Keiner eine Ahnung?
Ok vieleicht hilft das:
Es folgen die Daten Vom "datFind.bat", "Blacklight" und "E-Scan".
Ich hab mal ein bischen vorgearbeitet.
datFind:
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: DCA6-794A
Verzeichnis von C:\WINDOWS\system32
19.12.2005 23:33 13.646 wpa.dbl
19.12.2005 20:06 394.914 perfh009.dat
19.12.2005 20:06 409.016 perfh007.dat
19.12.2005 20:06 60.248 perfc009.dat
19.12.2005 20:06 72.710 perfc007.dat
19.12.2005 20:06 947.974 PerfStringBackup.INI
19.12.2005 20:02 101.440 FNTCACHE.DAT
19.12.2005 19:28 5 AuxDrv32_g.dlx
19.12.2005 19:28 5 SndDrv32_g.dlx
19.12.2005 19:10 16.393 $winnt$.inf
19.12.2005 19:07 16.832 amcompat.tlb
19.12.2005 19:07 23.392 nscompat.tlb
19.12.2005 19:07 488 logonui.exe.manifest
19.12.2005 19:07 488 WindowsLogon.manifest
19.12.2005 19:06 749 sapi.cpl.manifest
19.12.2005 19:06 749 cdplayer.exe.manifest
19.12.2005 19:06 749 wuaucpl.cpl.manifest
19.12.2005 19:06 749 ncpa.cpl.manifest
19.12.2005 19:06 749 nwc.cpl.manifest
19.12.2005 19:06 23.488 emptyregdb.dat
14.12.2005 03:15 902 InstallUtil.InstallLog
13.12.2005 16:12 7.006 jupdate-1.5.0_06-b05.log
09.12.2005 01:21 2.723.680 MRT.exe
05.12.2005 18:09 2.323.664 d3dx9_28.dll
05.12.2005 18:07 61.136 xinput9_1_0.dll
01.12.2005 04:31 1.492.480 shdocvw.dll
24.11.2005 06:44 151.552 xvidvfw.dll
24.11.2005 06:43 843.776 xvidcore.dll
24.11.2005 00:58 1.022.464 browseui.dll
24.11.2005 00:58 3.013.632 mshtml.dll
10.11.2005 13:03 127.078 javaws.exe
10.11.2005 13:03 49.265 jpicpl32.cpl
10.11.2005 11:27 49.250 javaw.exe
10.11.2005 11:27 49.248 java.exe
05.11.2005 04:16 606.208 urlmon.dll
05.11.2005 04:16 1.056.256 danim.dll
29.10.2005 19:07 146.650 BuzzingBee.wav
29.10.2005 19:07 125.690 LoopyMusic.wav
29.10.2005 00:50 26.112 bcsprsrc.dll
29.10.2005 00:50 86.016 pintool.exe
29.10.2005 00:25 151.552 ifxcardm.dll
29.10.2005 00:25 133.120 axaltocm.dll
28.10.2005 16:40 96.792 basecsp.dll
27.10.2005 20:37 53.248 dpuGUI10.dll
27.10.2005 20:37 86.016 dpl100.dll
27.10.2005 20:37 593.920 dpuGUI11.dll
27.10.2005 20:37 200.704 dtu100.dll
27.10.2005 20:37 339.968 dpus11.dll
27.10.2005 20:37 57.344 dpv11.dll
27.10.2005 20:37 294.912 dpu11.dll
27.10.2005 20:37 294.912 dpu10.dll
21.10.2005 04:40 664.064 wininet.dll
21.10.2005 04:40 474.112 shlwapi.dll
21.10.2005 04:40 448.512 mshtmled.dll
21.10.2005 04:40 39.424 pngfilt.dll
21.10.2005 04:40 146.432 msrating.dll
21.10.2005 04:40 530.944 mstime.dll
21.10.2005 04:40 96.768 inseng.dll
21.10.2005 04:40 251.392 iepeers.dll
21.10.2005 04:40 55.808 extmgr.dll
21.10.2005 04:40 205.312 dxtrans.dll
21.10.2005 04:40 152.064 cdfview.dll
20.10.2005 23:25 1.094.144 esent.dll
13.10.2005 00:15 15.584 spmsg.dll
06.10.2005 04:18 280.064 gdi32.dll
06.10.2005 04:08 1.839.616 win32k.sys
30.09.2005 16:59 3.799 jupdate-1.5.0_04-b05.log
28.09.2005 19:50 1.044.480 libdivx.dll
28.09.2005 19:50 200.704 ssldivx.dll
23.09.2005 07:28 150.016 mscorier.dll
23.09.2005 07:28 74.240 mscories.dll
23.09.2005 07:28 270.848 mscoree.dll
