Habe alles so gemacht wie Du mir es beschrieben hast. Hier die ganzen Textdateien:
Hier die System32
Verzeichnis von C:\WINDOWS\SYSTEM32
15.11.2005 13:13 5.384 ncompat.tlb
15.11.2005 10:19 5.120 msvol.tlb
15.11.2005 10:14 31.767 vsconfig.xml
15.11.2005 10:13 16.384 hp8509.tmp
15.11.2005 09:01 98.304 svchosts.dll
15.11.2005 09:01 4.286 ot.ico
15.11.2005 09:01 4.286 ts.ico
15.11.2005 09:01 9.748 mssearchnet.exe
15.11.2005 09:01 13.398 nvctrl.exe
15.11.2005 08:57 114.176 FNTCACHE.DAT
14.11.2005 12:34 10.774 mscornet.exe
14.11.2005 10:54 4.212 zllictbl.dat
14.11.2005 10:49 49.152 cdrtc.dll
14.11.2005 10:49 45.056 cdral.dll
14.11.2005 10:49 401.462 Msvcp60.dll
14.11.2005 10:16 2.822 $winnt$.inf
14.11.2005 10:12 910 AUTOEXEC.NT
14.11.2005 10:12 286.992 migicons.exe
14.11.2005 10:08 2.951 CONFIG.NT
14.11.2005 10:08 16.832 amcompat.tlb
14.11.2005 10:08 23.392 nscompat.tlb
14.11.2005 10:07 38.036 perfc009.dat
14.11.2005 10:07 300.378 perfh009.dat
14.11.2005 10:07 289.156 perfh007.dat
14.11.2005 10:07 46.232 perfc007.dat
14.11.2005 10:07 271 desktop.ini
14.11.2005 10:07 21.817 folder.htt
14.11.2005 10:06 525 mapisvc.inf
14.11.2005 10:06 15.076 emptyregdb.dat
14.11.2005 09:58 11.680 $WINNT$.PNF
14.11.2005 09:54 303.354 PerfStringBackup_001.INI
14.11.2005 09:54 303.354 PerfStringBackup.INI
29.08.2005 19:09 71.424 zlcommdb.dll
29.08.2005 19:09 79.616 zlcomm.dll
29.08.2005 19:09 100.096 vsxml.dll
29.08.2005 19:09 382.720 vsutil.dll
29.08.2005 19:09 71.424 vsregexp.dll
29.08.2005 19:08 227.072 vspubapi.dll
29.08.2005 19:08 104.192 vsmonapi.dll
29.08.2005 19:08 141.056 vsinit.dll
29.08.2005 19:08 368.256 vsdatant.sys
29.08.2005 19:08 83.712 vsdata.dll
29.08.2005 18:52 54.960 vsutil_loc0407.dll
Hier die SystemTemp!
Verzeichnis von C:\
15.11.2005 13:16 0 systemtemp.txt
15.11.2005 13:15 88.095 system32.txt
15.11.2005 10:12 805.306.368 pagefile.sys
14.11.2005 12:32 9.141 eied_s7.cab
14.11.2005 11:22 2.602 wsinst.log
14.11.2005 10:12 10 BOOT.DOS
14.11.2005 10:12 27 CONFIG.SYS
14.11.2005 10:12 256 AUTOEXEC.BAT
14.11.2005 10:12 79 MSDOS.SYS
14.11.2005 10:02 196 boot.ini
14.11.2005 09:46 512 BOOTSECT.DOS
14.11.2005 09:30 0 CONFIG.BAK
14.11.2005 09:20 208.928 CLASSES.1ST
08.06.2000 17:00 110.592 IO.SYS
Hier die System
Verzeichnis von C:\WINDOWS
15.11.2005 10:23 1.716 win.ini
15.11.2005 10:11 32.477 SchedLog.Txt
15.11.2005 10:10 1.196.736 ShellIconCache
14.11.2005 13:55 0 s
14.11.2005 13:46 1.015 ODBC.INI
14.11.2005 13:46 59 vbaddin.ini
14.11.2005 11:36 20.784 hpoins01.dat
14.11.2005 11:35 5.538 ~TempMui.inf
14.11.2005 11:35 4.161 ODBCINST.INI
14.11.2005 11:00 356 ULead32.ini
14.11.2005 10:49 57.344 uneng.exe
14.11.2005 10:48 316.640 WMSysPr9.prx
14.11.2005 10:13 356 LnkStub.dat
14.11.2005 10:12 412 system.ini
14.11.2005 10:08 0 control.ini
14.11.2005 10:07 271 desktop.ini
14.11.2005 10:07 21.817 folder.htt
14.11.2005 10:05 36 vb.ini
14.11.2005 09:58 41 ModemDet.txt
14.11.2005 09:45 5.623 upgrade.txt
14.11.2005 09:44 281 dead.ini
14.11.2005 09:44 60 POWERPNT.INI
14.11.2005 09:44 54 WAVEMIX.INI
14.11.2005 09:28 288.562 WMSysPrx.prx
14.11.2005 09:28 225 TELEPHON.INI
