Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Mein Papierkorb meldet (Dc1 kann nich gelöscht werden) (https://www.trojaner-board.de/27615-papierkorb-meldet-dc1-nich-geloescht.html)

hanes123 17.03.2006 14:00

Mein Papierkorb meldet (Dc1 kann nich gelöscht werden)
 
Hallo

Ich hab da so ein Problem mit meinem Papierkrob. Immer wenn ich ihn leeren will, kommt dann eine Meldung, dass Dc1 nicht gelöscht werden kann. Nach einem Neustart ist der Papierkorb leer, aber nach dem 3 oder 4 Papierkorb Leerung kommt die Meldung wieder.

Hier mal Mein HiJacK:

Logfile of HijackThis v1.99.1
Scan saved at 13:54:56, on 17.03.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Dokumente und Einstellungen\Zakaria\Eigene Dateien\Eigene Bilder und Videos\Eigene Bilder\libanon\Wallpaper.exe
C:\PROGRA~1\Versatel\Versatel.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\BitComet\BitComet.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Dokumente und Einstellungen\0000\Desktop\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://link0777.com/tracker/dtracker.asp?provider=1&version=19&redir=http://www.mazika.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.versatel.de/internet-cd/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WallPaper] C:\Dokumente und Einstellungen\000000\Eigene Dateien\Eigene Bilder und Videos\Eigene Bilder\libanon\Wallpaper.exe /h
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Programme\Microsoft Works\WkDetect.exe
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O14 - IERESET.INF: START_PAGE_URL=http://link0777.com/tracker/dtracker.asp?provider=1&version=19&redir=http://www.mazika.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{D26EC3D9-FD35-4191-95AE-9346D749F573}: NameServer = 212.7.148.65 212.7.148.97
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: lxcg_device - Unknown owner - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Programme\TuneUp Utilities 2006\WinStylerThemeSvc.exe


Danke im Voraus

hoerni26 17.03.2006 14:00

hallo,

beim logfile fehlt leider der kopf..

BataAlexander 17.03.2006 14:14

Hallo,

scanne

C:\Dokumente und Einstellungen\Zakaria\Eigene Dateien\Eigene Bilder und Videos\Eigene Bilder\libanon\Wallpaper.exe

online bei Jotti und/oder Virustotal poste das Ergebnis hier.

[edit]Hallo Feierfox, in dem Log endecke ich aber nix von Symantec? [/edit]

Gruß

Schrulli

Feierfox 17.03.2006 14:22

DC 1 dürfte von Norton Systemworks (?) kommen. Dessen Protect-Funktion für den Papierkorb. Abstellbar in den Eigenschaften des Papierkorbes.

hanes123 17.03.2006 14:27

hallo

aber ich benutzte Norton Systemworks gar nicht, und kann es auch nicht abschalten

C:\Dokumente und Einstellungen\oooo\Eigene Dateien\Eigene Bilder und Videos\Eigene Bilder\libanon\Wallpaper.exe

kann ich so viel zu sagen, dass ist ein prog. womit sich mein wallpapaer immer automatisch ändert. Denoch scannen?

hanes123 17.03.2006 14:28

und ihr noch der "Kopf des logfiles"

Logfile of HijackThis v1.99.1
Scan saved at 13:54:56, on 17.03.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

BataAlexander 17.03.2006 14:38

Hallo,
Zitat:

Zitat von hanes123
Denoch scannen?

bitte :)

[edit]Nimm Dir mal 2-3 Stunden Zeit und führe einen eScan durch, Anleitung in meiner Signatur verlinkt[/edit]

Gruß

Schrulli

hanes123 17.03.2006 15:51

Hallo

hat keiner eine andere lösung für mich als das Scannen mit dem escann


Bitte hilft mir doch

felix1 17.03.2006 15:56

Dann lasse den PC mal hier online scannen und teile das Ergebnis mit.

hanes123 17.03.2006 16:15

achso nein hab jetzt den escan vorgenommen, dachte aber mein Problem wäre schon bekannt oder so.

hanes123 17.03.2006 16:18

Hier mein escan:

Fri Mar 17 15:56:19 2006 => **********************************************************
Fri Mar 17 15:56:19 2006 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Fri Mar 17 15:56:19 2006 => Copyright © 2003-2006, MicroWorld Technologies Inc.
Fri Mar 17 15:56:19 2006 => **********************************************************
Fri Mar 17 15:56:19 2006 => Source: C:\DOKUME~1\Zakaria\Desktop\mwav.exe
Fri Mar 17 15:56:19 2006 => Version 8.2.1 (C:\DOKUME~1\Zakaria\LOKALE~1\Temp\mexe.com)
Fri Mar 17 15:56:19 2006 => Log File: C:\DOKUME~1\Zakaria\LOKALE~1\Temp\MWAV.LOG
Fri Mar 17 15:56:19 2006 => MWAV Registered: FALSE.
Fri Mar 17 15:56:19 2006 => OS Type: Windows Workstation
Fri Mar 17 15:56:19 2006 => Local Fixed Drives: c:\,d:\
Fri Mar 17 15:56:19 2006 => MWAV Mode: Only Scan files.
Fri Mar 17 15:56:19 2006 => Latest Date of files inside MWAV: 14 Mar 2006 06:21:15.
Fri Mar 17 15:56:23 2006 => AV Library Loaded...
Fri Mar 17 15:56:23 2006 => MWAV doing self scanning...
Fri Mar 17 15:56:23 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavss.exe
Fri Mar 17 15:56:23 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\Getvlist.exe
Fri Mar 17 15:56:24 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavss.dll
Fri Mar 17 15:56:24 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavssdi.dll
Fri Mar 17 15:56:24 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavssi.dll
Fri Mar 17 15:56:24 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavvlg.dll
Fri Mar 17 15:56:24 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\msvlclnt.dll
Fri Mar 17 15:56:24 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\ipc.dll
Fri Mar 17 15:56:24 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\main.avi
Fri Mar 17 15:56:24 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\virus.avi
Fri Mar 17 15:56:24 2006 => MWAV files are clean.
Fri Mar 17 15:56:31 2006 => Virus Database Date: 3/14/2006
Fri Mar 17 15:56:31 2006 => Virus Database Count: 182276
Fri Mar 17 15:56:58 2006 => Downloading AntiVirus and Anti-Spyware Databases...
Fri Mar 17 15:57:44 2006 => Downloads Successful...
Fri Mar 17 15:57:50 2006 => Reload of AntiVirus Signatures successfully done.
Fri Mar 17 15:57:50 2006 => Virus Database Date: 3/17/2006
Fri Mar 17 15:57:50 2006 => Virus Database Count: 178892
Fri Mar 17 15:57:53 2006 => AV Library Unloaded (3)...
Fri Mar 17 16:05:49 2006 => **********************************************************
Fri Mar 17 16:05:49 2006 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Fri Mar 17 16:05:49 2006 => Copyright © 2003-2006, MicroWorld Technologies Inc.
Fri Mar 17 16:05:49 2006 => **********************************************************
Fri Mar 17 16:05:49 2006 => Source: C:\DOKUME~1\Zakaria\Desktop\mwav.exe
Fri Mar 17 16:05:49 2006 => Version 8.2.1 (C:\DOKUME~1\Zakaria\LOKALE~1\Temp\mexe.com)
Fri Mar 17 16:05:49 2006 => Log File: C:\DOKUME~1\Zakaria\LOKALE~1\Temp\MWAV.LOG
Fri Mar 17 16:05:49 2006 => MWAV Registered: FALSE.
Fri Mar 17 16:05:49 2006 => OS Type: Windows Workstation
Fri Mar 17 16:05:49 2006 => Local Fixed Drives: c:\,d:\
Fri Mar 17 16:05:49 2006 => MWAV Mode: Only Scan files.
Fri Mar 17 16:05:49 2006 => Latest Date of files inside MWAV: 14 Mar 2006 06:21:15.
Fri Mar 17 16:05:52 2006 => AV Library Loaded...
Fri Mar 17 16:05:52 2006 => MWAV doing self scanning...
Fri Mar 17 16:05:52 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavss.exe
Fri Mar 17 16:05:52 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\Getvlist.exe
Fri Mar 17 16:05:52 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavss.dll
Fri Mar 17 16:05:52 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavssdi.dll
Fri Mar 17 16:05:52 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavssi.dll
Fri Mar 17 16:05:52 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavvlg.dll
Fri Mar 17 16:05:52 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\msvlclnt.dll
Fri Mar 17 16:05:52 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\ipc.dll
Fri Mar 17 16:05:52 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\main.avi
Fri Mar 17 16:05:52 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\virus.avi
Fri Mar 17 16:05:52 2006 => MWAV files are clean.
Fri Mar 17 16:05:52 2006 => Virus Database Date: 3/14/2006
Fri Mar 17 16:05:52 2006 => Virus Database Count: 182276

Fri Mar 17 16:06:08 2006 => **********************************************************
Fri Mar 17 16:06:08 2006 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Fri Mar 17 16:06:08 2006 => Copyright © 2003-2006, MicroWorld Technologies Inc.
Fri Mar 17 16:06:08 2006 =>
Fri Mar 17 16:06:08 2006 => Support: support@mwti.net
Fri Mar 17 16:06:08 2006 => Web: http://www.mwti.net
Fri Mar 17 16:06:08 2006 => **********************************************************
Fri Mar 17 16:06:08 2006 => Version 8.2.1 (C:\DOKUME~1\Zakaria\LOKALE~1\Temp\mexe.com)
Fri Mar 17 16:06:08 2006 => Log File: C:\DOKUME~1\Zakaria\LOKALE~1\Temp\MWAV.LOG
Fri Mar 17 16:06:08 2006 => User Account: Zakaria
Fri Mar 17 16:06:08 2006 => Windows Root Folder: C:\WINDOWS
Fri Mar 17 16:06:08 2006 => Windows Sys32 Folder: C:\WINDOWS\system32
Fri Mar 17 16:06:08 2006 => OS: Windows XP
Fri Mar 17 16:06:08 2006 => Latest Date of files inside MWAV: 14 Mar 2006 06:21:15.

Fri Mar 17 16:06:08 2006 => Options Selected by User:
Fri Mar 17 16:06:08 2006 => Memory Check: Enabled
Fri Mar 17 16:06:08 2006 => Registry Check: Enabled
Fri Mar 17 16:06:08 2006 => StartUp Folder Check: Disabled
Fri Mar 17 16:06:08 2006 => System Folder Check: Disabled
Fri Mar 17 16:06:08 2006 => System Area Check: Disabled
Fri Mar 17 16:06:08 2006 => Services Check: Enabled
Fri Mar 17 16:06:08 2006 => Drive Check: Disabled
Fri Mar 17 16:06:08 2006 => All Drive Check :Enabled
Fri Mar 17 16:06:08 2006 => Folder Check: Disabled

