TEIL2 Code:
Alles auswählen Aufklappen ATTFilter
======File associations======
.js - edit - C:\Windows\SysWOW64\Notepad.exe %1
.js - open - C:\Windows\SysWOW64\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2009-08-31 19:12:20 ----D---- C:\Program Files (x86)\CCleaner
2009-08-31 19:01:00 ----D---- C:\Users\Parick\AppData\Roaming\Uniblue
2009-08-31 13:40:50 ----D---- C:\Users\Parick\AppData\Roaming\Malwarebytes
2009-08-31 13:40:44 ----D---- C:\ProgramData\Malwarebytes
2009-08-31 13:40:44 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2009-08-31 13:33:43 ----D---- C:\rsit
2009-08-30 15:06:44 ----D---- C:\Program Files (x86)\Trend Micro
2009-08-29 15:30:13 ----D---- C:\Program Files (x86)\NCSoft
2009-08-29 15:03:11 ----D---- C:\Users\Parick\AppData\Roaming\GetRightToGo
2009-08-29 13:42:27 ----A---- C:\Windows\system32\javaws.exe
2009-08-29 13:42:27 ----A---- C:\Windows\system32\javaw.exe
2009-08-29 13:42:27 ----A---- C:\Windows\system32\java.exe
2009-08-27 13:00:13 ----A---- C:\Windows\system32\tzres.dll
2009-08-26 12:31:47 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-08-26 12:31:47 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-08-22 17:50:22 ----A---- C:\Windows\dd_NET_Framework35_LangPack_MSI20EE.txt
2009-08-22 17:50:05 ----A---- C:\Windows\dd_depcheck_NETFX_EXP_35.txt
2009-08-22 17:49:58 ----A---- C:\Windows\dd_dotnetfx35install_lp.txt
2009-08-22 17:49:58 ----A---- C:\Windows\dd_dotnetfx35error_lp.txt
2009-08-20 10:49:25 ----D---- C:\ProgramData\Blizzard Entertainment
2009-08-18 20:52:49 ----D---- C:\Windows\My Video Downloader
2009-08-18 19:25:02 ----D---- C:\Program Files (x86)\GIMP-2.0
2009-08-13 17:40:48 ----A---- C:\Windows\system32\mstscax.dll
2009-08-13 17:40:46 ----A---- C:\Windows\system32\atl.dll
2009-08-13 17:40:36 ----A---- C:\Windows\system32\avifil32.dll
2009-08-13 17:40:29 ----A---- C:\Windows\system32\wmp.dll
2009-08-13 17:40:28 ----A---- C:\Windows\system32\wmpdxm.dll
2009-08-13 17:40:27 ----A---- C:\Windows\system32\wmploc.DLL
2009-08-13 17:40:27 ----A---- C:\Windows\system32\spwmp.dll
2009-08-13 17:40:27 ----A---- C:\Windows\system32\dxmasf.dll
2009-08-02 21:16:03 ----D---- C:\Users\Parick\AppData\Roaming\gtk-2.0
======List of files/folders modified in the last 1 months======
2009-08-31 22:20:18 ----D---- C:\Windows\Prefetch
2009-08-31 22:20:15 ----D---- C:\Windows\Temp
2009-08-31 20:53:30 ----D---- C:\Program Files (x86)\Mozilla Firefox
2009-08-31 20:26:19 ----RD---- C:\Program Files (x86)
2009-08-31 19:14:14 ----D---- C:\Windows\Debug
2009-08-31 19:14:14 ----D---- C:\Windows
2009-08-31 15:10:50 ----SHD---- C:\System Volume Information
2009-08-31 13:40:46 ----D---- C:\Windows\system32\drivers
2009-08-31 13:40:44 ----HD---- C:\ProgramData
2009-08-30 15:30:30 ----D---- C:\Program Files (x86)\DivX
2009-08-30 15:05:58 ----D---- C:\Windows\SysWOW64
2009-08-30 14:57:47 ----D---- C:\Program Files (x86)\Common Files\PX Storage Engine
2009-08-30 14:37:04 ----D---- C:\Program Files (x86)\Curse
2009-08-30 14:36:25 ----D---- C:\Program Files (x86)\AceHide Free
2009-08-29 18:11:34 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2009-08-29 18:10:46 ----D---- C:\Windows\System32
2009-08-29 16:15:20 ----SD---- C:\Users\Parick\AppData\Roaming\Microsoft
2009-08-29 16:15:18 ----D---- C:\ProgramData\avg8
2009-08-29 13:42:29 ----SHD---- C:\Windows\Installer
2009-08-29 13:42:26 ----D---- C:\Program Files (x86)\Java
2009-08-28 19:03:10 ----D---- C:\Windows\inf
2009-08-27 13:13:54 ----D---- C:\Windows\rescache
2009-08-27 13:00:53 ----D---- C:\Windows\winsxs
2009-08-27 13:00:53 ----D---- C:\Program Files (x86)\Internet Explorer
2009-08-27 13:00:44 ----D---- C:\Windows\system32\de-DE
2009-08-27 13:00:02 ----D---- C:\Windows\AppPatch
2009-08-26 01:37:11 ----RSD---- C:\Windows\Fonts
2009-08-23 14:27:39 ----D---- C:\Users\Parick\AppData\Roaming\teamspeak2
2009-08-22 17:51:05 ----RSD---- C:\Windows\assembly
2009-08-21 00:18:20 ----D---- C:\ProgramData\TrackMania
2009-08-15 21:38:26 ----D---- C:\Program Files (x86)\Safari
2009-08-14 03:31:07 ----D---- C:\Windows\Tasks
2009-08-14 03:31:05 ----D---- C:\Windows\registration
2009-08-14 03:04:38 ----D---- C:\Program Files (x86)\Windows Mail
2009-08-14 03:04:37 ----D---- C:\Program Files (x86)\Windows Media Player
2009-08-02 12:24:01 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2009-08-01 19:11:46 ----D---- C:\Users\Parick\AppData\Roaming\Apple Computer
2009-08-01 18:51:45 ----D---- C:\ProgramData\Apple
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49}; \??\c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2008-09-26 27632]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys []
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys []
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys []
R3 CT20XUT.SYS;CT20XUT.SYS; C:\Windows\System32\drivers\CT20XUT.SYS []
R3 ctaud2k;Creative Audio Driver (WDM); C:\Windows\system32\drivers\ctaud2k.sys []
R3 CTEXFIFX.SYS;CTEXFIFX.SYS; C:\Windows\System32\drivers\CTEXFIFX.SYS []
R3 CTHWIUT.SYS;CTHWIUT.SYS; C:\Windows\System32\drivers\CTHWIUT.SYS []
R3 ctprxy2k;Creative Proxy Driver; C:\Windows\system32\drivers\ctprxy2k.sys []
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\Windows\system32\drivers\ctsfm2k.sys []
R3 emupia;E-mu Plug-in Architecture Driver; C:\Windows\system32\drivers\emupia2k.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys []
R3 ha20x22k;Creative 20X2 HAL Driver; C:\Windows\system32\drivers\ha20x22k.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 ksthunk;Kernel Streaming Thunks; C:\Windows\system32\drivers\ksthunk.sys []
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys []
R3 ossrv;Creative OS Services Driver; C:\Windows\system32\drivers\ctoss2k.sys []
R3 Ps2;PS2; C:\Windows\system32\DRIVERS\PS2.sys []
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh64.sys []
R3 VaneFltr;Lachesis Mouse Driver; C:\Windows\system32\drivers\Lachesis.sys []
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys []
S3 CT20XUT;CT20XUT; C:\Windows\system32\drivers\CT20XUT.SYS []
S3 ctac32k;Creative AC3 Software Decoder; C:\Windows\system32\drivers\ctac32k.sys []
S3 CTEXFIFX;CTEXFIFX; C:\Windows\system32\drivers\CTEXFIFX.SYS []
S3 CTHWIUT;CTHWIUT; C:\Windows\system32\drivers\CTHWIUT.SYS []
S3 drmkaud;Microsoft Kernel-DRM-Audioentschlüsselung; C:\Windows\system32\drivers\drmkaud.sys []
S3 ha20x2k;Creative 20X HAL Driver; C:\Windows\system32\drivers\ha20x2k.sys []
S3 HdAudAddService;Microsoft 1.1 UAA-Funktionstreiber für High Definition Audio-Dienst; C:\Windows\system32\drivers\HdAudio.sys []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys []
S3 MSPCLOCK;Microsoft Proxy für Streaming Clock; C:\Windows\system32\drivers\MSPCLOCK.sys []
S3 MSPQM;Microsoft Proxy für Streaming Quality Manager; C:\Windows\system32\drivers\MSPQM.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-Konvertierung; C:\Windows\system32\drivers\MSTEE.sys []
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys []
S3 usbscan;USB-Scannertreiber; C:\Windows\system32\DRIVERS\usbscan.sys []
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys []
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys []
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys []
S4 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\Windows\System32\drivers\sfdrv01.sys []
S4 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\Windows\System32\drivers\sfhlp02.sys []
S4 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\Windows\System32\drivers\sfvfs02.sys []
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirSchedulerService;Avira AntiVir Planer; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2009-06-09 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2009-08-05 185089]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-05-29 144712]
R2 Bonjour Service;Bonjour-Dienst; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2008-11-18 307200]
R2 ezSharedSvc;Easybits Shared Services for Windows; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-10-09 94208]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2008-11-03 354840]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2008-08-22 73728]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe []
R3 iPod Service;iPod-Dienst; C:\Program Files (x86)\iPod\bin\iPodService.exe [2009-07-13 542496]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2008-07-27 93184]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2009-07-04 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-07-04 79360]
S3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2009-07-04 79360]
S3 GameConsoleService;GameConsoleService; C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe [2008-05-06 165416]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-21 19968]
-----------------EOF-----------------
eine kurze zusatz frage noch:
ist es normal das sychost.exe(netsvcs) eine dauer verbindung zum internet hat bzw generell sychost.exe(networkService)