Warum kostenlos registrieren?

Nur als registriertes Mitglied hast Du vollen Zugriff auf alle Funktionen unserer Website. So kannst Du eigene Fragen stellen und hast die volle Übersicht über neue interessante Themen im Forum.
Jetzt kostenlos registrieren.

Login


iexplore.exe als prozess

Warnungen vor Sicherheitslücken und Hilfe beim Enfernen von Viren, Würmern und Trojanern.

iexplore.exe als prozess

Beitragvon muh am 15.09.2006, 13:37

Hi,

ich hab seit einiger zeit den prozess iexplore.exe prozess der sich immer beim Windows start, auch startet leider verbraucht er viel zu viel speicher und es sind 2 prozesse beide iexplore.exe ich benutze aber kein Internet Explorer sonder Fire Fox wie krieg ich die Prozesse weg ???

danke im Vorraus

gruß MuH :)
muh
 
Beiträge: 11
Registriert: 02.06.2006, 14:38


Re: iexplore.exe als prozess

Beitragvon prince am 15.09.2006, 14:39

muh hat geschrieben:Hi,

ich hab seit einiger zeit den prozess iexplore.exe prozess der sich immer beim Windows start, auch startet leider verbraucht er viel zu viel speicher und es sind 2 prozesse beide iexplore.exe ich benutze aber kein Internet Explorer sonder Fire Fox wie krieg ich die Prozesse weg ???


Hi,

Poste ein Hijackthis File:
Lade:
http://www.merijn.org/files/hijackthis.zip
=======
Entpacke in einen eigenen Ordner ==> Doppelklick auf: "Hijackthis.exe" ==> Haken setzen ==> [Noone of the above Just start the Programm] ==> Button [Scan] ==> Nach dem Scan [Save Logfile] Speichere es ==> Ein Editor öffnet sich: kopiere den Inhalt hierher ins Forum.
Bebilderte Kurzanleitung

cu
prince
prince
 
Beiträge: 2163
Registriert: 11.07.2005, 14:13
Wohnort: Castle country

ok fertig :)

Beitragvon muh am 15.09.2006, 15:31

Logfile of HijackThis v1.99.1
Scan saved at 15:30:56, on 15.09.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\ANYCOM\Blue USB-200-250\bin\btwdins.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\DJSNETCN.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programme\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Symphony\sw_serv.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Programme\ICQLite\ICQLite.exe
C:\Programme\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\alg.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Console\NSCSRVCE.EXE
c:\progra~1\intern~1\iexplore.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\WINDOWS\system\CmSNXeye.exe
D:\Spiele\World of Warcraft\Launcher.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Dokumente und Einstellungen\KOJIC MISA\Desktop\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.shopnav.com/sidesearch ... id=1.20031
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.shopnav.com/sidesearch ... id=1.20031
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... x_homepage


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.shopnav.com/sidesearch ... id=1.20031
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.shopnav.com/sidesearch ... id=1.20031
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... x_homepage

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.shopnav.com/sidesearch ... id=1.20031
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.shopnav.com/sidesearch ... id=1.20031
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.shopnav.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank


R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll

O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com

O2 - BHO: Band Class - {00027925-0017-4faf-9539-90E4AC0B9EC5} - C:\WINDOWS\eltt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: metaspinner media GmbH - {12FC9A49-CFE0-49AA-BE9E-8F4EEAFC9443} - C:\Programme\Yetisports\IEButtonYetiSportsEBayInterface.dll
O2 - BHO: CBundleObj Object - {447160CD-ECF5-4EA2-8A8A-1F70CA363F85} - c:\program files\clientman\run\bundleaef94639.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: IAdvertisementBHO Class - {80672997-D58C-4190-9843-C6C61AF8FE97} - C:\WINDOWS\rundll16.dll (file missing)
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programme\Gemeinsame Dateien\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programme\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: WhenUSearch Helper - {BA2325ED-F9EB-4830-8FCE-0BC35B16969B} - C:\Programme\WhenUSearch\search.dll (file missing)
O2 - BHO: (no name) - {E8BD8185-320E-3377-A1E3-E1DAD8B95F44} - C:\DOKUME~1\KOJICM~2\ANWEND~1\MEETAMEN\FRAG SOAP.exe
O3 - Toolbar: (no name) - {2CF0B992-5EEB-4143-99C2-5297EF71F44B} - (no file)
O3 - Toolbar: (no name) - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - (no file)
O3 - Toolbar: (no name) - {FE6BC4EF-5676-484B-88AE-883323913256} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programme\Gemeinsame Dateien\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programme\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Programme\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Rundll32_7] rundll32.exe C:\WINDOWS\System32\msiefr40.dll,DllRunServer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AdRoarUpdate] C:\WINDOWS\ARUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Configuration] PESVLWM.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [qjmvgzsb] C:\WINDOWS\qjmvgzsb.exe
O4 - HKLM\..\Run: [urijcn] C:\WINDOWS\urijcn.exe

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe /onreboot
O4 - HKLM\..\Run: [fknmtmn] C:\WINDOWS\fknmtmn.exe
O4 - HKLM\..\Run: [Prein] C:\DOKUME~1\KOJICM~2\LOKALE~1\Temp\app63.tmp
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WhenUSearch] "C:\Programme\WhenUSearch\Search.exe"
O4 - HKLM\..\Run: [WhenUSearchWHSE] "C:\Programme\WhenUSearch\whse.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [eltupt] C:\WINDOWS\eltupt.exe
O4 - HKLM\..\Run: [smanp] C:\DOKUME~1\KOJICM~1\LOKALE~1\Temp\app4F.tmp
O4 - HKLM\..\Run: [shimdumbroaminter] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Boobwarnshimdumb\BROWSE WIN.exe

O4 - HKLM\..\Run: [ToADiMon.exe] C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe -TOnlineAutodialStart
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NetPumper] "C:\Programme\NetPumper\NetPumperIEProxy.exe"
O4 - HKLM\..\Run: [ICQ Lite] "C:\Programme\ICQLite\ICQLite.exe" -minimize
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\RunServices: [KERNEL32] kernel32.exe
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Programme\Gemeinsame Dateien\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [Red Swoosh EDN Client] C:\Programme\RSNet\RSEDNClient.exe
O4 - HKCU\..\Run: [LDM] C:\Programme\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Programme\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\spiele\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [InfoCockpit] C:\Programme\T-Online\T-Online_Software_6\Info-Cockpit\INFOCOCKPIT.EXE /nosplash
O4 - HKCU\..\Run: [Bone Sixth] C:\DOKUME~1\KOJICM~2\ANWEND~1\Grimref\copy type cast.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Gigaset H48data Konfiguration.lnk = C:\Programme\Symphony\maestro.exe
O4 - Global Startup: Mauseigenschaften (2).lnk = C:\WINDOWS\system32\control.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: Alles mit FlashGet laden - C:\Programme\FlashGet\jc_all.htm
O8 - Extra context menu item: Download with NetPumper - C:\Programme\NetPumper\AddUrl.htm
O8 - Extra context menu item: Mit FlashGet laden - C:\Programme\FlashGet\jc_link.htm
O8 - Extra context menu item: Senden an &Bluetooth - C:\Programme\ANYCOM\Blue USB-200-250\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - d:\spiele\MICROS~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - d:\spiele\MICROS~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - d:\spiele\MICROS~1\INetRepl.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ANYCOM\Blue USB-200-250\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ANYCOM\Blue USB-200-250\btsendto_ie.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'spacklsp.dll' missing
O16 - DPF: {861FDA2A-2B57-4BDA-8B8B-305C9D5D8604} (_Multimedia Player) - http://stream.pussyharem.com/stream/mmp.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O18 - Protocol: bw+0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: offline-8876480 - {FC319D1C-FA5B-4EAE-B131-DDF3D7188FEF} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Filter: text/html - {CC905FF6-B553-496C-9DFA-CFF65ADCD0FC} - c:\program files\clientman\run\searchrep4acf6c0b.dll
O20 - AppInit_DLLs: pushow50.dll
O20 - Winlogon Notify: switcher - C:\WINDOWS\SYSTEM32\sw_note.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programme\ANYCOM\Blue USB-200-250\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Programme\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programme\Norton Internet Security\comHost.exe
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\DJSNETCN.exe
O23 - Service: Norton AntiVirus Auto-Protect-Dienst (navapsvc) - Symantec Corporation - C:\Programme\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programme\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symphony Switcher Service - Unknown owner - C:\Programme\Symphony\sw_serv.exe
O23 - Service: T-Online DSL-Manager (TODslService) - T-Systems International GmbH - C:\Programme\T-Online\DSL-Manager\TODslSvc.exe
muh
 
Beiträge: 11
Registriert: 02.06.2006, 14:38

Beitragvon Nikita am 16.09.2006, 14:33

stelle den CleanUp genauso ein, wie hier angegeben:
http://virus-protect.org/cleanup.html

Kopiere diese 4 Textdateien ab . (rechtsklick mit der Maus -> den Text markieren -> kopieren -> einfügen) Sie sind nach Datum geordnet. (kopiere nur die letzten 3 Monate ab)
http://virus-protect.org/datfindbat.html

Den folgenden Text in den Editor (Start - Zubehör - Editor) kopieren und als listen.bat mit 'Speichern unter' auf dem Desktop. Gebe bei Dateityp 'Alle Dateien' an. Du solltest jetzt auf dem Desktop diese Datei finden. --> die listen.bat doppelt klicken--> kopiere den Text, der erscheint
cd\
dir "C:\Programme\RSNet" >>files.txt
dir "c:\program files\clientman\run" >>files.txt
dir "c:\program files\clientman" >>files.txt
dir "C:\Programme\WhenUSearch" >>files.txt
dir "C:\WINDOWS\Downloaded Program Files" >>files.txt
dir "C:\Programme\Common Files" >>files.txt
dir "C:\Dokumente und Einstellungen\%UserName%" >>files.txt
dir "C:\Program Files" >>files.txt
dir "C:\Dokumente und Einstellungen\%UserName%\Lokale Einstellungen\Temp" >>files.txt
dir "C:\WINDOWS\Temp" >>files.txt
dir "C:\Temp" >>files.txt
dir "C:\Programme" >>files.txt
dir "C:\Dokumente und Einstellungen\%UserName%\Lokale Einstellungen\Anwendungsdaten" >>files.txt
dir "C:\Dokumente und Einstellungen\%UserName%\Anwendungsdaten" >>files.txt
dir "C:\Dokumente und Einstellungen\All Users\Anwendungsdaten" >>files.txt
dir "C:\Programme\Gemeinsame Dateien" >>files.txt
dir "C:Windows\tasks" >>files.txt
notepad files.txt
Nikita
Moderator
 
Beiträge: 11478
Registriert: 07.12.2003, 16:53
Wohnort: Lissabon

Beitragvon muh am 18.09.2006, 14:20

CleanUp! Ausgeführt!


Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 20B6-75ED

Verzeichnis von C:\WINDOWS\system32

18.09.2006 14:09 2.206 wpa.dbl
18.09.2006 14:09 3.725 nvapps.xml
13.09.2006 16:14 8.775 jupdate-1.5.0_08-b03.log
11.09.2006 19:37 8.960.936 MRT.exe
21.08.2006 14:26 16.896 fltlib.dll
21.08.2006 11:14 23.040 fltmc.exe
29.07.2006 19:32 48.936 sirenacm.dll
28.07.2006 13:28 3.075.072 mshtml.dll
27.07.2006 15:25 679.424 inetcomm.dll
26.07.2006 03:03 127.078 javaws.exe
26.07.2006 03:03 49.265 jpicpl32.cpl
26.07.2006 01:26 53.346 javaw.exe
26.07.2006 01:25 49.248 java.exe
25.07.2006 22:33 615.936 urlmon.dll
21.07.2006 10:29 72.704 hlink.dll
17.07.2006 14:46 381.692 perfh009.dat
17.07.2006 14:46 53.436 perfc009.dat
17.07.2006 14:46 392.512 perfh007.dat
17.07.2006 14:46 64.452 perfc007.dat
17.07.2006 14:46 902.652 PerfStringBackup.INI
14.07.2006 17:38 332.288 netapi32.dll
14.07.2006 17:25 546.304 hhctrl.ocx
13.07.2006 15:34 8.494.592 shell32.dll
05.07.2006 12:55 1.057.792 kernel32.dll


Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 20B6-75ED

Verzeichnis von C:\DOKUME~1\KOJICM~2\LOKALE~1\Temp

18.09.2006 14:14 173 jusched.log
18.09.2006 14:12 16.384 ~DF8F32.tmp
18.09.2006 14:09 224 WCESCOMM.LOG
3 Datei(en) 16.781 Bytes
0 Verzeichnis(se), 8.460.210.176 Bytes frei



Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 20B6-75ED

Verzeichnis von C:\WINDOWS

18.09.2006 14:09 54.156 QTFont.qfn
18.09.2006 14:09 65 iTouch.ini
18.09.2006 14:08 0 0.log
18.09.2006 14:08 4.362 ModemLog_V9X HAM 1394V.txt
18.09.2006 14:08 159 wiadebug.log
18.09.2006 14:08 1.274.052 WindowsUpdate.log
18.09.2006 14:08 50 wiaservc.log
18.09.2006 14:07 2.048 bootstat.dat
18.09.2006 14:06 32.468 SchedLgU.Txt
18.09.2006 13:58 81.920 unist2.exe
18.09.2006 13:44 7.280 kwv2.dat
15.09.2006 12:58 8.971 WgaNotify.log
15.09.2006 12:58 328.876 setupapi.log
14.09.2006 19:40 235.765 ntdtcsetup.log
14.09.2006 19:40 444.044 tsoc.log
14.09.2006 19:40 147.652 iis6.log
14.09.2006 19:40 359.756 comsetup.log
14.09.2006 19:40 55.466 ocmsn.log
14.09.2006 19:40 1.374 imsins.log
14.09.2006 19:40 12.336 KB920685.log
14.09.2006 19:40 693.153 ocgen.log
14.09.2006 19:40 54.462 msgsocm.log
14.09.2006 19:40 1.075.917 FaxSetup.log
14.09.2006 19:40 1.374 imsins.BAK
14.09.2006 19:40 14.073 KB920872.log
14.09.2006 19:40 12.535 KB919007.log
14.09.2006 19:40 8.209 KB922582.log
14.09.2006 19:40 36.454 updspapi.log
14.09.2006 18:59 116 NeroDigital.ini
25.08.2006 13:28 1.409 QTFont.for
23.08.2006 23:46 60.548 War3Unin.dat
23.08.2006 23:44 2.829 War3Unin.pif
23.08.2006 23:44 139.264 War3Unin.exe
23.08.2006 14:54 233 system.ini
21.08.2006 01:44 15.618 KB920214.log
21.08.2006 01:43 15.443 KB921883.log
21.08.2006 01:43 15.193 KB922616.log
21.08.2006 01:43 15.654 KB921398.log
21.08.2006 01:42 18.929 KB918899.log
21.08.2006 01:42 11.575 KB920670.log
21.08.2006 01:42 11.732 KB917422.log
21.08.2006 01:42 12.068 KB920683.log
21.08.2006 01:38 118.784 bwUnin-7.2.0.157-8876480SL.exe
30.07.2006 13:58 324 setupact.log
20.07.2006 11:46 12.688 wmsetup.log
15.07.2006 20:01 11.834 KB917159.log
15.07.2006 20:01 12.344 KB914388.log
15.07.2006 20:01 10.380 KB916595.log


Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 20B6-75ED

Verzeichnis von C:\

18.09.2006 14:17 0 sys.txt
18.09.2006 14:16 18.827 system.txt
18.09.2006 14:15 394 systemtemp.txt
18.09.2006 14:14 122.701 system32.txt
18.09.2006 14:06 943.718.400 pagefile.sys
28.02.2006 22:15 2.058 tracert.txt
09.02.2006 13:59 368 TO_InstallLog.txt
22.01.2006 22:45 150 YServer.txt
muh
 
Beiträge: 11
Registriert: 02.06.2006, 14:38

listen.bat

Beitragvon muh am 18.09.2006, 14:46

Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 20B6-75ED

Verzeichnis von C:\Programme\RSNet

30.12.2004 12:02 <DIR> .
30.12.2004 12:02 <DIR> ..
30.10.2004 14:39 507.025 ClientCoreLib-1.020-4720.dll
24.12.2004 16:28 514.152 ClientCoreLib-1.021-4780.dll
21.04.2003 00:05 155 install.ini
05.10.2004 18:50 0 metadata.txt
21.04.2003 00:05 0 precache.txt
22.12.2003 12:40 123.989 RSEDNClientUninstaller.exe
24.12.2004 16:28 7.358 upgrade.txt
7 Datei(en) 1.152.679 Bytes
2 Verzeichnis(se), 8.455.057.408 Bytes frei
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 20B6-75ED

Verzeichnis von c:\program files\clientman\run

10.10.2005 21:30 <DIR> .
10.10.2005 21:30 <DIR> ..
27.08.2003 11:42 <DIR> data
18.04.2004 20:28 44.544 iezula581a92c3.dll
18.04.2004 20:28 119.296 imcasebb116505.dll
18.04.2004 20:28 152.064 isidesearch4955ecbd.dll
04.01.2004 13:20 222.208 newadse27968c4.dll
18.04.2004 20:28 217.088 searchrep4acf6c0b.dll
5 Datei(en) 755.200 Bytes
3 Verzeichnis(se), 8.455.053.312 Bytes frei
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 20B6-75ED

Verzeichnis von c:\program files\clientman

23.02.2006 17:27 <DIR> .
23.02.2006 17:27 <DIR> ..
22.05.2004 12:51 648 client.cfg
10.10.2005 21:30 <DIR> new
10.10.2005 21:30 <DIR> run
29.12.2004 22:13 4 update.tim
2 Datei(en) 652 Bytes
4 Verzeichnis(se), 8.455.053.312 Bytes frei
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 20B6-75ED

Verzeichnis von C:\Programme

Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 20B6-75ED

Verzeichnis von C:\WINDOWS\Downloaded Program Files

02.01.2003 16:17 18.888 574.exe
04.02.2004 22:51 241.664 ax_mjpeg.ocx
01.10.2002 13:49 1.154 cci.inf
25.07.2002 17:13 24.576 dwusplay.dll
25.07.2002 17:13 196.608 dwusplay.exe
28.03.2002 17:05 1.268 erma.inf
13.01.2003 13:06 345.600 ffav.dll
25.07.2002 17:05 172.032 isusweb.dll
20.01.2000 16:25 1.162 Microsoft XML Parser for Java.osd
04.02.2004 22:51 281 mmp.inf
16.11.2002 22:08 36.864 MsnChat40de-de.dll
04.06.2002 13:14 278 MsnChat42.inf
04.06.2002 14:52 420.168 MSNChat42.ocx
18.11.2002 17:28 278 MSNChat45.inf
19.11.2002 17:59 457.280 MSNChat45.ocx
18.12.2002 13:00 341.072 Play365.dll
18.12.2002 12:57 477 play365.inf
22.12.1999 18:42 544.768 PresentCtl.dll
16.04.2002 15:03 483.328 PWActiveXImgCtl.dll
13.09.2002 11:56 144 QTPlugin.inf
15.12.2002 16:13 802 QuickTimeInstallCache.qdat
23.07.2002 15:38 274 SaveInst.inf
26.02.2004 13:41 3.888 swflash.inf
23 Datei(en) 3.292.854 Bytes
0 Verzeichnis(se), 8.455.053.312 Bytes frei
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 20B6-75ED

Verzeichnis von C:\Programme\Common Files

03.02.2005 17:05 <DIR> .
03.02.2005 17:05 <DIR> ..
06.05.2005 21:45 <DIR> Microsoft Shared
31.12.2003 17:23 <DIR> System
0 Datei(en) 0 Bytes
4 Verzeichnis(se), 8.455.053.312 Bytes frei
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: 20B6-75ED

