MisterFlames | 22.08.2008 18:37 | also schonmal nr1 Code:
SDFix: Version 1.218
Run by Martin on 22.08.2008 at 19:17
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Restoring Default Desktop Wallpaper
Restoring Default ScreenSaver value
Rebooting Checking Files :
Trojan Files Found:
C:\WINDOWS\system32\lphctg7j0eaae.exe - Deleted
C:\WINDOWS\SYSTEM32\PHCTG7~1.BMP - Deleted
C:\WINDOWS\system32\blphctg7j0eaae.scr - Deleted
C:\WINDOWS\EBAN.EXE - Deleted
C:\DOKUME~1\Martin\LOKALE~1\Temp\privacy_danger\index.htm - Deleted
C:\DOKUME~1\Martin\LOKALE~1\Temp\privacy_danger\images\capt.gif - Deleted
C:\DOKUME~1\Martin\LOKALE~1\Temp\privacy_danger\images\danger.jpg - Deleted
C:\DOKUME~1\Martin\LOKALE~1\Temp\privacy_danger\images\down.gif - Deleted
C:\DOKUME~1\Martin\LOKALE~1\Temp\privacy_danger\images\spacer.gif - Deleted
C:\Dokumente und Einstellungen\Martin\Lokale Einstellungen\Temp\ubi15.tmp.exe - Deleted
C:\Dokumente und Einstellungen\Martin\Favoriten\Error Cleaner.url - Deleted
C:\Dokumente und Einstellungen\Martin\Favoriten\Privacy Protector.url - Deleted
C:\Dokumente und Einstellungen\Martin\Favoriten\Spyware&Malware Protection.url - Deleted
C:\WINDOWS\mslagent\2_mslagent.dll - Deleted
C:\WINDOWS\mslagent\mslagent.exe - Deleted
C:\WINDOWS\mslagent\uninstall.exe - Deleted
C:\Programme\akl\akl.dll - Deleted
C:\Programme\akl\akl.exe - Deleted
C:\Programme\akl\uninstall.exe - Deleted
C:\Programme\akl\unsetup.exe - Deleted
C:\Programme\Inet Delivery\inetdl.exe - Deleted
C:\Programme\Inet Delivery\intdel.exe - Deleted
C:\DOKUME~1\Martin\LOKALE~1\Temp\.tt4C.tmp - Deleted
C:\DOKUME~1\Martin\LOKALE~1\Temp\.tt4E.tmp - Deleted
C:\DOKUME~1\Martin\LOKALE~1\Temp\sfsrv.exe.bat - Deleted
C:\WINDOWS\a.bat - Deleted
C:\WINDOWS\wnlmdakqnwt.dll - Deleted
C:\WINDOWS\zip1.tmp - Deleted
C:\WINDOWS\zip2.tmp - Deleted
C:\WINDOWS\zip3.tmp - Deleted
C:\WINDOWS\zipped.tmp - Deleted
C:\DOKUME~1\Martin\LOKALE~1\Temp\s1265.php.bat - Deleted
C:\WINDOWS\a.bat - Deleted
C:\WINDOWS\base64.tmp - Deleted
C:\WINDOWS\bdn.com - Deleted
C:\WINDOWS\bgrqfetx.dll - Deleted
C:\WINDOWS\FVProtect.exe - Deleted
C:\WINDOWS\iTunesMusic.exe - Deleted
C:\WINDOWS\lnvegaow.exe - Deleted
C:\WINDOWS\mssecu.exe - Deleted
C:\WINDOWS\system32\akttzn.exe - Deleted
C:\WINDOWS\system32\anticipator.dll - Deleted
C:\WINDOWS\system32\awtoolb.dll - Deleted
C:\WINDOWS\system32\bdn.com - Deleted
C:\WINDOWS\system32\bsva-egihsg52.exe - Deleted
C:\WINDOWS\system32\dpcproxy.exe - Deleted
C:\WINDOWS\system32\emesx.dll - Deleted
C:\WINDOWS\system32\h@tkeysh@@k.dll - Deleted
