Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: spoolw.exe

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 15.04.2008, 23:20   #16
Sabina
 
spoolw.exe - Standard

spoolw.exe



Den folgenden Text in den Editor (Start - Zubehör - Editor) kopieren und als cfscript.txt mit 'Speichern unter' auf dem Desktop. Gib an "Alle Dateien" - Speichern



Code:
ATTFilter
KILLALL:: 

Registry:: 
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{72A128E0-2240-40c8-9E92-5387D64F839E}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"spoolw"=-
"igfxsvc"=-
"ctfmon.exe"=-
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{1D516154-6AC0-426C-92A1-FDC0073E8A1B}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxsvc]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spoolw]

File:: 
C:\WINDOWS\xml2u32.dll
C:\WINDOWS\system32\609467646.dat
C:\WINDOWS\system32\igfxsvc.exe
C:\WINDOWS\system32\spoolw.exe
C:\Dokumente und Einstellungen\odkies\Lokale Einstellungen\Temp\ntwzhook.dll
         
Man sollte jetzt auf dem Desktop diese Datei cfscript.txt finden.

cfscript.txt und mit der rechten Maustaste auf das Symbol von Combofix ziehen




danach: Combofix noch einmal anwenden

PC neustarten

---

poste das neue Log von Combofix
__________________
MfG Sabina

Alt 18.04.2008, 10:32   #17
Janis
 
spoolw.exe - Standard

spoolw.exe



Ui, diesmal ist er ja noch länger:

ComboFix 08-04-14.2 - odkies 2008-04-16 11:14:17.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1031.18.536 [GMT 2:00]
ausgeführt von:: C:\Dokumente und Einstellungen\odkies\Desktop\Antivir\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\_000007_.tmp.dll
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\_000019_.tmp.dll

.
((((((((((((((((((((((( Dateien erstellt von 2008-03-16 bis 2008-04-16 ))))))))))))))))))))))))))))))
.

2008-04-16 11:04 . 2008-04-16 11:12 <DIR> d-------- C:\WINDOWS\LastGood
2008-04-15 22:12 . 2006-08-21 11:14 128,896 -----c--- C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-04-15 22:12 . 2006-08-21 11:14 23,040 -----c--- C:\WINDOWS\system32\dllcache\fltmc.exe
2008-04-15 22:12 . 2006-08-21 14:26 16,896 -----c--- C:\WINDOWS\system32\dllcache\fltlib.dll
2008-04-15 17:21 . 2007-07-09 15:11 584,192 --a------ C:\WINDOWS\system32\SET10B.tmp
2008-04-15 17:21 . 2007-07-09 15:11 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-04-15 17:13 . 2007-04-18 18:13 2,854,400 --a------ C:\WINDOWS\system32\SET85.tmp
2008-04-15 17:12 . 2005-10-21 00:25 1,094,144 --a------ C:\WINDOWS\system32\SET67.tmp
2008-04-14 22:29 . 2008-04-16 11:17 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-04-14 22:29 . 2008-04-16 11:16 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-04-14 20:17 . 2008-04-14 20:17 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-14 20:17 . 2008-04-14 20:34 <DIR> d-------- C:\SDFix
2008-04-14 20:04 . 2008-04-14 20:04 <DIR> d-------- C:\_OTMoveIt
2008-04-12 19:04 . 2008-04-12 19:04 <DIR> d-------- C:\Programme\CCleaner
2008-03-21 16:02 . 2008-03-21 16:02 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SUPERAntiSpyware.com
2008-03-20 21:31 . 2008-03-20 21:31 <DIR> d-------- C:\fsaua.data
2008-03-20 16:30 . 2008-03-20 22:46 <DIR> d-a------ C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP

.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-14 18:03 --------- d-----w C:\Programme\Trillian
2008-03-20 08:03 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 12:51 --------- d-----w C:\Programme\Symphony
2008-02-20 06:50 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:33 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 22:29 3,080,704 ----a-w C:\WINDOWS\system32\SET91.tmp
2008-02-16 08:59 665,088 ----a-w C:\WINDOWS\system32\SET89.tmp
2008-02-16 08:59 617,984 ----a-w C:\WINDOWS\system32\SET8A.tmp
2008-02-16 08:59 474,624 ----a-w C:\WINDOWS\system32\SET8B.tmp
2008-02-16 08:59 1,494,528 ----a-w C:\WINDOWS\system32\SET8C.tmp
2008-02-16 08:59 1,023,488 ----a-w C:\WINDOWS\system32\SET99.tmp
2008-02-15 23:03 374,272 ----a-w C:\WINDOWS\system32\SET9B.tmp
2007-10-12 13:20 109 --sha-w C:\WINDOWS\system32\609467646.dat
.

