und wg. der Größe hier Teil 2 Code:
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\PM7_G_ns.css
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\RoboHHRE.lng
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\webhelp.cab
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\webhelp.jar
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whcsh_home.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whcshdata.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whftdata.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whftdata0.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whfts.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whfts.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whfwdata.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whfwdata0.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whfwdata1.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whfwdata2.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whfwdata3.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whfwdata4.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whfwdata5.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whgdata.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whglo.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whglo.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whidata.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whidata0.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whidx.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whidx.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whtdata.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whtdata0.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whtoc.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whdata\whtoc.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whestart.ico
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whfbody.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whfdhtml.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whfform.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whfhost.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whform.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whframes.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgbody.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whexpbar.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstf0.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstf1.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstf10.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstf11.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstf2.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstf3.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstf4.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstf5.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstf6.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstf7.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstf8.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstf9.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl0.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl1.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl10.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl11.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl12.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl13.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl14.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl15.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl16.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl17.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl18.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl19.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl2.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl20.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl21.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl22.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl23.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl3.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl4.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl5.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl6.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl7.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl8.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstfl9.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstg0.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlsti0.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt0.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt1.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt10.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt11.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt12.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt13.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt14.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt15.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt16.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt17.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt18.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt19.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt2.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt20.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt21.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt22.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt3.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt4.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt5.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt6.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt7.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt8.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whlstt9.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvf30.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvf31.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvf32.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvf33.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvl31.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvl32.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvl33.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvp30.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvp31.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvp32.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvp33.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvt30.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvt31.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvt32.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdata\whnvt33.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdef.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whgdhtml.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whghost.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whhost.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whibody.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whidhtml.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whiform.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whihost.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whlang.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whmozemu.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whmsg.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whnjs.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whphost.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whproj.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whproj.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whproj.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whproxy.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whres.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whrstart.ico
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whskin_banner.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whskin_blank.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whskin_frmset01.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whskin_frmset010.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whskin_homepage.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whskin_info.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whskin_mbars.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whskin_papplet.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whskin_pdhtml.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whskin_pickup.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whskin_plist.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whskin_tbars.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whst_topics.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whstart.ico
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whstart.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whstub.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_abge.jpg
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_abgi.jpg
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_abgw.jpg
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_abte.jpg
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_abti.jpg
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_abtw.jpg
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_fts_h.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_fts_n.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_glo_h.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_glo_n.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_go.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_hide.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_idx_h.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_idx_n.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_logo1.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_logo2.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_next.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_next_g.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_prev.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_prev_g.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_spac.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_sync.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_tab0.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_tab1.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_tab2.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_tab3.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_tab4.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_tab5.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_tab6.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_tab7.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_tab8.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_toc_h.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_toc_n.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_toc1.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_toc2.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_toc3.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_toc4.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_ws.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\wht_ws_g.gif
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whtbar.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whtdhtml.htm
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whthost.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whtopic.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whutils.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whver.js
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whxdata\whftdata0.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whxdata\whfts.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whxdata\whfwdata0.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whxdata\whfwdata1.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whxdata\whfwdata2.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whxdata\whfwdata3.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whxdata\whfwdata4.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whxdata\whfwdata5.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whxdata\whglo.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whxdata\whidata0.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whxdata\whidx.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whxdata\whtdata0.xml
c:\programme\newsoft\Presto! PageManager 7.15\WebHelp\whxdata\whtoc.xml
c:\programme\newsoft\Presto! PageManager 7.15\WEBSYNC.INI
c:\programme\newsoft\Presto! PageManager 7.15\WebSyncEx.dll
c:\programme\newsoft\Presto! PageManager 7.15\WordVBA.dll
c:\programme\newsoft\Presto! PageManager 7.15\Work\ANNODB\stamp.___
c:\programme\newsoft\Presto! PageManager 7.15\WpdfViewer.exe
c:\programme\newsoft\Presto! PageManager 7.15\WpdfViewer.tlb
c:\programme\newsoft\Presto! PageManager 7.15\WriteData2Pdf.dll
c:\programme\newsoft\Presto! PageManager 7.15\WriteDriver2Pdf.dll
c:\programme\newsoft\Presto! PageManager 7.15\WriteIfo2Pdf.dll
c:\programme\newsoft\Presto! PageManager 7.15\WriteOcr2Pdf.dll
c:\programme\newsoft\Presto! PageManager 7.15\WriteTxt2Pdf.dll
c:\programme\newsoft\Presto! PageManager 7.15\xpdfrc
c:\programme\newsoft\Presto! PageManager 7.15\XpsCreator.dll
c:\programme\newsoft\Presto! PageManager 7.15\zip32.dll
c:\windows\IsUn0407.exe
c:\windows\unin0407.exe
c:\windows\XSxS
H:\install.exe
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_STEC3
-------\Service_STEC3
.