Fri Mar 17 16:06:08 2006 => ***** Scanning Memory Files *****
Fri Mar 17 16:06:08 2006 => Scanning File C:\WINDOWS\System32\smss.exe
Fri Mar 17 16:06:08 2006 => Scanning File C:\WINDOWS\system32\ntdll.dll
Fri Mar 17 16:06:08 2006 => Scanning File C:\WINDOWS\SYSTEM32\CSRSS.EXE
Fri Mar 17 16:06:08 2006 => Scanning File C:\WINDOWS\system32\CSRSRV.dll
Fri Mar 17 16:06:09 2006 => Scanning File C:\WINDOWS\system32\basesrv.dll
Fri Mar 17 16:06:09 2006 => Scanning File C:\WINDOWS\system32\winsrv.dll
Fri Mar 17 16:06:09 2006 => Scanning File C:\WINDOWS\system32\GDI32.dll
Fri Mar 17 16:06:09 2006 => Scanning File C:\WINDOWS\system32\KERNEL32.dll
Fri Mar 17 16:06:09 2006 => Scanning File C:\WINDOWS\system32\USER32.dll
Fri Mar 17 16:06:09 2006 => Scanning File C:\WINDOWS\system32\sxs.dll
Fri Mar 17 16:06:09 2006 => Scanning File C:\WINDOWS\system32\ADVAPI32.dll
Fri Mar 17 16:06:09 2006 => Scanning File C:\WINDOWS\system32\RPCRT4.dll
Fri Mar 17 16:06:09 2006 => Scanning File C:\WINDOWS\SYSTEM32\WINLOGON.EXE
Fri Mar 17 16:06:11 2006 => Scanning File C:\WINDOWS\system32\AUTHZ.dll
Fri Mar 17 16:06:11 2006 => Scanning File C:\WINDOWS\system32\msvcrt.dll
Fri Mar 17 16:06:11 2006 => Scanning File C:\WINDOWS\system32\CRYPT32.dll
Fri Mar 17 16:06:11 2006 => Scanning File C:\WINDOWS\system32\MSASN1.dll
Fri Mar 17 16:06:11 2006 => Scanning File C:\WINDOWS\system32\NDdeApi.dll
Fri Mar 17 16:06:11 2006 => Scanning File C:\WINDOWS\system32\PROFMAP.dll
Fri Mar 17 16:06:11 2006 => Scanning File C:\WINDOWS\system32\NETAPI32.dll
Fri Mar 17 16:06:11 2006 => Scanning File C:\WINDOWS\system32\USERENV.dll
Fri Mar 17 16:06:11 2006 => Scanning File C:\WINDOWS\system32\PSAPI.DLL
Fri Mar 17 16:06:11 2006 => Scanning File C:\WINDOWS\system32\REGAPI.dll
Fri Mar 17 16:06:12 2006 => Scanning File C:\WINDOWS\system32\Secur32.dll
Fri Mar 17 16:06:12 2006 => Scanning File C:\WINDOWS\system32\SETUPAPI.dll
Fri Mar 17 16:06:12 2006 => Scanning File C:\WINDOWS\system32\VERSION.dll
Fri Mar 17 16:06:12 2006 => Scanning File C:\WINDOWS\system32\WINSTA.dll
Fri Mar 17 16:06:12 2006 => Scanning File C:\WINDOWS\system32\WINTRUST.dll
Fri Mar 17 16:06:12 2006 => Scanning File C:\WINDOWS\system32\IMAGEHLP.dll
Fri Mar 17 16:06:12 2006 => Scanning File C:\WINDOWS\system32\WS2_32.dll
Fri Mar 17 16:06:12 2006 => Scanning File C:\WINDOWS\system32\WS2HELP.dll
Fri Mar 17 16:06:12 2006 => Scanning File C:\WINDOWS\system32\MSGINA.dll
Fri Mar 17 16:06:13 2006 => Scanning File C:\WINDOWS\system32\SHELL32.dll
Fri Mar 17 16:06:13 2006 => Scanning File C:\WINDOWS\system32\SHLWAPI.dll
Fri Mar 17 16:06:13 2006 => Scanning File C:\WINDOWS\system32\COMCTL32.dll
Fri Mar 17 16:06:13 2006 => Scanning File C:\WINDOWS\system32\ODBC32.dll
Fri Mar 17 16:06:13 2006 => Scanning File C:\WINDOWS\system32\comdlg32.dll
Fri Mar 17 16:06:13 2006 => Scanning File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2649_x-ww_aac16c8b\comctl32.dll
Fri Mar 17 16:06:13 2006 => Scanning File C:\WINDOWS\system32\odbcint.dll
Fri Mar 17 16:06:14 2006 => Scanning File C:\WINDOWS\system32\SHSVCS.dll
Fri Mar 17 16:06:14 2006 => Scanning File C:\WINDOWS\system32\sfc.dll
Fri Mar 17 16:06:14 2006 => Scanning File C:\WINDOWS\system32\sfc_os.dll
Fri Mar 17 16:06:14 2006 => Scanning File C:\WINDOWS\system32\ole32.dll
Fri Mar 17 16:06:14 2006 => Scanning File C:\WINDOWS\system32\Apphelp.dll
Fri Mar 17 16:06:14 2006 => Scanning File C:\WINDOWS\system32\WINMM.dll
Fri Mar 17 16:06:14 2006 => Scanning File C:\WINDOWS\system32\cscdll.dll
Fri Mar 17 16:06:14 2006 => Scanning File C:\WINDOWS\system32\WlNotify.dll
Fri Mar 17 16:06:14 2006 => Scanning File C:\WINDOWS\system32\WinSCard.dll
Fri Mar 17 16:06:14 2006 => Scanning File C:\WINDOWS\system32\WTSAPI32.dll
Fri Mar 17 16:06:14 2006 => Scanning File C:\WINDOWS\system32\WINSPOOL.DRV
Fri Mar 17 16:06:15 2006 => Scanning File C:\WINDOWS\system32\MPR.dll
Fri Mar 17 16:06:15 2006 => Scanning File C:\WINDOWS\system32\rsaenh.dll
Fri Mar 17 16:06:15 2006 => Scanning File C:\WINDOWS\system32\UxTheme.dll
Fri Mar 17 16:06:15 2006 => Scanning File C:\WINDOWS\system32\SAMLIB.dll
Fri Mar 17 16:06:15 2006 => Scanning File C:\WINDOWS\system32\cscui.dll
Fri Mar 17 16:06:15 2006 => Scanning File C:\WINDOWS\system32\NTMARTA.DLL
Fri Mar 17 16:06:15 2006 => Scanning File C:\WINDOWS\system32\WLDAP32.dll
Fri Mar 17 16:06:15 2006 => Scanning File C:\WINDOWS\system32\COMRes.dll
Fri Mar 17 16:06:15 2006 => Scanning File C:\WINDOWS\system32\OLEAUT32.dll
Fri Mar 17 16:06:15 2006 => Scanning File C:\WINDOWS\system32\CLBCATQ.DLL
Fri Mar 17 16:06:16 2006 => Scanning File C:\WINDOWS\system32\xpsp2res.dll
Fri Mar 17 16:06:16 2006 => Scanning File C:\WINDOWS\system32\services.exe
Fri Mar 17 16:06:16 2006 => Scanning File C:\WINDOWS\system32\SCESRV.dll
Fri Mar 17 16:06:16 2006 => Scanning File C:\WINDOWS\system32\umpnpmgr.dll
Fri Mar 17 16:06:17 2006 => Scanning File C:\WINDOWS\system32\NCObjAPI.DLL
Fri Mar 17 16:06:17 2006 => Scanning File C:\WINDOWS\system32\MSVCP60.dll
Fri Mar 17 16:06:17 2006 => Scanning File C:\WINDOWS\system32\ShimEng.dll
Fri Mar 17 16:06:17 2006 => Scanning File C:\WINDOWS\AppPatch\AcGenral.DLL
Fri Mar 17 16:06:17 2006 => Scanning File C:\WINDOWS\system32\MSACM32.dll
Fri Mar 17 16:06:17 2006 => Scanning File C:\WINDOWS\system32\eventlog.dll
Fri Mar 17 16:06:17 2006 => Scanning File C:\WINDOWS\system32\lsass.exe
Fri Mar 17 16:06:17 2006 => Scanning File C:\WINDOWS\system32\LSASRV.dll
Fri Mar 17 16:06:17 2006 => Scanning File C:\WINDOWS\system32\NTDSAPI.dll
Fri Mar 17 16:06:18 2006 => Scanning File C:\WINDOWS\system32\DNSAPI.dll
Fri Mar 17 16:06:18 2006 => Scanning File C:\WINDOWS\system32\SAMSRV.dll
Fri Mar 17 16:06:18 2006 => Scanning File C:\WINDOWS\system32\cryptdll.dll
Fri Mar 17 16:06:18 2006 => Scanning File C:\WINDOWS\system32\msprivs.dll
Fri Mar 17 16:06:18 2006 => Scanning File C:\WINDOWS\system32\kerberos.dll
Fri Mar 17 16:06:18 2006 => Scanning File C:\WINDOWS\system32\msv1_0.dll
Fri Mar 17 16:06:18 2006 => Scanning File C:\WINDOWS\system32\iphlpapi.dll
Fri Mar 17 16:06:18 2006 => Scanning File C:\WINDOWS\system32\netlogon.dll
Fri Mar 17 16:06:18 2006 => Scanning File C:\WINDOWS\system32\w32time.dll
Fri Mar 17 16:06:19 2006 => Scanning File C:\WINDOWS\system32\schannel.dll
Fri Mar 17 16:06:19 2006 => Scanning File C:\WINDOWS\system32\wdigest.dll
Fri Mar 17 16:06:19 2006 => Scanning File C:\WINDOWS\system32\scecli.dll
Fri Mar 17 16:06:19 2006 => Scanning File C:\WINDOWS\system32\svchost.exe
Fri Mar 17 16:06:19 2006 => Scanning File c:\windows\system32\rpcss.dll
Fri Mar 17 16:06:19 2006 => Scanning File C:\WINDOWS\system32\mswsock.dll
Fri Mar 17 16:06:19 2006 => Scanning File C:\WINDOWS\system32\hnetcfg.dll
Fri Mar 17 16:06:19 2006 => Scanning File C:\WINDOWS\System32\wshtcpip.dll
Fri Mar 17 16:06:19 2006 => Scanning File C:\WINDOWS\System32\winrnr.dll
Fri Mar 17 16:06:19 2006 => Scanning File C:\WINDOWS\system32\rasadhlp.dll
Fri Mar 17 16:06:19 2006 => Scanning File c:\windows\system32\cryptsvc.dll
Fri Mar 17 16:06:20 2006 => Scanning File c:\windows\system32\certcli.dll
Fri Mar 17 16:06:20 2006 => Scanning File c:\windows\system32\ATL.DLL
Fri Mar 17 16:06:20 2006 => Scanning File C:\WINDOWS\system32\CRYPTUI.dll
Fri Mar 17 16:06:20 2006 => Scanning File C:\WINDOWS\system32\WININET.dll
Fri Mar 17 16:06:20 2006 => Scanning File c:\windows\system32\ESENT.dll
Fri Mar 17 16:06:20 2006 => Scanning File c:\windows\system32\wbem\wmisvc.dll
Fri Mar 17 16:06:20 2006 => Scanning File C:\WINDOWS\system32\VSSAPI.DLL
Fri Mar 17 16:06:21 2006 => Scanning File c:\windows\system32\srsvc.dll
Fri Mar 17 16:06:21 2006 => Scanning File c:\windows\system32\POWRPROF.dll
Fri Mar 17 16:06:21 2006 => Scanning File c:\windows\pchealth\helpctr\binaries\pchsvc.dll
Fri Mar 17 16:06:21 2006 => Scanning File C:\WINDOWS\System32\wbem\wbemcore.dll
Fri Mar 17 16:06:21 2006 => Scanning File C:\WINDOWS\System32\wbem\esscli.dll
Fri Mar 17 16:06:21 2006 => Scanning File C:\WINDOWS\System32\wbem\wbemcomn.dll
Fri Mar 17 16:06:21 2006 => Scanning File C:\WINDOWS\System32\wbem\FastProx.dll
Fri Mar 17 16:06:21 2006 => Scanning File C:\WINDOWS\System32\wbem\wmiutils.dll
Fri Mar 17 16:06:21 2006 => Scanning File C:\WINDOWS\System32\wbem\repdrvfs.dll
Fri Mar 17 16:06:21 2006 => Scanning File C:\WINDOWS\System32\wbem\wmiprvsd.dll
Fri Mar 17 16:06:22 2006 => Scanning File C:\WINDOWS\System32\wbem\wbemess.dll
Fri Mar 17 16:06:22 2006 => Scanning File C:\WINDOWS\System32\wbem\ncprov.dll
Fri Mar 17 16:06:22 2006 => Scanning File C:\WINDOWS\System32\wbem\wbemcons.dll
Fri Mar 17 16:06:22 2006 => Scanning File C:\WINDOWS\Explorer.EXE
Fri Mar 17 16:06:22 2006 => Scanning File C:\WINDOWS\system32\BROWSEUI.dll
Fri Mar 17 16:06:22 2006 => Scanning File C:\WINDOWS\system32\SHDOCVW.dll
Fri Mar 17 16:06:22 2006 => Scanning File C:\WINDOWS\System32\themeui.dll
Fri Mar 17 16:06:23 2006 => Scanning File C:\WINDOWS\System32\MSIMG32.dll
Fri Mar 17 16:06:23 2006 => Scanning File C:\WINDOWS\System32\msutb.dll
Fri Mar 17 16:06:23 2006 => Scanning File C:\WINDOWS\System32\MSCTF.dll
Fri Mar 17 16:06:23 2006 => Scanning File C:\WINDOWS\system32\urlmon.dll
Fri Mar 17 16:06:23 2006 => Scanning File C:\WINDOWS\system32\LINKINFO.dll
Fri Mar 17 16:06:23 2006 => Scanning File C:\WINDOWS\system32\ntshrui.dll
Fri Mar 17 16:06:23 2006 => Scanning File C:\WINDOWS\system32\NETSHELL.dll
Fri Mar 17 16:06:23 2006 => Scanning File C:\WINDOWS\system32\credui.dll
Fri Mar 17 16:06:24 2006 => Scanning File C:\WINDOWS\system32\rtutils.dll
Fri Mar 17 16:06:24 2006 => Scanning File C:\WINDOWS\system32\browselc.dll
Fri Mar 17 16:06:24 2006 => Scanning File C:\WINDOWS\System32\drprov.dll
Fri Mar 17 16:06:24 2006 => Scanning File C:\WINDOWS\System32\ntlanman.dll
Fri Mar 17 16:06:24 2006 => Scanning File C:\WINDOWS\System32\NETUI0.dll
Fri Mar 17 16:06:24 2006 => Scanning File C:\WINDOWS\System32\NETUI1.dll
Fri Mar 17 16:06:24 2006 => Scanning File C:\WINDOWS\System32\NETRAP.dll
Fri Mar 17 16:06:24 2006 => Scanning File C:\WINDOWS\System32\davclnt.dll
Fri Mar 17 16:06:24 2006 => Scanning File C:\WINDOWS\system32\MLANG.dll
Fri Mar 17 16:06:24 2006 => Scanning File C:\WINDOWS\system32\msi.dll
Fri Mar 17 16:06:25 2006 => Scanning File C:\PROGRA~1\Adobe\ACROBA~1.0\ActiveX\PDFShell.dll
Fri Mar 17 16:06:25 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\mexe.com
Fri Mar 17 16:06:25 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\msvlclnt.dll
Fri Mar 17 16:06:25 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavssdi.dll
Fri Mar 17 16:06:25 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavssd.dll
Fri Mar 17 16:06:25 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavssi.dll
Fri Mar 17 16:06:26 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\ipc.dll
Fri Mar 17 16:06:26 2006 => Scanning File C:\WINDOWS\system32\RICHED32.DLL
Fri Mar 17 16:06:26 2006 => Scanning File C:\WINDOWS\system32\RICHED20.dll
Fri Mar 17 16:06:26 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\PSAPI.DLL
Fri Mar 17 16:06:26 2006 => Scanning File C:\WINDOWS\system32\VDMDBG.DLL
Fri Mar 17 16:06:26 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavss.exe
Fri Mar 17 16:06:26 2006 => Scanning File C:\DOKUME~1\Zakaria\LOKALE~1\Temp\kavss.dll

