Anti Virus 2008 XP |
||
---|---|---|
#0
| ||
29.07.2008, 19:06
...neu hier
Beiträge: 3 |
||
|
||
29.07.2008, 19:54
Ehrenmitglied
Beiträge: 6028 |
||
|
||
29.07.2008, 22:44
...neu hier
Themenstarter Beiträge: 3 |
#3
So das wärs - is ja ganz schön umfangreich (Der Labtop läuft inzwischen wieder einwandfrei...):
Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_CLASSES_ROOT\codecbho.codecplugin (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\codecbho.codecplugin.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{098716a9-0310-4cbe-bd64-b790a9761158} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{098716a9-0310-4cbe-bd64-b790a9761158} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{f4406238-983a-4845-9053-f1d0007fd135} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\codecbho.xmldomdocumenteventssink (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\codecbho.xmldomdocumenteventssink.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d37d6c1a-7ba4-47f4-9bf2-75031e257df6} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{48e92754-2daf-4de4-8385-34f631580e9b} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{a1c23ba2-8f20-4c01-b663-7ff2b3421194} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{84562fca-ee8b-4585-a1d1-eae97b23370e} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\CodecBHO.DLL (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\RichVideoCodec (Trojan.FakeAlert) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphcjg9j0ere7 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphcjg9j0ere7 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Infizierte Verzeichnisse: C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Users\Schorsch\AppData\Roaming\rhcng9j0ere7\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008 (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. Infizierte Dateien: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. C:\Windows\System32\blphcjg9j0ere7.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Windows\System32\phcjg9j0ere7.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Users\Public\Desktop\Antivirus XP 2008.lnk (Rogue.Antivirus) -> Quarantined and deleted successfully. ComboFix 08-07-28.7 - Schorsch 2008-07-29 22:58:09.1 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1031.18.1966 [GMT 2:00] ausgeführt von:: C:\Users\Schorsch\Desktop\ComboFix.exe * Neuer Wiederherstellungspunkt wurde erstellt . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . C:\Windows\msetup C:\Windows\msetup\BASW-00500A10\Install.exe C:\Windows\msetup\BASW-00500A10\install.ini C:\Windows\msetup\BASW-00500A10\setup.exe C:\Windows\msetup\BASW-00500A10\SWDesc.txt C:\Windows\msetup\MSetup.exe C:\Windows\msetup\MSetupLog.log C:\Windows\system32\x64 . ((((((((((((((((((((((( Dateien erstellt von 2008-06-28 bis 2008-07-29 )))))))))))))))))))))))))))))) . 2008-07-29 20:15 . 2008-07-29 20:15 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\Malwarebytes 2008-07-29 20:15 . 2008-07-29 20:15 <DIR> d-------- C:\Users\All Users\Malwarebytes 2008-07-29 20:15 . 2008-07-29 20:15 <DIR> d-------- C:\ProgramData\Malwarebytes 2008-07-29 20:15 . 2008-07-29 20:15 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-07-29 20:15 . 2008-07-23 20:09 38,472 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys 2008-07-29 20:15 . 2008-07-23 20:09 17,144 --a------ C:\Windows\System32\drivers\mbam.sys 2008-07-29 20:11 . 2008-07-29 20:11 <DIR> d-------- C:\Program Files\CCleaner 2008-07-29 13:11 . 2008-07-29 13:11 <DIR> d-------- C:\Program Files\Enigma Software Group 2008-07-28 19:04 . 2008-07-28 19:04 <DIR> d-------- C:\Program Files\MDIviewer 2008-07-28 19:04 . 2002-08-12 14:56 1,706,800 --a------ C:\Windows\System32\GDIPLUS.DLL 2008-07-28 19:04 . 2003-06-18 17:31 1,033,216 --a------ C:\Windows\System32\MSPCORE.DLL 2008-07-28 19:04 . 2003-06-18 17:31 443,904 --a------ C:\Windows\System32\MDIVWCTL.DLL 2008-07-28 19:04 . 2003-06-18 17:31 16,384 --a------ C:\Windows\System32\MSPGIMME.DLL 2008-07-28 16:18 . 2008-07-28 16:18 <DIR> d-------- C:\Program Files\Plus! 2008-07-28 16:18 . 2008-07-28 16:18 <DIR> d-------- C:\Program Files\Catalyst.Net Ltd 2008-07-28 16:18 . 2000-03-01 09:25 2,359,350 --a------ C:\Windows\Haka Wallpaper 1024x768.bmp 2008-07-28 16:18 . 2000-03-01 09:26 1,440,054 --a------ C:\Windows\Haka Wallpaper 800x600.bmp 2008-07-28 16:18 . 2000-02-27 12:02 372,683 --a------ C:\Windows\System32\Haka.scr 2008-07-28 16:18 . 1997-12-17 18:33 304,128 --a------ C:\Windows\IsUninst.exe 2008-07-28 16:18 . 2000-02-28 18:22 129,149 --a------ C:\Windows\Logo.sys 2008-07-28 16:18 . 2000-02-28 18:22 129,149 --a------ C:\Logo.sys 2008-07-28 16:18 . 2000-02-28 18:05 129,078 --a------ C:\Windows\Logow.sys 2008-07-28 16:18 . 2000-02-28 18:04 129,078 --a------ C:\Windows\Logos.sys 2008-07-28 16:04 . 2008-07-28 16:05 <DIR> d-------- C:\Windows\System32\All Blacks dir 2008-07-28 16:04 . 2008-07-28 16:04 203,264 --a------ C:\Windows\System32\All Blacks.scr 2008-07-27 15:10 . 