so vielen dank erstmal für die vielen Tips ......  :)  
  
nach nochmaligen nachfragen was die freundin angestellt hat bevor es nicht mehr gefunzt hat hat sie mir folgendes geschickt. Sie hat es wohl bis zum Schritt - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run - ausgeführt. 
  
Kann evtl. jemand damit etwas anfangen bzw. hat einen Tip es zu reparieren??? 
  
  
danke schon mal vorab 
  
--------------------------------------------------------------------------------- 
  
When W32.Funner is executed, it performs the following actions: 
  
1. Copies itself as: 
* %System%\IEXPLORE.EXE 
* %System%\EXPLORE.EXE 
* %Windir%\rundll32.exe 
* %System%\userinit32.exe 
* c:\funny.exe 
  
and executes the first three files listed. 
  
Notes: 
* The three files make sure that the other two are running and will restart them if any are stopped. 
* These files require the MSVBVM60.DLL file, which is a component of the Microsoft Visual Basic run-time environment. 
* %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP). 
* %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt. 
  
2. Creates a log file named %System%\bsfirst2.log. 
  
3. Adds the value: 
  
"Userinit"="userinit32.exe," 
  
to the registry key: 
  
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon 
  
so that the userinit32.exe runs when you start Windows. 
  
4. Adds the value: 
  
"MMSystem"="%Windir%\rundll32.exe "%System%\mmsystem.dll"", RunDll32" 
  
to some of the following registry keys: 
  
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 
  
so that the rundll32.exe runs when you start Windows. 
  
----------------------------------------------------------------------------------------------