Trojaner Problem

Maja
Hallo Mopao,
vielen Dank!

Ich habe die Anweisungen befolgt und hier die files kopiert:

Schritt 1:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:38:23, on 05.09.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Intel\Wireless\Bin\EvtEng.exe
C:\Programme\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Programme\Synaptics\SynTP\SynTPLpr.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe
C:\acer\Empowering Technology\ePower\epm-dm.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\Programme\Launch Manager\Wbutton.exe
C:\Programme\Launch Manager\HotkeyApp.exe
C:\Programme\Launch Manager\LaunchAp.exe
C:\Acer\Empowering Technology\admtray.exe
C:\Programme\Launch Manager\OSDCtrl.exe
C:\Programme\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Programme\Babylon\Babylon-Pro\Babylon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programme\Rainlendar\Rainlendar.exe
C:\Programme\Intel\Wireless\Bin\RegSrvc.exe
c:\Programme\Sophos\Sophos Anti-Virus\SAVAdminService.exe
c:\Programme\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\svchost.exe
c:\Programme\Sophos\Sophos Anti-Virus\SavProgress.exe
C:\WINDOWS\explorer.exe
C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Programme\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Programme\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\ENDNOT~1\EndNote.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\Programme\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar1.dll
O3 - Toolbar: Babylon - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - C:\Programme\Babylon\Babylon-Pro\Babylon Toolbar\BabylonIEToolBar.dll
O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\GEMEIN~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [epm-dm] c:\acer\Empowering Technology\ePower\epm-dm.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Programme\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [LManager] "C:\Programme\Launch Manager\HotkeyApp.exe"
O4 - HKLM\..\Run: [LaunchAp] "C:\Programme\Launch Manager\LaunchAp.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
O4 - HKLM\..\Run: [CtrlVol] "C:\Programme\Launch Manager\CtrlVol.exe"
O4 - HKLM\..\Run: [LMgrOSD] "C:\Programme\Launch Manager\OSDCtrl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [StatusClient] C:\Programme\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [Babylon Client] C:\Programme\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [keyman.exe] C:\Programme\Tavultesoft\Keyman\keyman.exe
O4 - HKCU\..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Rainlendar.lnk = C:\Programme\Rainlendar\Rainlendar.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Programme\Sophos\AutoUpdate\ALMon.exe
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon - res://C:\Programme\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Programme\WinPcap\rpcapd.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sophos Anti-Virus Statusreporter (SAVAdminService) - Sophos Plc - c:\Programme\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - c:\Programme\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - c:\Programme\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: System Scheduler - Unknown owner - C:\WINDOWS\Offline Web Pages\svchost.exe

--
End of file - 8888 bytes

Schritt 2:

Die 30 neuesten Dateien im Ordner Windows:

***** ***** ***** ***** *****
***** Scanning C:\WINDOWS *****
***** ***** ***** ***** *****

05.09.2007 0.log 10 10:0
Soft 05.09.2007 ModemLog_AC97 10 10:4.168
05.09.2007 wiadebug.log 09 50:159
05.09.2007 ComponentList.xml 09 49:97
05.09.2007 bootstat.dat 09 49:2.048
05.09.2007 WindowsUpdate.log 09 46:1.125.738
04.09.2007 SchedLgU.Txt 17 27:32.574
04.09.2007 wiaservc.log 17 27:50
04.09.2007 msgsocm.log 13 47:40.373
04.09.2007 netfxocm.log 13 47:140.955
04.09.2007 comsetup.log 13 47:295.084
04.09.2007 KB939683.log 13 47:12.034
04.09.2007 tabletoc.log 13 47:41.421
04.09.2007 ntdtcsetup.log 13 47:175.751
04.09.2007 imsins.log 13 47:1.355
04.09.2007 ocmsn.log 13 47:44.520
04.09.2007 ocgen.log 13 47:393.964
04.09.2007 tsoc.log 13 47:378.468
04.09.2007 MedCtrOC.log 13 47:56.258
04.09.2007 iis6.log 13 47:952.563
04.09.2007 msmqinst.log 13 47:258.976
04.09.2007 FaxSetup.log 13 47:841.468
04.09.2007 setupapi.log 13 46:42.964
03.09.2007 spupdsvc.log 13 57:1.064.960
03.09.2007 KB936021.log 12 33:18.098
03.09.2007 imsins.BAK 12 33:1.355
03.09.2007 updspapi.log 12 33:50.471


Die 50 neuesten Dateien im Ordner Windows\system32:

***** ***** ***** ***** *****
***** Scanning C:\WINDOWS\system32 *****
***** ***** ***** ***** *****

05.09.2007 eRLog.ini 10 10:451
05.09.2007 wpa.dbl 09 13:13.646
03.09.2007 TZLog.log 12 32:357.852
03.08.2007 MRT.exe 06 34:16.789.464
02.08.2007 FNTCACHE.DAT 10 01:454.064
02.08.2007 perfc009.dat 09 55:69.066
02.08.2007 perfh009.dat 09 55:433.606
02.08.2007 perfc007.dat 09 55:81.534
02.08.2007 perfh007.dat 09 55:450.192
02.08.2007 PerfStringBackup.INI 09 55:1.009.824
30.07.2007 wuaucpl.cpl.mui 19 20:30.040
30.07.2007 wuapi.dll.mui 19 20:30.040
30.07.2007 wuaueng.dll 19 19:1.712.984
30.07.2007 wuapi.dll 19 19:549.720
30.07.2007 wucltui.dll 19 19:325.976
30.07.2007 wuweb.dll 19 19:203.096
30.07.2007 wuaucpl.cpl 19 19:216.408
30.07.2007 cdm.dll 19 19:92.504
30.07.2007 wuauclt.exe 19 19:53.080
30.07.2007 wups2.dll 19 19:43.352
30.07.2007 wucltui.dll.mui 19 18:34.136
30.07.2007 wups.dll 19 18:33.624
30.07.2007 wuaueng.dll.mui 19 18:20.824
18.07.2007 tzchange.exe 14 42:60.416
26.06.2007 wininet.dll 16 09:664.576
26.06.2007 msxml3.dll 08 08:1.104.896
19.06.2007 gdi32.dll 15 31:282.112
14.06.2007 shlwapi.dll 20 09:474.624
14.06.2007 urlmon.dll 20 09:617.472
14.06.2007 mshtml.dll 20 09:3.079.680
14.06.2007 shdocvw.dll 20 09:1.494.528
14.06.2007 pngfilt.dll 20 09:39.424
14.06.2007 cdfview.dll 20 09:152.064
14.06.2007 browseui.dll 20 09:1.023.488
14.06.2007 danim.dll 20 09:1.056.256
14.06.2007 dxtrans.dll 20 09:205.312
14.06.2007 msrating.dll 20 09:146.432
14.06.2007 iepeers.dll 20 09:251.392
14.06.2007 mshtmled.dll 20 09:449.024
14.06.2007 jsproxy.dll 20 09:16.384
14.06.2007 inseng.dll 20 09:96.768
14.06.2007 extmgr.dll 20 09:55.808
14.06.2007 dxtmsft.dll 20 09:357.888
14.06.2007 mstime.dll 20 09:532.480
14.06.2007 xpsp3res.dll 16 24:123.904
11.06.2007 wmp.dll 23 51:10.834.944
01.06.2007 HLDRV.LOG 19 08:1.853


***** ***** ***** ***** *****
***** Scanning C:\WINDOWS\system32\drivers\etc\hosts *****
***** ***** ***** ***** *****

# Copyright (c) 1993-1999 Microsoft Corp.
#
# Dies ist eine HOSTS-Beispieldatei, die von Microsoft TCP/IP
# für Windows 2000 verwendet wird.
#
# Diese Datei enthält die Zuordnungen der IP-Adressen zu Hostnamen.
# Jeder Eintrag muss in einer eigenen Zeile stehen. Die IP-
# Adresse sollte in der ersten Spalte gefolgt vom zugehörigen
# Hostnamen stehen.
# Die IP-Adresse und der Hostname müssen durch mindestens ein
# Leerzeichen getrennt sein.
#
# Zusätzliche Kommentare (so wie in dieser Datei) können in
# einzelnen Zeilen oder hinter dem Computernamen eingefügt werden,
# aber müssen mit dem Zeichen '#' eingegeben werden.
#
# Zum Beispiel:
#
# 102.54.94.97 rhino.acme.com # Quellserver
# 38.25.63.10 x.acme.com # x-Clienthost