Verzeichnis von C:\Dokumente und Einstellungen\KOJIC MISA

12.09.2006 12:43 <DIR> .
12.09.2006 12:43 <DIR> ..
08.09.2003 21:13 <DIR> .java
08.09.2003 21:14 <DIR> .jpi_cache
13.09.2006 16:15 <DIR> .limewire
12.09.2006 12:43 823 .plugin141_04.trace
22.07.2003 12:16 <DIR> Application Data
20.07.2006 11:39 <DIR> Bluetooth Software
21.08.2006 13:32 <DIR> Contacts
02.01.2003 16:50 25 Default.PLS
18.09.2006 14:45 <DIR> Desktop
25.08.2006 13:44 <DIR> Eigene Dateien
12.07.2006 20:26 <DIR> Favoriten
02.08.2003 23:22 2 filter.dat
27.01.2005 21:31 <DIR> Incomplete
02.08.2003 23:22 142 serverlist.dat
10.02.2005 21:18 <DIR> Shared
19.07.2003 18:02 <DIR> Start Menu
03.03.2006 13:40 <DIR> Startmen
muh
 
Beiträge: 11
Registriert: 02.06.2006, 14:38

Beitragvon Nikita am 18.09.2006, 16:19

Avenger
http://virus-protect.org/artikel/tools/avenger.html
kopiere rein

Files to delete:
C:\WINDOWS\eltt.dll
C:\WINDOWS\unist2.exe
C:\WINDOWS\urijcn.exe
C:\WINDOWS\kwv2.dat
C:\WINDOWS\qjmvgzsb.exe
C:\WINDOWS\ARUpdate.exe
C:\WINDOWS\System32\pushow50.dll
C:\WINDOWS\System32\msiefr40.dll
C:\WINDOWS\System32\Cpr.dll
C:\WINDOWS\Downloaded Program Files\574.exe
C:\Dokumente und Einstellungen\KOJIC MISA\Lokale Einstellungen\Temp\app63.tmp
C:\Dokumente und Einstellungen\KOJIC MISA\Lokale Einstellungen\Temp\app4F.tmp

Folders to delete:
C:\Programme\Save
C:\Programme\websearch
C:\Programme\RSNet
C:\Program Files\ClientMan
C:\Programme\Anti-Leech
C:\Programme\CasinoOnNet
C:\Programme\HbTools
C:\Programme\HbTools_Icons
C:\Programme\MediaLoads
C:\Programme\NetPumper
C:\Programme\Power Scan
C:\Programme\Yetisports
C:\Dokumente und Einstellungen\KOJIC MISA\Anwendungsdaten\HbTools
C:\Dokumente und Einstellungen\KOJIC MISA\Anwendungsdaten\NetPumper
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Boobwarnshimdumb
C:\Programme\Gemeinsame Dateien\tppnjcbn
C:\Programme\Gemeinsame Dateien\fun communications

Klicke die gruene Ampel
das Script wird nun ausgeführt, dann wird der PC automatisch neustarten

**
poste den scanreport vom avenger, der nach neustart erscheint


**
öffne das HijackThis -- Button "scan" -- vor die Malware-Einträge Häkchen setzen -- Button "Fix checked" -- PC neustarten
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.shopnav.com/sidesearch ... id=1.20031
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.shopnav.com/sidesearch ... id=1.20031
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... x_homepage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.shopnav.com/sidesearch ... id=1.20031
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.shopnav.com/sidesearch ... id=1.20031
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... x_homepage

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.shopnav.com/sidesearch ... id=1.20031
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.shopnav.com/sidesearch ... id=1.20031
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.shopnav.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank

O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com

O2 - BHO: Band Class - {00027925-0017-4faf-9539-90E4AC0B9EC5} - C:\WINDOWS\eltt.dll

O2 - BHO: CBundleObj Object - {447160CD-ECF5-4EA2-8A8A-1F70CA363F85} - c:\program files\clientman\run\bundleaef94639.dll (file missing)

O2 - BHO: IAdvertisementBHO Class - {80672997-D58C-4190-9843-C6C61AF8FE97} - C:\WINDOWS\rundll16.dll (file missing)

O2 - BHO: WhenUSearch Helper - {BA2325ED-F9EB-4830-8FCE-0BC35B16969B} - C:\Programme\WhenUSearch\search.dll (file missing)
O2 - BHO: (no name) - {E8BD8185-320E-3377-A1E3-E1DAD8B95F44} - C:\DOKUME~1\KOJICM~2\ANWEND~1\MEETAMEN\FRAG SOAP.exe
O3 - Toolbar: (no name) - {2CF0B992-5EEB-4143-99C2-5297EF71F44B} - (no file)
O3 - Toolbar: (no name) - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - (no file)
O3 - Toolbar: (no name) - {FE6BC4EF-5676-484B-88AE-883323913256} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O4 - HKLM\..\Run: [Rundll32_7] rundll32.exe C:\WINDOWS\System32\msiefr40.dll,DllRunServer

O4 - HKLM\..\Run: [AdRoarUpdate] C:\WINDOWS\ARUpdate.exe

O4 - HKLM\..\Run: [Windows Configuration] PESVLWM.EXE

O4 - HKLM\..\Run: [qjmvgzsb] C:\WINDOWS\qjmvgzsb.exe
O4 - HKLM\..\Run: [urijcn] C:\WINDOWS\urijcn.exe

O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe /onreboot
O4 - HKLM\..\Run: [fknmtmn] C:\WINDOWS\fknmtmn.exe
O4 - HKLM\..\Run: [Prein] C:\DOKUME~1\KOJICM~2\LOKALE~1\Temp\app63.tmp
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WhenUSearch] "C:\Programme\WhenUSearch\Search.exe"
O4 - HKLM\..\Run: [WhenUSearchWHSE] "C:\Programme\WhenUSearch\whse.exe"

O4 - HKLM\..\Run: [smanp] C:\DOKUME~1\KOJICM~1\LOKALE~1\Temp\app4F.tmp
O4 - HKLM\..\Run: [shimdumbroaminter] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Boobwarnshimdumb\BROWSE WIN.exe

O4 - HKLM\..\Run: [NetPumper] "C:\Programme\NetPumper\NetPumperIEProxy.exe"

O4 - HKCU\..\Run: [Red Swoosh EDN Client] C:\Programme\RSNet\RSEDNClient.exe

O4 - HKCU\..\Run: [Bone Sixth] C:\DOKUME~1\KOJICM~2\ANWEND~1\Grimref\copy type cast.exe

O8 - Extra context menu item: Download with NetPumper - C:\Programme\NetPumper\AddUrl.htm

O18 - Filter: text/html - {CC905FF6-B553-496C-9DFA-CFF65ADCD0FC} - c:\program files\clientman\run\searchrep4acf6c0b.dll
O20 - AppInit_DLLs: pushow50.dll
O20 - Winlogon Notify: switcher - C:\WINDOWS\SYSTEM32\sw_note.dll


scanne mit counterspy, stelle nach dem scan alles auf remove und poste den scanreport
http://virus-protect.org/counterspy.html
Nikita
Moderator
 
Beiträge: 11478
Registriert: 07.12.2003, 16:53
Wohnort: Lissabon

Beitragvon muh am 19.09.2006, 14:45

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\ealfnjfd

*******************

Script file located at: \??\C:\WINDOWS\system32\jaeihcqc.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\eltt.dll deleted successfully.
File C:\WINDOWS\unist2.exe deleted successfully.


File C:\WINDOWS\urijcn.exe not found!
Deletion of file C:\WINDOWS\urijcn.exe failed!

Could not process line:
C:\WINDOWS\urijcn.exe
Status: 0xc0000034

File C:\WINDOWS\kwv2.dat deleted successfully.


File C:\WINDOWS\qjmvgzsb.exe not found!
Deletion of file C:\WINDOWS\qjmvgzsb.exe failed!

Could not process line:
C:\WINDOWS\qjmvgzsb.exe
Status: 0xc0000034



File C:\WINDOWS\ARUpdate.exe not found!
Deletion of file C:\WINDOWS\ARUpdate.exe failed!

Could not process line:
C:\WINDOWS\ARUpdate.exe
Status: 0xc0000034

File C:\WINDOWS\System32\pushow50.dll deleted successfully.


File C:\WINDOWS\System32\msiefr40.dll not found!
Deletion of file C:\WINDOWS\System32\msiefr40.dll failed!

Could not process line:
C:\WINDOWS\System32\msiefr40.dll
Status: 0xc0000034

File C:\WINDOWS\System32\Cpr.dll deleted successfully.
File C:\WINDOWS\Downloaded Program Files\574.exe deleted successfully.


File C:\Dokumente und Einstellungen\KOJIC MISA\Lokale Einstellungen\Temp\app63.tmp not found!
Deletion of file C:\Dokumente und Einstellungen\KOJIC MISA\Lokale Einstellungen\Temp\app63.tmp failed!

Could not process line:
C:\Dokumente und Einstellungen\KOJIC MISA\Lokale Einstellungen\Temp\app63.tmp
Status: 0xc0000034



File C:\Dokumente und Einstellungen\KOJIC MISA\Lokale Einstellungen\Temp\app4F.tmp not found!
Deletion of file C:\Dokumente und Einstellungen\KOJIC MISA\Lokale Einstellungen\Temp\app4F.tmp failed!

