Verzeichnis von C:\WINDOWS\system32
25.01.2006 16:35 5.068 ncompat.tlb
25.01.2006 16:12 5.120 msvol.tlb
25.01.2006 16:12 10.152 hp49E5.tmp
25.01.2006 16:12 21.001 ld46D7.tmp
25.01.2006 14:48 102.400 replmap.dll
25.01.2006 14:48 15.244 nvctrl.exe
25.01.2006 14:48 4.286 ts.ico
25.01.2006 14:48 4.286 ot.ico
25.01.2006 14:48 9.268 mssearchnet.exe
25.01.2006 14:41 13.821 mscornet.exe
24.01.2006 21:01 1.158 wpa.dbl
05.01.2006 04:41 2.836.320 MRT.exe
03.01.2006 15:31 91.904 S32EVNT1.DLL
29.12.2005 03:54 280.064 gdi32.dll
26.12.2005 14:51 619 lsprst7.tgz
26.12.2005 14:51 87 ssprs.tgz
26.12.2005 14:51 605 lsprst7.dll
26.12.2005 14:51 73 ssprs.dll
01.12.2005 04:31 1.492.480 shdocvw.dll
27.11.2005 13:20 217.656 FNTCACHE.DAT
24.11.2005 00:58 1.022.464 browseui.dll
24.11.2005 00:58 3.013.632 mshtml.dll
05.11.2005 04:16 606.208 urlmon.dll
05.11.2005 04:16 1.056.256 danim.dll
22.10.2005 12:33 1.025 sysprs7.dll
22.10.2005 12:33 1.025 sysprs7.tgz
22.10.2005 12:33 1.025 clauth1.dll
22.10.2005 12:33 1.025 clauth2.dll
21.10.2005 04:40 474.112 shlwapi.dll
21.10.2005 04:40 664.064 wininet.dll
21.10.2005 04:40 39.424 pngfilt.dll
21.10.2005 04:40 146.432 msrating.dll
21.10.2005 04:40 530.944 mstime.dll
21.10.2005 04:40 448.512 mshtmled.dll
21.10.2005 04:40 205.312 dxtrans.dll
21.10.2005 04:40 251.392 iepeers.dll
21.10.2005 04:40 96.768 inseng.dll
21.10.2005 04:40 152.064 cdfview.dll
21.10.2005 04:40 55.808 extmgr.dll
20.10.2005 23:25 1.094.144 esent.dll
18.10.2005 00:48 176.167 rmoc3260.dll
18.10.2005 00:48 5.632 pndx5032.dll
Verzeichnis von C:\WINDOWS
25.01.2006 16:42 1.470.070 WindowsUpdate.log
25.01.2006 16:29 116 NeroDigital.ini
25.01.2006 16:12 4.468 ModemLog_SoftV92 Data Fax Modem with SmartCP.txt
25.01.2006 16:12 159 wiadebug.log
25.01.2006 16:11 0 0.log
25.01.2006 16:11 2.048 bootstat.dat
25.01.2006 16:10 32.426 SchedLgU.Txt
25.01.2006 16:10 50 wiaservc.log
25.01.2006 16:10 12 bthservsdp.dat
23.01.2006 21:05 155 winamp.ini
16.01.2006 19:16 707 win.ini
16.01.2006 19:15 65 gvcasinos.ini
15.01.2006 11:12 949.922 setupapi.log
14.01.2006 00:16 142.989 ocgen.log
14.01.2006 00:16 14.467 msgsocm.log
14.01.2006 00:16 114.597 tsoc.log
14.01.2006 00:16 15.933 ocmsn.log
14.01.2006 00:16 62.566 ntdtcsetup.log
14.01.2006 00:16 105.440 comsetup.log
14.01.2006 00:16 45.883 iis6.log
14.01.2006 00:16 307.217 FaxSetup.log
14.01.2006 00:16 10.150 KB908519.log
14.01.2006 00:16 1.374 imsins.log
07.01.2006 10:05 11.061 KB912919.log
07.01.2006 10:05 1.355 imsins.BAK
07.01.2006 10:05 20.889 updspapi.log
01.01.2006 15:32 377 wincmd.ini
28.12.2005 17:07 151 PhotoSnapViewer.INI
22.12.2005 09:14 626 CLIP.INI