((((((((((((((((((((((((((((( snapshot@2008-04-15_17.10.44,54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-11-17 17:37:46 356,352 ----a-w C:\WINDOWS\$hf_mig$\KB873339\SP2QFE\hypertrm.dll
+ 2004-10-14 08:34:42 8,704 ----a-w C:\WINDOWS\$hf_mig$\KB873339\spmsg.dll
+ 2004-10-14 08:36:18 172,032 ----a-w C:\WINDOWS\$hf_mig$\KB873339\spuninst.exe
+ 2004-10-14 08:36:16 21,504 ----a-w C:\WINDOWS\$hf_mig$\KB873339\update\spcustom.dll
+ 2004-10-14 08:34:42 663,552 ----a-w C:\WINDOWS\$hf_mig$\KB873339\update\update.exe
+ 2004-10-13 16:21:24 1,694,208 ----a-w C:\WINDOWS\$hf_mig$\KB887472\SP2QFE\msmsgs.exe
+ 2004-10-14 09:34:42 8,704 ----a-w C:\WINDOWS\$hf_mig$\KB887472\spmsg.dll
+ 2004-10-14 09:36:18 172,032 ----a-w C:\WINDOWS\$hf_mig$\KB887472\spuninst.exe
+ 2004-10-14 09:36:16 21,504 ----a-w C:\WINDOWS\$hf_mig$\KB887472\update\spcustom.dll
+ 2004-10-14 09:34:42 663,552 ----a-w C:\WINDOWS\$hf_mig$\KB887472\update\update.exe
+ 2005-04-22 05:19:51 57,344 ----a-w C:\WINDOWS\$hf_mig$\KB890046\SP2QFE\agentdpv.dll
+ 2005-05-17 00:44:45 20,480 ----a-w C:\WINDOWS\$hf_mig$\KB890046\SP2QFE\spru0407.dll
+ 2005-02-24 18:34:56 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB890046\spmsg.dll
+ 2005-02-24 18:34:56 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB890046\spuninst.exe
+ 2005-02-24 18:34:56 22,240 ----a-w C:\WINDOWS\$hf_mig$\KB890046\update\spcustom.dll
+ 2005-02-24 18:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB890046\update\update.exe
+ 2005-02-24 18:34:58 378,080 ----a-w C:\WINDOWS\$hf_mig$\KB890046\update\updspapi.dll
+ 2004-11-30 12:46:28 8,704 ----a-w C:\WINDOWS\$hf_mig$\KB891781\spmsg.dll
+ 2004-11-30 18:22:38 172,032 ----a-w C:\WINDOWS\$hf_mig$\KB891781\spuninst.exe
+ 2004-11-30 18:22:38 21,504 ----a-w C:\WINDOWS\$hf_mig$\KB891781\update\spcustom.dll
+ 2004-11-30 12:46:30 663,552 ----a-w C:\WINDOWS\$hf_mig$\KB891781\update\update.exe
+ 2005-07-08 16:29:45 249,344 ----a-w C:\WINDOWS\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
+ 2005-02-24 18:34:56 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB893756\spmsg.dll
+ 2005-02-24 18:34:56 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB893756\spuninst.exe
+ 2005-07-07 17:27:08 30,720 ----a-w C:\WINDOWS\$hf_mig$\KB893756\update\arpidfix.exe
+ 2005-02-24 18:34:56 22,240 ----a-w C:\WINDOWS\$hf_mig$\KB893756\update\spcustom.dll
+ 2005-02-24 18:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB893756\update\update.exe
+ 2005-02-24 18:34:58 378,080 ----a-w C:\WINDOWS\$hf_mig$\KB893756\update\updspapi.dll
+ 2005-05-26 23:26:50 10,752 ----a-w C:\WINDOWS\$hf_mig$\KB896358\SP2QFE\hh.exe
+ 2005-05-27 02:10:34 41,472 ----a-w C:\WINDOWS\$hf_mig$\KB896358\SP2QFE\hhsetup.dll
+ 2005-05-27 02:10:34 155,136 ----a-w C:\WINDOWS\$hf_mig$\KB896358\SP2QFE\itircl.dll
+ 2005-05-27 02:10:34 137,216 ----a-w C:\WINDOWS\$hf_mig$\KB896358\SP2QFE\itss.dll
+ 2005-02-24 18:34:56 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB896358\spmsg.dll
+ 2005-02-24 18:34:56 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB896358\spuninst.exe
+ 2005-02-24 18:34:56 22,240 ----a-w C:\WINDOWS\$hf_mig$\KB896358\update\spcustom.dll
+ 2005-02-24 18:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB896358\update\update.exe
+ 2005-02-24 18:34:58 378,080 ----a-w C:\WINDOWS\$hf_mig$\KB896358\update\updspapi.dll
+ 2005-06-11 00:17:13 57,856 ----a-w C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
+ 2005-02-24 18:34:56 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB896423\spmsg.dll
+ 2005-02-24 18:34:56 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB896423\spuninst.exe
+ 2005-06-29 14:54:32 30,720 ----a-w C:\WINDOWS\$hf_mig$\KB896423\update\arpidfix.exe
+ 2005-02-24 18:34:56 22,240 ----a-w C:\WINDOWS\$hf_mig$\KB896423\update\spcustom.dll
+ 2005-02-24 18:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB896423\update\update.exe
+ 2005-02-24 18:34:58 378,080 ----a-w C:\WINDOWS\$hf_mig$\KB896423\update\updspapi.dll
+ 2005-02-24 18:34:56 15,584 ------w C:\WINDOWS\$hf_mig$\KB899591\spmsg.dll
+ 2005-02-24 18:34:56 213,216 ------w C:\WINDOWS\$hf_mig$\KB899591\spuninst.exe
+ 2005-06-29 14:54:32 30,720 ------w C:\WINDOWS\$hf_mig$\KB899591\update\arpidfix.exe
+ 2005-02-24 18:34:56 22,240 ------w C:\WINDOWS\$hf_mig$\KB899591\update\spcustom.dll
+ 2005-02-24 18:34:56 727,776 ------w C:\WINDOWS\$hf_mig$\KB899591\update\update.exe
+ 2005-02-24 18:34:58 378,080 ------w C:\WINDOWS\$hf_mig$\KB899591\update\updspapi.dll
+ 2005-07-26 04:28:59 225,792 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\catsrv.dll
+ 2005-07-26 04:28:59 625,152 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\catsrvut.dll
+ 2005-07-26 04:28:59 110,080 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatex.dll
+ 2005-07-26 04:29:00 498,688 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatq.dll
+ 2005-07-26 04:29:01 60,416 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\colbact.dll
+ 2005-07-26 04:29:01 195,072 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\comadmin.dll
+ 2005-07-26 04:29:02 97,792 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\comrepl.dll
+ 2005-07-26 04:29:04 1,267,200 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\comsvcs.dll
+ 2005-07-26 04:29:04 540,160 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\comuid.dll
+ 2005-07-26 04:29:04 243,200 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\es.dll
+ 2005-07-25 23:42:35 8,704 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\migregdb.exe
+ 2005-07-26 04:29:05 425,472 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\msdtcprx.dll
+ 2005-07-26 04:29:10 945,152 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\msdtctm.dll
+ 2005-07-26 04:29:10 161,280 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\msdtcuiu.dll
+ 2005-07-26 04:29:10 66,560 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\mtxclu.dll
+ 2005-07-26 04:29:11 91,136 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\mtxoci.dll
+ 2005-07-26 04:29:16 1,286,144 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\ole32.dll
+ 2005-07-26 04:29:17 74,752 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\olecli32.dll
+ 2005-07-26 04:29:17 37,376 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\olecnv32.dll
+ 2005-07-26 04:29:19 398,336 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\rpcss.dll
+ 2005-07-26 04:29:19 101,376 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\txflog.dll
+ 2005-07-26 04:29:19 11,776 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\xolehlp.dll
+ 2005-02-24 18:34:56 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB902400\spmsg.dll
+ 2005-02-24 18:34:56 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB902400\spuninst.exe
+ 2005-07-25 17:21:18 30,720 ----a-w C:\WINDOWS\$hf_mig$\KB902400\update\arpidfix.exe
+ 2005-02-24 18:34:56 22,240 ----a-w C:\WINDOWS\$hf_mig$\KB902400\update\spcustom.dll
+ 2005-02-24 18:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB902400\update\update.exe
+ 2005-02-24 18:34:58 378,080 ----a-w C:\WINDOWS\$hf_mig$\KB902400\update\updspapi.dll
+ 2006-06-22 10:36:56 180,736 ----a-w C:\WINDOWS\$hf_mig$\KB911280\SP2QFE\rasmans.dll
+ 2005-10-12 23:11:08 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB911280\spmsg.dll
+ 2005-10-12 23:11:08 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB911280\spuninst.exe
+ 2005-10-12 23:11:04 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB911280\update\spcustom.dll
+ 2005-10-12 23:11:11 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB911280\update\update.exe
+ 2005-10-12 23:11:17 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB911280\update\updspapi.dll
+ 2006-03-23 05:52:23 143,360 ----a-w C:\WINDOWS\$hf_mig$\KB911562\SP2QFE\msadco.dll
+ 2005-10-12 23:11:08 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB911562\spmsg.dll
+ 2005-10-12 23:11:08 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB911562\spuninst.exe
+ 2005-10-12 23:11:04 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB911562\update\spcustom.dll
+ 2005-10-12 23:11:11 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB911562\update\update.exe
+ 2005-10-12 23:11:17 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB911562\update\updspapi.dll
+ 2006-06-01 19:39:47 163,840 ----a-w C:\WINDOWS\$hf_mig$\KB918439\SP2QFE\jgdw400.dll
+ 2006-06-01 19:39:47 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB918439\SP2QFE\jgpl400.dll
+ 2005-10-12 23:11:08 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB918439\spmsg.dll
+ 2005-10-12 23:11:08 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB918439\spuninst.exe
+ 2005-10-12 23:11:04 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB918439\update\spcustom.dll
+ 2005-10-12 23:11:11 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB918439\update\update.exe
+ 2005-10-12 23:11:17 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB918439\update\updspapi.dll
+ 2006-07-21 08:28:16 72,704 ----a-w C:\WINDOWS\$hf_mig$\KB920670\SP2QFE\hlink.dll
+ 2005-10-12 23:15:13 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB920670\spmsg.dll
+ 2005-10-12 23:15:13 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB920670\spuninst.exe
+ 2005-10-12 23:15:13 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB920670\update\spcustom.dll
+ 2005-10-12 23:15:15 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB920670\update\update.exe
+ 2005-10-12 23:15:23 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB920670\update\updspapi.dll
+ 2006-06-22 05:22:09 69,120 ----a-w C:\WINDOWS\$hf_mig$\KB920685\SP2QFE\ciodm.dll
+ 2006-06-22 05:22:10 1,441,792 ----a-w C:\WINDOWS\$hf_mig$\KB920685\SP2QFE\query.dll
+ 2005-10-12 23:11:08 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB920685\spmsg.dll
+ 2005-10-12 23:11:08 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB920685\spuninst.exe
+ 2005-10-12 23:11:04 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB920685\update\spcustom.dll