Could not process line:
C:\Dokumente und Einstellungen\KOJIC MISA\Lokale Einstellungen\Temp\app4F.tmp
Status: 0xc0000034

Folder C:\Programme\Save deleted successfully.
Folder C:\Programme\websearch deleted successfully.
Folder C:\Programme\RSNet deleted successfully.
Folder C:\Program Files\ClientMan deleted successfully.
Folder C:\Programme\Anti-Leech deleted successfully.
Folder C:\Programme\CasinoOnNet deleted successfully.
Folder C:\Programme\HbTools deleted successfully.
Folder C:\Programme\HbTools_Icons deleted successfully.
Folder C:\Programme\MediaLoads deleted successfully.
Folder C:\Programme\NetPumper deleted successfully.
Folder C:\Programme\Power Scan deleted successfully.
Folder C:\Programme\Yetisports deleted successfully.
Folder C:\Dokumente und Einstellungen\KOJIC MISA\Anwendungsdaten\HbTools deleted successfully.
Folder C:\Dokumente und Einstellungen\KOJIC MISA\Anwendungsdaten\NetPumper deleted successfully.
Folder C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Boobwarnshimdumb deleted successfully.
Folder C:\Programme\Gemeinsame Dateien\tppnjcbn deleted successfully.
Folder C:\Programme\Gemeinsame Dateien\fun communications deleted successfully.

Completed script processing.

*******************

Finished! Terminate.
muh
 
Beiträge: 11
Registriert: 02.06.2006, 14:38

Counter Spy

Beitragvon muh am 19.09.2006, 18:21

Spyware Scan Details
Start Date: 19.09.2006 15:20:50
End Date: 19.09.2006 16:56:08
Total Time: 1 hrs 35 mins 18 secs

Detected spyware

IEPlugin Adware (General) more information...
Details: IEPlugin is an IE Browser Helper Object that monitors site addresses, content entered into forms, and even local filenames browsed, and pops up advertisements when it sees a targeted keyword.
Status: Deleted

Infected files detected
c:\windows\eltupt.exe
c:\windows\lu.dat
C:\Dokumente und Einstellungen\KOJIC MILAN\Lokale Einstellungen\Temp\eltupt.exe

Infected registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run eltupt
HKEY_CURRENT_USER\Software\intexp
HKEY_CURRENT_USER\Software\intexp\Config SystemDate 09/19/06
HKEY_CURRENT_USER\Software\intexp\Config InstallDay 3.853071E+004
HKEY_CURRENT_USER\Software\intexp\Config LogUrl 1
HKEY_CURRENT_USER\Software\intexp\Config KeywordMatch 0
HKEY_CURRENT_USER\Software\intexp\Config LeftPanel 1
HKEY_CURRENT_USER\Software\intexp\Config PostCGITime 44940
HKEY_CURRENT_USER\Software\intexp\MyFileSystem2 SystemID 11083418
HKEY_CURRENT_USER\Software\intexp version 1.20031
HKEY_CLASSES_ROOT\remove


Spybot CC Backdoor more information...
Details: Spybot-CC is a backdoor Trojan and worm which spreads via file sharing on Kazaa P2P networks and by copying itself to network shares that have weak password protection on the $ADMIN share.
Status: Deleted


BrowserAid Browser Plug-in more information...
Details: BrowserAid is a group of Internet Explorer software toolbars which are installed without the users consent (most).
Status: Deleted

Infected files detected
c:\dokumente und einstellungen\kojic misa\anwendungsdaten\browser pal\pstopper.sts
c:\windows\system32\stlbupdt.dll

Infected registry entries detected
HKEY_CLASSES_ROOT\bho.iadvertisementbho.1
HKEY_CLASSES_ROOT\bho.iadvertisementbho.1\CLSID {80672997-D58C-4190-9843-C6C61AF8FE97}
HKEY_CLASSES_ROOT\bho.iadvertisementbho.1 IAdvertisementBHO Class
HKEY_CLASSES_ROOT\bho.iadvertisementbho
HKEY_CLASSES_ROOT\bho.iadvertisementbho\CLSID {80672997-D58C-4190-9843-C6C61AF8FE97}
HKEY_CLASSES_ROOT\bho.iadvertisementbho\CurVer bho.IAdvertisementBHO.1
HKEY_CLASSES_ROOT\bho.iadvertisementbho IAdvertisementBHO Class
HKEY_CLASSES_ROOT\typelib\{85c2c2a1-3f20-4ead-adc3-bd3217391543}
HKEY_CLASSES_ROOT\typelib\{85c2c2a1-3f20-4ead-adc3-bd3217391543}\1.0\0\win32 C:\WINDOWS\rundll16.dll
HKEY_CLASSES_ROOT\typelib\{85c2c2a1-3f20-4ead-adc3-bd3217391543}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\typelib\{85c2c2a1-3f20-4ead-adc3-bd3217391543}\1.0\HELPDIR C:\WINDOWS\
HKEY_CLASSES_ROOT\typelib\{85c2c2a1-3f20-4ead-adc3-bd3217391543}\1.0 bho 1.0 Type Library
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate\Active 00 1046780210
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate\Active 06 1050672208
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate\Active 07 1051869104
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate\Active 12 1067642666
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate\Installed mads100
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate\Installed hp100
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate\Installed mads102
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate\Installed fr100
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate\Installed hp101
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate\Installed stupdt
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate Gid 583820241035506028884704756352
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate LastNI 1067642656
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate Country DE


NetPumper Adware Bundler more information...
Details: Bundles with a number of adware components.
Status: Deleted

Infected files detected
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\netpumper help.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\netpumper.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\readme.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\shutdown netpumper.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\uninstall netpumper.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\anti-leech\install plugin for ms internet explorer.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\anti-leech\install plugin for netscape, mozilla, opera.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\anti-leech\license.lnk

Infected registry entries detected
HKEY_CLASSES_ROOT\NetPumperNNProxy.NetscapeInterface
HKEY_CLASSES_ROOT\NetPumperNNProxy.NetscapeInterface\CLSID {E19B133D-184E-4BBA-8A70-38489C9DD31B}
HKEY_CLASSES_ROOT\NetPumperNNProxy.NetscapeInterface NetscapeInterface Object
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetPumper_is1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetPumper_is1 Inno Setup: Setup Version 2.0.18 with ISX 2.0.18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetPumper_is1 Inno Setup: App Path C:\Programme\NetPumper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetPumper_is1 Inno Setup: Icon Group NetPumper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetPumper_is1 Inno Setup: User KOJIC MISA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetPumper_is1 Inno Setup: Setup Type standard
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetPumper_is1 Inno Setup: Selected Components netpumper,zone__np_0001,alie,alnn
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetPumper_is1 Inno Setup: Deselected Components
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetPumper_is1 DisplayName NetPumper 1.25.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetPumper_is1 UninstallString C:\Programme\NetPumper\unins000.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetPumper_is1 DisplayVersion 1.25.1
HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-netpumper-detector
HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-netpumper-detector Extension .xnpd
HKEY_CLASSES_ROOT\NetPumper.AddUrl
HKEY_CLASSES_ROOT\NetPumper.AddUrl\CLSID {1AA406AB-F581-42AB-B4D1-31D2E13819EF}
HKEY_CLASSES_ROOT\NetPumper.AddUrl AddUrl Object
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper\Affiliated\free\Firstrun state 2
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper\Installed state 2
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper VersionInfo GEZ3XqQM1B+KNTKdpD812nqGRUcYq7UxkS2dE9XYuIsK+VtU0FsGtXdSa8UzcZv06-q5Hsx-SOsK0Y0Br1MX3ExPhDyJtYPGmFWlAdvsUu0zi62-uxf0UMnzqJeG-TAx8NtvShp9IWmDuGvwX094JikO41PxPyVbZb5+f6dZtZRpSGY2orDSjIgFri6TxI8gUY3lmkFTEpSU
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper Application NetPumper
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper NEWVER http://cv.netpumper.com/
HKEY_CLASSES_ROOT\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B}
HKEY_CLASSES_ROOT\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\InprocServer32 C:\Programme\NetPumper\NetPumperNNProxy.dll
HKEY_CLASSES_ROOT\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\ProgID NetPumperNNProxy.NetscapeInterface
HKEY_CLASSES_ROOT\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\Typelib {F7258F6E-9F60-49C0-8C82-F0A0993D68E0}
HKEY_CLASSES_ROOT\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\Version 1.0
HKEY_CLASSES_ROOT\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B} NetscapeInterface Object
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\LocalServer32 C:\Programme\NetPumper\NetPumper.exe /Automation
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\LocalServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\ProgID NetPumper.AddUrl
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\Typelib {1145A909-A836-44B8-B03A-48D858B0F43E}
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\Version 1.2
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF} AddUrl Object
HKEY_CLASSES_ROOT\Interface\{A8B0F390-E6BF-4027-A4D4-1E4363F5E27B}
HKEY_CLASSES_ROOT\Interface\{A8B0F390-E6BF-4027-A4D4-1E4363F5E27B}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{A8B0F390-E6BF-4027-A4D4-1E4363F5E27B}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{A8B0F390-E6BF-4027-A4D4-1E4363F5E27B}\TypeLib {1145A909-A836-44B8-B03A-48D858B0F43E}
HKEY_CLASSES_ROOT\Interface\{A8B0F390-E6BF-4027-A4D4-1E4363F5E27B}\TypeLib Version 1.2
HKEY_CLASSES_ROOT\Interface\{A8B0F390-E6BF-4027-A4D4-1E4363F5E27B} IAddUrl
HKEY_CLASSES_ROOT\Interface\{A9E33220-0B05-11D7-88D2-444553540000}
HKEY_CLASSES_ROOT\Interface\{A9E33220-0B05-11D7-88D2-444553540000}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{A9E33220-0B05-11D7-88D2-444553540000}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{A9E33220-0B05-11D7-88D2-444553540000}\TypeLib {1145A909-A836-44B8-B03A-48D858B0F43E}
HKEY_CLASSES_ROOT\Interface\{A9E33220-0B05-11D7-88D2-444553540000}\TypeLib Version 1.2
HKEY_CLASSES_ROOT\Interface\{A9E33220-0B05-11D7-88D2-444553540000} IAddPackage
HKEY_CLASSES_ROOT\Interface\{E0ABBF96-17DC-44CA-96D0-6217064A97BA}
HKEY_CLASSES_ROOT\Interface\{E0ABBF96-17DC-44CA-96D0-6217064A97BA}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{E0ABBF96-17DC-44CA-96D0-6217064A97BA}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{E0ABBF96-17DC-44CA-96D0-6217064A97BA}\TypeLib {F7258F6E-9F60-49C0-8C82-F0A0993D68E0}
HKEY_CLASSES_ROOT\Interface\{E0ABBF96-17DC-44CA-96D0-6217064A97BA}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{E0ABBF96-17DC-44CA-96D0-6217064A97BA} INetscapeInterface
HKEY_CLASSES_ROOT\TypeLib\{1145A909-A836-44B8-B03A-48D858B0F43E}
HKEY_CLASSES_ROOT\TypeLib\{1145A909-A836-44B8-B03A-48D858B0F43E}\1.2\0\win32 C:\Programme\NetPumper\NetPumper.exe
HKEY_CLASSES_ROOT\TypeLib\{1145A909-A836-44B8-B03A-48D858B0F43E}\1.2\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{1145A909-A836-44B8-B03A-48D858B0F43E}\1.2\HELPDIR C:\Programme\NetPumper\
HKEY_CLASSES_ROOT\TypeLib\{1145A909-A836-44B8-B03A-48D858B0F43E}\1.2 NetPumper Library
HKEY_CLASSES_ROOT\TypeLib\{F7258F6E-9F60-49C0-8C82-F0A0993D68E0}
HKEY_CLASSES_ROOT\TypeLib\{F7258F6E-9F60-49C0-8C82-F0A0993D68E0}\1.0\0\win32 C:\Programme\NetPumper\NetPumperNNProxy.dll
HKEY_CLASSES_ROOT\TypeLib\{F7258F6E-9F60-49C0-8C82-F0A0993D68E0}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{F7258F6E-9F60-49C0-8C82-F0A0993D68E0}\1.0\HELPDIR C:\Programme\NetPumper\
HKEY_CLASSES_ROOT\TypeLib\{F7258F6E-9F60-49C0-8C82-F0A0993D68E0}\1.0 NetPumperNNProxy Library
HKEY_CURRENT_USER\Software\NetPumper
HKEY_CURRENT_USER\Software\NetPumper\KOJIC MISA Field1 1062844196
HKEY_CURRENT_USER\Software\NetPumper\KOJIC MISA Field2 21499785
HKEY_CURRENT_USER\Software\NetPumper\KOJIC MISA Field3 2085512238
HKEY_CURRENT_USER\Software\NetPumper\KOJIC MISA Field4 2143839533


Delfin.WebBar Browser Plug-in more information...
Details: Delfin WebBar adds a generic search bar to Internet Explorer that submits searches the authors web site.
Status: Deleted

Infected files detected
c:\programme\appliedsearch_autoinstall\bar.dll
c:\programme\appliedsearch_autoinstall\bar.ini
c:\programme\appliedsearch_autoinstall\logo.bmp

Infected registry entries detected
HKEY_CLASSES_ROOT\Interface\{6600D22D-083F-11D6-99DE-D172E92EBC2A}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{6600D22E-083F-11D6-99DE-D172E92EBC2A}\TypeLib Version 1.0


eXact.SearchBar Browser Plug-in more information...
Details: eXactSearchBar is an Internet Explorer toolbar with standard search features that performs targeted advertising based on the computer usage and the URLs associated with Web pages.
Status: Deleted

Infected files detected
c:\windows\system32\exacctsetup3.exe
c:\windows\system32\ezstubi.exe
c:\windows\system32\exactsetup.dll


Claria.GAIN.CommonElements Adware (General) more information...
Details: Claria's GAIN network consists of several applications inlcuding Gator eWallet, GotSmiley, ScreenSeenes, WebSecureAlert, DashBar, Weatherscope, Date Manager and Precision Time.
Status: Deleted

Infected files detected
c:\windows\gatorpatch.log


IGetNet Hijacker more information...
Details: IGetNet is a browser hijacker that is implemented as an Internet Explorer BHO. When you enter something into the address bar, IGetNet checks to see whether it includes keyword they have sold to one of their advertisers.
Status: Deleted

Infected files detected
c:\windows\system\update_removeold.dll
c:\windows\system\rules.dat

Infected registry entries detected
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}\InprocServer32 C:\Programme\ClearSearch\IE_ClrSch.DLL
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}\ProgID Ie_clrsch.IEHooks.1
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}\TypeLib {95B3AF07-0E4F-4CDF-ACFD-3D4EFD9AEC0B}
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}\VersionIndependentProgID Ie_clrsch.IEHooks
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313} IEHooks Class
HKEY_CLASSES_ROOT\interface\{3683fd85-0501-40dc-9edb-9d9181800d72}
HKEY_CLASSES_ROOT\interface\{3683fd85-0501-40dc-9edb-9d9181800d72}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{3683fd85-0501-40dc-9edb-9d9181800d72}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{3683fd85-0501-40dc-9edb-9d9181800d72}\TypeLib {676058DB-89BD-11D6-8A8C-0050BA8452C0}
HKEY_CLASSES_ROOT\interface\{3683fd85-0501-40dc-9edb-9d9181800d72}\TypeLib Version a1.0
HKEY_CLASSES_ROOT\interface\{3683fd85-0501-40dc-9edb-9d9181800d72} BizLgk


Transponder.MsView Adware (General) more information...
Status: Deleted

Infected files detected
c:\windows\inf\msview.inf


NewDotNet Browser Plug-in more information...
Details: New.Net is an Internet Explorer spyware/hijacker plug-in that adds subdomains of 'new.net' to your name resolution system (Windows Host file), resulting in what appear to be extra top-level domains (.shop, and so on) being resolvable.
Status: Deleted

Infected files detected
c:\windows\ndnuninstall4_50.exe


WhenU.WeatherCast Low Risk Adware more information...
Details: WeatherCast is an ad supported desktop weather program that that puts an icon in the system tray displaying the local temperature. It also offers current weather data and forecasts. Weathercast is often bundled with the Save advertising program and/or th
Status: Deleted

Infected files detected
c:\windows\downloaded program files\saveinst.inf

Infected registry entries detected
HKEY_CLASSES_ROOT\WhenU.EmbedSE
HKEY_CLASSES_ROOT\WhenU.EmbedSE\CLSID {389A5A59-1306-4389-A779-2EB9D0BC1FFB}
HKEY_CLASSES_ROOT\WhenU.EmbedSE\CurVer WhenU.EmbedSE.1
HKEY_CLASSES_ROOT\WhenU.EmbedSE WhenU EmbedSE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WeatherCast
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WeatherCast SlowInfoCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WeatherCast Changed 0


ABetterInternet Adware (General) more information...
Details: ABetterInternet shows advertisements based on the web pages you view and the web sites you visit.
Status: Deleted

Infected files detected
c:\windows\susp.ini


Comet Cursor Browser Plug-in more information...
Details: Comet Cursor is a browser pulg-in which logs web information like cookies, IP addresses etc.
Status: Deleted