18.12.2005 22:48 254 wcx_ftp.ini
18.12.2005 22:37 9.962 KB910437.log
18.12.2005 22:36 17.030 KB905915.log
18.12.2005 15:42 4.604 ModemLog_SAMSUNG Mobile USB Modem 1.0.txt
01.12.2005 15:43 88.975 DirectX.log
14.11.2005 20:31 1.406 psmplay.ini
10.11.2005 19:00 11.933 KB896424.log
08.11.2005 18:42 7.168 Thumbs.db
08.11.2005 10:43 156.910 WMSysPr8.prx
31.10.2005 09:51 227 system.ini
24.10.2005 23:00 12.719 cdplayer.ini
18.10.2005 17:56 27.804 wmsetup.log
17.10.2005 12:52 23.278 KB902400.log
17.10.2005 12:52 14.050 KB896688.log
17.10.2005 12:52 13.134 KB900725.log
16.10.2005 21:24 10.600 KB901017.log
16.10.2005 19:00 11.725 KB905414.log
13.10.2005 23:55 12.945 KB904706.log
13.10.2005 10:13 14.102 KB905749.log
13.10.2005 10:07 4.376 SYMEVENT.LOG
13.10.2005 10:01 83 MININU.LOG
13.10.2005 10:01 264 _delis32.ini
13.10.2005 09:59 1.142 LUINSTALL.LOG
Verzeichnis von C:\
25.01.2006 16:45 0 sys.txt
25.01.2006 16:44 9.466 system.txt
25.01.2006 16:42 55.242 systemtemp.txt
25.01.2006 16:42 106.001 system32.txt
25.01.2006 16:11 1.071.763.456 hiberfil.sys
25.01.2006 16:11 1.607.540.736 pagefile.sys
02.11.2005 23:32 5.589 data
31.10.2005 09:51 194 BOOT.INI
03.08.2005 19:08 1.120 INSTALL.LOG
12.07.2005 20:18 0 DBS.TXT
20.06.2005 14:33 6 ISACER.ID
27.12.2004 17:02 75 PRELOAD.AAA
27.12.2004 16:58 776 IPH.PH
27.12.2004 12:08 0 CONFIG.SYS
27.12.2004 12:08 0 MSDOS.SYS
27.12.2004 12:08 0 AUTOEXEC.BAT
27.12.2004 12:08 0 IO.SYS
Verzeichnis von C:\DOKUME~1\Nachti\LOKALE~1\Temp
25.01.2006 16:13 16.384 ~DFE907.tmp
25.01.2006 16:10 16.384 ~DFAF1B.tmp
25.01.2006 15:51 16.384 ~DF1BDD.tmp
25.01.2006 15:48 31.784 SSLanguage.ini
25.01.2006 15:47 4.699 SYMEVENT.LOG
25.01.2006 14:08 16.384 ~DF230D.tmp
24.01.2006 21:14 16.384 ~DFB2C2.tmp
23.01.2006 21:05 16.384 ~DF284E.tmp
22.01.2006 18:46 16.384 ~DF10E1.tmp
22.01.2006 10:41 16.384 ~DF2138.tmp
21.01.2006 22:05 16.384 ~DFA9C8.tmp
21.01.2006 21:10 125 3FCA41B8.TMP
21.01.2006 20:32 16.384 ~DF78E3.tmp
20.01.2006 20:36 16.384 ~DFEA62.tmp
19.01.2006 21:21 16.384 ~DF7826.tmp
18.01.2006 20:58 16.384 ~DFB265.tmp
18.01.2006 20:38 16.384 ~DF176E.tmp
17.01.2006 19:20 16.384 ~DFFEA3.tmp
16.01.2006 20:42 16.384 ~DFC4AF.tmp
15.01.2006 21:15 16.384 ~DF6D9.tmp
15.01.2006 19:10 16.384 ~DF3F73.tmp
15.01.2006 11:44 902 logfile.txt
15.01.2006 11:41 2.485 Skin.ini
15.01.2006 11:24 16.384 ~DFCEBB.tmp
15.01.2006 01:43 65.536 ~DFB0D5.tmp
15.01.2006 01:42 16.384 ~DFD9C5.tmp
14.01.2006 00:16 16.384 ~DFD326.tmp
12.01.2006 07:59 16.384 ~DF61ED.tmp
11.01.2006 21:00 16.384 ~DF1089.tmp
09.01.2006 20:00 16.384 ~DF74AC.tmp
09.01.2006 18:04 16.384 ~DF57EC.tmp
07.01.2006 18:41 16.384 ~DF63B6.tmp