23.09.2005 07:28 83.456 dfshim.dll
23.09.2005 04:06 8.491.520 shell32.dll
10.09.2005 02:54 2.067.968 cdosys.dll
01.09.2005 02:44 292.352 winsrv.dll
01.09.2005 02:44 19.968 linkinfo.dll
---------------------------------------------------------------
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: DCA6-794A
Verzeichnis von C:\DOKUME~1\KraSS\LOKALE~1\Temp
20.12.2005 21:19 16.384 Perflib_Perfdata_594.dat
20.12.2005 18:43 16.384 ~DFC9F2.tmp
20.12.2005 18:06 16.384 Perflib_Perfdata_98.dat
20.12.2005 18:03 1.139 kb.log
20.12.2005 18:02 16.384 ~DF8B38.tmp
20.12.2005 00:51 0 aax3F.tmp
20.12.2005 00:46 0 aax3B.tmp
20.12.2005 00:44 0 aax3A.tmp
19.12.2005 23:35 16.384 ~DF566D.tmp
19.12.2005 23:26 462 MSI43c65.LOG
19.12.2005 23:15 0 aax20.tmp
19.12.2005 21:42 0 aax5B.tmp
19.12.2005 20:15 16.384 ~DFDF29.tmp
19.12.2005 13:22 90.112.000 fn629e4350.pk3
19.12.2005 13:15 16.384 ~DFA3C3.tmp
19.12.2005 13:12 16.384 ~DFA388.tmp
19.12.2005 13:06 0 aax13.tmp
19.12.2005 12:33 16.384 ~DF296.tmp
19.12.2005 12:20 0 aax12.tmp
19.12.2005 12:19 16.384 ~DFC50A.tmp
19.12.2005 11:50 16.384 ~DF75FC.tmp
19.12.2005 09:23 0 aax19D.tmp
19.12.2005 09:20 0 aax19C.tmp
19.12.2005 06:39 0 aax16E.tmp
19.12.2005 06:37 0 aax16D.tmp
19.12.2005 04:51 344.064 e7f4.rra
19.12.2005 04:13 0 aax154.tmp
19.12.2005 01:40 0 aax13F.tmp
19.12.2005 00:56 0 aax132.tmp
19.12.2005 00:54 0 aax131.tmp
19.12.2005 00:51 0 aax130.tmp
19.12.2005 00:50 0 aax12F.tmp
19.12.2005 00:40 0 aax123.tmp
19.12.2005 00:32 0 aax122.tmp
19.12.2005 00:24 0 aax11F.tmp
18.12.2005 19:21 16.384 ~DFCE19.tmp
18.12.2005 14:57 16.384 ~DFA564.tmp
18.12.2005 05:38 0 aax52.tmp
18.12.2005 05:38 0 aax51.tmp
18.12.2005 05:33 24.253 flourish.mid
18.12.2005 05:30 0 aax4E.tmp
18.12.2005 05:28 0 aax4D.tmp
18.12.2005 05:27 0 aax4C.tmp
18.12.2005 04:48 0 aax22.tmp
18.12.2005 04:38 0 aax1B.tmp
18.12.2005 04:08 0 aax16.tmp
18.12.2005 04:01 16.384 ~DF5AA.tmp
18.12.2005 03:57 0 aax11.tmp
18.12.2005 03:54 0 aax10.tmp
18.12.2005 03:54 0 aaxF.tmp
18.12.2005 03:53 0 aaxE.tmp
18.12.2005 03:53 0 aaxD.tmp
18.12.2005 03:53 0 aax6.tmp
18.12.2005 03:52 0 aax5.tmp
18.12.2005 03:50 0 aax4.tmp
18.12.2005 03:46 0 aax3.tmp
18.12.2005 03:32 0 aax368.tmp
18.12.2005 03:32 0 aax367.tmp
18.12.2005 03:31 0 aax366.tmp
18.12.2005 03:29 0 aax35D.tmp
18.12.2005 03:00 0 aax35A.tmp
18.12.2005 01:02 0 ErronousFilesFoundDuringScan.txt
15.12.2005 19:52 16.384 ~DF7846.tmp
15.12.2005 19:52 16.384 ~DF6FFC.tmp
15.12.2005 15:36 16.384 ~DF8BE8.tmp
15.12.2005 03:22 16.384 ~DF7707.tmp
14.12.2005 15:12 16.384 ~DFE7C7.tmp
14.12.2005 03:21 12.615 jusched.log
14.12.2005 03:16 16.384 ~DF9AFD.tmp
13.12.2005 16:12 8.354 java_install_reg.log
13.12.2005 16:11 23.544 java_install.log
13.12.2005 16:02 884 jinstall.cfg
13.12.2005 05:27 0 aax84.tmp
12.12.2005 18:17 16.384 ~DF22E1.tmp
12.12.2005 15:52 146.155 spydb.avs
12.12.2005 15:41 904 daily-ex.avc
12.12.2005 15:41 41.471 ext005.avc
12.12.2005 15:41 107.730 unp026.avc
12.12.2005 15:41 11.409 avp.klb
12.12.2005 15:41 1.569 avp.set
