R1 - HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R0 - HKCU\Software\Microsoft\Internet Connection Wizard, Shellnext: http://www.sarc.com/avcenter/cgi-bin/virauto.cgi?vid=36524
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Default_Page_URL: http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Default_Search_URL: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch: http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
R1 - HKU\S-1-5\Software\Microsoft\Internet Explorer\Main, Search Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKU\S-1-5\Software\Microsoft\Internet Explorer\Main, Start Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R0 - HKU\S-1-5\Software\Microsoft\Internet Connection Wizard, Shellnext: http://www.sarc.com/avcenter/cgi-bin/virauto.cgi?vid=36524
O2 - BHO:AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO:(no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO:CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Programme\Norton AntiVirus\NavShExt.dll
F2 - HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows, load:
F2 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon, Userinit: E:\WINDOWS\system32\userinit.exe,
F2 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs:
F2 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon, shell: Explorer.exe
F2 - HKU\.DEFA\Software\Microsoft\Windows NT\CurrentVersion\Windows, load:
F2 - HKU\S-1-5\Software\Microsoft\Windows NT\CurrentVersion\Windows, load:
F2 - HKU\S-1-5\Software\Microsoft\Windows NT\CurrentVersion\Windows, load:
F2 - HKU\S-1-5\Software\Microsoft\Windows NT\CurrentVersion\Windows, load:
F2 - HKU\S-1-5\Software\Microsoft\Windows NT\CurrentVersion\Windows, load:
O4 - HKCU..\Run:[CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU..\Run:[NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU..\Run:[MSMSGS] "E:\Programme\Messenger\msmsgs.exe" /background
O4 - HKLM..\Run:[nForce Tray Options] sstray.exe /r
O4 - HKLM..\Run:[NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM..\Run:[nwiz] nwiz.exe /install
O4 - HKLM..\Run:[Mirabilis ICQ] E:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM..\Run:[WinampAgent] E:\Programme\Winamp\winampa.exe
O4 - HKLM..\Run:[Lexmark X1100 Series] "E:\Programme\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM..\Run:[ToADiMon.exe] E:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis1\ToADiMon.exe -TOnlineAutodialStart
O4 - HKLM..\Run:[AVGCtrl] "E:\Programme\AVPersonal\AVGNT.EXE" /min
O4 - HKLM..\Run:[TkBellExe] E:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe -osboot
O4 - HKLM..\Run:[Trojancheck 6 Guard] E:\Programme\Trojancheck 6\tcguard.exe
O4 - HKLM..\Run:[Zone Labs Client] E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM..\Run:[ccApp] "E:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM..\Run:[ccRegVfy] "E:\Programme\Gemeinsame Dateien\Symantec Shared\ccRegVfy.exe"
O4 - HKLM..\Run:[SunJavaUpdateSched] E:\Programme\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKU\.DEFA..\Run:[CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE
O4 - HKU\S-1-5..\Run:[CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE
O4 - HKU\S-1-5..\Run:[CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE
O4 - HKU\S-1-5..\Run:[CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
O4 - HKU\S-1-5..\Run:[NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKU\S-1-5..\Run:[MSMSGS] "E:\Programme\Messenger\msmsgs.exe" /background
O4 - HKU\S-1-5..\Run:[CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE
Stealthed *.dll's:
Stealthed *.exe's:
Stealthed *.sys's: