrVarMove, __vbaLenBstr, __vbaLineInputStr, -, __vbaPut3, __vbaFreeVarList, __vbaEnd, _adj_fdiv_m64, EVENT_SINK_Invoke, __vbaRaiseEvent, -, __vbaFreeObjList, -, __vbaStrErrVarCopy, _adj_fprem1, -, __vbaRecAnsiToUni, -, __vbaResume, -, __vbaStrCat, -, __vbaVarTextTstEq, __vbaLsetFixstr, -, -, __vbaRecDestruct, __vbaSetSystemError, -, __vbaHresultCheckObj, -, -, __vbaVargVarCopy, __vbaLenVar, _adj_fdiv_m32, __vbaAryVar, Zombie_GetTypeInfo, __vbaAryDestruct, __vbaVarForInit, __vbaBoolStr, -, __vbaStrBool, __vbaExitProc, -, __vbaI4Abs, -, __vbaFileCloseAll, __vbaObjSet, -, __vbaOnError, __vbaStrLike, -, _adj_fdiv_m16i, -, __vbaObjSetAddref, _adj_fdivr_m16i, __vbaVarIndexLoad, -, __vbaFpR4, -, __vbaStrFixstr, -, __vbaStrTextCmp, -, __vbaVarTstLt, __vbaBoolVarNull, __vbaFpR8, __vbaRefVarAry, _CIsin, __vbaErase, -, -, -, __vbaVarZero, __vbaVargVarMove, __vbaVarCmpGt, -, -, __vbaChkstk, -, __vbaFileClose, EVENT_SINK_AddRef, -, __vbaGenerateBoundsError, -, __vbaStrCmp, -, __vbaGet3, __vbaAryConstruct2, __vbaVarTstEq, __vbaObjVar, -, __vbaI2I4, DllFunctionCall, -, __vbaVarOr, __vbaCastObjVar, __vbaLbound, __vbaRedimPreserve, _adj_fpatan, __vbaR4Var, __vbaFixstrConstruct, __vbaLateIdCallLd, Zombie_GetTypeInfoCount, __vbaStrR8, __vbaRedim, __vbaRecUniToAnsi, EVENT_SINK_Release, __vbaNew, -, -, __vbaUI1I2, _CIsqrt, __vbaLateIdCallSt, __vbaObjIs, __vbaVarAnd, EVENT_SINK_QueryInterface, -, __vbaStrUI1, __vbaVarMul, __vbaExceptHandler, -, __vbaStrToUnicode, __vbaPrintFile, -, -, _adj_fprem, _adj_fdivr_m64, -, -, -, -, __vbaFPException, -, __vbaInStrVar, __vbaStrCompVar, -, __vbaGetOwner3, __vbaStrVarVal, __vbaUbound, __vbaVarCat, -, __vbaDateVar, -, __vbaLsetFixstrFree, -, __vbaI2Var, -, -, -, _CIlog, __vbaErrorOverflow, __vbaFileOpen, __vbaVar2Vec, __vbaVarLateMemCallLdRf, __vbaNew2, -, __vbaInStr, __vbaR8Str, -, -, _adj_fdiv_m32i, -, _adj_fdivr_m32i, __vbaStrCopy, __vbaI4Str, -, __vbaFreeStrList, __vbaVarNot, _adj_fdivr_m32, __vbaPowerR8, _adj_fdiv_r, -, -, -, __vbaVarTstNe, -, __vbaI4Var, -, __vbaVarCmpEq, -, __vbaVarAdd, __vbaAryLock, -, __vbaVarDup, __vbaStrComp, __vbaStrToAnsi, -, -, __vbaFpI2, __vbaVarCopy, -, __vbaVarLateMemCallLd, __vbaVarTstGe, __vbaFpI4, __vbaLateMemCallLd, __vbaR8IntI2, __vbaRecDestructAnsi, -, _CIatan, __vbaAryCopy, -, __vbaCastObj, __vbaStrMove, -, __vbaStrVarCopy, __vbaR8IntI4, -, -, -, _allmul, -, __vbaLateIdSt, -, _CItan, -, __vbaFPInt, -, __vbaAryUnlock, __vbaVarForNext, __vbaFpCSngR8, -, _CIexp, __vbaMidStmtBstr, __vbaI4ErrVar, -, __vbaFreeObj, __vbaFreeStr, -

( 0 exports )

=> hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:16:57, on 18.07.2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Sauber\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: Blue Coat K9 Web Protection (WebFilter) - Unknown owner - C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe
O24 - Desktop Component 0: (no name) - http://www.hotel-roese.de/images/button_menu/button2.gif

--
End of file - 4104 bytes
Seitenanfang Seitenende
18.07.2008, 18:48
Moderator

Beiträge: 7805
#4 Loesche bitte die bei Virustotal getestete Datei und starte neu. Ob damit dein Browserproblem behoben ist, kann ich nicht sagen.
Nutzt du Blue Coat K9 Web Protection?
__________
MfG Ralf
SEO-Spam Hunter
Seitenanfang Seitenende
19.07.2008, 12:07
...neu hier

Themenstarter

Beiträge: 4
#5 ... ja blue coat nutze ich

... heute ist internet explorer wieder mal abgestürzt - auch ein neustart des laptops funktionierte dann nicht; musste kaltstarten
Seitenanfang Seitenende
19.07.2008, 12:33
Moderator

Beiträge: 5694
#6 Hallo asd99

Lass Dial-a-Fix laufen und poste das Log:
http://www.virus-protect.org/artikel/tools/dial_a_fix.html

Gruss Swiss
Seitenanfang Seitenende
19.07.2008, 13:11
...neu hier

Themenstarter

Beiträge: 4
#7 ... läuft nicht unter vista - oder gibts da noch ne andere version?
Seitenanfang Seitenende
20.07.2008, 01:11
Moderator

Beiträge: 5694
#8 ads999

Also ich denke das dein Problem irgend durch eine Software entstanden ist. Kann es sein, dass du evtl ein neues Programm geladen hast und es seit dem nicht mehr richtig funktioniert?

Du könntest dein System zu einem früheren zeitpunkt wieder herstellen und schauen ob es da noch besser lief.

Eventuellliegt es an "HD Audio Control Panel" welches im letzten Monat geladen hast.

Hier noch ein Zitat aus einem anderen beitrag:

Zitat

Der Problem lag bei einer Software, die mir mit meinem Canon Pixma MP500 geliefert wurde, nämlich OmniPage (zum Scannen von Text/OCR)!
Gruss Swiss
Seitenanfang Seitenende
Um auf dieses Thema zu ANTWORTEN
bitte erst » hier kostenlos registrieren!!

Folgende Themen könnten Dich auch interessieren: