Anti Virus 2008 XP

#0
29.07.2008, 19:06
...neu hier

Beiträge: 3
#1 Hi Leute!

Hab mir heute was eingfangen. Nennt sich "Antivirus 2008 XP". Habe bereits einiges gemacht aber es bleibt der Desktophintergrund: "Warning Spyware detected on your computer! install an antivirus or spyware ..."

Bitte um Hilfe

Georg

p.s. habe windows vista home premium
Seitenanfang Seitenende
29.07.2008, 19:54
Ehrenmitglied
Avatar Argus

Beiträge: 6028
#2 Poste mal die daten von: http://board.protecus.de/t23187.htm
__________
MfG Argus
Seitenanfang Seitenende
29.07.2008, 22:44
...neu hier

Themenstarter

Beiträge: 3
#3 So das wärs - is ja ganz schön umfangreich (Der Labtop läuft inzwischen wieder einwandfrei...):


Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CLASSES_ROOT\codecbho.codecplugin (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\codecbho.codecplugin.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{098716a9-0310-4cbe-bd64-b790a9761158} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{098716a9-0310-4cbe-bd64-b790a9761158} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{f4406238-983a-4845-9053-f1d0007fd135} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\codecbho.xmldomdocumenteventssink (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\codecbho.xmldomdocumenteventssink.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d37d6c1a-7ba4-47f4-9bf2-75031e257df6} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{48e92754-2daf-4de4-8385-34f631580e9b} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a1c23ba2-8f20-4c01-b663-7ff2b3421194} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{84562fca-ee8b-4585-a1d1-eae97b23370e} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\CodecBHO.DLL (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\RichVideoCodec (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphcjg9j0ere7 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphcjg9j0ere7 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008 (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.

Infizierte Dateien:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Windows\System32\blphcjg9j0ere7.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\phcjg9j0ere7.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Public\Desktop\Antivirus XP 2008.lnk (Rogue.Antivirus) -> Quarantined and deleted successfully.




ComboFix 08-07-28.7 - Schorsch 2008-07-29 22:58:09.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1031.18.1966 [GMT 2:00]
ausgeführt von:: C:\Users\Schorsch\Desktop\ComboFix.exe
* Neuer Wiederherstellungspunkt wurde erstellt
.

(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\msetup
C:\Windows\msetup\BASW-00500A10\Install.exe
C:\Windows\msetup\BASW-00500A10\install.ini
C:\Windows\msetup\BASW-00500A10\setup.exe
C:\Windows\msetup\BASW-00500A10\SWDesc.txt
C:\Windows\msetup\MSetup.exe
C:\Windows\msetup\MSetupLog.log
C:\Windows\system32\x64

.
((((((((((((((((((((((( Dateien erstellt von 2008-06-28 bis 2008-07-29 ))))))))))))))))))))))))))))))
.