Infected files detected
c:\windows\inf\dm.inf
c:\windows\inf\dm.pnf

Infected registry entries detected
HKEY_CLASSES_ROOT\CLSID\{DA0882FB-49A3-4A9E-BB09-5E15347B5647}
HKEY_CLASSES_ROOT\CLSID\{DA0882FB-49A3-4A9E-BB09-5E15347B5647}\InprocServer32 C:\PROGRA~1\COMETS~1\Platform\Bin\csadzap.dll
HKEY_CLASSES_ROOT\CLSID\{DA0882FB-49A3-4A9E-BB09-5E15347B5647}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{DA0882FB-49A3-4A9E-BB09-5E15347B5647}\ProgID Puk.PukBHO.1
HKEY_CLASSES_ROOT\CLSID\{DA0882FB-49A3-4A9E-BB09-5E15347B5647}\TypeLib {5D2D50F6-6BE2-41A0-B827-1ACCD3E2E2F7}
HKEY_CLASSES_ROOT\CLSID\{DA0882FB-49A3-4A9E-BB09-5E15347B5647}\VersionIndependentProgID Puk.PukBHO
HKEY_CLASSES_ROOT\CLSID\{DA0882FB-49A3-4A9E-BB09-5E15347B5647} PukBHO Class
HKEY_CLASSES_ROOT\CLSID\{EDC4193F-34AD-4D07-AA87-E3FDB89E3E76}
HKEY_CLASSES_ROOT\CLSID\{EDC4193F-34AD-4D07-AA87-E3FDB89E3E76}\InprocServer32 C:\PROGRA~1\COMETS~1\Platform\Bin\csband.dll
HKEY_CLASSES_ROOT\CLSID\{EDC4193F-34AD-4D07-AA87-E3FDB89E3E76}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{EDC4193F-34AD-4D07-AA87-E3FDB89E3E76} Vertical Bar
HKEY_CLASSES_ROOT\Puk.PukBHO.1
HKEY_CLASSES_ROOT\Puk.PukBHO.1\CLSID {DA0882FB-49A3-4A9E-BB09-5E15347B5647}
HKEY_CLASSES_ROOT\Puk.PukBHO.1 PukBHO Class
HKEY_CLASSES_ROOT\Puk.PukBHO
HKEY_CLASSES_ROOT\Puk.PukBHO\CLSID {DA0882FB-49A3-4A9E-BB09-5E15347B5647}
HKEY_CLASSES_ROOT\Puk.PukBHO\CurVer Puk.PukBHO.1
HKEY_CLASSES_ROOT\Puk.PukBHO PukBHO Class
HKEY_CLASSES_ROOT\TypeLib\{062EFA78-8BBB-11D3-80D0-00500487B1C5}
HKEY_CLASSES_ROOT\TypeLib\{062EFA78-8BBB-11D3-80D0-00500487B1C5}\1.0\0\win32 C:\PROGRA~1\COMETS~1\Platform\Bin\cscore.dll
HKEY_CLASSES_ROOT\TypeLib\{062EFA78-8BBB-11D3-80D0-00500487B1C5}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{062EFA78-8BBB-11D3-80D0-00500487B1C5}\1.0\HELPDIR C:\PROGRA~1\COMETS~1\Platform\Bin\
HKEY_CLASSES_ROOT\TypeLib\{062EFA78-8BBB-11D3-80D0-00500487B1C5}\1.0 CORELib
HKEY_CLASSES_ROOT\TypeLib\{3F4386E5-2FBE-44A8-81CF-4B792490605F}
HKEY_CLASSES_ROOT\TypeLib\{3F4386E5-2FBE-44A8-81CF-4B792490605F}\1.0\0\win32 C:\PROGRA~1\COMETS~1\Platform\Bin\cseng.dll
HKEY_CLASSES_ROOT\TypeLib\{3F4386E5-2FBE-44A8-81CF-4B792490605F}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{3F4386E5-2FBE-44A8-81CF-4B792490605F}\1.0\HELPDIR C:\PROGRA~1\COMETS~1\Platform\Bin\
HKEY_CLASSES_ROOT\TypeLib\{3F4386E5-2FBE-44A8-81CF-4B792490605F}\1.0 CSEng 1.0 Type Library
HKEY_CLASSES_ROOT\TypeLib\{5D2D50F6-6BE2-41A0-B827-1ACCD3E2E2F7}
HKEY_CLASSES_ROOT\TypeLib\{5D2D50F6-6BE2-41A0-B827-1ACCD3E2E2F7}\1.0\0\win32 C:\PROGRA~1\COMETS~1\Platform\Bin\csadzap.dll
HKEY_CLASSES_ROOT\TypeLib\{5D2D50F6-6BE2-41A0-B827-1ACCD3E2E2F7}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{5D2D50F6-6BE2-41A0-B827-1ACCD3E2E2F7}\1.0\HELPDIR C:\PROGRA~1\COMETS~1\Platform\Bin\
HKEY_CLASSES_ROOT\TypeLib\{5D2D50F6-6BE2-41A0-B827-1ACCD3E2E2F7}\1.0 Puk 1.0 Type Library
HKEY_CLASSES_ROOT\TypeLib\{7F0F5D9A-84CB-11D4-8137-00500487B1C5}
HKEY_CLASSES_ROOT\TypeLib\{7F0F5D9A-84CB-11D4-8137-00500487B1C5}\1.0\0\win32 C:\PROGRA~1\COMETS~1\Platform\Bin\skinui.dll
HKEY_CLASSES_ROOT\TypeLib\{7F0F5D9A-84CB-11D4-8137-00500487B1C5}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{7F0F5D9A-84CB-11D4-8137-00500487B1C5}\1.0\HELPDIR C:\PROGRA~1\COMETS~1\Platform\Bin\
HKEY_CLASSES_ROOT\TypeLib\{7F0F5D9A-84CB-11D4-8137-00500487B1C5}\1.0 SKINUILib
HKEY_CLASSES_ROOT\TypeLib\{878ACE1B-8DB0-4D75-9034-504756AD4215}
HKEY_CLASSES_ROOT\TypeLib\{878ACE1B-8DB0-4D75-9034-504756AD4215}\1.0\0\win32 C:\PROGRA~1\COMETS~1\Platform\Bin\csietb.dll
HKEY_CLASSES_ROOT\TypeLib\{878ACE1B-8DB0-4D75-9034-504756AD4215}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{878ACE1B-8DB0-4D75-9034-504756AD4215}\1.0\HELPDIR C:\PROGRA~1\COMETS~1\Platform\Bin\
HKEY_CLASSES_ROOT\TypeLib\{878ACE1B-8DB0-4D75-9034-504756AD4215}\1.0 CometIEToolbar 1.0 Type Library
HKEY_CLASSES_ROOT\TypeLib\{C09FB84D-B9ED-43EB-AFED-F145C26CB839}
HKEY_CLASSES_ROOT\TypeLib\{C09FB84D-B9ED-43EB-AFED-F145C26CB839}\1.0\0\win32 C:\PROGRA~1\COMETS~1\Platform\Bin\csband.dll
HKEY_CLASSES_ROOT\TypeLib\{C09FB84D-B9ED-43EB-AFED-F145C26CB839}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{C09FB84D-B9ED-43EB-AFED-F145C26CB839}\1.0\HELPDIR C:\PROGRA~1\COMETS~1\Platform\Bin\
HKEY_CLASSES_ROOT\TypeLib\{C09FB84D-B9ED-43EB-AFED-F145C26CB839}\1.0 CometIEBand 1.0 Type Library
HKEY_CLASSES_ROOT\TypeLib\{D14D6786-9B65-11D3-80B6-00500487BDBA}
HKEY_CLASSES_ROOT\TypeLib\{D14D6786-9B65-11D3-80B6-00500487BDBA}\1.0\0\win32 C:\PROGRA~1\COMETS~1\Platform\Bin\csbho.dll
HKEY_CLASSES_ROOT\TypeLib\{D14D6786-9B65-11D3-80B6-00500487BDBA}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{D14D6786-9B65-11D3-80B6-00500487BDBA}\1.0\HELPDIR C:\PROGRA~1\COMETS~1\Platform\Bin\
HKEY_CLASSES_ROOT\TypeLib\{D14D6786-9B65-11D3-80B6-00500487BDBA}\1.0 BHOLib
HKEY_CLASSES_ROOT\CLSID\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E}
HKEY_CLASSES_ROOT\CLSID\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E}\InprocServer32 C:\PROGRA~1\COMETS~1\Platform\Bin\csband.dll
HKEY_CLASSES_ROOT\CLSID\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E} Horizontal Bar


TopRebates.WebRebates Browser Plug-in more information...
Details: TopRebates is a browser toolbar that can display pop-up advertisements and monitor your Web browsing activities.
Status: Deleted

Infected files detected
c:\windows\artmmp.ini


FavoriteMan Browser Plug-in more information...
Details: FavoriteMan is an Internet Explorer Browser Helper Object (BHO) that intermittently connects to its controlling servers which may direct it to download and install other programs and add entries to the IE Favorites menu or background Desktop.
Status: Deleted

Infected files detected
c:\windows\system32\sysldr.dll

Infected registry entries detected
HKEY_CURRENT_USER\Software\Microsoft\Windows Counter
HKEY_CURRENT_USER\Software\Microsoft\Windows Object
HKEY_CURRENT_USER\Software\Microsoft\Windows Server


Dimpy.Win32VBsy Backdoor more information...
Details: Dimpy.Win32VBsy is a trojan that records certain keystrokes and steals other data from the infected machine.
Status: Deleted

Infected files detected
c:\windows\urls.dat


PrizeSurfer Adware (General) more information...
Details: PrizeSurfer open pop up windows in Internet Explorer.
Status: Deleted

Infected files detected
c:\windows\system32\pr1ze5.dll


My Way Speedbar Potentially Unwanted Program more information...
Details: MyWay Speedbar is a search toolbar that installs into Internet Explorer and Netscape Navigator, adding search functions and popup blocking.
Status: Deleted

Infected files detected
c:\windows\system32\xcite.dll
c:\windows\system32\xcite.exe