07.01.2006 10:05 16.384 ~DFC4CD.tmp
06.01.2006 17:14 16.384 ~DF6F62.tmp
05.01.2006 18:44 16.384 ~DFC7E8.tmp
05.01.2006 16:28 16.384 ~DFDC3D.tmp
05.01.2006 15:25 72.192 ~e5.0001
03.01.2006 18:56 16.384 ~DF6342.tmp
02.01.2006 22:46 16.384 ~DFC682.tmp
02.01.2006 18:04 65.536 ~DF8FAF.tmp
02.01.2006 18:04 16.384 ~DF2BD.tmp
02.01.2006 08:37 16.384 ~DFC73C.tmp
01.01.2006 22:30 16.384 ~DFD49.tmp
01.01.2006 21:28 4.132 bt0835.bat
01.01.2006 19:59 65.536 ~DF759.tmp
01.01.2006 19:59 16.384 ~DF7029.tmp
31.12.2005 21:56 16.384 ~DF1751.tmp
31.12.2005 21:32 283 wahtmltmp00.htm
31.12.2005 20:48 16.384 ~DF95DE.tmp
31.12.2005 20:19 16.384 ~DFA259.tmp
30.12.2005 17:21 16.384 ~DF50BB.tmp
30.12.2005 14:02 16.384 ~DF3FD4.tmp
30.12.2005 12:46 16.384 ~DF4EC3.tmp
30.12.2005 12:46 4.132 bt7553.bat
29.12.2005 21:01 16.384 ~DFD393.tmp
29.12.2005 21:00 65.536 ~DF59AB.tmp
29.12.2005 20:07 2.488 java_install_reg.log
27.12.2005 23:55 16.384 ~DF2DDB.tmp
27.12.2005 22:23 4.132 bt0478.bat
27.12.2005 20:59 16.384 ~DF6E15.tmp
27.12.2005 19:01 4.132 bt5356.bat
27.12.2005 18:05 16.384 ~DF7F46.tmp
27.12.2005 18:01 16.384 ~DFD291.tmp
27.12.2005 16:29 16.384 ~DF4E07.tmp
27.12.2005 16:11 4.132 bt6433.bat
27.12.2005 16:11 4.132 bt7445.bat
27.12.2005 16:02 16.384 ~DFF86C.tmp
27.12.2005 16:02 4.132 bt5035.bat
27.12.2005 15:59 16.384 ~DF3A7A.tmp
27.12.2005 15:59 4.132 bt7408.bat
27.12.2005 15:59 4.132 bt4776.bat
27.12.2005 15:58 4.132 bt3581.bat
27.12.2005 15:58 4.132 bt0033.bat
27.12.2005 15:10 4.132 bt0134.bat
27.12.2005 14:46 65.536 ~DF85C2.tmp
27.12.2005 14:27 16.384 ~DFA39E.tmp
27.12.2005 13:22 16.384 ~DFF652.tmp
26.12.2005 22:58 65.536 ~DF9CC.tmp
26.12.2005 22:16 16.384 ~DF5DF.tmp
26.12.2005 15:11 65.536 ~DFD71D.tmp
26.12.2005 15:11 16.384 ~DFB50D.tmp
26.12.2005 12:13 4.132 bt7173.bat
25.12.2005 21:36 16.384 ~DF14C5.tmp
25.12.2005 18:30 0 g5eB5.tmp
25.12.2005 17:03 0 25i2C.tmp
25.12.2005 16:15 16.384 ~DF4D2.tmp
25.12.2005 13:57 16.384 ~DF3CE.tmp
24.12.2005 17:07 16.384 ~DFD7FD.tmp
24.12.2005 12:08 4.132 bt4180.bat
23.12.2005 22:42 16.384 ~DFE311.tmp
23.12.2005 21:22 4.132 bt1432.bat
23.12.2005 21:17 4.132 bt8586.bat
23.12.2005 20:13 16.384 ~DFC4CC.tmp
23.12.2005 18:32 4.132 bt7201.bat
23.12.2005 17:30 16.384 ~DFD246.tmp
23.12.2005 14:54 4.132 bt4617.bat
23.12.2005 14:45 16.384 ~DFC6BE.tmp
22.12.2005 22:05 16.384 ~DFE9C5.tmp
22.12.2005 20:07 4.132 bt8211.bat
22.12.2005 19:56 16.384 ~DFB5C7.tmp
22.12.2005 09:37 16.384 ~DF1AAE.tmp
21.12.2005 18:04 16.384 ~DF7798.tmp
21.12.2005 17:29 4.132 bt8828.bat
20.12.2005 21:58 16.384 ~DF4605.tmp
20.12.2005 21:27 92.864 au_setuph.dll
20.12.2005 21:27 9.920 au_res.dll
20.12.2005 21:27 302.611 au_all.cab
20.12.2005 21:27 602 manifest.cfg
20.12.2005 21:27 14.238 msntb.cfg
20.12.2005 17:27 16.384 ~DF6339.tmp
20.12.2005 15:04 4.132 bt7451.bat
20.12.2005 12:38 0 5dv62.tmp
19.12.2005 23:25 16.384 ~DF45E9.tmp
19.12.2005 22:17 0 9w5553.tmp
18.12.2005 23:48 16.384 ~DFA02F.tmp
18.12.2005 17:31 3 Twain001.Mtx
18.12.2005 17:31 695 TWAIN.LOG
18.12.2005 17:31 156 Twunk001.MTX
18.12.2005 15:42 16.384 ~DF4945.tmp
18.12.2005 15:34 16.384 ~DF9C98.tmp
15.12.2005 21:07 16.384 ~DF2A99.tmp
15.12.2005 20:40 4.132 bt0068.bat
15.12.2005 20:40 4.132 bt6465.bat
15.12.2005 20:36 16.384 ~DFC4FE.tmp
15.12.2005 17:27 4.132 bt7540.bat
15.12.2005 17:27 4.132 bt7743.bat
15.12.2005 17:26 4.132 bt2678.bat
Logfile of HijackThis v1.99.1
Scan saved at 16:52:22, on 25.01.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\WINDOWS\system32\nvctrl.exe
C:\WINDOWS\system32\rundll32.exe
C:\acer\epm\epm-dm.exe
C:\Programme\Centrino HC\Centrino_HC.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\Programme\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\NMain.exe
C:\Programme\Norton AntiVirus\navapsvc.exe
C:\Programme\Norton AntiVirus\SAVScan.exe
C:\PROGRA~1\NORTON~1\navw32.exe
C:\Programme\Winamp\Winamp.exe
C:\Programme\Opera\Opera.exe
C:\DOKUME~1\Nachti\LOKALE~1\Temp\Rar$EX05.172\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://g.msn.de/0SEDEDE/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://global.acer.com
O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hp49E5.tmp
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [CentrinoHardwareControl] "C:\Programme\Centrino HC\Centrino_HC.exe" -quiet
O4 - HKLM\..\Run: [load32] C:\WINDOWS\system32\winldra.exe
O4 - HKLM\..\Run: [LManager] C:\Programme\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Programme\Gemeinsame Dateien\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programme\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: Nach Microsoft &Excel exportieren -
res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O12 - Plugin for .avi: C:\Programme\Internet Explorer\PLUGINS\npqtplugin.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{605791D1-5373-4622-930E-F57C7F057E2D}: NameServer = 217.237.149.161 217.237.150.97
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto-Protect-Dienst (navapsvc) - Symantec Corporation - C:\Programme\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programme\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Programme\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programme\Alcohol 120%\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe
So, das wars...