Fri Mar 17 16:06:26 2006 => ***** Scanning Registry Files *****

Fri Mar 17 16:06:26 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
Fri Mar 17 16:06:26 2006 => Scanning File C:\WINDOWS\system32\SHELL32.dll
Fri Mar 17 16:06:26 2006 => Scanning File C:\WINDOWS\system32\SHELL32.dll
Fri Mar 17 16:06:26 2006 => Scanning File C:\WINDOWS\System32\webcheck.dll
Fri Mar 17 16:06:26 2006 => Scanning File C:\WINDOWS\System32\stobject.dll

Fri Mar 17 16:06:26 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

Fri Mar 17 16:06:27 2006 => Scanning HKLM\SOFTWARE\Microsoft\Internet Explorer\Plugins\Extension

Fri Mar 17 16:06:27 2006 => Scanning HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar

Fri Mar 17 16:06:27 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects
Fri Mar 17 16:06:27 2006 => {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
Fri Mar 17 16:06:27 2006 => Scanning File C:\PROGRA~1\Adobe\ACROBA~1.0\ActiveX\ACROIE~1.DLL
Fri Mar 17 16:06:27 2006 => {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} = C:\Programme\Java\jre1.5.0_06\bin\ssv.dll
Fri Mar 17 16:06:27 2006 => Scanning File C:\Programme\Java\jre1.5.0_06\bin\ssv.dll

Fri Mar 17 16:06:27 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler
Fri Mar 17 16:06:27 2006 => Scanning File C:\WINDOWS\System32\browseui.dll
Fri Mar 17 16:06:27 2006 => Scanning File C:\WINDOWS\System32\browseui.dll

Fri Mar 17 16:06:27 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Fri Mar 17 16:06:27 2006 => Scanning File C:\PROGRA~1\ANTIVI~1\shlext.dll
Fri Mar 17 16:06:27 2006 => Scanning File C:\WINDOWS\System32\msgsple.dll
Fri Mar 17 16:06:33 2006 => File C:\WINDOWS\System32\msgsple.dll tagged as "not-a-virus:AdWare.Win32.Agent.o". Action Taken: No Action Taken.

Fri Mar 17 16:06:33 2006 => Scanning File C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
Fri Mar 17 16:06:33 2006 => Scanning File C:\PROGRA~1\MICROS~4\Office10\msohev.dll
Fri Mar 17 16:06:33 2006 => Scanning File C:\WINDOWS\system32\wmpshell.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\wmpshell.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\wmpshell.dll

Fri Mar 17 16:06:34 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

Fri Mar 17 16:06:34 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\Explorer.exe
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\userinit.exe
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\dskquota.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\iedkcs32.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\scecli.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\iedkcs32.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\scecli.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\crypt32.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\cryptnet.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\cscdll.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\wlnotify.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\wlnotify.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\sclgntfy.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\WlNotify.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\wlnotify.dll
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\wlnotify.dll

Fri Mar 17 16:06:34 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

Fri Mar 17 16:06:34 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System

Fri Mar 17 16:06:34 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

Fri Mar 17 16:06:34 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AEDEBUG
Fri Mar 17 16:06:34 2006 => Scanning File C:\WINDOWS\system32\drwtsn32.exe

Fri Mar 17 16:06:35 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
Fri Mar 17 16:06:35 2006 => Scanning File C:\WINDOWS\system32\ntsd.exe

Fri Mar 17 16:06:35 2006 => Scanning HKCU\Control Panel\Desktop

Fri Mar 17 16:06:35 2006 => Scanning HKLM\SYSTEM\CurrentControlSet\Control\WOW
Fri Mar 17 16:06:35 2006 => Scanning File C:\WINDOWS\system32\ntvdm.exe
Fri Mar 17 16:06:35 2006 => Scanning File C:\WINDOWS\system32\ntvdm.exe

Fri Mar 17 16:06:35 2006 => Scanning HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
Fri Mar 17 16:06:35 2006 => Scanning File C:\WINDOWS\inf\unregmp2.exe
Fri Mar 17 16:06:35 2006 => Scanning File C:\WINDOWS\system32\shmgrate.exe
Fri Mar 17 16:06:35 2006 => Scanning File C:\WINDOWS\system32\RunDLL32.exe
Fri Mar 17 16:06:35 2006 => Scanning File C:\WINDOWS\system32\shmgrate.exe
Fri Mar 17 16:06:35 2006 => Scanning File C:\WINDOWS\system32\regsvr32.exe
Fri Mar 17 16:06:35 2006 => Scanning File C:\PROGRA~1\OUTLOO~1\setup50.exe
Fri Mar 17 16:06:35 2006 => Scanning File C:\WINDOWS\system32\rundll32.exe
Fri Mar 17 16:06:35 2006 => Scanning File C:\WINDOWS\system32\rundll32.exe
Fri Mar 17 16:06:35 2006 => Scanning File C:\WINDOWS\system32\rundll32.exe
Fri Mar 17 16:06:35 2006 => Scanning File C:\PROGRA~1\OUTLOO~1\setup50.exe
Fri Mar 17 16:06:35 2006 => Scanning File C:\WINDOWS\system32\regsvr32.exe
Fri Mar 17 16:06:35 2006 => Scanning File C:\WINDOWS\system32\ie4uinit.exe
Fri Mar 17 16:06:36 2006 => Scanning File C:\WINDOWS\system32\Rundll32.exe

Fri Mar 17 16:06:36 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

Fri Mar 17 16:06:36 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

Fri Mar 17 16:06:36 2006 => Scanning HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Run

Fri Mar 17 16:06:36 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Run

Fri Mar 17 16:06:36 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Fri Mar 17 16:06:36 2006 => Scanning File C:\WINDOWS\Mixer.exe
Fri Mar 17 16:06:36 2006 => Scanning File C:\PROGRA~1\ANTIVI~1\avgnt.exe
Fri Mar 17 16:06:36 2006 => Scanning File C:\PROGRA~1\GEMEIN~1\Real\UPDATE~1\REALSC~1.EXE
Fri Mar 17 16:06:37 2006 => Scanning File C:\PROGRA~1\GEMEIN~1\SCANSO~1\SSBKGD~1\SSBKGD~1.EXE
Fri Mar 17 16:06:37 2006 => Scanning File C:\WINDOWS\system32\rundll32.exe

Fri Mar 17 16:06:37 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

Fri Mar 17 16:06:37 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx

Fri Mar 17 16:06:37 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

Fri Mar 17 16:06:37 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce

Fri Mar 17 16:06:37 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Fri Mar 17 16:06:37 2006 => Scanning File C:\WINDOWS\system32\ctfmon.exe



Die Erste Hälfte

Und

hanes123 17.03.2006 16:19

Fri Mar 17 16:06:37 2006 => Scanning File C:\DOKUME~1\Zakaria\EIGENE~1\EIGENE~4\EIGENE~2\libanon\WALLPA~1.EXE
Fri Mar 17 16:06:37 2006 => ERROR!!! Invalid Entry Microsoft Works Update Detection = C:\Programme\Microsoft Works\WkDetect.exe (in key SOFTWARE\Microsoft\Windows\CurrentVersion\Run). No Action Taken.

Fri Mar 17 16:06:37 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

Fri Mar 17 16:06:37 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx

Fri Mar 17 16:06:37 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

Fri Mar 17 16:06:37 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Setup

Fri Mar 17 16:06:37 2006 => Scanning HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Fri Mar 17 16:06:38 2006 => Scanning File C:\WINDOWS\System32\CTFMON.EXE

Fri Mar 17 16:06:38 2006 => Scanning HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

Fri Mar 17 16:06:38 2006 => Scanning HKCR\txtfile\shell\open\command

Fri Mar 17 16:06:38 2006 => Scanning HKCR\comfile\shell\open\command

Fri Mar 17 16:06:38 2006 => Scanning HKCR\exefile\shell\open\command

Fri Mar 17 16:06:38 2006 => Scanning HKCR\dllfile\shell\open\command

Fri Mar 17 16:06:38 2006 => Scanning HKCR\batfile\shell\open\command

Fri Mar 17 16:06:38 2006 => Scanning HKCR\piffile\shell\open\command

Fri Mar 17 16:06:38 2006 => Scanning HKCR\scrfile\shell\open\command

Fri Mar 17 16:06:38 2006 => Scanning HKCR\scrfile\shell\config\command

Fri Mar 17 16:06:38 2006 => Scanning HKCR\regfile\shell\open\command

Fri Mar 17 16:06:38 2006 => Scanning HKCR\htmlfile\shell\open\command
Fri Mar 17 16:06:38 2006 => Scanning File C:\PROGRA~1\INTERN~1\iexplore.exe

