| foxylady |  19.05.2008 14:09 |        Hallo undoreal,  
vielen Dank. Hoffe ich habe alles richtig gemacht. Muss wegen dem Umfang in mehreren Posts antworten.   
Happy day, Nadja   Blacklight-Log (keine Bedrohung gefunden)   Code:  
 05/19/08 02:55:36 [Info]: BlackLight Engine 1.0.70 initialized 
05/19/08 02:55:36 [Info]: OS: 5.1 build 2600 (Service Pack 2) 
05/19/08 02:55:37 [Note]: 7019 4 
05/19/08 02:55:37 [Note]: 7005 0 
05/19/08 02:56:45 [Note]: 7006 0 
05/19/08 02:56:45 [Note]: 7011 308 
05/19/08 02:56:45 [Note]: 7035 0 
05/19/08 02:56:46 [Note]: 7026 0 
05/19/08 02:56:46 [Note]: 7026 0 
05/19/08 02:56:49 [Note]: FSRAW library version 1.7.1024 
05/19/08 02:58:57 [Note]: 7007 0   Silentrunners-Log  Code:  
 "Silent Runners.vbs", revision 58, h**p://www.silentrunners.org/ 
Operating System: Windows XP SP2 
Output limited to non-default values, except where indicated by "{++}"     
Startup items buried in registry: 
---------------------------------   
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} 
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} 
"LaunchApp" = "Alaunch" ["Acer Inc."] 
"SynTPLpr" = "REM C:\Programme\Synaptics\SynTP\SynTPLpr.exe" [file not found] 
"SynTPEnh" = "REM C:\Programme\Synaptics\SynTP\SynTPEnh.exe" [file not found] 
"SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."] 
"AGRSMMSG" = "AGRSMMSG.exe" ["Agere Systems"] 
"SiSPower" = "Rundll32.exe SiSPower.dll,ModeAgent" [MS] 
"SiS Windows KeyHook" = "C:\WINDOWS\system32\keyhook.exe" ["Silicon Integrated Systems Corporation"] 
"PCMService" = ""C:\Programme\Arcade\PCMService.exe"" ["CyberLink Corp."] 
"IMJPMIG8.1" = ""C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32" [MS] 
"MSPY2002" = "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC" [null data] 
"PHIME2002ASync" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC" [MS] 
"PHIME2002A" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName" [MS] 
"QuickTime Task" = ""C:\Programme\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."] 
"eRecoveryService" = "C:\Windows\System32\Check.exe" ["acer Inc."] 
"hpppta" = "C:\Programme\HP Scan\PrecisionScan\hpppta.exe /ICON" ["Hewlett-Packard Company"] 
"NeroCheck" = "REM C:\WINDOWS\system32\NeroCheck.exe" [file not found] 
"OpwareSE2" = ""C:\Programme\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"" ["ScanSoft, Inc."] 
"winlogon" = "C:\WINDOWS\csrss.exe" [null data] 
"HP Software Update" = "C:\Programme\HP\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Co."]   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ 
{055FD26D-3A88-4e15-963D-DC8493744B1D}\(Default) = "XTTBPos00" 
  -> {HKLM...CLSID} = "XTTBPos00 Class" 
                   \InProcServer32\(Default) = "C:\Programme\ICQToolbar\toolbaru.dll" ["IE Toolbar"] 
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = "AcroIEHlprObj Class" 
                   \InProcServer32\(Default) = "C:\Programme\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"] 
{AE7CD045-E861-484f-8273-0445EE161910}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = "AcroIEToolbarHelper Class" 
                   \InProcServer32\(Default) = "C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll" [null data] 
{AE84A6AA-A333-4B92-B276-C11E2212E4FE}\(Default) = "HP Smart Web Printing 1.0" 
  -> {HKLM...CLSID} = "CPrintEnhancer Object" 
                   \InProcServer32\(Default) = "C:\Programme\HP\Smart Web Printing\SmartWebPrinting.dll" ["Hewlett-Packard Co."]   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ 
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "CPL-Erweiterung für Anzeigeverschiebung" 
  -> {HKLM...CLSID} = "CPL-Erweiterung für Anzeigeverschiebung" 
                   \InProcServer32\(Default) = "deskpan.dll" [file not found] 
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Erweiterung für HyperTerminal-Icons" 
  -> {HKLM...CLSID} = "HyperTerminal Icon Ext" 
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."] 
"{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel" 
  -> {HKLM...CLSID} = (no title provided) 
                   \InProcServer32\(Default) = "C:\Programme\Synaptics\SynTP\SynTPCpl.dll" ["Synaptics, Inc."] 
"{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}" = "Adobe.Acrobat.ContextMenu" 
  -> {HKLM...CLSID} = "Acrobat Elements Context Menu" 
                   \InProcServer32\(Default) = "C:\Programme\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll" ["Adobe Systems Inc."] 
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip" 
  -> {HKLM...CLSID} = "WinZip" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."] 
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip" 
  -> {HKLM...CLSID} = "WinZip" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."] 
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip" 
  -> {HKLM...CLSID} = "WinZip" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."] 
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip" 
  -> {HKLM...CLSID} = "WinZip" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."] 
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler" 
  -> {HKLM...CLSID} = "Microsoft Office Outlook" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS] 
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler" 
  -> {HKLM...CLSID} = "Outlook-Dateisymbolerweiterung" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS] 
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler" 
  -> {HKLM...CLSID} = (no title provided) 
                   \InProcServer32\(Default) = "C:\Programme\Microsoft Office\OFFICE11\msohev.dll" [MS] 
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player" 
  -> {HKLM...CLSID} = "RealOne Player Context Menu Class" 
                   \InProcServer32\(Default) = "C:\Programme\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."] 
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension" 
  -> {HKLM...CLSID} = "WinRAR" 
                   \InProcServer32\(Default) = "C:\Programme\WinRAR\rarext.dll" [null data] 
"{73B24247-042E-4EF5-ADC2-42F62E6FD654}" = "ICQ Lite Shell Extension" 
  -> {HKLM...CLSID} = "MCLiteShellExt Class" 
                   \InProcServer32\(Default) = "C:\Programme\ICQLite\ICQLiteShell.dll" [empty string] 
"{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5}" = "dBpoweramp Music Converter" 
  -> {HKLM...CLSID} = "dMCIShell Class" 
                   \InProcServer32\(Default) = "C:\Programme\dBpoweramp\dMCShell.dll" ["Illustrate"]   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ 
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" 
  -> {HKLM...CLSID} = "WPDShServiceObj Class" 
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]   
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\ 
<<!>> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}" 
  -> {HKLM...CLSID} = (no title provided) 
                   \InProcServer32\(Default) = "C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]   
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\ 
{FED7043D-346A-414D-ACD7-550D052499A7}\(Default) = "dBpoweramp Column Handler" 
  -> {HKLM...CLSID} = "dBpShell Class" 
                   \InProcServer32\(Default) = "C:\Programme\dBpoweramp\dBShell.dll" ["Illustrate"]   
HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ 
Adobe.Acrobat.ContextMenu\(Default) = "{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}" 
  -> {HKLM...CLSID} = "Acrobat Elements Context Menu" 
                   \InProcServer32\(Default) = "C:\Programme\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll" ["Adobe Systems Inc."] 
ICQLiteMenu\(Default) = "{73B24247-042E-4EF5-ADC2-42F62E6FD654}" 
  -> {HKLM...CLSID} = "MCLiteShellExt Class" 
                   \InProcServer32\(Default) = "C:\Programme\ICQLite\ICQLiteShell.dll" [empty string] 
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" 
  -> {HKLM...CLSID} = "WinRAR" 
                   \InProcServer32\(Default) = "C:\Programme\WinRAR\rarext.dll" [null data] 
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}" 
  -> {HKLM...CLSID} = "WinZip" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]   
HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ 
ICQLiteMenu\(Default) = "{73B24247-042E-4EF5-ADC2-42F62E6FD654}" 
  -> {HKLM...CLSID} = "MCLiteShellExt Class" 
                   \InProcServer32\(Default) = "C:\Programme\ICQLite\ICQLiteShell.dll" [empty string] 
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" 
  -> {HKLM...CLSID} = "WinRAR" 
                   \InProcServer32\(Default) = "C:\Programme\WinRAR\rarext.dll" [null data] 
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}" 
  -> {HKLM...CLSID} = "WinZip" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]   
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\ 
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" 
  -> {HKLM...CLSID} = "WinRAR" 
                   \InProcServer32\(Default) = "C:\Programme\WinRAR\rarext.dll" [null data] 
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}" 
  -> {HKLM...CLSID} = "WinZip" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]     
Group Policies {policy setting}: 
--------------------------------   
Note: detected settings may not have any effect.   