+ 2005-10-12 23:11:11 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB920685\update\update.exe
+ 2005-10-12 23:11:17 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB920685\update\updspapi.dll
+ 2006-10-13 12:41:39 64,000 ----a-w C:\WINDOWS\$hf_mig$\KB923980\SP2QFE\nwapi32.dll
+ 2006-10-13 12:41:39 146,432 ----a-w C:\WINDOWS\$hf_mig$\KB923980\SP2QFE\nwprovau.dll
+ 2006-10-13 10:39:12 163,456 ----a-w C:\WINDOWS\$hf_mig$\KB923980\SP2QFE\nwrdr.sys
+ 2006-10-13 12:41:39 65,536 ----a-w C:\WINDOWS\$hf_mig$\KB923980\SP2QFE\nwwks.dll
+ 2005-10-12 23:15:13 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB923980\spmsg.dll
+ 2005-10-12 23:15:13 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB923980\spuninst.exe
+ 2005-10-12 23:15:13 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB923980\update\spcustom.dll
+ 2005-10-12 23:15:15 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB923980\update\update.exe
+ 2005-10-12 23:15:23 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB923980\update\updspapi.dll
+ 2006-08-17 12:41:25 734,208 ----a-w C:\WINDOWS\$hf_mig$\KB924270\SP2QFE\lsasrv.dll
+ 2006-08-17 12:41:25 337,408 ----a-w C:\WINDOWS\$hf_mig$\KB924270\SP2QFE\netapi32.dll
+ 2006-08-17 12:41:25 132,096 ----a-w C:\WINDOWS\$hf_mig$\KB924270\SP2QFE\wkssvc.dll
+ 2005-10-12 23:11:08 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB924270\spmsg.dll
+ 2005-10-12 23:11:08 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB924270\spuninst.exe
+ 2005-10-12 23:11:04 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB924270\update\spcustom.dll
+ 2005-10-12 23:11:11 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB924270\update\update.exe
+ 2005-10-12 23:11:17 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB924270\update\updspapi.dll
+ 2006-09-04 06:13:53 1,497,088 ----a-w C:\WINDOWS\$hf_mig$\KB924496\SP2QFE\shdocvw.dll
+ 2005-10-12 23:11:08 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB924496\spmsg.dll
+ 2005-10-12 23:11:08 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB924496\spuninst.exe
+ 2005-10-12 23:11:04 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB924496\update\spcustom.dll
+ 2005-10-12 23:11:11 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB924496\update\update.exe
+ 2005-10-12 23:11:17 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB924496\update\updspapi.dll
+ 2007-03-08 15:48:39 282,112 ----a-w C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\gdi32.dll
+ 2007-03-08 15:48:39 40,960 ----a-w C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\mf3216.dll
+ 2007-03-08 15:48:39 579,584 ----a-w C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
+ 2007-03-08 15:45:09 1,844,096 ----a-w C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\win32k.sys
+ 2006-01-19 19:29:14 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB925902\spmsg.dll
+ 2006-01-19 19:29:14 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB925902\spuninst.exe
+ 2006-01-19 19:29:14 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB925902\update\spcustom.dll
+ 2006-01-19 19:29:14 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB925902\update\update.exe
+ 2006-01-19 19:29:15 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB925902\update\updspapi.dll
+ 2006-10-16 17:16:32 126,976 ----a-w C:\WINDOWS\$hf_mig$\KB926436\SP2QFE\oledlg.dll
+ 2005-10-12 23:15:13 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB926436\spmsg.dll
+ 2005-10-12 23:15:13 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB926436\spuninst.exe
+ 2005-10-12 23:15:13 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB926436\update\spcustom.dll
+ 2005-10-12 23:15:15 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB926436\update\update.exe
+ 2005-10-12 23:15:23 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB926436\update\updspapi.dll
+ 2007-05-16 15:26:27 86,528 ----a-w C:\WINDOWS\$hf_mig$\KB929123\SP2QFE\directdb.dll
+ 2007-05-16 15:26:27 683,520 ----a-w C:\WINDOWS\$hf_mig$\KB929123\SP2QFE\inetcomm.dll
+ 2007-05-16 15:26:31 1,314,816 ----a-w C:\WINDOWS\$hf_mig$\KB929123\SP2QFE\msoe.dll
+ 2007-05-16 15:26:33 510,976 ----a-w C:\WINDOWS\$hf_mig$\KB929123\SP2QFE\wab32.dll
+ 2007-05-16 15:26:33 85,504 ----a-w C:\WINDOWS\$hf_mig$\KB929123\SP2QFE\wabimp.dll
+ 2006-01-19 19:29:14 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB929123\spmsg.dll
+ 2006-01-19 19:29:14 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB929123\spuninst.exe
+ 2006-01-19 19:29:14 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB929123\update\spcustom.dll
+ 2006-01-19 19:29:14 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB929123\update\update.exe
+ 2006-01-19 19:29:15 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB929123\update\updspapi.dll
+ 2007-02-05 20:19:54 185,856 ----a-w C:\WINDOWS\$hf_mig$\KB931261\SP2QFE\upnphost.dll
+ 2006-01-19 19:29:14 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB931261\spmsg.dll
+ 2006-01-19 19:29:14 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB931261\spuninst.exe
+ 2006-01-19 19:29:14 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB931261\update\spcustom.dll
+ 2006-01-19 19:29:14 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB931261\update\update.exe
+ 2006-01-19 19:29:15 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB931261\update\updspapi.dll
+ 2007-06-26 06:06:22 1,104,896 ----a-w C:\WINDOWS\$hf_mig$\KB936021\SP2QFE\msxml3.dll
+ 2005-10-12 23:11:08 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB936021\spmsg.dll
+ 2005-10-12 23:11:08 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB936021\spuninst.exe
+ 2005-10-12 23:11:04 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB936021\update\spcustom.dll
+ 2005-10-12 23:11:11 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB936021\update\update.exe
+ 2005-10-12 23:11:17 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB936021\update\updspapi.dll
+ 2007-06-13 13:10:08 1,036,288 ----a-w C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
+ 2005-10-12 23:11:08 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB938828\spmsg.dll
+ 2005-10-12 23:11:08 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB938828\spuninst.exe
+ 2005-10-12 23:11:04 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB938828\update\spcustom.dll
+ 2005-10-12 23:11:11 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB938828\update\update.exe
+ 2005-10-12 23:11:17 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB938828\update\updspapi.dll
+ 2007-10-30 16:53:32 360,832 ----a-w C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
+ 2007-03-06 01:14:12 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spmsg.dll
+ 2007-03-06 01:14:17 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spuninst.exe
+ 2007-03-06 01:14:11 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\spcustom.dll
+ 2007-03-06 01:14:35 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\update.exe
+ 2007-03-06 01:15:25 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\updspapi.dll
+ 2008-03-20 07:56:37 1,846,016 ----a-w C:\WINDOWS\$hf_mig$\KB941693\SP2QFE\win32k.sys
+ 2007-03-06 01:14:12 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spmsg.dll
+ 2007-03-06 01:14:17 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spuninst.exe
+ 2007-03-06 01:14:11 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\spcustom.dll
+ 2007-03-06 01:14:35 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\update.exe
+ 2007-03-06 01:15:25 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\updspapi.dll
+ 2007-12-18 09:38:59 179,712 ----a-w C:\WINDOWS\$hf_mig$\KB946026\SP2QFE\mrxdav.sys
+ 2007-03-06 01:14:12 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB946026\spmsg.dll
+ 2007-03-06 01:14:17 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB946026\spuninst.exe
+ 2007-03-06 01:14:11 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\spcustom.dll
+ 2007-03-06 01:14:35 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\update.exe
+ 2007-03-06 01:15:25 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\updspapi.dll
+ 2008-02-16 09:30:52 1,024,000 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\browseui.dll
+ 2008-02-16 09:30:52 152,064 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\cdfview.dll
+ 2008-02-16 09:30:53 1,056,256 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\danim.dll
+ 2008-02-16 09:30:53 357,888 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\dxtmsft.dll
+ 2008-02-16 09:30:53 205,312 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\dxtrans.dll
+ 2008-02-16 09:30:53 55,808 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\extmgr.dll
+ 2008-02-15 09:07:53 18,432 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\iedw.exe
+ 2008-02-16 09:30:53 251,904 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\iepeers.dll
+ 2008-02-16 09:30:53 96,768 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\inseng.dll
+ 2008-02-16 09:30:53 16,384 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\jsproxy.dll
+ 2008-02-16 09:30:55 3,087,872 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\mshtml.dll
+ 2008-02-16 09:30:55 449,024 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\mshtmled.dll
+ 2008-02-16 09:30:55 146,432 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\msrating.dll
+ 2008-02-16 09:30:55 532,480 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\mstime.dll
+ 2008-02-16 09:30:55 39,424 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\pngfilt.dll
+ 2008-02-16 09:30:56 1,499,136 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\shdocvw.dll
+ 2008-02-16 09:30:57 474,624 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\shlwapi.dll
+ 2008-02-15 23:03:14 374,272 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\spru0407.dll
+ 2008-02-16 09:30:57 620,544 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\urlmon.dll
+ 2008-02-16 09:30:57 671,744 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\wininet.dll
__________________


Alt 18.04.2008, 10:45   #18
Janis
 
spoolw.exe - Standard

spoolw.exe



+ 2007-03-06 01:14:12 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB947864\spmsg.dll
+ 2007-03-06 01:14:17 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB947864\spuninst.exe
+ 2007-03-06 01:14:11 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB947864\update\spcustom.dll
+ 2007-03-06 01:14:35 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB947864\update\update.exe
+ 2007-03-06 01:15:25 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB947864\update\updspapi.dll
+ 2001-08-18 12:00:00 121,856 -c----w C:\WINDOWS\$NtUninstallKB926436$\oledlg.dll
+ 2005-10-12 23:15:13 217,312 -c----w C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe
+ 2005-10-12 23:15:23 377,568 -c----w C:\WINDOWS\$NtUninstallKB926436$\spuninst\updspapi.dll
+ 2007-03-06 01:14:11 22,752 -c----w C:\WINDOWS\$NtUninstallKB942763$\spcustom.dll
+ 2007-03-06 01:14:12 15,584 -c----w C:\WINDOWS\$NtUninstallKB942763$\spmsg.dll
+ 2007-03-06 01:14:17 217,312 -c----w
C:\WINDOWS\$NtUninstallKB942763$\spuninst.exe
+ 2007-03-06 01:14:17 217,312 -c----w
C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe
+ 2007-03-06 01:15:25 377,568 -c----w C:\WINDOWS\$NtUninstallKB942763$\spuninst\updspapi.dll
+ 2007-03-06 01:14:35 725,728 -c----w C:\WINDOWS\$NtUninstallKB942763$\update.exe
+ 2007-03-06 01:15:25 377,568 -c----w C:\WINDOWS\$NtUninstallKB942763$\updspapi.dll
- 2008-04-15 14:54:33 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-16 09:01:31 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2006-03-17 00:33:10 262,784 ------w C:\WINDOWS\Driver Cache\i386\http.sys
+ 2006-06-14 08:47:45 172,416 ------w C:\WINDOWS\Driver Cache\i386\kmixer.sys
+ 2006-05-05 09:41:45 453,120 ------w C:\WINDOWS\Driver Cache\i386\mrxsmb.sys
+ 2005-03-02 18:06:17 2,138,112 ------w C:\WINDOWS\Driver Cache\i386\ntkrnlmp.exe
+ 2005-03-02 18:06:16 2,059,136 ------w C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
+ 2005-03-02 18:06:25 2,017,792 ------w C:\WINDOWS\Driver Cache\i386\ntkrpamp.exe
+ 2005-03-02 18:06:32 2,181,632 ------w C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
+ 2006-06-14 08:47:46 6,400 ------w C:\WINDOWS\Driver Cache\i386\splitter.sys
+ 2006-06-14 09:00:45 82,944 ------w C:\WINDOWS\Driver Cache\i386\wdmaud.sys
- 2004-08-03 22:57:58 10,752 ----a-w C:\WINDOWS\hh.exe
+ 2005-05-26 23:22:01 10,752 ----a-w C:\WINDOWS\hh.exe
+ 2004-08-03 22:57:22 354,304 ----a-w C:\WINDOWS\LastGood\system32\hypertrm.dll
- 2004-08-03 22:57:16 41,984 ----a-w C:\WINDOWS\msagent\agentdp2.dll
+ 2006-10-12 14:02:58 42,496 ----a-w C:\WINDOWS\msagent\agentdp2.dll
- 2004-08-03 22:57:16 58,880 ----a-w C:\WINDOWS\msagent\agentdpv.dll
+ 2007-03-09 13:48:08 57,344 ----a-w C:\WINDOWS\msagent\agentdpv.dll
- 2004-08-03 22:57:42 256,512 ----a-w C:\WINDOWS\msagent\agentsvr.exe
+ 2006-10-12 11:09:53 256,512 ----a-w C:\WINDOWS\msagent\agentsvr.exe
- 2004-08-03 22:57:16 56,832 ----a-w C:\WINDOWS\system32\authz.dll
+ 2005-03-02 18:09:46 56,832 ----a-w C:\WINDOWS\system32\authz.dll
- 2004-08-03 22:57:16 151,552 ----a-w C:\WINDOWS\system32\cdfview.dll
+ 2008-02-16 08:59:22 152,064 ----a-w C:\WINDOWS\system32\cdfview.dll
- 2004-08-03 22:57:18 69,120 ----a-w C:\WINDOWS\system32\ciodm.dll
+ 2006-06-22 05:06:23 69,120 ----a-w C:\WINDOWS\system32\ciodm.dll
- 2004-08-03 22:57:18 110,080 ----a-w C:\WINDOWS\system32\clbcatex.dll
+ 2005-07-26 04:39:43 110,080 ----a-w C:\WINDOWS\system32\clbcatex.dll
- 2004-08-03 22:57:18 195,584 ----a-w C:\WINDOWS\system32\Com\comadmin.dll
+ 2005-07-26 04:39:44 195,072 ----a-w C:\WINDOWS\system32\Com\comadmin.dll
- 2004-08-03 22:57:18 611,328 ----a-w C:\WINDOWS\system32\comctl32.dll
+ 2006-08-25 15:46:47 617,472 ----a-w C:\WINDOWS\system32\comctl32.dll
- 2001-08-18 12:00:00 82,432 ----a-w C:\WINDOWS\system32\comrepl.dll
+ 2005-07-26 04:39:44 97,792 ----a-w C:\WINDOWS\system32\comrepl.dll
- 2004-08-03 22:54:44 540,160 ----a-w C:\WINDOWS\system32\comuid.dll
+ 2005-07-26 04:39:46 540,160 ----a-w C:\WINDOWS\system32\comuid.dll
- 2004-08-03 22:57:18 1,055,744 ----a-w C:\WINDOWS\system32\danim.dll
+ 2008-02-16 08:59:22 1,056,256 ----a-w C:\WINDOWS\system32\danim.dll
- 2004-08-03 22:57:18 111,616 ----a-w C:\WINDOWS\system32\dhcpcsvc.dll
+ 2006-05-19 13:09:50 112,128 ----a-w C:\WINDOWS\system32\dhcpcsvc.dll
+ 2006-10-12 14:02:58 42,496 -c----w C:\WINDOWS\system32\dllcache\agentdp2.dll
+ 2007-03-09 13:48:08 57,344 -c--a-w C:\WINDOWS\system32\dllcache\agentdpv.dll
+ 2006-10-12 11:09:53 256,512 -c----w C:\WINDOWS\system32\dllcache\agentsvr.exe
+ 2008-02-16 08:59:21 1,023,488 -c----w C:\WINDOWS\system32\dllcache\browseui.dll
+ 2008-02-16 08:59:22 152,064 -c----w C:\WINDOWS\system32\dllcache\cdfview.dll
+ 2006-06-22 05:06:23 69,120 -c----w C:\WINDOWS\system32\dllcache\ciodm.dll
+ 2006-08-25 15:46:47 617,472 -c----w C:\WINDOWS\system32\dllcache\comctl32.dll
- 2001-08-18 12:00:00 82,432 -c--a-w C:\WINDOWS\system32\dllcache\comrepl.dll
+ 2005-07-26 04:39:44 97,792 -c--a-w C:\WINDOWS\system32\dllcache\comrepl.dll
+ 2008-02-16 08:59:22 1,056,256 -c----w C:\WINDOWS\system32\dllcache\danim.dll
+ 2006-05-19 13:09:50 112,128 -c----w C:\WINDOWS\system32\dllcache\dhcpcsvc.dll
+ 2007-05-16 15:11:38 86,528 -c----w C:\WINDOWS\system32\dllcache\directdb.dll
+ 2008-02-20 05:33:54 148,992 -c----w C:\WINDOWS\system32\dllcache\dnsapi.dll
+ 2008-02-20 05:33:54 45,568 -c----w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
+ 2006-08-24 11:17:12 500,278 -c----w C:\WINDOWS\system32\dllcache\dxmasf.dll
+ 2008-02-16 08:59:23 357,888 -c----w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-02-16 08:59:23 205,312 -c----w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2007-06-13 13:21:45 1,036,288 -c----w C:\WINDOWS\system32\dllcache\explorer.exe
+ 2008-02-16 08:59:23 55,808 -c----w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2001-08-18 12:00:00 79,360 -c--a-w C:\WINDOWS\system32\dllcache\fontsub.dll
+ 2005-10-17 21:20:02 80,896 -c--a-w C:\WINDOWS\system32\dllcache\fontsub.dll
+ 2008-02-20 06:50:29 282,624 -c----w C:\WINDOWS\system32\dllcache\gdi32.dll
- 2001-08-18 12:00:00 81,978 -c--a-w C:\WINDOWS\system32\dllcache\hlink.dll
+ 2006-07-21 08:29:00 72,704 -c--a-w C:\WINDOWS\system32\dllcache\hlink.dll
+ 2008-02-15 09:23:37 18,432 -c----w C:\WINDOWS\system32\dllcache\iedw.exe
+ 2008-02-16 08:59:23 251,392 -c----w C:\WINDOWS\system32\dllcache\iepeers.dll
+ 2007-08-21 06:16:14 683,520 -c----w C:\WINDOWS\system32\dllcache\inetcomm.dll
+ 2008-02-16 08:59:23 96,768 -c----w C:\WINDOWS\system32\dllcache\inseng.dll
+ 2006-05-19 13:09:50 95,744 -c----w C:\WINDOWS\system32\dllcache\iphlpapi.dll
- 2001-08-18 12:00:00 144,896 -c--a-w C:\WINDOWS\system32\dllcache\jgdw400.dll
+ 2006-06-01 18:47:07 163,840 -c--a-w C:\WINDOWS\system32\dllcache\jgdw400.dll
- 2001-08-18 12:00:00 42,496 -c--a-w C:\WINDOWS\system32\dllcache\jgpl400.dll
+ 2006-06-01 18:47:07 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jgpl400.dll
+ 2007-12-18 14:41:00 450,560 -c----w C:\WINDOWS\system32\dllcache\jscript.dll
+ 2008-02-16 08:59:23 16,384 -c----w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2007-04-16 15:53:05 1,058,304 -c----w C:\WINDOWS\system32\dllcache\kernel32.dll
+ 2006-06-14 08:47:45 172,416 -c----w C:\WINDOWS\system32\dllcache\kmixer.sys
+ 2007-11-07 09:27:10 729,600 -c----w C:\WINDOWS\system32\dllcache\lsasrv.dll
+ 2007-03-08 15:36:30 40,960 -c----w C:\WINDOWS\system32\dllcache\mf3216.dll
- 2001-08-18 12:00:00 924,432 -c--a-w C:\WINDOWS\system32\dllcache\mfc40u.dll
+ 2006-11-01 19:17:41 927,504 -c--a-w C:\WINDOWS\system32\dllcache\mfc40u.dll
+ 2006-10-14 08:13:25 981,760 -c----w C:\WINDOWS\system32\dllcache\mfc42u.dll
+ 2007-12-18 09:51:35 179,584 -c----w C:\WINDOWS\system32\dllcache\mrxdav.sys
+ 2006-05-05 09:41:45 453,120 -c----w C:\WINDOWS\system32\dllcache\mrxsmb.sys
+ 2006-11-27 14:54:15 539,136 -c----w C:\WINDOWS\system32\dllcache\msftedit.dll
+ 2008-02-16 22:29:28 3,080,704 -c----w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-02-16 08:59:28 449,024 -c----w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2005-05-04 12:45:32 2,890,240 -c--a-w C:\WINDOWS\system32\dllcache\msi.dll
+ 2007-04-18 16:13:24 2,854,400 -c--a-w C:\WINDOWS\system32\dllcache\msi.dll
+ 2007-05-16 15:11:55 1,314,816 -c----w C:\WINDOWS\system32\dllcache\msoe.dll
+ 2008-02-16 08:59:28 146,432 -c----w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-02-16 08:59:28 532,480 -c----w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2007-06-26 06:08:37 1,104,896 -c----w C:\WINDOWS\system32\dllcache\msxml3.dll
+ 2006-08-17 12:28:44 332,288 -c----w C:\WINDOWS\system32\dllcache\netapi32.dll
+ 2007-02-09 11:10:35 574,464 -c----w C:\WINDOWS\system32\dllcache\ntfs.sys
- 2001-08-18 12:00:00 58,880 -c--a-w C:\WINDOWS\system32\dllcache\nwapi32.dll
+ 2006-10-13 12:35:14 64,000 -c--a-w C:\WINDOWS\system32\dllcache\nwapi32.dll
+ 2006-10-13 12:35:14 146,432 -c----w C:\WINDOWS\system32\dllcache\nwprovau.dll
+ 2006-10-13 10:23:15 163,584 -c----w C:\WINDOWS\system32\dllcache\nwrdr.sys
+ 2006-10-13 12:35:14 65,536 -c----w C:\WINDOWS\system32\dllcache\nwwks.dll
+ 2007-12-04 18:40:03 550,912 -c----w C:\WINDOWS\system32\dllcache\oleaut32.dll
- 2001-08-18 12:00:00 68,608 -c--a-w C:\WINDOWS\system32\dllcache\olecli32.dll
+ 2005-07-26 04:39:50 74,752 -c--a-w C:\WINDOWS\system32\dllcache\olecli32.dll
- 2001-08-18 12:00:00 34,304 -c--a-w C:\WINDOWS\system32\dllcache\olecnv32.dll
+ 2005-07-26 04:39:50 37,888 -c--a-w C:\WINDOWS\system32\dllcache\olecnv32.dll
- 2001-08-18 12:00:00 121,856 -c--a-w C:\WINDOWS\system32\dllcache\oledlg.dll
+ 2006-10-16 16:15:58 126,976 -c--a-w C:\WINDOWS\system32\dllcache\oledlg.dll
+ 2008-02-16 08:59:28 39,424 -c----w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2007-10-29 22:42:30 1,293,312 -c----w C:\WINDOWS\system32\dllcache\quartz.dll
+ 2006-06-22 05:06:24 1,441,792 -c----w C:\WINDOWS\system32\dllcache\query.dll
+ 2006-06-26 17:40:34 8,192 -c----w C:\WINDOWS\system32\dllcache\rasadhlp.dll
+ 2006-06-22 10:47:23 181,248 -c----w C:\WINDOWS\system32\dllcache\rasmans.dll
+ 2006-05-05 09:47:57 174,592 -c----w C:\WINDOWS\system32\dllcache\rdbss.sys
+ 2006-11-27 14:54:15 433,152 -c----w C:\WINDOWS\system32\dllcache\riched20.dll
- 2001-08-18 12:00:00 200,064 -c--a-w C:\WINDOWS\system32\dllcache\rmcast.sys
+ 2006-07-13 08:48:58 202,240 -c--a-w C:\WINDOWS\system32\dllcache\rmcast.sys
+ 2007-04-25 14:22:27 144,896 -c----w C:\WINDOWS\system32\dllcache\schannel.dll
+ 2008-02-16 08:59:29 1,494,528 -c----w C:\WINDOWS\system32\dllcache\shdocvw.dll
+ 2008-02-16 08:59:29 474,624 -c----w C:\WINDOWS\system32\dllcache\shlwapi.dll
+ 2006-06-14 08:47:46 6,400 -c----w C:\WINDOWS\system32\dllcache\splitter.sys
+ 2006-08-24 11:19:40 246,814 -c----w C:\WINDOWS\system32\dllcache\strmdll.dll
+ 2006-10-20 01:38:26 715,776 -c----w C:\WINDOWS\system32\dllcache\sxs.dll
+ 2007-10-30 17:20:55 360,064 -c----w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2007-02-05 20:18:44 185,856 -c----w C:\WINDOWS\system32\dllcache\upnphost.dll
+ 2008-02-16 08:59:29 617,984 -c----w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2007-03-08 15:36:30 579,072 -c----w C:\WINDOWS\system32\dllcache\user32.dll
+ 2007-12-18 14:41:00 417,792 -c----w C:\WINDOWS\system32\dllcache\vbscript.dll
+ 2007-06-26 13:55:41 851,968 -c----w C:\WINDOWS\system32\dllcache\vgx.dll
+ 2007-05-16 15:12:01 510,976 -c----w C:\WINDOWS\system32\dllcache\wab32.dll
+ 2007-05-16 15:12:02 85,504 -c----w C:\WINDOWS\system32\dllcache\wabimp.dll
+ 2006-06-14 09:00:45 82,944 -c----w C:\WINDOWS\system32\dllcache\wdmaud.sys
+ 2008-03-20 08:03:19 1,845,376 -c----w C:\WINDOWS\system32\dllcache\win32k.sys
+ 2008-02-16 08:59:29 665,088 -c----w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2007-03-17 13:44:25 293,376 -c----w C:\WINDOWS\system32\dllcache\winsrv.dll
+ 2006-08-17 12:28:44 132,096 -c----w C:\WINDOWS\system32\dllcache\wkssvc.dll
- 2004-09-22 16:46:12 229,376 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
+ 2007-10-20 04:01:32 227,328 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
- 2004-09-22 16:46:32 2,362,104 -c--a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
+ 2006-12-07 06:40:49 2,362,184 -c--a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
- 2004-08-03 22:57:18 148,480 ----a-w C:\WINDOWS\system32\dnsapi.dll
+ 2008-02-20 05:33:54 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll
- 2004-08-03 21:01:20 124,800 ------w C:\WINDOWS\system32\drivers\fltmgr.sys
+ 2006-08-21 09:14:58 128,896 ------w C:\WINDOWS\system32\drivers\fltmgr.sys
- 2004-08-03 21:00:14 263,040 ------w C:\WINDOWS\system32\drivers\http.sys
+ 2006-03-17 00:33:10 262,784 ------w C:\WINDOWS\system32\drivers\http.sys
- 2004-08-03 21:04:52 134,912 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
+ 2004-09-29 22:28:37 134,912 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
- 2004-08-03 21:07:50 171,776 ----a-w C:\WINDOWS\system32\drivers\kmixer.sys
+ 2006-06-14 08:47:45 172,416 ----a-w C:\WINDOWS\system32\drivers\kmixer.sys
- 2004-08-03 21:00:58 181,248 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
+ 2007-12-18 09:51:35 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
- 2004-08-03 21:15:18 451,456 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
+ 2006-05-05 09:41:45 453,120 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
- 2004-08-03 21:15:10 574,592 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
+ 2007-02-09 11:10:35 574,464 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
- 2004-08-03 21:02:24 163,584 ----a-w C:\WINDOWS\system32\drivers\nwrdr.sys
+ 2006-10-13 10:23:15 163,584 ----a-w C:\WINDOWS\system32\drivers\nwrdr.sys
- 2004-08-03 21:20:08 176,512 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
+ 2006-05-05 09:47:57 174,592 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
- 2001-08-18 12:00:00 200,064 ----a-w C:\WINDOWS\system32\drivers\RMCast.sys
+ 2006-07-13 08:48:58 202,240 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
- 2001-08-18 12:00:00 27,440 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
+ 2007-11-13 10:25:53 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
- 2004-08-03 21:07:48 6,400 ----a-w C:\WINDOWS\system32\drivers\splitter.sys
+ 2006-06-14 08:47:46 6,400 ----a-w C:\WINDOWS\system32\drivers\splitter.sys
- 2004-08-03 21:14:42 359,040 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
+ 2007-10-30 17:20:55 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
- 2004-08-03 21:15:06 82,944 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
+ 2006-06-14 09:00:45 82,944 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
- 2004-08-03 22:57:18 499,741 ----a-w C:\WINDOWS\system32\dxmasf.dll
+ 2006-08-24 11:17:12 500,278 ----a-w C:\WINDOWS\system32\dxmasf.dll
- 2004-08-03 22:57:18 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-02-16 08:59:23 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2004-08-03 22:57:18 201,728 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-02-16 08:59:23 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2004-08-03 22:57:20 55,808 ------w C:\WINDOWS\system32\extmgr.dll
+ 2008-02-16 08:59:23 55,808 ------w C:\WINDOWS\system32\extmgr.dll
- 2004-08-03 22:57:20 16,896 ------w C:\WINDOWS\system32\fltlib.dll
+ 2006-08-21 12:26:05 16,896 ----a-w C:\WINDOWS\system32\fltlib.dll
- 2004-08-03 22:57:54 22,528 ------w C:\WINDOWS\system32\fltmc.exe
+ 2006-08-21 09:14:58 23,040 ----a-w C:\WINDOWS\system32\fltmc.exe
- 2008-03-14 16:38:54 262,232 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-04-16 09:01:26 262,232 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2001-08-18 12:00:00 79,360 ----a-w C:\WINDOWS\system32\fontsub.dll
+ 2005-10-17 21:20:02 80,896 ----a-w C:\WINDOWS\system32\fontsub.dll
- 2004-08-03 22:57:22 38,912 ----a-w C:\WINDOWS\system32\hhsetup.dll
+ 2005-05-27 02:04:47 41,472 ----a-w C:\WINDOWS\system32\hhsetup.dll
- 2001-08-18 12:00:00 81,978 ----a-w C:\WINDOWS\system32\hlink.dll
+ 2006-07-21 08:29:00 72,704 ----a-w C:\WINDOWS\system32\hlink.dll
- 2004-08-03 22:57:22 354,304 ----a-w C:\WINDOWS\system32\hypertrm.dll
+ 2004-11-17 17:42:24 356,352 ----a-w C:\WINDOWS\system32\hypertrm.dll
- 2004-08-03 22:57:22 253,952 ----a-w C:\WINDOWS\system32\icm32.dll
+ 2005-06-29 01:49:39 254,976 ----a-w C:\WINDOWS\system32\icm32.dll
- 2004-08-03 22:57:22 249,344 ----a-w C:\WINDOWS\system32\iepeers.dll
+ 2008-02-16 08:59:23 251,392 ----a-w C:\WINDOWS\system32\iepeers.dll
- 2004-08-03 22:57:22 678,400 ----a-w C:\WINDOWS\system32\inetcomm.dll
+ 2007-08-21 06:16:14 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
- 2004-08-03 22:57:22 96,768 ----a-w C:\WINDOWS\system32\inseng.dll
+ 2008-02-16 08:59:23 96,768 ----a-w C:\WINDOWS\system32\inseng.dll
- 2004-08-03 22:57:22 95,744 ----a-w C:\WINDOWS\system32\iphlpapi.dll
+ 2006-05-19 13:09:50 95,744 ----a-w C:\WINDOWS\system32\iphlpapi.dll
- 2004-08-03 22:57:24 143,872 ----a-w C:\WINDOWS\system32\itircl.dll
+ 2005-05-27 02:04:47 155,136 ----a-w C:\WINDOWS\system32\itircl.dll
- 2004-08-03 22:57:24 134,144 ----a-w C:\WINDOWS\system32\itss.dll
+ 2005-05-27 02:04:47 137,216 ----a-w C:\WINDOWS\system32\itss.dll
- 2001-08-18 12:00:00 144,896 ----a-w C:\WINDOWS\system32\jgdw400.dll
+ 2006-06-01 18:47:07 163,840 ----a-w C:\WINDOWS\system32\jgdw400.dll
- 2001-08-18 12:00:00 42,496 ----a-w C:\WINDOWS\system32\jgpl400.dll
+ 2006-06-01 18:47:07 27,648 ----a-w C:\WINDOWS\system32\jgpl400.dll
- 2004-08-03 22:57:24 450,560 ----a-w C:\WINDOWS\system32\jscript.dll