2008-07-27 15:10 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\Apple Computer 2008-07-27 15:10 . 2008-07-27 15:10 <DIR> d-------- C:\Program Files\iTunes 2008-07-27 15:10 . 2008-07-27 15:10 <DIR> d-------- C:\Program Files\iPod 2008-07-27 15:10 . 2008-07-27 15:10 <DIR> d-------- C:\Program Files\Bonjour 2008-07-27 15:09 . 2008-07-27 15:09 <DIR> d-------- C:\Program Files\Common Files\Apple 2008-07-26 23:35 . 2008-07-26 23:35 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2 2008-07-26 23:29 . 2008-07-26 23:29 <DIR> d-------- C:\Users\All Users\SlySoft 2008-07-26 23:29 . 2008-07-26 23:29 <DIR> d-------- C:\ProgramData\SlySoft 2008-07-26 23:27 . 2008-07-26 23:27 <DIR> d-------- C:\Program Files\SlySoft 2008-07-26 19:48 . 2008-07-26 23:25 <DIR> d-------- C:\Users\All Users\Google 2008-07-26 19:48 . 2008-07-26 23:28 <DIR> d-------- C:\Program Files\Google 2008-07-26 19:47 . 2008-07-26 19:47 <DIR> d-------- C:\Program Files\Java 2008-07-26 19:46 . 2008-07-26 19:46 <DIR> d-------- C:\Program Files\Common Files\Java 2008-07-25 15:09 . 2008-07-25 15:09 <DIR> d-------- C:\Program Files\DivX 2008-07-25 15:09 . 2008-07-25 15:09 <DIR> d-------- C:\Program Files\Common Files\PX Storage Engine 2008-07-25 11:38 . 2008-07-25 11:38 <DIR> d-------- C:\Program Files\Hp 2008-07-25 11:36 . 2008-07-25 11:38 <DIR> d-------- C:\Program Files\Hewlett-Packard 2008-07-25 11:35 . 2008-07-25 11:38 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\Hewlett-Packard 2008-07-25 11:33 . 2008-07-25 11:37 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard 2008-07-25 11:31 . 2008-07-25 11:38 80,602 --a------ C:\Windows\HPEasyPrinterCare.his 2008-07-25 11:31 . 2008-07-25 11:31 1,984 --a------ C:\Windows\sounder.his 2008-07-25 11:30 . 2008-07-25 11:30 <DIR> d-------- C:\Temp\Easy Printer Care 2.5.2.0 2008-07-25 11:30 . 2008-07-25 11:30 <DIR> d-------- C:\Temp 2008-07-25 11:16 . 2008-07-25 11:16 52 --a------ C:\Windows\seumain.INI 2008-07-25 11:11 . 2008-07-25 11:11 <DIR> d-------- C:\Users\All Users\Sage 2008-07-25 11:11 . 2008-07-25 11:11 <DIR> d-------- C:\ProgramData\Sage 2008-07-25 11:11 . 2008-07-25 11:11 <DIR> d-------- C:\Program Files\Sage 2008-07-25 11:11 . 2008-07-25 11:21 <DIR> d-------- C:\Program Files\Common Files\Sage KHK Shared 2008-07-25 11:11 . 2008-07-25 11:11 <DIR> d-------- C:\Program Files\Common Files\Sage Group 2008-07-25 11:11 . 1997-07-21 18:30 1,045,776 --a------ C:\Windows\System32\msjet35.dll 2008-07-25 11:11 . 2008-07-25 11:11 570,971 --a------ C:\Windows\System32\PC-Kaufmann Fibu Pro 2007.isu 2008-07-25 11:11 . 2005-04-06 15:13 487,424 --a------ C:\Windows\System32\msvcp70.dll 2008-07-25 11:11 . 1997-06-23 11:06 407,312 --a------ C:\Windows\System32\msrepl35.dll 2008-07-25 11:11 . 2005-04-06 15:13 344,064 --a------ C:\Windows\System32\msvcr70.dll 2008-07-25 11:11 . 1997-06-23 11:06 252,176 --a------ C:\Windows\System32\msrd2x35.dll 2008-07-25 11:11 . 1996-01-24 12:27 244,496 --a------ C:\Windows\System32\VBAR2232.DLL 2008-07-25 11:11 . 1997-06-23 11:06 123,664 --a------ C:\Windows\System32\msjint35.dll 2008-07-25 11:11 . 1997-06-23 11:06 24,848 --a------ C:\Windows\System32\msjter35.dll 2008-07-25 11:11 . 2008-07-25 11:11 0 --a------ C:\Windows\KHKSManC.INI 2008-07-25 11:08 . 1998-11-17 13:44 328,704 --a------ C:\Windows\IsUn0407.exe 2008-07-24 15:46 . 2008-07-24 15:46 <DIR> d-------- C:\Program Files\K-Lite Codec Pack 2008-07-24 15:46 . 2008-07-04 08:34 860,160 --a------ C:\Windows\System32\lameACM.acm 2008-07-24 15:46 . 2004-01-25 18:18 217,088 --a------ C:\Windows\System32\yv12vfw.dll 2008-07-24 15:46 . 2007-09-04 18:56 164,352 --a------ C:\Windows\System32\unrar.dll 2008-07-24 15:46 . 2007-09-21 02:52 118,784 --a------ C:\Windows\System32\ac3acm.acm 2008-07-24 15:46 . 2007-07-10 18:10 547 --a------ C:\Windows\System32\ff_vfw.dll.manifest 2008-07-24 15:46 . 2007-10-03 17:03 414 --a------ C:\Windows\System32\lame_acm.xml 2008-07-24 14:58 . 2008-07-24 15:53 <DIR> d-------- C:\Users\All Users\NOS 2008-07-24 14:58 . 2008-07-24 15:53 <DIR> d-------- C:\ProgramData\NOS 2008-07-24 14:58 . 2008-07-24 15:53 <DIR> d-------- C:\Program Files\NOS 2008-07-24 14:43 . 2008-07-24 14:43 <DIR> d-------- C:\Program Files\Microsoft Silverlight 2008-07-23 22:34 . 2008-07-23 22:34 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\CyberLink 2008-07-23 22:34 . 2008-07-23 22:34 <DIR> d-------- C:\Users\All Users\CyberLink 2008-07-23 22:34 . 2008-07-23 22:34 <DIR> d-------- C:\ProgramData\CyberLink 2008-07-23 15:56 . 2008-07-23 15:56 <DIR> d-------- C:\PerfLogs 2008-07-23 15:01 . 2008-04-23 06:42 428,544 --a------ C:\Windows\System32\EncDec.dll 2008-07-23 15:01 . 2008-04-23 06:42 293,376 --a------ C:\Windows\System32\psisdecd.dll 2008-07-23 15:01 . 2008-04-23 06:41 218,624 --a------ C:\Windows\System32\psisrndr.ax 2008-07-23 15:01 . 2008-01-19 09:33 80,896 --a------ C:\Windows\System32\MSNP.ax 2008-07-23 15:01 . 2008-01-19 09:33 69,632 --a------ C:\Windows\System32\Mpeg2Data.ax 2008-07-23 15:01 . 2008-04-23 06:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax 2008-07-23 13:17 . 2008-01-19 08:06 8,147,456 --a------ C:\Windows\System32\wmploc.DLL 2008-07-23 13:16 . 2008-01-19 09:34 305,152 --a------ C:\Windows\System32\msdelta.dll 2008-07-23 13:16 . 2008-01-19 09:34 258,560 --a------ C:\Windows\System32\dpx.dll 2008-07-23 13:16 . 2008-01-19 09:34 246,784 --a------ C:\Windows\System32\drvstore.dll 2008-07-23 13:16 . 2008-01-19 09:35 35,328 --a------ C:\Windows\System32\mspatcha.dll 2008-07-23 13:00 . 2008-07-23 13:00 <DIR> d-------- C:\Users\All Users\FLEXnet 2008-07-23 13:00 . 2008-07-23 13:00 <DIR> d-------- C:\ProgramData\FLEXnet 2008-07-23 12:49 . 2008-07-23 12:49 <DIR> d-------- C:\Program Files\VistaCodecPack 2008-07-23 12:48 . 2008-07-23 12:48 <DIR> d-------- C:\Users\All Users\VistaCodecs 2008-07-23 12:48 . 2008-07-23 12:48 <DIR> d-------- C:\ProgramData\VistaCodecs 2008-07-23 11:33 . 2007-02-20 16:04 2,463,976 --a------ C:\Windows\System32\NPSWF32.dll 2008-07-23 11:33 . 2007-02-20 16:04 190,696 --a------ C:\Windows\System32\NPSWF32_FlashUtil.exe 2008-07-23 11:12 . 2008-07-23 11:12 <DIR> d-------- C:\Program Files\DAEMON Tools Lite 2008-07-23 11:00 . 2008-07-23 11:00 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\DAEMON Tools 2008-07-23 11:00 . 2008-07-23 11:00 717,296 --a------ C:\Windows\System32\drivers\sptd.sys 2008-07-23 10:27 . 2008-07-24 15:02 <DIR> d-------- C:\Users\All Users\Adobe 2008-07-23 10:27 . 2008-07-24 15:02 <DIR> d-------- C:\Program Files\Common Files\Adobe 2008-07-23 10:20 . 2008-07-23 10:20 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\AdobeUM 2008-07-23 08:21 . 2008-07-23 08:21 <DIR> d-------- C:\Users\All Users\DVD Shrink 2008-07-23 08:21 . 2008-07-23 08:21 <DIR> d-------- C:\ProgramData\DVD Shrink 2008-07-23 08:21 . 2008-07-23 08:21 <DIR> d-------- C:\Program Files\DVD Shrink 2008-07-23 08:15 . 2008-07-23 08:15 <DIR> d-------- C:\Program Files\VideoLAN 2008-07-22 22:03 . 2008-07-22 22:03 <DIR> d-------- C:\Users\Schorsch\AppData\Roaming\Logitech 2008-07-22 22:03 . 2008-07-22 22:03 <DIR> d-------- C:\Users\All Users\LogiShrd 2008-07-22 22:03 . 2008-07-22 22:03 <DIR> d-------- C:\ProgramData\LogiShrd 2008-07-22 22:03 . 2008-07-22 22:03 0 --ah----- C:\Windows\System32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2008-07-22 22:02 . 2008-07-22 22:02 <DIR> d-------- C:\Users\All Users\Logitech 2008-07-22 22:02 . 2008-07-22 22:02 <DIR> d-------- C:\ProgramData\Logitech 2008-07-22 22:02 . 2008-07-22 22:02 <DIR> d-------- C:\Program Files\Logitech 2008-07-22 22:02 . 2008-07-22 22:02 <DIR> d-------- C:\Program Files\Common Files\Logitech 2008-07-22 22:02 . 2007-04-23 04:00 163,840 --a------ C:\Windows\System32\kemutb.dll 2008-07-22 22:02 . 2007-04-23 04:00 135,168 --a------ C:\Windows\System32\KemUtil.dll 2008-07-22 22:02 . 2007-04-23 04:00 110,592 --a------ C:\Windows\System32\KemWnd.dll 2008-07-22 22:02 . 2007-04-23 04:00 69,632 --a------ C:\Windows\System32\KemXML.dll 2008-07-22 21:53 . 2008-07-27 15:10 <DIR> d-------- C:\Users\All Users\Apple Computer 2008-07-22 21:53 . 2008-07-22 21:53 <DIR> d-------- C:\Users\All Users\Apple 2008-07-22 21:53 . 2008-07-27 15:10 <DIR> d-------- C:\ProgramData\Apple Computer 2008-07-22 21:53 . 2008-07-22 21:53 <DIR> d-------- C:\ProgramData\Apple 2008-07-22 21:53 . 2008-07-22 21:53 <DIR> d-------- C:\Program Files\QuickTime . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-29 16:45 51 --sha-w C:\Program Files\Common Files\desktop.ini 2008-07-23 14:06 174 --sha-w C:\Program Files\desktop.ini 2008-07-23 13:58 --------- d-----w C:\Program Files\Windows Sidebar 2008-07-23 13:58 --------- d-----w C:\Program Files\Windows Photo Gallery 2008-07-23 13:58 --------- d-----w C:\Program Files\Windows Mail 2008-07-23 13:58 --------- d-----w C:\Program Files\Windows Journal 2008-07-23 13:58 --------- d-----w C:\Program Files\Windows Collaboration 2008-07-23 13:58 --------- d-----w C:\Program Files\Windows Calendar 2008-07-23 13:57 --------- d-----w C:\Program Files\Windows Defender 2008-07-23 13:14 82,432 ----a-w C:\Windows\System32\axaltocm.dll 2008-07-23 13:14 101,888 ----a-w C:\Windows\System32\ifxcardm.dll 2008-07-22 20:02 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-07-22 18:12 --------- d-----w C:\Program Files\Microsoft.NET 2008-07-22 18:09 --------- d-----w C:\Program Files\Microsoft Small Business 2008-07-22 17:49 --------- d-----w C:\Program Files\Microsoft SQL Server 2008-07-22 12:01 --------- d-----w C:\ProgramData\McAfee 2008-07-22 11:52 --------- d-----w C:\ProgramData\Microsoft Help 2008-07-22 11:08 --------- d-----w C:\Program Files\Intel 2008-07-22 10:53 --------- d-sh--w C:\ProgramData\Vorlagen 2008-07-22 10:53 --------- d-sh--w C:\ProgramData\Startmenü 2008-07-22 10:53 --------- d-sh--w C:\ProgramData\Favoriten 2008-07-22 10:53 --------- d-sh--w C:\ProgramData\Dokumente 2008-07-22 10:53 --------- d-sh--w C:\ProgramData\Anwendungsdaten 2008-07-22 10:53 --------- d--h--r C:\Program Files\Gemeinsame Dateien 2008-06-26 11:06 93,128 ----a-w C:\Windows\System32\ElbyCDIO.dll 2008-06-18 17:52 161,096 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe 2008-06-12 18:36 7,680 ----a-w C:\Windows\System32\ff_vfw.dll 2008-06-12 17:25 966,656 ----a-w C:\Windows\System32\VSFilter.dll 2008-06-11 00:07 524,288 ----a-w C:\Windows\System32\DivXsm.exe 2008-06-11 00:07 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll 2008-06-11 00:04 200,704 ----a-w C:\Windows\System32\ssldivx.dll 2008-06-11 00:04 1,044,480 ----a-w C:\Windows\System32\libdivx.dll 2008-06-06 17:13 106,496 ----a-w C:\Windows\System32\HPSTDSoap.dll 2008-06-06 16:47 49,152 ----a-w C:\Windows\System32\FXCompChannel.dll 2008-06-06 16:47 290,816 ----a-w C:\Windows\System32\WINHTTP5.DLL 2008-06-06 16:47 163,840 ----a-w C:\Windows\System32\hppatusg01.dll 2008-06-06 16:46 126,976 ----a-w C:\Windows\System32\HPDevEnm.dll 2008-05-27 05:21 1,582,592 ----a-w C:\Windows\System32\tquery.dll 2008-05-27 05:21 1,418,240 ----a-w C:\Windows\System32\mssrch.dll 2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\SearchFilterHost.exe 2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\mssitlb.dll 2008-05-27 05:17 754,176 ----a-w C:\Windows\System32\propsys.dll 2008-05-27 05:17 60,416 ----a-w C:\Windows\System32\msscntrs.dll 2008-05-27 05:17 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll 2008-05-27 05:17 34,816 ----a-w C:\Windows\System32\msscb.dll 2008-05-27 05:17 32,768 ----a-w C:\Windows\System32\mssprxy.dll 2008-05-27 05:17 313,344 ----a-w C:\Windows\System32\thawbrkr.dll 2008-05-27 05:17 301,568 ----a-w C:\Windows\System32\srchadmin.dll 2008-05-27 05:17 194,560 ----a-w C:\Windows\System32\offfilt.dll 2008-05-27 05:17 143,872 ----a-w C:\Windows\System32\korwbrkr.dll 2008-05-27 05:17 11,776 ----a-w C:\Windows\System32\msshooks.dll 2008-05-27 05:17 1,671,680 ----a-w C:\Windows\System32\chsbrkr.dll 2008-05-27 04:59 18,904 ----a-w C:\Windows\System32\StructuredQuerySchemaTrivial.bin 2008-05-27 04:59 106,605 ----a-w C:\Windows\System32\StructuredQuerySchema.bin 2008-05-22 22:18 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll 2008-05-10 03:35 564,736 ----a-w C:\Windows\System32\emdmgmt.dll 2008-05-08 21:59 90,112 ----a-w C:\Windows\System32\wshext.dll 2008-05-08 21:59 430,080 ----a-w C:\Windows\System32\vbscript.dll 2008-05-08 21:59 180,224 ----a-w C:\Windows\System32\scrobj.dll 2008-05-08 21:59 172,032 ----a-w C:\Windows\System32\scrrun.dll 2008-05-08 21:59 155,648 ----a-w C:\Windows\System32\wscript.exe 2008-05-08 21:58 135,168 ----a-w C:\Windows\System32\cscript.exe . (((((((((((((((((((((((((((( Autostart Punkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 09:33 1233920] "DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-07-17 14:20 490952] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 09:33 202240] "AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe" [2008-07-21 14:15 2157504] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-07 04:17 839680] "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 08:10 56928] "LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 15:55 54832] "Play AVStation TV Scheduler"="C:\Program Files\Samsung\Play AVStation\TvScheduler.exe" [2007-01-09 04:09 73728] "ViivMonitor"="C:\Program Files\Intel\Intel Media Share Software\ViivMonitor.exe" [2007-03-10 13:41 69632] "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-11 20:13 141848] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-11 20:13 166424] "Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-11 20:13 133656] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672] "KnexStarter"="C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\Appinterfaces\HPDeviceService.exe" [2008-06-06 19:13 73728] "RunTasktray"="C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe" [2008-06-06 18:46 69120] "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784] "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064] "RtHDVCpl"="RtHDVCpl.exe" [2007-03-15 01:50 4399104 C:\Windows\RtHDVCpl.exe] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\Windows\KHALMNPR.Exe] "Skytel"="Skytel.exe" [2007-03-14 04:55 1822720 C:\Windows\SkyTel.exe] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-12-20 05:27:40 719664] Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-07-22 22:02:11 692224] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "NoHotStart"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.divxa32"= divxa32.acm [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List] "C:\\Program Files\\Hewlett-Packard\\HP Easy Printer Care\\HPPRun.exe"= C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe:*:Enabled:HP Easy Printer Care HPPRun [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{31C53CE9-ACCD-411D-A50F-D84C6C392D56}"= UDP:C:\Program Files\Intel\Intel Media Share Software\IMSS.exe:Intel® Media Share Software "{73460D40-0364-425C-8F64-8F2683788668}"= TCP:C:\Program Files\Intel\Intel Media Share Software\IMSS.exe:Intel® Media Share Software "{5EB2C1DA-FF07-4057-B8B0-C95663040888}"= UDP:C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe:Intel® Media Share Synch Service "{4EAADDCE-5C1A-4F85-A3AC-11EF0967D747}"= TCP:C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe:Intel® Media Share Synch Service "TCP Query User{B378C651-678C-4A99-8616-56BB6BAB87F6}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer "UDP Query User{71A6EFF2-754D-4399-85E2-703AD1825814}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer "{D22CD4B1-DEE7-4DC1-B698-A3EC407D07F1}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour "{4441814C-3F8E-4EA0-BBFD-049123922827}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour "{95B10FD1-BA85-40CA-81E5-5C5721EC8CF4}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{7C9F8565-DB11-4154-86A7-6830CC341F27}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List] "C:\\Program Files\\Hewlett-Packard\\HP Easy Printer Care\\HPPRun.exe"= C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe:*:Enabled:HP Easy Printer Care HPPRun R2 IMSSync;Intel® Media Share Synch Service;C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe [2007-03-10 13:40] R2 KMDFMEMIO;SAMSUNG Kernel Driver;C:\Windows\system32\DRIVERS\kmdfmemio.sys [2006-11-14 02:11] R3 btwaudio;Bluetooth-Audiogerät;C:\Windows\system32\drivers\btwaudio.sys [2006-12-20 21:08] R3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2006-12-20 21:04] R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2006-12-20 21:07] R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-06 09:51] S3 NETw2v32;Intel(R) PRO/Wireless 2915ABG Network Connection Driver for Windows Vista;C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 09:30] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 *Newly Created Service* - CATCHME *Newly Created Service* - PROCEXP90 . Inhalt des "geplante Tasks" Ordners 2008-07-29 C:\Windows\Tasks\User_Feed_Synchronization-{71EDB7DA-0C0C-4FDD-ADE9-E85DA199D6BF}.job - C:\Windows\system32\msfeedssync.exe [2008-01-19 09:33] . . ------- Zusätzlicher Scan ------- . R0 -: HKCU-Main,Start Page = about:blank R1 -: HKCU-Internet Settings,ProxyOverride = *.local O8 -: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 -: Nach Microsoft &Excel exportieren - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 -: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O18 -: Handler: HPDCS - {ba135f49-a12c-4e26-a2c4-6ea945999072} - C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\APP\hpdcsapp.dll O18 -: Handler: hppfile - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll O18 -: Handler: hppsam - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll O18 -: Handler: hppzip - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll O16 -: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab C:\Windows\Downloaded Program Files\DownloadManagerV2.inf C:\Windows\Downloaded Program Files\Manager.exe C:\Windows\Downloaded Program Files\DownloadManagerV2.ocx ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-29 23:01:13 Windows 6.0.6001 Service Pack 1 NTFS Scanne versteckte Prozesse... Scanne versteckte Autostart Einträge... Scanne versteckte Dateien... Scan erfolgreich abgeschlossen versteckte Dateien: 0 ************************************************************************** . Zeit der Fertigstellung: 2008-07-29 23:02:44 ComboFix-quarantined-files.txt 2008-07-29 21:02:27 Pre-Run: 10 Verzeichnis(se), 61,958,242,304 Bytes frei Post-Run: 17 Verzeichnis(se), 64,732,028,928 Bytes frei 313 --- E O F --- 2008-07-26 21:35:45 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:20:56, on 29.07.2008 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Intel\Intel Media Share Software\Viivmonitor.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Windows\System32\igfxtray.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\AppInterfaces\HPDeviceService.exe C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\AppInterfaces\HPDeviceHost.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE C:\Program Files\Windows Mail\WinMail.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\NOTEPAD.EXE C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe C:\Users\Schorsch\Desktop\HJT.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" O4 - HKLM\..\Run: [Play AVStation TV Scheduler] C:\Program Files\Samsung\Play AVStation\TvScheduler.exe O4 - HKLM\..\Run: [ViivMonitor] C:\Program Files\Intel\Intel Media Share Software\ViivMonitor.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [Skytel] Skytel.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [KnexStarter] C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\Appinterfaces\HPDeviceService.exe O4 - HKLM\..\Run: [RunTasktray] "C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe" --regkeypath=Software\Hewlett-Packard\HP Easy Printer Care\HPPRun --valuename=InstallTTM O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe O4 - Global Startup: BTTray.lnk = ? O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O13 - Gopher Prefix: O15 - Trusted Zone: http://*.hp.com (HKLM) O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1217094401155&h=f65e49af411fb66e0b6c7d6ba9f4c1bd/&filename=jinstall-6u7-windows-i586-jc.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx O18 - Protocol: HPDCS - {BA135F49-A12C-4E26-A2C4-6EA945999072} - C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\APP\hpdcsapp.dll O18 - Protocol: hppfile - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll O18 - Protocol: hppsam - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll O18 - Protocol: hppzip - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe O23 - Service: Avira AntiVir Personal – Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Intel® Media Share Synch Service (IMSSync) - Intel® Corporation - C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe -- End of file - 8879 bytes 32 Bit HP CIO Components Installer Adobe Flash Player 9 ActiveX Adobe Flash Player ActiveX Adobe Reader 9 - Deutsch Agere Systems HDA Modem All Blacks Screen Saver AnyDVD Apple Mobile Device Support Apple Software Update Avira AntiVir Personal – Free Antivirus AVStation Now Bonjour CCleaner (remove only) CDDRV_Installer CorelDRAW Graphics Suite 11 DivX Codec DivX Converter DivX Player DivX Web Player DVD Shrink 3.2 DVD Suite Easy Battery Manager Easy Burning (remove only) Easy Display Manager Easy Network Manager 3.0 Easy SpeedUp Manager Haka Theme HP Easy Printer Care HP Easy Printer Care HP Printer Settings Tools HP Printer Usage Report HP Proactive Services HP Update imagine digital freedom - Samsung Intel(R) Graphics Media Accelerator Driver Intel(R) PROSet/Wireless Software Intel® Media-Share-Software iTunes Java(TM) 6 Update 7 KhalInstallWrapper K-Lite Codec Pack 4.0.0 (Full) Komponenten der Betriebssystemkommunikation Komponenten der Ereigniskommunikation Komponenten der Gerätedatenkommunikation Komponenten der Kernkommunikation Logitech SetPoint Malwarebytes' Anti-Malware MDI viewer 0.1 mDriver Microsoft Office 2003 Web Components Microsoft Office 2007 Primary Interop Assemblies Microsoft Office Professional Edition 2003 Microsoft Office Small Business Connectivity Components Microsoft Silverlight Microsoft SQL Server Native Client Microsoft SQL Server VSS Writer Microsoft Visual C++ 2005 Redistributable MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 Parser and SDK PC-Kaufmann Fibu Pro Vollversion 2007 PhotoNow! 1.0 Play AVStation PlayCamera PowerDVD Q45 Q46 User Guide QuickTime Realtek High Definition Audio Driver Samsung Magic Doctor Samsung Recovery Solution II Samsung Update Plus Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Synaptics Pointing Device Driver Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) VideoLAN VLC media player 0.8.6i Vista Codec Package WIDCOMM Bluetooth Software . . Bitte nur die Eintraege der letzten 3 Monate pro Ordner posten . . Volume in Laufwerk C: hat keine Bezeichnung. Volumeseriennummer: 8CED-D108 Verzeichnis von C:\Windows\system32 29.07.2008 23:17 590.082 perfh009.dat 29.07.2008 23:17 102.094 perfc009.dat 29.07.2008 23:17 621.942 perfh007.dat 29.07.2008 23:17 123.666 perfc007.dat 29.07.2008 23:17 1.427.210 PerfStringBackup.INI 29.07.2008 23:10 3.296 7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 29.07.2008 23:10 3.296 7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 29.07.2008 18:32 4.144 scan.log 28.07.2008 16:04 203.264 All Blacks.scr 26.07.2008 19:47 6.894 jupdate-1.6.0_07-b06.log 26.07.2008 12:47 1.771.864 FNTCACHE.DAT 25.07.2008 11:11 570.971 PC-Kaufmann Fibu Pro 2007.isu 23.07.2008 15:14 101.888 ifxcardm.dll 23.07.2008 15:14 82.432 axaltocm.dll 22.07.2008 18:14 11.580.416 shell32.dll 22.07.2008 18:10 1.793.536 NlsLexicons0045.dll 22.07.2008 18:10 1.808.896 NlsLexicons0046.dll 22.07.2008 18:10 1.411.072 NlsLexicons0047.dll 22.07.2008 18:10 1.558.016 NlsLexicons0049.dll 22.07.2008 18:10 1.236.992 NlsLexicons0020.dll 22.07.2008 18:10 1.782.272 NlsLexicons0039.dll 22.07.2008 18:10 2.136.064 NlsLexicons0021.dll 22.07.2008 18:10 5.499.904 NlsLexicons0022.dll 22.07.2008 18:10 7.964.672 NlsLexicons0024.dll 22.07.2008 18:10 5.791.232 NlsLexicons0026.dll 22.07.2008 18:10 6.224.896 NlsLexicons0027.dll 22.07.2008 18:10 4.175.872 NlsLexicons0010.dll 22.07.2008 18:10 2.466.816 NlsLexicons0011.dll 22.07.2008 18:10 4.981.248 NlsLexicons0013.dll 22.07.2008 18:10 3.331.072 NlsLexicons0018.dll 22.07.2008 18:10 6.781.440 NlsLexicons0019.dll 22.07.2008 18:10 11.722.752 NlsLexicons0001.dll 22.07.2008 18:10 4.164.096 NlsLexicons0002.dll 22.07.2008 18:10 1.452.544 NlsLexicons0003.dll 22.07.2008 18:10 12.240.896 NlsLexicons0007.dll 22.07.2008 18:10 2.644.480 NlsLexicons0009.dll 22.07.2008 18:10 3.419.136 NlsLexicons004a.dll 22.07.2008 18:10 1.702.912 NlsLexicons004b.dll 22.07.2008 18:10 4.093.440 NlsLexicons004c.dll 22.07.2008 18:10 1.972.736 NlsLexicons004e.dll 22.07.2008 18:10 4.045.824 NlsLexicons003e.dll 22.07.2008 18:10 4.096 NlsLexicons002a.dll 22.07.2008 18:10 6.014.976 NlsLexicons001a.dll 22.07.2008 18:10 6.585.856 NlsLexicons001b.dll 22.07.2008 18:10 6.346.240 NlsLexicons001d.dll 22.07.2008 18:10 9.892.864 NlsLexicons000a.dll 22.07.2008 18:10 6.237.696 NlsLexicons000c.dll 22.07.2008 18:10 1.722.368 NlsLexicons000d.dll 22.07.2008 18:10 5.654.528 NlsLexicons000f.dll 22.07.2008 18:10 4.616.192 NlsLexicons0414.dll 22.07.2008 18:10 5.090.816 NlsLexicons0416.dll 22.07.2008 18:10 5.031.936 NlsLexicons0816.dll 22.07.2008 18:10 7.042.560 NlsLexicons081a.dll 22.07.2008 18:10 5.071.872 NlsModels0011.dll 22.07.2008 18:10 3.104.768 NlsData0045.dll 22.07.2008 18:10 3.104.768 NlsData0046.dll 22.07.2008 18:10 3.104.768 NlsData0047.dll 22.07.2008 18:10 3.104.768 NlsData0049.dll 22.07.2008 18:10 3.104.768 NlsData0039.dll 22.07.2008 18:10 3.104.768 NlsData0020.dll 22.07.2008 18:10 1.801.216 NlsData0021.dll 22.07.2008 18:10 1.801.216 NlsData0022.dll 22.07.2008 18:10 1.965.056 NlsData0024.dll 22.07.2008 18:10 1.965.056 NlsData0026.dll 22.07.2008 18:10 1.966.592 NlsData0027.dll 22.07.2008 18:10 4.495.360 NlsData0010.dll 22.07.2008 18:10 2.657.280 NlsData0011.dll 22.07.2008 18:10 3.466.752 NlsData0013.dll 22.07.2008 18:10 1.965.056 NlsData0018.dll 22.07.2008 18:10 1.523.712 NlsData0000.dll 22.07.2008 18:10 4.497.408 NlsData0019.dll 22.07.2008 18:10 2.599.936 NlsData0001.dll 22.07.2008 18:10 1.965.056 NlsData0002.dll 22.07.2008 18:10 1.965.056 NlsData0003.dll 22.07.2008 18:10 2.243.072 NlsData0007.dll 22.07.2008 18:10 4.875.776 NlsData0009.dll 22.07.2008 18:10 3.104.768 NlsData004a.dll 22.07.2008 18:10 3.104.768 NlsData004b.dll 22.07.2008 18:10 3.104.768 NlsData004c.dll 22.07.2008 18:10 3.104.768 NlsData004e.dll 22.07.2008 18:10 1.801.216 NlsData003e.dll 22.07.2008 18:10 1.801.216 NlsData002a.dll 22.07.2008 18:10 1.965.056 NlsData001a.dll 22.07.2008 18:10 1.965.056 NlsData001b.dll 22.07.2008 18:10 4.495.360 NlsData001d.dll 22.07.2008 18:10 9.847.296 NlsData000a.dll 22.07.2008 18:10 2.643.456 NlsData000c.dll 22.07.2008 18:10 2.342.912 NlsData000d.dll 22.07.2008 18:10 1.965.056 NlsData000f.dll 22.07.2008 18:10 4.495.360 NlsData0414.dll 22.07.2008 18:10 4.495.360 NlsData0416.dll 22.07.2008 18:10 801.280 NaturalLanguage6.dll 22.07.2008 18:10 4.495.360 NlsData0816.dll 22.07.2008 18:10 1.965.056 NlsData081a.dll 22.07.2008 18:10 6.917.120 NlsLexicons0c1a.dll 22.07.2008 18:10 1.965.056 NlsData0c1a.dll 22.07.2008 18:09 181.760 fsquirt.exe 22.07.2008 18:08 6.656 kbd106n.dll 22.07.2008 18:07 927.288 winresume.exe 22.07.2008 18:07 988.216 winload.exe 22.07.2008 18:07 40.960 srclient.dll 22.07.2008 18:07 318.464 rstrui.exe 22.07.2008 18:07 378.368 srcore.dll 22.07.2008 18:07 14.848 srdelayed.exe 22.07.2008 18:07 19.000 kd1394.dll 22.07.2008 18:07 46.592 setbcdlocale.dll 22.07.2008 18:07 615.992 ci.dll 22.07.2008 18:06 2.032.128 win32k.sys 22.07.2008 18:06 295.936 gdi32.dll 22.07.2008 18:05 14.848 wshrm.dll 22.07.2008 18:02 1.314.816 quartz.dll 22.07.2008 18:01 826.880 wininet.dll 22.07.2008 18:01 28.160 jsproxy.dll 22.07.2008 18:01 3.578.368 mshtml.dll 22.07.2008 18:01 1.383.424 mshtml.tlb 22.07.2008 18:01 671.232 mstime.dll 22.07.2008 18:01 1.166.336 urlmon.dll 04.07.2008 08:34 860.160 lameACM.acm 26.06.2008 13:06 93.128 ElbyCDIO.dll 25.06.2008 09:15 17.972.344 mrt.exe 18.06.2008 19:52 161.096 DivXCodecVersionChecker.exe 12.06.2008 20:36 7.680 ff_vfw.dll 12.06.2008 19:25 966.656 VSFilter.dll 11.06.2008 02:07 524.288 DivXsm.exe 11.06.2008 02:07 10.152 dsm_de.qm 11.06.2008 02:07 4.816 divxsm.tlb 11.06.2008 02:07 3.596.288 qt-dx331.dll 11.06.2008 02:04 200.704 ssldivx.dll 11.06.2008 02:04 1.044.480 libdivx.dll 11.06.2008 02:03 81.920 dpl100.dll 11.06.2008 02:03 196.608 dtu100.dll 11.06.2008 02:03 416 dpl100.dll.manifest 11.06.2008 02:03 416 dtu100.dll.manifest 11.06.2008 02:03 8.523 dpude.qm 11.06.2008 02:03 3.051 dtu_de.qm 11.06.2008 02:03 294.912 dpu11.dll 11.06.2008 02:03 294.912 dpu10.dll 11.06.2008 02:03 344.064 dpus11.dll 11.06.2008 02:03 57.344 dpv11.dll 11.06.2008 02:03 593.920 dpuGUI11.dll 11.06.2008 02:03 53.248 dpuGUI10.dll 11.06.2008 02:03 802.816 divx_xx11.dll 11.06.2008 02:03 823.296 divx_xx0c.dll 11.06.2008 02:03 815.104 divx_xx0a.dll 11.06.2008 02:03 823.296 divx_xx07.dll 11.06.2008 02:03 683.520 DivX.dll 11.06.2008 02:03 630.784 divxdec.ax 10.06.2008 02:32 139.264 javaws.exe 10.06.2008 01:21 135.168 javaw.exe 10.06.2008 01:21 135.168 java.exe 06.06.2008 19:13 106.496 HPSTDSoap.dll 06.06.2008 18:47 290.816 WINHTTP5.DLL 06.06.2008 18:47 163.840 hppatusg01.dll 06.06.2008 18:47 49.152 FXCompChannel.dll 06.06.2008 18:46 126.976 HPDevEnm.dll 06.06.2008 18:45 516.832 capicom.dll 27.05.2008 10:50 57.344 QuickTime.qts 27.05.2008 10:50 90.112 QuickTimeVR.qtx 27.05.2008 07:21 1.418.240 mssrch.dll 27.05.2008 07:21 1.582.592 tquery.dll 27.05.2008 07:18 670.208 mssvp.dll 27.05.2008 07:18 203.776 mssphtb.dll 27.05.2008 07:18 439.808 SearchIndexer.exe 27.05.2008 07:18 44.032 msstrc.dll 27.05.2008 07:18 29.184 wsepno.dll 27.05.2008 07:18 40.448 mimefilt.dll 27.05.2008 07:18 231.936 msshsq.dll 27.05.2008 07:18 56.320 xmlfilter.dll 27.05.2008 07:18 136.704 nlhtml.dll 27.05.2008 07:18 38.400 rtffilt.dll 27.05.2008 07:18 350.208 mssph.dll 27.05.2008 07:18 184.832 SearchProtocolHost.exe 27.05.2008 07:18 71.680 propdefs.dll 27.05.2008 07:17 87.552 SearchFilterHost.exe 27.05.2008 07:17 754.176 propsys.dll 