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\   
"NoWinKeys" = (REG_DWORD) dword:0x00000001 
{Disable Windows+X hotkeys}   
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\   
"disableregistrytools" = (REG_DWORD) dword:0x00000000 
{Prevent access to registry editing tools}   
HKCU\Software\Policies\Microsoft\Windows\System\   
"disablecmd" = (REG_DWORD) dword:0x00000000 
{Disable the command prompt}   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\   
"shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001 
{Shutdown: Allow system to be shut down without having to log on}   
"undockwithoutlogon" = (REG_DWORD) dword:0x00000001 
{Devices: Allow undock without having to log on}     
Active Desktop and Wallpaper: 
-----------------------------   
Active Desktop may be disabled at this entry: 
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState   
Displayed if Active Desktop enabled and wallpaper not set by Group Policy: 
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ 
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp"   
Displayed if Active Desktop disabled and wallpaper not set by Group Policy: 
HKCU\Control Panel\Desktop\ 
"Wallpaper" = "C:\Dokumente und Einstellungen\*****\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp"     
Windows Portable Device AutoPlay Handlers 
-----------------------------------------   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\   
dMCAudioCDInput\ 
"Provider" = "dBpoweramp CD Ripper" 
"InvokeProgID" = "dMC.AudioCD.Autorun" 
"InvokeVerb" = "open" 
HKLM\SOFTWARE\Classes\dMC.AudioCD.Autorun\shell\open\command\(Default) = ""C:\Programme\dBpoweramp\CDGrab.exe" %1" ["Illustrate"]   
MSWPDShellNamespaceHandler\ 
"Provider" = "@%SystemRoot%\System32\WPDShextRes.dll,-501" 
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}" 
"InitCmdLine" = " " 
  -> {HKLM...CLSID} = "WPDShextAutoplay" 
                   \LocalServer32\(Default) = "C:\WINDOWS\system32\WPDShextAutoplay.exe" [MS]   
NTIBurner\ 
"Provider" = "NTI CD-Maker" 
"InvokeProgID" = "NTIBurnerOpen" 
"InvokeVerb" = "open" 
HKLM\SOFTWARE\Classes\NTIBurnerOpen\shell\open\command\(Default) = "C:\Programme\NewTech Infosystems\NTI CD & DVD-Maker 7\Cdmkr32.exe" ["NewTech Infosystems, Inc."]   
PCinemaDCameraArrival\ 
"Provider" = "Arcade" 
"InvokeProgID" = "Picture" 
"InvokeVerb" = "PlayWithPowerCinema" 
HKLM\SOFTWARE\Classes\Picture\shell\PlayWithPowerCinema\Command\(Default) = ""C:\Programme\Arcade\PCM3.exe" DSC" ["Acer Corp."]   
PCinemaDVArrival\ 
"Provider" = "Arcade" 
"ProgID" = "Shell.HWEventHandlerShellExecute" 
"InitCmdLine" = ""C:\Programme\Arcade\PCM3.exe" DV" 
HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" 
  -> {HKLM...CLSID} = "ShellExecute HW Event Handler" 
                   \LocalServer32\(Default) = "rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]   
PCinemaMediaFilesArrival\ 
"Provider" = "Arcade" 
"InvokeProgID" = "MeidaFiles" 
"InvokeVerb" = "BrowseWithPowerCinema" 
HKLM\SOFTWARE\Classes\MeidaFiles\shell\BrowseWithPowerCinema\Command\(Default) = ""C:\Programme\Arcade\PCM3.exe"" ["Acer Corp."]   