12.12.2005 15:41 48.372 base006.avc
12.12.2005 15:41 21.425 fa.avc
12.12.2005 15:41 61.647 base082.avc
12.12.2005 15:41 16.591 daily.avc
12.12.2005 15:41 63.298 base007.avc
11.12.2005 18:25 0 aaxA2.tmp
11.12.2005 18:22 0 aax9F.tmp
11.12.2005 09:38 0 aaxA.tmp
11.12.2005 09:35 0 aax9.tmp
11.12.2005 09:34 0 aax8.tmp
11.12.2005 09:33 0 aax7.tmp
11.12.2005 09:30 16.384 ~DF1140.tmp
10.12.2005 21:18 20.480 ~WRC0000.tmp
10.12.2005 06:05 0 aax158.tmp
09.12.2005 19:27 16.384 ~DFDB12.tmp
09.12.2005 19:26 16.384 ~DFA984.tmp
09.12.2005 15:35 489.984 Download.exe
09.12.2005 13:42 80.084 unp019.avc
09.12.2005 13:35 97.792 MWAVL.exe
09.12.2005 02:50 361.984 viewtcp.exe
09.12.2005 02:32 1.706 English.tcp
09.12.2005 02:32 1.706 ViewTcp.lan
08.12.2005 16:47 48.062 ext004.avc
08.12.2005 16:47 49.098 ext001.avc
08.12.2005 16:47 48.070 ext003.avc
08.12.2005 14:50 331.776 esupdate.exe
08.12.2005 14:29 69.442 ca.avc
08.12.2005 14:15 122.880 msvlclnt.dll
08.12.2005 14:13 41.024 Getvlist.exe
08.12.2005 13:55 375.360 mwavscan.com
07.12.2005 18:23 50.388 troj016.avc
07.12.2005 18:05 45.017 Finnish.Age
07.12.2005 18:05 47.980 Polish.Age
07.12.2005 18:05 5.108 English.dow
07.12.2005 18:05 48.362 Spanish.Age
07.12.2005 18:05 43.958 Romanian.Age
07.12.2005 18:05 47.530 Portuguese.Age
07.12.2005 18:05 55.566 Italian.Age
07.12.2005 17:55 42.626 English.Age
07.12.2005 17:55 42.626 language.ini
07.12.2005 17:52 16.384 ~DF3286.tmp
07.12.2005 17:31 47.859 French.Age
07.12.2005 16:51 5.881 Polish.dow
07.12.2005 16:39 29.619 gen004.avc
07.12.2005 16:39 61.107 unp014.avc
07.12.2005 16:39 51.435 troj025.avc
07.12.2005 16:22 58.098 German.Age
06.12.2005 16:10 5.523 German.dow
06.12.2005 14:30 36.526 virus020.avc
06.12.2005 14:30 32.826 krnexe.avc
05.12.2005 13:46 340.480 MWAVReg.EXE
05.12.2005 11:35 52.896 base081.avc
05.12.2005 11:35 100.027 troj007.avc
04.12.2005 22:04 0 aaxC.tmp
04.12.2005 22:04 0 aaxB.tmp
04.12.2005 21:59 16.384 ~DF6F08.tmp
04.12.2005 21:58 16.384 ~DF3B7A.tmp
04.12.2005 21:58 16.384 ~DF3382.tmp
04.12.2005 19:45 0 aax2.tmp
04.12.2005 19:22 0 aax1.tmp
04.12.2005 14:53 1.737 German.tcp
04.12.2005 14:29 13.347 German.con
04.12.2005 01:01 673 sendung_suchen.gif
03.12.2005 19:27 16.384 ~DF4CD9.tmp
03.12.2005 19:26 16.384 ~DF44D1.tmp
02.12.2005 19:09 16.384 ~DF1584.tmp
02.12.2005 10:59 48.179 malw004.avc
02.12.2005 10:59 83.879 virus016.avc
02.12.2005 10:59 48.117 ext002.avc
01.12.2005 19:49 16.384 ~DFF732.tmp
01.12.2005 19:49 16.384 ~DFE895.tmp
01.12.2005 18:18 5.306 Finnish.dow
01.12.2005 18:18 5.768 French.dow
01.12.2005 18:18 5.766 Spanish.dow
01.12.2005 18:18 5.371 Romanian.dow
01.12.2005 18:18 5.710 Portuguese.dow
01.12.2005 18:18 5.393 Italian.dow
01.12.2005 15:52 16.384 ~DFA5C2.tmp
01.12.2005 14:45 1.841 Polish.tcp
01.12.2005 14:02 11.277 Polish.con
30.11.2005 19:50 14.442 ICQ154.tmp
30.11.2005 19:50 5.767 ICQ153.tmp
30.11.2005 17:44 0 aax13E.tmp
29.11.2005 21:04 16.384 ~DF8E88.tmp
29.11.2005 21:04 16.384 ~DF86D3.tmp
29.11.2005 19:59 16.384 ~DF5ACE.tmp