Infected registry entries detected
HKEY_CLASSES_ROOT\interface\{0494d0da-f8e0-41ad-92a3-14154ece70ac}
HKEY_CLASSES_ROOT\interface\{0494d0da-f8e0-41ad-92a3-14154ece70ac}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{0494d0da-f8e0-41ad-92a3-14154ece70ac}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{0494d0da-f8e0-41ad-92a3-14154ece70ac}\TypeLib {0494D0D0-F8E0-41AD-92A3-14154ECE70AC}
HKEY_CLASSES_ROOT\interface\{0494d0da-f8e0-41ad-92a3-14154ece70ac}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{0494d0da-f8e0-41ad-92a3-14154ece70ac} IMyWaySettings
HKEY_CLASSES_ROOT\typelib\{0494d0d0-f8e0-41ad-92a3-14154ece70ac}
HKEY_CLASSES_ROOT\typelib\{0494d0d0-f8e0-41ad-92a3-14154ece70ac}\1.0\0\win32 C:\Programme\MyWay\myBar\1.bin\MYBAR.DLL
HKEY_CLASSES_ROOT\typelib\{0494d0d0-f8e0-41ad-92a3-14154ece70ac}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\typelib\{0494d0d0-f8e0-41ad-92a3-14154ece70ac}\1.0\HELPDIR C:\Programme\MyWay\myBar\1.bin\
HKEY_CLASSES_ROOT\typelib\{0494d0d0-f8e0-41ad-92a3-14154ece70ac}\1.0 Toolbar 1.0 Type Library
HKEY_CLASSES_ROOT\interface\{0494d0d6-f8e0-41ad-92a3-14154ece70ac}
HKEY_CLASSES_ROOT\interface\{0494d0d6-f8e0-41ad-92a3-14154ece70ac}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{0494d0d6-f8e0-41ad-92a3-14154ece70ac}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{0494d0d6-f8e0-41ad-92a3-14154ece70ac}\TypeLib {0494D0D0-F8E0-41AD-92A3-14154ECE70AC}
HKEY_CLASSES_ROOT\interface\{0494d0d6-f8e0-41ad-92a3-14154ece70ac}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{0494d0d6-f8e0-41ad-92a3-14154ece70ac} IMyWayBarNetscapeStartup
HKEY_CLASSES_ROOT\interface\{0494d0d4-f8e0-41ad-92a3-14154ece70ac}
HKEY_CLASSES_ROOT\interface\{0494d0d4-f8e0-41ad-92a3-14154ece70ac}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{0494d0d4-f8e0-41ad-92a3-14154ece70ac}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{0494d0d4-f8e0-41ad-92a3-14154ece70ac}\TypeLib {0494D0D0-F8E0-41AD-92A3-14154ECE70AC}
HKEY_CLASSES_ROOT\interface\{0494d0d4-f8e0-41ad-92a3-14154ece70ac}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{0494d0d4-f8e0-41ad-92a3-14154ece70ac} IMyWayBarNetscapeShutdown
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner test "C:\Program Files\Altnet\Points Manager\Points Manager.exe" -p 1
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner PM-Home C:\Program Files\Altnet\Points Manager\Points Manager.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner PM-Points "C:\Program Files\Altnet\Points Manager\Points Manager.exe" -p 1
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner PM-Redeem "C:\Program Files\Altnet\Points Manager\Points Manager.exe" -p 2
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner PM-Wallet "C:\Program Files\Altnet\Points Manager\Points Manager.exe" -p 3
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner PM-Settings "C:\Program Files\Altnet\Points Manager\Points Manager.exe" -p 4
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner autologin http://ki.rd.myway.com/jsp/cfg_redir.jsp?id=KI&url=
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner bitmap C:\Programme\MyWay\myBar\1.bin\partner.bmp
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner cfg http://ki.barcfg.myway.com/speedbar/myS ... ?s=al&p=KI
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner mywayurl http://ki.search.myway.com/
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner name Altnet Points Manager
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner search http://ki.bar.myway.com/KI/barsearch.ht ... searchfor=
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner uninstallurl http://mcc.myway.com/jsp/baruninstall.jsp?id=KI
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar Dir C:\Programme\MyWay\myBar\
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar ShzmCurInstall 1
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar CurInstall 1
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar Id D1401481-974E-4B3B-B893-5962680FAAC9
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar Build 198.13765
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar CacheDir C:\Programme\MyWay\myBar\Cache\
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar HistoryDir C:\Programme\MyWay\myBar\History\
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar Visible 1
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar SettingsDir C:\Programme\MyWay\myBar\Settings\
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar ConfigRevision 38
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar ConfigRevisionURL http://ki.barcfg.myway.com/speedbar/myS ... ?s=al&p=KI
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar ConfigDateStamp 2003071212
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar Branding 10
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar Maximized 0
HKEY_CLASSES_ROOT\Interface\{0494D0DC-F8E0-41AD-92A3-14154ECE70AC}
HKEY_CLASSES_ROOT\Interface\{0494D0DC-F8E0-41AD-92A3-14154ECE70AC}\ProxyStubClsid {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{0494D0DC-F8E0-41AD-92A3-14154ECE70AC}\ProxyStubClsid32 {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{0494D0DC-F8E0-41AD-92A3-14154ECE70AC}\TypeLib {0494D0D0-F8E0-41AD-92A3-14154ECE70AC}
HKEY_CLASSES_ROOT\Interface\{0494D0DC-F8E0-41AD-92A3-14154ECE70AC}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{0494D0DC-F8E0-41AD-92A3-14154ECE70AC} _IMyWaySettingsEvents
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner test "C:\Program Files\Altnet\Points Manager\Points Manager.exe" -p 1
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner PM-Home C:\Program Files\Altnet\Points Manager\Points Manager.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner PM-Points "C:\Program Files\Altnet\Points Manager\Points Manager.exe" -p 1
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner PM-Redeem "C:\Program Files\Altnet\Points Manager\Points Manager.exe" -p 2
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner PM-Wallet "C:\Program Files\Altnet\Points Manager\Points Manager.exe" -p 3
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner PM-Settings "C:\Program Files\Altnet\Points Manager\Points Manager.exe" -p 4
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner autologin http://ki.rd.myway.com/jsp/cfg_redir.jsp?id=KI&url=
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner bitmap C:\Programme\MyWay\myBar\1.bin\partner.bmp
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner cfg http://ki.barcfg.myway.com/speedbar/myS ... ?s=al&p=KI
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner mywayurl http://ki.search.myway.com/
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner name Altnet Points Manager
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner search http://ki.bar.myway.com/KI/barsearch.ht ... searchfor=
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\Partner uninstallurl http://mcc.myway.com/jsp/baruninstall.jsp?id=KI
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar Dir C:\Programme\MyWay\myBar\
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar ShzmCurInstall 1
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar CurInstall 1
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar Id D1401481-974E-4B3B-B893-5962680FAAC9
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar Build 198.13765
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar CacheDir C:\Programme\MyWay\myBar\Cache\
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar HistoryDir C:\Programme\MyWay\myBar\History\
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar Visible 1
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar SettingsDir C:\Programme\MyWay\myBar\Settings\
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar ConfigRevision 38
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar ConfigRevisionURL http://ki.barcfg.myway.com/speedbar/myS ... ?s=al&p=KI
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar ConfigDateStamp 2003071212
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar Branding 10
HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar Maximized 0


C2.Lop Hijacker more information...
Details: Lop is a group of spyware and hijacker programs that set your Internet Explorer start page and search features to use the site lop.com ('Live Online Portal') or one of its clone sites.
Status: Deleted

Infected files detected
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\iegluzd.lib


Hotbar Toolbar more information...
Details: Hotbar Web Tools is a collection of browser and system enhancements. The primary application is the Hotbar toolbar, a which is a "skinable" browser toolbar for Internet Explorer.
Status: Deleted

Infected files detected
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\btntrans.idx
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\btntrans1.dat
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\country.exe
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\Default_hotbarcom.mnu
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\d_icons_buttons_1000.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\d_icons_buttons_2000.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\d_icons_buttons_3000.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar1.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\d_icons_weather.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\icons2.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\progress.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\s_icons_buttons.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\t2_bg.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\1\tsd_bg.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\btntrans.idx
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\btntrans1.dat
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\country.exe
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\Default_hotbarcom.mnu
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\d_icons_buttons_1000.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\d_icons_buttons_2000.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\d_icons_buttons_3000.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\d_icons_buttons_bbar1.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\d_icons_weather.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\icons2.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\progress.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\s_icons_buttons.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\t2_bg.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\2\tsd_bg.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\DownLoad\BtnTrans.xip
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\DownLoad\BtnTrans1.xip
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\DownLoad\country.xip
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_1000.xip
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_2000.xip
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_3000.xip
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_bbar1.xip
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\DownLoad\d_icons_weather.xip
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\DownLoad\icons2.xip
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\DownLoad\s_icons_buttons.xip
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HbTools\static\DownLoad\t2_bg.xip
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HostOI\static\1\progress.res
C:\Dokumente und Einstellungen\KOJIC MILAN\Anwendungsdaten\HbTools\v3.0\HostOI\static\2\progress.res

Infected registry entries detected
HKEY_CLASSES_ROOT\Interface\{175816A5-219E-4079-B2F9-53C501C409BA}
HKEY_CLASSES_ROOT\Interface\{175816A5-219E-4079-B2F9-53C501C409BA}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{175816A5-219E-4079-B2F9-53C501C409BA}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{175816A5-219E-4079-B2F9-53C501C409BA}\TypeLib {71EFE583-62FE-4419-9918-CA3B683F7B36}
HKEY_CLASSES_ROOT\Interface\{175816A5-219E-4079-B2F9-53C501C409BA}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{175816A5-219E-4079-B2F9-53C501C409BA} IHbSkinsManager
HKEY_CLASSES_ROOT\Interface\{5D16197A-1EAA-45AF-B29A-69F1AA055E87}
HKEY_CLASSES_ROOT\Interface\{5D16197A-1EAA-45AF-B29A-69F1AA055E87}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{5D16197A-1EAA-45AF-B29A-69F1AA055E87}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{5D16197A-1EAA-45AF-B29A-69F1AA055E87}\TypeLib {71EFE583-62FE-4419-9918-CA3B683F7B36}
HKEY_CLASSES_ROOT\Interface\{5D16197A-1EAA-45AF-B29A-69F1AA055E87}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{5D16197A-1EAA-45AF-B29A-69F1AA055E87} IDynamicProp
HKEY_CLASSES_ROOT\Interface\{8A61A950-C325-4F44-BA64-273180FF3464}
HKEY_CLASSES_ROOT\Interface\{8A61A950-C325-4F44-BA64-273180FF3464}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{8A61A950-C325-4F44-BA64-273180FF3464}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{8A61A950-C325-4F44-BA64-273180FF3464}\TypeLib {71EFE583-62FE-4419-9918-CA3B683F7B36}
HKEY_CLASSES_ROOT\Interface\{8A61A950-C325-4F44-BA64-273180FF3464}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{8A61A950-C325-4F44-BA64-273180FF3464} IHbLicense
HKEY_CLASSES_ROOT\Interface\{B53D4CD4-406D-43CC-8244-7893D72236DD}
HKEY_CLASSES_ROOT\Interface\{B53D4CD4-406D-43CC-8244-7893D72236DD}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{B53D4CD4-406D-43CC-8244-7893D72236DD}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{B53D4CD4-406D-43CC-8244-7893D72236DD}\TypeLib {71EFE583-62FE-4419-9918-CA3B683F7B36}
HKEY_CLASSES_ROOT\Interface\{B53D4CD4-406D-43CC-8244-7893D72236DD}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{B53D4CD4-406D-43CC-8244-7893D72236DD} IHbLfg2
HKEY_CLASSES_ROOT\Interface\{B9BB3219-F84C-4060-966B-4A1E73E24226}
HKEY_CLASSES_ROOT\Interface\{B9BB3219-F84C-4060-966B-4A1E73E24226}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{B9BB3219-F84C-4060-966B-4A1E73E24226}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{B9BB3219-F84C-4060-966B-4A1E73E24226}\TypeLib {71EFE583-62FE-4419-9918-CA3B683F7B36}
HKEY_CLASSES_ROOT\Interface\{B9BB3219-F84C-4060-966B-4A1E73E24226}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{B9BB3219-F84C-4060-966B-4A1E73E24226} IHbHttpClient
HKEY_CLASSES_ROOT\Interface\{F786CB18-3809-4E49-BC99-9A66DA47DB8B}
HKEY_CLASSES_ROOT\Interface\{F786CB18-3809-4E49-BC99-9A66DA47DB8B}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{F786CB18-3809-4E49-BC99-9A66DA47DB8B}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{F786CB18-3809-4E49-BC99-9A66DA47DB8B}\TypeLib {71EFE583-62FE-4419-9918-CA3B683F7B36}
HKEY_CLASSES_ROOT\Interface\{F786CB18-3809-4E49-BC99-9A66DA47DB8B}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{F786CB18-3809-4E49-BC99-9A66DA47DB8B} IHbXip
HKEY_CLASSES_ROOT\TypeLib\{71EFE583-62FE-4419-9918-CA3B683F7B36}
HKEY_CLASSES_ROOT\TypeLib\{71EFE583-62FE-4419-9918-CA3B683F7B36}\1.0\0\win32 C:\Programme\HbTools\Bin\4.7.0.0\HbtCoreSrv.dll
HKEY_CLASSES_ROOT\TypeLib\{71EFE583-62FE-4419-9918-CA3B683F7B36}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{71EFE583-62FE-4419-9918-CA3B683F7B36}\1.0\HELPDIR C:\Programme\HbTools\Bin\4.7.0.0\
HKEY_CLASSES_ROOT\TypeLib\{71EFE583-62FE-4419-9918-CA3B683F7B36}\1.0 HbCoreSrv 1.0 Type Library
HKEY_LOCAL_MACHINE\SOFTWARE\HbTools
HKEY_LOCAL_MACHINE\SOFTWARE\HbTools\HbTools\PI\3.2 PID00
HKEY_LOCAL_MACHINE\SOFTWARE\HbTools\Hotbar\Install StartInstall 524187
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E} Hotbar Information Window