C:\WINDOWS\system32\hoproxy.dll - Deleted
C:\WINDOWS\system32\hxiwlgpm.dat - Deleted
C:\WINDOWS\system32\hxiwlgpm.exe - Deleted
C:\WINDOWS\system32\medup012.dll - Deleted
C:\WINDOWS\system32\medup020.dll - Deleted
C:\WINDOWS\system32\msgp.exe - Deleted
C:\WINDOWS\system32\msnbho.dll - Deleted
C:\WINDOWS\system32\mssecu.exe - Deleted
C:\WINDOWS\system32\msvchost.exe - Deleted
C:\WINDOWS\system32\mtr2.exe - Deleted
C:\WINDOWS\system32\mwin32.exe - Deleted
C:\WINDOWS\system32\netode.exe - Deleted
C:\WINDOWS\system32\newsd32.exe - Deleted
C:\WINDOWS\system32\ps1.exe - Deleted
C:\WINDOWS\system32\psof1.exe - Deleted
C:\WINDOWS\system32\psoft1.exe - Deleted
C:\WINDOWS\system32\regc64.dll - Deleted
C:\WINDOWS\system32\regm64.dll - Deleted
C:\WINDOWS\system32\Rundl1.exe - Deleted
C:\WINDOWS\system32\sncntr.exe - Deleted
C:\WINDOWS\system32\ssurf022.dll - Deleted
C:\WINDOWS\system32\ssvchost.com - Deleted
C:\WINDOWS\system32\ssvchost.exe - Deleted
C:\WINDOWS\system32\sysreq.exe - Deleted
C:\WINDOWS\system32\taack.dat - Deleted
C:\WINDOWS\system32\taack.exe - Deleted
C:\WINDOWS\system32\temp#01.exe - Deleted
C:\WINDOWS\system32\thun.dll - Deleted
C:\WINDOWS\system32\thun32.dll - Deleted
C:\WINDOWS\system32\VBIEWER.OCX - Deleted
C:\WINDOWS\system32\vbsys2.dll - Deleted
C:\WINDOWS\system32\vcatchpi.dll - Deleted
C:\WINDOWS\system32\winlogonpc.exe - Deleted
C:\WINDOWS\system32\winsystem.exe - Deleted
C:\WINDOWS\system32\WINWGPX.EXE - Deleted
C:\WINDOWS\tfnslopk.dll - Deleted
C:\WINDOWS\userconfig9x.dll - Deleted
C:\WINDOWS\winsystem.exe - Deleted
C:\WINDOWS\xokvrpwg.dll - Deleted
Folder C:\DOKUME~1\Martin\LOKALE~1\Temp\privacy_danger - Removed
Folder C:\Programme\akl - Removed
Folder C:\Programme\Inet Delivery - Removed
Folder C:\WINDOWS\mslagent - Removed
Removing Temp Files ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-22 19:32:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:57,9e,91,d2,56,d7,ed,80,45,03,1f,ff,8c,5c,d1,d6,d8,3c,23,49,7c,..
"p0"="C:\Programme\DAEMON Tools Lite\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,53,76,f1,3e,39,ab,84,ea,47,d9,c4,9d,65,10,d5,4c,d5,..
"khjeh"=hex:36,aa,47,af,8a,9e,0e,1a,0c,ce,54,e2,d1,ab,b1,9d,be,90,db,19,fa,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:9d,93,ef,48,1b,38,f5,8e,c9,ea,55,b0,7a,3d,2a,29,0a,db,f9,85,65,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:57,9e,91,d2,56,d7,ed,80,45,03,1f,ff,8c,5c,d1,d6,d8,3c,23,49,7c,..
"p0"="C:\Programme\DAEMON Tools Lite\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,53,76,f1,3e,39,ab,84,ea,47,d9,c4,9d,65,10,d5,4c,d5,..
"khjeh"=hex:36,aa,47,af,8a,9e,0e,1a,0c,ce,54,e2,d1,ab,b1,9d,be,90,db,19,fa,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:9d,93,ef,48,1b,38,f5,8e,c9,ea,55,b0,7a,3d,2a,29,0a,db,f9,85,65,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0 Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:enabled:Remoteuntersttzung"
"C:\\Programme\\Messenger\\msmsgs.exe"="C:\\Programme\\Messenger\\msmsgs.exe:*:enabled:Windows Messenger"
"C:\\Programme\\AOL 9.0\\AOL.exe"="C:\\Programme\\AOL 9.0\\AOL.exe:*:enabled:AOL 9.0"
"C:\\Programme\\AOL 9.0\\WAOL.exe"="C:\\Programme\\AOL 9.0\\WAOL.exe:*:enabled:AOL 9.0"
"C:\\Programme\\Gemeinsame Dateien\\AOL\\ACS\\AOLACSD.exe"="C:\\Programme\\Gemeinsame Dateien\\AOL\\ACS\\AOLACSD.exe:*:enabled:AOL 9.0 (Connectivity Service)"
"C:\\Programme\\Gemeinsame Dateien\\AOL\\ACS\\AOLDIAL.exe"="C:\\Programme\\Gemeinsame Dateien\\AOL\\ACS\\AOLDIAL.exe:*:enabled:AOL 9.0 (Connectivity Service Dialer)"
"C:\\WINDOWS\\system32\\fxsclnt.exe"="C:\\WINDOWS\\system32\\fxsclnt.exe:*:enabled:Microsoft Fax"
"C:\\Programme\\CA\\eTrust Antivirus\\InocIT.exe"="C:\\Programme\\CA\\eTrust Antivirus\\InocIT.exe:*:enabled:eTrust Antivirus - Local Scanner"
"C:\\Programme\\CA\\eTrust Antivirus\\Realmon.exe"="C:\\Programme\\CA\\eTrust Antivirus\\Realmon.exe:*:enabled:eTrust Antivirus - Realtime monitor"
"C:\\Programme\\CA\\eTrust Antivirus\\InoRpc.exe"="C:\\Programme\\CA\\eTrust Antivirus\\InoRpc.exe:*:enabled:eTrust Antivirus - RPC Server"
"C:\\Programme\\NetMeeting\\Conf.exe"="C:\\Programme\\NetMeeting\\Conf.exe:*:enabled:NetMeeting"
"C:\\Programme\\Ahead\\Nero MediaHome\\NeroMediaHome.exe"="C:\\Programme\\Ahead\\Nero MediaHome\\NeroMediaHome.exe:*:enabled:Nero MediaHome"
"C:\\Sierra\\EE-ZDE\\EE-AOC.exe"="C:\\Sierra\\EE-ZDE\\EE-AOC.exe:*:Enabled:EE-AOC"
"C:\\Programme\\ICQLite\\ICQLite.exe"="C:\\Programme\\ICQLite\\ICQLite.exe:*:Enabled:ICQ Lite"
"C:\\Programme\\Ascaron Entertainment\\Sacred Underworld\\sacred.exe"="C:\\Programme\\Ascaron Entertainment\\Sacred Underworld\\sacred.exe:*:Enabled:Sacred"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Eine DLL-Datei als Anwendung ausfhren"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Programme\\Electronic Arts\\Die Schlacht um Mittelerde II\\game.dat"="C:\\Programme\\Electronic Arts\\Die Schlacht um Mittelerde II\\game.dat:*:Enabled:Die Schlacht um MittelerdeT II"
"C:\\Programme\\Ascaron Entertainment\\Sacred Underworld\\gameserver.exe"="C:\\Programme\\Ascaron Entertainment\\Sacred Underworld\\gameserver.exe:*:Enabled:Sacred Gameserver"
"C:\\Programme\\Electronic Arts\\Die Schlacht um Mittelerde II\\patchget.dat"="C:\\Programme\\Electronic Arts\\Die Schlacht um Mittelerde II\\patchget.dat:*:Enabled:patchgrabber"
"C:\\Programme\\iTunes\\iTunes.exe"="C:\\Programme\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Programme\\America's Army\\System\\ArmyOps.exe"="C:\\Programme\\America's Army\\System\\ArmyOps.exe:*:Enabled:ArmyOps"
"C:\\Programme\\audioGnome\\Client4.exe"="C:\\Programme\\audioGnome\\Client4.exe:*:Disabled:Client4"
"C:\\Programme\\eMule\\eMule.exe"="C:\\Programme\\eMule\\eMule.exe:*:Enabled:eMule Plus"
"C:\\Programme\\BitTorrent\\bittorrent.exe"="C:\\Programme\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Programme\\Silkroad\\SilkErrSender.exe"="C:\\Programme\\Silkroad\\SilkErrSender.exe:*:Enabled:FTPSender MFC ?? ????"
"C:\\Games\\FreeSpace2\\FS2.exe"="C:\\Games\\FreeSpace2\\FS2.exe:*:Enabled:FreeSpace"
"C:\\Programme\\THQ\\Titan Quest\\Titan Quest.exe"="C:\\Programme\\THQ\\Titan Quest\\Titan Quest.exe:*:Enabled:Titan Quest"
"C:\\Programme\\Warez\\Warez.exe"="C:\\Programme\\Warez\\Warez.exe:*:Enabled:Warez3"
"C:\\Programme\\Gemeinsame Dateien\\PocketSoft\\RTPatch\\AutoRTP\\artpschd.exe"="C:\\Programme\\Gemeinsame Dateien\\PocketSoft\\RTPatch\\AutoRTP\\artpschd.exe:*:Enabled:artpschd"
"C:\\Dokumente und Einstellungen\\Martin\\Lokale Einstellungen\\Temporary Internet Files\\Content.IE5\\OLMNOPUN\\CabalTemp\\ESTdnheadless.exe"="C:\\Dokumente und Einstellungen\\Martin\\Lokale Einstellungen\\Temporary Internet Files\\Content.IE5\\OLMNOPUN\\CabalTemp\\ESTdnheadless.exe:*:Enabled:EST! download engine"
"C:\\Dokumente und Einstellungen\\Martin\\Desktop\\andere\\srobot.exe"="C:\\Dokumente und Einstellungen\\Martin\\Desktop\\andere\\srobot.exe:*:Enabled:HookSrv"
"C:\\Dokumente und Einstellungen\\Martin\\Desktop\\Wichtig!\\LittleFighter2\\LF2_v1.9\\lf2.exe"="C:\\Dokumente und Einstellungen\\Martin\\Desktop\\Wichtig!\\LittleFighter2\\LF2_v1.9\\lf2.exe:*:Enabled:lf2"
"C:\\Programme\\LittleFighter2\\LF2_v1.9\\lf2.exe"="C:\\Programme\\LittleFighter2\\LF2_v1.9\\lf2.exe:*:Enabled:lf2"
"C:\\Programme\\Hamachi\\hamachi.exe"="C:\\Programme\\Hamachi\\hamachi.exe:*:Enabled:Hamachi Client"
"C:\\Programme\\metal oxide software\\Downhill PAKOON! 2.Many Unlimited 2009\\Pakoon2.exe"="C:\\Programme\\metal oxide software\\Downhill PAKOON! 2.Many Unlimited 2009\\Pakoon2.exe:*:Disabled:downhill Pakoon2.MANY unlimited 2009"
"C:\\WINDOWS\\system32\\dpnsvr.exe"="C:\\WINDOWS\\system32\\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8-Server"
"C:\\Programme\\Microsoft Games\\Dungeon Siege\\DungeonSiege.exe"="C:\\Programme\\Microsoft Games\\Dungeon Siege\\DungeonSiege.exe:*:Enabled:Dungeon Siege Game Executable"
"C:\\Programme\\Metin2\\metin2.bin"="C:\\Programme\\Metin2\\metin2.bin:*:Enabled:metin2"
"C:\\WINDOWS\\system32\\msmsgs.exe"="C:\\WINDOWS\\system32\\msmsgs.exe:*:Disabled:msmsgs"
"C:\\Dokumente und Einstellungen\\Martin\\Lokale Einstellungen\\Temporary Internet Files\\Content.IE5\\4NLRIY7P\\Intel%20chiputil[1].exe"="C:\\Dokumente und Einstellungen\\Martin\\Lokale Einstellungen\\Temporary Internet Files\\Content.IE5\\4NLRIY7P\\Intel%20chiputil[1].exe:*:Enabled:ChipUtil"
"C:\\Programme\\THQ\\Titan Quest Immortal Throne\\Tqit.exe"="C:\\Programme\\THQ\\Titan Quest Immortal Throne\\Tqit.exe:*:Enabled:Tqit"
"C:\\Programme\\Microsoft Games\\Age of Mythology\\aomx.exe"="C:\\Programme\\Microsoft Games\\Age of Mythology\\aomx.exe:*:Enabled:Age of Mythology - The Titans Expansion"
"C:\\Dokumente und Einstellungen\\Martin\\Lokale Einstellungen\\Temp\\Rar$EX00.844\\volley.exe"="C:\\Dokumente und Einstellungen\\Martin\\Lokale Einstellungen\\Temp\\Rar$EX00.844\\volley.exe:*:Enabled:volley"
"C:\\Dokumente und Einstellungen\\Martin\\Desktop\\SPIELE\\andere spiele\\Blobby\\volley.exe"="C:\\Dokumente und Einstellungen\\Martin\\Desktop\\SPIELE\\andere spiele\\Blobby\\volley.exe:*:Enabled:volley"
"C:\\Programme\\ICQ6\\ICQ.exe"="C:\\Programme\\ICQ6\\ICQ.exe:*:Enabled:ICQ6"
"C:\\Programme\\Xfire\\xfire.exe"="C:\\Programme\\Xfire\\xfire.exe:*:Enabled:Xfire"
"C:\\Programme\\Ascaron Entertainment\\Sacred\\sacred.exe"="C:\\Programme\\Ascaron Entertainment\\Sacred\\sacred.exe:*:Enabled:Sacred"
"C:\\Programme\\Ascaron Entertainment\\Sacred\\GameServer.exe"="C:\\Programme\\Ascaron Entertainment\\Sacred\\GameServer.exe:*:Enabled:Sacred Gameserver"
"C:\\Programme\\Firefly Studios\\Stronghold 2\\Stronghold2.exe"="C:\\Programme\\Firefly Studios\\Stronghold 2\\Stronghold2.exe:*:Enabled:Stronghold 2"
"C:\\Programme\\LittleFighter2_2\\LF2_v1.9\\lf2.exe"="C:\\Programme\\LittleFighter2_2\\LF2_v1.9\\lf2.exe:*:Enabled:lf2"
"C:\\Programme\\uTorrent\\uTorrent.exe"="C:\\Programme\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Dokumente und Einstellungen\\Martin\\Desktop\\GAMES\\andere spiele\\Blobby\\volley.exe"="C:\\Dokumente und Einstellungen\\Martin\\Desktop\\GAMES\\andere spiele\\Blobby\\volley.exe:*:Enabled:volley"
"C:\\Programme\\MSN Messenger\\msnmsgr.exe"="C:\\Programme\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Programme\\MSN Messenger\\livecall.exe"="C:\\Programme\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Programme\\Microsoft Games\\Age of Empires III\\age3.exe"="C:\\Programme\\Microsoft Games\\Age of Empires III\\age3.exe:*:Enabled:Age of Empires III"
"C:\\Programme\\Microsoft Games\\Age of Empires III\\age3x.exe"="C:\\Programme\\Microsoft Games\\Age of Empires III\\age3x.exe:*:Enabled:Age of Empires III - The WarChiefs"
"C:\\Programme\\Microsoft Games\\Age of Empires III\\age3y.exe"="C:\\Programme\\Microsoft Games\\Age of Empires III\\age3y.exe:*:Enabled:Age of Empires III - The Asian Dynasties"
"C:\\Dokumente und Einstellungen\\Martin\\Desktop\\GAMES\\Strategie\\Age of Empires II\\empires2.exe"="C:\\Dokumente und Einstellungen\\Martin\\Desktop\\GAMES\\Strategie\\Age of Empires II\\empires2.exe:*:Enabled:Age of Empires II"
"C:\\WINDOWS\\system32\\dplaysvr.exe"="C:\\WINDOWS\\system32\\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\\Programme\\Gravity\\Requiem\\system\\DebugSystem.exe"="C:\\Programme\\Gravity\\Requiem\\system\\DebugSystem.exe:*:Enabled:DebugSystem"
"C:\\Programme\\Glest_3.1.2\\glest.exe"="C:\\Programme\\Glest_3.1.2\\glest.exe:*:Enabled:glest"
"C:\\Games\\Fussball Challenge 2008 (SPORT1)\\Game.exe"="C:\\Games\\Fussball Challenge 2008 (SPORT1)\\Game.exe:*:Enabled:Game"
"C:\\Programme\\Ubisoft\\Splinter Cell Pandora Tomorrow\\pandora.exe"="C:\\Programme\\Ubisoft\\Splinter Cell Pandora Tomorrow\\pandora.exe:*:Enabled:pandora"
"C:\\Programme\\TmNationsForever\\TmForever.exe"="C:\\Programme\\TmNationsForever\\TmForever.exe:*:Enabled:TmForever"
"C:\\Programme\\Freeciv-2.1.4-win32\\civserver.exe"="C:\\Programme\\Freeciv-2.1.4-win32\\civserver.exe:*:Enabled:civserver"
"C:\\Programme\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jamp.exe"="C:\\Programme\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jamp.exe:*:Enabled:Jedi Academy MultiPlayer"
"C:\\Programme\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jampDed.exe"="C:\\Programme\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jampDed.exe:*:Enabled:Jedi Academy MP Dedicated Server"
"C:\\Programme\\LucasArts\\KotF Jedi Academy Expansion Pack\\GameData\\jamp.exe"="C:\\Programme\\LucasArts\\KotF Jedi Academy Expansion Pack\\GameData\\jamp.exe:*:Enabled:Jedi Academy MultiPlayer"
"C:\\Programme\\LucasArts\\Star Wars Empire at War\\GameData\\sweaw.exe"="C:\\Programme\\LucasArts\\Star Wars Empire at War\\GameData\\sweaw.exe:*:Enabled:Star Wars: Empire at War"
"C:\\Programme\\LucasArts\\Star Wars Empire at War Forces of Corruption\\swfoc.exe"="C:\\Programme\\LucasArts\\Star Wars Empire at War Forces of Corruption\\swfoc.exe:*:Enabled:Star Wars(TM): Empire at War(TM): Forces of Corruption(TM)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:enabled:Remoteuntersttzung"
"C:\\Programme\\Messenger\\msmsgs.exe"="C:\\Programme\\Messenger\\msmsgs.exe:*:enabled:Windows Messenger"
"C:\\Programme\\AOL 9.0\\AOL.exe"="C:\\Programme\\AOL 9.0\\AOL.exe:*:enabled:AOL 9.0"
"C:\\Programme\\AOL 9.0\\WAOL.exe"="C:\\Programme\\AOL 9.0\\WAOL.exe:*:enabled:AOL 9.0"
"C:\\Programme\\Gemeinsame Dateien\\AOL\\ACS\\AOLACSD.exe"="C:\\Programme\\Gemeinsame Dateien\\AOL\\ACS\\AOLACSD.exe:*:enabled:AOL 9.0 (Connectivity Service)"
"C:\\Programme\\Gemeinsame Dateien\\AOL\\ACS\\AOLDIAL.exe"="C:\\Programme\\Gemeinsame Dateien\\AOL\\ACS\\AOLDIAL.exe:*:enabled:AOL 9.0 (Connectivity Service Dialer)"
"C:\\WINDOWS\\system32\\fxsclnt.exe"="C:\\WINDOWS\\system32\\fxsclnt.exe:*:enabled:Microsoft Fax"
"C:\\Programme\\CA\\eTrust Antivirus\\InocIT.exe"="C:\\Programme\\CA\\eTrust Antivirus\\InocIT.exe:*:enabled:eTrust Antivirus - Local Scanner"
"C:\\Programme\\CA\\eTrust Antivirus\\Realmon.exe"="C:\\Programme\\CA\\eTrust Antivirus\\Realmon.exe:*:enabled:eTrust Antivirus - Realtime monitor"
"C:\\Programme\\CA\\eTrust Antivirus\\InoRpc.exe"="C:\\Programme\\CA\\eTrust Antivirus\\InoRpc.exe:*:enabled:eTrust Antivirus - RPC Server"
"C:\\Programme\\NetMeeting\\Conf.exe"="C:\\Programme\\NetMeeting\\Conf.exe:*:enabled:NetMeeting"
"C:\\Programme\\Ahead\\Nero MediaHome\\NeroMediaHome.exe"="C:\\Programme\\Ahead\\Nero MediaHome\\NeroMediaHome.exe:*:enabled:Nero MediaHome"
"C:\\Programme\\MSN Messenger\\msnmsgr.exe"="C:\\Programme\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Programme\\MSN Messenger\\livecall.exe"="C:\\Programme\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes :
Mon 10 May 2004 54,384 A..H. --- "C:\Programme\AOL 9.0\aolphx.exe"
Mon 10 May 2004 156,784 A..H. --- "C:\Programme\AOL 9.0\aoltray.exe"
Mon 10 May 2004 31,344 A..H. --- "C:\Programme\AOL 9.0\RBM.exe"
Mon 19 Jan 2004 428,544 A..H. --- "C:\Programme\AOL 9.0\StartSM.exe"
Wed 13 Oct 2004 1,694,208 ..SH. --- "C:\Programme\Messenger\msmsgs.exe"
Tue 28 Feb 2006 8 ..SHR --- "C:\WINDOWS\system32\7512B216B4.sys"
Sun 1 Jun 2008 56 ..SHR --- "C:\WINDOWS\system32\7B2B38A438.sys"
Sun 1 Jun 2008 5,018 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Tue 25 Apr 2006 4,348 A.SH. --- "C:\Dokumente und Einstellungen\All Users\DRM\DRMv1.bak"
Sun 28 May 2006 401 ..SH. --- "C:\Dokumente und Einstellungen\All Users\DRM\DRMv12.bak"
Tue 26 Dec 2006 401 ..SH. --- "C:\Dokumente und Einstellungen\All Users\DRM\DRMv13.bak"
Fri 29 Dec 2006 0 A.SH. --- "C:\Dokumente und Einstellungen\All Users\DRM\Cache\Indiv01.tmp"
Mon 13 Nov 2006 319,456 A..H. --- "C:\Programme\Gemeinsame Dateien\Motorola Shared\MotPCSDrivers\difxapi.dll"
Tue 25 Apr 2006 4,348 ...H. --- "C:\Dokumente und Einstellungen\Martin\Eigene Dateien\Eigene Musik\Lizenzsicherung\drmv1key.bak"
Tue 25 Apr 2006 20 A..H. --- "C:\Dokumente und Einstellungen\Martin\Eigene Dateien\Eigene Musik\Lizenzsicherung\drmv1lic.bak"
Tue 25 Apr 2006 312 A.SH. --- "C:\Dokumente und Einstellungen\Martin\Eigene Dateien\Eigene Musik\Lizenzsicherung\drmv2key.bak"
Tue 25 Apr 2006 4,348 ...H. --- "C:\Dokumente und Einstellungen\Martin\Eigene Dateien\Eigene Musik\Tokcicity\Lizenzsicherung\drmv1key.bak"
Tue 26 Dec 2006 782 A..H. --- "C:\Dokumente und Einstellungen\Martin\Eigene Dateien\Eigene Musik\Tokcicity\Lizenzsicherung\drmv1lic.bak"
Tue 25 Apr 2006 312 A.SH. --- "C:\Dokumente und Einstellungen\Martin\Eigene Dateien\Eigene Musik\Tokcicity\Lizenzsicherung\drmv2key.bak" Finished! hj kommt gleich (zu langer text deshalb schonma sry für doppelposts) |