Fri Mar 17 16:06:38 2006 => Scanning HKCR\htafile\shell\open\command
Fri Mar 17 16:06:38 2006 => Scanning File C:\WINDOWS\System32\mshta.exe

Fri Mar 17 16:06:38 2006 => Scanning HKCR\jsfile\shell\open\command
Fri Mar 17 16:06:38 2006 => Scanning File C:\WINDOWS\System32\WScript.exe

Fri Mar 17 16:06:38 2006 => Scanning HKCR\jsefile\shell\open\command
Fri Mar 17 16:06:38 2006 => Scanning File C:\WINDOWS\System32\WScript.exe

Fri Mar 17 16:06:38 2006 => Scanning HKCR\vbsfile\shell\open\command
Fri Mar 17 16:06:38 2006 => Scanning File C:\WINDOWS\System32\WScript.exe

Fri Mar 17 16:06:38 2006 => Scanning HKCR\vbefile\shell\open\command
Fri Mar 17 16:06:38 2006 => Scanning File C:\WINDOWS\System32\WScript.exe

Fri Mar 17 16:06:38 2006 => Scanning HKCR\wshfile\shell\open\command
Fri Mar 17 16:06:38 2006 => Scanning File C:\WINDOWS\System32\WScript.exe

Fri Mar 17 16:06:38 2006 => Scanning HKCR\wsffile\shell\open\command
Fri Mar 17 16:06:39 2006 => Scanning File C:\WINDOWS\System32\WScript.exe

Fri Mar 17 16:06:39 2006 => ***** Scanning Service Files *****
Fri Mar 17 16:06:39 2006 => Scanning HKLM\SYSTEM\CurrentControlSet\Services
Fri Mar 17 16:06:39 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\ACPI.sys
Fri Mar 17 16:06:39 2006 => Scanning File C:\WINDOWS\system32\drivers\aec.sys
Fri Mar 17 16:06:39 2006 => Scanning File C:\WINDOWS\System32\drivers\afd.sys
Fri Mar 17 16:06:39 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\agp440.sys
Fri Mar 17 16:06:39 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:39 2006 => Scanning File C:\WINDOWS\System32\alg.exe
Fri Mar 17 16:06:39 2006 => Scanning File C:\PROGRA~1\ANTIVI~1\sched.exe
Fri Mar 17 16:06:39 2006 => Scanning File C:\PROGRA~1\ANTIVI~1\avguard.exe
Fri Mar 17 16:06:39 2006 => Scanning File C:\WINDOWS\system32\svchost.exe
Fri Mar 17 16:06:39 2006 => Scanning File C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\asyncmac.sys
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\atapi.sys
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\atmarpc.sys
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\audstub.sys
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\avgntdd.sys
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\system32\drivers\avgntmgr.sys
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\cdrom.sys
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\System32\cisvc.exe
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\system32\clipsrv.exe
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\system32\drivers\cmaudio.sys
Fri Mar 17 16:06:40 2006 => Scanning File C:\WINDOWS\System32\dllhost.exe
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\system32\svchost.exe
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\system32\svchost.exe
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\disk.sys
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\System32\dmadmin.exe
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\system32\drivers\dmboot.sys
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\system32\drivers\dmio.sys
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\system32\drivers\dmload.sys
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\system32\drivers\DMusic.sys
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\system32\drivers\drmkaud.sys
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\system32\services.exe
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\fdc.sys
Fri Mar 17 16:06:41 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\flpydisk.sys
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\system32\drivers\fltmgr.sys
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\ftdisk.sys
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\gameenum.sys
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\msgpc.sys
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\system32\drivers\HCWBT8XX.sys
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\hidusb.sys
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\system32\Drivers\HTTP.sys
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\i8042prt.sys
Fri Mar 17 16:06:42 2006 => Scanning File C:\PROGRA~1\GEMEIN~1\INSTAL~1\Driver\11\INTEL3~1\IDriverT.exe
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\System32\imapi.exe
Fri Mar 17 16:06:42 2006 => ERROR!!! Invalid Entry system32\drivers\InCDFs.sys in SYSTEM\CurrentControlSet\Services\InCDFs...
Fri Mar 17 16:06:42 2006 => ERROR!!! Invalid Entry system32\drivers\InCDPass.sys in SYSTEM\CurrentControlSet\Services\InCDPass...
Fri Mar 17 16:06:42 2006 => ERROR!!! Invalid Entry system32\drivers\InCDRm.sys in SYSTEM\CurrentControlSet\Services\InCDRm...
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\intelide.sys
Fri Mar 17 16:06:42 2006 => Scanning File C:\WINDOWS\system32\drivers\ip6fw.sys
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\ipinip.sys
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\ipnat.sys
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\ipsec.sys
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\irenum.sys
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\isapnp.sys
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\kbdclass.sys
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\system32\drivers\kmixer.sys
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\system32\lxcgcoms.exe
Fri Mar 17 16:06:43 2006 => Scanning File C:\PROGRA~1\GEMEIN~1\MICROS~1\VS7Debug\mdm.exe
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:43 2006 => Scanning File C:\WINDOWS\System32\mnmsrvc.exe
Fri Mar 17 16:06:44 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\mouclass.sys
Fri Mar 17 16:06:44 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\mouhid.sys
Fri Mar 17 16:06:44 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\mrxdav.sys
Fri Mar 17 16:06:44 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Fri Mar 17 16:06:44 2006 => Scanning File C:\WINDOWS\System32\msdtc.exe
Fri Mar 17 16:06:44 2006 => Scanning File C:\WINDOWS\system32\msiexec.exe
Fri Mar 17 16:06:44 2006 => Scanning File C:\WINDOWS\system32\drivers\MSKSSRV.sys
Fri Mar 17 16:06:44 2006 => Scanning File C:\WINDOWS\system32\drivers\MSPCLOCK.sys
Fri Mar 17 16:06:44 2006 => Scanning File C:\WINDOWS\system32\drivers\MSPQM.sys
Fri Mar 17 16:06:44 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\mssmbios.sys
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\system32\drivers\MSTEE.sys
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\system32\drivers\msmpu401.sys
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\NdisIP.sys
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\ndistapi.sys
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\ndisuio.sys
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\ndiswan.sys
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\netbios.sys
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\netbt.sys
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\system32\netdde.exe
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\system32\netdde.exe
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\System32\lsass.exe
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\System32\lsass.exe
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\system32\svchost.exe
Fri Mar 17 16:06:45 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\Drivers\ov519vid.sys
Fri Mar 17 16:06:46 2006 => ERROR!!! Invalid Entry system32\DRIVERS\P2k.sys in SYSTEM\CurrentControlSet\Services\P2k...
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\parport.sys
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\pci.sys
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\drivers\pfc.sys
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\services.exe
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\System32\lsass.exe
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\raspptp.sys
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\lsass.exe
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\psched.sys
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\ptilink.sys
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\rasacd.sys
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\raspppoe.sys
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\raspti.sys
Fri Mar 17 16:06:46 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\rdbss.sys
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\sessmgr.exe
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\redbook.sys
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\Drivers\RootMdm.sys
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\System32\locator.exe
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\svchost.exe
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\System32\rsvp.exe
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\lsass.exe
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\System32\SCardSvr.exe
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\drivers\scsiport.sys
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\secdrv.sys
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\svchost.exe
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\serenum.sys
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\serial.sys
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\SLIP.sys
Fri Mar 17 16:06:47 2006 => Scanning File C:\WINDOWS\system32\drivers\splitter.sys
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\system32\spoolsv.exe
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\System32\DRIVERS\sr.sys
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\srv.sys
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\StreamIP.sys
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\swenum.sys
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\system32\drivers\swmidi.sys
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\System32\dllhost.exe
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\system32\drivers\sysaudio.sys
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\system32\smlogsvc.exe
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:48 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\tcpip.sys
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\termdd.sys
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\system32\svchost.exe
Fri Mar 17 16:06:49 2006 => Scanning File C:\PROGRA~1\TUNEUP~1\WINSTY~2.EXE
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\system32\wdfmgr.exe
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\update.sys
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\System32\ups.exe
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\system32\drivers\usbaudio.sys
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\usbccgp.sys
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\usbhub.sys
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\usbprint.sys
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\usbscan.sys
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\usbser.sys
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\System32\drivers\vga.sys
Fri Mar 17 16:06:49 2006 => Scanning File C:\WINDOWS\System32\vssvc.exe
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\wanarp.sys
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\system32\drivers\wdmaud.sys
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\system32\svchost.exe
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\System32\wbem\wmiapsrv.exe
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\System32\svchost.exe