29.11.2005 10:37 49.343 worm005.avc
29.11.2005 10:37 218.120 troj033.avc
28.11.2005 12:45 0 aax4F4.tmp
27.11.2005 18:46 0 aax460.tmp
27.11.2005 10:47 983 schwarz118x28.gif
27.11.2005 09:32 0 aax3DF.tmp
26.11.2005 12:34 0 aax309.tmp
25.11.2005 23:49 107.785 troj034.avc
25.11.2005 23:49 49.194 troj032.avc
25.11.2005 19:22 0 aax272.tmp
25.11.2005 19:20 0 aax271.tmp
25.11.2005 17:33 1.397 Chinese.tcp
25.11.2005 17:33 7.378 Chinese.con
25.11.2005 17:29 1.718 Spanishl.tcp
25.11.2005 17:29 1.718 Spanish.tcp
25.11.2005 17:29 10.405 Spanish.con
25.11.2005 17:25 1.895 Portuguese.tcp
25.11.2005 17:24 10.655 Portuguese.con
25.11.2005 17:24 1.718 Italian.tcp
25.11.2005 17:23 9.555 Italian.con
25.11.2005 17:23 1.886 French.tcp
25.11.2005 17:21 10.998 French.con
25.11.2005 17:19 1.750 Finnish.tcp
25.11.2005 17:18 10.091 Finnish.con
25.11.2005 14:51 0 aax233.tmp
25.11.2005 10:23 16.384 ~DF5663.tmp
25.11.2005 10:23 16.384 ~DF4EC6.tmp
24.11.2005 04:09 479 mmreg.log
24.11.2005 04:05 3.956 INSTALL.LOG
23.11.2005 22:25 37.093 unp012.avc
23.11.2005 22:25 188.662 unp025.avc
23.11.2005 22:25 50.879 troj009.avc
23.11.2005 18:40 16.384 ~DF4469.tmp
22.11.2005 20:13 0 aaxB4.tmp
22.11.2005 20:03 0 aaxB3.tmp
22.11.2005 17:14 16.384 ~DF6236.tmp
21.11.2005 10:00 0 aax145.tmp
21.11.2005 06:35 0 aaxDA.tmp
21.11.2005 05:50 0 aaxD5.tmp
21.11.2005 05:07 0 aaxCE.tmp
21.11.2005 01:43 0 aaxAF.tmp
20.11.2005 21:53 0 aax7F.tmp
20.11.2005 21:39 0 aax7C.tmp
20.11.2005 11:17 16.384 ~DF934B.tmp
20.11.2005 11:17 16.384 ~DF8B92.tmp
20.11.2005 11:00 16.384 ~DF577.tmp
20.11.2005 08:09 0 aax172.tmp
20.11.2005 04:55 0 aax14B.tmp
20.11.2005 04:11 0 aax144.tmp
19.11.2005 02:29 16.384 ~DF3825.tmp
18.11.2005 21:36 0 aax4AB.tmp
18.11.2005 21:33 0 aax4AA.tmp
18.11.2005 20:38 0 aax495.tmp
18.11.2005 19:32 101.737 troj005.avc
18.11.2005 19:32 14.008 kernel.avc
18.11.2005 19:32 44.623 unp018.avc
18.11.2005 19:32 29.097 unp021.avc
18.11.2005 19:32 50.729 krnexe32.avc
18.11.2005 19:32 28.752 krnengn.avc
18.11.2005 12:01 7.187 Polish.lic
18.11.2005 01:15 0 aax3AF.tmp
17.11.2005 23:49 0 aax3A1.tmp
17.11.2005 22:26 0 aax396.tmp
17.11.2005 21:02 0 aax388.tmp
17.11.2005 20:01 0 aax37D.tmp
17.11.2005 13:10 9.374 unp000.avc
17.11.2005 13:10 62.198 unp015.avc
17.11.2005 13:10 92.411 krnmacro.avc
17.11.2005 07:29 0 aax300.tmp
17.11.2005 02:02 0 aax29B.tmp
16.11.2005 01:43 0 aax186.tmp
15.11.2005 23:27 0 aax16F.tmp
15.11.2005 23:06 16.384 ~DFB82A.tmp
15.11.2005 23:04 0 aax16C.tmp
15.11.2005 11:54 6.101 smart.avc
15.11.2005 11:54 14.227 mail.avc
15.11.2005 05:31 0 aaxB2.tmp
15.11.2005 05:27 0 aaxB1.tmp
15.11.2005 05:24 0 aaxB0.tmp
14.11.2005 23:21 0 aax7A.tmp
14.11.2005 23:12 0 aax77.tmp
14.11.2005 23:03 0 aax76.tmp
14.11.2005 07:33 16.384 ~DF8562.tmp
14.11.2005 07:33 16.384 ~DF7D08.tmp
14.11.2005 04:40 0 aax7B.tmp
12.11.2005 07:43 0 aax167.tmp
12.11.2005 03:59 0 aax11A.tmp
12.11.2005 03:54 0 aax119.tmp
12.11.2005 03:50 0 aax116.tmp
12.11.2005 00:39 0 x798E.tmp
12.11.2005 00:38 0 6fr8D.tmp