14.11.2005 09:28 514 ModemCpl.txt
14.11.2005 09:28 176.160 HWINFO.DAT
14.11.2005 09:26 86 SYSTEM.CB
14.11.2005 09:25 0 Sti_Trace.log
14.11.2005 09:25 0 progman.ini
14.11.2005 09:24 3.456 ttfCache
14.11.2005 09:20 26 MSOFFICE.INI
14.11.2005 09:20 28 QTW.INI
14.11.2005 09:20 19.131 SETVER.EXE
22.08.2004 17:04 69.120 daemon.dll
16.06.2004 08:39 16.633 hpomdl01.dat
08.06.2000 17:00 1.185 HLPLOGO.GIF
Hier die SYS
Verzeichnis von C:\
15.11.2005 13:17 0 sys.txt
15.11.2005 13:17 5.649 system1.txt
15.11.2005 13:16 5.649 system.txt
15.11.2005 13:16 1.038 systemtemp1.txt
15.11.2005 13:16 1.038 systemtemp.txt
15.11.2005 13:15 88.095 system32.txt
15.11.2005 10:12 805.306.368 pagefile.sys
14.11.2005 12:32 9.141 eied_s7.cab
14.11.2005 11:22 2.602 wsinst.log
14.11.2005 10:12 10 BOOT.DOS
14.11.2005 10:12 256 AUTOEXEC.BAT
14.11.2005 10:12 27 CONFIG.SYS
14.11.2005 10:12 79 MSDOS.SYS
14.11.2005 10:02 196 boot.ini
14.11.2005 09:46 512 BOOTSECT.DOS
14.11.2005 09:30 0 CONFIG.BAK
14.11.2005 09:20 208.928 CLASSES.1ST
08.06.2000 17:00 110.592 IO.SYS
Und das Log vom Silentrunner!
"Silent Runners.vbs", revision 41,
http://www.silentrunners.org/
Operating System: Windows 2000
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"internat.exe" = "internat.exe" [MS]
"iIWiper" = "E:\Programme\iISystem Wiper\SystemWiper.exe m" ["iISoftware"]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ {++}
"wininet.dll" = "mscornet.exe" [null data]
"nvctrl.exe" = "nvctrl.exe" [null data]
"kernel32.dll" = "C:\WINDOWS\System32\mssearchnet.exe" [null data]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"SystemTray" = "SysTray.Exe" [MS]
"Synchronization Manager" = "mobsync.exe /logon" [MS]
"Zone Labs Client" = "E:\Programme\Zone Labs\ZoneAlarm\zlclient.exe" ["Zone Labs, LLC"]
"Arcor Online" = (empty string)
"DAEMON Tools-1033" = ""E:\Programme\D-Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]
"SpyAxe" = "C:\Programme\SpyAxe\spyaxe.exe /h" [file not found]
"BDMCon" = "C:\Programme\Softwin\BitDefender Free Edition\\bdmcon.exe" ["SOFTWIN S.R.L."]
"BDNewsAgent" = "C:\Programme\Softwin\BitDefender Free Edition\\bdnagent.exe" [null data]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{e9ccf15d-4c68-4b5a-9e9a-8e12e4bd39bd}\(Default) = "HomepageBHO" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hp8509.tmp" [null data]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "CPL-Erweiterung für Anzeigeverschiebung"
-> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Erweiterung für HyperTerminal-Icons"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {CLSID}\InProcServer32\(Default) = "E:\Programme\WinRAR\rarext.dll" [null data]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "E:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "E:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "E:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "E:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
"{D653647D-D607-4DF6-A5B8-48D2BA195F7B}" = "BitDefender Antivirus v7"
-> {CLSID}\InProcServer32\(Default) = "C:\Programme\Softwin\BitDefender Free Edition\bdshelxt.dll" ["SOFTWIN S.R.L."]