Fri Mar 17 16:06:50 2006 => Scanning HKLM\SYSTEM\CurrentControlSet\Services\VxD

Fri Mar 17 16:06:50 2006 => ***** Scanning Important System Files *****
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\system32\winsock.dll
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\WsBtn.dll
Fri Mar 17 16:06:50 2006 => Scanning File C:\WINDOWS\wsutil.exe
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\ws2help.dll
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\ws2_32.dll
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wscntfy.exe
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wscript.exe
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wscsvc.dll
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wscui.cpl
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wshatm.dll
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wshbth.dll
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wshcon.dll
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wshde.dll
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wshext.dll
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wship6.dll
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wshisn.dll
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wshnetbs.dll
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wshom.ocx
Fri Mar 17 16:06:51 2006 => Scanning File C:\WINDOWS\system32\wshrm.dll
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\system32\wshtcpip.dll
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\system32\wsnmp32.dll
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\system32\wsock32.dll
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\system32\wstdecod.dll
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\explorer.exe
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\explorer.scf
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\system32\rundll32.exe
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\system32\browseui.dll
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\notepad.exe
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\system32\notepad.exe
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\system32\ctfmon.exe
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\system32\cmd.exe
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\system32\kernel32.dll
Fri Mar 17 16:06:52 2006 => Scanning File C:\WINDOWS\system32\ntoskrnl.exe
Fri Mar 17 16:06:53 2006 => Scanning File C:\WINDOWS\system32\ntkrnlpa.exe
Fri Mar 17 16:06:53 2006 => Scanning File C:\WINDOWS\system32\HAL.DLL
Fri Mar 17 16:06:53 2006 => Scanning File C:\WINDOWS\system32\win32k.sys
Fri Mar 17 16:06:53 2006 => Scanning File C:\WINDOWS\system32\ntdll.dll
Fri Mar 17 16:06:53 2006 => Scanning File C:\WINDOWS\system32\advapi32.dll
Fri Mar 17 16:06:53 2006 => Scanning File C:\WINDOWS\system32\user32.dll
Fri Mar 17 16:06:53 2006 => Scanning File C:\WINDOWS\system32\gdi32.dll
Fri Mar 17 16:06:53 2006 => Scanning File C:\WINDOWS\system32\bootvid.dll
Fri Mar 17 16:06:53 2006 => Scanning File C:\WINDOWS\system32\command.com

Fri Mar 17 16:06:53 2006 => ***** Scanning Registry and File system for Adware/Spyware *****
Fri Mar 17 16:06:53 2006 => Loading Spyware Signatures from new External Database (Size: 153719).
Fri Mar 17 16:06:56 2006 => Indexed Spyware Databases Successfully Created...

Fri Mar 17 16:06:58 2006 => Offending Key found: HKLM\Software\magnet\handlers\limewire !!!
Fri Mar 17 16:06:58 2006 => Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.



Danke im Voraus

BataAlexander 17.03.2006 19:00

Hallo,

die Anleitung lesen und das Stichwort find.bat suchen ;)

Gruß

Schrulli


Alle Zeitangaben in WEZ +1. Es ist jetzt 08:58 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129