11.11.2005 21:05 0 aax6C.tmp
10.11.2005 15:11 81.196 unp007.avc
10.11.2005 15:11 34.528 unp024.avc
10.11.2005 15:11 50.028 troj031.avc
10.11.2005 15:11 56.430 unp006.avc
10.11.2005 15:11 65.807 krnunp.avc
10.11.2005 05:45 16.384 ~DFA573.tmp
10.11.2005 05:45 16.384 ~DF9DCC.tmp
10.11.2005 05:28 16.384 ~DF798D.tmp
10.11.2005 05:27 16.384 ~DF6528.tmp
09.11.2005 17:47 14.732 dd_netfx20UI7F26.txt
09.11.2005 17:47 4.600.428 dd_netfx20MSI7F26.txt
09.11.2005 17:46 5.238 ASPNETSetup_00000.log
09.11.2005 17:38 16.384 ~DF629F.tmp
09.11.2005 17:38 16.384 ~DF545C.tmp
08.11.2005 20:48 0 aax3D7.tmp
08.11.2005 20:39 0 aax3D4.tmp
08.11.2005 18:15 0 aax385.tmp
08.11.2005 06:59 0 aax32A.tmp
08.11.2005 05:54 0 aax321.tmp
08.11.2005 05:20 0 aax31C.tmp
08.11.2005 05:19 0 aax31B.tmp
08.11.2005 05:08 0 aax318.tmp
08.11.2005 05:02 0 aax317.tmp
08.11.2005 05:01 0 aax316.tmp
08.11.2005 05:01 0 aax315.tmp
08.11.2005 04:52 0 aax310.tmp
08.11.2005 04:52 0 aax30F.tmp
07.11.2005 16:36 109.301 troj003.avc
07.11.2005 16:36 73.725 virus003.avc
06.11.2005 19:37 16.384 ~DF106A.tmp
06.11.2005 19:37 16.384 ~DF689.tmp
06.11.2005 01:40 0 aaxA6.tmp
05.11.2005 23:04 0 aax45.tmp
05.11.2005 07:32 0 aax11D5.tmp
05.11.2005 07:11 0 aax11C3.tmp
05.11.2005 07:11 0 aax11C1.tmp
05.11.2005 07:11 0 aax11C2.tmp
05.11.2005 07:11 0 aax11C0.tmp
05.11.2005 07:10 0 aax11BF.tmp
05.11.2005 06:51 0 aax11BA.tmp
05.11.2005 06:51 0 aax11B9.tmp
05.11.2005 06:42 0 aax11B8.tmp
05.11.2005 06:37 0 aax11B5.tmp
05.11.2005 06:37 0 aax11B4.tmp
05.11.2005 06:35 0 aax11B3.tmp
05.11.2005 05:36 0 aax11AA.tmp
05.11.2005 03:49 70.318 groeni31_.jpeg
05.11.2005 00:35 0 aax113D.tmp
05.11.2005 00:34 0 aax113C.tmp
05.11.2005 00:24 0 aax113B.tmp
05.11.2005 00:22 0 aax113A.tmp
05.11.2005 00:19 0 aax1137.tmp
05.11.2005 00:18 0 aax1136.tmp
04.11.2005 19:42 16.384 ~DF3AAD.tmp
04.11.2005 05:10 0 aax1061.tmp
04.11.2005 05:10 0 aax1060.tmp
04.11.2005 00:36 0 aaxF17.tmp
04.11.2005 00:36 0 aaxF16.tmp
04.11.2005 00:33 0 aaxF15.tmp
03.11.2005 23:39 0 aaxF0E.tmp
03.11.2005 22:50 0 aaxF05.tmp
03.11.2005 22:48 0 aaxF04.tmp
03.11.2005 21:52 0 aaxEFB.tmp
02.11.2005 13:21 48.314 malw003.avc
02.11.2005 13:21 54.697 malw002.avc
02.11.2005 13:21 113.508 krn001.avc
02.11.2005 13:21 56.623 troj022.avc
26.10.2005 11:22 50.124 troj013.avc
26.10.2005 11:22 54.896 unp003.avc
26.10.2005 11:22 77.389 virus012.avc
21.10.2005 17:29 31.186 Chinese.Age
21.10.2005 16:36 50.443 troj018.avc
21.10.2005 16:36 50.224 worm001.avc
21.10.2005 16:36 68.829 unp010.avc
21.10.2005 16:36 41.440 troj028.avc
21.10.2005 16:36 43.378 troj027.avc
20.10.2005 13:39 3.518 Chinese.dow
11.10.2005 11:05 74.103 virus010.avc
08.10.2005 17:35 52.101 unp009.avc
08.10.2005 17:35 50.740 unp001.avc
08.10.2005 17:35 48.724 troj030.avc
06.10.2005 21:25 7.414 English.lic
06.10.2005 21:25 7.414 license.txt
06.10.2005 10:42 50.654 unp022.avc
04.10.2005 11:20 47.070 troj026.avc
27.09.2005 11:25 27.019 unp004.avc
26.09.2005 12:30 50.208 troj010.avc
26.09.2005 12:30 75.027 virus014.avc