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
AntiVir/Win\(Default) = "{a7cda720-84ee-11d0-b5c0-00001b3ca278}"
-> {CLSID}\InProcServer32\(Default) = "C:\Programme\AVPersonal\AVShlExt.DLL" ["H+BEDV Datentechnik GmbH"]
BitDefender Antivirus v7\(Default) = "{D653647D-D607-4DF6-A5B8-48D2BA195F7B}"
-> {CLSID}\InProcServer32\(Default) = "C:\Programme\Softwin\BitDefender Free Edition\bdshelxt.dll" ["SOFTWIN S.R.L."]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "E:\Programme\WinRAR\rarext.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "E:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "E:\Programme\WinRAR\rarext.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "E:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
AntiVir/Win\(Default) = "{a7cda720-84ee-11d0-b5c0-00001b3ca278}"
-> {CLSID}\InProcServer32\(Default) = "C:\Programme\AVPersonal\AVShlExt.DLL" ["H+BEDV Datentechnik GmbH"]
BitDefender Antivirus v7\(Default) = "{D653647D-D607-4DF6-A5B8-48D2BA195F7B}"
-> {CLSID}\InProcServer32\(Default) = "C:\Programme\Softwin\BitDefender Free Edition\bdshelxt.dll" ["SOFTWIN S.R.L."]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "E:\Programme\WinRAR\rarext.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "E:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
Active Desktop and Wallpaper:
-----------------------------
Active Desktop is enabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "D:\HintergrundHolly.JPG"
Enabled Screen Saver:
---------------------
HKCU\Control Panel\Desktop\
HKCU\Software\Microsoft\Internet Explorer\Desktop\Components\0\
"SCRNSAVE.EXE" = "(Kein)" [file not found]
Startup items in "Seda & Daniel" & "All Users" startup folders:
---------------------------------------------------------------
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart
"hpoddt01.exe" -> shortcut to: "E:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" ["Hewlett-Packard"]
"Microsoft Office" -> shortcut to: "C:\Programme\Microsoft Office\Office\OSA9.EXE -b -l" [MS]
"officejet 6100" -> shortcut to: "E:\Programme\Hewlett-Packard\Digital Imaging\bin\hposol08.exe" ["Hewlett-Packard Co."]
Enabled Scheduled Tasks:
------------------------
"PCHealth-Planer für die Zusammenstellung der Daten" -> launches: "C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE -c" [file not found]
"Programmstart beschleunigen" -> launches: "walign" [file not found]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\rnr20.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\msafd.dll [MS], 01 - 03, 06 - 15
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = "&Google" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "c:\programme\google\googletoolbar2.dll" ["Google Inc."]
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = "&Google" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "c:\programme\google\googletoolbar2.dll" ["Google Inc."]
Miscellaneous IE Hijack Points
------------------------------
C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")
Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Missing lines (compared with English-language version):
[Strings]: 1 line
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
AntiVir Service, AntiVirService, ""C:\Programme\AVPersonal\AVGUARD.EXE"" ["H+BEDV Datentechnik GmbH"]
AntiVir Update, AVWUpSrv, ""C:\Programme\AVPersonal\AVWUPSRV.EXE"" ["H+BEDV Datentechnik GmbH, Germany"]
BitDefender Communicator, XCOMM, "C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe /service" ["Softwin"]
BitDefender Scan Server, bdss, "C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe /service" [null data]
COM+-Ereignissystem, EventSystem, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\es.dll" [null data]}
TrueVector Internet Monitor, vsmon, "C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe -service" ["Zone Labs, LLC"]
Print Monitors:
---------------
HKLM\System\CurrentControlSet\Control\Print\Monitors\
hpzlnt07\Driver = "hpzlnt07.dll" ["HP"]
----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
use the -supp parameter or answer "No" at the first message box.
---------- (total run time: 48 seconds, including 6 seconds for message boxes)