.
((((((((((((((((((((((( Dateien erstellt von 2011-07-28 bis 2011-08-30 ))))))))))))))))))))))))))))))
.
.
2011-08-29 22:29 . 2011-08-29 22:29 -------- d-----w- c:\dokumente und einstellungen\Heini\Lokale Einstellungen\Anwendungsdaten\Samsung
2011-08-29 22:27 . 2011-07-18 04:24 136808 ----a-w- c:\windows\system32\drivers\ssadmdm.sys
2011-08-29 22:27 . 2011-07-18 04:24 12776 ----a-w- c:\windows\system32\drivers\ssadmdfl.sys
2011-08-29 22:23 . 2011-08-29 22:26 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Samsung
2011-08-29 22:16 . 2011-08-29 22:16 -------- d-----w- c:\dokumente und einstellungen\Heini\Lokale Einstellungen\Anwendungsdaten\Downloaded Installations
2011-08-29 18:31 . 2011-08-29 18:31 -------- d-----w- C:\_OTL
2011-08-28 19:16 . 2011-08-28 19:16 -------- d-----w- c:\programme\ESET
2011-08-21 18:51 . 2011-08-21 18:51 -------- d-----w- c:\dokumente und einstellungen\Heini\Anwendungsdaten\Malwarebytes
2011-08-21 18:51 . 2011-07-06 17:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-21 18:51 . 2011-08-21 18:51 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes
2011-08-21 18:51 . 2011-08-21 18:51 -------- d-----w- c:\programme\Malwarebytes' Anti-Malware
2011-08-21 18:51 . 2011-07-06 17:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-13 09:38 . 2011-08-13 09:38 -------- d-----w- c:\dokumente und einstellungen\Heini\Anwendungsdaten\SUPERAntiSpyware.com
2011-08-11 14:27 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-11 14:26 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-23 19:16 . 2011-05-15 10:00 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-26 15:26 . 2011-07-26 15:26 90112 ----a-w- c:\windows\MAMCityDownload.ocx
2011-07-26 15:26 . 2011-07-26 15:26 325552 ----a-w- c:\windows\MASetupCaller.dll
2011-07-26 15:26 . 2011-07-26 15:26 30568 ----a-w- c:\windows\MusiccityDownload.exe
2011-07-26 15:26 . 2011-07-26 15:26 974848 ----a-w- c:\windows\system32\cis-2.4.dll
2011-07-26 15:26 . 2011-07-26 15:26 81920 ----a-w- c:\windows\system32\issacapi_bs-2.3.dll
2011-07-26 15:26 . 2011-07-26 15:26 65536 ----a-w- c:\windows\system32\issacapi_pe-2.3.dll
2011-07-26 15:26 . 2011-07-26 15:26 57344 ----a-w- c:\windows\system32\MTXSYNCICON.dll
2011-07-26 15:26 . 2011-07-26 15:26 57344 ----a-w- c:\windows\system32\MK_Lyric.dll
2011-07-26 15:26 . 2011-07-26 15:26 57344 ----a-w- c:\windows\system32\issacapi_se-2.3.dll
2011-07-26 15:26 . 2011-07-26 15:26 569344 ----a-w- c:\windows\system32\muzdecode.ax
2011-07-26 15:26 . 2011-07-26 15:26 491520 ----a-w- c:\windows\system32\muzapp.dll
2011-07-26 15:26 . 2011-07-26 15:26 49152 ----a-w- c:\windows\system32\MaJGUILib.dll
2011-07-26 15:26 . 2011-07-26 15:26 45056 ----a-w- c:\windows\system32\MaXMLProto.dll
2011-07-26 15:26 . 2011-07-26 15:26 45056 ----a-w- c:\windows\system32\MACXMLProto.dll
2011-07-26 15:26 . 2011-07-26 15:26 40960 ----a-w- c:\windows\system32\MTTELECHIP.dll
2011-07-26 15:26 . 2011-07-26 15:26 40960 ----a-w- c:\windows\system32\MAMACExtract.dll
2011-07-26 15:26 . 2011-07-26 15:26 352256 ----a-w- c:\windows\system32\MSLUR71.dll
2011-07-26 15:26 . 2011-07-26 15:26 258048 ----a-w- c:\windows\system32\muzoggsp.ax
2011-07-26 15:26 . 2011-07-26 15:26 245760 ----a-w- c:\windows\system32\MSCLib.dll
2011-07-26 15:26 . 2011-07-26 15:26 24576 ----a-w- c:\windows\system32\MASetupCleaner.exe
2011-07-26 15:26 . 2011-07-26 15:26 200704 ----a-w- c:\windows\system32\muzwmts.dll
2011-07-26 15:26 . 2011-07-26 15:26 172032 ----a-w- c:\windows\system32\muzapp.exe
2011-07-26 15:26 . 2011-07-26 15:26 155648 ----a-w- c:\windows\system32\MSFLib.dll
2011-07-26 15:26 . 2011-07-26 15:26 143360 ----a-w- c:\windows\system32\3DAudio.ax
2011-07-26 15:26 . 2011-07-26 15:26 14336 ----a-w- c:\windows\system32\avrt.dll
2011-07-26 15:26 . 2011-07-26 15:26 135168 ----a-w- c:\windows\system32\muzaf1.dll
2011-07-26 15:26 . 2011-07-26 15:26 131072 ----a-w- c:\windows\system32\muzmpgsp.ax
2011-07-26 15:26 . 2011-07-26 15:26 122880 ----a-w- c:\windows\system32\muzeffect.ax
2011-07-26 15:26 . 2011-07-26 15:26 118784 ----a-w- c:\windows\system32\MaDRM.dll
2011-07-26 15:26 . 2011-07-26 15:26 110592 ----a-w- c:\windows\system32\muzmp4sp.ax
2011-07-15 13:29 . 2001-08-23 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2001-08-23 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-03 16:31 . 2011-07-03 16:32 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-07-03 16:31 . 2010-08-04 19:09 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-06-30 18:49 . 2009-03-27 18:13 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-30 18:49 . 2009-03-27 18:13 138192 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-24 14:10 . 2005-07-30 14:46 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-21 18:18 . 2008-03-09 18:41 672768 ----a-w- c:\windows\system32\wininet.dll
2011-06-21 18:18 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-06-21 18:18 . 2001-08-23 12:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-06-21 18:16 . 2004-08-04 12:00 371200 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2001-08-23 12:00 293888 ----a-w- c:\windows\system32\winsrv.dll
2011-06-06 11:35 . 2001-08-23 12:00 1859072 ----a-w- c:\windows\system32\win32k.sys
2007-08-10 15:35 . 2007-08-10 15:28 21733696 ----a-w- c:\programme\SkypeSetup.exe
2008-01-29 12:51 . 2008-01-29 12:51 27976 ----a-w- c:\programme\mozilla firefox\plugins\atgpcdec.dll
2008-01-29 12:51 . 2008-01-29 12:51 125848 ----a-w- c:\programme\mozilla firefox\plugins\atgpcext.dll
2008-01-29 12:51 . 2008-01-29 12:51 46408 ----a-w- c:\programme\mozilla firefox\plugins\atmccli.dll
2008-01-29 12:51 . 2008-01-29 12:51 98712 ----a-w- c:\programme\mozilla firefox\plugins\ieatgpc.dll
2011-08-21 09:33 . 2011-03-29 16:48 134104 ----a-w- c:\programme\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TuneUp MemOptimizer"="c:\programme\TuneUp Utilities 2007\MemOptimizer.exe" [2007-04-26 313352]
"H/PC Connection Agent"="c:\programme\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"CTSyncU.exe"="c:\programme\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]
"KiesPDLR"="c:\programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-08-22 20880]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2010-11-02 281768]
"SiSPower"="SiSPower.dll" [2006-03-09 49152]
"BCSSync"="c:\programme\microsoft office\Office14\BCSSync.exe" [2010-03-13 91520]
"CTCheck"="c:\programme\Creative\ZEN Media Explorer\CTCheck.exe" [2007-11-06 397312]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-07-03 273544]
"SunJavaUpdateSched"="c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2011-04-08 254696]
"KiesHelper"="c:\programme\Samsung\Kies\KiesHelper.exe" [2011-08-22 958352]
"KiesTrayAgent"="c:\programme\Samsung\Kies\KiesTrayAgent.exe" [2011-08-22 3507088]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\GEMEIN~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584]
.
c:\dokumente und einstellungen\All Users\Startmen\Programme\Autostart\
Sitecom 300N USB Wireless LAN Utility.lnk - c:\programme\SITECOM\300N USB Wireless LAN Utility\RtWLan.exe [2010-12-8 937984]
Wireless Configuration Utility.lnk - c:\programme\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.30\WlanCU.exe [2004-10-6 442368]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programme\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\programme\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk*\0sprestrt\0sprestrt
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBCSSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^SanDisk Media Manager.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\SanDisk Media Manager.lnk
backup=c:\windows\pss\SanDisk Media Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Squeezebox Server-Taskleisten-Tool.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Squeezebox Server-Taskleisten-Tool.lnk
backup=c:\windows\pss\Squeezebox Server-Taskleisten-Tool.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^WISO Mein Steuer-Sparbuch heute.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\WISO Mein Steuer-Sparbuch heute.lnk
backup=c:\windows\pss\WISO Mein Steuer-Sparbuch heute.lnkCommon Startup
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"H/PC Connection Agent"="c:\programme\Microsoft ActiveSync\wcescomm.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMan"=SOUNDMAN.EXE
"WrtMon.exe"=c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe
"TrueImageMonitor.exe"=c:\programme\Acronis\TrueImageHome\TrueImageMonitor.exe
"CanonSolutionMenu"=c:\programme\Canon\SolutionMenu\CNSLMAIN.exe /logon
"AcronisTimounterMonitor"=c:\programme\Acronis\TrueImageHome\TimounterMonitor.exe
"Acronis Scheduler2 Service"="c:\programme\Gemeinsame Dateien\Acronis\Schedule2\schedhlp.exe"
"SBCSTray"=c:\programme\Sunbelt Software\CounterSpy\SBCSTray.exe
"OpwareSE4"="c:\programme\ScanSoft\OmniPageSE4\OpwareSE4.exe"
"SSBkgdUpdate"="c:\programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
"ATICCC"="c:\programme\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
"ATIPTA"=c:\programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
"ISUSScheduler"="c:\programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe" -start
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programme\\NX Client for Windows\\nxclient.exe"=
"c:\\Programme\\NX Client for Windows\\bin\\nxssh.exe"=
"c:\programme\Microsoft ActiveSync\rapimgr.exe"= c:\programme\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\programme\Microsoft ActiveSync\wcescomm.exe"= c:\programme\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\programme\Microsoft ActiveSync\WCESMgr.exe"= c:\programme\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Programme\\Squeezebox\\SqueezePlay\\squeezeplay.exe"=
"c:\\Programme\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Programme\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Programme\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Programme\\SITECOM\\300N USB Wireless LAN Utility\\RtWLan.exe"=
"c:\\Programme\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9000:TCP"= 9000:TCP:Squeezebox Server 9000 tcp (UI)
"3483:UDP"= 3483:UDP:Squeezebox Server 3483 udp
"3483:TCP"= 3483:TCP:Squeezebox Server 3483 tcp
"9090:TCP"= 9090:TCP:Squeezebox Server 9090 tcp (UI)
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"9001:TCP"= 9001:TCP:Squeezebox Server 9001 tcp (UI)
"9002:TCP"= 9002:TCP:Squeezebox Server 9002 tcp (UI)
"9003:TCP"= 9003:TCP:Squeezebox Server 9003 tcp (UI)
"9004:TCP"= 9004:TCP:Squeezebox Server 9004 tcp (UI)
"9005:TCP"= 9005:TCP:Squeezebox Server 9005 tcp (UI)
"9006:TCP"= 9006:TCP:Squeezebox Server 9006 tcp (UI)
"9007:TCP"= 9007:TCP:Squeezebox Server 9007 tcp (UI)
"9008:TCP"= 9008:TCP:Squeezebox Server 9008 tcp (UI)
"9009:TCP"= 9009:TCP:Squeezebox Server 9009 tcp (UI)
"9010:TCP"= 9010:TCP:Squeezebox Server 9010 tcp (UI)
"9100:TCP"= 9100:TCP:Squeezebox Server 9100 tcp (UI)
"8000:TCP"= 8000:TCP:Squeezebox Server 8000 tcp (UI)
"10000:TCP"= 10000:TCP:Squeezebox Server 10000 tcp (UI)
"1542:TCP"= 1542:TCP:Realtek WPS TCP Prot
"1542:UDP"= 1542:UDP:Realtek WPS UDP Prot
"53:UDP"= 53:UDP:Realtek AP UDP Prot
.
R0 SBHR;SBHR;c:\windows\system32\drivers\sbhr.sys [21.09.2007 20:11 15544]
R1 SASDIFSV;SASDIFSV;c:\programme\SUPERAntiSpyware\sasdifsv.sys [17.02.2010 20:25 12872]
R1 SASKUTIL;SASKUTIL;c:\programme\SUPERAntiSpyware\SASKUTIL.SYS [10.05.2010 20:41 67656]
R2 a2free;a-squared Free Service;c:\programme\a-squared Free\a2service.exe [30.08.2007 21:19 380528]
R2 ACEDRV08;ACEDRV08;c:\windows\system32\drivers\ACEDRV08.sys [10.01.2009 20:41 108768]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\programme\Avira\AntiVir Desktop\avmailc.exe [27.03.2009 20:13 340136]
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [27.03.2009 20:13 136360]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\programme\Avira\AntiVir Desktop\avwebgrd.exe [27.03.2009 20:13 428200]
R2 AVMPORT;AVMPORT;c:\windows\system32\drivers\avmport.sys [31.07.2005 19:03 59520]
R2 CDMA Device Service;CDMA Device Service;c:\programme\Samsung\USB Drivers\26_VIA_driver2\x86\VIAService.exe [30.08.2011 00:28 63488]
R2 Netzmanager Service;Netzmanager Infrastruktur Informationssystem Dienst;c:\programme\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [04.11.2010 16:41 9728]
R2 SqueezeMySQL;SqueezeMySQL;c:\progra~1\SQUEEZ~2\server\Bin\MSWIN3~1\mysqld.exe --defaults-file=c:\dokume~1\ALLUSE~1\ANWEND~1\SQUEEZ~2\Cache\my.cnf SqueezeMySQL --> c:\progra~1\SQUEEZ~2\server\Bin\MSWIN3~1\mysqld.exe --defaults-file=c:\dokume~1\ALLUSE~1\ANWEND~1\SQUEEZ~2\Cache\my.cnf SqueezeMySQL [?]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\rtl8192su.sys [08.12.2010 16:54 605856]
S2 gupdate;Google Update Service (gupdate);c:\programme\Google\Update\GoogleUpdate.exe [20.12.2009 22:09 135664]
S3 ACRUSBTM;ACRUSBTM;c:\windows\system32\drivers\ACRUSBTM.SYS [26.09.2008 19:52 28672]
S3 ALSysIO;ALSysIO;\??\c:\dokume~1\Heini\LOKALE~1\Temp\ALSysIO.sys --> c:\dokume~1\Heini\LOKALE~1\Temp\ALSysIO.sys [?]
S3 AVMBTPARALLEL;AVM Bluetooth Druckeranschluss;c:\windows\system32\drivers\avmbtpar.sys [09.12.2003 02:00 60032]
S3 AVMBTSERIAL;AVM Bluetooth Kommunikationsanschluss;c:\windows\system32\drivers\avmbtser.sys [09.12.2003 02:00 61056]
S3 AVMBTSND;AVM Bluetooth Audio Driver;c:\windows\system32\drivers\avmbtsnd.sys [09.12.2003 02:00 48128]
S3 AVMCOWAN;AVM ISDN CoNDIS WAN CAPI Treiber;c:\windows\system32\drivers\avmcowan.sys [09.12.2003 02:00 53120]
S3 AVMWAN;NDIS WAN CAPI Treiber;c:\windows\system32\drivers\avmwan.sys [11.01.2002 02:00 37568]
S3 bfubase;BlueFRITZ! USB (WinXP/2000);c:\windows\system32\drivers\bfubase.sys [11.01.2002 02:00 741600]
S3 CAPI_CIP;AVM Bluetooth CAPI-Controller;c:\windows\system32\drivers\capi_cip.sys [09.12.2003 02:00 334464]
S3 FXDRV;FXDRV;\??\f:\fxdrv.sys --> f:\Fxdrv.sys [?]
S3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\DRIVERS\gflmouhid.sys --> c:\windows\system32\DRIVERS\gflmouhid.sys [?]
S3 gMouPS2;PS2 Scroll Mouse Device;c:\windows\system32\DRIVERS\gMouPS2.sys --> c:\windows\system32\DRIVERS\gMouPS2.sys [?]
S3 gupdatem;Google Update-Dienst (gupdatem);c:\programme\Google\Update\GoogleUpdate.exe [20.12.2009 22:09 135664]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\programme\Microsoft Office\Office14\GROOVE.EXE [25.03.2010 10:25 30969208]
S3 NETBFPAN;AVM Bluetooth Netzwerkadapter;c:\windows\system32\drivers\netbfpan.sys [09.12.2003 02:00 35914]
S3 NETPPPOI;PPP over ISDN;c:\windows\system32\DRIVERS\NETPPPOI.SYS --> c:\windows\system32\DRIVERS\NETPPPOI.SYS [?]
S3 osppsvc;Office Software Protection Platform;c:\programme\Gemeinsame Dateien\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09.01.2010 21:37 4640000]
S3 SBAPIFS;SBAPIFS;\??\c:\windows\system32\drivers\sbapifs.sys --> c:\windows\system32\drivers\sbapifs.sys [?]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [30.08.2011 00:27 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [30.08.2011 00:27 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [30.08.2011 00:27 136808]
S3 TelekomNM3;Telekom Netzmanager Packet Filter Driver;c:\programme\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys [16.09.2010 17:02 35040]
S3 vmdmd;Fax Port Driver;c:\windows\system32\DRIVERS\vmdmd.sys --> c:\windows\system32\DRIVERS\vmdmd.sys [?]
.
Inhalt des "geplante Tasks" Ordners
.
2011-07-29 c:\windows\Tasks\1-Klick-Wartung.job
- c:\programme\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 18:08]
.
2011-08-30 c:\windows\Tasks\Google Software Updater.job
- c:\programme\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-24 08:49]
.
2011-08-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programme\Google\Update\GoogleUpdate.exe [2009-12-20 20:09]
.
2011-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programme\Google\Update\GoogleUpdate.exe [2009-12-20 20:09]
.
2011-08-30 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-436374069-507921405-725345543-1005.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2011-03-29 08:47]
.
2011-08-28 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-436374069-507921405-725345543-1005.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2011-03-29 08:47]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
mSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: An vorhandene PDF-Datei anfügen - c:\programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Google Sidewiki... - c:\programme\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: In Adobe PDF konvertieren - c:\programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\programme\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\dokumente und einstellungen\Heini\Anwendungsdaten\Mozilla\Firefox\Profiles\d0fnmop5.Heini\
FF - prefs.js: browser.startup.homepage - www.google.de
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-01_Simmental - c:\programme\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\programme\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\programme\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\programme\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\programme\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\programme\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\programme\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\programme\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\programme\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\programme\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-12_Symbian_USB_Download_Driver - c:\programme\Samsung\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe
AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\programme\Samsung\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe
AddRemove-16_Shrewsbury - c:\programme\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\programme\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\programme\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\programme\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\programme\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\programme\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\programme\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
AddRemove-24_flashusbdriver - c:\programme\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\programme\Samsung\USB Drivers\25_escape\Uninstall.exe
AddRemove-26_VIA_driver2 - c:\programme\Samsung\USB Drivers\26_VIA_driver2\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-08-30 21:17
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-08ab-d9f0-6a52fa0881df}\InprocServer32*]
"Class"=hex:ab,c2,74,5b,6c,67,a9,07,13,e0,e1,24,c4,1e,4a,fb,d0,dd,48,ff,50,95,
74,f9,62,57,09,f4,e8,d4,30,f1,4b,a8,a7,f4,da,c8,33,9b,48,b8,7b,81,1c,3c,a0,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-1f88-36b0-b09afa0881df}\InprocServer32*]
"Class"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-2576-8912-f53dfa0881df}\InprocServer32*]
"Class"=hex:d4,5f,d4,fd,c6,b4,bf,77,56,75,0e,52,68,44,fd,05,8e,61,64,c7,8d,04,
9a,0b,b9,cb,a4,63,56,e1,dc,88,12,6f,67,c0,be,41,6e,1a,5f,f5,6e,06,f1,d3,3b,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-3150-4425-126ffa0881df}\InprocServer32*]
"Class"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-64ef-77df-c2c1fa0881df}\InprocServer32*]
"Class"=hex:f3,ab,5e,97,03,e1,3c,b2,5c,49,a2,43,b6,d1,e5,c5,4b,ee,a8,8b,ce,e3,
cb,73,38,b0,4e,da,18,a2,d6,e6,a5,c5,c6,e0,b7,1a,9c,c8,70,f7,de,d4,54,22,a8,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-6636-c91b-6095fa0881df}\InprocServer32*]
"Class"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-6e26-b11c-3015fa0881df}\InprocServer32*]
"Class"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-6f17-c4cf-3ea4fa0881df}\InprocServer32*]
"Class"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-7c74-c331-6118fa0881df}\InprocServer32*]
"Class"=hex:00,6d,78,af,8e,b4,c4,17,0d,65,d8,5a,38,fb,be,e6,2f,8e,89,d1,8e,02,
54,5e,95,6e,74,67,f4,3e,de,b1,ca,82,ab,ce,60,43,ae,c2,54,81,2e,60,f2,26,2a,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-7f38-c99b-f006fa0881df}\InprocServer32*]
"Class"=hex:89,da,99,86,00,20,ba,1a,0b,25,73,fb,c0,a4,b3,0a,6e,4f,c7,08,79,c4,
d1,83,39,9c,db,89,9d,f2,49,60,5c,1f,96,f0,be,29,fa,4e,76,f3,eb,fa,6e,f6,eb,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-99e4-1168-679dfa0881df}\InprocServer32*]
"Class"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-af5c-ec88-46a0fa0881df}\InprocServer32*]
"Class"=hex:e0,87,86,cb,2c,02,0d,e2,e4,2d,5f,b7,cc,39,20,ae,75,dd,d6,b4,27,7e,
88,a3,95,7b,a8,60,04,6e,49,6d,c2,61,b4,4e,e4,fa,0e,8e,5d,e4,9e,e3,2c,8f,95,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-bcd3-c197-9e28fa0881df}\InprocServer32*]
"Class"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C09C5BC9-8988-caf3-6d62-7c91fa0881df}\InprocServer32*]
"Class"=hex:62,d9,7b,80,32,b6,7f,b4,72,cc,ad,10,b5,81,92,8c,f4,2d,3f,f2,17,44,
72,ff,30,bf,6d,7f,b6,a7,14,b7,e4,dc,27,c8,a4,ed,83,e5,c2,49,5d,bc,c1,fa,a0,\
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
.
[HKEY_LOCAL_MACHINE\software\PSGuard.com\PSGuard\P.S.Guard\License*]
"Data"="InstallTime=1c5c537:93680c70\0d\0aLastRunTime=1c5c539:45626050\0d\0a"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(660)
c:\programme\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'lsass.exe'(716)
c:\programme\Avira\AntiVir Desktop\avsda.dll
.
- - - - - - - > 'explorer.exe'(3128)
c:\progra~1\GEMEIN~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1031\GrooveIntlResource.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\programme\Avira\AntiVir Desktop\avguard.exe
c:\programme\Avira\AntiVir Desktop\avshadow.exe
c:\programme\Gemeinsame Dateien\Acronis\Schedule2\schedul2.exe
c:\windows\system32\CTsvcCDA.exe
c:\programme\Java\jre6\bin\jqs.exe
c:\programme\Gemeinsame Dateien\Nero\Nero BackItUp 4\NBService.exe
c:\programme\Sunbelt Software\CounterSpy\SBCSSvc.exe
c:\progra~1\SQUEEZ~2\server\Bin\MSWIN3~1\mysqld.exe
c:\programme\Gemeinsame Dateien\Acronis\Fomatik\TrueImageTryStartService.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\MICROS~3\rapimgr.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-08-30 21:31:09 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2011-08-30 19:31
ComboFix2.txt 2007-09-07 16:21
.
Vor Suchlauf: 17 Verzeichnis(se), 21.577.994.240 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 21.583.536.128 Bytes frei
.
WindowsXP-KB310994-SP2-Home-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect
.
- - End Of File - - C430AB272156B5FD96A200FE93017425 Und nu?
Gruß
Heini |