26.09.2005 12:30 50.231 troj020.avc
26.09.2005 12:30 17.722 ext999.avc
21.09.2005 15:41 81.306 unp023.avc
19.09.2005 10:36 49.994 troj019.avc
19.09.2005 10:36 50.490 troj029.avc
16.09.2005 10:51 101.225 troj001.avc
13.09.2005 12:10 79.269 virus017.avc
12.09.2005 12:09 43.035 gen999.avc
08.09.2005 11:30 57.965 unp013.avc
06.09.2005 10:58 55.660 troj023.avc
04.09.2005 23:12 56.341 troj024.avc
03.09.2005 12:49 41.540 gen003.avc
-----------------------------------------------------------------
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: DCA6-794A
Verzeichnis von C:\WINDOWS
21.12.2005 20:07 69 NeroDigital.ini
20.12.2005 18:06 0 0.log
20.12.2005 18:06 749.676 WindowsUpdate.log
20.12.2005 18:06 2.048 bootstat.dat
19.12.2005 23:35 492.153 setupapi.log
19.12.2005 23:27 99.970 UninstallFirefox.exe
19.12.2005 23:27 4.224 mozver.dat
19.12.2005 21:03 38.046 KB893066.log
19.12.2005 20:58 52.030 Omega Drivers Log.txt
19.12.2005 20:55 737.280 iun6002.exe
19.12.2005 20:12 4.230 SchedLgU.Txt
19.12.2005 20:07 13.126 KB902344.log
19.12.2005 20:07 624 avmcoins.log
19.12.2005 20:06 202.808 comsetup.log
19.12.2005 20:06 80.427 iis6.log
19.12.2005 20:06 1.393 imsins.log
19.12.2005 20:06 207.663 tsoc.log
19.12.2005 20:06 29.331 ocmsn.log
19.12.2005 20:06 124.375 ntdtcsetup.log
19.12.2005 20:06 23.703 KB900930.log
19.12.2005 20:06 271.109 ocgen.log
19.12.2005 20:06 26.631 msgsocm.log
19.12.2005 20:06 516.406 FaxSetup.log
19.12.2005 20:06 37.964 updspapi.log
19.12.2005 20:06 1.393 imsins.BAK
19.12.2005 20:06 21.282 KB887797.log
19.12.2005 20:00 49.656 KB905915.log
19.12.2005 20:00 44.012 KB904706.log
19.12.2005 20:00 27.992 KB910437.log
19.12.2005 20:00 37.001 KB896424.log
19.12.2005 20:00 44.599 KB900725.log
19.12.2005 19:59 41.949 KB905749.log
19.12.2005 19:59 42.329 KB905414.log
19.12.2005 19:59 40.273 KB901017.log
19.12.2005 19:59 45.974 KB902400.log
19.12.2005 19:59 43.057 KB894391.log
19.12.2005 19:59 39.479 KB896423.log
19.12.2005 19:59 38.463 KB899587.log
19.12.2005 19:59 37.453 KB899591.log
19.12.2005 19:59 37.746 KB893756.log
19.12.2005 19:58 27.043 KB896358.log
19.12.2005 19:58 35.094 KB890859.log
19.12.2005 19:58 28.686 KB901214.log
19.12.2005 19:58 28.366 KB896428.log
19.12.2005 19:58 29.031 KB896422.log
19.12.2005 19:58 29.073 KB890046.log
19.12.2005 19:58 26.035 KB885250.log
19.12.2005 19:58 26.534 KB885835.log
19.12.2005 19:58 24.370 KB887742.log
19.12.2005 19:57 21.664 KB888113.log
19.12.2005 19:57 21.749 KB891781.log
19.12.2005 19:57 21.540 KB887472.log
19.12.2005 19:57 21.785 KB888302.log
19.12.2005 19:57 20.950 KB885836.log
19.12.2005 19:57 13.610 KB886185.log
19.12.2005 19:57 20.956 KB873339.log
19.12.2005 19:47 129.570 KB893803v2.log
19.12.2005 19:14 643.616 setuplog.txt
19.12.2005 19:10 71.070 setupact.log
19.12.2005 19:07 85.193 wmsetup.log
19.12.2005 19:07 316.640 WMSysPr9.prx
19.12.2005 19:07 1.272 OEWABLog.txt
19.12.2005 19:07 4.348 ODBCINST.INI
19.12.2005 19:06 749 WindowsShell.Manifest
19.12.2005 19:06 1.013 win.ini