INetBar Adware (General) more information...
Details: INetBar installs in Internet Explorer using a known user exploit via an ActiveX drive-by-download.
Status: Deleted

Infected files detected
C:\Dokumente und Einstellungen\KOJIC MILAN\Eigene Dateien\My eBooks\Neuer Ordner\inetbar15r5.exe


mIRC based Backdoor more information...
Status: Deleted

Infected files detected
C:\Dokumente und Einstellungen\KOJIC MISA\Desktop\Master-Script1.2\mirc.exe
C:\Dokumente und Einstellungen\KOJIC MISA\Desktop\Master-Script1.2\Addons\Bots\Floodbot\mirc.exe
C:\Dokumente und Einstellungen\KOJIC MISA\Desktop\Master-Script1.2\Addons\Bots\Idle-Bot\mirc.exe
C:\Program Files\mIRC\backup\mirc.exe
D:\Mischa\Müll\Master-Script1.2\Addons\Bots\Floodbot\mirc.exe
D:\Mischa\Müll\Master-Script1.2\Addons\Bots\Idle-Bot\mirc.exe


IRC.Backdoor.Trojan Backdoor more information...
Status: Deleted

Infected files detected
C:\Dokumente und Einstellungen\KOJIC MISA\Eigene Dateien\mirc\mirc.exe


MyNabyoo Surveillance (General) more information...
Details: My Nabyoo is an Internet Filter which effortlessly blocks and restricts Porn, Chat Programs, All P2P Software, Secretly Monitors PC activity and more.
Status: Deleted

Infected files detected
C:\Programme\LOADSTREET\Systerac XP Tools\URLHIST.tlb


AntiLeech Plugin Adware (General) more information...
Details: Plugin is an Ad-Ware software which enables the broadcasting of advertisements, and execution of e-commerce and other internet related services on the user-interface of the software.
Status: Deleted

Infected files detected
C:\Programme\Mozilla Firefox\plugins\al2np.dll

Infected registry entries detected
HKEY_CURRENT_USER\Software\Anti-Leech\Anti-Leech Plugin
HKEY_CURRENT_USER\Software\Anti-Leech\Anti-Leech Plugin Mozilla Firefox 0.8. C:\Programme\Mozilla Firefox\Plugins
HKEY_CURRENT_USER\Software\Anti-Leech\Anti-Leech Plugin Mozilla Firefox 1.0 C:\Programme\Mozilla Firefox\Plugins
HKEY_CURRENT_USER\Software\Anti-Leech\Anti-Leech Plugin Mozilla Firefox 1.5.0.4 C:\Programme\Mozilla Firefox\plugins\
HKEY_CLASSES_ROOT\AntiLeech.ALIE.1
HKEY_CLASSES_ROOT\AntiLeech.ALIE.1\CLSID {056738EE-E15C-11D6-B876-0050BF5D85C7}
HKEY_CLASSES_ROOT\AntiLeech.ALIE.1 Anti-Leech Plug-in
HKEY_CLASSES_ROOT\AntiLeech.ALIE
HKEY_CLASSES_ROOT\AntiLeech.ALIE\CLSID {056738EE-E15C-11D6-B876-0050BF5D85C7}
HKEY_CLASSES_ROOT\AntiLeech.ALIE\CurVer AntiLeech.ALIE.1
HKEY_CLASSES_ROOT\AntiLeech.ALIE Anti-Leech Plug-in
HKEY_CLASSES_ROOT\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7}
HKEY_CLASSES_ROOT\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7}\InprocServer32 C:\PROGRA~1\ANTI-L~1\ALIE_1~1.3\alie.dll
HKEY_CLASSES_ROOT\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7}\ProgID AntiLeech.ALIE.1
HKEY_CLASSES_ROOT\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7}\TypeLib {056738E1-E15C-11D6-B876-0050BF5D85C7}
HKEY_CLASSES_ROOT\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7}\VersionIndependentProgID AntiLeech.ALIE
HKEY_CLASSES_ROOT\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7} Anti-Leech Plug-in
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALIE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALIE DisplayName Anti-Leech Plugin for Internet Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALIE UninstallString C:\Programme\Anti-Leech\ALIE_1.0.2.3\iesetup2.exe uninstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALNN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALNN DisplayName Anti-Leech Plugin for Mozilla, Opera, Netscape
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALNN UninstallString C:\Programme\Anti-Leech\ALNN\setup2.exe -u


FirstLook Search Portal Adware (General) more information...
Details: Ad supported program that displays ads from Firstlook.com, a paid-placement search portal.
Status: Deleted

Infected files detected
C:\WINDOWS\NDNuninstall4_34.exe


ClearSearch Hijacker more information...
Details: ClearSearch is an adware component that periodically contacts the search site, www.clrsch.com, for advertisement-tracking purposes.
Status: Deleted

Infected files detected
C:\WINDOWS\system\Update_RemoveOld.DLL

Infected registry entries detected
HKEY_CLASSES_ROOT\ie_clrsch.iehooks.1
HKEY_CLASSES_ROOT\ie_clrsch.iehooks.1\CLSID {947E6D5A-4B9F-4CF4-91B3-562CA8D03313}
HKEY_CLASSES_ROOT\ie_clrsch.iehooks.1 IEHooks Class
HKEY_CLASSES_ROOT\ie_clrsch.iehooks
HKEY_CLASSES_ROOT\ie_clrsch.iehooks\CLSID {947E6D5A-4B9F-4CF4-91B3-562CA8D03313}
HKEY_CLASSES_ROOT\ie_clrsch.iehooks\CurVer Ie_clrsch.IEHooks.1
HKEY_CLASSES_ROOT\ie_clrsch.iehooks IEHooks Class
HKEY_CLASSES_ROOT\interface\{a351d4b1-bf54-41f1-bec0-8a1c4ecd72c7}
HKEY_CLASSES_ROOT\interface\{a351d4b1-bf54-41f1-bec0-8a1c4ecd72c7}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{a351d4b1-bf54-41f1-bec0-8a1c4ecd72c7}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{a351d4b1-bf54-41f1-bec0-8a1c4ecd72c7}\TypeLib {95B3AF07-0E4F-4CDF-ACFD-3D4EFD9AEC0B}
HKEY_CLASSES_ROOT\interface\{a351d4b1-bf54-41f1-bec0-8a1c4ecd72c7}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{a351d4b1-bf54-41f1-bec0-8a1c4ecd72c7} IIEHooks
HKEY_CLASSES_ROOT\typelib\{95b3af07-0e4f-4cdf-acfd-3d4efd9aec0b}
HKEY_CLASSES_ROOT\typelib\{95b3af07-0e4f-4cdf-acfd-3d4efd9aec0b}\1.0\0\win32 C:\Programme\ClearSearch\IE_ClrSch.DLL
HKEY_CLASSES_ROOT\typelib\{95b3af07-0e4f-4cdf-acfd-3d4efd9aec0b}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\typelib\{95b3af07-0e4f-4cdf-acfd-3d4efd9aec0b}\1.0\HELPDIR C:\Programme\ClearSearch\
HKEY_CLASSES_ROOT\typelib\{95b3af07-0e4f-4cdf-acfd-3d4efd9aec0b}\1.0 ie_clrsch 1.0 Type Library
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}\InprocServer32 C:\Programme\ClearSearch\IE_ClrSch.DLL
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}\ProgID Ie_clrsch.IEHooks.1
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}\TypeLib {95B3AF07-0E4F-4CDF-ACFD-3D4EFD9AEC0B}
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}\VersionIndependentProgID Ie_clrsch.IEHooks
HKEY_CLASSES_ROOT\clsid\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313} IEHooks Class


EGroup Sex Dialer Porn Dialer more information...
Details: EGroup Sex Dialer is a program that changes your modem's dial-up settings and attempts to connect to a premium or international phone number to access adult material.
Status: Deleted

Infected registry entries detected
HKEY_CLASSES_ROOT\clsid\{b843da96-2b2d-447e-90ab-b92929aa11af}
HKEY_CLASSES_ROOT\clsid\{b843da96-2b2d-447e-90ab-b92929aa11af}\InprocServer32 C:\WINDOWS\System32\EGHTMLDialer.dll
HKEY_CLASSES_ROOT\clsid\{b843da96-2b2d-447e-90ab-b92929aa11af}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{b843da96-2b2d-447e-90ab-b92929aa11af}\MiscStatus\1 131473
HKEY_CLASSES_ROOT\clsid\{b843da96-2b2d-447e-90ab-b92929aa1