PCinemaPlayCDAudioOnArrival\ 
"Provider" = "Arcade" 
"InvokeProgID" = "AudioCD" 
"InvokeVerb" = "PlayWithPowerCinema" 
HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithPowerCinema\Command\(Default) = ""C:\Programme\Arcade\PCM3.exe" CD "%L"" ["Acer Corp."]   
PCinemaPlayDVDMovieOnArrival\ 
"Provider" = "Arcade" 
"InvokeProgID" = "DVD" 
"InvokeVerb" = "PlayWithPowerCinema" 
HKLM\SOFTWARE\Classes\DVD\shell\PlayWithPowerCinema\Command\(Default) = ""C:\Programme\Arcade\PCM3.exe" MOVIE "%L"" ["Acer Corp."]   
PPCDBurningOnArrival\ 
"Provider" = "PowerProducer" 
"InvokeProgID" = "Picture" 
"InvokeVerb" = "OpenWithPowerProducer" 
HKLM\SOFTWARE\Classes\Picture\shell\OpenWithPowerProducer\Command\(Default) = ""C:\Programme\CyberLink\PowerProducer\Producer.exe"" ["Cyberlink"]   
PPDCameraArrival\ 
"Provider" = "PowerProducer" 
"InvokeProgID" = "Picture" 
"InvokeVerb" = "OpenWithPowerProducer" 
HKLM\SOFTWARE\Classes\Picture\shell\OpenWithPowerProducer\Command\(Default) = ""C:\Programme\CyberLink\PowerProducer\Producer.exe"" ["Cyberlink"]   
PPDVArrival\ 
"Provider" = "PowerProducer" 
"ProgID" = "Shell.HWEventHandlerShellExecute" 
"InitCmdLine" = "C:\Programme\CyberLink\PowerProducer\Producer.exe" 
HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" 
  -> {HKLM...CLSID} = "ShellExecute HW Event Handler" 
                   \LocalServer32\(Default) = "rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]   
RPCDBurningOnArrival\ 
"Provider" = "RealPlayer" 
"InvokeProgID" = "RealPlayer.CDBurn.6" 
"InvokeVerb" = "open" 
HKLM\SOFTWARE\Classes\RealPlayer.CDBurn.6\shell\open\command\(Default) = "C:\Programme\Real\RealPlayer\RealPlay.exe /burn "%1"" ["RealNetworks, Inc."]   
RPDeviceOnArrival\ 
"Provider" = "RealPlayer" 
"ProgID" = "RealPlayer.HWEventHandler" 
HKLM\SOFTWARE\Classes\RealPlayer.HWEventHandler\CLSID\(Default) = "{67E76F1D-BDE2-4052-913C-2752366192D2}" 
  -> {HKLM...CLSID} = "RealNetworks Scheduler" 
                   \LocalServer32\(Default) = ""C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -autoplay" ["RealNetworks, Inc."]   
RPPlayCDAudioOnArrival\ 
"Provider" = "RealPlayer" 
"InvokeProgID" = "RealPlayer.AudioCD.6" 
"InvokeVerb" = "play" 
HKLM\SOFTWARE\Classes\RealPlayer.AudioCD.6\shell\play\command\(Default) = "C:\Programme\Real\RealPlayer\RealPlay.exe  /play %1 " ["RealNetworks, Inc."]   
RPPlayDVDMovieOnArrival\ 
"Provider" = "RealPlayer" 
"InvokeProgID" = "RealPlayer.DVD.6" 
"InvokeVerb" = "play" 
HKLM\SOFTWARE\Classes\RealPlayer.DVD.6\shell\play\command\(Default) = "C:\Programme\Real\RealPlayer\RealPlay.exe  /dvd %1 " ["RealNetworks, Inc."]   
RPPlayMediaOnArrival\ 
"Provider" = "RealPlayer" 
"InvokeProgID" = "RealPlayer.AutoPlay.6" 
"InvokeVerb" = "open" 
HKLM\SOFTWARE\Classes\RealPlayer.AutoPlay.6\shell\open\command\(Default) = "C:\Programme\Real\RealPlayer\RealPlay.exe /autoplay "%1"" ["RealNetworks, Inc."]     