19.12.2005 19:06 253 DtcInstall.log
19.12.2005 19:06 2.065 sessmgr.setup.log
19.12.2005 19:05 373 cmsetacl.log
19.12.2005 19:04 509 wiadebug.log
19.12.2005 19:04 50 wiaservc.log
19.12.2005 19:00 4.016 regopt.log
19.12.2005 19:00 246 system.ini
19.12.2005 18:53 12.246 WINNT32.LOG
19.12.2005 18:53 0 setuperr.log
19.12.2005 18:52 842 UPGRADE.TXT
19.12.2005 18:52 29.917 wsdu.log
19.12.2005 18:50 403 DHCPUPG.LOG
19.12.2005 18:31 226.211 setupapi.old
18.12.2005 05:06 42.890 DirectX.log
18.12.2005 04:16 60.416 ALCFDRTM.VER
15.12.2005 03:19 923 spupdsvc.log
14.12.2005 03:15 7.525 WMCSetup.log
14.12.2005 03:15 3.435 basecsp.log
30.11.2005 11:16 467 cdPlayer.ini
09.11.2005 17:45 5.167 KB891122.log
05.11.2005 04:13 4.609 WINASTAR.INI
05.11.2005 04:00 387 winastar.lic
29.10.2005 19:07 60.416 ALCFDRTM.EXE
25.10.2005 18:23 1.647.097 setupapi.log.0.old
18.10.2005 18:52 10 WININIT.INI
18.10.2005 17:20 350 RefreshLock.ini
13.10.2005 16:23 110.618 ntbtlog.txt
12.10.2005 19:46 27.728 KB896688.log
18.08.2005 16:25 15.348 KraSS.acl
-------------------------------------------------------------
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: DCA6-794A
Verzeichnis von C:\
21.12.2005 20:56 0 sys.txt
21.12.2005 20:56 8.301 system.txt
21.12.2005 20:54 21.523 systemtemp.txt
21.12.2005 20:52 100.843 system32.txt
21.12.2005 20:15 2 AVPCallback.log
20.12.2005 18:06 1.073.270.784 hiberfil.sys
20.12.2005 18:06 1.610.612.736 pagefile.sys
19.12.2005 19:05 211 boot.ini
19.12.2005 11:57 6.486.826 reclock_log.txt
19.12.2005 08:38 7.631 CLDMA.LOG
17.08.2005 04:02 0 MSDOS.SYS
17.08.2005 04:02 0 IO.SYS
17.08.2005 04:02 0 CONFIG.SYS
17.08.2005 04:02 0 AUTOEXEC.BAT
03.08.2004 21:59 251.184 ntldr
03.08.2004 21:38 47.564 NTDETECT.COM
02.04.2003 13:00 4.952 bootfont.bin
17 Datei(en) 2.690.812.557 Bytes
0 Verzeichnis(se), 14.587.027.456 Bytes frei
-------------------------------------------------------
-------------------------------------------------------
Blacklight:
12/21/05 21:07:22 [Info]: BlackLight Engine 1.0.30 initialized
12/21/05 21:07:22 [Info]: OS: 5.1 build 2600 (Service Pack 2)
12/21/05 21:07:23 [Note]: 7019 4
12/21/05 21:07:23 [Note]: 7005 0
12/21/05 21:07:26 [Note]: 7006 0
12/21/05 21:07:26 [Note]: 7011 1428
12/21/05 21:07:27 [Note]: FSRAW library version 1.7.1014
12/21/05 21:09:47 [Note]: 7007 0
-----------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------
E-Scan:
Thu Dec 22 03:26:39 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.*
Thu Dec 22 02:00:00 2005 => System found infected with zipitpro Spyware/Adware (iun6002.exe)! Action taken: No Action Taken.
Thu Dec 22 02:00:02 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken.
Thu Dec 22 02:00:03 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action
Taken.Thu Dec 22 02:18:58 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.*
Thu Dec 22 02:00:04 2005 => System found infected with zipitpro Spyware/Adware (C:\WINDOWS\iun6002.exe)! Action taken: No Action Taken.