+ 2007-12-18 14:41:00 450,560 ----a-w C:\WINDOWS\system32\jscript.dll
- 2004-08-03 22:57:24 15,872 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2008-02-16 08:59:23 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
- 2004-08-03 22:57:24 1,057,280 ----a-w C:\WINDOWS\system32\kernel32.dll
+ 2007-04-16 15:53:05 1,058,304 ----a-w C:\WINDOWS\system32\kernel32.dll
- 2004-08-03 22:57:24 18,944 ----a-w C:\WINDOWS\system32\linkinfo.dll
+ 2005-09-01 01:44:41 19,968 ----a-w C:\WINDOWS\system32\linkinfo.dll
- 2004-08-03 22:57:24 729,600 ----a-w C:\WINDOWS\system32\lsasrv.dll
+ 2007-11-07 09:27:10 729,600 ----a-w C:\WINDOWS\system32\lsasrv.dll
- 2004-08-03 22:57:24 39,936 ----a-w C:\WINDOWS\system32\mf3216.dll
+ 2007-03-08 15:36:30 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
- 2001-08-18 12:00:00 924,432 ----a-w C:\WINDOWS\system32\mfc40u.dll
+ 2006-11-01 19:17:41 927,504 ----a-w C:\WINDOWS\system32\mfc40u.dll
- 2004-08-03 22:57:24 1,024,000 ----a-w C:\WINDOWS\system32\mfc42u.dll
+ 2006-10-14 08:13:25 981,760 ----a-w C:\WINDOWS\system32\mfc42u.dll
- 2004-08-03 22:57:26 73,728 ----a-w C:\WINDOWS\system32\mscms.dll
+ 2005-06-29 01:49:39 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
- 2004-08-03 22:57:28 425,472 ----a-w C:\WINDOWS\system32\msdtcprx.dll
+ 2006-03-01 19:43:33 426,496 ----a-w C:\WINDOWS\system32\msdtcprx.dll
- 2004-08-03 22:57:28 949,248 ----a-w C:\WINDOWS\system32\msdtctm.dll
+ 2006-03-01 19:43:33 956,416 ----a-w C:\WINDOWS\system32\msdtctm.dll
- 2004-08-03 22:57:28 161,280 ----a-w C:\WINDOWS\system32\msdtcuiu.dll
+ 2006-03-01 19:43:33 161,280 ----a-w C:\WINDOWS\system32\msdtcuiu.dll
- 2004-08-03 22:57:28 537,088 ------w C:\WINDOWS\system32\msftedit.dll
+ 2006-11-27 14:54:15 539,136 ------w C:\WINDOWS\system32\msftedit.dll
- 2004-08-03 22:57:28 448,512 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-02-16 08:59:28 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2004-08-03 22:57:30 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
+ 2008-02-16 08:59:28 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
- 2004-08-03 22:57:30 530,432 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2008-02-16 08:59:28 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
- 2004-08-03 22:57:30 66,560 ----a-w C:\WINDOWS\system32\mtxclu.dll
+ 2006-03-01 19:43:33 66,560 ----a-w C:\WINDOWS\system32\mtxclu.dll
- 2004-08-03 22:57:30 90,112 ----a-w C:\WINDOWS\system32\mtxoci.dll
+ 2006-03-01 19:43:33 91,136 ----a-w C:\WINDOWS\system32\mtxoci.dll
- 2004-08-03 22:57:32 198,144 ----a-w C:\WINDOWS\system32\netman.dll
+ 2005-08-22 18:31:48 197,632 ----a-w C:\WINDOWS\system32\netman.dll
- 2004-08-03 22:50:14 2,059,136 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
+ 2005-03-02 18:06:16 2,059,136 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
- 2004-08-03 22:50:28 2,183,296 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
+ 2005-03-02 18:06:32 2,181,632 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
- 2001-08-18 12:00:00 58,880 ----a-w C:\WINDOWS\system32\nwapi32.dll
+ 2006-10-13 12:35:14 64,000 ----a-w C:\WINDOWS\system32\nwapi32.dll
- 2004-08-03 22:57:32 148,480 ----a-w C:\WINDOWS\system32\nwprovau.dll
+ 2006-10-13 12:35:14 146,432 ----a-w C:\WINDOWS\system32\nwprovau.dll
- 2004-08-03 22:57:32 64,000 ----a-w C:\WINDOWS\system32\nwwks.dll
+ 2006-10-13 12:35:14 65,536 ----a-w C:\WINDOWS\system32\nwwks.dll
- 2004-08-03 22:57:32 1,281,536 ----a-w C:\WINDOWS\system32\ole32.dll
+ 2005-04-28 19:31:43 1,285,120 ------w C:\WINDOWS\system32\ole32.dll
- 2004-08-03 22:57:32 553,472 ----a-w C:\WINDOWS\system32\oleaut32.dll
+ 2007-12-04 18:40:03 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
- 2001-08-18 12:00:00 68,608 ----a-w C:\WINDOWS\system32\olecli32.dll
+ 2005-04-28 19:31:43 74,752 ------w C:\WINDOWS\system32\olecli32.dll
- 2001-08-18 12:00:00 34,304 ----a-w C:\WINDOWS\system32\olecnv32.dll
+ 2005-07-26 04:39:50 37,888 ----a-w C:\WINDOWS\system32\olecnv32.dll
- 2001-08-18 12:00:00 121,856 ----a-w C:\WINDOWS\system32\oledlg.dll
+ 2006-10-16 16:15:58 126,976 ----a-w C:\WINDOWS\system32\oledlg.dll
- 2008-03-30 16:38:19 48,156 ----a-w C:\WINDOWS\system32\perfc007.dat
+ 2008-04-16 09:03:23 48,156 ----a-w C:\WINDOWS\system32\perfc007.dat
- 2008-03-30 16:38:19 39,992 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-16 09:03:23 39,992 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-30 16:38:19 316,594 ----a-w C:\WINDOWS\system32\perfh007.dat
+ 2008-04-16 09:03:23 316,594 ----a-w C:\WINDOWS\system32\perfh007.dat
- 2008-03-30 16:38:19 311,604 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-16 09:03:23 311,604 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2004-08-03 22:57:34 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-02-16 08:59:28 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2004-08-03 22:57:34 1,293,312 ----a-w C:\WINDOWS\system32\quartz.dll
+ 2007-10-29 22:42:30 1,293,312 ----a-w C:\WINDOWS\system32\quartz.dll
- 2004-08-03 22:57:34 1,441,792 ----a-w C:\WINDOWS\system32\query.dll
+ 2006-06-22 05:06:24 1,441,792 ----a-w C:\WINDOWS\system32\query.dll
- 2004-08-03 22:57:34 8,192 ----a-w C:\WINDOWS\system32\rasadhlp.dll
+ 2006-06-26 17:40:34 8,192 ----a-w C:\WINDOWS\system32\rasadhlp.dll
- 2004-08-03 22:57:34 431,616 ----a-w C:\WINDOWS\system32\riched20.dll
+ 2006-11-27 14:54:15 433,152 ----a-w C:\WINDOWS\system32\riched20.dll
- 2004-08-03 22:57:34 395,776 ----a-w C:\WINDOWS\system32\rpcss.dll
+ 2005-04-28 19:31:44 395,776 ------w C:\WINDOWS\system32\rpcss.dll
- 2004-08-03 22:57:34 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
+ 2007-04-25 14:22:27 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
- 2004-08-03 22:57:34 8,424,960 ----a-w C:\WINDOWS\system32\shell32.dll
+ 2006-03-17 04:03:36 8,493,056 ----a-w C:\WINDOWS\system32\shell32.dll
__________________

Alt 18.04.2008, 10:46   #19
Janis
 
spoolw.exe - Standard

spoolw.exe



- 2004-08-03 22:57:34 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
+ 2005-09-02 23:53:21 474,112 ------w C:\WINDOWS\system32\shlwapi.dll
- 2005-02-25 03:34:54 15,584 ------w C:\WINDOWS\system32\spmsg.dll
+ 2005-10-12 23:11:08 15,584 ------w C:\WINDOWS\system32\spmsg.dll
- 2005-02-25 03:34:54 22,752 ----a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2005-06-28 07:21:34 22,752 ----a-w C:\WINDOWS\system32\spupdsvc.exe
- 2004-08-03 22:57:36 96,768 ----a-w C:\WINDOWS\system32\srvsvc.dll
+ 2004-12-07 19:33:24 96,768 ----a-w C:\WINDOWS\system32\srvsvc.dll
- 2004-08-03 22:57:36 246,302 ----a-w C:\WINDOWS\system32\strmdll.dll
+ 2006-08-24 11:19:40 246,814 ----a-w C:\WINDOWS\system32\strmdll.dll
- 2004-08-03 22:57:36 715,776 ----a-w C:\WINDOWS\system32\sxs.dll
+ 2006-10-20 01:38:26 715,776 ----a-w C:\WINDOWS\system32\sxs.dll
- 2004-08-03 22:57:36 210,432 ----a-w C:\WINDOWS\system32\t2embed.dll
+ 2005-10-17 21:20:02 118,272 ----a-w C:\WINDOWS\system32\t2embed.dll
- 2004-08-03 22:58:16 77,824 ----a-w C:\WINDOWS\system32\telnet.exe
+ 2005-05-11 02:30:02 78,336 ----a-w C:\WINDOWS\system32\telnet.exe
- 2004-08-03 22:57:38 101,376 ----a-w C:\WINDOWS\system32\txflog.dll
+ 2005-07-26 04:39:50 101,376 ----a-w C:\WINDOWS\system32\txflog.dll
+ 2007-11-13 11:31:11 60,416 ------w C:\WINDOWS\system32\tzchange.exe
- 2004-08-03 22:57:38 119,296 ----a-w C:\WINDOWS\system32\umpnpmgr.dll
+ 2005-08-23 03:39:57 124,416 ----a-w C:\WINDOWS\system32\umpnpmgr.dll
- 2004-08-03 22:57:38 185,856 ----a-w C:\WINDOWS\system32\upnphost.dll
+ 2007-02-05 20:18:44 185,856 ----a-w C:\WINDOWS\system32\upnphost.dll
- 2004-08-03 22:57:38 578,560 ----a-w C:\WINDOWS\system32\user32.dll
+ 2005-03-02 18:09:46 578,560 ------w C:\WINDOWS\system32\user32.dll
- 2004-08-03 22:57:38 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll
+ 2007-12-18 14:41:00 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll
+ 2006-03-17 00:38:01 28,672 ------w C:\WINDOWS\system32\verclsid.exe
- 2004-08-03 22:57:38 291,328 ----a-w C:\WINDOWS\system32\winsrv.dll
+ 2007-03-17 13:44:25 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
- 2004-08-03 22:57:38 132,096 ----a-w C:\WINDOWS\system32\wkssvc.dll
+ 2006-08-17 12:28:44 132,096 ----a-w C:\WINDOWS\system32\wkssvc.dll
- 2004-09-22 16:46:12 229,376 ----a-w C:\WINDOWS\system32\wmasf.dll
+ 2007-10-20 04:01:32 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
- 2004-09-22 16:46:16 5,550,080 ----a-w C:\WINDOWS\system32\wmp.dll
+ 2007-04-30 06:20:24 5,537,792 ----a-w C:\WINDOWS\system32\wmp.dll
- 2004-09-22 16:46:32 2,362,104 ----a-w C:\WINDOWS\system32\wmvcore.dll
+ 2006-12-07 06:40:49 2,362,184 ----a-w C:\WINDOWS\system32\wmvcore.dll
- 2004-08-03 22:57:42 11,776 ----a-w C:\WINDOWS\system32\xolehlp.dll
+ 2006-03-01 19:43:33 11,776 ----a-w C:\WINDOWS\system32\xolehlp.dll
+ 2007-03-09 10:24:04 123,392 ------w C:\WINDOWS\system32\xpsp3res.dll
+ 2007-01-19 12:50:53 74,802 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
+ 2007-01-19 12:50:53 995,383 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
+ 2007-01-19 12:50:53 1,011,774 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
+ 2007-01-19 12:50:53 401,462 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2006-08-25 15:46:44 1,054,208 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
.
-- Snapshot reset to current date --

(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{72A128E0-2240-40c8-9E92-5387D64F839E}]
C:\WINDOWS\xml2u32.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:57 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"="C:\Programme\ATI Technologies\HydraVision\HydraDM.exe" [2002-08-14 10:28 262144]
"ATIPTA"="C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-02-28 21:00 315392]
"WinampAgent"="C:\Programme\Winamp\winampa.exe" [2007-05-15 00:22 35328]
"C-Media Mixer"="Mixer.exe" [2001-11-15 12:08 1216512 C:\WINDOWS\mixer.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:57 15360]

C:\Dokumente und Einstellungen\All Users\Startmen\Programme\Autostart\
Adobe Gamma Loader.lnk - C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-10 16:31:12 110592]
T-Sinus 930 Konfiguration.lnk - C:\Programme\Symphony\maestro.exe [2007-07-10 00:11:30 540729]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{1D516154-6AC0-426C-92A1-FDC0073E8A1B}"= C:\DOKUME~1\odkies\LOKALE~1\Temp\ntwzhook.dll [ ]

[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Google Updater.lnk]
path=C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-11 03:06 40048 C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxsvc]
--a------ 2004-08-04 00:57 2108 C:\WINDOWS\system32\igfxsvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Programme\MSN Messenger\MsnMsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spoolw]
C:\WINDOWS\system32\spoolw.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Programme\Java\jre1.6.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"Symphony Switcher Service"=2 (0x2)
"gusvc"=2 (0x2)
"BITS"=2 (0x2)
"AudioSrv"=2 (0x2)
"aawservice"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programme\\Trillian\\trillian.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:UDP"= 6112:UDP:Startcraft
"6119:UDP"= 6119:UDP:Starcraft2

R2 sympxchm;sympxchm;C:\WINDOWS\system32\DRIVERS\sympxchm.sys [2001-09-10 17:42]
R3 NtApm;Herkömmlicher NT APM-Schnittstellentreiber;C:\WINDOWS\system32\DRIVERS\NtApm.sys [2001-08-18 05:27]
R3 sympusb;sympusb;C:\WINDOWS\system32\DRIVERS\sympusb.sys [2001-10-22 11:23]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;C:\DOKUME~1\odkies\LOKALE~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys []
S4 Symphony Switcher Service;Symphony Switcher Service;C:\Programme\Symphony\sw_serv.exe [2002-01-23 09:05]

.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-16 11:17:57
Windows 5.1.2600 Service Pack 2 NTFS

Scanne versteckte Prozesse...

Scanne versteckte Autostart Einträge...

Scanne versteckte Dateien...

Scan erfolgreich abgeschlossen
versteckte Dateien: 0

**************************************************************************
.
Zeit der Fertigstellung: 2008-04-16 11:21:52
ComboFix-quarantined-files.txt 2008-04-16 09:20:59
ComboFix2.txt 2008-04-15 15:12:07

13 Verzeichnis(se), 27,414,056,960 Bytes frei
17 Verzeichnis(se), 27,372,457,984 Bytes frei
.
2008-04-14 20:29:17 --- E O F ---

Alt 18.04.2008, 10:47   #20
Sabina
 
spoolw.exe - Standard

spoolw.exe



Hallo,

denke , dass eine Reinigung so gut wie sinnlos ist, dein Rechner ist voll gepackt mit Cracks + dazugehörigen Trojanern und Viren. Sauber bekommt man den Rechner nicht mehr
Das sicherste und vernünftigste ist: formatieren und in Zukunft keine cracks mehr laden.

__________________
MfG Sabina

Alt 19.04.2008, 12:32   #21
Janis
 
spoolw.exe - Standard

spoolw.exe



Hört sich ja nicht so gut an... Aber ich hab nur einen Crack runtergeladen und die Seite ist eigentlich serious. Also spoolw.exe und igfxsvc.exe sind verschwunden und der IE öffnet sich nicht mehr von selbst.

Danke für deine Zeit und deine Hilfe Sabrina!!

Alt 19.04.2008, 12:40   #22
Sabina
 
spoolw.exe - Standard

spoolw.exe



Hallo,
ich hatte doch ein script erstellt, für die Combofix... wenn man dann die txt-Datei auf die Combofix zieht + Combofix noch mal anwendet, wird ein neues Log erstellt sollte alles entfernt sein, was im Script enthalten war... das was ich sehe: alles noch da, was eigentlich gelöscht sein sollte.

Wenn du mit der Grösse der Combofix-Logs Probleme hast, kannst du sie als txt-Datei als Anhang hochladen.
Erstelle also das Script noch mal neu, genau nach Anleitung (beim Abspeichern angeben: "Alle Dateien" - und dann noch mal das neue Log von Combofix posten (komplett), damit ich sehen kann, was entfernt wurde und was nicht.
__________________
MfG Sabina

Antwort

Themen zu spoolw.exe
acrobat, adobe, bho, button, datei, dateien, einstellungen, explorer, google, hijack, hijackthis, hotkey, internet explorer, log, löschen, pdf, programme, prozess, seite, system, system32, taskmanager, windows, windows xp, ändern, öffnet




Zum Thema spoolw.exe - Den folgenden Text in den Editor (Start - Zubehör - Editor) kopieren und als cfscript.txt mit 'Speichern unter' auf dem Desktop. Gib an "Alle Dateien" - Speichern Code: Alles auswählen - spoolw.exe...
Archiv
Du betrachtest: spoolw.exe auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.