|
Plagegeister aller Art und deren Bekämpfung: AV Security Suite Antimalware- was noch?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
12.07.2010, 22:11 | #1 |
| AV Security Suite Antimalware- was noch? Hallo, ich habe mir diese AV Security Suite eingefangen Ich habe im Forum gelesen und die AntiMalware laufen lassen: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4052 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 6.0.2900.5512 12.07.2010 22:59:29 mbam-log-2010-07-12 (22-59-29).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 258240 Laufzeit: 1 Stunde(n), 32 Minute(n), 20 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 6 Infizierte Registrierungswerte: 3 Infizierte Dateiobjekte der Registrierung: 1 Infizierte Verzeichnisse: 1 Infizierte Dateien: 6 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\avsuite (Rogue.AntivirusSuite) -> No action taken. HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> No action taken. Infizierte Registrierungswerte: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\getdo (Trojan.Agent) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> No action taken. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\helper (Trojan.Agent) -> No action taken. Infizierte Dateiobjekte der Registrierung: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (Userinit.exe) -> No action taken. Infizierte Verzeichnisse: C:\WINDOWS\SYSTEM32\lowsec (Stolen.data) -> No action taken. Infizierte Dateien: C:\Dokumente und Einstellungen\Marie.BALOU\Anwendungsdaten\Desktopicon\eBayShortcuts.exe (Adware.ADON) -> No action taken. C:\WINDOWS\SYSTEM32\lowsec\local.ds (Stolen.data) -> No action taken. C:\WINDOWS\SYSTEM32\lowsec\user.ds (Stolen.data) -> No action taken. C:\Dokumente und Einstellungen\Marie.BALOU\Anwendungsdaten\wiaservg.log (Malware.Trace) -> No action taken. C:\WINDOWS\aconti.log (Fake.Dropped.Malware) -> No action taken. C:\WINDOWS\aconti.sdb (Fake.Dropped.Malware) -> No action taken. Die infizierten Dateien habe ich gelöscht. Das Programm ist nach einem Neustart aber immer noch da! Was muß ich noch machen? Danke & Grüße caruso |
13.07.2010, 04:40 | #2 | |
/// Helfer-Team | AV Security Suite Antimalware- was noch? Hallo und Herzlich Willkommen!
__________________- Die Anweisungen bitte gründlich lesen und immer streng einhalten, da ich die Reihenfolge nach bestimmten Kriterien vorbereitet habe: 1. lade Dir HijackThis von *von hier* herunter HijackThis starten→ "Do a system scan and save a logfile" klicken→ das erhaltene Logfile "markieren" → "kopieren"→ hier in deinem Thread (rechte Maustaste) "einfügen" 2. Bitte Versteckte - und Systemdateien sichtbar machen den Link hier anklicken: System-Dateien und -Ordner unter XP und Vista sichtbar machen Am Ende unserer Arbeit, kannst wieder rückgängig machen! 3. → Lade Dir HJTscanlist.zip herunter → entpacke die Datei auf deinem Desktop → Bei WindowsXP Home musst vor dem Scan zusätzlich tasklist.zip installieren → per Doppelklick starten → Wähle dein Betriebsystem aus - Vista → Wenn Du gefragt wirst, die Option "Einstellung" (1) - scanlist" wählen → Nach kurzer Zeit sollte sich Dein Editor öffnen und die Datei hjtscanlist.txt präsentieren → Bitte kopiere den Inhalt hier in Deinen Thread. 4. Ich würde gerne noch all deine installierten Programme sehen: Lade dir das Tool CCleaner herunter installieren ("Füge CCleaner Yahoo! Toolbar hinzu" abwählen)→ starten→ falls nötig - unter Options settings-> "german" einstellen dann klick auf "Extra (um die installierten Programme auch anzuzeigen)→ weiter auf "Als Textdatei speichern..." wird eine Textdatei (*.txt) erstellt, kopiere dazu den Inhalt und füge ihn da ein Zitat:
Coverflow |
15.07.2010, 08:32 | #3 |
| AV Security Suite Antimalware- was noch? hi coverflow,
__________________die logs sind zu lang und daher im anhang zu finden danke & grüße caruso |
15.07.2010, 14:06 | #4 |
/// Helfer-Team | AV Security Suite Antimalware- was noch? Logs eingefügt: HiJackthis Logfile: Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 09:04:46, on 15.07.2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Safe mode Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\trojboard\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://wer-mit-wem.webhop.net/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2096149 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5577 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: TBSB03968 - {AA61DE26-FA67-4575-9033-918671094293} - C:\Dokumente und Einstellungen\Marie.BALOU\Anwendungsdaten\Toolbars\Toolbar fuer eBay\ebay.dll O2 - BHO: kikin Plugin - {E601996F-E400-41CA-804B-CD6373A7EEE2} - C:\Programme\kikin\ie_kikin.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programme\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: Toolbar fuer eBay - {000E148C-F7A7-445A-9044-93BF6CE09ECB} - C:\Dokumente und Einstellungen\Marie.BALOU\Anwendungsdaten\Toolbars\Toolbar fuer eBay\ebay.dll O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [EM_EXEC] C:\Install\DRIVERS\Logitech\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [OpwareSE2] "C:\Programme\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" O4 - HKLM\..\Run: [BearShare] "C:\Programme\BearShare\BearShare.exe" /pause O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [ktevdfku] C:\Dokumente und Einstellungen\Marie.BALOU\Lokale Einstellungen\Anwendungsdaten\nuvcaykvs\essdlwctssd.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [updateMgr] "C:\Programme\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 O4 - HKCU\..\Run: [{24F4C586-D8F0-4283-ABE9-DB908DBF1B13}] "C:\Dokumente und Einstellungen\Marie.BALOU\Anwendungsdaten\Uculym\ylags.exe" O4 - HKCU\..\Run: [Xyudobubobogeb] rundll32.exe "C:\WINDOWS\kbuipmsd.dll",Startup O4 - HKCU\..\Run: [ktevdfku] C:\Dokumente und Einstellungen\Marie.BALOU\Lokale Einstellungen\Anwendungsdaten\nuvcaykvs\essdlwctssd.exe O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Adobe-Gamma-Lader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: WISO Mein Sparbuch heute.lnk = C:\Programme\WISO\Sparbuch 2010\meinsparbuchheute.exe O8 - Extra context menu item: Easy-WebPrint - Drucken - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint - Vorschau - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Programme\kikin\ie_kikin.dll O9 - Extra 'Tools' menuitem: My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Programme\kikin\ie_kikin.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O16 - DPF: {162247AF-26A7-44FC-A93A-69506EA244F3} (HWTest.HWTestControl) - http://service.maxdome.de/de/systemcheck/HWTest.CAB O16 - DPF: {59136DB4-6CA3-4B40-8F2F-BBF84B6F1E91} (Attachment Upload Control) - https://stream.web.de/mail/activex/mail_upload_11213.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1229691117308 O16 - DPF: {7527E129-A524-434A-A337-8C19F6F25C91} (AldiSuedActiveFormX Element) - http://shop.aldisued-fotos-druck.de/shop/activex/aldi_sued_express_upload.cab O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader.cab O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\avguard.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Programme\Bonjour\mDNSResponder.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Programme\iPod\bin\iPodService.exe O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Programme\Lavasoft\Ad-Aware\AAWService.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe -- End of file - 6720 bytes |
15.07.2010, 14:11 | #5 |
/// Helfer-Team | AV Security Suite Antimalware- was noch?Code:
ATTFilter $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ º º hjtscanlist v2.0 º º $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ Microsoft Windows XP [Version 5.1.2600] C: 15.07.2010 09:04 C:\trojboard --------- 0 C:\pagefile.sys --------- 15.07.2010 08:58 C:\aaw7boot.log --------- 14108 12.07.2010 23:04 C:\WINDOWS --------- 0 12.07.2010 14:58 C:\rkill.log --------- 380 12.07.2010 14:45 C:\Programme --------- 0 12.07.2010 12:02 C:\INFECTED --------- 0 08.07.2010 13:37 C:\Temp --------- 0 27.05.2010 11:18 C:\reclock_log.txt --------- 39972937 07.02.2010 14:17 C:\TIVOLA --------- 0 17.08.2009 23:01 C:\e0440d62c1b6e93c17 --------- 0 07.01.2009 22:19 C:\index.html --------- 745 19.12.2008 17:31 C:\System Volume Information --------- 0 19.12.2008 17:01 C:\boot.ini --------- 211 19.12.2008 16:36 C:\NTDETECT.COM --------- 47564 19.12.2008 16:36 C:\ntldr --------- 251712 15.04.2007 13:55 C:\clony.txt --------- 299 23.03.2007 23:06 C:\GERCC.txt --------- 3726 23.03.2007 23:06 C:\RCPARAM.txt --------- 1061 19.02.2007 11:03 C:\Dell --------- 0 29.04.2006 18:11 C:\CanonMP --------- 0 01.06.2004 08:59 C:\Verknpfung mit 3«-Diskette (A).lnk --------- 129 16.03.2004 13:10 C:\Verknpfung mit CD-Laufwerk.lnk --------- 145 16.09.2003 11:08 C:\Dokumente und Einstellungen --------- 0 05.05.2003 15:53 C:\INSTALL.LOG --------- 1119 06.03.2003 21:44 C:\aconti.log --------- 1853 03.03.2003 14:29 C:\Install --------- 0 01.03.2003 23:04 C:\aconti.log1 --------- 195 01.03.2003 17:27 C:\RECYCLER --------- 0 18.02.2003 21:53 C:\DELL.SDR --------- 3194 28.11.2002 14:00 C:\bootfont.bin --------- 4952 11.09.2002 15:48 C:\IO.SYS --------- 0 11.09.2002 15:48 C:\CONFIG.SYS --------- 0 11.09.2002 15:48 C:\AUTOEXEC.BAT --------- 0 11.09.2002 15:48 C:\MSDOS.SYS --------- 0 11.09.2002 15:25 C:\BOOTSECT.DOS --------- 512 10.01.2001 12:23 C:\UNWISE.EXE --------- 162304 ---------------------------------------- C:\WINDOWS 15.07.2010 08:59 C:\WINDOWS\ntbtlog.txt --------- 968646 15.07.2010 08:58 C:\WINDOWS\bootstat.dat --------- 2048 12.07.2010 23:07 C:\WINDOWS\WindowsUpdate.log --------- 1369406 12.07.2010 23:07 C:\WINDOWS\SchedLgU.Txt --------- 32622 12.07.2010 23:07 C:\WINDOWS\wiaservc.log --------- 50 12.07.2010 23:07 C:\WINDOWS\wiadebug.log --------- 216 12.07.2010 23:04 C:\WINDOWS\eyalutiholurac.dll --------- 2716 12.07.2010 23:03 C:\WINDOWS\0.log --------- 0 12.07.2010 20:24 C:\WINDOWS\udecahex.dll --------- 2716 12.07.2010 14:37 C:\WINDOWS\ewipihax.dll --------- 2716 12.07.2010 14:27 C:\WINDOWS\apukatiyuwaxo.dll --------- 2716 12.07.2010 14:02 C:\WINDOWS\efibebax.dll --------- 2716 12.07.2010 13:08 C:\WINDOWS\igiyovox.dll --------- 2716 12.07.2010 11:37 C:\WINDOWS\izecoqaf.dll --------- 2716 12.07.2010 10:48 C:\WINDOWS\eqawinaqa.dll --------- 2716 12.07.2010 10:14 C:\WINDOWS\ayiyiyim.dll --------- 2716 12.07.2010 10:07 C:\WINDOWS\WISO.INI --------- 271 12.07.2010 09:44 C:\WINDOWS\abirisohahozew.dll --------- 0 31.05.2010 12:59 C:\WINDOWS\iis6.log --------- 1011011 31.05.2010 12:59 C:\WINDOWS\comsetup.log --------- 302631 31.05.2010 12:59 C:\WINDOWS\tabletoc.log --------- 43456 31.05.2010 12:59 C:\WINDOWS\ntdtcsetup.log --------- 185520 31.05.2010 12:59 C:\WINDOWS\imsins.log --------- 1374 31.05.2010 12:59 C:\WINDOWS\tsoc.log --------- 404392 31.05.2010 12:59 C:\WINDOWS\ocmsn.log --------- 45937 31.05.2010 12:59 C:\WINDOWS\KB981793.log --------- 3952 31.05.2010 12:59 C:\WINDOWS\netfxocm.log --------- 151843 31.05.2010 12:59 C:\WINDOWS\medctroc.Log --------- 49504 31.05.2010 12:59 C:\WINDOWS\ocgen.log --------- 447477 31.05.2010 12:59 C:\WINDOWS\msgsocm.log --------- 43863 31.05.2010 12:59 C:\WINDOWS\FaxSetup.log --------- 857121 31.05.2010 12:58 C:\WINDOWS\msmqinst.log --------- 279852 21.05.2010 21:19 C:\WINDOWS\imsins.BAK --------- 1374 21.05.2010 21:19 C:\WINDOWS\KB978542.log --------- 18098 19.05.2010 20:32 C:\WINDOWS\setupapi.log --------- 494459 17.05.2010 11:43 C:\WINDOWS\cdplayer.ini --------- 6398 15.04.2010 09:22 C:\WINDOWS\KB979683.log --------- 12932 15.04.2010 09:19 C:\WINDOWS\KB980232.log --------- 11454 15.04.2010 09:11 C:\WINDOWS\KB981349.log --------- 20321 15.04.2010 09:11 C:\WINDOWS\updspapi.log --------- 114960 15.04.2010 09:11 C:\WINDOWS\KB978338.log --------- 19074 15.04.2010 09:10 C:\WINDOWS\KB977816.log --------- 18687 15.04.2010 09:09 C:\WINDOWS\KB978601.log --------- 19181 15.04.2010 09:09 C:\WINDOWS\KB979309.log --------- 18260 04.04.2010 22:22 C:\WINDOWS\KB980182.log --------- 22857 28.03.2010 21:06 C:\WINDOWS\NeroDigital.ini --------- 116 23.03.2010 21:13 C:\WINDOWS\setupact.log --------- 148471 10.03.2010 21:26 C:\WINDOWS\KB975561.log --------- 9972 25.02.2010 09:41 C:\WINDOWS\KB979306.log --------- 7489 11.02.2010 12:53 C:\WINDOWS\KB978262.log --------- 10418 11.02.2010 12:53 C:\WINDOWS\KB971468.log --------- 11068 11.02.2010 12:50 C:\WINDOWS\KB978037.log --------- 19047 11.02.2010 12:49 C:\WINDOWS\KB975713.log --------- 18798 11.02.2010 12:49 C:\WINDOWS\KB978251.log --------- 10189 11.02.2010 12:49 C:\WINDOWS\KB975560.log --------- 18765 11.02.2010 12:48 C:\WINDOWS\KB977914.log --------- 19506 11.02.2010 12:48 C:\WINDOWS\KB978706.log --------- 18037 11.02.2010 12:48 C:\WINDOWS\KB977165.log --------- 12094 07.02.2010 14:17 C:\WINDOWS\tkkg_1.ini --------- 36 01.02.2010 10:13 C:\WINDOWS\KB978207.log --------- 41204 16.01.2010 23:06 C:\WINDOWS\KB958869.log --------- 16298 16.01.2010 23:06 C:\WINDOWS\KB970430.log --------- 29368 16.01.2010 23:06 C:\WINDOWS\KB976098-v2.log --------- 11753 16.01.2010 23:05 C:\WINDOWS\KB955759.log --------- 18276 16.01.2010 23:05 C:\WINDOWS\KB974318.log --------- 26796 16.01.2010 23:05 C:\WINDOWS\KB969059.log --------- 25452 16.01.2010 23:05 C:\WINDOWS\KB954155.log --------- 11920 16.01.2010 23:05 C:\WINDOWS\KB972270.log --------- 16040 16.01.2010 23:04 C:\WINDOWS\KB974112.log --------- 25363 16.01.2010 23:04 C:\WINDOWS\KB975025.log --------- 25197 16.01.2010 23:04 C:\WINDOWS\KB974571.log --------- 25761 16.01.2010 23:04 C:\WINDOWS\KB976325.log --------- 26655 16.01.2010 23:01 C:\WINDOWS\KB973687.log --------- 14216 16.01.2010 23:00 C:\WINDOWS\KB973904.log --------- 14296 16.01.2010 23:00 C:\WINDOWS\KB974392.log --------- 22578 16.01.2010 23:00 C:\WINDOWS\KB971737.log --------- 22084 16.01.2010 23:00 C:\WINDOWS\KB971486.log --------- 13894 16.01.2010 22:59 C:\WINDOWS\KB973525.log --------- 12127 16.01.2010 22:59 C:\WINDOWS\msxml4-KB973688-enu.LOG --------- 316700 16.01.2010 22:59 C:\WINDOWS\KB975467.log --------- 21542 16.01.2010 22:59 C:\WINDOWS\KB969947.log --------- 21356 10.09.2009 14:53 C:\WINDOWS\KB968816.log --------- 6163 10.09.2009 14:53 C:\WINDOWS\KB956844.log --------- 9781 10.09.2009 14:53 C:\WINDOWS\KB971961.log --------- 11942 26.08.2009 14:27 C:\WINDOWS\KB970653-v3.log --------- 3964 19.08.2009 14:30 C:\WINDOWS\KB961118.log --------- 8215 18.08.2009 09:01 C:\WINDOWS\spupdsvc.log --------- 38002 17.08.2009 23:14 C:\WINDOWS\KB960859.log --------- 26845 17.08.2009 23:14 C:\WINDOWS\KB971657.log --------- 26691 17.08.2009 23:14 C:\WINDOWS\KB971557.log --------- 26195 17.08.2009 23:13 C:\WINDOWS\KB956744.log --------- 18286 17.08.2009 22:52 C:\WINDOWS\KB973869.log --------- 13893 17.08.2009 22:52 C:\WINDOWS\KB973507.log --------- 22740 17.08.2009 22:52 C:\WINDOWS\KB973354.log --------- 13476 17.08.2009 22:52 C:\WINDOWS\KB973540.log --------- 10234 17.08.2009 22:52 C:\WINDOWS\wmsetup.log --------- 83050 17.08.2009 22:49 C:\WINDOWS\KB973815.log --------- 22079 17.08.2009 22:49 C:\WINDOWS\KB968389.log --------- 23890 30.07.2009 20:38 C:\WINDOWS\KB972260.log --------- 23385 15.07.2009 22:50 C:\WINDOWS\KB973346.log --------- 9548 15.07.2009 22:50 C:\WINDOWS\KB971633.log --------- 17722 15.07.2009 22:47 C:\WINDOWS\KB961371.log --------- 18039 14.06.2009 10:33 C:\WINDOWS\KB961501.log --------- 21418 14.06.2009 10:33 C:\WINDOWS\KB969897.log --------- 22512 14.06.2009 10:33 C:\WINDOWS\KB969898.log --------- 10607 14.06.2009 10:31 C:\WINDOWS\KB970238.log --------- 19100 14.06.2009 10:31 C:\WINDOWS\KB968537.log --------- 18932 18.04.2009 13:03 C:\WINDOWS\KB959426.log --------- 29586 18.04.2009 13:03 C:\WINDOWS\KB961373.log --------- 28262 18.04.2009 13:00 C:\WINDOWS\KB956572.log --------- 22244 18.04.2009 13:00 C:\WINDOWS\KB952004.log --------- 25987 18.04.2009 12:59 C:\WINDOWS\KB960803.log --------- 24406 18.04.2009 12:59 C:\WINDOWS\KB963027.log --------- 25381 18.04.2009 12:59 C:\WINDOWS\KB923561.log --------- 13691 03.04.2009 12:53 C:\WINDOWS\spupdsvc.log.1.log --------- 352 03.04.2009 11:51 C:\WINDOWS\WgaNotify.log --------- 21167 11.03.2009 19:41 C:\WINDOWS\KB960225.log --------- 18568 11.03.2009 19:41 C:\WINDOWS\KB958690.log --------- 18707 26.02.2009 19:35 C:\WINDOWS\KB967715.log --------- 18939 12.02.2009 13:31 C:\WINDOWS\KB960715.log --------- 9655 15.01.2009 21:20 C:\WINDOWS\KB958687.log --------- 11091 15.01.2009 21:20 C:\WINDOWS\KB951748.log --------- 20287 12.01.2009 13:19 C:\WINDOWS\KB951376-v2.log --------- 16614 12.01.2009 13:19 C:\WINDOWS\KB952954.log --------- 25962 12.01.2009 13:18 C:\WINDOWS\KB946648.log --------- 15881 12.01.2009 13:18 C:\WINDOWS\KB956803.log --------- 15964 12.01.2009 13:18 C:\WINDOWS\ie7_main.log --------- 1183 12.01.2009 13:06 C:\WINDOWS\KB955839.log --------- 38886 12.01.2009 13:06 C:\WINDOWS\KB956391.log --------- 15541 12.01.2009 13:06 C:\WINDOWS\KB957095.log --------- 16064 12.01.2009 13:06 C:\WINDOWS\KB958215.log --------- 16734 12.01.2009 13:05 C:\WINDOWS\KB951978.log --------- 25035 12.01.2009 13:03 C:\WINDOWS\KB950974.log --------- 23900 12.01.2009 13:02 C:\WINDOWS\KB951698.log --------- 23095 12.01.2009 13:02 C:\WINDOWS\KB954211.log --------- 14113 12.01.2009 13:02 C:\WINDOWS\KB952069.log --------- 12270 12.01.2009 13:02 C:\WINDOWS\KB956841.log --------- 15105 12.01.2009 13:01 C:\WINDOWS\KB960714.log --------- 14153 12.01.2009 13:01 C:\WINDOWS\KB941569.log --------- 12480 12.01.2009 13:00 C:\WINDOWS\KB950762.log --------- 13437 12.01.2009 13:00 C:\WINDOWS\KB957097.log --------- 13502 12.01.2009 13:00 C:\WINDOWS\KB923689.log --------- 12632 12.01.2009 12:59 C:\WINDOWS\KB952287.log --------- 13125 12.01.2009 12:59 C:\WINDOWS\KB954459.log --------- 22223 12.01.2009 12:59 C:\WINDOWS\KB938464.log --------- 10900 12.01.2009 12:59 C:\WINDOWS\KB954600.log --------- 13205 12.01.2009 12:58 C:\WINDOWS\KB958644.log --------- 13514 12.01.2009 12:58 C:\WINDOWS\KB955069.log --------- 12997 12.01.2009 12:58 C:\WINDOWS\KB956802.log --------- 21931 12.01.2009 12:58 C:\WINDOWS\msxml4-KB954430-enu.LOG --------- 320392 12.01.2009 12:58 C:\WINDOWS\KB936782.log --------- 9248 12.01.2009 12:55 C:\WINDOWS\setuplog.txt --------- 834346 19.12.2008 17:37 C:\WINDOWS\DtcInstall.log --------- 354 19.12.2008 17:36 C:\WINDOWS\WMSysPr9.prx --------- 316640 19.12.2008 17:34 C:\WINDOWS\OEWABLog.txt --------- 1519 19.12.2008 17:29 C:\WINDOWS\svcpack.log --------- 508929 19.12.2008 16:57 C:\WINDOWS\cmsetacl.log --------- 200 19.12.2008 16:56 C:\WINDOWS\sessmgr.setup.log --------- 1330 19.12.2008 16:07 C:\WINDOWS\KB885835.log --------- 7044 19.12.2008 16:06 C:\WINDOWS\KB899587.log --------- 6456 19.12.2008 16:06 C:\WINDOWS\KB923414.log --------- 6362 19.12.2008 16:06 C:\WINDOWS\KB921883.log --------- 6257 19.12.2008 16:06 C:\WINDOWS\KB920685.log --------- 6159 19.12.2008 16:06 C:\WINDOWS\KB896424.log --------- 6070 19.12.2008 16:05 C:\WINDOWS\KB893756.log --------- 5961 19.12.2008 16:05 C:\WINDOWS\KB896423.log --------- 5863 19.12.2008 16:05 C:\WINDOWS\KB873339.log --------- 5847 19.12.2008 16:05 C:\WINDOWS\KB924496.log --------- 5667 19.12.2008 16:04 C:\WINDOWS\KB921398.log --------- 5657 19.12.2008 15:16 C:\WINDOWS\KB905495.log --------- 4812 19.12.2008 15:15 C:\WINDOWS\KB902400.log --------- 4727 19.12.2008 15:15 C:\WINDOWS\KB920670.log --------- 4613 19.12.2008 15:15 C:\WINDOWS\KB891781.log --------- 4574 19.12.2008 15:15 C:\WINDOWS\KB890046.log --------- 4419 19.12.2008 15:15 C:\WINDOWS\KB919007.log --------- 4318 19.12.2008 15:15 C:\WINDOWS\KB914388.log --------- 4488 19.12.2008 15:14 C:\WINDOWS\KB890859.log --------- 3737 19.12.2008 15:12 C:\WINDOWS\KB917344.log --------- 4122 19.12.2008 15:11 C:\WINDOWS\KB905414.log --------- 4022 19.12.2008 15:11 C:\WINDOWS\KB917953.log --------- 3924 19.12.2008 15:11 C:\WINDOWS\KB901214.log --------- 3826 19.12.2008 15:11 C:\WINDOWS\KB923191.log --------- 3737 19.12.2008 15:11 C:\WINDOWS\KB917422.log --------- 3627 19.12.2008 15:11 C:\WINDOWS\KB892944.log --------- 3632 19.12.2008 15:10 C:\WINDOWS\KB888302.log --------- 3583 19.12.2008 15:10 C:\WINDOWS\KB900725.log --------- 3442 19.12.2008 15:10 C:\WINDOWS\KB912919.log --------- 3330 19.12.2008 15:09 C:\WINDOWS\KB908531.log --------- 3245 19.12.2008 15:09 C:\WINDOWS\KB905749.log --------- 3129 19.12.2008 15:09 C:\WINDOWS\KB913580.log --------- 3039 19.12.2008 15:08 C:\WINDOWS\KB896428.log --------- 2929 19.12.2008 15:08 C:\WINDOWS\KB835409.log --------- 2929 19.12.2008 15:08 C:\WINDOWS\KB908519.log --------- 2835 19.12.2008 15:08 C:\WINDOWS\KB920683.log --------- 2735 19.12.2008 15:08 C:\WINDOWS\KB914389.log --------- 2783 19.12.2008 15:00 C:\WINDOWS\KB898461.log --------- 8455 19.12.2008 14:59 C:\WINDOWS\KB892130.log --------- 9405 19.12.2008 14:59 C:\WINDOWS\KB893803v2.log --------- 10529 19.12.2008 14:58 C:\WINDOWS\KB842773.log --------- 6420 19.12.2008 14:57 C:\WINDOWS\setupapi.log.0.old --------- 1838482 14.04.2008 08:53 C:\WINDOWS\winhlp32.exe --------- 288768 14.04.2008 08:53 C:\WINDOWS\slrundll.exe --------- 32866 14.04.2008 08:53 C:\WINDOWS\regedit.exe --------- 153600 14.04.2008 08:52 C:\WINDOWS\notepad.exe --------- 70144 14.04.2008 08:52 C:\WINDOWS\hh.exe --------- 10752 14.04.2008 08:52 C:\WINDOWS\explorer.exe --------- 1036800 14.04.2008 08:52 C:\WINDOWS\kbuipmsd.dll --------- 65024 14.04.2008 08:52 C:\WINDOWS\twain_32.dll --------- 50688 07.04.2008 10:32 C:\WINDOWS\Windows Update.log --------- 54418 29.07.2007 21:42 C:\WINDOWS\BUHL.INI --------- 223 13.07.2007 22:12 C:\WINDOWS\EventSystem.log --------- 1902 31.05.2007 21:00 C:\WINDOWS\DPINST.LOG --------- 1219370 24.02.2007 21:21 C:\WINDOWS\mozver.dat --------- 3630 29.12.2006 01:31 C:\WINDOWS\002810_.tmp --------- 19569 18.12.2006 11:50 C:\WINDOWS\Seopolo.INI --------- 85 11.12.2006 12:23 C:\WINDOWS\mgxoschk.ini --------- 6537 15.07.2006 20:38 C:\WINDOWS\win.ini --------- 870 15.07.2006 20:38 C:\WINDOWS\system.ini --------- 227 09.07.2006 13:35 C:\WINDOWS\wmsetup10.log --------- 236 09.07.2006 13:33 C:\WINDOWS\WMSysPrx.prx --------- 299552 26.06.2006 12:13 C:\WINDOWS\nsw.log --------- 764 26.06.2006 11:35 C:\WINDOWS\ModemLog_Conexant D480 MDC V.92 Modem.txt --------- 33252 29.04.2006 18:17 C:\WINDOWS\MAXLINK.INI --------- 516 30.03.2006 09:15 C:\WINDOWS\tm.ini --------- 0 10.12.2005 21:32 C:\WINDOWS\DirectX.log --------- 77155 28.05.2004 15:28 C:\WINDOWS\nsreg.dat --------- 335 15.04.2004 00:00 C:\WINDOWS\xmd.ico --------- 25214 05.04.2004 11:39 C:\WINDOWS\WINNT32.LOG --------- 1870 05.04.2004 11:37 C:\WINDOWS\UPGRADE.TXT --------- 1699 05.04.2004 11:37 C:\WINDOWS\wsdu.log --------- 149 05.04.2004 11:37 C:\WINDOWS\DHCPUPG.LOG --------- 178 21.11.2003 10:39 C:\WINDOWS\alltop.17.0.INI --------- 33 20.11.2003 15:58 C:\WINDOWS\getrootcert.cer --------- 576 10.11.2003 17:33 C:\WINDOWS\runit.exe --------- 18944 29.09.2003 22:50 C:\WINDOWS\xpsp1hfm.log --------- 10113 29.09.2003 22:50 C:\WINDOWS\Q329170.log --------- 45388 29.09.2003 22:49 C:\WINDOWS\Q811630.log --------- 43098 29.09.2003 22:48 C:\WINDOWS\Q817606.log --------- 41556 29.09.2003 22:47 C:\WINDOWS\Q810577.log --------- 39062 29.09.2003 22:45 C:\WINDOWS\Q810833.log --------- 36584 29.09.2003 22:44 C:\WINDOWS\Q810565.log --------- 36120 29.09.2003 22:43 C:\WINDOWS\Q328310.log --------- 29268 29.09.2003 22:40 C:\WINDOWS\Q329115.log --------- 15177 29.09.2003 22:40 C:\WINDOWS\Q329390.log --------- 14594 29.09.2003 22:39 C:\WINDOWS\Q329048.log --------- 14236 29.09.2003 22:39 C:\WINDOWS\Q323255.log --------- 14194 29.09.2003 22:39 C:\WINDOWS\Q329834.log --------- 13549 29.09.2003 22:38 C:\WINDOWS\Q814033.log --------- 23345 29.09.2003 22:35 C:\WINDOWS\Q329441.log --------- 22758 29.09.2003 22:32 C:\WINDOWS\Q815021.log --------- 22206 29.09.2003 22:27 C:\WINDOWS\vminst.log --------- 2078 29.09.2003 22:26 C:\WINDOWS\Q817287.log --------- 21048 29.09.2003 22:23 C:\WINDOWS\Q811493.log --------- 20950 29.09.2003 22:19 C:\WINDOWS\Q819696.log --------- 20080 29.09.2003 22:16 C:\WINDOWS\KB823559.log --------- 19429 29.09.2003 22:10 C:\WINDOWS\dahotfix.log --------- 18596 29.09.2003 22:09 C:\WINDOWS\KB821557.log --------- 18138 29.09.2003 22:00 C:\WINDOWS\KB824146.log --------- 16989 29.09.2003 21:51 C:\WINDOWS\KB824105.log --------- 16001 24.06.2003 15:54 C:\WINDOWS\ccolwiz.ini --------- 63 16.06.2003 17:51 C:\WINDOWS\PowerReg.dat --------- 197 18.03.2003 21:40 C:\WINDOWS\EPSTPLOG.TXT --------- 26817 06.03.2003 21:44 C:\WINDOWS\aconti.dat --------- 765 05.03.2003 21:31 C:\WINDOWS\ODBC.INI --------- 400 05.03.2003 21:23 C:\WINDOWS\Cmousecc.ini --------- 448 28.02.2003 18:26 C:\WINDOWS\setdebug.exe --------- 46352 28.02.2003 16:35 C:\WINDOWS\jautoexp.dat --------- 6550 27.02.2003 14:44 C:\WINDOWS\REGLOCS.OLD --------- 8192 27.02.2003 14:38 C:\WINDOWS\control.ini --------- 0 27.02.2003 14:38 C:\WINDOWS\ODBCINST.INI --------- 4161 27.02.2003 14:36 C:\WINDOWS\WindowsShell.Manifest --------- 749 27.02.2003 14:33 C:\WINDOWS\vb.ini --------- 36 27.02.2003 14:33 C:\WINDOWS\vbaddin.ini --------- 37 27.02.2003 14:26 C:\WINDOWS\Sti_Trace.log --------- 0 27.02.2003 14:22 C:\WINDOWS\regopt.log --------- 1348 27.02.2003 14:22 C:\WINDOWS\System.ini.backup --------- 231 27.02.2003 14:21 C:\WINDOWS\setuperr.log --------- 0 28.11.2002 14:00 C:\WINDOWS\Rhododendron.bmp --------- 17362 28.11.2002 14:00 C:\WINDOWS\twain.dll --------- 94800 28.11.2002 14:00 C:\WINDOWS\F„cher.bmp --------- 26680 28.11.2002 14:00 C:\WINDOWS\twunk_16.exe --------- 49680 28.11.2002 14:00 C:\WINDOWS\Granit.bmp --------- 26582 28.11.2002 14:00 C:\WINDOWS\Blaue Spitzen 16.bmp --------- 1272 28.11.2002 14:00 C:\WINDOWS\Zapotek.bmp --------- 9522 28.11.2002 14:00 C:\WINDOWS\Angler.bmp --------- 17336 28.11.2002 14:00 C:\WINDOWS\Seifenblase.bmp --------- 65978 28.11.2002 14:00 C:\WINDOWS\TASKMAN.EXE --------- 15872 28.11.2002 14:00 C:\WINDOWS\Kaffeetasse.bmp --------- 17062 28.11.2002 14:00 C:\WINDOWS\SET3.tmp --------- 1086182 28.11.2002 14:00 C:\WINDOWS\vmmreg32.dll --------- 18944 28.11.2002 14:00 C:\WINDOWS\desktop.ini --------- 2 28.11.2002 14:00 C:\WINDOWS\Pr„riewind.bmp --------- 65954 28.11.2002 14:00 C:\WINDOWS\wmprfDEU.prx --------- 34818 28.11.2002 14:00 C:\WINDOWS\msdfmap.ini --------- 1405 28.11.2002 14:00 C:\WINDOWS\SETA.tmp --------- 13898 28.11.2002 14:00 C:\WINDOWS\Santa Fe-Stuck.bmp --------- 65832 28.11.2002 14:00 C:\WINDOWS\clock.avi --------- 82944 28.11.2002 14:00 C:\WINDOWS\winhelp.exe --------- 257568 28.11.2002 14:00 C:\WINDOWS\explorer.scf --------- 80 28.11.2002 14:00 C:\WINDOWS\winnt.bmp --------- 48680 28.11.2002 14:00 C:\WINDOWS\winnt256.bmp --------- 48680 28.11.2002 14:00 C:\WINDOWS\twunk_32.exe --------- 25600 28.11.2002 14:00 C:\WINDOWS\Feder.bmp --------- 16730 28.11.2002 14:00 C:\WINDOWS\_default.pif --------- 707 22.06.2001 17:34 C:\WINDOWS\HPLTLNK.EXE --------- 38400 18.06.2001 09:41 C:\WINDOWS\ActiveSkin.INI --------- 112 07.03.1999 23:53 C:\WINDOWS\corelpf.lrs --------- 28252 17.11.1998 13:44 C:\WINDOWS\IsUn0407.exe --------- 328704 29.10.1998 17:45 C:\WINDOWS\IsUninst.exe --------- 306688 06.05.1998 18:06 C:\WINDOWS\unin0407.exe --------- 299008 17.01.1997 05:00 C:\WINDOWS\PI.EXE --------- 182528 10.12.1996 05:21 C:\WINDOWS\iccsigs.dat --------- 39095 01.08.1995 04:44 C:\WINDOWS\PCDLIB32.DLL --------- 212480 ---------------------------------------- C:\WINDOWS\System 14.04.2008 08:53 C:\WINDOWS\System\winspool.drv --------- 146944 14.04.2008 08:19 C:\WINDOWS\System\mmsystem.dll --------- 69632 18.03.2003 21:17 C:\WINDOWS\System\color --------- 0 28.11.2002 14:00 C:\WINDOWS\System\COMMDLG.DLL --------- 33744 28.11.2002 14:00 C:\WINDOWS\System\KEYBOARD.DRV --------- 2000 28.11.2002 14:00 C:\WINDOWS\System\LZEXPAND.DLL --------- 9936 28.11.2002 14:00 C:\WINDOWS\System\MCIAVI.DRV --------- 73760 28.11.2002 14:00 C:\WINDOWS\System\MCISEQ.DRV --------- 25296 28.11.2002 14:00 C:\WINDOWS\System\MCIWAVE.DRV --------- 28160 28.11.2002 14:00 C:\WINDOWS\System\AVIFILE.DLL --------- 109504 28.11.2002 14:00 C:\WINDOWS\System\MMTASK.TSK --------- 1152 28.11.2002 14:00 C:\WINDOWS\System\MOUSE.DRV --------- 2032 28.11.2002 14:00 C:\WINDOWS\System\AVICAP.DLL --------- 70368 28.11.2002 14:00 C:\WINDOWS\System\OLECLI.DLL --------- 82944 28.11.2002 14:00 C:\WINDOWS\System\OLESVR.DLL --------- 24064 28.11.2002 14:00 C:\WINDOWS\System\setup.inf --------- 59167 28.11.2002 14:00 C:\WINDOWS\System\SHELL.DLL --------- 5120 28.11.2002 14:00 C:\WINDOWS\System\SOUND.DRV --------- 1744 28.11.2002 14:00 C:\WINDOWS\System\stdole.tlb --------- 5532 28.11.2002 14:00 C:\WINDOWS\System\SYSTEM.DRV --------- 3360 28.11.2002 14:00 C:\WINDOWS\System\TAPI.DLL --------- 19200 28.11.2002 14:00 C:\WINDOWS\System\TIMER.DRV --------- 4048 28.11.2002 14:00 C:\WINDOWS\System\VER.DLL --------- 9200 28.11.2002 14:00 C:\WINDOWS\System\VGA.DRV --------- 2176 28.11.2002 14:00 C:\WINDOWS\System\WFWNET.DRV --------- 13600 28.11.2002 14:00 C:\WINDOWS\System\MSVIDEO.DLL --------- 127104 10.09.1999 13:06 C:\WINDOWS\System\WOWPOST.EXE --------- 4672 10.09.1999 13:06 C:\WINDOWS\System\WINASPI.DLL --------- 5600 ---------------------------------------- C:\WINDOWS\System32 15.07.2010 08:59 C:\WINDOWS\system32\wpa.dbl --------- 1374 12.07.2010 23:03 C:\WINDOWS\system32\CatRoot2 --------- 0 12.07.2010 23:03 C:\WINDOWS\system32\nvModes.001 --------- 8313 12.07.2010 23:01 C:\WINDOWS\system32\DRIVERS --------- 0 31.05.2010 12:59 C:\WINDOWS\system32\TZLog.log --------- 227464 21.05.2010 21:18 C:\WINDOWS\system32\DLLCACHE --------- 0 20.05.2010 11:33 C:\WINDOWS\system32\MRT.INI --------- 173 30.04.2010 20:51 C:\WINDOWS\system32\MRT.exe --------- 32058312 26.04.2010 10:01 C:\WINDOWS\system32\DRVSTORE --------- 0 26.04.2010 10:01 C:\WINDOWS\system32\lsdelete.exe --------- 15880 22.04.2010 13:11 C:\WINDOWS\system32\LogFiles --------- 0 21.04.2010 15:28 C:\WINDOWS\system32\tzchange.exe --------- 46080 15.04.2010 09:04 C:\WINDOWS\system32\WBEM --------- 0 28.03.2010 20:50 C:\WINDOWS\system32\perfh009.dat --------- 432690 28.03.2010 20:50 C:\WINDOWS\system32\perfh007.dat --------- 449044 28.03.2010 20:50 C:\WINDOWS\system32\perfc009.dat --------- 67646 28.03.2010 20:50 C:\WINDOWS\system32\perfc007.dat --------- 80306 28.03.2010 20:50 C:\WINDOWS\system32\PerfStringBackup.INI --------- 1042054 10.03.2010 06:33 C:\WINDOWS\system32\shdocvw.dll --------- 1509888 10.03.2010 06:33 C:\WINDOWS\system32\browseui.dll --------- 1025024 09.03.2010 13:09 C:\WINDOWS\system32\vbscript.dll --------- 430080 26.02.2010 07:41 C:\WINDOWS\system32\wininet.dll --------- 672768 26.02.2010 07:41 C:\WINDOWS\system32\urlmon.dll --------- 628736 26.02.2010 07:41 C:\WINDOWS\system32\tdc.ocx --------- 61952 26.02.2010 07:41 C:\WINDOWS\system32\mshtml.dll --------- 3094016 26.02.2010 07:41 C:\WINDOWS\system32\iepeers.dll --------- 251904 26.02.2010 07:41 C:\WINDOWS\system32\ieencode.dll --------- 81920 26.02.2010 07:31 C:\WINDOWS\system32\html.iec --------- 371200 17.02.2010 14:04 C:\WINDOWS\system32\ntoskrnl.exe --------- 2192256 16.02.2010 21:04 C:\WINDOWS\system32\ntkrnlpa.exe --------- 2069120 12.02.2010 06:33 C:\WINDOWS\system32\6to4svc.dll --------- 100864 01.02.2010 13:55 C:\WINDOWS\system32\USER.SCP --------- 254 01.02.2010 13:55 C:\WINDOWS\system32\TEMPSCP.SCP --------- 254 29.01.2010 16:59 C:\WINDOWS\system32\inetcomm.dll --------- 691712 29.01.2010 16:43 C:\WINDOWS\system32\l3codeca.acm --------- 307260 21.01.2010 09:44 C:\WINDOWS\system32\FNTCACHE.DAT --------- 164320 16.01.2010 22:23 C:\WINDOWS\system32\SoftwareDistribution --------- 0 13.01.2010 16:00 C:\WINDOWS\system32\cabview.dll --------- 86528 24.12.2009 08:59 C:\WINDOWS\system32\wintrust.dll --------- 177664 17.12.2009 09:40 C:\WINDOWS\system32\mspaint.exe --------- 346624 14.12.2009 09:08 C:\WINDOWS\system32\csrsrv.dll --------- 33280 08.12.2009 11:23 C:\WINDOWS\system32\shlwapi.dll --------- 474624 27.11.2009 19:11 C:\WINDOWS\system32\msyuv.dll --------- 17920 27.11.2009 19:11 C:\WINDOWS\system32\quartz.dll --------- 1297408 27.11.2009 18:08 C:\WINDOWS\system32\msrle32.dll --------- 11264 27.11.2009 18:08 C:\WINDOWS\system32\avifil32.dll --------- 85504 27.11.2009 18:08 C:\WINDOWS\system32\iyuv_32.dll --------- 48128 27.11.2009 18:08 C:\WINDOWS\system32\msvidc32.dll --------- 28672 27.11.2009 18:08 C:\WINDOWS\system32\tsbyuv.dll --------- 8704 11.11.2009 00:08 C:\WINDOWS\system32\QuickTime.qts --------- 69632 11.11.2009 00:08 C:\WINDOWS\system32\QuickTimeVR.qtx --------- 94208 21.10.2009 07:38 C:\WINDOWS\system32\strmfilt.dll --------- 75776 21.10.2009 07:38 C:\WINDOWS\system32\httpapi.dll --------- 25088 15.10.2009 18:28 C:\WINDOWS\system32\fontsub.dll --------- 81920 15.10.2009 18:28 C:\WINDOWS\system32\t2embed.dll --------- 119808 13.10.2009 12:32 C:\WINDOWS\system32\oakley.dll --------- 271360 12.10.2009 15:38 C:\WINDOWS\system32\raschap.dll --------- 79872 12.10.2009 15:38 C:\WINDOWS\system32\rastls.dll --------- 150528 11.09.2009 16:17 C:\WINDOWS\system32\msv1_0.dll --------- 136192 04.09.2009 23:03 C:\WINDOWS\system32\msasn1.dll --------- 58880 01.09.2009 16:46 C:\WINDOWS\system32\msaud32.acm --------- 282654 28.08.2009 20:42 C:\WINDOWS\system32\usbaaplrc.dll --------- 2065696 26.08.2009 10:00 C:\WINDOWS\system32\strmdll.dll --------- 247326 25.08.2009 11:17 C:\WINDOWS\system32\winhttp.dll --------- 354816 19.08.2009 14:29 C:\WINDOWS\system32\CatRoot --------- 0 18.08.2009 19:38 C:\WINDOWS\system32\ssprs.tgz --------- 87 18.08.2009 19:38 C:\WINDOWS\system32\ssprs.dll --------- 73 17.08.2009 23:02 C:\WINDOWS\system32\XPSViewer --------- 0 17.08.2009 23:01 C:\WINDOWS\system32\en-US --------- 0 17.08.2009 23:00 C:\WINDOWS\system32\SPOOL --------- 0 17.08.2009 22:56 C:\WINDOWS\system32\MUI --------- 0 14.08.2009 17:10 C:\WINDOWS\system32\win32k.sys --------- 1850752 13.08.2009 17:15 C:\WINDOWS\system32\jscript.dll --------- 512000 06.08.2009 20:24 C:\WINDOWS\system32\wucltui.dll --------- 327896 06.08.2009 20:24 C:\WINDOWS\system32\wuweb.dll --------- 209632 06.08.2009 20:24 C:\WINDOWS\system32\wuaueng.dll.mui --------- 18144 06.08.2009 20:24 C:\WINDOWS\system32\wups.dll --------- 35552 06.08.2009 20:24 C:\WINDOWS\system32\wuaucpl.cpl --------- 217816 06.08.2009 20:24 C:\WINDOWS\system32\wups2.dll --------- 44768 06.08.2009 20:24 C:\WINDOWS\system32\wuapi.dll.mui --------- 15584 06.08.2009 20:24 C:\WINDOWS\system32\wuauclt.exe --------- 53472 06.08.2009 20:24 C:\WINDOWS\system32\wuaucpl.cpl.mui --------- 15584 06.08.2009 20:24 C:\WINDOWS\system32\cdm.dll --------- 96480 06.08.2009 20:24 C:\WINDOWS\system32\wucltui.dll.mui --------- 23264 06.08.2009 20:23 C:\WINDOWS\system32\wuapi.dll --------- 575704 06.08.2009 20:23 C:\WINDOWS\system32\wuaueng.dll --------- 1929952 05.08.2009 10:59 C:\WINDOWS\system32\mswebdvd.dll --------- 206336 31.07.2009 11:02 C:\WINDOWS\system32\msxml6.dll --------- 1372672 31.07.2009 06:32 C:\WINDOWS\system32\msxml3.dll --------- 1172480 21.07.2009 01:05 C:\WINDOWS\system32\msxml4.dll --------- 1348432 17.07.2009 21:01 C:\WINDOWS\system32\atl.dll --------- 58880 17.07.2009 18:15 C:\WINDOWS\system32\query.dll --------- 1441792 13.07.2009 10:08 C:\WINDOWS\system32\wmpdxm.dll --------- 286720 13.07.2009 10:08 C:\WINDOWS\system32\wmp.dll --------- 5537792 25.06.2009 10:25 C:\WINDOWS\system32\kerberos.dll --------- 301568 25.06.2009 10:25 C:\WINDOWS\system32\schannel.dll --------- 147456 25.06.2009 10:25 C:\WINDOWS\system32\secur32.dll --------- 56832 25.06.2009 10:25 C:\WINDOWS\system32\lsasrv.dll --------- 737792 25.06.2009 10:25 C:\WINDOWS\system32\wdigest.dll --------- 54272 15.06.2009 12:43 C:\WINDOWS\system32\telnet.exe --------- 78848 ---------------------------------------- |
15.07.2010, 14:13 | #6 |
/// Helfer-Team | AV Security Suite Antimalware- was noch?Code:
ATTFilter C:\WINDOWS\Prefetch 12.07.2010 23:07 C:\WINDOWS\Prefetch\WSCNTFY.EXE-0B14C27D.pf --------- 8528 12.07.2010 23:06 C:\WINDOWS\Prefetch\IEXPLORE.EXE-360BBB5C.pf --------- 89830 12.07.2010 23:06 C:\WINDOWS\Prefetch\RUNDLL32.EXE-6E8D4657.pf --------- 13868 12.07.2010 23:05 C:\WINDOWS\Prefetch\GENERIC.EXE-0D0328B3.pf --------- 36614 12.07.2010 23:04 C:\WINDOWS\Prefetch\ALG.EXE-275708CF.pf --------- 24506 12.07.2010 23:04 C:\WINDOWS\Prefetch\AVWSC.EXE-1742FD55.pf --------- 36222 12.07.2010 23:04 C:\WINDOWS\Prefetch\IPODSERVICE.EXE-07892C80.pf --------- 30590 12.07.2010 23:04 C:\WINDOWS\Prefetch\POWERPNT.EXE-3186F235.pf --------- 46858 12.07.2010 23:04 C:\WINDOWS\Prefetch\IMAPI.EXE-201490BB.pf --------- 27030 12.07.2010 23:04 C:\WINDOWS\Prefetch\RUNDLL32.EXE-3E7C6A43.pf --------- 42730 12.07.2010 23:04 C:\WINDOWS\Prefetch\EXCEL.EXE-11B6929A.pf --------- 41678 12.07.2010 23:04 C:\WINDOWS\Prefetch\CAPABILITYMANAGER.EXE-15EE2405.pf --------- 78016 12.07.2010 23:04 C:\WINDOWS\Prefetch\APPLICATION LAUNCHER.EXE-21E0EA77.pf --------- 29252 12.07.2010 23:04 C:\WINDOWS\Prefetch\CTFMON.EXE-05E57A5E.pf --------- 15802 12.07.2010 23:04 C:\WINDOWS\Prefetch\ESSDLWCTSSD.EXE-08DB6B5D.pf --------- 19888 12.07.2010 23:04 C:\WINDOWS\Prefetch\ITUNESHELPER.EXE-1CC2818B.pf --------- 28232 12.07.2010 23:04 C:\WINDOWS\Prefetch\EM_EXEC.EXE-3740A861.pf --------- 23304 12.07.2010 23:04 C:\WINDOWS\Prefetch\OPWARESE2.EXE-159F1707.pf --------- 20656 12.07.2010 23:04 C:\WINDOWS\Prefetch\MEINSPARBUCHHEUTE.EXE-054ADC03.pf --------- 59472 12.07.2010 23:04 C:\WINDOWS\Prefetch\CARPSERV.EXE-2E100564.pf --------- 8154 12.07.2010 23:04 C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf --------- 80084 12.07.2010 23:04 C:\WINDOWS\Prefetch\RUNDLL32.EXE-4DED6A50.pf --------- 19460 12.07.2010 23:04 C:\WINDOWS\Prefetch\WGATRAY.EXE-350D4455.pf --------- 42636 12.07.2010 23:04 C:\WINDOWS\Prefetch\NWIZ.EXE-2D374245.pf --------- 12622 12.07.2010 23:04 C:\WINDOWS\Prefetch\QTTASK.EXE-0C419446.pf --------- 10060 12.07.2010 23:04 C:\WINDOWS\Prefetch\USERINIT.EXE-0743FDA9.pf --------- 21186 12.07.2010 23:04 C:\WINDOWS\Prefetch\NEROCHECK.EXE-30941580.pf --------- 9376 12.07.2010 23:04 C:\WINDOWS\Prefetch\MBAMGUI.EXE-1253A586.pf --------- 7568 12.07.2010 23:04 C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf --------- 1090050 12.07.2010 20:27 C:\WINDOWS\Prefetch\RKILL.EXE-130826E5.pf --------- 2360 12.07.2010 20:26 C:\WINDOWS\Prefetch\WUAUCLT.EXE-1360D60A.pf --------- 49042 12.07.2010 20:24 C:\WINDOWS\Prefetch\MBAM.EXE-325FAE38.pf --------- 28676 12.07.2010 20:24 C:\WINDOWS\Prefetch\AVSCAN.EXE-068A2CAC.pf --------- 23604 12.07.2010 20:23 C:\WINDOWS\Prefetch\EPMWORKER.EXE-2F955D77.pf --------- 30778 12.07.2010 20:23 C:\WINDOWS\Prefetch\SENDTODEVICE.EXE-1ABD1666.pf --------- 32876 12.07.2010 14:52 C:\WINDOWS\Prefetch\LOGONUI.EXE-312BE1BF.pf --------- 18816 12.07.2010 14:51 C:\WINDOWS\Prefetch\FIREFOX.EXE-28BE8AE1.pf --------- 90800 12.07.2010 14:46 C:\WINDOWS\Prefetch\REGEDIT.EXE-2AE3423E.pf --------- 15268 12.07.2010 14:46 C:\WINDOWS\Prefetch\VERCLSID.EXE-28F52AD2.pf --------- 17176 12.07.2010 14:45 C:\WINDOWS\Prefetch\REGSVR32.EXE-396DEA2C.pf --------- 16982 12.07.2010 14:45 C:\WINDOWS\Prefetch\MBAM-SETUP.TMP-125A874A.pf --------- 26094 12.07.2010 14:45 C:\WINDOWS\Prefetch\MBAM-SETUP.EXE-08D83AB1.pf --------- 16822 12.07.2010 14:37 C:\WINDOWS\Prefetch\SVCHOST.EXE-2D5FBD18.pf --------- 22130 12.07.2010 14:34 C:\WINDOWS\Prefetch\AVCONFIG.EXE-0014E46E.pf --------- 26214 12.07.2010 14:34 C:\WINDOWS\Prefetch\AVCENTER.EXE-377C5668.pf --------- 37572 12.07.2010 14:33 C:\WINDOWS\Prefetch\CMD.EXE-034B0549.pf --------- 14952 12.07.2010 14:26 C:\WINDOWS\Prefetch\ADOBE GAMMA LOADER.EXE-0C2694E8.pf --------- 21622 12.07.2010 14:26 C:\WINDOWS\Prefetch\READER_SL.EXE-2A604B5A.pf --------- 15324 12.07.2010 14:26 C:\WINDOWS\Prefetch\WINWORD.EXE-2F8AFD78.pf --------- 96646 12.07.2010 14:26 C:\WINDOWS\Prefetch\RUNDLL32.EXE-477CF919.pf --------- 32060 12.07.2010 14:26 C:\WINDOWS\Prefetch\ADOBEUPDATEMANAGER.EXE-123A1126.pf --------- 18842 12.07.2010 14:26 C:\WINDOWS\Prefetch\RUNDLL32.EXE-671FE8B2.pf --------- 15756 12.07.2010 14:26 C:\WINDOWS\Prefetch\AVGNT.EXE-0B50EBC8.pf --------- 51830 12.07.2010 14:26 C:\WINDOWS\Prefetch\WMIPRVSE.EXE-0D449B4F.pf --------- 72036 12.07.2010 14:09 C:\WINDOWS\Prefetch\RSTRUI.EXE-05C31B56.pf --------- 30776 12.07.2010 14:09 C:\WINDOWS\Prefetch\RUNDLL32.EXE-419F288A.pf --------- 33422 12.07.2010 14:09 C:\WINDOWS\Prefetch\CONTROL.EXE-24FBF8B3.pf --------- 30578 12.07.2010 14:08 C:\WINDOWS\Prefetch\AD-AWAREINSTALLER.EXE-18A3B703.pf --------- 36030 12.07.2010 14:08 C:\WINDOWS\Prefetch\RUNDLL32.EXE-6E0E3853.pf --------- 1556 12.07.2010 13:13 C:\WINDOWS\Prefetch\UPDATE.EXE-33FE454B.pf --------- 60498 12.07.2010 11:39 C:\WINDOWS\Prefetch\NOTEPAD.EXE-2F2D61E1.pf --------- 17454 12.07.2010 09:58 C:\WINDOWS\Prefetch\TASKMGR.EXE-06144C13.pf --------- 29094 12.07.2010 09:56 C:\WINDOWS\Prefetch\WISO2010.EXE-0FCF4318.pf --------- 25254 12.07.2010 09:56 C:\WINDOWS\Prefetch\WMAIN10.DLL-1C71775B.pf --------- 60448 12.07.2010 09:54 C:\WINDOWS\Prefetch\IFNP.EXE-0597BCA8.pf --------- 7036 12.07.2010 09:54 C:\WINDOWS\Prefetch\VKUL.EXE-3A5655BE.pf --------- 11218 12.07.2010 09:52 C:\WINDOWS\Prefetch\ACRORD32.EXE-0ABDA372.pf --------- 103100 12.07.2010 09:47 C:\WINDOWS\Prefetch\SNDVOL32.EXE-0EC6FD20.pf --------- 17434 10.07.2010 12:03 C:\WINDOWS\Prefetch\RUNDLL32.EXE-426A8BD3.pf --------- 17342 10.07.2010 12:03 C:\WINDOWS\Prefetch\DBMB.EXE-0A126500.pf --------- 21474 10.07.2010 12:03 C:\WINDOWS\Prefetch\GBNX.EXE-1260A1F3.pf --------- 12632 08.07.2010 13:37 C:\WINDOWS\Prefetch\ACRORD32INFO.EXE-3AD69296.pf --------- 43952 08.07.2010 13:30 C:\WINDOWS\Prefetch\VLC.EXE-2584CE07.pf --------- 108814 08.07.2010 12:52 C:\WINDOWS\Prefetch\HELPSVC.EXE-1C192440.pf --------- 64618 08.07.2010 12:50 C:\WINDOWS\Prefetch\DFRGNTFS.EXE-38C3807C.pf --------- 51858 08.07.2010 12:50 C:\WINDOWS\Prefetch\DEFRAG.EXE-2858C7E2.pf --------- 16876 08.07.2010 12:50 C:\WINDOWS\Prefetch\Layout.ini --------- 408244 07.07.2010 09:52 C:\WINDOWS\Prefetch\AGENTSVR.EXE-260B72BD.pf --------- 19068 07.07.2010 09:42 C:\WINDOWS\Prefetch\GUARDGUI.EXE-1FA25B88.pf --------- 23890 05.07.2010 09:43 C:\WINDOWS\Prefetch\AVNOTIFY.EXE-22D2A6A0.pf --------- 56346 01.07.2010 14:03 C:\WINDOWS\Prefetch\XOCR32B.EXE-246DDA4A.pf --------- 43088 01.07.2010 14:03 C:\WINDOWS\Prefetch\RUNDLL32.EXE-515BFDB1.pf --------- 17948 01.07.2010 14:03 C:\WINDOWS\Prefetch\OPA11.EXE-1924A7CA.pf --------- 14196 01.07.2010 14:02 C:\WINDOWS\Prefetch\OMNIPAGE.EXE-0242FAE8.pf --------- 6338 01.07.2010 12:58 C:\WINDOWS\Prefetch\NERO.EXE-2D2B9A2A.pf --------- 55388 29.06.2010 11:51 C:\WINDOWS\Prefetch\RUNDLL32.EXE-58D7DDCC.pf --------- 35926 29.06.2010 11:09 C:\WINDOWS\Prefetch\WINZIP32.EXE-2F3C90C9.pf --------- 27744 29.06.2010 11:07 C:\WINDOWS\Prefetch\DWWIN.EXE-2C373FB7.pf --------- 53968 28.06.2010 23:25 C:\WINDOWS\Prefetch\RUNDLL32.EXE-60287359.pf --------- 18758 28.06.2010 23:22 C:\WINDOWS\Prefetch\PHOTOSHOP.EXE-25FD3C17.pf --------- 71454 28.06.2010 23:22 C:\WINDOWS\Prefetch\RUNDLL32.EXE-545445AE.pf --------- 20100 28.06.2010 23:16 C:\WINDOWS\Prefetch\DRWTSN32.EXE-01DDCF15.pf --------- 44504 28.06.2010 22:19 C:\WINDOWS\Prefetch\YLAGS.EXE-368A7C45.pf --------- 11622 28.06.2010 19:00 C:\WINDOWS\Prefetch\LOGON.SCR-24ADF392.pf --------- 44000 28.06.2010 10:01 C:\WINDOWS\Prefetch\CRASHREPORTER.EXE-05610F59.pf --------- 14642 28.06.2010 09:01 C:\WINDOWS\Prefetch\NIAB.EXE-0309D800.pf --------- 12292 28.06.2010 09:01 C:\WINDOWS\Prefetch\SVCHOST.EXE-2130E909.pf --------- 18270 17.06.2010 10:17 C:\WINDOWS\Prefetch\FLASHPLAYERUPDATE01.EXE-31FFFD46.pf --------- 1578 08.06.2010 17:48 C:\WINDOWS\Prefetch\RUNDLL32.EXE-55CA3755.pf --------- 27906 08.06.2010 17:45 C:\WINDOWS\Prefetch\RUNDLL32.EXE-4FF9832D.pf --------- 13382 07.06.2010 08:38 C:\WINDOWS\Prefetch\MSIEXEC.EXE-330626DC.pf --------- 16902 31.05.2010 12:58 C:\WINDOWS\Prefetch\UPDATE.EXE-09ADE36F.pf --------- 61814 31.05.2010 12:00 C:\WINDOWS\Prefetch\WMPLAYER.EXE-017735AC.pf --------- 39180 27.05.2010 11:16 C:\WINDOWS\Prefetch\WMPLAYER.EXE-017735B2.pf --------- 72844 21.05.2010 21:16 C:\WINDOWS\Prefetch\UPDATE.EXE-17E940DC.pf --------- 71070 21.05.2010 21:12 C:\WINDOWS\Prefetch\UPDATE.EXE-16981349.pf --------- 56278 20.05.2010 11:33 C:\WINDOWS\Prefetch\AAWWSC.EXE-3A84F9F6.pf --------- 30192 20.05.2010 11:29 C:\WINDOWS\Prefetch\MRT.EXE-161A5291.pf --------- 53512 20.05.2010 11:29 C:\WINDOWS\Prefetch\WINDOWS-KB890830-V3.7-DELTA.E-056EEAB2.pf --------- 46262 20.05.2010 11:29 C:\WINDOWS\Prefetch\MRTSTUB.EXE-2612F9A8.pf --------- 52584 20.05.2010 09:56 C:\WINDOWS\Prefetch\AD-AWAREADMIN.EXE-2E1F7B25.pf --------- 46190 20.05.2010 09:51 C:\WINDOWS\Prefetch\AAWTRAY.EXE-11640CC2.pf --------- 106802 20.05.2010 09:49 C:\WINDOWS\Prefetch\AD-AWARE.EXE-22291502.pf --------- 60302 20.05.2010 09:49 C:\WINDOWS\Prefetch\UNSECAPP.EXE-16EB9856.pf --------- 18768 20.05.2010 09:49 C:\WINDOWS\Prefetch\AAWSERVICE.EXE-03154300.pf --------- 67802 19.05.2010 22:02 C:\WINDOWS\Prefetch\SYNCSERVER.EXE-00A8F031.pf --------- 87452 19.05.2010 21:51 C:\WINDOWS\Prefetch\APPLEMOBILEDEVICEHELPER.EXE-1E0001FD.pf --------- 51034 19.05.2010 20:36 C:\WINDOWS\Prefetch\APPLEMOBILEBACKUP.EXE-3094C8ED.pf --------- 76394 19.05.2010 20:36 C:\WINDOWS\Prefetch\OUTLOOKSYNCCLIENT.EXE-2187338C.pf --------- 152548 19.05.2010 20:35 C:\WINDOWS\Prefetch\MDCRASHREPORTTOOL.EXE-218DA579.pf --------- 50682 19.05.2010 20:33 C:\WINDOWS\Prefetch\DISTNOTED.EXE-21F80628.pf --------- 19232 19.05.2010 20:33 C:\WINDOWS\Prefetch\WIAACMGR.EXE-335C1EE8.pf --------- 62666 19.05.2010 20:32 C:\WINDOWS\Prefetch\RUNDLL32.EXE-5BC0CDD9.pf --------- 14816 19.05.2010 20:30 C:\WINDOWS\Prefetch\ITUNES.EXE-39AF51BF.pf --------- 59172 17.05.2010 11:44 C:\WINDOWS\Prefetch\DLLHOST.EXE-14573387.pf --------- 19946 17.05.2010 11:44 C:\WINDOWS\Prefetch\SOFTWAREUPDATE.EXE-25CB4300.pf --------- 43056 17.05.2010 11:19 C:\WINDOWS\Prefetch\AUDIOGRABBER.EXE-11936669.pf --------- 47408 17.05.2010 09:49 C:\WINDOWS\Prefetch\THREATWORK.EXE-00C9F0E5.pf --------- 34068 10.05.2010 10:35 C:\WINDOWS\Prefetch\DUMPREP.EXE-0AF2BF67.pf --------- 38476 ---------------------------------------- C:\WINDOWS\Tasks 12.07.2010 23:07 C:\WINDOWS\Tasks\SA.DAT --------- 6 28.11.2002 14:00 C:\WINDOWS\Tasks\desktop.ini --------- 65 ---------------------------------------- C:\WINDOWS\Temp 15.07.2010 08:59 C:\WINDOWS\Temp\WGAErrLog.txt --------- 483 28.06.2010 09:01 C:\WINDOWS\Temp\cski.tmp --------- 0 16.06.2010 10:07 C:\WINDOWS\Temp\fla71.tmp --------- 866872 14.06.2010 09:57 C:\WINDOWS\Temp\fla51.tmp --------- 1753237 14.06.2010 09:19 C:\WINDOWS\Temp\fla4A.tmp --------- 2458417 08.06.2010 17:50 C:\WINDOWS\Temp\fla6.tmp --------- 464949 26.04.2010 14:18 C:\WINDOWS\Temp\Cookies --------- 0 26.04.2010 08:56 C:\WINDOWS\Temp\5.tmp --------- 0 20.04.2010 20:35 C:\WINDOWS\Temp\4.tmp --------- 0 16.04.2010 08:56 C:\WINDOWS\Temp\B.tmp --------- 0 15.04.2010 10:53 C:\WINDOWS\Temp\AVSETUP_4bc6d2bc --------- 0 01.02.2010 14:04 C:\WINDOWS\Temp\Perflib_Perfdata_de4.dat --------- 16384 16.01.2010 23:14 C:\WINDOWS\Temp\Perflib_Perfdata_320.dat --------- 16384 16.01.2010 23:13 C:\WINDOWS\Temp\ASPNETSetup_00002.log --------- 5158 17.08.2009 23:11 C:\WINDOWS\Temp\dd_wcf_retCA4082.txt --------- 4374 17.08.2009 23:10 C:\WINDOWS\Temp\Perflib_Perfdata_8bc.dat --------- 16384 17.08.2009 23:09 C:\WINDOWS\Temp\ASPNETSetup_00001.log --------- 5158 17.08.2009 23:04 C:\WINDOWS\Temp\dd_dotnetfx35install.txt --------- 279828 17.08.2009 23:04 C:\WINDOWS\Temp\uxeventlog.txt --------- 42618 17.08.2009 23:04 C:\WINDOWS\Temp\dd_NET_Framework35_MSI09F1.txt --------- 1441448 17.08.2009 23:03 C:\WINDOWS\Temp\dd_NET_Framework30_Setup0818.txt --------- 3280924 17.08.2009 23:02 C:\WINDOWS\Temp\dd_wcf_retCA7570.txt --------- 4509 17.08.2009 23:00 C:\WINDOWS\Temp\dd_XPS.txt --------- 15776 17.08.2009 23:00 C:\WINDOWS\Temp\dd_NET_Framework20_Setup02FA.txt --------- 10492772 17.08.2009 22:58 C:\WINDOWS\Temp\ASPNETSetup_00000.log --------- 5158 17.08.2009 22:54 C:\WINDOWS\Temp\dd_RGB9RAST_x86.msi02E0.txt --------- 134976 17.08.2009 22:54 C:\WINDOWS\Temp\dd_clwireg.txt --------- 7944 17.08.2009 22:54 C:\WINDOWS\Temp\dd_depcheck_NETFX_EXP_35.txt --------- 204176 17.08.2009 22:53 C:\WINDOWS\Temp\dd_dotnetfx35error.txt --------- 2 19.12.2008 01:26 C:\WINDOWS\Temp\D653F3EC.TMP --------- 127 15.05.2008 14:12 C:\WINDOWS\Temp\etilqs_S8xnMqDuj64g8VZ --------- 1028 15.05.2008 14:12 C:\WINDOWS\Temp\etilqs_7HudhYDgUTlYGkI-journal --------- 0 15.05.2008 14:12 C:\WINDOWS\Temp\etilqs_hi7gsGkhWsdDHmC --------- 17408 28.02.2008 13:38 C:\WINDOWS\Temp\~sraxdir.tmp --------- 0 10.09.2007 10:34 C:\WINDOWS\Temp\Upd2C.tmp --------- 0 08.09.2007 13:11 C:\WINDOWS\Temp\Upd2B.tmp --------- 0 07.09.2007 15:36 C:\WINDOWS\Temp\Upd2A.tmp --------- 0 07.09.2007 15:04 C:\WINDOWS\Temp\Upd29.tmp --------- 0 03.09.2007 13:42 C:\WINDOWS\Temp\Upd28.tmp --------- 0 03.09.2007 13:19 C:\WINDOWS\Temp\Upd27.tmp --------- 0 30.08.2007 10:53 C:\WINDOWS\Temp\Upd3B.tmp --------- 0 30.08.2007 09:02 C:\WINDOWS\Temp\Upd26.tmp --------- 0 25.08.2007 20:31 C:\WINDOWS\Temp\Upd25.tmp --------- 0 24.08.2007 20:31 C:\WINDOWS\Temp\Upd24.tmp --------- 0 23.08.2007 20:31 C:\WINDOWS\Temp\Upd23.tmp --------- 0 18.08.2007 14:00 C:\WINDOWS\Temp\Upd22.tmp --------- 0 17.08.2007 20:16 C:\WINDOWS\Temp\Upd20.tmp --------- 0 14.08.2007 21:00 C:\WINDOWS\Temp\Upd21.tmp --------- 0 14.08.2007 21:00 C:\WINDOWS\Temp\Upd1F.tmp --------- 0 12.08.2007 13:12 C:\WINDOWS\Temp\Upd1D.tmp --------- 0 10.08.2007 21:28 C:\WINDOWS\Temp\Upd1E.tmp --------- 0 06.08.2007 07:11 C:\WINDOWS\Temp\Upd1C.tmp --------- 0 31.07.2007 12:11 C:\WINDOWS\Temp\Upd2AEB.tmp --------- 0 30.07.2007 12:11 C:\WINDOWS\Temp\UpdDB5.tmp --------- 0 29.07.2007 12:11 C:\WINDOWS\Temp\Upd6E.tmp --------- 0 26.07.2007 22:25 C:\WINDOWS\Temp\Upd8C.tmp --------- 0 25.07.2007 21:13 C:\WINDOWS\Temp\Upd1B.tmp --------- 0 21.07.2007 13:27 C:\WINDOWS\Temp\Upd1A.tmp --------- 0 17.07.2007 20:22 C:\WINDOWS\Temp\Upd19.tmp --------- 0 16.07.2007 08:23 C:\WINDOWS\Temp\Upd18.tmp --------- 0 14.07.2007 13:05 C:\WINDOWS\Temp\Upd17.tmp --------- 0 13.07.2007 22:09 C:\WINDOWS\Temp\Upd16.tmp --------- 0 13.07.2007 20:59 C:\WINDOWS\Temp\Upd14.tmp --------- 0 09.07.2007 21:03 C:\WINDOWS\Temp\Upd13.tmp --------- 0 04.07.2007 12:06 C:\WINDOWS\Temp\Upd12.tmp --------- 0 17.06.2007 13:28 C:\WINDOWS\Temp\Upd11.tmp --------- 0 16.06.2007 13:29 C:\WINDOWS\Temp\Upd10.tmp --------- 0 10.06.2007 22:04 C:\WINDOWS\Temp\UpdF.tmp --------- 0 07.06.2007 12:49 C:\WINDOWS\Temp\UpdD.tmp --------- 0 01.06.2007 19:50 C:\WINDOWS\Temp\Upd15.tmp --------- 0 01.06.2007 19:43 C:\WINDOWS\Temp\UpdC.tmp --------- 0 28.05.2007 13:05 C:\WINDOWS\Temp\UpdB.tmp --------- 0 28.05.2007 12:52 C:\WINDOWS\Temp\UpdA.tmp --------- 0 27.05.2007 13:05 C:\WINDOWS\Temp\Upd9.tmp --------- 0 22.05.2007 20:16 C:\WINDOWS\Temp\Upd1.tmp --------- 0 20.05.2007 11:12 C:\WINDOWS\Temp\Upd7.tmp --------- 0 14.05.2007 11:10 C:\WINDOWS\Temp\Upd70.tmp --------- 0 14.05.2007 08:19 C:\WINDOWS\Temp\Upd6.tmp --------- 0 10.05.2007 20:08 C:\WINDOWS\Temp\Upd1CC.tmp --------- 0 09.05.2007 20:08 C:\WINDOWS\Temp\UpdE.tmp --------- 0 08.05.2007 20:10 C:\WINDOWS\Temp\Upd13B.tmp --------- 0 08.05.2007 20:10 C:\WINDOWS\Temp\Upd13A.tmp --------- 0 08.05.2007 20:08 C:\WINDOWS\Temp\Upd138.tmp --------- 0 07.05.2007 20:08 C:\WINDOWS\Temp\Upd116.tmp --------- 0 06.05.2007 20:08 C:\WINDOWS\Temp\Upd2.tmp --------- 0 04.05.2007 20:08 C:\WINDOWS\Temp\Upd8.tmp --------- 0 02.05.2007 13:37 C:\WINDOWS\Temp\Upd1EA5.tmp --------- 0 01.05.2007 13:37 C:\WINDOWS\Temp\Upd5.tmp --------- 0 30.04.2007 13:37 C:\WINDOWS\Temp\Upd130.tmp --------- 0 29.04.2007 13:37 C:\WINDOWS\Temp\Upd153D.tmp --------- 0 28.04.2007 13:40 C:\WINDOWS\Temp\Upd4.tmp --------- 0 28.04.2007 13:40 C:\WINDOWS\Temp\Upd3.tmp --------- 0 24.02.2003 18:12 C:\WINDOWS\Temp\Verlauf --------- 0 24.02.2003 18:12 C:\WINDOWS\Temp\Temporary Internet Files --------- 0 18.02.2003 22:17 C:\WINDOWS\Temp\WMFA --------- 0 18.02.2003 22:15 C:\WINDOWS\Temp\remove --------- 0 29.08.2001 18:03 C:\WINDOWS\Temp\845.CAT --------- 6749 23.08.2001 14:28 C:\WINDOWS\Temp\ICH3USB.CAT --------- 6757 02.08.2001 16:58 C:\WINDOWS\Temp\845.INF --------- 3527 02.08.2001 15:19 C:\WINDOWS\Temp\ICH3USB.INF --------- 3344 ---------------------------------------- C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp 12.07.2010 23:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{000E148C-F7A7-445A-9044-93BF6CE09ECB} --------- 0 12.07.2010 14:58 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\2.tmp --------- 0 12.07.2010 14:57 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\1.tmp --------- 0 12.07.2010 14:46 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DF1C05.tmp --------- 16384 12.07.2010 14:08 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\mia1 --------- 0 12.07.2010 10:24 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\TTL7UsvY.htm.part --------- 0 12.07.2010 09:54 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\14.tmp --------- 92160 12.07.2010 09:54 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\vKul.exe --------- 293632 10.07.2010 12:03 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\dBMB.exe --------- 65024 10.07.2010 12:03 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\E.tmp --------- 83456 08.07.2010 11:47 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\8ghXr5+u.htm.part --------- 0 01.07.2010 13:33 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR53.tmp --------- 0 01.07.2010 13:09 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR4B.tmp --------- 0 01.07.2010 10:07 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR3E.tmp --------- 0 01.07.2010 09:11 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR12.tmp --------- 0 28.06.2010 23:22 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\TWAIN.LOG --------- 902 28.06.2010 23:22 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Twain001.Mtx --------- 5 28.06.2010 23:22 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Twunk001.MTX --------- 156 28.06.2010 09:59 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-31 --------- 0 17.06.2010 10:30 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-30 --------- 0 16.06.2010 13:05 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-29 --------- 0 16.06.2010 09:29 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\E 01.01.06 Info und Packzettel 1. Woche.pdf --------- 108738 08.06.2010 17:50 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JIS6J127.emf --------- 384368 31.05.2010 12:25 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR1AF.tmp --------- 0 31.05.2010 12:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR1A9.tmp --------- 0 27.05.2010 11:16 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\0raB3.tmp --------- 0 27.05.2010 11:13 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\9x0B2.tmp --------- 0 27.05.2010 11:12 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\3vyAF.tmp --------- 0 27.05.2010 11:11 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\p44AE.tmp --------- 0 27.05.2010 11:08 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\6vcAD.tmp --------- 0 27.05.2010 11:04 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\sufAC.tmp --------- 0 27.05.2010 10:01 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-28 --------- 0 20.05.2010 09:43 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\vxuCmfiW.htm.part --------- 0 19.05.2010 17:47 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-27 --------- 0 17.05.2010 13:49 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ab33_appcompat.txt --------- 52092 29.04.2010 11:22 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR109.tmp --------- 0 29.04.2010 11:05 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBRFB.tmp --------- 0 26.04.2010 09:59 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\info.txt --------- 1714 26.04.2010 09:16 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\f05c_appcompat.txt --------- 224 26.04.2010 09:07 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\70f9_appcompat.txt --------- 224 20.04.2010 20:55 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-26 --------- 0 15.04.2010 10:47 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\dd_vcredistUI64C2.txt --------- 11714 15.04.2010 10:47 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\dd_vcredistMSI64C2.txt --------- 529718 14.04.2010 21:20 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{BC4A4B1B-4162-4E0B-B1A1-3EAAD757ACD2} --------- 0 04.04.2010 22:12 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-25 --------- 0 04.04.2010 21:37 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-24 --------- 0 26.03.2010 23:42 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\5a2d_appcompat.txt --------- 52092 22.03.2010 21:55 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\GuOhbg+V.htm.part --------- 0 22.03.2010 21:55 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\wtoTfqIO.htm.part --------- 0 11.03.2010 11:15 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\MSI83782.LOG --------- 278 11.03.2010 10:54 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\r3f7.tmp --------- 0 17.02.2010 14:12 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\c38b_appcompat.txt --------- 52092 16.02.2010 13:28 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\c480_appcompat.txt --------- 52092 11.02.2010 13:56 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR14.tmp --------- 0 11.02.2010 13:31 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBRC.tmp --------- 0 11.02.2010 11:20 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\QTInstallCode.log --------- 31347 11.02.2010 11:18 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\SetupAdminA7C.log --------- 85 11.02.2010 11:18 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\qtplugin.log --------- 3956 04.02.2010 14:31 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\OwRFdVl7.htm.part --------- 0 04.02.2010 14:30 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\e+B4pEbo.htm.part --------- 0 04.02.2010 09:41 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DF572E.tmp --------- 245760 01.02.2010 10:08 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WERf1bc.dir00 --------- 0 01.11.2009 11:02 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\mtf6.tmp --------- 16384 01.11.2009 11:02 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\mtf4.tmp --------- 16384 01.11.2009 11:02 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\mtf3.tmp --------- 32768 25.10.2009 21:26 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\msohtml1 --------- 0 25.09.2009 12:54 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\5f8f_appcompat.txt --------- 52092 18.09.2009 20:49 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\9ybu1qi8.JPG.part --------- 0 18.09.2009 20:48 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\RUzN7rGO.JPG.part --------- 0 18.09.2009 12:09 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\faeb_appcompat.txt --------- 52092 09.09.2009 12:21 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\moz_mapi --------- 0 01.09.2009 11:05 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{21C87289-B627-443B-BF19-E7D5253FFCA5} --------- 0 24.08.2009 21:01 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\v0016.wmv --------- 1288155 21.08.2009 10:24 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester8015.tmp --------- 0 18.08.2009 22:48 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\rwstjg.tmp --------- 2919 18.08.2009 22:41 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\X_4.png --------- 2295 18.08.2009 22:26 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Safety Copy --------- 0 18.08.2009 22:23 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\X_3.png --------- 4583 18.08.2009 21:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\thumbs --------- 0 21.07.2009 12:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\SetupAdmin378.log --------- 85 15.07.2009 22:46 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-23 --------- 0 14.07.2009 17:16 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-22 --------- 0 12.07.2009 19:51 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\4451_appcompat.txt --------- 52092 30.06.2009 14:01 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\sommerfest.jpg --------- 633634 30.06.2009 11:45 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-21 --------- 0 29.06.2009 10:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester40687.tmp --------- 0 25.06.2009 20:54 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\FrontPageTempDir --------- 0 25.06.2009 20:54 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\wecerr.txt --------- 169 24.06.2009 14:38 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Lui Juli V2-1.xls --------- 18944 24.06.2009 12:15 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Lui Juli V2.xls --------- 15872 24.06.2009 12:14 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\7 RH Darmstadt.pdf --------- 629943 24.06.2009 12:13 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-20 --------- 0 23.06.2009 21:37 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\IMT2E.xml --------- 798234 23.06.2009 21:37 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\IMT2D.xml --------- 426 23.06.2009 21:37 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\IMT2C.xml --------- 2036 23.06.2009 08:29 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-19 --------- 0 14.06.2009 21:24 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\SetupAdmin1F8.log --------- 85 07.06.2009 10:14 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ed51_appcompat.txt --------- 52092 05.06.2009 13:15 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-18 --------- 0 05.06.2009 11:41 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\spezial.jpg --------- 729621 05.06.2009 11:40 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\einladung.jpg --------- 959871 04.06.2009 12:23 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-17 --------- 0 04.06.2009 12:05 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Schulfest2009schillerschule1.doc --------- 22528 18.05.2009 14:10 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester4926.tmp --------- 0 18.05.2009 13:48 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\SetupAdminEC0.log --------- 85 16.05.2009 18:55 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester13288.tmp --------- 0 16.05.2009 18:44 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester13287.tmp --------- 0 04.05.2009 20:40 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester43815.tmp --------- 0 04.05.2009 20:32 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester29533.tmp --------- 0 04.05.2009 09:43 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester58320.tmp --------- 0 04.05.2009 09:25 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester37758.tmp --------- 0 04.05.2009 09:21 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\xs31OHL0.htm.part --------- 0 03.05.2009 20:28 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester14382.tmp --------- 0 28.04.2009 22:39 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester49369.tmp --------- 0 27.04.2009 12:45 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester7328.tmp --------- 0 27.04.2009 11:15 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester4390.tmp --------- 0 23.04.2009 11:47 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\E-428-EG H8.pdf --------- 169281 23.04.2009 10:19 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-16 --------- 0 16.04.2009 13:12 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~WRS1065.tmp --------- 28518 16.04.2009 12:41 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~WRD0002.doc --------- 69 07.04.2009 12:10 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\MSI5e401.LOG --------- 234420 03.04.2009 20:42 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester50990.tmp --------- 0 03.04.2009 13:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\M943B_7m.html.part --------- 0 03.04.2009 13:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\aa7gyVcL.html.part --------- 0 02.04.2009 21:01 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester171.tmp --------- 0 02.04.2009 20:59 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester170.tmp --------- 0 02.04.2009 20:52 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester169.tmp --------- 0 02.04.2009 11:59 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR5.tmp --------- 0 30.03.2009 11:52 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fc53_appcompat.txt --------- 0 30.03.2009 10:49 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester33861.tmp --------- 0 29.03.2009 15:37 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester29053.tmp --------- 0 29.03.2009 15:35 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester29052.tmp --------- 0 23.03.2009 22:46 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~nsu.tmp --------- 0 23.03.2009 10:36 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{0e5702e5-15b0-4228-8812-2bebf662fdc9} --------- 0 23.03.2009 10:33 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\AVSETUP_49c7483c --------- 0 23.03.2009 10:28 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\dd_vcredistUI6A5F.txt --------- 11418 23.03.2009 10:28 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\dd_vcredistMSI6A5F.txt --------- 523768 22.03.2009 23:04 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester21696.tmp --------- 0 22.03.2009 22:51 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\InstTemp1 --------- 0 22.03.2009 22:37 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\xuninst.exe --------- 336896 16.03.2009 23:12 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester12241.tmp --------- 0 16.03.2009 22:53 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester60182.tmp --------- 0 09.03.2009 12:30 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester54889.tmp --------- 0 24.02.2009 14:10 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\etilqs_0qcmbMwTmIKpeigFhJSG-journal --------- 1544 24.02.2009 14:10 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\etilqs_0qcmbMwTmIKpeigFhJSG --------- 1024 24.02.2009 14:10 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\etilqs_dRlOmOxuV8CTDkkV7L4D --------- 16400 24.02.2009 11:29 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-15 --------- 0 24.02.2009 11:17 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\qpg15.tmp --------- 0 20.02.2009 15:09 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\62d5_appcompat.txt --------- 52076 12.02.2009 22:07 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{59BA0FF2-B963-4780-B33A-DADBF9BEA828} --------- 0 12.02.2009 21:59 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\dd_netfx20UI0B55.txt --------- 13548 12.02.2009 21:59 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\dd_netfx20MSI0B55.txt --------- 4608514 12.02.2009 21:53 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ASPNETSetup_00000.log --------- 4562 11.02.2009 13:37 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\PDFB.tmp --------- 81127 11.02.2009 11:36 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\PDF5.tmp --------- 0 10.02.2009 14:58 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\PDF1C.tmp --------- 1023 10.02.2009 14:58 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\PDF21.tmp --------- 122038 04.02.2009 18:25 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\etilqs_OKPX2vCmxcOMla2lgNl5-journal --------- 1544 04.02.2009 18:25 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\etilqs_OKPX2vCmxcOMla2lgNl5 --------- 1024 04.02.2009 18:09 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Vollmacht Bauherrenvertreter.pdf --------- 11834 04.02.2009 12:41 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-14 --------- 0 04.02.2009 11:19 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ Protokoll 7. BHS 02.02.2009.pdf --------- 26625 04.02.2009 11:19 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\etilqs_PahlCY8KtkzMHZ95JhOL --------- 16400 28.01.2009 13:55 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\TOPïs 7. Bauherrensitzung 02.02.2009 k6.5.pdf --------- 17191 27.01.2009 11:37 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\5xl_HXLX.jpg.part --------- 0 26.01.2009 21:58 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~WRS0002.tmp --------- 15590 26.01.2009 21:58 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~WRF0003.tmp --------- 16384 26.01.2009 21:58 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~WRD0001.doc --------- 47577 26.01.2009 15:00 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JAlbumDateDiffTester36157.tmp --------- 0 26.01.2009 14:38 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\InstTemp0 --------- 0 21.01.2009 21:39 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR19.tmp --------- 0 21.01.2009 21:15 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR11.tmp --------- 0 21.01.2009 20:54 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR4.tmp --------- 0 14.01.2009 21:45 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{6f7808a0-ee32-11d4-a743-00b0d06cbf2a} --------- 0 12.01.2009 15:24 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\flaB.tmp --------- 28082375 12.01.2009 15:24 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla9.tmp --------- 392923 12.01.2009 15:24 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-13 --------- 0 12.01.2009 11:53 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-12 --------- 0 12.01.2009 11:29 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\RPj95bh3.htm.part --------- 0 09.01.2009 10:11 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\agUmFBTJ.htm.part --------- 0 06.01.2009 21:27 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\1383_appcompat.txt --------- 53752 05.01.2009 14:05 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\d875_appcompat.txt --------- 5694 22.12.2008 23:28 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\69de_appcompat.txt --------- 52076 20.12.2008 13:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR66.tmp --------- 0 20.12.2008 12:41 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR37.tmp --------- 0 19.12.2008 14:50 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DF538B.tmp --------- 16384 19.12.2008 14:47 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\MPC29.tmp --------- 10328 18.12.2008 18:21 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WER25.tmp.dir00 --------- 0 18.12.2008 18:21 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WER25.tmp --------- 0 18.12.2008 17:12 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\D653F3EC.TMP --------- 127 17.12.2008 12:51 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ProtokollSEBNov2008.doc --------- 33792 17.12.2008 11:03 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WETTBEW2.doc --------- 23040 17.12.2008 11:03 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WETTBEW1.doc --------- 22528 17.12.2008 11:02 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\PROT151208.doc --------- 73216 17.12.2008 11:01 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\MARKTATTR.doc --------- 28672 17.12.2008 11:00 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\CHECKLISTVK2.doc --------- 30208 15.12.2008 10:42 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-11 --------- 0 10.12.2008 13:46 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\X_2.png --------- 6018 10.12.2008 13:45 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\26.jpg --------- 962441 10.12.2008 13:29 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\25.jpg --------- 474944 10.12.2008 13:08 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\X_1.png --------- 1576 09.12.2008 18:58 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\X.png --------- 1578 09.12.2008 18:55 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\24.jpg --------- 1082855 09.12.2008 15:12 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\info --------- 0 09.12.2008 12:52 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Planungstand 9.12.2008.pdf --------- 18747 16.11.2008 18:27 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR2.tmp --------- 0 11.11.2008 21:52 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-10 --------- 0 11.11.2008 21:44 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\etilqs_gAOdERb3KV6vdB95x4dp-journal --------- 1544 11.11.2008 21:44 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\etilqs_gAOdERb3KV6vdB95x4dp --------- 0 11.11.2008 21:44 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\etilqs_F1l3srXraGvThDsgXkcA --------- 0 11.11.2008 14:12 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-9 --------- 0 07.11.2008 17:00 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\_is2.exe --------- 455600 02.10.2008 20:37 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR9.tmp --------- 0 29.09.2008 09:18 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\S4N01iXp.flv.part --------- 0 29.09.2008 09:16 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\JNnRSlgZ.flv.part --------- 0 26.09.2008 13:04 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR27.tmp --------- 0 26.09.2008 12:43 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR15.tmp --------- 0 26.08.2008 23:12 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\MSI78fb9.LOG --------- 234170 26.08.2008 23:12 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\MSI78fb7.LOG --------- 234170 18.08.2008 18:17 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR4C.tmp --------- 0 18.08.2008 17:57 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR43.tmp --------- 0 18.08.2008 17:36 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR3C.tmp --------- 0 18.08.2008 17:15 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR36.tmp --------- 0 18.08.2008 16:54 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR30.tmp --------- 0 18.08.2008 16:21 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR2A.tmp --------- 0 18.08.2008 15:56 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR23.tmp --------- 0 18.08.2008 15:30 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR1D.tmp --------- 0 18.08.2008 15:04 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR16.tmp --------- 0 18.08.2008 14:45 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBRB.tmp --------- 0 15.08.2008 10:11 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DF6E66.tmp --------- 16384 15.08.2008 10:11 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\14480DIR.TMP --------- 0 02.08.2008 20:09 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\23.jpg --------- 3295833 02.08.2008 20:08 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\22.jpg --------- 2855198 02.08.2008 20:02 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\21.jpg --------- 3143740 02.08.2008 19:49 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\20.jpg --------- 2910060 02.08.2008 19:49 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\19.jpg --------- 3410706 02.08.2008 19:49 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\18.jpg --------- 2729419 02.08.2008 19:36 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\17.jpg --------- 1932599 02.08.2008 19:29 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\16.jpg --------- 4106461 02.08.2008 19:29 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\15.jpg --------- 3891909 01.08.2008 16:16 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\14.jpg --------- 3050803 30.07.2008 18:10 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\13.jpg --------- 3315838 30.07.2008 18:04 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\12.jpg --------- 3710752 30.07.2008 18:04 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\11.jpg --------- 3498549 30.07.2008 17:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\10.jpg --------- 2657220 30.07.2008 17:32 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\9.jpg --------- 3242167 30.07.2008 13:48 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\8.jpg --------- 4281651 30.07.2008 13:38 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\7.jpg --------- 3956305 30.07.2008 13:36 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\6.jpg --------- 3025524 30.07.2008 13:36 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\5.jpg --------- 2794832 30.07.2008 13:11 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\4.jpg --------- 3308149 30.07.2008 13:11 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\3.jpg --------- 3308149 30.07.2008 13:10 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\2.jpg --------- 3074878 29.07.2008 10:32 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\1.jpg --------- 2327988 11.06.2008 11:31 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Kostenuebernahmeerklaerung_durch_Privatzahler.doc --------- 28672 11.06.2008 10:14 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-8 --------- 0 06.06.2008 11:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\tmp-3.xpi --------- 382352 30.04.2008 10:33 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla8.tmp --------- 0 30.04.2008 10:33 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla7.tmp --------- 0 30.04.2008 10:33 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla6.tmp --------- 0 30.04.2008 10:32 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla5.tmp --------- 0 30.04.2008 10:28 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla4.tmp --------- 0 30.04.2008 10:27 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla3.tmp --------- 0 13.04.2008 20:21 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR1B.tmp --------- 0 13.04.2008 20:05 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR8.tmp --------- 0 05.04.2008 14:35 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\tmp-2.xpi --------- 382352 01.04.2008 21:07 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMPE.tmp --------- 0 01.04.2008 21:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMP9.tmp --------- 0 01.04.2008 21:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMP8.tmp --------- 0 13.03.2008 11:14 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-7 --------- 0 01.03.2008 15:51 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~sraxdir.tmp --------- 0 01.03.2008 10:47 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\control.xml --------- 12818 22.02.2008 22:13 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\UsrPath.Inf --------- 49 22.02.2008 11:15 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\mso4BAB2.jpg --------- 35598 22.02.2008 11:09 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\msoF47DD.jpg --------- 65048 15.02.2008 11:16 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla1E.tmp --------- 0 15.02.2008 11:15 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla1D.tmp --------- 0 15.02.2008 11:11 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla1C.tmp --------- 0 15.02.2008 11:11 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla1B.tmp --------- 0 15.02.2008 11:08 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla1A.tmp --------- 0 15.02.2008 11:07 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla19.tmp --------- 0 15.02.2008 11:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla18.tmp --------- 0 15.02.2008 11:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla17.tmp --------- 0 26.01.2008 14:22 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-6 --------- 0 13.01.2008 14:25 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{98DC1DE8-F5DD-4603-BF6A-878B3ED2BA0B} --------- 0 12.01.2008 17:24 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DF7433.tmp --------- 16384 12.01.2008 17:24 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\5806DIR.TMP --------- 0 12.01.2008 17:02 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DF227.tmp --------- 16384 12.01.2008 17:01 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DF7EBA.tmp --------- 16384 12.01.2008 17:00 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\1120DIR.TMP --------- 0 03.01.2008 12:04 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\PPT11.0 --------- 0 31.12.2007 14:53 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-5 --------- 0 31.12.2007 14:50 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-4 --------- 0 21.12.2007 14:54 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-3 --------- 0 07.12.2007 20:10 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR3.tmp --------- 0 05.12.2007 12:51 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-2 --------- 0 04.12.2007 12:44 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp-1 --------- 0 03.12.2007 21:37 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMP7.tmp --------- 0 19.11.2007 17:06 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\CWSysinfo.exe --------- 1254400 15.11.2007 21:29 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR11B.tmp --------- 0 14.11.2007 21:18 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR1.tmp --------- 0 10.11.2007 18:50 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\v --------- 0 03.11.2007 16:00 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\_is1.exe --------- 455600 01.11.2007 21:25 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMP160.tmp --------- 0 27.09.2007 10:54 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\plugtmp --------- 0 27.09.2007 10:52 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Grundriss.tif --------- 426002 20.09.2007 12:22 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Expos‚-Gesamt-Fax%2E%70%64%66.pdf --------- 2376921 17.09.2007 19:02 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DF94B6.tmp --------- 512 17.09.2007 19:02 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DF949B.tmp --------- 512 17.09.2007 18:27 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~WRD0000.doc --------- 573 17.09.2007 18:24 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DFD8A.tmp --------- 512 17.09.2007 18:22 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DF72F.tmp --------- 512 17.09.2007 18:17 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DFFB81.tmp --------- 512 17.09.2007 18:15 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DFCFCF.tmp --------- 512 17.09.2007 18:11 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DFC516.tmp --------- 512 17.09.2007 18:08 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DFBF1E.tmp --------- 512 17.09.2007 18:08 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~WRS1550.tmp --------- 51200 17.09.2007 18:03 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DFB2D4.tmp --------- 512 17.09.2007 17:56 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DFA3AC.tmp --------- 512 17.09.2007 17:53 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DF9360.tmp --------- 512 17.09.2007 17:47 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\~DF685D.tmp --------- 512 14.09.2007 12:30 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ACD2 --------- 0 14.09.2007 12:29 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ACD --------- 0 14.09.2007 12:29 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ACD1 --------- 0 18.08.2007 14:03 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ScanSoft --------- 0 10.08.2007 21:13 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\_ISTMP3.DIR --------- 0 07.07.2007 20:33 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Excel8.0 --------- 0 06.06.2007 21:01 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\a120.ini --------- 394 04.06.2007 18:48 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBRD.tmp --------- 0 31.05.2007 22:19 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WER436.tmp.dir00 --------- 0 31.05.2007 22:19 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WER436.tmp --------- 0 31.05.2007 21:09 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\_FeaturePhone_PCSuite.log --------- 5672374 31.05.2007 21:08 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\MSI40E.tmp --------- 45056 31.05.2007 20:47 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\35f2f4.mst --------- 78848 28.05.2007 20:37 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\MSI81fc4.LOG --------- 234252 15.05.2007 20:49 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WER1F9.tmp.dir00 --------- 0 15.05.2007 20:49 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WER1F9.tmp --------- 0 15.05.2007 20:49 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\7F3E2E.dmp --------- 0 15.05.2007 20:49 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WER1F8.tmp --------- 0 15.05.2007 20:49 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WER1F8.tmp.dir00 --------- 0 15.05.2007 20:12 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WER1ED.tmp.dir00 --------- 0 15.05.2007 20:12 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WER1ED.tmp --------- 0 15.04.2007 13:15 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\86973.mst --------- 53760 14.04.2007 22:54 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR50.tmp --------- 0 14.04.2007 22:20 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR6.tmp --------- 0 05.04.2007 22:02 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMPD.tmp --------- 0 23.03.2007 12:28 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBRA.tmp --------- 0 25.02.2007 23:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR63.tmp --------- 0 25.02.2007 22:57 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR5D.tmp --------- 0 25.02.2007 21:52 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR7.tmp --------- 0 24.02.2007 21:21 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\jinstall.cfg --------- 1156 24.02.2007 21:21 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\tmp-1.xpi --------- 94879 19.02.2007 11:05 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{7c21eee0-e6fd-11d4-bd19-00d0b702aec0} --------- 0 19.02.2007 11:04 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{efb7d050-cad2-11d4-b34d-00105a1c23dd} --------- 0 17.02.2007 22:19 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{806047C5-625E-493E-B527-870D54460C6C} --------- 0 06.02.2007 22:40 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\NBR28.tmp --------- 0 21.01.2007 13:39 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\appv6zs3.lnk --------- 0 20.01.2007 21:26 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Adobe --------- 0 15.01.2007 17:56 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMPC.tmp --------- 0 13.01.2007 14:25 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMP6.tmp --------- 0 27.12.2006 14:47 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla72.tmp --------- 0 27.12.2006 14:45 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla70.tmp --------- 0 27.12.2006 14:45 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla6D.tmp --------- 0 27.12.2006 14:44 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fla6A.tmp --------- 0 22.12.2006 14:54 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMPB.tmp --------- 0 11.12.2006 14:45 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\unwise.exe --------- 81920 11.12.2006 12:22 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\mgxlicense --------- 0 11.12.2006 12:22 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\mgxgroups --------- 0 18.11.2006 14:09 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ff_temp --------- 0 31.10.2006 19:57 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\sv7b3x1m.lnk --------- 0 30.10.2006 13:32 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMP5.tmp --------- 0 16.10.2006 11:23 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMP4.tmp --------- 0 15.10.2006 10:22 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Word8.0 --------- 0 18.09.2006 11:28 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ImageUploader_Temp --------- 0 18.09.2006 09:26 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\scw106.tmp --------- 603561 13.09.2006 13:19 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\mgxfonts.exe --------- 1146818 10.09.2006 13:11 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMPA.tmp --------- 0 14.08.2006 08:42 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\tmp.xpi --------- 1324838 13.08.2006 20:13 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\FlashPlayerUpdate.exe --------- 1134728 05.08.2006 17:46 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\TempFolder.aaa --------- 0 05.08.2006 17:45 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\TempFolder.aad --------- 0 24.07.2006 10:31 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMP17F.tmp --------- 0 24.07.2006 08:48 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WMP9D.tmp --------- 0 08.07.2006 13:19 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{cbe0fca1-4e95-11d4-9875-00105ace7734} --------- 0 29.04.2006 18:21 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\MS41.LOG --------- 3806 29.04.2006 18:15 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\59319.mst --------- 0 29.04.2006 18:15 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\59318.mst --------- 0 29.04.2006 18:15 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{85309D89-7BE9-4094-BB17-24999C6118FC} --------- 0 06.12.2005 15:10 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\set23.tmp --------- 107512 28.10.2005 17:09 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\GLF1BGLF1B.EXE --------- 138757 20.10.2005 14:19 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\_ISTMP2.DIR --------- 0 20.10.2005 14:16 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\_ISTMP1.DIR --------- 0 07.08.2005 11:57 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\5784DIR.TMP --------- 0 18.05.2005 12:00 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\Install.exe --------- 10841966 12.10.2004 12:14 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\InstHelp.dll --------- 57344 02.08.2004 21:03 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ginstall.dll --------- 55296 02.08.2004 21:00 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{C388D147-CCBA-411C-B9FC-2CC1B4EFB240} --------- 0 18.07.2004 12:56 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\16988DIR.TMP --------- 0 22.03.2004 10:01 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\{8711bc93-93f2-4fb1-8463-8e6c5cb53f36} --------- 0 21.03.2004 14:39 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\VBE --------- 0 15.03.2004 22:36 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\GRD$LOGFILE.LOG --------- 0 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\WZSE1.TMP --------- 0 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fepherc.bin.av --------- 192512 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fepdense.bin.av --------- 1941504 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fem556n5.sys.av --------- 22090 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fdc.sys.av --------- 26240 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fa410nd5.sys.av --------- 24618 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\fa312nd5.sys.av --------- 16074 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\f71rx503.ppd.av --------- 11877 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\f3ab18xi.sys.av --------- 12362 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\exp24res.dll.av --------- 24576 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\f3ab18xj.sys.av --------- 11850 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\exabyte2.sys.av --------- 7040 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ex10.sys.av --------- 16998 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\evpnt50p.chm.av --------- 11595 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\esuimg.dll.av --------- 34816 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\evpnt50i.chm.av --------- 11457 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\esunib.dll.av --------- 46080 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\esuni.dll.av --------- 46080 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\esucm.dll.av --------- 43008 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\essm2e.sys.av --------- 136960 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ess.sys.av --------- 63360 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\escriptf.ppd.av --------- 24187 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\escriptd.ppd.av --------- 25701 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\escripte.ppd.av --------- 23156 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\escript7.ppd.av --------- 15433 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\escriptb.ppd.av --------- 22754 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\escript8.ppd.av --------- 23522 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\escript6.ppd.av --------- 17569 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\escript4.ppd.av --------- 20511 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\escript5.ppd.av --------- 21131 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\escript2.ppd.av --------- 16587 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\escript3.ppd.av --------- 20490 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\es56tpi.sys.av --------- 347870 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\escript1.ppd.av --------- 16558 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\escp2res.dll.av --------- 6144 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\es56hpi.sys.av --------- 594558 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\es56cvmp.sys.av --------- 595999 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\es198x.sys.av --------- 174464 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\es1370mp.sys.av --------- 37120 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\es1371mp.sys.av --------- 40704 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\es1969.sys.av --------- 72192 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eqnlogr.exe.av --------- 52224 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eqnloop.exe.av --------- 62464 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eqn.sys.av --------- 629952 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eqndiag.exe.av --------- 53760 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi27.dxt.av --------- 177 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epx1050p.gpd.av --------- 23218 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi41.dxt.av --------- 337 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi37.dxt.av --------- 305 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi31.dxt.av --------- 288 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi29.dxt.av --------- 177 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi25.dxt.av --------- 272 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi23.dxt.av --------- 249 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi19.dxt.av --------- 241 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi17.dxt.av --------- 177 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi15.dxt.av --------- 175 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi11.dxt.av --------- 253 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi09.dxt.av --------- 176 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputbm10.wbf.av --------- 34318 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi07.dxt.av --------- 253 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi05.dxt.av --------- 172 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi03.dxt.av --------- 176 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputpi01.dxt.av --------- 237 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputbm09.wbf.av --------- 34318 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputbm07.wbf.av --------- 34318 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputbm08.wbf.av --------- 151078 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputbm06.wbf.av --------- 136678 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputbm05.wbf.av --------- 34318 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputbm03.wbf.av --------- 136678 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputbm02.wbf.av --------- 34318 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eputbm01.wbf.av --------- 34318 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ept750.gpd.av --------- 20642 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ept1000.gpd.av --------- 12553 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epstw2k.sys.av --------- 114944 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epst1000.gpd.av --------- 18688 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epst800p.gpd.av --------- 12557 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epst800.gpd.av --------- 13050 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epst400.gpd.av --------- 13050 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epst300.gpd.av --------- 13050 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epsq2500.gpd.av --------- 40173 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epsq870.gpd.av --------- 34847 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epsq850.gpd.av --------- 24234 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epsq2550.gpd.av --------- 40600 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epsq2000.gpd.av --------- 35061 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eprx80ft.gpd.av --------- 12566 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epsq1170.gpd.av --------- 64946 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eps1170s.gpd.av --------- 27649 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eprx80.gpd.av --------- 7570 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eprx100p.gpd.av --------- 19898 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eprx100.gpd.av --------- 14954 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epro4.sys.av --------- 18503 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epr80ftp.gpd.av --------- 16399 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnutx22.dll.av --------- 31744 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti71.dxt.av --------- 304 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnutia3.dxt.av --------- 400 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnutia1.dxt.av --------- 400 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti97.dxt.av --------- 323 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti81.dxt.av --------- 306 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti77.dxt.av --------- 304 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti63.dxt.av --------- 321 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti69.dxt.av --------- 321 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti67.dxt.av --------- 320 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti65.dxt.av --------- 306 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti53.dxt.av --------- 177 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti57.dxt.av --------- 320 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti55.dxt.av --------- 320 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti51.dxt.av --------- 306 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti49.dxt.av --------- 306 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnuti47.dxt.av --------- 177 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx2h.dll.av --------- 1147904 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx16.dll.av --------- 538624 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx15.dll.av --------- 620032 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx14.dll.av --------- 579584 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx13.dll.av --------- 539136 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx12.dll.av --------- 488448 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx11.dll.av --------- 539136 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx0a.dll.av --------- 347136 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx09.dll.av --------- 340992 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx07.dll.av --------- 414208 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx05.dll.av --------- 397824 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx04.dll.av --------- 368128 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx02.dll.av --------- 341504 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhtx01.dll.av --------- 334336 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte5d.dll.av --------- 1388032 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte5a.dll.av --------- 1246208 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte4s.dll.av --------- 1256448 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte4p.dll.av --------- 1068544 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte4n.dll.av --------- 1619968 |
15.07.2010, 14:13 | #7 |
/// Helfer-Team | AV Security Suite Antimalware- was noch?Code:
ATTFilter 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte4l.dll.av --------- 1489408 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte4k.dll.av --------- 2195968 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte4j.dll.av --------- 2057216 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte4i.dll.av --------- 1281536 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte4h.dll.av --------- 1181184 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte4g.dll.av --------- 1181184 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte4d.dll.av --------- 522752 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte4c.dll.av --------- 1081856 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte4b.dll.av --------- 1081856 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte4a.dll.av --------- 655360 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte3v.dll.av --------- 911360 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte3t.dll.av --------- 1740288 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte3q.dll.av --------- 1415168 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte3p.dll.av --------- 377344 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte3o.dll.av --------- 428544 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte3n.dll.av --------- 921088 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte2m.dll.av --------- 608768 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte2k.dll.av --------- 895488 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epnhte2j.dll.av --------- 1287680 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epngui40.dll.av --------- 62976 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epngui10.dll.av --------- 79872 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epngui30.dll.av --------- 59392 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epngui11.hlp.av --------- 14217 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx5d.gpd.av --------- 17884 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx5a.gpd.av --------- 17882 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx4s.gpd.av --------- 26023 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx4p.gpd.av --------- 17438 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx4k.gpd.av --------- 26115 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx4n.gpd.av --------- 18436 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx4l.gpd.av --------- 17357 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx4j.gpd.av --------- 23493 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx4d.gpd.av --------- 17056 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx4i.gpd.av --------- 18994 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx4h.gpd.av --------- 17420 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx4g.gpd.av --------- 17420 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx4c.gpd.av --------- 17363 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx4b.gpd.av --------- 17363 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx3q.gpd.av --------- 15711 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx4a.gpd.av --------- 16006 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx3v.gpd.av --------- 15709 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx3t.gpd.av --------- 17283 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx3p.gpd.av --------- 15372 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx3o.gpd.av --------- 15581 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx3n.gpd.av --------- 15713 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx2m.gpd.av --------- 9684 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx2k.gpd.av --------- 9660 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx16.gpd.av --------- 9353 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx2j.gpd.av --------- 10784 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx2h.gpd.av --------- 12823 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx19.gpd.av --------- 8176 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx18.gpd.av --------- 8010 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx12.gpd.av --------- 8891 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx15.gpd.av --------- 49360 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx14.gpd.av --------- 47645 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx13.gpd.av --------- 8927 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx0a.gpd.av --------- 7294 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx11.gpd.av --------- 9353 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx0m.gpd.av --------- 1163 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx08.gpd.av --------- 9419 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx09.gpd.av --------- 8176 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx06.gpd.av --------- 9419 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx05.gpd.av --------- 7612 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx04.gpd.av --------- 6864 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx03.gpd.av --------- 33278 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx02.gpd.av --------- 7693 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4s.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx01.gpd.av --------- 8010 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndvx00.gpd.av --------- 1158 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve5d.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve5d.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve5a.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve5a.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4s.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4p.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4p.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4n.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4n.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4l.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4i.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4l.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4k.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4k.gpd.av --------- 287 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4j.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4j.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4g.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4i.gpd.av --------- 287 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4h.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4h.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4g.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4d.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4d.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4c.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4c.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4b.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4b.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4a.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve4a.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve3v.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve3t.gpd.av --------- 287 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve3v.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve3t.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve3q.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve3q.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve3p.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve2m.gpd.av --------- 167 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve3p.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve3o.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve3o.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve3n.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve3n.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve2m.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve19.gpd.av --------- 161 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve2k.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve2k.gpd.av --------- 167 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve2j.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve2j.gpd.av --------- 166 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve2h.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve2h.gpd.av --------- 166 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve15.gpd.av --------- 168 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve18.gpd.av --------- 161 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve17.gpd.av --------- 155 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve16.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve16.gpd.av --------- 167 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve15.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve12.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve14.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve14.gpd.av --------- 168 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve13.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve13.gpd.av --------- 163 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve12.gpd.av --------- 167 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve11.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve11.gpd.av --------- 167 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve0a.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve0a.gpd.av --------- 167 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve09.gpd.av --------- 167 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve09.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve05.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve08.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve08.gpd.av --------- 165 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve06.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve06.gpd.av --------- 164 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve03.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve05.gpd.av --------- 161 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve04.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve04.gpd.av --------- 163 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve03.gpd.av --------- 162 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve02.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve02.gpd.av --------- 166 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve01.gpd.av --------- 167 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndve01.ini.av --------- 122 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde5d.cfg.av --------- 8616 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndva5d.gpd.av --------- 286 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndrv01.dll.av --------- 13312 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde5d.dat.av --------- 3628 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4p.cfg.av --------- 7498 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde5a.dat.av --------- 3138 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde5a.cfg.av --------- 8444 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4s.dat.av --------- 2496 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4s.cfg.av --------- 4488 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4p.dat.av --------- 3476 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4l.dat.av --------- 3476 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4n.dat.av --------- 3696 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4n.cfg.av --------- 8444 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4k.cfg.av --------- 9562 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4l.cfg.av --------- 7498 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4k.dat.av --------- 4338 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4j.dat.av --------- 4118 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4j.cfg.av --------- 8616 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4i.dat.av --------- 3626 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4i.cfg.av --------- 8616 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4h.dat.av --------- 3406 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4h.cfg.av --------- 7670 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4d.dat.av --------- 2632 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4g.dat.av --------- 3406 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4g.cfg.av --------- 7670 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4d.cfg.av --------- 6982 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4c.dat.av --------- 3476 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4c.cfg.av --------- 7498 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4a.cfg.av --------- 7670 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4b.dat.av --------- 3476 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4b.cfg.av --------- 7498 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde4a.dat.av --------- 2984 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde3v.dat.av --------- 2188 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde3p.dat.av --------- 1764 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde3v.cfg.av --------- 3248 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde3t.dat.av --------- 2618 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde3t.cfg.av --------- 3908 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde3q.dat.av --------- 2398 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde3q.cfg.av --------- 3446 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde2m.dat.av --------- 2128 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde3p.cfg.av --------- 2918 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde3o.dat.av --------- 1976 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde3o.cfg.av --------- 3314 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde3n.dat.av --------- 2398 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde3n.cfg.av --------- 3182 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde2h.dat.av --------- 2146 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde2m.cfg.av --------- 3440 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde2k.dat.av --------- 1948 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde2k.cfg.av --------- 3694 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde2j.dat.av --------- 1992 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde2j.cfg.av --------- 4128 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde2h.cfg.av --------- 4000 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde16.dat.av --------- 1960 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde15.dat.av --------- 4736 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde16.cfg.av --------- 3440 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde13.dat.av --------- 1838 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde15.cfg.av --------- 4370 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde14.dat.av --------- 4664 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde14.cfg.av --------- 4370 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde11.cfg.av --------- 3440 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde13.cfg.av --------- 3506 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde12.dat.av --------- 1778 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde12.cfg.av --------- 3068 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde11.dat.av --------- 1960 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde0a.dat.av --------- 1468 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde0a.cfg.av --------- 2694 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde09.dat.av --------- 1162 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde09.cfg.av --------- 2136 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde08.dat.av --------- 1598 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde08.cfg.av --------- 2694 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde04.cfg.av --------- 2134 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde06.dat.av --------- 1598 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde06.cfg.av --------- 2692 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde05.dat.av --------- 1454 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde05.cfg.av --------- 2692 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde04.dat.av --------- 1226 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde01.cfg.av --------- 1576 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde03.dat.av --------- 3360 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde03.cfg.av --------- 2196 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde02.dat.av --------- 1366 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde02.cfg.av --------- 2382 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epndde01.dat.av --------- 1102 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epn4000p.gpd.av --------- 48252 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epn4000.gpd.av --------- 47215 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epn2750.gpd.av --------- 46656 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epn2700.gpd.av --------- 46843 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epn2050.gpd.av --------- 39609 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epn1600.gpd.av --------- 31836 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epn2000.gpd.av --------- 27447 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplx86.gpd.av --------- 16904 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epn1200.gpd.av --------- 26523 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epmx80ft.gpd.av --------- 11360 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epmx80.gpd.av --------- 6880 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epmx100.gpd.av --------- 13468 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplx850.gpd.av --------- 16423 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplx850p.gpd.av --------- 16425 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplx80.gpd.av --------- 16814 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplx810.gpd.av --------- 11760 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplx800.gpd.av --------- 16423 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplx400.gpd.av --------- 12591 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplx300p.gpd.av --------- 22434 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplx300.gpd.av --------- 12610 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplx1050.gpd.av --------- 19927 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplx100.gpd.av --------- 16423 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplvcd07.gpd.av --------- 156698 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplvcd08.gpd.av --------- 158523 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplvcd06.gpd.av --------- 155652 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplvcd05.gpd.av --------- 157983 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplvcd00.dll.av --------- 113152 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplvcd00.ini.av --------- 107 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq870.gpd.av --------- 34895 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplrcz00.dll.av --------- 97792 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq950.gpd.av --------- 25024 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq670.gpd.av --------- 22219 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq800.gpd.av --------- 19688 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq680p.gpd.av --------- 22251 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq680.gpd.av --------- 22247 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq580.gpd.av --------- 20288 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq570p.gpd.av --------- 34887 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq570e.gpd.av --------- 19827 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq570.gpd.av --------- 36872 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq560.gpd.av --------- 17865 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq300.gpd.av --------- 42669 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq2180.gpd.av --------- 25865 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq2550.gpd.av --------- 22595 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq2170.gpd.av --------- 25865 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq1170.gpd.av --------- 33895 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq2080.gpd.av --------- 25865 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq2070.gpd.av --------- 25865 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq150.gpd.av --------- 38401 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq1010.gpd.av --------- 24312 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq1070.gpd.av --------- 33769 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq1000.gpd.av --------- 40744 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplq100.gpd.av --------- 12577 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epln400p.ppd.av --------- 93696 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epln4000.ppd.av --------- 73306 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epln2750.ppd.av --------- 112925 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epln2050.ppd.av --------- 102717 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epln2700.ppd.av --------- 74210 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epl750.gpd.av --------- 40477 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\eplc8200.ppd.av --------- 63599 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epl870s.gpd.av --------- 24370 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epl75523.ppd.av --------- 12684 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epl3kf51.ppd.av --------- 18694 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epl5800.ppd.av --------- 42812 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epl3kf21.ppd.av --------- 14967 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epl105x.gpd.av --------- 41245 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epl1050p.gpd.av --------- 276 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epgq3500.gpd.av --------- 25469 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epl1050.gpd.av --------- 274 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epl1000.gpd.av --------- 24986 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epjx80.gpd.av --------- 17567 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx980.gpd.av --------- 21459 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx880.gpd.av --------- 30913 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx870.gpd.av --------- 21341 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx86e.gpd.av --------- 17098 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx850.gpd.av --------- 20471 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx800.gpd.av --------- 11700 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx85.gpd.av --------- 16913 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx80p.gpd.av --------- 16409 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx80.gpd.av --------- 16404 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx286.gpd.av --------- 20417 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx286e.gpd.av --------- 20602 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx2170.gpd.av --------- 25085 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx2180.gpd.av --------- 48551 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx185.gpd.av --------- 20417 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx1180.gpd.av --------- 48651 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx1170.gpd.av --------- 29321 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx100.gpd.av --------- 19908 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx1050.gpd.av --------- 25085 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx105.gpd.av --------- 20417 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx100p.gpd.av --------- 19913 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epfx1000.gpd.av --------- 20143 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epe6000.gpd.av --------- 25305 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epex800.gpd.av --------- 18225 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epex1000.gpd.av --------- 26671 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epe7100.gpd.av --------- 22418 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epe7000.gpd.av --------- 25263 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epdq3xxx.gpd.av --------- 18041 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epe5000.gpd.av --------- 24277 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epe4100.gpd.av --------- 23973 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epe4000.gpd.av --------- 23964 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epd8000.gpd.av --------- 8953 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epdq3000.gpd.av --------- 249 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epdf8500.gpd.av --------- 21500 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epd3000p.gpd.av --------- 266 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epd5000p.gpd.av --------- 8689 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epd5000.gpd.av --------- 8679 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epcomp9.gpd.av --------- 16435 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epcomp24.gpd.av --------- 41411 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epcl5ui.ini.av --------- 42 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epcl5ui.dll.av --------- 9728 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epcfw2k.sys.av --------- 144896 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epcl5res.dll.av --------- 120832 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epap5500.gpd.av --------- 64946 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epap5000.gpd.av --------- 35047 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epap3260.gpd.av --------- 38365 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epap4500.gpd.av --------- 32914 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epap4000.gpd.av --------- 20377 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epap3300.gpd.av --------- 42633 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epap2500.gpd.av --------- 19937 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epap3250.gpd.av --------- 12542 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epap3000.gpd.av --------- 19446 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epap2250.gpd.av --------- 16387 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epap2000.gpd.av --------- 16435 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epalpls.gpd.av --------- 24677 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epalc850.ppd.av --------- 61384 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epalc200.ppd.av --------- 50491 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epal2.gpd.av --------- 23968 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epal1500.gpd.av --------- 26209 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epal1600.gpd.av --------- 27158 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epal1400.gpd.av --------- 21346 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epa5500p.gpd.av --------- 64947 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epal1100.gpd.av --------- 23679 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epal1000.gpd.av --------- 24328 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep9res.dll.av --------- 36864 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\epa5000p.gpd.av --------- 35048 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep870sf.gpd.av --------- 17883 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep9bres.dll.av --------- 38400 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep9000.gpd.av --------- 30995 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep860p.gpd.av --------- 26624 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep860.gpd.av --------- 26192 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep85x.gpd.av --------- 24919 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep850p.gpd.av --------- 422 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep850.gpd.av --------- 250 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep826051.ppd.av --------- 12557 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep8100.gpd.av --------- 24129 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep5800.gpd.av --------- 29015 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep8000.gpd.av --------- 24129 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep5xx.gpd.av --------- 20191 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep5500.gpd.av --------- 22486 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep570sf.gpd.av --------- 24408 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep5700.gpd.av --------- 28736 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep5600.gpd.av --------- 29067 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep5500sf.gpd.av --------- 40381 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep550.gpd.av --------- 271 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep5200ps.gpd.av --------- 25398 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep5200.gpd.av --------- 25193 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep510.gpd.av --------- 271 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep5000sf.gpd.av --------- 24372 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep4200.gpd.av --------- 23512 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep500.gpd.av --------- 19689 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep450.gpd.av --------- 19580 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep4300.gpd.av --------- 23512 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep2bres.dll.av --------- 64512 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep400.gpd.av --------- 19538 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep3325sf.gpd.av --------- 16699 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep3000.gpd.av --------- 22482 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep2000.gpd.av --------- 41800 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep2500.gpd.av --------- 41847 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep24res.dll.av --------- 26624 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep1500.gpd.av --------- 34622 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep200.gpd.av --------- 19406 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep1170sf.gpd.av --------- 40419 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep1070sf.gpd.av --------- 40419 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep1070p.gpd.av --------- 34220 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep106x.gpd.av --------- 42415 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep100sf.gpd.av --------- 16735 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep1060p.gpd.av --------- 274 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ep1060.gpd.av --------- 277 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\emu10k1m.sys.av --------- 283904 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\enum1394.sys.av --------- 6400 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\em556n4.sys.av --------- 19996 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\elnk3.sys.av --------- 25159 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\elmsmc.sys.av --------- 7296 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el99xn51.sys.av --------- 176128 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el99xrun.out.av --------- 60096 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el98xn5.sys.av --------- 70174 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el985n51.sys.av --------- 455711 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el90xnd5.sys.av --------- 153631 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el90xbc5.sys.av --------- 66591 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el656se5.sys.av --------- 241270 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el656ct5.sys.av --------- 634198 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el656nd5.sys.av --------- 77386 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el656cd5.sys.av --------- 69194 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el589nd5.sys.av --------- 26141 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el575nd5.sys.av --------- 69692 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el574nd4.sys.av --------- 24653 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efxjx503.ppd.av --------- 48856 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el556nd5.sys.av --------- 55999 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\el515.sys.av --------- 44103 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efxjx303.ppd.av --------- 41536 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efxjx404.ppd.av --------- 47534 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efxjx403.ppd.av --------- 40677 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efxjx203.ppd.av --------- 41548 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efsix303.ppd.av --------- 32830 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efsix503.ppd.av --------- 65121 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efsix203.ppd.av --------- 32843 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efnc9a10.ppd.av --------- 149023 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efnc9010.ppd.av --------- 149045 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efnc6e10.ppd.av --------- 180851 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efnc6b10.ppd.av --------- 137210 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efnc6c10.ppd.av --------- 137178 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efnc6010.ppd.av --------- 180887 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efnc5e10.ppd.av --------- 143671 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efnc5c10.ppd.av --------- 138455 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efnc5b10.ppd.av --------- 138487 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efnc5010.ppd.av --------- 143634 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efmc6b30.ppd.av --------- 117181 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efmc7b10.ppd.av --------- 86847 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efmc7a10.ppd.av --------- 86864 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efmc6b20.ppd.av --------- 113941 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efmc6b10.ppd.av --------- 109782 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efmc6a30.ppd.av --------- 117205 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efmc6a20.ppd.av --------- 113961 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efmc6a10.ppd.av --------- 109786 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efmc5b20.ppd.av --------- 70382 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efmc5020.ppd.av --------- 70386 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efac4d10.ppd.av --------- 144910 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\efac4b10.ppd.av --------- 144942 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ef3c6u10.ppd.av --------- 115330 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ef3c6e10.ppd.av --------- 115290 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ef3c6c10.ppd.av --------- 137248 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ef3c6b10.ppd.av --------- 137284 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ee510__1.icm.av --------- 216736 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ee508__1.icm.av --------- 216736 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ee504__1.icm.av --------- 216832 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ee501__1.icm.av --------- 216824 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ee129__1.icm.av --------- 216888 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ee127__1.icm.av --------- 216888 15.03.2004 22:34 C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\ee119__1.icm.av --------- 216888 ---------------------------------------- C:\Programme 12.07.2010 22:59 C:\Programme\Malwarebytes' Anti-Malware --------- 0 12.07.2010 14:43 C:\Programme\Mozilla Firefox --------- 0 21.05.2010 21:18 C:\Programme\Outlook Express --------- 0 26.04.2010 09:52 C:\Programme\Lavasoft --------- 0 14.04.2010 21:15 C:\Programme\WISO --------- 0 14.04.2010 21:15 C:\Programme\InstallShield Installation Information --------- 0 19.03.2010 17:30 C:\Programme\kikin --------- 0 10.03.2010 21:26 C:\Programme\Movie Maker --------- 0 11.02.2010 11:23 C:\Programme\iTunes --------- 0 11.02.2010 11:22 C:\Programme\iPod --------- 0 11.02.2010 11:18 C:\Programme\QuickTime --------- 0 12.09.2009 12:42 C:\Programme\Mozilla Thunderbird --------- 0 01.09.2009 11:10 C:\Programme\Audiograbber --------- 0 17.08.2009 23:01 C:\Programme\MSBuild --------- 0 17.08.2009 23:01 C:\Programme\Reference Assemblies --------- 0 17.08.2009 22:56 C:\Programme\Internet Explorer --------- 0 18.05.2009 13:48 C:\Programme\Bonjour --------- 0 03.04.2009 20:32 C:\Programme\Tools&More --------- 0 30.03.2009 10:22 C:\Programme\FileZilla FTP Client --------- 0 23.03.2009 10:30 C:\Programme\Avira --------- 0 23.03.2009 10:25 C:\Programme\AntiVir PersonalEdition Classic --------- 0 22.03.2009 22:51 C:\Programme\Jalbum8.1 --------- 0 14.01.2009 21:45 C:\Programme\Dell --------- 0 12.01.2009 13:18 C:\Programme\Messenger --------- 0 12.01.2009 12:58 C:\Programme\MSXML 4.0 --------- 0 25.12.2008 12:13 C:\Programme\Apple Software Update --------- 0 25.12.2008 12:11 C:\Programme\Gemeinsame Dateien --------- 0 23.12.2008 10:32 C:\Programme\Alcohol 120 --------- 0 19.12.2008 16:53 C:\Programme\msn --------- 0 19.12.2008 16:43 C:\Programme\NetMeeting --------- 0 19.12.2008 16:43 C:\Programme\Windows Media Player --------- 0 19.12.2008 16:43 C:\Programme\Windows NT --------- 0 21.11.2008 20:12 C:\Programme\IKEA HomePlanner --------- 0 27.07.2008 15:05 C:\Programme\dm --------- 0 26.11.2007 13:00 C:\Programme\CeWe Color --------- 0 15.09.2007 13:24 C:\Programme\Xing --------- 0 14.09.2007 12:35 C:\Programme\LameFE --------- 0 10.08.2007 21:03 C:\Programme\NetObjects --------- 0 06.06.2007 21:00 C:\Programme\SlySoft --------- 0 31.05.2007 20:52 C:\Programme\Sony Ericsson --------- 0 22.01.2007 11:22 C:\Programme\Rising Research --------- 0 20.01.2007 14:23 C:\Programme\Ad-aware 6 --------- 0 14.01.2007 15:16 C:\Programme\VideoLAN --------- 0 29.11.2006 22:05 C:\Programme\Intelore --------- 0 11.10.2006 20:14 C:\Programme\Adobe --------- 0 17.07.2006 15:29 C:\Programme\VectorWorks ArLa D1-10.1.0 --------- 0 26.06.2006 12:16 C:\Programme\AVPersonal --------- 0 29.04.2006 18:17 C:\Programme\ScanSoft --------- 0 29.04.2006 18:15 C:\Programme\ArcSoft --------- 0 29.04.2006 18:13 C:\Programme\Canon --------- 0 10.12.2005 22:35 C:\Programme\Ahead --------- 0 10.12.2005 22:34 C:\Programme\Nero --------- 0 16.02.2005 21:41 C:\Programme\ACD Systems --------- 0 15.03.2004 21:41 C:\Programme\CoolSky --------- 0 17.02.2004 21:35 C:\Programme\WinRAR --------- 0 15.02.2004 21:49 C:\Programme\Tsunami-Filter-Pack --------- 0 15.02.2004 21:49 C:\Programme\Avisynth --------- 0 15.02.2004 21:49 C:\Programme\VirtualDub --------- 0 25.01.2004 14:21 C:\Programme\Morgan --------- 0 21.10.2003 10:50 C:\Programme\phase5 --------- 0 29.09.2003 23:49 C:\Programme\Ubi Soft --------- 0 29.09.2003 21:35 C:\Programme\WindowsUpdate --------- 0 27.09.2003 13:49 C:\Programme\WS_FTP --------- 0 16.06.2003 17:49 C:\Programme\XEROX --------- 0 12.04.2003 14:32 C:\Programme\Corel --------- 0 18.03.2003 21:17 C:\Programme\Agfa --------- 0 03.03.2003 15:29 C:\Programme\CONEXANT --------- 0 03.03.2003 14:28 C:\Programme\WinZip --------- 0 03.03.2003 09:39 C:\Programme\Nemetschek --------- 0 27.02.2003 14:51 C:\Programme\Microsoft Office --------- 0 18.02.2003 22:17 C:\Programme\Norton AntiVirus --------- 0 18.02.2003 22:15 C:\Programme\Intel --------- 0 18.02.2003 22:15 C:\Programme\Digital Line Detect --------- 0 18.02.2003 22:14 C:\Programme\Modem Helper --------- 0 18.02.2003 21:47 C:\Programme\Uninstall Information --------- 0 18.02.2003 21:47 C:\Programme\microsoft frontpage --------- 0 18.02.2003 21:47 C:\Programme\MSN Gaming Zone --------- 0 ---------------------------------------- C:\Dokumente und Einstellungen\All Users.WINDOWS\.. NetworkService.NT-AUTORITŽT.000 LocalService.NT-AUTORITŽT.000 Marie.BALOU Andreas MARIE~1~BAL Default User.WINDOWS All Users.WINDOWS LocalService.NT-AUTORITŽT NetworkService.NT-AUTORITŽT Marie All Users Default User NetworkService LocalService ---------------------------------------- C:\WINDOWS\system32\drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 localhost ---------------------------------------- Abbildname PID Sitzungsname Sitz.-Nr. Speichernutzung ========================= ===== ================ ========== =============== System Idle Process 0 0 16 K System 4 0 208 K smss.exe 200 0 400 K csrss.exe 260 0 3.296 K winlogon.exe 284 0 2.264 K services.exe 328 0 3.188 K lsass.exe 340 0 1.336 K svchost.exe 496 0 3.396 K svchost.exe 556 0 4.120 K svchost.exe 616 0 9.904 K explorer.exe 876 0 24.372 K cmd.exe 1468 0 2.276 K tasklist.exe 1664 0 4.204 K wmiprvse.exe 1692 0 5.676 K ***** Ende des Scans 15.07.2010 um 9:10:28,29 *** |
15.07.2010, 14:14 | #8 |
/// Helfer-Team | AV Security Suite Antimalware- was noch?Code:
ATTFilter Ad-Aware Lavasoft Ad-Aware Email Scanner for Outlook Lavasoft 1.0.0 Adaptec USB CardBus Manager Adobe Flash Player 10 Plugin Adobe Systems Incorporated 10.0.22.87 Adobe Flash Player 9 ActiveX Adobe Systems 9 Adobe InDesign 1.5 Adobe Systems, Inc. 1.5 Adobe InDesign 2.0 Adobe Systems, Inc. 2.0 Adobe Photoshop 7.0 Adobe Systems, Inc. 7.0 Adobe Reader 7.0.8 - Deutsch Adobe Systems Incorporated 7.0.8 Adobe SVG Viewer 3.0 Adobe Systems, Inc. 3.0 Apple Application Support Apple Inc. 1.1.0 Apple Mobile Device Support Apple Inc. 2.6.0.32 Apple Software Update Apple Inc. 2.1.1.116 ArcSoft PhotoStudio 5.5 ArcSoft Audiograbber 1.83 SE Audiograbber Deutschland 1.83 SE Audiograbber Lame-MP3-Plugin AG 1.0 Avira AntiVir Personal - Free Antivirus Avira GmbH 10.0.0.561 Bonjour Apple Inc. 1.0.106 Canon MP Navigator 2.0 Canon MP500 Canon Utilities Easy-PhotoPrint CCleaner Piriform 2.33 CD-LabelPrint Conexant D480 MDC V.92 Modem Corel Applications Digital Video Repair 1.0 dm Fotowelt Easy-WebPrint EPSON Printer Software FileZilla Client 3.2.3.1 3.2.3.1 FreeDoko 0.7.5 Borg Enders und Diether Knof 0.7.5 Hardlock Device Driver HijackThis 2.0.2 TrendMicro 2.0.2 IKEA Home Planner IKEA IT 1.9.7 iTunes Apple Inc. 9.0.3.15 Jalbum 8.1 Joe Wirth New Media Sarl 3.05.0100 kikin Plugin (AudioGrabber Edition) 2.0 kikin 2.0 Logitech MouseWare 9.42 .1 Malwarebytes' Anti-Malware Malwarebytes Corporation Mein CeWe Fotobuch Meine CeWe Fotowelt Microsoft .NET Framework 2.0 Service Pack 2 Microsoft Corporation 2.2.30729 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft Corporation 3.2.30729 Microsoft .NET Framework 3.5 SP1 Microsoft Corporation Microsoft Office XP Professional mit FrontPage Microsoft Corporation 10.0.2701.0 Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 8.0.56336 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 9.0.30729.4148 Morgan Stream Switcher Mozilla Firefox (3.0.6) Mozilla 3.0.6 (de) Mozilla Thunderbird (2.0.0.21) Mozilla 2.0.0.21 (de) MSXML 4.0 SP2 (KB954430) Microsoft Corporation 4.20.9870.0 MSXML 4.0 SP2 (KB973688) Microsoft Corporation 4.20.9876.0 Nemetschek Allplan FT V17 Nero 6 Ultra Edition NVIDIA Windows 2000/XP Display Drivers OmniPage SE ScanSoft, Inc. 2.00.0004 PlanDesign FT V 3.0a Nemetschek AG 3.00.1000 QuickTime Apple Inc. 7.65.17.80 Sony Ericsson PC Suite Sony Ericsson 2.0.60 Toolbar fuer eBay Tsunami-Filter-Pack 3.8.8 VectorWorks ArchLand D1-10.1.0 VideoLAN VLC media player 0.8.6a VideoLAN Team 0.8.6a Windows Genuine Advantage Validation Tool (KB892130) Microsoft Corporation Windows XP Service Pack 3 Microsoft Corporation 20080414.031514 WinRAR Archivierer WinZip WinZip Computing, Inc. 8.1 SR-1 (5266g) WISO Sparbuch 2004 On4U WISO Sparbuch 2010 Buhl Data Service GmbH 17.00.6531 Xerox Phaser 7700 |
15.07.2010, 14:15 | #9 | |
/// Helfer-Team | AV Security Suite Antimalware- was noch? hi... Die Ergebnisse kannst Du da geteilt auch reinkopieren 1. Um einen tieferen Einblick in dein System, um eine mögliche Infektion mit einem Rootkit/Info v.wikipedia.org) aufzuspüren, werden wir ein Tool - Gmer - einsetzen :
** keine Verbindung zu einem Netzwerk und Internet - WLAN nicht vergessen Wenn der Scan beendet ist, bitte alle Programme und Tools wieder aktivieren! Achtung!: WENN GMER NICHT AUSGEFÜHRT WERDEN KANN ODER PROBMLEME VERURSACHT, fahre mit dem nächsten Punkt fort! - Es ist NICHT sinnvoll einen zweiten Versuch zu starten 2. Lade und installiere das Tool RootRepeal herunter
3. Code:
ATTFilter BearShare Zitat:
4. Schliesse alle Programme einschliesslich Internet Explorer und fixe mit Hijackthis die Einträge aus der nachfolgenden Codebox (HijackThis starten→ "Do a system scan only"→ Einträge auswählen→ Häckhen setzen→ "Fix checked" klicken→ PC neu aufstarten): HijackThis erstellt ein Backup, Falls bei "Fixen" etwas schief geht, kann man unter "View the list of backups"- die Objekte wiederherstellen Code:
ATTFilter O4 - HKLM\..\Run: [BearShare] "C:\Programme\BearShare\BearShare.exe" /pause → besuche die Seite von virustotal und die Datei/en aus Codebox bitte prüfen lassen - inklusive Dateigröße und Name, MD5 und SHA1 auch mitkopieren: → Tipps für die Suche nach Dateien Code:
ATTFilter C:\Dokumente und Einstellungen\Marie.BALOU\Lokale Einstellungen\Anwendungsdaten\nuvcaykvs\essdlwctssd.exe C:\Dokumente und Einstellungen\Marie.BALOU\Anwendungsdaten\Uculym\ylags.exe C:\WINDOWS\kbuipmsd.dll C:\WINDOWS\eyalutiholurac.dll C:\WINDOWS\udecahex.dll C:\WINDOWS\ewipihax.dll C:\WINDOWS\apukatiyuwaxo.dll C:\WINDOWS\efibebax.dll C:\WINDOWS\igiyovox.dll C:\WINDOWS\izecoqaf.dll C:\WINDOWS\eqawinaqa.dll C:\WINDOWS\ayiyiyim.dll → Suche die Datei auf deinem Rechner→ Doppelklick auf die zu prüfende Datei (oder kopiere den Inhalt ab aus der Codebox) → "Senden der Datei" und Warte, bis der Scandurchlauf aller Virenscanner beendet ist → das Ergebnis wie Du es bekommst (NICHT AUSLASSEN!) da reinkoperen (inklusive <geprüfter Dateiname> + Dateigröße und Name, MD5 und SHA1) ** Beispiel - das zu postende Logfile von Virustotal soll so wie hier aussehen Also nicht auslassen, sondern wie Du es bekommst da reinkopieren!: Code:
ATTFilter Datei <hier kommt die Dateiname> empfangen 2009.xx.xx xx:xx:xx (CET) Antivirus Version letzte aktualisierung Ergebnis a-squared 4.0.0.73 2009.01.28 - AhnLab-V3 5.0.0.2 2009.01.28 - AntiVir 7.9.0.60 2009.01.28 - Authentium 5.1.0.4 2009.01.27 - ...über 40 Virenscannern...also Geduld!! Geändert von kira (15.07.2010 um 14:27 Uhr) |
15.07.2010, 20:16 | #10 |
| AV Security Suite Antimalware- was noch?Code:
ATTFilter File yahoo_1_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set |
15.07.2010, 20:34 | #11 |
| AV Security Suite Antimalware- was noch? Hallo, hier wieder alle Infos: 1. Gmer GMER Logfile: GMER Logfile: Code:
ATTFilter GMER 1.0.15.15281 - hxxp://www.gmer.net Rootkit scan 2010-07-15 20:45:53 Windows 5.1.2600 Service Pack 3 Running: gmer.exe; Driver: C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\pxtdqpog.sys ---- System - GMER 1.0.15 ---- SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF885687E] SSDT sptd.sys ZwEnumerateKey [0xF870484C] SSDT sptd.sys ZwEnumerateValueKey [0xF8704BEC] SSDT sptd.sys ZwOpenKey [0xF86FF090] SSDT sptd.sys ZwQueryKey [0xF8704CC4] SSDT sptd.sys ZwQueryValueKey [0xF8704B44] SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF8856BFE] ---- Kernel code sections - GMER 1.0.15 ---- ? jcwwarnm.sys Das System kann die angegebene Datei nicht finden. ! ? C:\WINDOWS\system32\drivers\sptd.sys Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird. .text C:\WINDOWS\System32\DRIVERS\nv4_mini.sys section is writeable [0xF7DE3340, 0xFD01F, 0xF8000020] .text USBPORT.SYS!DllUnload F7DC38AC 5 Bytes JMP 831FB960 .text C:\WINDOWS\System32\drivers\SSHDRV86.sys section is writeable [0xF69D3000, 0x26354, 0xE8000020] .pklstb C:\WINDOWS\System32\drivers\SSHDRV86.sys entry point in ".pklstb" section [0xF6A08000] .relo2 C:\WINDOWS\System32\drivers\SSHDRV86.sys unknown last section [0xF6A1F000, 0x8E, 0x42000040] .text C:\WINDOWS\System32\nv4_disp.dll section is writeable [0xBF012300, 0x235FC0, 0xF8000020] .text C:\WINDOWS\System32\drivers\hardlock.sys section is writeable [0xF41B8400, 0x4C904, 0xE0000020] .protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".p" section [0xF421CA20] C:\WINDOWS\System32\drivers\hardlock.sys entry point in ".protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".p" section [0xF421CA20] .protectÿÿÿÿhardlockunknown last code section [0xF421C800, 0x548B, 0xE0000020] C:\WINDOWS\System32\drivers\hardlock.sys unknown last code section [0xF421C800, 0x548B, 0xE0000020] .text C:\WINDOWS\System32\DRIVERS\litsgt.sys section is writeable [0xF4172300, 0x1F510, 0xE8000020] ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!IoConnectInterrupt] [F8713580] sptd.sys IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F871352C] sptd.sys IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F872DAB8] sptd.sys IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F8713580] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F86FFABA] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F86FFC00] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F86FFB82] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F870072E] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F8700604] sptd.sys IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F8712B9A] sptd.sys ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 833661D8 Device \FileSystem\Fastfat \FatCdrom 83177600 Device \Driver\usbuhci \Device\USBPDO-0 831FA1D8 Device \Driver\dmio \Device\DmControl\DmIoDaemon 833D51D8 Device \Driver\dmio \Device\DmControl\DmConfig 833D51D8 Device \Driver\dmio \Device\DmControl\DmPnP 833D51D8 Device \Driver\dmio \Device\DmControl\DmInfo 833D51D8 Device \Driver\usbuhci \Device\USBPDO-1 831FA1D8 Device \Driver\NetBT \Device\NetBT_Tcpip_{C6F9D222-67B7-4520-9E86-F604831D9E73} 83147980 Device \Driver\Ftdisk \Device\HarddiskVolume1 833681D8 Device \Driver\Ftdisk \Device\HarddiskVolume2 833681D8 Device \Driver\Cdrom \Device\CdRom0 83104980 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F8634B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort0 [F8634B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [F8634B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F8634B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\NetBT \Device\NetBt_Wins_Export 83147980 Device \Driver\NetBT \Device\NetbiosSmb 83147980 Device \Driver\usbuhci \Device\USBFDO-0 831FA1D8 Device \Driver\usbuhci \Device\USBFDO-1 831FA1D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8309E8E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 8309E8E8 Device \Driver\Ftdisk \Device\FtControl 833681D8 Device \FileSystem\Fastfat \Fat 83177600 AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) Device \FileSystem\Cdfs \Cdfs 82F7E378 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 -146420503 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 -916502386 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xA9 0x02 0xA8 0x4A ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xA9 0x02 0xA8 0x4A ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Programme\Alcohol 120\ Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xA9 0x02 0xA8 0x4A ... ---- EOF - GMER 1.0.15 ---- --- --- --- [/code] 2. rootrepeal hidden Code:
ATTFilter ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2010/07/15 21:03 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ------------------- Name: 00000099 Image Path: \Driver\00000099 Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Name: ac97intc.sys Image Path: C:\WINDOWS\system32\drivers\ac97intc.sys Address: 0xF7D2D000 Size: 96256 File Visible: - Signed: - Status: - Name: ACPI.sys Image Path: ACPI.sys Address: 0xF86B7000 Size: 188800 File Visible: - Signed: - Status: - Name: ACPI_HAL Image Path: \Driver\ACPI_HAL Address: 0x804D7000 Size: 2192256 File Visible: - Signed: - Status: - Name: ACPIEC.sys Image Path: ACPIEC.sys Address: 0xF8C12000 Size: 12160 File Visible: - Signed: - Status: - Name: afd.sys Image Path: C:\WINDOWS\System32\drivers\afd.sys Address: 0xF68FC000 Size: 138496 File Visible: - Signed: - Status: - Name: agp440.sys Image Path: agp440.sys Address: 0xF8866000 Size: 42368 File Visible: - Signed: - Status: - Name: ASPI32.SYS Image Path: C:\WINDOWS\System32\Drivers\ASPI32.SYS Address: 0xF8BCE000 Size: 16512 File Visible: - Signed: - Status: - Name: atapi.sys Image Path: atapi.sys Address: 0xF862B000 Size: 98304 File Visible: - Signed: - Status: - Name: atapi.sys Image Path: atapi.sys Address: 0x00000000 Size: 0 File Visible: - Signed: - Status: - Name: ATMFD.DLL Image Path: C:\WINDOWS\System32\ATMFD.DLL Address: 0xBFFA0000 Size: 286720 File Visible: - Signed: - Status: - Name: aucbcfg.sys Image Path: C:\WINDOWS\system32\DRIVERS\aucbcfg.sys Address: 0xF8D26000 Size: 5088 File Visible: - Signed: - Status: - Name: audstub.sys Image Path: C:\WINDOWS\System32\DRIVERS\audstub.sys Address: 0xF8DCE000 Size: 3072 File Visible: - Signed: - Status: - Name: avgio.sys Image Path: C:\Programme\Avira\AntiVir Desktop\avgio.sys Address: 0xF8D74000 Size: 6144 File Visible: - Signed: - Status: - Name: avgntflt.sys Image Path: C:\WINDOWS\system32\DRIVERS\avgntflt.sys Address: 0xF44F7000 Size: 81920 File Visible: - Signed: - Status: - Name: BATTC.SYS Image Path: C:\WINDOWS\System32\DRIVERS\BATTC.SYS Address: 0xF8C0E000 Size: 16384 File Visible: - Signed: - Status: - Name: Beep.SYS Image Path: C:\WINDOWS\System32\Drivers\Beep.SYS Address: 0xF8D6E000 Size: 4224 File Visible: - Signed: - Status: - Name: BOOTVID.dll Image Path: C:\WINDOWS\system32\BOOTVID.dll Address: 0xF8C06000 Size: 12288 File Visible: - Signed: - Status: - Name: Cdfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Cdfs.SYS Address: 0xF89A6000 Size: 63744 File Visible: - Signed: - Status: - Name: cdrom.sys Image Path: C:\WINDOWS\System32\DRIVERS\cdrom.sys Address: 0xF7F17000 Size: 62976 File Visible: - Signed: - Status: - Name: CLASSPNP.SYS Image Path: C:\WINDOWS\System32\DRIVERS\CLASSPNP.SYS Address: 0xF8846000 Size: 53248 File Visible: - Signed: - Status: - Name: CmBatt.sys Image Path: C:\WINDOWS\System32\DRIVERS\CmBatt.sys Address: 0xF8CDE000 Size: 13952 File Visible: - Signed: - Status: - Name: compbatt.sys Image Path: compbatt.sys Address: 0xF8C0A000 Size: 10240 File Visible: - Signed: - Status: - Name: disk.sys Image Path: disk.sys Address: 0xF8836000 Size: 36352 File Visible: - Signed: - Status: - Name: dmio.sys Image Path: dmio.sys Address: 0xF8643000 Size: 154112 File Visible: - Signed: - Status: - Name: dmload.sys Image Path: dmload.sys Address: 0xF8CFC000 Size: 5888 File Visible: - Signed: - Status: - Name: drmk.sys Image Path: C:\WINDOWS\system32\drivers\drmk.sys Address: 0xF88A6000 Size: 61440 File Visible: - Signed: - Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xF67FB000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF8D76000 Size: 8192 File Visible: No Signed: - Status: - Name: Dxapi.sys Image Path: C:\WINDOWS\System32\drivers\Dxapi.sys Address: 0xF7A3C000 Size: 12288 File Visible: - Signed: - Status: - Name: dxg.sys Image Path: C:\WINDOWS\System32\drivers\dxg.sys Address: 0xBF000000 Size: 73728 File Visible: - Signed: - Status: - Name: dxgthk.sys Image Path: C:\WINDOWS\System32\drivers\dxgthk.sys Address: 0xF8E4F000 Size: 4096 File Visible: - Signed: - Status: - Name: el90xbc5.sys Image Path: C:\WINDOWS\System32\DRIVERS\el90xbc5.sys Address: 0xF7D9A000 Size: 66560 File Visible: - Signed: - Status: - Name: Fastfat.SYS Image Path: C:\WINDOWS\System32\Drivers\Fastfat.SYS Address: 0xF4194000 Size: 143744 File Visible: - Signed: - Status: - Name: fdc.sys Image Path: C:\WINDOWS\System32\DRIVERS\fdc.sys Address: 0xF8B46000 Size: 27392 File Visible: - Signed: - Status: - Name: Fips.SYS Image Path: C:\WINDOWS\System32\Drivers\Fips.SYS Address: 0xF8976000 Size: 44672 File Visible: - Signed: - Status: - Name: flpydisk.sys Image Path: C:\WINDOWS\System32\DRIVERS\flpydisk.sys Address: 0xF8B8E000 Size: 20480 File Visible: - Signed: - Status: - Name: fltmgr.sys Image Path: fltmgr.sys Address: 0xF860B000 Size: 129792 File Visible: - Signed: - Status: - Name: Fs_Rec.SYS Image Path: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS Address: 0xF8D6C000 Size: 7936 File Visible: - Signed: - Status: - Name: ftdisk.sys Image Path: ftdisk.sys Address: 0xF8669000 Size: 126336 File Visible: - Signed: - Status: - Name: GEARAspiWDM.sys Image Path: C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys Address: 0xF8B4E000 Size: 21120 File Visible: - Signed: - Status: - Name: hal.dll Image Path: C:\WINDOWS\system32\hal.dll Address: 0x806EF000 Size: 81152 File Visible: - Signed: - Status: - Name: hardlock.sys Image Path: C:\WINDOWS\System32\drivers\hardlock.sys Address: 0xF41B8000 Size: 433664 File Visible: - Signed: - Status: - Name: HIDCLASS.SYS Image Path: C:\WINDOWS\System32\DRIVERS\HIDCLASS.SYS Address: 0xF89B6000 Size: 36864 File Visible: - Signed: - Status: - Name: HIDPARSE.SYS Image Path: C:\WINDOWS\System32\DRIVERS\HIDPARSE.SYS Address: 0xF8B9E000 Size: 28672 File Visible: - Signed: - Status: - Name: hidusb.sys Image Path: C:\WINDOWS\System32\DRIVERS\hidusb.sys Address: 0xF7B2B000 Size: 10368 File Visible: - Signed: - Status: - Name: HSF_CNXT.sys Image Path: C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys Address: 0xF7B4F000 Size: 569088 File Visible: - Signed: - Status: - Name: HSF_DP.sys Image Path: C:\WINDOWS\System32\DRIVERS\HSF_DP.sys Address: 0xF7BDA000 Size: 1091936 File Visible: - Signed: - Status: - Name: HSFHWICH.sys Image Path: C:\WINDOWS\System32\DRIVERS\HSFHWICH.sys Address: 0xF7CE5000 Size: 144832 File Visible: - Signed: - Status: - Name: HTTP.sys Image Path: C:\WINDOWS\System32\Drivers\HTTP.sys Address: 0xF3A9B000 Size: 265728 File Visible: - Signed: - Status: - Name: i8042prt.sys Image Path: C:\WINDOWS\System32\DRIVERS\i8042prt.sys Address: 0xF7F57000 Size: 52992 File Visible: - Signed: - Status: - Name: imapi.sys Image Path: C:\WINDOWS\System32\DRIVERS\imapi.sys Address: 0xF7F27000 Size: 42112 File Visible: - Signed: - Status: - Name: intelide.sys Image Path: intelide.sys Address: 0xF8CFA000 Size: 5504 File Visible: - Signed: - Status: - Name: intelppm.sys Image Path: C:\WINDOWS\System32\DRIVERS\intelppm.sys Address: 0xF7F67000 Size: 40448 File Visible: - Signed: - Status: - Name: ipnat.sys Image Path: C:\WINDOWS\System32\DRIVERS\ipnat.sys Address: 0xF6813000 Size: 152832 File Visible: - Signed: - Status: - Name: ipsec.sys Image Path: C:\WINDOWS\System32\DRIVERS\ipsec.sys Address: 0xF699F000 Size: 75264 File Visible: - Signed: - Status: - Name: isapnp.sys Image Path: isapnp.sys Address: 0xF8806000 Size: 37632 File Visible: - Signed: - Status: - Name: jcwwarnm.sys Image Path: jcwwarnm.sys Address: 0xF87F6000 Size: 54016 File Visible: No Signed: - Status: - Name: kbdclass.sys Image Path: C:\WINDOWS\System32\DRIVERS\kbdclass.sys Address: 0xF8B36000 Size: 25216 File Visible: - Signed: - Status: - Name: KDCOM.DLL Image Path: C:\WINDOWS\system32\KDCOM.DLL Address: 0xF8CF6000 Size: 8192 File Visible: - Signed: - Status: - Name: kmixer.sys Image Path: C:\WINDOWS\system32\drivers\kmixer.sys Address: 0xF3076000 Size: 172416 File Visible: - Signed: - Status: - Name: ks.sys Image Path: C:\WINDOWS\System32\DRIVERS\ks.sys Address: 0xF7D45000 Size: 143360 File Visible: - Signed: - Status: - Name: KSecDD.sys Image Path: KSecDD.sys Address: 0xF85E2000 Size: 92928 File Visible: - Signed: - Status: - Name: L8042Pr2.sys Image Path: C:\WINDOWS\System32\DRIVERS\L8042Pr2.sys Address: 0xF7F47000 Size: 45984 File Visible: - Signed: - Status: - Name: Lbd.sys Image Path: Lbd.sys Address: 0xF8856000 Size: 57600 File Visible: - Signed: - Status: - Name: LHidFlt2.sys Image Path: C:\WINDOWS\System32\DRIVERS\LHidFlt2.sys Address: 0xF8BD6000 Size: 20992 File Visible: - Signed: - Status: - Name: litsgt.sys Image Path: C:\WINDOWS\System32\DRIVERS\litsgt.sys Address: 0xF4172000 Size: 137344 File Visible: - Signed: - Status: - Name: LKbdFlt2.sys Image Path: C:\WINDOWS\System32\DRIVERS\LKbdFlt2.sys Address: 0xF8D2C000 Size: 5248 File Visible: - Signed: - Status: - Name: LMouFlt2.sys Image Path: C:\WINDOWS\System32\DRIVERS\LMouFlt2.sys Address: 0xF7F37000 Size: 60384 File Visible: - Signed: - Status: - Name: mdmxsdk.sys Image Path: C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys Address: 0xF4357000 Size: 8768 File Visible: - Signed: - Status: - Name: mnmdd.SYS Image Path: C:\WINDOWS\System32\Drivers\mnmdd.SYS Address: 0xF8D70000 Size: 4224 File Visible: - Signed: - Status: - Name: Modem.SYS Image Path: C:\WINDOWS\System32\Drivers\Modem.SYS Address: 0xF8B56000 Size: 30336 File Visible: - Signed: - Status: - Name: mouclass.sys Image Path: C:\WINDOWS\System32\DRIVERS\mouclass.sys Address: 0xF8B3E000 Size: 23552 File Visible: - Signed: - Status: - Name: mouhid.sys Image Path: C:\WINDOWS\System32\DRIVERS\mouhid.sys Address: 0xF7B27000 Size: 12288 File Visible: - Signed: - Status: - Name: MountMgr.sys Image Path: MountMgr.sys Address: 0xF8816000 Size: 42368 File Visible: - Signed: - Status: - Name: mrxdav.sys Image Path: C:\WINDOWS\System32\DRIVERS\mrxdav.sys Address: 0xF4312000 Size: 180608 File Visible: - Signed: - Status: - Name: mrxsmb.sys Image Path: C:\WINDOWS\System32\DRIVERS\mrxsmb.sys Address: 0xF6839000 Size: 455680 File Visible: - Signed: - Status: - Name: Msfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Msfs.SYS Address: 0xF8BAE000 Size: 19072 File Visible: - Signed: - Status: - Name: msgpc.sys Image Path: C:\WINDOWS\System32\DRIVERS\msgpc.sys Address: 0xF88E6000 Size: 35072 File Visible: - Signed: - Status: - Name: mssmbios.sys Image Path: C:\WINDOWS\System32\DRIVERS\mssmbios.sys Address: 0xF84BD000 Size: 15488 File Visible: - Signed: - Status: - Name: Mup.sys Image Path: Mup.sys Address: 0xF850E000 Size: 105344 File Visible: - Signed: - Status: - Name: NDIS.sys Image Path: NDIS.sys Address: 0xF8528000 Size: 182656 File Visible: - Signed: - Status: - Name: ndistapi.sys Image Path: C:\WINDOWS\System32\DRIVERS\ndistapi.sys Address: 0xF8CE6000 Size: 10112 File Visible: - Signed: - Status: - Name: ndisuio.sys Image Path: C:\WINDOWS\System32\DRIVERS\ndisuio.sys Address: 0xF4533000 Size: 14592 File Visible: - Signed: - Status: - Name: ndiswan.sys Image Path: C:\WINDOWS\System32\DRIVERS\ndiswan.sys Address: 0xF7B10000 Size: 91520 File Visible: - Signed: - Status: - Name: NDProxy.SYS Image Path: C:\WINDOWS\System32\Drivers\NDProxy.SYS Address: 0xF8916000 Size: 40576 File Visible: - Signed: - Status: - Name: netbios.sys Image Path: C:\WINDOWS\System32\DRIVERS\netbios.sys Address: 0xF8956000 Size: 34688 File Visible: - Signed: - Status: - Name: netbt.sys Image Path: C:\WINDOWS\System32\DRIVERS\netbt.sys Address: 0xF691E000 Size: 162816 File Visible: - Signed: - Status: - Name: Npfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Npfs.SYS Address: 0xF8BB6000 Size: 30848 File Visible: - Signed: - Status: - Name: Ntfs.sys Image Path: Ntfs.sys Address: 0xF8555000 Size: 574976 File Visible: - Signed: - Status: - Name: ntoskrnl.exe Image Path: C:\WINDOWS\system32\ntoskrnl.exe Address: 0x804D7000 Size: 2192256 File Visible: - Signed: - Status: - Name: Null.SYS Image Path: C:\WINDOWS\System32\Drivers\Null.SYS Address: 0xF8DF6000 Size: 2944 File Visible: - Signed: - Status: - Name: nv4_disp.dll Image Path: C:\WINDOWS\System32\nv4_disp.dll Address: 0xBF012000 Size: 3346432 File Visible: - Signed: - Status: - Name: nv4_mini.sys Image Path: C:\WINDOWS\System32\DRIVERS\nv4_mini.sys Address: 0xF7DE3000 Size: 1260928 File Visible: - Signed: - Status: - Name: omci.sys Image Path: C:\WINDOWS\system32\DRIVERS\omci.sys Address: 0xF8B7E000 Size: 17088 File Visible: - Signed: - Status: - Name: OPRGHDLR.SYS Image Path: C:\WINDOWS\System32\DRIVERS\OPRGHDLR.SYS Address: 0xF8DBE000 Size: 4096 File Visible: - Signed: - Status: - Name: parport.sys Image Path: C:\WINDOWS\System32\DRIVERS\parport.sys Address: 0xF7D68000 Size: 80384 File Visible: - Signed: - Status: - Name: PartMgr.sys Image Path: PartMgr.sys Address: 0xF8A7E000 Size: 19712 File Visible: - Signed: - Status: - Name: ParVdm.SYS Image Path: C:\WINDOWS\System32\Drivers\ParVdm.SYS Address: 0xF8D22000 Size: 7040 File Visible: - Signed: - Status: - Name: pci.sys Image Path: pci.sys Address: 0xF86A6000 Size: 68224 File Visible: - Signed: - Status: - Name: PCIIDEX.SYS Image Path: C:\WINDOWS\System32\DRIVERS\PCIIDEX.SYS Address: 0xF8A76000 Size: 28672 File Visible: - Signed: - Status: - Name: pcmcia.sys Image Path: C:\WINDOWS\System32\DRIVERS\pcmcia.sys Address: 0xF7D7C000 Size: 120576 File Visible: - Signed: - Status: - Name: PnpManager Image Path: \Driver\PnpManager Address: 0x804D7000 Size: 2192256 File Visible: - Signed: - Status: - Name: portcls.sys Image Path: C:\WINDOWS\system32\drivers\portcls.sys Address: 0xF7D09000 Size: 147456 File Visible: - Signed: - Status: - Name: psched.sys Image Path: C:\WINDOWS\System32\DRIVERS\psched.sys Address: 0xF7AD6000 Size: 69120 File Visible: - Signed: - Status: - Name: ptilink.sys Image Path: C:\WINDOWS\System32\DRIVERS\ptilink.sys Address: 0xF8B6E000 Size: 17792 File Visible: - Signed: - Status: - Name: pxtdqpog.sys Image Path: C:\DOKUME~1\MARIE~1.BAL\LOKALE~1\Temp\pxtdqpog.sys Address: 0xF30A1000 Size: 93056 File Visible: No Signed: - Status: - Name: rasacd.sys Image Path: C:\WINDOWS\System32\DRIVERS\rasacd.sys Address: 0xF8CCE000 Size: 8832 File Visible: - Signed: - Status: - Name: rasl2tp.sys Image Path: C:\WINDOWS\System32\DRIVERS\rasl2tp.sys Address: 0xF88B6000 Size: 51328 File Visible: - Signed: - Status: - Name: raspppoe.sys Image Path: C:\WINDOWS\System32\DRIVERS\raspppoe.sys Address: 0xF88C6000 Size: 41472 File Visible: - Signed: - Status: - Name: raspptp.sys Image Path: C:\WINDOWS\System32\DRIVERS\raspptp.sys Address: 0xF88D6000 Size: 48384 File Visible: - Signed: - Status: - Name: raspti.sys Image Path: C:\WINDOWS\System32\DRIVERS\raspti.sys Address: 0xF8B76000 Size: 16512 File Visible: - Signed: - Status: - Name: RAW Image Path: \FileSystem\RAW Address: 0x804D7000 Size: 2192256 File Visible: - Signed: - Status: - Name: rdbss.sys Image Path: C:\WINDOWS\System32\DRIVERS\rdbss.sys Address: 0xF68D1000 Size: 175744 File Visible: - Signed: - Status: - Name: RDPCDD.sys Image Path: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys Address: 0xF8D72000 Size: 4224 File Visible: - Signed: - Status: - Name: rdpdr.sys Image Path: C:\WINDOWS\System32\DRIVERS\rdpdr.sys Address: 0xF7AA6000 Size: 196224 File Visible: - Signed: - Status: - Name: redbook.sys Image Path: C:\WINDOWS\System32\DRIVERS\redbook.sys Address: 0xF8896000 Size: 57728 File Visible: - Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xF3D23000 Size: 49152 File Visible: No Signed: - Status: - Name: SCSIPORT.SYS Image Path: C:\WINDOWS\System32\Drivers\SCSIPORT.SYS Address: 0xF86E6000 Size: 98304 File Visible: - Signed: - Status: - Name: sptd.sys Image Path: sptd.sys Address: 0xF86FE000 Size: 880640 File Visible: - Signed: - Status: - Name: sr.sys Image Path: sr.sys Address: 0xF85F9000 Size: 73472 File Visible: - Signed: - Status: - Name: srv.sys Image Path: C:\WINDOWS\System32\DRIVERS\srv.sys Address: 0xF40F3000 Size: 353792 File Visible: - Signed: - Status: - Name: SSHDRV61.sys Image Path: C:\WINDOWS\System32\drivers\SSHDRV61.sys Address: 0xF8946000 Size: 53248 File Visible: - Signed: - Status: - Name: SSHDRV86.sys Image Path: C:\WINDOWS\System32\drivers\SSHDRV86.sys Address: 0xF69D2000 Size: 319488 File Visible: - Signed: - Status: - Name: ssmdrv.sys Image Path: C:\WINDOWS\system32\DRIVERS\ssmdrv.sys Address: 0xF8BC6000 Size: 23040 File Visible: - Signed: - Status: - Name: strmdisp.sys Image Path: C:\WINDOWS\System32\DRIVERS\strmdisp.sys Address: 0xF8B06000 Size: 21280 File Visible: - Signed: - Status: - Name: swenum.sys Image Path: C:\WINDOWS\System32\DRIVERS\swenum.sys Address: 0xF8D34000 Size: 4352 File Visible: - Signed: - Status: - Name: sysaudio.sys Image Path: C:\WINDOWS\system32\drivers\sysaudio.sys Address: 0xF3F3B000 Size: 60800 File Visible: - Signed: - Status: - Name: tansgt.sys Image Path: C:\WINDOWS\System32\DRIVERS\tansgt.sys Address: 0xF416A000 Size: 12032 File Visible: - Signed: - Status: - Name: tcpip.sys Image Path: C:\WINDOWS\System32\DRIVERS\tcpip.sys Address: 0xF6946000 Size: 361600 File Visible: - Signed: - Status: - Name: TDI.SYS Image Path: C:\WINDOWS\System32\DRIVERS\TDI.SYS Address: 0xF8B5E000 Size: 20480 File Visible: - Signed: - Status: - Name: termdd.sys Image Path: C:\WINDOWS\System32\DRIVERS\termdd.sys Address: 0xF88F6000 Size: 40704 File Visible: - Signed: - Status: - Name: update.sys Image Path: C:\WINDOWS\System32\DRIVERS\update.sys Address: 0xF7A48000 Size: 384768 File Visible: - Signed: - Status: - Name: USBD.SYS Image Path: C:\WINDOWS\System32\DRIVERS\USBD.SYS Address: 0xF8D48000 Size: 8192 File Visible: - Signed: - Status: - Name: usbhub.sys Image Path: C:\WINDOWS\System32\DRIVERS\usbhub.sys Address: 0xF8926000 Size: 59520 File Visible: - Signed: - Status: - Name: USBPORT.SYS Image Path: C:\WINDOWS\System32\DRIVERS\USBPORT.SYS Address: 0xF7DAB000 Size: 147456 File Visible: - Signed: - Status: - Name: usbuhci.sys Image Path: C:\WINDOWS\System32\DRIVERS\usbuhci.sys Address: 0xF8B26000 Size: 20608 File Visible: - Signed: - Status: - Name: vga.sys Image Path: C:\WINDOWS\System32\drivers\vga.sys Address: 0xF8BA6000 Size: 20992 File Visible: - Signed: - Status: - Name: VIDEOPRT.SYS Image Path: C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS Address: 0xF7DCF000 Size: 81920 File Visible: - Signed: - Status: - Name: VolSnap.sys Image Path: VolSnap.sys Address: 0xF8826000 Size: 53760 File Visible: - Signed: - Status: - Name: wanarp.sys Image Path: C:\WINDOWS\System32\DRIVERS\wanarp.sys Address: 0xF8A06000 Size: 34560 File Visible: - Signed: - Status: - Name: watchdog.sys Image Path: C:\WINDOWS\System32\watchdog.sys Address: 0xF8BEE000 Size: 20480 File Visible: - Signed: - Status: - Name: wdmaud.sys Image Path: C:\WINDOWS\system32\drivers\wdmaud.sys Address: 0xF3D96000 Size: 83072 File Visible: - Signed: - Status: - Name: Win32k Image Path: \Driver\Win32k Address: 0xBF800000 Size: 1851392 File Visible: - Signed: - Status: - Name: win32k.sys Image Path: C:\WINDOWS\System32\win32k.sys Address: 0xBF800000 Size: 1851392 File Visible: - Signed: - Status: - Name: WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\WMILIB.SYS Address: 0xF8CF8000 Size: 8192 File Visible: - Signed: - Status: - Name: WMIxWDM Image Path: \Driver\WMIxWDM Address: 0x804D7000 Size: 2192256 File Visible: - Signed: - Status: - Code:
ATTFilter ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2010/07/15 21:03 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Stealth Objects ------------------- Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP] Process: System Address: 0x833661d8 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP] Process: System Address: 0x83177600 Size: 463 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE] Process: System Address: 0x83104980 Size: 463 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE] Process: System Address: 0x83104980 Size: 463 Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ] Process: System Address: 0x83104980 Size: 463 Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE] Process: System Address: 0x83104980 Size: 463 Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x83104980 Size: 463 Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x83104980 Size: 463 Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x83104980 Size: 463 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN] Process: System Address: 0x83104980 Size: 463 Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER] Process: System Address: 0x83104980 Size: 463 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x83104980 Size: 463 Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP] Process: System Address: 0x83104980 Size: 463 Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE] Process: System Address: 0x833d51d8 Size: 463 Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE] Process: System Address: 0x833d51d8 Size: 463 Object: Hidden Code [Driver: dmio, IRP_MJ_READ] Process: System Address: 0x833d51d8 Size: 463 Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE] Process: System Address: 0x833d51d8 Size: 463 Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x833d51d8 Size: 463 Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x833d51d8 Size: 463 Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x833d51d8 Size: 463 Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN] Process: System Address: 0x833d51d8 Size: 463 Object: Hidden Code [Driver: dmio, IRP_MJ_POWER] Process: System Address: 0x833d51d8 Size: 463 Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x833d51d8 Size: 463 Object: Hidden Code [Driver: dmio, IRP_MJ_PNP] Process: System Address: 0x833d51d8 Size: 463 Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE] Process: System Address: 0x831fa1d8 Size: 463 Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE] Process: System Address: 0x831fa1d8 Size: 463 Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x831fa1d8 Size: 463 Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x831fa1d8 Size: 463 Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER] Process: System Address: 0x831fa1d8 Size: 463 Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x831fa1d8 Size: 463 Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP] Process: System Address: 0x831fa1d8 Size: 463 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE] Process: System Address: 0x833681d8 Size: 463 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ] Process: System Address: 0x833681d8 Size: 463 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE] Process: System Address: 0x833681d8 Size: 463 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x833681d8 Size: 463 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x833681d8 Size: 463 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x833681d8 Size: 463 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN] Process: System Address: 0x833681d8 Size: 463 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP] Process: System Address: 0x833681d8 Size: 463 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER] Process: System Address: 0x833681d8 Size: 463 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x833681d8 Size: 463 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP] Process: System Address: 0x833681d8 Size: 463 Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE] Process: System Address: 0x83147980 Size: 463 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE] Process: System Address: 0x83147980 Size: 463 Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x83147980 Size: 463 Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x83147980 Size: 463 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP] Process: System Address: 0x83147980 Size: 463 Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP] Process: System Address: 0x83147980 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP] Process: System Address: 0x8309e8e8 Size: 463 Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭�쀚܁ListBo, IRP_MJ_CREATE] Process: System Address: 0x82f7e378 Size: 463 Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭�쀚܁ListBo, IRP_MJ_CLOSE] Process: System Address: 0x82f7e378 Size: 463 Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭�쀚܁ListBo, IRP_MJ_READ] Process: System Address: 0x82f7e378 Size: 463 Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭�쀚܁ListBo, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x82f7e378 Size: 463 Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭�쀚܁ListBo, IRP_MJ_SET_INFORMATION] Process: System Address: 0x82f7e378 Size: 463 Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭�쀚܁ListBo, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x82f7e378 Size: 463 Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭�쀚܁ListBo, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x82f7e378 Size: 463 Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭�쀚܁ListBo, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x82f7e378 Size: 463 Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭�쀚܁ListBo, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x82f7e378 Size: 463 Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭�쀚܁ListBo, IRP_MJ_SHUTDOWN] Process: System Address: 0x82f7e378 Size: 463 Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭�쀚܁ListBo, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x82f7e378 Size: 463 Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭�쀚܁ListBo, IRP_MJ_CLEANUP] Process: System Address: 0x82f7e378 Size: 463 Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭�쀚܁ListBo, IRP_MJ_PNP] Process: System Address: 0x82f7e378 Size: 463 3. bin mir keiner schuld bewusst....... 4. erledigt 5. Code:
ATTFilter File yahoo_1_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set Code:
ATTFilter File yahoo_1_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set - Code:
ATTFilter File yahoo_1_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set Code:
ATTFilter File yahoo_1_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set Code:
ATTFilter File yahoo_1_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set Code:
ATTFilter File yahoo_1_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set Code:
ATTFilter File yahoo_1_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set Code:
ATTFilter File yahoo_1_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set - danke & grüße caruso2010 |
15.07.2010, 23:36 | #12 | |
/// Helfer-Team | AV Security Suite Antimalware- was noch?Zitat:
- die restlichen Dateien bitte nochmal prüfen lassen und posten, da fast überall fehlt die Dateiname oder eben separat gepostet Ich würde doch gerne, die Dateiname zusammen mit die Scanergebnisse sehen (wie ich es habe Dir beschrieben!) danke |
16.07.2010, 07:52 | #13 |
| AV Security Suite Antimalware- was noch? hallo, das scanergebnis poste ich heute abend nochmal. die scanergebnisse von virustotal stehen doch im coding, der dateiname jeweils darüber viele grüße caruso2010 |
17.07.2010, 05:40 | #14 |
/// Helfer-Team | AV Security Suite Antimalware- was noch? unter Punkt 5. z.B beim ersten fehlt ...:-> http://www.trojaner-board.de/88093-av-security-suite-antimalware-noch.html#post542553 |
19.07.2010, 08:18 | #15 |
| AV Security Suite Antimalware- was noch? so, hier das scanergebnis: Code:
ATTFilter Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4320 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 16.07.2010 22:12:50 mbam-log-2010-07-16 (22-12-50).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Durchsuchte Objekte: 277216 Laufzeit: 2 Stunde(n), 2 Minute(n), 57 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) Code:
ATTFilter File eyalutiholurac.dll_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Code:
ATTFilter File ewipihax.dll_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set - Code:
ATTFilter File apukatiyuwaxo.dll _ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set Code:
ATTFilter File efibebax.dll_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set Code:
ATTFilter File igiyovox.dll_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set Code:
ATTFilter File izecoqaf.dll_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set Code:
ATTFilter File eqawinaqa.dll_ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set Code:
ATTFilter File ayiyiyim.dll _ received on 2010.07.15 15:59:08 (UTC) Current status: finished Result: 8/38 (21.05%) Compact Compact Print results Print results Antivirus Version Last Update Result a-squared 5.0.0.31 2010.07.15 Trojan.JS.FakeSpypro!IK AhnLab-V3 2010.07.15.01 2010.07.15 - AntiVir 8.2.4.10 2010.07.15 - Antiy-AVL 2.0.3.7 2010.07.15 - Authentium 5.2.0.5 2010.07.15 - Avast 4.8.1351.0 2010.07.15 - Avast5 5.0.332.0 2010.07.15 - BitDefender 7.2 2010.07.15 Trojan.FakeAV.KZQ CAT-QuickHeal 11.00 2010.07.15 - ClamAV 0.96.0.3-git 2010.07.15 - Comodo 5438 2010.07.15 - eTrust-Vet 36.1.7710 2010.07.15 HTML/FakeAlert.BHB F-Prot 4.6.1.107 2010.07.15 - Fortinet 4.1.143.0 2010.07.15 - GData 21 2010.07.15 Trojan.FakeAV.KZQ Ikarus T3.1.1.84.0 2010.07.15 Trojan.JS.FakeSpypro Jiangmin 13.0.900 2010.07.15 - Kaspersky 7.0.0.125 2010.07.15 - McAfee 5.400.0.1158 2010.07.15 - McAfee-GW-Edition 2010.1 2010.07.15 - Microsoft 1.5902 2010.07.15 Trojan:JS/FakeSpypro NOD32 5281 2010.07.15 - Norman 6.05.11 2010.07.15 - nProtect 2010-07-15.02 2010.07.15 Trojan.FakeAV.KZQ Panda 10.0.2.7 2010.07.15 - PCTools 7.0.3.5 2010.07.15 - Prevx 3.0 2010.07.15 - Rising 22.56.03.04 2010.07.15 - Sophos 4.55.0 2010.07.15 Mal/FakeAvHm-A Sunbelt 6587 2010.07.15 - SUPERAntiSpyware 4.40.0.1006 2010.07.15 - Symantec 20101.1.1.7 2010.07.15 - TheHacker 6.5.2.1.316 2010.07.15 - TrendMicro 9.120.0.1004 2010.07.15 - TrendMicro-HouseCall 9.120.0.1004 2010.07.15 - VBA32 3.12.12.6 2010.07.15 - ViRobot 2010.7.12.3932 2010.07.15 - VirusBuster 5.0.27.0 2010.07.14 - Additional information File size: 2716 bytes MD5 : a5d202d140c48986bae5a927c053b16d SHA1 : b88ce11f4d69356ac71c23b59eee631b435b5541 SHA256: 999272c7ff116aa898b5942f706c6bf460d31445f4053a5256424d75bb688391 TrID : File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) ssdeep: 48:yGMHyjuA1gPcPFxH/qBfCccADIZDEoxbBZDnrc:LMHIYqca/8oRk sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEiD : - RDS : NSRL Reference Data Set - |
Themen zu AV Security Suite Antimalware- was noch? |
adware.adon, anti-malware, antimalware, backdoor.bot, c:\windows, dateien, ebayshortcuts.exe, einstellungen, explorer, fake.dropped.malware, forum, gen, helper, hijack.userinit, microsoft, network, neustart, programm, security, security suite, service, service pack 3, software, stolen.data, system, system32, trojan.agent, userinit, version, winlogon |