so vielen dank erstmal für die vielen Tips ...... :)
nach nochmaligen nachfragen was die freundin angestellt hat bevor es nicht mehr gefunzt hat hat sie mir folgendes geschickt. Sie hat es wohl bis zum Schritt - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run - ausgeführt.
Kann evtl. jemand damit etwas anfangen bzw. hat einen Tip es zu reparieren???
danke schon mal vorab
---------------------------------------------------------------------------------
When W32.Funner is executed, it performs the following actions:
1. Copies itself as:
* %System%\IEXPLORE.EXE
* %System%\EXPLORE.EXE
* %Windir%\rundll32.exe
* %System%\userinit32.exe
* c:\funny.exe
and executes the first three files listed.
Notes:
* The three files make sure that the other two are running and will restart them if any are stopped.
* These files require the MSVBVM60.DLL file, which is a component of the Microsoft Visual Basic run-time environment.
* %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
* %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
2. Creates a log file named %System%\bsfirst2.log.
3. Adds the value:
"Userinit"="userinit32.exe,"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
so that the userinit32.exe runs when you start Windows.
4. Adds the value:
"MMSystem"="%Windir%\rundll32.exe "%System%\mmsystem.dll"", RunDll32"
to some of the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
so that the rundll32.exe runs when you start Windows.
----------------------------------------------------------------------------------------------