Thu Dec 22 01:59:59 2005 => Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Thu Dec 22 01:16:51 2005 => ERROR!!! Invalid Entry POINTER = point32.exe (in key SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.
Thu Dec 22 01:59:59 2005 => Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Thu Dec 22 02:00:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\OFFPRO97.CD\Office\Assistnt\logo.act". Action Taken: No Action Taken.
Thu Dec 22 02:00:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\OFFPRO97.CD\Office\Assistnt\scribble.act". Action Taken: No Action Taken.
Thu Dec 22 02:00:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\OFFPRO97.CD\Office\Assistnt\dot.act". Action Taken: No Action Taken.
Thu Dec 22 02:00:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\OFFPRO97.CD\Office\Assistnt\mnature.act". Action Taken: No Action Taken.
Thu Dec 22 02:00:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\OFFPRO97.CD\Office\Assistnt\hoverbot.act". Action Taken: No Action Taken.
Thu Dec 22 02:00:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\OFFPRO97.CD\Office\Assistnt\will.act". Action Taken: No Action Taken.
Thu Dec 22 02:00:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\OFFPRO97.CD\Office\Assistnt\powerpup.act". Action Taken: No Action Taken.
Thu Dec 22 02:00:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\OFFPRO97.CD\Office\Assistnt\genius.act". Action Taken: No Action Taken.
Thu Dec 22 02:00:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\Nero BackItUp\BackItUp-Jpn.nls". Action Taken: No Action Taken.
Thu Dec 22 02:00:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Micr
Thu Dec 22 02:00:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.EnterpriseServices.tlb". Action Taken: No Action Taken.
"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.Windows.Forms.tlb". Action Taken: No Action Taken.
Thu Dec 22 02:00:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.JScript.tlb". Action Taken: No Action Taken.
Thu Dec 22 02:00:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.Vsa.tlb". Action Taken: No Action Taken.
Thu Dec 22 02:00:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.Drawing.tlb". Action Taken: No Action Taken.
Thu Dec 22 02:00:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscoree.tlb". Action Taken: No Action Taken.
Thu Dec 22 02:00:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscorlib.tlb". Action Taken: No Action Taken.
Thu Dec 22 02:00:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.tlb". Action Taken: No Action Taken.
Thu Dec 22 02:00:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb". Action Taken: No Action Taken.
Thu Dec 22 02:00:10 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".ape". Action Taken: No Action Taken.
Thu Dec 22 02:00:10 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".avc". Action Taken: No Action Taken.
Thu Dec 22 02:00:10 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".tcp". Action Taken: No Action Taken.
Thu Dec 22 02:00:10 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".tmp". Action Taken: No Action Taken.
Thu Dec 22 02:00:12 2005 => Entry "HKCR\CLSID\{A0717E52-8AC8-4dd9-8682-0B76775125E6}" refers to invalid object "C:\WINDOWS\system32\divxsm.exe". Action Taken: No Action Taken.
Thu Dec 22 02:00:12 2005 => Entry "HKCR\CLSID\{A433AA50-648A-4EF0-AE29-BA8995585D92}" refers to invalid object "D:\install4\VBWINSYS.EXE". Action Taken: No Action Taken.
Thu Dec 22 02:00:13 2005 => Entry "HKCR\TypeLib\{1D29F3E7-72A2-490E-926B-22E32F34A8DE}" refers to invalid object "D:\install4\VBWINSYS.EXE". Action Taken: No Action Taken.
Thu Dec 22 02:00:13 2005 => Entry "HKCR\TypeLib\{A4CA8810-6E46-36FF-A048-B7FD564742F8}" refers to invalid object "Path". Action Taken: No Action Taken.
Thu Dec 22 02:00:15 2005 => Entry "HKCR\mpc_auto_file\shell\open\command" refers to invalid object ""c:\privat\filme\mpxchange.exe" "%1"". Action Taken: No Action Taken.
Thu Dec 22 02:56:31 2005 => File C:\System Volume Information\_restore{7F92434C-964F-47EC-852D-37131FB69CAA}\RP6\A0003476.exe tagged as "not-a-virus:AdWare.Win32.Webdir.b". Action Taken: No Action Taken.
Thu Dec 22 03:58:38 2005 => File C:\System Volume Information\_restore{7F92434C-964F-47EC-852D-37131FB69CAA}\RP6\A0003476.exe tagged as "not-a-virus:AdWare.Win32.Webdir.b". Action Taken: No Action Taken.
Thu Dec 22 01:59:59 2005 => Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Thu Dec 22 04:16:29 2005 => Total Virus(es) Found: 8
Thu Dec 22 04:16:29 2005 => Total Disinfected Files: 0
Da steht ich habe 8 Viren? Und nun?
THX Michael