Startup items in "*****" & "All Users" startup folders: 
-------------------------------------------------------   
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart 
"Utility Tray" -> shortcut to: "C:\WINDOWS\system32\sistray.exe" ["Silicon Integrated Systems Corporation"] 
"Adobe Gamma Loader" -> shortcut to: "C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."] 
"Acrobat Assistant" -> shortcut to: "C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe" ["Adobe Systems Inc."] 
"VPN Client" -> shortcut to: "C:\WINDOWS\Installer\{176130BC-99A1-41FE-A78B-56045E33AD70}\Icon3E5562ED7.ico -user_logon" [null data] 
"HP Digital Imaging Monitor" -> shortcut to: "C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe" ["Hewlett-Packard Co."]     
Winsock2 Service Provider DLLs: 
-------------------------------   
Namespace Service Providers   
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]   
Transport Service Providers   
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: 
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 19 
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05     
Toolbars, Explorer Bars, Extensions: 
------------------------------------   
Toolbars   
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ 
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" 
  -> {HKLM...CLSID} = "Adobe PDF" 
                   \InProcServer32\(Default) = "C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll" [null data] 
"{855F3B16-6D32-4FE6-8A56-BBB695989046}" 
  -> {HKLM...CLSID} = "ICQ Toolbar" 
                   \InProcServer32\(Default) = "C:\Programme\ICQToolbar\toolbaru.dll" ["IE Toolbar"]   
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ 
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" = (no title provided) 
  -> {HKLM...CLSID} = "Adobe PDF" 
                   \InProcServer32\(Default) = "C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll" [null data] 
"{855F3B16-6D32-4FE6-8A56-BBB695989046}" = (no title provided) 
  -> {HKLM...CLSID} = "ICQ Toolbar" 
                   \InProcServer32\(Default) = "C:\Programme\ICQToolbar\toolbaru.dll" ["IE Toolbar"]   
Explorer Bars   
HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ 
{182EC0BE-5110-49C8-A062-BEB1D02A220B}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = "Adobe PDF" 
                   \InProcServer32\(Default) = "C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll" [null data] 
{FE54FA40-D68C-11D2-98FA-00C0F0318AFE}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = "Real.com" 
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\Shdocvw.dll" [MS]   
HKLM\SOFTWARE\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Recherchieren" 
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] 
InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS]   
Extensions (Tools menu items, main toolbar menu buttons)   
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\ 
{13C1DBF6-7535-495C-91F6-8C13714ED485}\ 
"ButtonText" = "Absolute Poker" 
"MenuText" = "Absolute Poker" 
"Exec" = "C:\Dokumente und Einstellungen\*****\Startmenü\Programme\Absolute Poker\Absolute Poker.lnk" [file not found]   
{49783ED4-258D-4F9F-BE11-137C18D3E543}\ 
"ButtonText" = "Titan Poker" 
"MenuText" = "Titan Poker" 
"Exec" = "C:\Poker\Titan Poker\casino.exe" [null data]   
{92780B25-18CC-41C8-B9BE-3C9C571A8263}\ 
"ButtonText" = "Recherchieren"   
{94148DB5-B42D-4915-95DA-2CBB4F7095BF}\ 
"ButtonText" = "UltimateBet" 
"MenuText" = "UltimateBet" 
"Exec" = "C:\Programme\Poker\Ultimate Bet\UltimateBet.exe" ["UltimateBet"]   
{A68FC757-51CF-4F3C-B13A-BFB8CA69BB99}\ 
"ButtonText" = "CDPoker" 
"MenuText" = "CDPoker" 
"Exec" = "D:\Poker\CDPoker\casino.exe" [null data]   
{B4B52284-A248-4C51-9F7C-F0A0C67FCC9D}\ 
"ButtonText" = "PartyCasino.com" 
"MenuText" = "PartyCasino.com" 
"Exec" = "C:\Programme\Poker\PartyPoker\PartyCasino\RunCasino.exe" [file not found]   
{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ 
"ButtonText" = "PartyPoker.com" 
"MenuText" = "PartyPoker.com" 
"Exec" = "C:\Programme\Poker\PartyPoker\PartyPoker\RunApp.exe" [empty string]   
{B863453A-26C3-4E1F-A54D-A2CD196348E9}\ 
"ButtonText" = "ICQ Lite" 
"MenuText" = "ICQ Lite" 
"Exec" = "C:\Programme\ICQLite\ICQLite.exe" ["ICQ Ltd."]   
{CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\ 
"ButtonText" = "Real.com"     
Miscellaneous IE Hijack Points 
------------------------------   
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\ 
<<H>> "{855F3B16-6D32-4fe6-8A56-BBB695989046}" = (no title provided) 
  -> {HKLM...CLSID} = "ICQ Toolbar" 
                   \InProcServer32\(Default) = "C:\Programme\ICQToolbar\toolbaru.dll" ["IE Toolbar"]     
Running Services (Display Name, Service Name, Path {Service DLL}): 
------------------------------------------------------------------   
Cisco Systems, Inc. VPN Service, CVPND, ""C:\Programme\VPN Client\cvpnd.exe"" ["Cisco Systems, Inc."] 
Firebird Guardian - DefaultInstance, FirebirdGuardianDefaultInstance, "C:\Programme\Firebird\Firebird_1_5\bin\fbguard.exe -s" ["The Firebird Project"] 
Firebird Server - DefaultInstance, FirebirdServerDefaultInstance, "C:\Programme\Firebird\Firebird_1_5\bin\fbserver.exe -s" ["The Firebird Project"] 
HP CUE DeviceDiscovery Service, hpqddsvc, "C:\WINDOWS\system32\svchost.exe -k hpdevmgmt" {"C:\Programme\HP\Digital Imaging\bin\hpqddsvc.dll" ["Hewlett-Packard Co."]} 
hpqcxs08, hpqcxs08, "C:\WINDOWS\system32\svchost.exe -k hpdevmgmt" {"C:\Programme\HP\Digital Imaging\bin\hpqcxs08.dll" ["Hewlett-Packard Co."]} 
Net Driver HPZ12, Net Driver HPZ12, "C:\WINDOWS\System32\svchost.exe -k HPZ12" {"C:\WINDOWS\system32\HPZinw12.dll" ["Hewlett-Packard"]} 
Notebook Manager Service, anbmService, "C:\Acer\eManager\anbmServ.exe" ["OSA Technologies Inc."] 
Pml Driver HPZ12, Pml Driver HPZ12, "C:\WINDOWS\System32\svchost.exe -k HPZ12" {"C:\WINDOWS\system32\HPZipm12.dll" ["Hewlett-Packard"]} 
PostgreSQL Database Server 8.3, pgsql-8.3, "C:\Programme\PostgreSQL\8.3\bin\pg_ctl.exe runservice -w -N "pgsql-8.3" -D "C:\Programme\PostgreSQL\8.3\data\"" ["PostgreSQL Global Development Group"]     
Print Monitors: 
---------------   
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ 
Adobe PDF Port\Driver = "C:\WINDOWS\system32\AdobePDF.dll" ["Adobe Systems Incorporated."] 
Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS] 
Microsoft Shared Fax Monitor\Driver = "FXSMON.DLL" [MS] 
PCL hpz3l4v2\Driver = "hpz3l4v2.dll" ["Hewlett-Packard Company"] 
PCL hpz3l4x6\Driver = "hpz3l4x6.dll" ["Hewlett-Packard Company"]     
---------- (launch time: 2008-05-19 03:13:45) 
<<!>>: Suspicious data at a malware launch point. 
<<H>>: Suspicious data at a browser hijack point.   
+ This report excludes default entries except where indicated. 
+ To see *everywhere* the script checks and *everything* it finds, 
  launch it from a command prompt or a shortcut with the -all parameter. 
+ The search for DESKTOP.INI DLL launch points on all local fixed drives 
  took 45 seconds. 
---------- (total run time: 646 seconds)      |