27.05.2008 07:17 34.816 msscb.dll 27.05.2008 07:17 11.776 msshooks.dll 27.05.2008 07:17 301.568 srchadmin.dll 27.05.2008 07:17 32.768 mssprxy.dll 27.05.2008 07:17 87.552 mssitlb.dll 27.05.2008 07:17 60.416 msscntrs.dll 27.05.2008 07:17 194.560 offfilt.dll 27.05.2008 07:17 6.103.040 chtbrkr.dll 27.05.2008 07:17 143.872 korwbrkr.dll 27.05.2008 07:17 313.344 thawbrkr.dll 27.05.2008 07:17 1.671.680 chsbrkr.dll 27.05.2008 06:59 18.904 StructuredQuerySchemaTrivial.bin 27.05.2008 06:59 106.605 StructuredQuerySchema.bin 23.05.2008 00:18 12.288 DivXWMPExtType.dll 10.05.2008 05:35 564.736 emdmgmt.dll 08.05.2008 23:59 90.112 wshext.dll 08.05.2008 23:59 430.080 vbscript.dll 08.05.2008 23:59 172.032 scrrun.dll 08.05.2008 23:59 180.224 scrobj.dll 08.05.2008 23:59 512.000 jscript.dll 08.05.2008 23:59 155.648 wscript.exe 08.05.2008 23:58 135.168 cscript.exe 08.05.2008 23:58 135.168 wshom.ocx . . Volume in Laufwerk C: hat keine Bezeichnung. Volumeseriennummer: 8CED-D108 Verzeichnis von C:\Users\Schorsch\AppData\Local\Temp\Low 29.07.2008 23:24 131.130 datfind.txt 1 Datei(en), 131.130 Bytes 0 Verzeichnis(se), 64.404.221.952 Bytes frei . . . Volume in Laufwerk C: hat keine Bezeichnung. Volumeseriennummer: 8CED-D108 Verzeichnis von C:\Windows 29.07.2008 23:13 1.654.001 WindowsUpdate.log 29.07.2008 23:10 67.584 bootstat.dat 29.07.2008 23:10 328 PFRO.log 29.07.2008 23:09 12 bthservsdp.dat 29.07.2008 23:02 53.248 PSEXESVC.EXE 29.07.2008 23:01 215 system.ini 25.07.2008 11:38 80.602 HPEasyPrinterCare.his 25.07.2008 11:31 1.984 sounder.his 25.07.2008 11:16 52 seumain.INI 25.07.2008 11:11 0 KHKSManC.INI 23.07.2008 16:06 749 WindowsShell.Manifest 22.07.2008 21:04 240 win.ini 22.07.2008 17:38 400 ODBC.INI 19.01.2008 09:33 134.656 regedit.exe 19.01.2008 09:33 151.040 notepad.exe 19.01.2008 09:33 498.176 HelpPane.exe 19.01.2008 09:33 13.312 fveupdate.exe 19.01.2008 09:33 2.927.104 explorer.exe 19.01.2008 09:33 58.880 bfsvc.exe 27.09.2007 07:41 10 Csup.txt 27.09.2007 06:37 319.456 DIFxAPI.dll 27.09.2007 06:36 315.392 HideWin.exe 27.09.2007 05:36 49.152 CBS.log.perf 27.09.2007 05:36 2.162.688 CBS.log.dpx 11.04.2007 15:32 56.080 KHALMNPR.Exe 15.03.2007 01:50 4.399.104 RtHDVCpl.exe 14.03.2007 04:55 1.822.720 SkyTel.exe 05.02.2007 20:05 38 AviSplitter.INI 31.01.2007 03:28 221.184 SetDisplayResolution.exe 23.01.2007 21:32 3.214 SetDisplayResolution.xml 16.01.2007 20:39 1.191.936 RtlUpd.exe 13.01.2007 02:54 520.192 RtlExUpd.dll 12.12.2006 17:38 319.488 SMCM.exe 03.12.2006 10:00 172.032 SMCM.dll 02.11.2006 14:35 316.640 WMSysPr9.prx 02.11.2006 14:34 49.680 twunk_16.exe 02.11.2006 14:34 50.688 twain_32.dll 02.11.2006 14:34 31.232 twunk_32.exe 02.11.2006 14:34 94.784 twain.dll 02.11.2006 11:45 9.216 winhlp32.exe 02.11.2006 11:45 14.848 hh.exe 02.11.2006 09:46 43.131 mib.bin 26.10.2006 23:08 50.752 agrsmdel.exe 19.09.2006 13:41 8.328 HomePremium.xml 18.09.2006 23:43 707 _default.pif 18.09.2006 23:43 256.192 winhelp.exe 18.09.2006 23:30 1.405 msdfmap.ini 13.09.2006 07:21 2.438 ebm.reg 31.08.2000 08:00 136.704 swsc.exe 31.08.2000 08:00 212.480 swxcacls.exe 31.08.2000 08:00 161.792 swreg.exe 31.08.2000 08:00 68.096 zip.exe 31.08.2000 08:00 89.504 fdsv.exe 31.08.2000 08:00 80.412 grep.exe 31.08.2000 08:00 28.672 Nircmd.exe 31.08.2000 08:00 98.816 sed.exe 31.08.2000 08:00 49.152 VFind.exe 01.03.2000 09:26 1.440.054 Haka Wallpaper 800x600.bmp 01.03.2000 09:25 2.359.350 Haka Wallpaper 1024x768.bmp 28.02.2000 18:22 129.149 Logo.sys 28.02.2000 18:05 129.078 Logow.sys 28.02.2000 18:04 129.078 Logos.sys 11.06.1999 12:18 28.252 corelpf.lrs 17.11.1998 13:44 328.704 IsUn0407.exe 17.12.1997 18:33 304.128 IsUninst.exe 65 Datei(en), 23.898.731 Bytes 0 Verzeichnis(se), 64.404.221.952 Bytes frei . . . Volume in Laufwerk C: hat keine Bezeichnung. Volumeseriennummer: 8CED-D108 Verzeichnis von C:\Windows\temp . . . Volume in Laufwerk C: hat keine Bezeichnung. Volumeseriennummer: 8CED-D108 Verzeichnis von C:\Windows\Downloaded Program Files 23.07.2008 12:45 43.760 crlocx.ocx 26.06.2008 10:25 512 gp.inf 10.06.2008 04:55 1.055 jinstall-6u7.inf 05.06.2008 18:40 660.856 Manager.exe 05.06.2008 18:27 45.056 DownloadManagerV2.ocx 05.06.2008 17:27 346 DownloadManagerV2.inf 24.03.2008 19:33 1.527.056 FP_AX_CAB_INSTALLER.exe 24.03.2008 19:18 247 swflash.inf 20.03.2008 15:10 367 LegitCheckControl.inf 18.09.2006 23:26 65 desktop.ini 10 Datei(en), 2.279.320 Bytes 0 Verzeichnis(se), 64.404.217.856 Bytes frei . . . Dieser Beitrag wurde am 29.07.2008 um 23:28 Uhr von gela13 editiert.
|
|
|
||
30.07.2008, 00:25
Ehrenmitglied
Beiträge: 6028 |
#4
CombiFix entfernen
Start > Ausführen>Kopiere rein ComboFix /U OK Malwarebytes'Anti-malware darfst du behalten,beim benutzen erst Up-daten __________ MfG Argus |
|
|
||
30.07.2008, 00:35
...neu hier
Themenstarter Beiträge: 3 |
||
|
||
Hab mir heute was eingfangen. Nennt sich "Antivirus 2008 XP". Habe bereits einiges gemacht aber es bleibt der Desktophintergrund: "Warning Spyware detected on your computer! install an antivirus or spyware ..."
Bitte um Hilfe
Georg
p.s. habe windows vista home premium