127.0.0.1 localhost



***** ***** ***** ***** *****
***** Scanning Processe *****
***** ***** ***** ***** *****


Abbildname PID Sitzungsname Sitz.-Nr. Speichernutzung
========================= ===== ================ ========== ===============
System Idle Process 0 Console 0 28 K
System 4 Console 0 40 K
SMSS.EXE 604 Console 0 136 K
CSRSS.EXE 672 Console 0 3.648 K
WINLOGON.EXE 696 Console 0 5.204 K
SERVICES.EXE 740 Console 0 2.412 K
LSASS.EXE 752 Console 0 1.700 K
SVCHOST.EXE 900 Console 0 3.268 K
SVCHOST.EXE 976 Console 0 2.600 K
SVCHOST.EXE 1068 Console 0 20.884 K
SavService.exe 1112 Console 0 41.876 K
EvtEng.exe 1348 Console 0 588 K
S24EvMon.exe 1388 Console 0 520 K
SVCHOST.EXE 1448 Console 0 1.796 K
SVCHOST.EXE 1540 Console 0 2.292 K
BRSVC01A.EXE 1836 Console 0 84 K
SPOOLSV.EXE 1856 Console 0 1.676 K
BRSS01A.EXE 1868 Console 0 528 K
admServ.exe 1336 Console 0 2.176 K
SynTPLpr.exe 1640 Console 0 340 K
SynTPEnh.exe 1656 Console 0 2.056 K
IGFXTRAY.EXE 1672 Console 0 276 K
HKCMD.EXE 1680 Console 0 284 K
IGFXPERS.EXE 1688 Console 0 288 K
ISSCH.EXE 1708 Console 0 304 K
EPM-DM.EXE 1716 Console 0 2.936 K
eDSloader.exe 1724 Console 0 296 K
Monitor.exe 1732 Console 0 1.852 K
WButton.exe 1744 Console 0 2.568 K
HotkeyApp.exe 1764 Console 0 5.460 K
LaunchAp.exe 1780 Console 0 404 K
ADMTRAY.EXE 2012 Console 0 4.332 K
OSDCtrl.exe 224 Console 0 364 K
StatusClient.exe 1520 Console 0 2.484 K
Babylon.exe 1144 Console 0 5.000 K
CTFMON.EXE 264 Console 0 712 K
NMBgMonitor.exe 404 Console 0 1.876 K
CDAC11BA.EXE 1948 Console 0 136 K
MDM.EXE 1980 Console 0 1.164 K
Rainlendar.exe 2116 Console 0 1.412 K
RegSrvc.exe 2180 Console 0 132 K
SAVAdminService.exe 2256 Console 0 2.836 K
ALsvc.exe 2384 Console 0 1.748 K
SVCHOST.EXE 2460 Console 0 1.492 K
SavProgress.exe 3508 Console 0 1.696 K
EXPLORER.EXE 3344 Console 0 11.696 K
wmiprvse.exe 2492 Console 0 5.076 K
alg.exe 2816 Console 0 3.492 K
GoogleToolbarNotifier.exe 3004 Console 0 1.836 K
iexplore.exe 560 Console 0 31.776 K
HijackThis.exe 3232 Console 0 4.116 K
WINWORD.EXE 2708 Console 0 50.852 K
iexplore.exe 2676 Console 0 32.872 K
EndNote.exe 312 Console 0 21.084 K
winzip32.exe 2000 Console 0 9.896 K
cmd.exe 3216 Console 0 1.860 K
tasklist.exe 2908 Console 0 5.080 K
wmiprvse.exe 3228 Console 0 5.644 K



Microsoft Windows XP [Version 5.1.2600]


http://www.paules-pc-forum.de
***** Malware Team *****


***** Ende des Scans 05.09.2007 um 13:28:28,71 ***

Schritt 3:
Search Navipromo version 2.0.9 began on 05.09.2007 at 13:33:23,10

!!! Warning, this report may include legitimate files/programs !!!
!!! Post this report on the forum you are being helped !!!
!!! Don't continue with removal unless instructed by an authorized helper !!!

Fix running from C:\Programme\navilog1
Updated on 20.08.2007 at 22h30 by IL-MAFIOSO

Done in normal mode

*** Searching for installed Software ***




*** Search folders in C:\WINDOWS ***




*** Search folders in C:\Programme ***




*** Search folders in C:\Dokumente und Einstellungen\All Users\Application Data ***




*** Search folders in C:\Dokumente und Einstellungen\krim\Anwendungsdaten ***



*** Search with BlackLight Engine/F-secure ***
BlackLight Engine is a product of F-secure, for more info:
http://www.f-secure.com/blacklight/blacklight_help.html


F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
======================================

Copyright 2005-2006 F-Secure Corporation. All rights reserved.
This is a beta version. It will expire on 1st of October, 2007.
Version information: 2.2.1064.

[+] Started on 09/05/07 at 13:33:24.
[+] Initializing ...
[+] Starting scan, press Ctrl-C to abort.
[+] Scanning for hidden items ........................
[+] Scan complete.
[+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
[+] Exited on 09/05/07 at 13:34:06 (return code = 0).


*** Search with GenericNaviSearch ***
!!! Possibility of legitims files in the result !!!
!!! To be always checked before manually deleting !!!

Files found :

No File found !

Suspicious Files :

No Suspicious File found !



*** Search files ***




*** Search registry keys ***


Search in [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]



Search in [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]



Search Magic Control Key



*** Complementary Search ***
(Search specifics files)

1)Search known files:


2)Heuristic Search :
*
**
***
****
*****
******
*******
********


3)Certificates Search :

Certificate Egroup not found !


*** Search completed on 05.09.2007 at 13:34:58,96 ***


Schritt 4:
09/05/07 13:45:03 [Info]: BlackLight Engine 1.0.64 initialized
09/05/07 13:45:03 [Info]: OS: 5.1 build 2600 (Service Pack 2)
09/05/07 13:45:03 [Note]: 7019 4
09/05/07 13:45:03 [Note]: 7005 0
09/05/07 13:45:11 [Note]: 7006 0
09/05/07 13:45:11 [Note]: 7011 3344
09/05/07 13:45:11 [Note]: 7026 0
09/05/07 13:45:11 [Note]: 7026 0
09/05/07 13:45:14 [Note]: FSRAW library version 1.7.1022
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:45:58 [Note]: 2000 1012
09/05/07 13:46:31 [Note]: 7007 0

Vielen Dank!
Maja