2008-07-29 20:15 . 2008-07-29 20:15 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\Malwarebytes
2008-07-29 20:15 . 2008-07-29 20:15 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-07-29 20:15 . 2008-07-29 20:15 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-07-29 20:15 . 2008-07-29 20:15 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-29 20:15 . 2008-07-23 20:09 38,472 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-07-29 20:15 . 2008-07-23 20:09 17,144 --a------ C:\Windows\System32\drivers\mbam.sys
2008-07-29 20:11 . 2008-07-29 20:11 <DIR> d-------- C:\Program Files\CCleaner
2008-07-29 13:11 . 2008-07-29 13:11 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-07-28 19:04 . 2008-07-28 19:04 <DIR> d-------- C:\Program Files\MDIviewer
2008-07-28 19:04 . 2002-08-12 14:56 1,706,800 --a------ C:\Windows\System32\GDIPLUS.DLL
2008-07-28 19:04 . 2003-06-18 17:31 1,033,216 --a------ C:\Windows\System32\MSPCORE.DLL
2008-07-28 19:04 . 2003-06-18 17:31 443,904 --a------ C:\Windows\System32\MDIVWCTL.DLL
2008-07-28 19:04 . 2003-06-18 17:31 16,384 --a------ C:\Windows\System32\MSPGIMME.DLL
2008-07-28 16:18 . 2008-07-28 16:18 <DIR> d-------- C:\Program Files\Plus!
2008-07-28 16:18 . 2008-07-28 16:18 <DIR> d-------- C:\Program Files\Catalyst.Net Ltd
2008-07-28 16:18 . 2000-03-01 09:25 2,359,350 --a------ C:\Windows\Haka Wallpaper 1024x768.bmp
2008-07-28 16:18 . 2000-03-01 09:26 1,440,054 --a------ C:\Windows\Haka Wallpaper 800x600.bmp
2008-07-28 16:18 . 2000-02-27 12:02 372,683 --a------ C:\Windows\System32\Haka.scr
2008-07-28 16:18 . 1997-12-17 18:33 304,128 --a------ C:\Windows\IsUninst.exe
2008-07-28 16:18 . 2000-02-28 18:22 129,149 --a------ C:\Windows\Logo.sys
2008-07-28 16:18 . 2000-02-28 18:22 129,149 --a------ C:\Logo.sys
2008-07-28 16:18 . 2000-02-28 18:05 129,078 --a------ C:\Windows\Logow.sys
2008-07-28 16:18 . 2000-02-28 18:04 129,078 --a------ C:\Windows\Logos.sys
2008-07-28 16:04 . 2008-07-28 16:05 <DIR> d-------- C:\Windows\System32\All Blacks dir
2008-07-28 16:04 . 2008-07-28 16:04 203,264 --a------ C:\Windows\System32\All Blacks.scr
2008-07-27 15:10 . 2008-07-27 15:10 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\Apple Computer
2008-07-27 15:10 . 2008-07-27 15:10 <DIR> d-------- C:\Program Files\iTunes
2008-07-27 15:10 . 2008-07-27 15:10 <DIR> d-------- C:\Program Files\iPod
2008-07-27 15:10 . 2008-07-27 15:10 <DIR> d-------- C:\Program Files\Bonjour
2008-07-27 15:09 . 2008-07-27 15:09 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-07-26 23:35 . 2008-07-26 23:35 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-07-26 23:29 . 2008-07-26 23:29 <DIR> d-------- C:\Users\All Users\SlySoft
2008-07-26 23:29 . 2008-07-26 23:29 <DIR> d-------- C:\ProgramData\SlySoft
2008-07-26 23:27 . 2008-07-26 23:27 <DIR> d-------- C:\Program Files\SlySoft
2008-07-26 19:48 . 2008-07-26 23:25 <DIR> d-------- C:\Users\All Users\Google
2008-07-26 19:48 . 2008-07-26 23:28 <DIR> d-------- C:\Program Files\Google
2008-07-26 19:47 . 2008-07-26 19:47 <DIR> d-------- C:\Program Files\Java
2008-07-26 19:46 . 2008-07-26 19:46 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-25 15:09 . 2008-07-25 15:09 <DIR> d-------- C:\Program Files\DivX
2008-07-25 15:09 . 2008-07-25 15:09 <DIR> d-------- C:\Program Files\Common Files\PX Storage Engine
2008-07-25 11:38 . 2008-07-25 11:38 <DIR> d-------- C:\Program Files\Hp
2008-07-25 11:36 . 2008-07-25 11:38 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-07-25 11:35 . 2008-07-25 11:38 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\Hewlett-Packard
2008-07-25 11:33 . 2008-07-25 11:37 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-07-25 11:31 . 2008-07-25 11:38 80,602 --a------ C:\Windows\HPEasyPrinterCare.his
2008-07-25 11:31 . 2008-07-25 11:31 1,984 --a------ C:\Windows\sounder.his
2008-07-25 11:30 . 2008-07-25 11:30 <DIR> d-------- C:\Temp\Easy Printer Care 2.5.2.0
2008-07-25 11:30 . 2008-07-25 11:30 <DIR> d-------- C:\Temp
2008-07-25 11:16 . 2008-07-25 11:16 52 --a------ C:\Windows\seumain.INI
2008-07-25 11:11 . 2008-07-25 11:11 <DIR> d-------- C:\Users\All Users\Sage
2008-07-25 11:11 . 2008-07-25 11:11 <DIR> d-------- C:\ProgramData\Sage
2008-07-25 11:11 . 2008-07-25 11:11 <DIR> d-------- C:\Program Files\Sage
2008-07-25 11:11 . 2008-07-25 11:21 <DIR> d-------- C:\Program Files\Common Files\Sage KHK Shared
2008-07-25 11:11 . 2008-07-25 11:11 <DIR> d-------- C:\Program Files\Common Files\Sage Group
2008-07-25 11:11 . 1997-07-21 18:30 1,045,776 --a------ C:\Windows\System32\msjet35.dll
2008-07-25 11:11 . 2008-07-25 11:11 570,971 --a------ C:\Windows\System32\PC-Kaufmann Fibu Pro 2007.isu
2008-07-25 11:11 . 2005-04-06 15:13 487,424 --a------ C:\Windows\System32\msvcp70.dll
2008-07-25 11:11 . 1997-06-23 11:06 407,312 --a------ C:\Windows\System32\msrepl35.dll
2008-07-25 11:11 . 2005-04-06 15:13 344,064 --a------ C:\Windows\System32\msvcr70.dll
2008-07-25 11:11 . 1997-06-23 11:06 252,176 --a------ C:\Windows\System32\msrd2x35.dll
2008-07-25 11:11 . 1996-01-24 12:27 244,496 --a------ C:\Windows\System32\VBAR2232.DLL
2008-07-25 11:11 . 1997-06-23 11:06 123,664 --a------ C:\Windows\System32\msjint35.dll
2008-07-25 11:11 . 1997-06-23 11:06 24,848 --a------ C:\Windows\System32\msjter35.dll
2008-07-25 11:11 . 2008-07-25 11:11 0 --a------ C:\Windows\KHKSManC.INI
2008-07-25 11:08 . 1998-11-17 13:44 328,704 --a------ C:\Windows\IsUn0407.exe
2008-07-24 15:46 . 2008-07-24 15:46 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-07-24 15:46 . 2008-07-04 08:34 860,160 --a------ C:\Windows\System32\lameACM.acm
2008-07-24 15:46 . 2004-01-25 18:18 217,088 --a------ C:\Windows\System32\yv12vfw.dll
2008-07-24 15:46 . 2007-09-04 18:56 164,352 --a------ C:\Windows\System32\unrar.dll
2008-07-24 15:46 . 2007-09-21 02:52 118,784 --a------ C:\Windows\System32\ac3acm.acm
2008-07-24 15:46 . 2007-07-10 18:10 547 --a------ C:\Windows\System32\ff_vfw.dll.manifest
2008-07-24 15:46 . 2007-10-03 17:03 414 --a------ C:\Windows\System32\lame_acm.xml
2008-07-24 14:58 . 2008-07-24 15:53 <DIR> d-------- C:\Users\All Users\NOS
2008-07-24 14:58 . 2008-07-24 15:53 <DIR> d-------- C:\ProgramData\NOS
2008-07-24 14:58 . 2008-07-24 15:53 <DIR> d-------- C:\Program Files\NOS
2008-07-24 14:43 . 2008-07-24 14:43 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-07-23 22:34 . 2008-07-23 22:34 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\CyberLink
2008-07-23 22:34 . 2008-07-23 22:34 <DIR> d-------- C:\Users\All Users\CyberLink
2008-07-23 22:34 . 2008-07-23 22:34 <DIR> d-------- C:\ProgramData\CyberLink
2008-07-23 15:56 . 2008-07-23 15:56 <DIR> d-------- C:\PerfLogs
2008-07-23 15:01 . 2008-04-23 06:42 428,544 --a------ C:\Windows\System32\EncDec.dll
2008-07-23 15:01 . 2008-04-23 06:42 293,376 --a------ C:\Windows\System32\psisdecd.dll
2008-07-23 15:01 . 2008-04-23 06:41 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-07-23 15:01 . 2008-01-19 09:33 80,896 --a------ C:\Windows\System32\MSNP.ax
2008-07-23 15:01 . 2008-01-19 09:33 69,632 --a------ C:\Windows\System32\Mpeg2Data.ax
2008-07-23 15:01 . 2008-04-23 06:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-07-23 13:17 . 2008-01-19 08:06 8,147,456 --a------ C:\Windows\System32\wmploc.DLL
2008-07-23 13:16 . 2008-01-19 09:34 305,152 --a------ C:\Windows\System32\msdelta.dll
2008-07-23 13:16 . 2008-01-19 09:34 258,560 --a------ C:\Windows\System32\dpx.dll
2008-07-23 13:16 . 2008-01-19 09:34 246,784 --a------ C:\Windows\System32\drvstore.dll
2008-07-23 13:16 . 2008-01-19 09:35 35,328 --a------ C:\Windows\System32\mspatcha.dll
2008-07-23 13:00 . 2008-07-23 13:00 <DIR> d-------- C:\Users\All Users\FLEXnet
2008-07-23 13:00 . 2008-07-23 13:00 <DIR> d-------- C:\ProgramData\FLEXnet
2008-07-23 12:49 . 2008-07-23 12:49 <DIR> d-------- C:\Program Files\VistaCodecPack
2008-07-23 12:48 . 2008-07-23 12:48 <DIR> d-------- C:\Users\All Users\VistaCodecs
2008-07-23 12:48 . 2008-07-23 12:48 <DIR> d-------- C:\ProgramData\VistaCodecs
2008-07-23 11:33 . 2007-02-20 16:04 2,463,976 --a------ C:\Windows\System32\NPSWF32.dll
2008-07-23 11:33 . 2007-02-20 16:04 190,696 --a------ C:\Windows\System32\NPSWF32_FlashUtil.exe
2008-07-23 11:12 . 2008-07-23 11:12 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-07-23 11:00 . 2008-07-23 11:00 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\DAEMON Tools
2008-07-23 11:00 . 2008-07-23 11:00 717,296 --a------ C:\Windows\System32\drivers\sptd.sys
2008-07-23 10:27 . 2008-07-24 15:02 <DIR> d-------- C:\Users\All Users\Adobe
2008-07-23 10:27 . 2008-07-24 15:02 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-07-23 10:20 . 2008-07-23 10:20 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\AdobeUM
2008-07-23 08:21 . 2008-07-23 08:21 <DIR> d-------- C:\Users\All Users\DVD Shrink
2008-07-23 08:21 . 2008-07-23 08:21 <DIR> d-------- C:\ProgramData\DVD Shrink
2008-07-23 08:21 . 2008-07-23 08:21 <DIR> d-------- C:\Program Files\DVD Shrink
2008-07-23 08:15 . 2008-07-23 08:15 <DIR> d-------- C:\Program Files\VideoLAN
2008-07-22 22:03 . 2008-07-22 22:03 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\Logitech
2008-07-22 22:03 . 2008-07-22 22:03 <DIR> d-------- C:\Users\All Users\LogiShrd
2008-07-22 22:03 . 2008-07-22 22:03 <DIR> d-------- C:\ProgramData\LogiShrd
2008-07-22 22:03 . 2008-07-22 22:03 0 --ah----- C:\Windows\System32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-07-22 22:02 . 2008-07-22 22:02 <DIR> d-------- C:\Users\All Users\Logitech
2008-07-22 22:02 . 2008-07-22 22:02 <DIR> d-------- C:\ProgramData\Logitech
2008-07-22 22:02 . 2008-07-22 22:02 <DIR> d-------- C:\Program Files\Logitech
2008-07-22 22:02 . 2008-07-22 22:02 <DIR> d-------- C:\Program Files\Common Files\Logitech
2008-07-22 22:02 . 2007-04-23 04:00 163,840 --a------ C:\Windows\System32\kemutb.dll
2008-07-22 22:02 . 2007-04-23 04:00 135,168 --a------ C:\Windows\System32\KemUtil.dll
2008-07-22 22:02 . 2007-04-23 04:00 110,592 --a------ C:\Windows\System32\KemWnd.dll
2008-07-22 22:02 . 2007-04-23 04:00 69,632 --a------ C:\Windows\System32\KemXML.dll
2008-07-22 21:53 . 2008-07-27 15:10 <DIR> d-------- C:\Users\All Users\Apple Computer
2008-07-22 21:53 . 2008-07-22 21:53 <DIR> d-------- C:\Users\All Users\Apple
2008-07-22 21:53 . 2008-07-27 15:10 <DIR> d-------- C:\ProgramData\Apple Computer
2008-07-22 21:53 . 2008-07-22 21:53 <DIR> d-------- C:\ProgramData\Apple
2008-07-22 21:53 . 2008-07-22 21:53 <DIR> d-------- C:\Program Files\QuickTime

.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-29 16:45 51 --sha-w C:\Program Files\Common Files\desktop.ini
2008-07-23 14:06 174 --sha-w C:\Program Files\desktop.ini
2008-07-23 13:58 --------- d-----w C:\Program Files\Windows Sidebar
2008-07-23 13:58 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-07-23 13:58 --------- d-----w C:\Program Files\Windows Mail
2008-07-23 13:58 --------- d-----w C:\Program Files\Windows Journal
2008-07-23 13:58 --------- d-----w C:\Program Files\Windows Collaboration
2008-07-23 13:58 --------- d-----w C:\Program Files\Windows Calendar
2008-07-23 13:57 --------- d-----w C:\Program Files\Windows Defender
2008-07-23 13:14 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-07-23 13:14 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-07-22 20:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-22 18:12 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-22 18:09 --------- d-----w C:\Program Files\Microsoft Small Business
2008-07-22 17:49 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-07-22 12:01 --------- d-----w C:\ProgramData\McAfee
2008-07-22 11:52 --------- d-----w C:\ProgramData\Microsoft Help
2008-07-22 11:08 --------- d-----w C:\Program Files\Intel
2008-07-22 10:53 --------- d-sh--w C:\ProgramData\Vorlagen
2008-07-22 10:53 --------- d-sh--w C:\ProgramData\Startmenü
2008-07-22 10:53 --------- d-sh--w C:\ProgramData\Favoriten
2008-07-22 10:53 --------- d-sh--w C:\ProgramData\Dokumente
2008-07-22 10:53 --------- d-sh--w C:\ProgramData\Anwendungsdaten
2008-07-22 10:53 --------- d--h--r C:\Program Files\Gemeinsame Dateien
2008-06-26 11:06 93,128 ----a-w C:\Windows\System32\ElbyCDIO.dll
2008-06-18 17:52 161,096 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-06-12 18:36 7,680 ----a-w C:\Windows\System32\ff_vfw.dll
2008-06-12 17:25 966,656 ----a-w C:\Windows\System32\VSFilter.dll
2008-06-11 00:07 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2008-06-11 00:07 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-06-11 00:04 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-06-11 00:04 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-06-06 17:13 106,496 ----a-w C:\Windows\System32\HPSTDSoap.dll
2008-06-06 16:47 49,152 ----a-w C:\Windows\System32\FXCompChannel.dll
2008-06-06 16:47 290,816 ----a-w C:\Windows\System32\WINHTTP5.DLL
2008-06-06 16:47 163,840 ----a-w C:\Windows\System32\hppatusg01.dll
2008-06-06 16:46 126,976 ----a-w C:\Windows\System32\HPDevEnm.dll
2008-05-27 05:21 1,582,592 ----a-w C:\Windows\System32\tquery.dll
2008-05-27 05:21 1,418,240 ----a-w C:\Windows\System32\mssrch.dll
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\SearchFilterHost.exe
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\mssitlb.dll
2008-05-27 05:17 754,176 ----a-w C:\Windows\System32\propsys.dll
2008-05-27 05:17 60,416 ----a-w C:\Windows\System32\msscntrs.dll
2008-05-27 05:17 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll
2008-05-27 05:17 34,816 ----a-w C:\Windows\System32\msscb.dll
2008-05-27 05:17 32,768 ----a-w C:\Windows\System32\mssprxy.dll
2008-05-27 05:17 313,344 ----a-w C:\Windows\System32\thawbrkr.dll
2008-05-27 05:17 301,568 ----a-w C:\Windows\System32\srchadmin.dll
2008-05-27 05:17 194,560 ----a-w C:\Windows\System32\offfilt.dll
2008-05-27 05:17 143,872 ----a-w C:\Windows\System32\korwbrkr.dll
2008-05-27 05:17 11,776 ----a-w C:\Windows\System32\msshooks.dll
2008-05-27 05:17 1,671,680 ----a-w C:\Windows\System32\chsbrkr.dll
2008-05-27 04:59 18,904 ----a-w C:\Windows\System32\StructuredQuerySchemaTrivial.bin
2008-05-27 04:59 106,605 ----a-w C:\Windows\System32\StructuredQuerySchema.bin
2008-05-22 22:18 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2008-05-10 03:35 564,736 ----a-w C:\Windows\System32\emdmgmt.dll
2008-05-08 21:59 90,112 ----a-w C:\Windows\System32\wshext.dll
2008-05-08 21:59 430,080 ----a-w C:\Windows\System32\vbscript.dll
2008-05-08 21:59 180,224 ----a-w C:\Windows\System32\scrobj.dll
2008-05-08 21:59 172,032 ----a-w C:\Windows\System32\scrrun.dll
2008-05-08 21:59 155,648 ----a-w C:\Windows\System32\wscript.exe
2008-05-08 21:58 135,168 ----a-w C:\Windows\System32\cscript.exe
.

(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 09:33 1233920]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-07-17 14:20 490952]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 09:33 202240]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe" [2008-07-21 14:15 2157504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-07 04:17 839680]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 08:10 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 15:55 54832]
"Play AVStation TV Scheduler"="C:\Program Files\Samsung\Play AVStation\TvScheduler.exe" [2007-01-09 04:09 73728]
"ViivMonitor"="C:\Program Files\Intel\Intel Media Share Software\ViivMonitor.exe" [2007-03-10 13:41 69632]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-11 20:13 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-11 20:13 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-11 20:13 133656]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"KnexStarter"="C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\Appinterfaces\HPDeviceService.exe" [2008-06-06 19:13 73728]
"RunTasktray"="C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe" [2008-06-06 18:46 69120]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-15 01:50 4399104 C:\Windows\RtHDVCpl.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\Windows\KHALMNPR.Exe]
"Skytel"="Skytel.exe" [2007-03-14 04:55 1822720 C:\Windows\SkyTel.exe]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-12-20 05:27:40 719664]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-07-22 22:02:11 692224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"NoHotStart"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"C:\\Program Files\\Hewlett-Packard\\HP Easy Printer Care\\HPPRun.exe"= C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe:*:Enabled:HP Easy Printer Care HPPRun

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{31C53CE9-ACCD-411D-A50F-D84C6C392D56}"= UDP:C:\Program Files\Intel\Intel Media Share Software\IMSS.exe:Intel® Media Share Software
"{73460D40-0364-425C-8F64-8F2683788668}"= TCP:C:\Program Files\Intel\Intel Media Share Software\IMSS.exe:Intel® Media Share Software
"{5EB2C1DA-FF07-4057-B8B0-C95663040888}"= UDP:C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe:Intel® Media Share Synch Service
"{4EAADDCE-5C1A-4F85-A3AC-11EF0967D747}"= TCP:C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe:Intel® Media Share Synch Service
"TCP Query User{B378C651-678C-4A99-8616-56BB6BAB87F6}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{71A6EFF2-754D-4399-85E2-703AD1825814}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{D22CD4B1-DEE7-4DC1-B698-A3EC407D07F1}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{4441814C-3F8E-4EA0-BBFD-049123922827}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{95B10FD1-BA85-40CA-81E5-5C5721EC8CF4}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{7C9F8565-DB11-4154-86A7-6830CC341F27}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\Hewlett-Packard\\HP Easy Printer Care\\HPPRun.exe"= C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe:*:Enabled:HP Easy Printer Care HPPRun

R2 IMSSync;Intel® Media Share Synch Service;C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe [2007-03-10 13:40]
R2 KMDFMEMIO;SAMSUNG Kernel Driver;C:\Windows\system32\DRIVERS\kmdfmemio.sys [2006-11-14 02:11]
R3 btwaudio;Bluetooth-Audiogerät;C:\Windows\system32\drivers\btwaudio.sys [2006-12-20 21:08]
R3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2006-12-20 21:04]
R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2006-12-20 21:07]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-06 09:51]
S3 NETw2v32;Intel(R) PRO/Wireless 2915ABG Network Connection Driver for Windows Vista;C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 09:30]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Inhalt des "geplante Tasks" Ordners

2008-07-29 C:\Windows\Tasks\User_Feed_Synchronization-{71EDB7DA-0C0C-4FDD-ADE9-E85DA199D6BF}.job
- C:\Windows\system32\msfeedssync.exe [2008-01-19 09:33]
.
.
------- Zusätzlicher Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 -: Nach Microsoft &Excel exportieren - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O18 -: Handler: HPDCS - {ba135f49-a12c-4e26-a2c4-6ea945999072} - C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\APP\hpdcsapp.dll
O18 -: Handler: hppfile - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
O18 -: Handler: hppsam - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
O18 -: Handler: hppzip - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll

O16 -: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
C:\Windows\Downloaded Program Files\DownloadManagerV2.inf
C:\Windows\Downloaded Program Files\Manager.exe
C:\Windows\Downloaded Program Files\DownloadManagerV2.ocx


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-29 23:01:13
Windows 6.0.6001 Service Pack 1 NTFS

Scanne versteckte Prozesse...

Scanne versteckte Autostart Einträge...

Scanne versteckte Dateien...

Scan erfolgreich abgeschlossen
versteckte Dateien: 0

**************************************************************************
.
Zeit der Fertigstellung: 2008-07-29 23:02:44
ComboFix-quarantined-files.txt 2008-07-29 21:02:27

Pre-Run: 10 Verzeichnis(se), 61,958,242,304 Bytes frei
Post-Run: 17 Verzeichnis(se), 64,732,028,928 Bytes frei

313 --- E O F --- 2008-07-26 21:35:45






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:20:56, on 29.07.2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Intel\Intel Media Share Software\Viivmonitor.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\AppInterfaces\HPDeviceService.exe
C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\AppInterfaces\HPDeviceHost.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Users\Schorsch\Desktop\HJT.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [Play AVStation TV Scheduler] C:\Program Files\Samsung\Play AVStation\TvScheduler.exe
O4 - HKLM\..\Run: [ViivMonitor] C:\Program Files\Intel\Intel Media Share Software\ViivMonitor.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KnexStarter] C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\Appinterfaces\HPDeviceService.exe
O4 - HKLM\..\Run: [RunTasktray] "C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe" --regkeypath=Software\Hewlett-Packard\HP Easy Printer Care\HPPRun --valuename=InstallTTM
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.hp.com (HKLM)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1217094401155&h=f65e49af411fb66e0b6c7d6ba9f4c1bd/&filename=jinstall-6u7-windows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O18 - Protocol: HPDCS - {BA135F49-A12C-4E26-A2C4-6EA945999072} - C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\APP\hpdcsapp.dll
O18 - Protocol: hppfile - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
O18 - Protocol: hppsam - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
O18 - Protocol: hppzip - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel® Media Share Synch Service (IMSSync) - Intel® Corporation - C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe

--
End of file - 8879 bytes





32 Bit HP CIO Components Installer
Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Reader 9 - Deutsch
Agere Systems HDA Modem
All Blacks Screen Saver
AnyDVD
Apple Mobile Device Support
Apple Software Update
Avira AntiVir Personal – Free Antivirus
AVStation Now
Bonjour
CCleaner (remove only)
CDDRV_Installer
CorelDRAW Graphics Suite 11
DivX Codec
DivX Converter
DivX Player
DivX Web Player
DVD Shrink 3.2
DVD Suite
Easy Battery Manager
Easy Burning (remove only)
Easy Display Manager
Easy Network Manager 3.0
Easy SpeedUp Manager
Haka Theme
HP Easy Printer Care
HP Easy Printer Care
HP Printer Settings Tools
HP Printer Usage Report
HP Proactive Services
HP Update
imagine digital freedom - Samsung
Intel(R) Graphics Media Accelerator Driver
Intel(R) PROSet/Wireless Software
Intel® Media-Share-Software
iTunes
Java(TM) 6 Update 7
KhalInstallWrapper
K-Lite Codec Pack 4.0.0 (Full)
Komponenten der Betriebssystemkommunikation
Komponenten der Ereigniskommunikation
Komponenten der Gerätedatenkommunikation
Komponenten der Kernkommunikation
Logitech SetPoint
Malwarebytes' Anti-Malware
MDI viewer 0.1
mDriver
Microsoft Office 2003 Web Components
Microsoft Office 2007 Primary Interop Assemblies
Microsoft Office Professional Edition 2003
Microsoft Office Small Business Connectivity Components
Microsoft Silverlight
Microsoft SQL Server Native Client
Microsoft SQL Server VSS Writer
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 Parser and SDK
PC-Kaufmann Fibu Pro Vollversion 2007
PhotoNow! 1.0
Play AVStation
PlayCamera
PowerDVD
Q45 Q46 User Guide
QuickTime
Realtek High Definition Audio Driver
Samsung Magic Doctor
Samsung Recovery Solution II
Samsung Update Plus
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Synaptics Pointing Device Driver
Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch)
VideoLAN VLC media player 0.8.6i
Vista Codec Package
WIDCOMM Bluetooth Software




.
.
Bitte nur die Eintraege der letzten 3 Monate pro Ordner posten
.
.
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 8CED-D108

Verzeichnis von C:\Windows\system32

29.07.2008 23:17 590.082 perfh009.dat
29.07.2008 23:17 102.094 perfc009.dat
29.07.2008 23:17 621.942 perfh007.dat
29.07.2008 23:17 123.666 perfc007.dat
29.07.2008 23:17 1.427.210 PerfStringBackup.INI
29.07.2008 23:10 3.296 7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
29.07.2008 23:10 3.296 7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
29.07.2008 18:32 4.144 scan.log
28.07.2008 16:04 203.264 All Blacks.scr
26.07.2008 19:47 6.894 jupdate-1.6.0_07-b06.log
26.07.2008 12:47 1.771.864 FNTCACHE.DAT
25.07.2008 11:11 570.971 PC-Kaufmann Fibu Pro 2007.isu
23.07.2008 15:14 101.888 ifxcardm.dll
23.07.2008 15:14 82.432 axaltocm.dll
22.07.2008 18:14 11.580.416 shell32.dll
22.07.2008 18:10 1.793.536 NlsLexicons0045.dll
22.07.2008 18:10 1.808.896 NlsLexicons0046.dll
22.07.2008 18:10 1.411.072 NlsLexicons0047.dll
22.07.2008 18:10 1.558.016 NlsLexicons0049.dll
22.07.2008 18:10 1.236.992 NlsLexicons0020.dll
22.07.2008 18:10 1.782.272 NlsLexicons0039.dll
22.07.2008 18:10 2.136.064 NlsLexicons0021.dll
22.07.2008 18:10 5.499.904 NlsLexicons0022.dll
22.07.2008 18:10 7.964.672 NlsLexicons0024.dll
22.07.2008 18:10 5.791.232 NlsLexicons0026.dll
22.07.2008 18:10 6.224.896 NlsLexicons0027.dll
22.07.2008 18:10 4.175.872 NlsLexicons0010.dll
22.07.2008 18:10 2.466.816 NlsLexicons0011.dll
22.07.2008 18:10 4.981.248 NlsLexicons0013.dll
22.07.2008 18:10 3.331.072 NlsLexicons0018.dll
22.07.2008 18:10 6.781.440 NlsLexicons0019.dll
22.07.2008 18:10 11.722.752 NlsLexicons0001.dll
22.07.2008 18:10 4.164.096 NlsLexicons0002.dll
22.07.2008 18:10 1.452.544 NlsLexicons0003.dll
22.07.2008 18:10 12.240.896 NlsLexicons0007.dll
22.07.2008 18:10 2.644.480 NlsLexicons0009.dll
22.07.2008 18:10 3.419.136 NlsLexicons004a.dll
22.07.2008 18:10 1.702.912 NlsLexicons004b.dll
22.07.2008 18:10 4.093.440 NlsLexicons004c.dll
22.07.2008 18:10 1.972.736 NlsLexicons004e.dll
22.07.2008 18:10 4.045.824 NlsLexicons003e.dll
22.07.2008 18:10 4.096 NlsLexicons002a.dll
22.07.2008 18:10 6.014.976 NlsLexicons001a.dll
22.07.2008 18:10 6.585.856 NlsLexicons001b.dll
22.07.2008 18:10 6.346.240 NlsLexicons001d.dll
22.07.2008 18:10 9.892.864 NlsLexicons000a.dll
22.07.2008 18:10 6.237.696 NlsLexicons000c.dll
22.07.2008 18:10 1.722.368 NlsLexicons000d.dll
22.07.2008 18:10 5.654.528 NlsLexicons000f.dll
22.07.2008 18:10 4.616.192 NlsLexicons0414.dll
22.07.2008 18:10 5.090.816 NlsLexicons0416.dll
22.07.2008 18:10 5.031.936 NlsLexicons0816.dll
22.07.2008 18:10 7.042.560 NlsLexicons081a.dll
22.07.2008 18:10 5.071.872 NlsModels0011.dll
22.07.2008 18:10 3.104.768 NlsData0045.dll
22.07.2008 18:10 3.104.768 NlsData0046.dll
22.07.2008 18:10 3.104.768 NlsData0047.dll
22.07.2008 18:10 3.104.768 NlsData0049.dll
22.07.2008 18:10 3.104.768 NlsData0039.dll
22.07.2008 18:10 3.104.768 NlsData0020.dll
22.07.2008 18:10 1.801.216 NlsData0021.dll
22.07.2008 18:10 1.801.216 NlsData0022.dll
22.07.2008 18:10 1.965.056 NlsData0024.dll
22.07.2008 18:10 1.965.056 NlsData0026.dll
22.07.2008 18:10 1.966.592 NlsData0027.dll
22.07.2008 18:10 4.495.360 NlsData0010.dll
22.07.2008 18:10 2.657.280 NlsData0011.dll
22.07.2008 18:10 3.466.752 NlsData0013.dll
22.07.2008 18:10 1.965.056 NlsData0018.dll
22.07.2008 18:10 1.523.712 NlsData0000.dll
22.07.2008 18:10 4.497.408 NlsData0019.dll
22.07.2008 18:10 2.599.936 NlsData0001.dll
22.07.2008 18:10 1.965.056 NlsData0002.dll
22.07.2008 18:10 1.965.056 NlsData0003.dll
22.07.2008 18:10 2.243.072 NlsData0007.dll
22.07.2008 18:10 4.875.776 NlsData0009.dll
22.07.2008 18:10 3.104.768 NlsData004a.dll
22.07.2008 18:10 3.104.768 NlsData004b.dll
22.07.2008 18:10 3.104.768 NlsData004c.dll
22.07.2008 18:10 3.104.768 NlsData004e.dll
22.07.2008 18:10 1.801.216 NlsData003e.dll
22.07.2008 18:10 1.801.216 NlsData002a.dll
22.07.2008 18:10 1.965.056 NlsData001a.dll
22.07.2008 18:10 1.965.056 NlsData001b.dll
22.07.2008 18:10 4.495.360 NlsData001d.dll
22.07.2008 18:10 9.847.296 NlsData000a.dll
22.07.2008 18:10 2.643.456 NlsData000c.dll
22.07.2008 18:10 2.342.912 NlsData000d.dll
22.07.2008 18:10 1.965.056 NlsData000f.dll
22.07.2008 18:10 4.495.360 NlsData0414.dll
22.07.2008 18:10 4.495.360 NlsData0416.dll
22.07.2008 18:10 801.280 NaturalLanguage6.dll
22.07.2008 18:10 4.495.360 NlsData0816.dll
22.07.2008 18:10 1.965.056 NlsData081a.dll
22.07.2008 18:10 6.917.120 NlsLexicons0c1a.dll
22.07.2008 18:10 1.965.056 NlsData0c1a.dll
22.07.2008 18:09 181.760 fsquirt.exe
22.07.2008 18:08 6.656 kbd106n.dll
22.07.2008 18:07 927.288 winresume.exe
22.07.2008 18:07 988.216 winload.exe
22.07.2008 18:07 40.960 srclient.dll
22.07.2008 18:07 318.464 rstrui.exe
22.07.2008 18:07 378.368 srcore.dll
22.07.2008 18:07 14.848 srdelayed.exe
22.07.2008 18:07 19.000 kd1394.dll
22.07.2008 18:07 46.592 setbcdlocale.dll
22.07.2008 18:07 615.992 ci.dll
22.07.2008 18:06 2.032.128 win32k.sys
22.07.2008 18:06 295.936 gdi32.dll
22.07.2008 18:05 14.848 wshrm.dll
22.07.2008 18:02 1.314.816 quartz.dll
22.07.2008 18:01 826.880 wininet.dll
22.07.2008 18:01 28.160 jsproxy.dll
22.07.2008 18:01 3.578.368 mshtml.dll
22.07.2008 18:01 1.383.424 mshtml.tlb
22.07.2008 18:01 671.232 mstime.dll
22.07.2008 18:01 1.166.336 urlmon.dll
04.07.2008 08:34 860.160 lameACM.acm
26.06.2008 13:06 93.128 ElbyCDIO.dll
25.06.2008 09:15 17.972.344 mrt.exe
18.06.2008 19:52 161.096 DivXCodecVersionChecker.exe
12.06.2008 20:36 7.680 ff_vfw.dll
12.06.2008 19:25 966.656 VSFilter.dll
11.06.2008 02:07 524.288 DivXsm.exe
11.06.2008 02:07 10.152 dsm_de.qm
11.06.2008 02:07 4.816 divxsm.tlb
11.06.2008 02:07 3.596.288 qt-dx331.dll
11.06.2008 02:04 200.704 ssldivx.dll
11.06.2008 02:04 1.044.480 libdivx.dll
11.06.2008 02:03 81.920 dpl100.dll
11.06.2008 02:03 196.608 dtu100.dll
11.06.2008 02:03 416 dpl100.dll.manifest
11.06.2008 02:03 416 dtu100.dll.manifest
11.06.2008 02:03 8.523 dpude.qm
11.06.2008 02:03 3.051 dtu_de.qm
11.06.2008 02:03 294.912 dpu11.dll
11.06.2008 02:03 294.912 dpu10.dll
11.06.2008 02:03 344.064 dpus11.dll
11.06.2008 02:03 57.344 dpv11.dll
11.06.2008 02:03 593.920 dpuGUI11.dll
11.06.2008 02:03 53.248 dpuGUI10.dll
11.06.2008 02:03 802.816 divx_xx11.dll
11.06.2008 02:03 823.296 divx_xx0c.dll
11.06.2008 02:03 815.104 divx_xx0a.dll
11.06.2008 02:03 823.296 divx_xx07.dll
11.06.2008 02:03 683.520 DivX.dll
11.06.2008 02:03 630.784 divxdec.ax
10.06.2008 02:32 139.264 javaws.exe
10.06.2008 01:21 135.168 javaw.exe
10.06.2008 01:21 135.168 java.exe
06.06.2008 19:13 106.496 HPSTDSoap.dll
06.06.2008 18:47 290.816 WINHTTP5.DLL
06.06.2008 18:47 163.840 hppatusg01.dll
06.06.2008 18:47 49.152 FXCompChannel.dll
06.06.2008 18:46 126.976 HPDevEnm.dll
06.06.2008 18:45 516.832 capicom.dll
27.05.2008 10:50 57.344 QuickTime.qts
27.05.2008 10:50 90.112 QuickTimeVR.qtx
27.05.2008 07:21 1.418.240 mssrch.dll
27.05.2008 07:21 1.582.592 tquery.dll
27.05.2008 07:18 670.208 mssvp.dll
27.05.2008 07:18 203.776 mssphtb.dll
27.05.2008 07:18 439.808 SearchIndexer.exe
27.05.2008 07:18 44.032 msstrc.dll
27.05.2008 07:18 29.184 wsepno.dll
27.05.2008 07:18 40.448 mimefilt.dll
27.05.2008 07:18 231.936 msshsq.dll
27.05.2008 07:18 56.320 xmlfilter.dll
27.05.2008 07:18 136.704 nlhtml.dll
27.05.2008 07:18 38.400 rtffilt.dll
27.05.2008 07:18 350.208 mssph.dll
27.05.2008 07:18 184.832 SearchProtocolHost.exe
27.05.2008 07:18 71.680 propdefs.dll
27.05.2008 07:17 87.552 SearchFilterHost.exe
27.05.2008 07:17 754.176 propsys.dll
27.05.2008 07:17 34.816 msscb.dll
27.05.2008 07:17 11.776 msshooks.dll
27.05.2008 07:17 301.568 srchadmin.dll
27.05.2008 07:17 32.768 mssprxy.dll
27.05.2008 07:17 87.552 mssitlb.dll
27.05.2008 07:17 60.416 msscntrs.dll
27.05.2008 07:17 194.560 offfilt.dll
27.05.2008 07:17 6.103.040 chtbrkr.dll
27.05.2008 07:17 143.872 korwbrkr.dll
27.05.2008 07:17 313.344 thawbrkr.dll
27.05.2008 07:17 1.671.680 chsbrkr.dll
27.05.2008 06:59 18.904 StructuredQuerySchemaTrivial.bin
27.05.2008 06:59 106.605 StructuredQuerySchema.bin
23.05.2008 00:18 12.288 DivXWMPExtType.dll
10.05.2008 05:35 564.736 emdmgmt.dll
08.05.2008 23:59 90.112 wshext.dll
08.05.2008 23:59 430.080 vbscript.dll
08.05.2008 23:59 172.032 scrrun.dll
08.05.2008 23:59 180.224 scrobj.dll
08.05.2008 23:59 512.000 jscript.dll
08.05.2008 23:59 155.648 wscript.exe
08.05.2008 23:58 135.168 cscript.exe
08.05.2008 23:58 135.168 wshom.ocx

.
.
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 8CED-D108

Verzeichnis von C:\Users\Schorsch\AppData\Local\Temp\Low

29.07.2008 23:24 131.130 datfind.txt
1 Datei(en), 131.130 Bytes
0 Verzeichnis(se), 64.404.221.952 Bytes frei
.
.
.
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 8CED-D108

Verzeichnis von C:\Windows

29.07.2008 23:13 1.654.001 WindowsUpdate.log
29.07.2008 23:10 67.584 bootstat.dat
29.07.2008 23:10 328 PFRO.log
29.07.2008 23:09 12 bthservsdp.dat
29.07.2008 23:02 53.248 PSEXESVC.EXE
29.07.2008 23:01 215 system.ini
25.07.2008 11:38 80.602 HPEasyPrinterCare.his
25.07.2008 11:31 1.984 sounder.his
25.07.2008 11:16 52 seumain.INI
25.07.2008 11:11 0 KHKSManC.INI
23.07.2008 16:06 749 WindowsShell.Manifest
22.07.2008 21:04 240 win.ini
22.07.2008 17:38 400 ODBC.INI
19.01.2008 09:33 134.656 regedit.exe
19.01.2008 09:33 151.040 notepad.exe
19.01.2008 09:33 498.176 HelpPane.exe
19.01.2008 09:33 13.312 fveupdate.exe
19.01.2008 09:33 2.927.104 explorer.exe
19.01.2008 09:33 58.880 bfsvc.exe
27.09.2007 07:41 10 Csup.txt
27.09.2007 06:37 319.456 DIFxAPI.dll
27.09.2007 06:36 315.392 HideWin.exe
27.09.2007 05:36 49.152 CBS.log.perf
27.09.2007 05:36 2.162.688 CBS.log.dpx
11.04.2007 15:32 56.080 KHALMNPR.Exe
15.03.2007 01:50 4.399.104 RtHDVCpl.exe
14.03.2007 04:55 1.822.720 SkyTel.exe
05.02.2007 20:05 38 AviSplitter.INI
31.01.2007 03:28 221.184 SetDisplayResolution.exe
23.01.2007 21:32 3.214 SetDisplayResolution.xml
16.01.2007 20:39 1.191.936 RtlUpd.exe
13.01.2007 02:54 520.192 RtlExUpd.dll
12.12.2006 17:38 319.488 SMCM.exe
03.12.2006 10:00 172.032 SMCM.dll
02.11.2006 14:35 316.640 WMSysPr9.prx
02.11.2006 14:34 49.680 twunk_16.exe
02.11.2006 14:34 50.688 twain_32.dll
02.11.2006 14:34 31.232 twunk_32.exe
02.11.2006 14:34 94.784 twain.dll
02.11.2006 11:45 9.216 winhlp32.exe
02.11.2006 11:45 14.848 hh.exe
02.11.2006 09:46 43.131 mib.bin
26.10.2006 23:08 50.752 agrsmdel.exe
19.09.2006 13:41 8.328 HomePremium.xml
18.09.2006 23:43 707 _default.pif
18.09.2006 23:43 256.192 winhelp.exe
18.09.2006 23:30 1.405 msdfmap.ini
13.09.2006 07:21 2.438 ebm.reg
31.08.2000 08:00 136.704 swsc.exe
31.08.2000 08:00 212.480 swxcacls.exe
31.08.2000 08:00 161.792 swreg.exe
31.08.2000 08:00 68.096 zip.exe
31.08.2000 08:00 89.504 fdsv.exe
31.08.2000 08:00 80.412 grep.exe
31.08.2000 08:00 28.672 Nircmd.exe
31.08.2000 08:00 98.816 sed.exe
31.08.2000 08:00 49.152 VFind.exe
01.03.2000 09:26 1.440.054 Haka Wallpaper 800x600.bmp
01.03.2000 09:25 2.359.350 Haka Wallpaper 1024x768.bmp
28.02.2000 18:22 129.149 Logo.sys
28.02.2000 18:05 129.078 Logow.sys
28.02.2000 18:04 129.078 Logos.sys
11.06.1999 12:18 28.252 corelpf.lrs
17.11.1998 13:44 328.704 IsUn0407.exe
17.12.1997 18:33 304.128 IsUninst.exe
65 Datei(en), 23.898.731 Bytes
0 Verzeichnis(se), 64.404.221.952 Bytes frei
.
.
.
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 8CED-D108

Verzeichnis von C:\Windows\temp

.
.
.
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 8CED-D108

Verzeichnis von C:\Windows\Downloaded Program Files

23.07.2008 12:45 43.760 crlocx.ocx
26.06.2008 10:25 512 gp.inf
10.06.2008 04:55 1.055 jinstall-6u7.inf
05.06.2008 18:40 660.856 Manager.exe
05.06.2008 18:27 45.056 DownloadManagerV2.ocx
05.06.2008 17:27 346 DownloadManagerV2.inf
24.03.2008 19:33 1.527.056 FP_AX_CAB_INSTALLER.exe
24.03.2008 19:18 247 swflash.inf
20.03.2008 15:10 367 LegitCheckControl.inf
18.09.2006 23:26 65 desktop.ini
10 Datei(en), 2.279.320 Bytes
0 Verzeichnis(se), 64.404.217.856 Bytes frei
.
.
.
Dieser Beitrag wurde am 29.07.2008 um 23:28 Uhr von gela13 editiert.
Seitenanfang Seitenende
30.07.2008, 00:25
Ehrenmitglied
Avatar Argus

Beiträge: 6028
#4 CombiFix entfernen
Start > Ausführen>Kopiere rein ComboFix /U OK

Malwarebytes'Anti-malware darfst du behalten,beim benutzen erst Up-daten
__________
MfG Argus
Seitenanfang Seitenende
30.07.2008, 00:35
...neu hier

Themenstarter

Beiträge: 3
#5 Hallo Arnold!

Wars das?
Wenn ja, dann danke.

LG Georg
Seitenanfang Seitenende
Um auf dieses Thema zu ANTWORTEN
bitte erst » hier kostenlos registrieren!!

Folgende Themen könnten Dich auch interessieren: