Seite 1 von 3 1 2 3 LetzteLetzte
Zeige Ergebnis 1 bis 10 von 24

Thema: Internet Explorer öffnet sich selbst

  1. #1
    Einsteiger
    Registriert seit
    13.01.2010
    Beiträge
    15

    Internet Explorer öffnet sich selbst

    Hallo,

    sorry bin ganz neu hier - auf meinem Windows Vista Pc kann ich
    für Windows keine Updates mehr vornehmen und es öffnet sich im Hintergrund immer wieder der Internet Explorer - spielt Werbespots ab etc.

    Hier mal mein Logfile - wer kann mir helfen ??

    Code:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:57:07, on 13.01.2010
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v8.00 (8.00.6001.18865)
    Boot mode: Normal
    
    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\rundll32.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\ASUS\ATK Media\DMedia.exe
    C:\Windows\System32\ASUSTPE.exe
    C:\Program Files\PowerForPhone\PowerForPhone.exe
    C:\Program Files\AnNoText GmbH\DictaPlus\bin\WK.MobileDevices.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\pvws\bin\w3dbsmgr.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\ASUS\ASUS Live Update\ALU.exe
    C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe
    C:\Windows\System32\rundll32.exe
    C:\ProgramData\AnNoText GmbH\DictaPlus\SpeechMagic Server\BIN\SmCtxSysTask.ngn
    C:\ProgramData\AnNoText GmbH\DictaPlus\SpeechMagic Server\BIN\SmPurgeSysTask.ngn
    C:\ProgramData\AnNoText GmbH\DictaPlus\SpeechMagic Server\BIN\SmRcgSysTask.ngn
    C:\ProgramData\AnNoText GmbH\DictaPlus\SpeechMagic Server\BIN\SmIPCSrv.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\totalcmd\TOTALCMD.EXE
    C:\Program Files\Internet Explorer\Iexplore.exe
    D:\Schrott\Malware\HijackThis.exe
    
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
    O1 - Hosts: ::1 localhost
    O1 - Hosts: server-rae.rae.local 192.168.0.1
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [Skytel] Skytel.exe
    O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
    O4 - HKLM\..\Run: [ASUSTPE] C:\Windows\system32\ASUSTPE.exe
    O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe
    O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
    O4 - HKLM\..\Run: [WKMobileDevices] "C:\Program Files\AnNoText GmbH\DictaPlus\bin\wk.MobileDevices.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
    O4 - HKUS\S-1-5-21-3480036674-3622741497-2829454337-1002\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'WKSMService')
    O4 - Startup: logonuser.bat
    O4 - Global Startup: Pervasive.SQL Workgroup Engine.lnk = C:\pvws\bin\w3dbsmgr.exe
    O4 - Global Startup: VR-NetWorld Auftragsprüfung.lnk = ?
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
    O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
    O13 - Gopher Prefix: 
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
    O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
    O23 - Service: AnNoText Updater Service (AT_LOADER_SERVICE) - AnNoText GmbH - C:\Program Files\AnNoText GmbH\AnNoText\updater\anoldrsv.exe
    O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: DictaPlus Ausgangsdienst (DictaPlus.OutboxService) - AnNoText GmbH - C:\Program Files\AnNoText GmbH\DictaPlus\bin\WK.OutboxService.exe
    O23 - Service: DictaPlus 3rd Party Communication (DictaPlus.ThirdPartyCommunication) - AnNoText GmbH - C:\Program Files\AnNoText GmbH\DictaPlus\bin\WK.ThirdPartyCommunication.exe
    O23 - Service: DictaPlus Workflow-Server (DictaPlus.WorkflowServer) - AnNoText GmbH - C:\Program Files\AnNoText GmbH\DictaPlus\bin\WK.WorkflowServer.exe
    O23 - Service: Google Update Service (gupdate1c98c328ab4244a) (gupdate1c98c328ab4244a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
    O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
    O23 - Service: SpeechMagic - Philips Speech Recognition Systems GmbH - C:\ProgramData\AnNoText GmbH\DictaPlus\SpeechMagic Server\BIN\SmNTService.exe
    
    --
    End of file - 8315 bytes
    Geändert von kira (13.01.2010 um 20:22 Uhr) Grund: Logfile in Code-Tags gesetzt

  2. #2
    Moderator Team-Mitglied Benutzerbild von kira
    Registriert seit
    28.03.2006
    Ort
    Wien/Sprachen: Deutsch-Ungarisch
    Beiträge
    25.767

    AW: Internet Explorer öffnet sich selbst

    Herzlich Willkommen hier bei uns am HijackThis Supportboard!

    **BITTE VOR DEM ERSTEN POST SORGFÄLTIG DURCHLESEN!:

    Deine persönlichen Angaben/Daten (die persönliche Merkmale enthalten, wie Name, Seriennummer etc) kannst Du aus dem geposteten Logs heraus löschen
    Wir helfen dir gerne, aber WIR verwenden dafür unsere Freizeit, daher bitten Dich um ein wenig Geduld! (kann es sein, dass Du auf eine Antwort 1-2 Tage warten musst, aber WIR werden uns bemühen, sie so rasch als möglich zu beantworten...*die Geduld lohnt sich* *Alle Ratsuchenden!*
    Ein System zu bereinigen kann ein paar Tage dauern (je nach Art der Infektion), kann aber sogar so stark kompromittiert sein, so dass eine wirkungsvolle technische Säuberung ist nicht mehr möglich bzw Du es neu installieren musst
    WENN DIR GEHOLFEN WERDEN SOLL, tue bitte NUR das, was man dir vorschlägt! So lange die Reinigungsarbeiten noch nicht abgeschlossen ist, alle Eigenaktion (= Ausführung/Installation von Scans/Removals außer zur Nutzung die von uns empfohlenen Programme/Tools etc) untersagt.→ Bei Probleme nochmal nachfragen!
    Kein Support per Email oder sonstiges! Fragen bitte im Forum stellen!→*Forenregeln* - bitte lesen!
    ANWEISUNGEN UND DEREN BEFOLGUNG, ERFOLGT AUF DEINE EIGENE VERANTWORTUNG!
    Wichtig: Du kannst deine Beiträge jederzeit (auf klicken) ändern, Du musst eingeloggt sein!
    Wir freuen uns über jede Spende, und keine ist zu gering! Falls Du unser Forum unterstützen möchtest, klick *hier*
    Also kann losgeh`n, ich/wir wünsche/n eine gute Zusammenarbeit mit Dir und erfolgreiche gute Einsätze
    Grundsätzlich muss ein infiziertes System als kompromittiert gelten, und man kann nie ganz sicher sein, dass man alle Folgen der Infektion beseitigen konnte. - Sicherheitskonzept v. SETI@home/Punkt 1.
    Falls du doch für die Systemreinigung entscheidest:
    Können wir versuchen dein PC von Viren zu befreien, aber nur "bis zu einem gewissen Punkt", wo dein System technisch auch noch einwandfrei funktioniert

    Bitte lese Dir zuerst in Ruhe die Anweisungen durch und Du sollst dabei die Reihenfolge einhalten! Ansonsten verlangsamt unsere Arbeit, wenn wir immer wieder noch an Kleinigkeiten nachschlagen müssen und dadurch eventuell die Übersicht verloren geht...

    Wichtig: Alle Befehle bitte als Administrator ausführen! rechte Maustaste auf die Eingabeaufforderung und "als Administrator ausführen" auswählen

    1.
    Um einen tieferen Einblick in dein System, um eine mögliche Infektion mit einem Rootkit/Info v.wikipedia.org) aufzuspüren, werden wir ein Tool - Gmer - einsetzen :
    • Also lade dir Gmer von *dieser Seite* oder von hier majorgeeks.com/gmer.zip - runter und entpacke es auf deinen Desktop.
    • "Show all" soll nicht angehakt sein!
    • Starte gmer.exe. Alle anderen Programme sollen geschlossen sein.
    • Starte den Scan mit "Scan". Mache nichts am Computer während der Scan läuft.
    • Wenn der Scan fertig ist klicke auf "Copy" um das Log in die Zwischenablage zu kopieren. Mit "Ok" wird Gmer beendet.
    • Füge das Log aus der Zwischenablage in deine Antwort hier ein.
    Wichtig: während des Scan-Vorgangs sollen:Scanner wieder einschalten, bevor Du ins Netz gehst!

    2.
    Zunächst bitte folgende Einstellungen vornehmen: System-Dateien und -Ordner unter XP, Vista und Win7 sichtbar machen
    Am Ende unserer Arbeit, kannst wieder rückgängig machen!

    3.
    Lade dir HJTscanlist.zip. -(Punkt 5) herunter ( den angegebenen Link anklicken ► Punkt 5. aussuchen ► Anweisungen folgen) anschließend das erhaltene Logfile hier posten.

    4.
    • Download den CCleaner
    • installieren,("Füge CCleaner Yahoo! Toolbar hinzu" - kannst Du abwählen!)--> starten --> unter Options settings --> "german" einstellen.
    • starten--> klick auf `Extras` (um auf deinem System installierte Software zu anzeigen)--> dann auf `Als Textdatei speichern...`
    • poste auch dieses Logfile (also die Liste alle installierten Programme...eine Textdatei)
    • Anleitung

    Bitte alle Ergebnisse im Code-Tags posten!

    vor dein log schreibst du:[code]
    hier kommt dein logfile rein
    dahinter:[/code]
    -----------------------
    Bitte den Rechner vom Netz trennen, wenn er unbeaufsichtigt ist.
    Bis zu einer eventuellen Reinigung oder dem Formatieren deines Systems
    kein Online-Banking, File-sharing, Mailing, Messaging betreiben.
    Keine Up und Downloads, ausser auf Security Seiten.
    ****Ehemöglichst nicht ins internet gehen
    Mehr Information hierzu unter System-Sicherheit

    -----------------------

    gruß
    argos
    Neuaufsetzen (Windows XP, Vista und Windows 7) - Anleitungen
    Virenscanner
    Wie man seinen Rechner von Viren befreit

    *Der beste Schutz ist immer noch der verantwortungsvolle Umgang mit dem Internet!*

  3. #3
    Einsteiger
    Registriert seit
    13.01.2010
    Beiträge
    15

    AW: Internet Explorer öffnet sich selbst

    Hallo argos,

    habe Punkt 1 ausgeführt - lief über 30 Minuten durch, dann ist das
    System ausgestiegen und hat den PC runtergefahren

    folgende Fehlermeldung/analyse:

    Product: 256_1

    Dateien, die bei der Beschreibung des Problems hilfreich sind:
    C:\Windows\Minidump\Mini011310-01.dmp
    C:\Users\Standke\AppData\Local\Temp\WER-54194-0.sysdata.xml
    C:\Users\Standke\AppData\Local\Temp\WER3FFC.tmp.version.txt

    Lesen Sie unsere Datenschutzrichtlinie:
    http://go.microsoft.com/fwlink/?link...3&clcid=0x0407

  4. #4
    Einsteiger
    Registriert seit
    13.01.2010
    Beiträge
    15

    AW: Internet Explorer öffnet sich selbst

    Code:
     
                            $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ 
                            º                                    º 
                                        hjtscanlist v2.0              
                            º                                    º 
                            $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ 
    
    Microsoft Windows [Version 6.0.6001]
     
     
    C:
    
           C:\hiberfil.sys ---------    
           C:\pagefile.sys ---------    
      13.01.2010 21:31     C:\Windows --------- 40960   
      11.01.2010 17:25     C:\MA1 --------- 4096   
      11.01.2010 11:50     C:\ProgramData --------- 8192   
      05.01.2010 00:21     C:\Program Files --------- 20480   
      01.01.2010 14:55     C:\System Volume Information --------- 32768   
      06.04.2009 13:16     C:\MA112 --------- 0   
      06.04.2009 10:35     C:\Ma --------- 0   
      25.02.2009 20:16     C:\Acarsoy --------- 4096   
      25.02.2009 18:47     C:\MA12 --------- 0   
      01.01.2009 14:10     C:\IO.SYS --------- 0   
      01.01.2009 14:10     C:\MSDOS.SYS --------- 0   
      18.12.2008 16:53     C:\ctapi_out_gr.txt --------- 0   
      13.12.2008 15:55     C:\logonuser.bat --------- 615   
      13.12.2008 14:46     C:\ExportAkten12 --------- 0   
      13.12.2008 14:44     C:\Exportierte Akten --------- 0   
      13.12.2008 14:06     C:\Users --------- 4096   
      13.12.2008 12:57     C:\pvws --------- 4096   
      13.12.2008 11:46     C:\.rnd --------- 1024   
      13.12.2008 11:19     C:\totalcmd --------- 4096   
      13.12.2008 10:46     C:\setup.log --------- 178   
      13.12.2008 10:46     C:\ADSM_PData_0150 --------- 0   
      13.12.2008 10:33     C:\RHDSetup.log --------- 420   
      13.12.2008 10:29     C:\Debug.txt --------- 286720   
      13.12.2008 10:15     C:\$Recycle.Bin --------- 0   
      13.12.2008 10:12     C:\Programme --------- 0   
      13.12.2008 10:12     C:\Dokumente und Einstellungen --------- 0   
      13.12.2008 09:59     C:\BOOTSECT.BAK --------- 8192   
      13.12.2008 09:59     C:\Boot --------- 4096   
      21.01.2008 03:33     C:\PerfLogs --------- 0   
      21.01.2008 03:25     C:\bootmgr --------- 333203   
      02.11.2006 14:02     C:\Documents and Settings --------- 0   
      18.09.2006 22:43     C:\config.sys --------- 10   
      18.09.2006 22:43     C:\autoexec.bat --------- 24   
    ----------------------------------------
    
     
    C:\Windows
    
      13.01.2010 21:35     C:\Windows\WindowsUpdate.log --------- 1662779   
      13.01.2010 21:33     C:\Windows\pvsw.log --------- 1039576   
      13.01.2010 21:31     C:\Windows\bootstat.dat --------- 67584   
      13.01.2010 21:31     C:\Windows\MEMORY.DMP --------- 342731687   
      11.01.2010 17:27     C:\Windows\setupact.log --------- 128228   
      11.01.2010 11:52     C:\Windows\PFRO.log --------- 51170   
      31.12.2009 15:18     C:\Windows\NeroDigital.ini --------- 69   
      16.12.2009 15:12     C:\Windows\ANNOSPCH.INI --------- 34   
      25.11.2009 18:35     C:\Windows\msxml4-KB973688-enu.LOG --------- 273272   
      11.11.2009 17:10     C:\Windows\win.ini --------- 274   
      29.10.2009 07:32     C:\Windows\ie8_main.log --------- 2084   
      10.09.2009 07:29     C:\Windows\DirectX.log --------- 91899   
      15.07.2009 13:18     C:\Windows\bi_group.ini --------- 135   
      18.02.2009 18:02     C:\Windows\DPINST.LOG --------- 14812   
      01.01.2009 14:10     C:\Windows\OpPrintServer.INI --------- 0   
      21.12.2008 18:47     C:\Windows\ODBC.INI --------- 1050   
      13.12.2008 18:33     C:\Windows\msxml4-KB954430-enu.LOG --------- 278400   
      13.12.2008 15:37     C:\Windows\ODBCINST.INI --------- 772   
      13.12.2008 13:44     C:\Windows\KB893803v2.log --------- 554   
      13.12.2008 12:57     C:\Windows\psqlinst.log --------- 1678838   
      13.12.2008 12:57     C:\Windows\INSTALL.log --------- 1678838   
      13.12.2008 12:56     C:\Windows\DBNAMES.CFG --------- 49152   
      13.12.2008 12:55     C:\Windows\bti.ini --------- 184   
      13.12.2008 10:46     C:\Windows\ASScrPro.exe --------- 33136   
      13.12.2008 10:46     C:\Windows\ASScrProlog.exe --------- 37232   
      13.12.2008 10:46     C:\Windows\ASUS Camera ScreenSaver.exe --------- 4814371   
      13.12.2008 10:45     C:\Windows\ASUS Camera ScreenSaver Uninstaller.exe --------- 274800   
      13.12.2008 10:45     C:\Windows\Asus_Camera_ScreenSaver.scr --------- 503808   
      13.12.2008 10:45     C:\Windows\flashax.exe --------- 606848   
      13.12.2008 10:45     C:\Windows\impborl.dll --------- 12288   
      13.12.2008 10:33     C:\Windows\DIFxAPI.dll --------- 319456   
      13.12.2008 10:32     C:\Windows\HideWin.exe --------- 315392   
      13.12.2008 10:07     C:\Windows\TSSysprep.log --------- 1355   
      13.12.2008 10:02     C:\Windows\DtcInstall.log --------- 3257   
      01.11.2008 16:53     C:\Windows\logonuser.bat --------- 520   
      29.10.2008 07:29     C:\Windows\explorer.exe --------- 2927104   
      08.08.2008 07:04     C:\Windows\PKUNZIP.PIF --------- 545   
      08.08.2008 07:04     C:\Windows\LHA.PIF --------- 545   
      08.08.2008 07:04     C:\Windows\UC.PIF --------- 545   
      08.08.2008 07:04     C:\Windows\PKZIP.PIF --------- 545   
      08.08.2008 07:04     C:\Windows\RAR.PIF --------- 545   
      08.08.2008 07:04     C:\Windows\NOCLOSE.PIF --------- 545   
      08.08.2008 07:04     C:\Windows\ARJ.PIF --------- 545   
      14.07.2008 05:09     C:\Windows\CMDLIC.DLL --------- 212728   
      14.07.2008 05:09     C:\Windows\UNBOC.EXE --------- 205560   
      21.01.2008 03:43     C:\Windows\WindowsShell.Manifest --------- 749   
      21.01.2008 03:25     C:\Windows\regedit.exe --------- 134656   
      21.01.2008 03:25     C:\Windows\bfsvc.exe --------- 58880   
      21.01.2008 03:24     C:\Windows\fveupdate.exe --------- 13312   
      21.01.2008 03:24     C:\Windows\HelpPane.exe --------- 498176   
      21.01.2008 03:24     C:\Windows\notepad.exe --------- 151040   
      03.09.2007 06:29     C:\Windows\DrvInst.exe --------- 11776   
      06.07.2007 04:06     C:\Windows\RtHDVCpl.exe --------- 4669440   
      15.06.2007 09:45     C:\Windows\SkyTel.exe --------- 1826816   
      30.03.2007 11:00     C:\Windows\Uninst.bat --------- 304   
      28.03.2007 00:46     C:\Windows\Uninst.reg --------- 384   
      16.01.2007 03:39     C:\Windows\RtlUpd.exe --------- 1191936   
      12.01.2007 09:54     C:\Windows\RtlExUpd.dll --------- 520192   
      02.11.2006 13:52     C:\Windows\setuperr.log --------- 0   
      02.11.2006 13:47     C:\Windows\SETUPAPI.LOG --------- 94   
      02.11.2006 13:36     C:\Windows\WMSysPr9.prx --------- 316640   
      02.11.2006 13:35     C:\Windows\twunk_32.exe --------- 31232   
      02.11.2006 13:35     C:\Windows\twunk_16.exe --------- 49680   
      02.11.2006 13:35     C:\Windows\twain_32.dll --------- 50688   
      02.11.2006 13:35     C:\Windows\twain.dll --------- 94784   
      02.11.2006 10:45     C:\Windows\winhlp32.exe --------- 9216   
      02.11.2006 10:45     C:\Windows\hh.exe --------- 14848   
      02.11.2006 08:46     C:\Windows\mib.bin --------- 43131   
      19.09.2006 12:41     C:\Windows\Business.xml --------- 4261   
      18.09.2006 22:46     C:\Windows\system.ini --------- 219   
      18.09.2006 22:43     C:\Windows\_default.pif --------- 707   
      18.09.2006 22:43     C:\Windows\winhelp.exe --------- 256192   
      18.09.2006 22:30     C:\Windows\msdfmap.ini --------- 1405   
      21.02.2003 00:42     C:\Windows\msvcr71.dll --------- 348160   
      30.06.2002 19:40     C:\Windows\keyhh.exe --------- 19456   
      15.07.2000 00:00     C:\Windows\MSVCRTD.DLL --------- 434252   
      17.11.1998 13:44     C:\Windows\IsUn0407.exe --------- 328704   
      29.10.1998 17:45     C:\Windows\IsUninst.exe --------- 306688   
    ----------------------------------------
    
     
    C:\Windows\System
    
     02.11.2006 13:35      C:\Windows\System\mciwave.drv --------- 28160 
     02.11.2006 13:35      C:\Windows\System\mciseq.drv --------- 25264 
     02.11.2006 13:35      C:\Windows\System\avifile.dll --------- 109456 
     02.11.2006 13:35      C:\Windows\System\avicap.dll --------- 69584 
     02.11.2006 13:35      C:\Windows\System\mciavi.drv --------- 73376 
     02.11.2006 13:35      C:\Windows\System\msvideo.dll --------- 126912 
     02.11.2006 08:10      C:\Windows\System\OLESVR.DLL --------- 24064 
     02.11.2006 08:10      C:\Windows\System\WFWNET.DRV --------- 12704 
     02.11.2006 08:10      C:\Windows\System\COMMDLG.DLL --------- 32816 
     02.11.2006 08:10      C:\Windows\System\TIMER.DRV --------- 4048 
     02.11.2006 08:10      C:\Windows\System\MMSYSTEM.DLL --------- 68992 
     02.11.2006 08:10      C:\Windows\System\mmtask.tsk --------- 1152 
     02.11.2006 08:10      C:\Windows\System\mouse.drv --------- 2032 
     02.11.2006 08:10      C:\Windows\System\vga.drv --------- 2176 
     02.11.2006 08:10      C:\Windows\System\sound.drv --------- 1744 
     02.11.2006 08:10      C:\Windows\System\keyboard.drv --------- 2000 
     02.11.2006 08:10      C:\Windows\System\SHELL.DLL --------- 5120 
     02.11.2006 08:10      C:\Windows\System\system.drv --------- 3360 
     18.09.2006 22:43      C:\Windows\System\ver.dll --------- 9008 
     18.09.2006 22:43      C:\Windows\System\olecli.dll --------- 82944 
     18.09.2006 22:43      C:\Windows\System\lzexpand.dll --------- 9936 
     18.09.2006 22:35      C:\Windows\System\stdole.tlb --------- 5532 
     05.07.2004 21:07      C:\Windows\System\DriveIcon.dll --------- 83968 
    ----------------------------------------
    
     
    C:\Windows\System32
    
     13.01.2010 21:48     C:\Windows\system32\hjtscanlist.txt --------- 9303  
     13.01.2010 21:31     C:\Windows\system32\acovcnt.exe --------- 45056  
     13.01.2010 21:31     C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 --------- 3712  
     13.01.2010 21:31     C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 --------- 3712  
     13.01.2010 18:08     C:\Windows\system32\catroot --------- 0  
     13.01.2010 18:08     C:\Windows\system32\catroot2 --------- 4096  
     13.01.2010 18:08     C:\Windows\system32\MRT.INI --------- 118  
     13.01.2010 18:06     C:\Windows\system32\Tasks --------- 4096  
     11.01.2010 16:55     C:\Windows\system32\perfh009.dat --------- 87872  
     11.01.2010 16:55     C:\Windows\system32\perfc009.dat --------- 119502  
     11.01.2010 16:55     C:\Windows\system32\perfh007.dat --------- 668896  
     11.01.2010 16:55     C:\Windows\system32\perfc007.dat --------- 141268  
     11.01.2010 16:55     C:\Windows\system32\PerfStringBackup.INI --------- 1005634  
     11.01.2010 12:35     C:\Windows\system32\krl32mainweq.dll --------- 847  
     11.01.2010 11:50     C:\Windows\system32\drivers --------- 65536  
     05.01.2010 07:13     C:\Windows\system32\srcr.dat --------- 202  
     05.01.2010 01:17     C:\Windows\system32\mrt.exe --------- 29634504  
     05.01.2010 00:37     C:\Windows\system32\FNTCACHE.DAT --------- 262480  
     05.01.2010 00:34     C:\Windows\system32\lv-LV --------- 0  
     05.01.2010 00:34     C:\Windows\system32\XPSViewer --------- 0  
     05.01.2010 00:34     C:\Windows\system32\da-DK --------- 0  
     05.01.2010 00:34     C:\Windows\system32\hr-HR --------- 0  
     05.01.2010 00:34     C:\Windows\system32\et-EE --------- 0  
     05.01.2010 00:34     C:\Windows\system32\sk-SK --------- 0  
     05.01.2010 00:34     C:\Windows\system32\ko-KR --------- 0  
     05.01.2010 00:34     C:\Windows\system32\en-US --------- 8192  
     05.01.2010 00:34     C:\Windows\system32\de-DE --------- 196608  
     05.01.2010 00:34     C:\Windows\system32\it-IT --------- 0  
     05.01.2010 00:34     C:\Windows\system32\el-GR --------- 0  
     05.01.2010 00:34     C:\Windows\system32\oobe --------- 4096  
     05.01.2010 00:34     C:\Windows\system32\migration --------- 0  
     05.01.2010 00:34     C:\Windows\system32\AdvancedInstallers --------- 0  
     05.01.2010 00:34     C:\Windows\system32\ru-RU --------- 0  
     05.01.2010 00:34     C:\Windows\system32\fr-FR --------- 0  
     05.01.2010 00:34     C:\Windows\system32\sv-SE --------- 0  
     05.01.2010 00:34     C:\Windows\system32\he-IL --------- 0  
     05.01.2010 00:34     C:\Windows\system32\setup --------- 0  
     05.01.2010 00:34     C:\Windows\system32\fi-FI --------- 0  
     05.01.2010 00:34     C:\Windows\system32\cs-CZ --------- 0  
     05.01.2010 00:34     C:\Windows\system32\hu-HU --------- 0  
     05.01.2010 00:34     C:\Windows\system32\pt-PT --------- 0  
     05.01.2010 00:34     C:\Windows\system32\SLUI --------- 0  
     05.01.2010 00:34     C:\Windows\system32\zh-CN --------- 0  
     05.01.2010 00:34     C:\Windows\system32\sr-Latn-CS --------- 0  
     05.01.2010 00:34     C:\Windows\system32\manifeststore --------- 0  
     05.01.2010 00:34     C:\Windows\system32\es-ES --------- 0  
     05.01.2010 00:34     C:\Windows\system32\sl-SI --------- 0  
     05.01.2010 00:34     C:\Windows\system32\zh-TW --------- 0  
     05.01.2010 00:34     C:\Windows\system32\pl-PL --------- 0  
     05.01.2010 00:34     C:\Windows\system32\uk-UA --------- 0  
     05.01.2010 00:34     C:\Windows\system32\ja-JP --------- 0  
     05.01.2010 00:34     C:\Windows\system32\bg-BG --------- 0  
     05.01.2010 00:34     C:\Windows\system32\ro-RO --------- 0  
     05.01.2010 00:34     C:\Windows\system32\th-TH --------- 0  
     05.01.2010 00:34     C:\Windows\system32\tr-TR --------- 0  
     05.01.2010 00:34     C:\Windows\system32\wbem --------- 65536  
     05.01.2010 00:34     C:\Windows\system32\nb-NO --------- 0  
     05.01.2010 00:34     C:\Windows\system32\nl-NL --------- 0  
     05.01.2010 00:34     C:\Windows\system32\lt-LT --------- 0  
     05.01.2010 00:34     C:\Windows\system32\ar-SA --------- 0  
     05.01.2010 00:34     C:\Windows\system32\migwiz --------- 4096  
     05.01.2010 00:34     C:\Windows\system32\pt-BR --------- 0  
     05.01.2010 00:34     C:\Windows\system32\Boot --------- 0  
     05.01.2010 00:33     C:\Windows\system32\RTCOM --------- 0  
     04.01.2010 19:41     C:\Windows\system32\LMIRfsClientNP.dll --------- 83288  
     04.01.2010 19:41     C:\Windows\system32\LMIport.dll --------- 28984  
     04.01.2010 19:41     C:\Windows\system32\lmimirr2.dll --------- 11552  
     04.01.2010 19:41     C:\Windows\system32\lmimirr.dll --------- 25248  
     04.01.2010 19:41     C:\Windows\system32\LMIinit.dll --------- 87352  
     02.01.2010 19:28     C:\Windows\system32\liveL.LCK --------- 0  
     21.11.2009 07:40     C:\Windows\system32\wininet.dll --------- 916480  
     21.11.2009 07:40     C:\Windows\system32\urlmon.dll --------- 1208832  
     21.11.2009 07:38     C:\Windows\system32\occache.dll --------- 206848  
     21.11.2009 07:35     C:\Windows\system32\mshtml.dll --------- 5940736  
     21.11.2009 07:35     C:\Windows\system32\msfeedsbs.dll --------- 55296  
     21.11.2009 07:35     C:\Windows\system32\msfeeds.dll --------- 594432  
     21.11.2009 07:34     C:\Windows\system32\jsproxy.dll --------- 25600  
     21.11.2009 07:34     C:\Windows\system32\inetcpl.cpl --------- 1469440  
     21.11.2009 07:34     C:\Windows\system32\ieui.dll --------- 164352  
     21.11.2009 07:34     C:\Windows\system32\iesysprep.dll --------- 109056  
     21.11.2009 07:34     C:\Windows\system32\iertutil.dll --------- 1985536  
     21.11.2009 07:34     C:\Windows\system32\iesetup.dll --------- 71680  
     21.11.2009 07:34     C:\Windows\system32\iernonce.dll --------- 55808  
     21.11.2009 07:34     C:\Windows\system32\iepeers.dll --------- 184320  
     21.11.2009 07:34     C:\Windows\system32\ieframe.dll --------- 11069952  
     21.11.2009 07:34     C:\Windows\system32\iedkcs32.dll --------- 387584  
     21.11.2009 05:59     C:\Windows\system32\ieUnatt.exe --------- 133632  
     21.11.2009 05:59     C:\Windows\system32\ie4uinit.exe --------- 173056  
     21.11.2009 05:59     C:\Windows\system32\msfeedssync.exe --------- 13312  
     21.11.2009 05:58     C:\Windows\system32\mshtml.tlb --------- 1638912  
     20.11.2009 13:42     C:\Windows\system32\EventProviders --------- 0  
     09.11.2009 14:22     C:\Windows\system32\nshhttp.dll --------- 24064  
     09.11.2009 14:20     C:\Windows\system32\httpapi.dll --------- 31232  
     02.11.2009 20:42     C:\Windows\system32\MpSigStub.exe --------- 195456  
     29.10.2009 10:41     C:\Windows\system32\tzres.dll --------- 2048  
     23.10.2009 18:42     C:\Windows\system32\timedate.cpl --------- 714240  
     19.10.2009 15:27     C:\Windows\system32\t2embed.dll --------- 156672  
     19.10.2009 15:24     C:\Windows\system32\fontsub.dll --------- 72704  
     07.10.2009 13:41     C:\Windows\system32\rastls.dll --------- 244224  
     07.10.2009 13:41     C:\Windows\system32\raschap.dll --------- 281600  
    ----------------------------------------
    
     
    C:\Windows\Prefetch
    
     13.01.2010 21:48     C:\Windows\Prefetch\CMD.EXE-4A81B364.pf --------- 14084  
     13.01.2010 21:47     C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf --------- 23338  
     13.01.2010 21:47     C:\Windows\Prefetch\VERCLSID.EXE-7C52E31C.pf --------- 16188  
     13.01.2010 21:47     C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf --------- 277024  
     13.01.2010 21:47     C:\Windows\Prefetch\DLLHOST.EXE-5E46FA0D.pf --------- 19320  
     13.01.2010 21:47     C:\Windows\Prefetch\SMIAONLINESYNCCLIENT.EXE-ED0CF9F4.pf --------- 54084  
     13.01.2010 21:46     C:\Windows\Prefetch\TASKENG.EXE-48D4E289.pf --------- 21716  
     13.01.2010 21:45     C:\Windows\Prefetch\CONIME.EXE-9781FD5F.pf --------- 15182  
     13.01.2010 21:45     C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-77482212.pf --------- 19820  
     13.01.2010 21:44     C:\Windows\Prefetch\WERMGR.EXE-0F2AC88C.pf --------- 34054  
     13.01.2010 21:43     C:\Windows\Prefetch\WERFAULT.EXE-E69F695A.pf --------- 72424  
     13.01.2010 21:38     C:\Windows\Prefetch\WERCON.EXE-E36BD04E.pf --------- 70650  
     13.01.2010 21:38     C:\Windows\Prefetch\GOOGLEUPDATE.EXE-FE771DDA.pf --------- 18648  
     13.01.2010 21:35     C:\Windows\Prefetch\WMIADAP.EXE-F8DFDFA2.pf --------- 20232  
     13.01.2010 21:35     C:\Windows\Prefetch\WUAUCLT.EXE-70318591.pf --------- 32958  
     13.01.2010 21:35     C:\Windows\Prefetch\WMPNETWK.EXE-D9F2A96F.pf --------- 67278  
     13.01.2010 21:35     C:\Windows\Prefetch\WMPNSCFG.EXE-FC0D39BF.pf --------- 23260  
     13.01.2010 21:35     C:\Windows\Prefetch\MOBSYNC.EXE-C5E2284F.pf --------- 39460  
     13.01.2010 21:35     C:\Windows\Prefetch\WMPLAYER.EXE-BAD6BD53.pf --------- 57648  
     13.01.2010 21:34     C:\Windows\Prefetch\GOOGLEUPDATERSERVICE.EXE-09540BCD.pf --------- 24528  
     13.01.2010 21:33     C:\Windows\Prefetch\ReadyBoot --------- 4096  
     13.01.2010 21:33     C:\Windows\Prefetch\WINWORD.EXE-71DAFA5C.pf --------- 286570  
     13.01.2010 21:33     C:\Windows\Prefetch\DLLHOST.EXE-766398D2.pf --------- 23140  
     13.01.2010 21:33     C:\Windows\Prefetch\SMIPCSRV.EXE-AB09C305.pf --------- 37410  
     13.01.2010 21:33     C:\Windows\Prefetch\SMRCGSYSTASK.NGN-F0AF14AD.pf --------- 75330  
     13.01.2010 21:33     C:\Windows\Prefetch\SMPURGESYSTASK.NGN-BAE58D70.pf --------- 70482  
     13.01.2010 21:33     C:\Windows\Prefetch\SMCTXSYSTASK.NGN-3CE8710C.pf --------- 69974  
     13.01.2010 21:33     C:\Windows\Prefetch\SEARCHINDEXER.EXE-4A6353B9.pf --------- 31502  
     13.01.2010 21:32     C:\Windows\Prefetch\WMIPRVSE.EXE-1628051C.pf --------- 40276  
     13.01.2010 21:32     C:\Windows\Prefetch\PRESENTATIONSETTINGS.EXE-2F4708C9.pf --------- 20720  
     13.01.2010 21:32     C:\Windows\Prefetch\GOOGLETOOLBARNOTIFIER.EXE-EB3F2433.pf --------- 16530  
     13.01.2010 21:32     C:\Windows\Prefetch\LOGMEIN.EXE-3B7E149E.pf --------- 22982  
     13.01.2010 21:32     C:\Windows\Prefetch\ALU.EXE-416FCC7B.pf --------- 4246  
     13.01.2010 21:32     C:\Windows\Prefetch\NTOSBOOT-B00DFAAD.pf --------- 2622590  
     13.01.2010 21:25     C:\Windows\Prefetch\SSTEXT3D.SCR-DBBF7C58.pf --------- 30978  
     13.01.2010 21:22     C:\Windows\Prefetch\AgGlFgAppHistory.db --------- 330814  
     13.01.2010 21:22     C:\Windows\Prefetch\AgGlFaultHistory.db --------- 318283  
     13.01.2010 21:22     C:\Windows\Prefetch\AgGlGlobalHistory.db --------- 1046930  
     13.01.2010 21:22     C:\Windows\Prefetch\AgRobust.db --------- 129744  
     13.01.2010 21:19     C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-3480036674-3622741497-2829454337-1000.db --------- 1080016  
     13.01.2010 21:19     C:\Windows\Prefetch\AgGlUAD_S-1-5-21-3480036674-3622741497-2829454337-1000.db --------- 1999565  
     13.01.2010 20:42     C:\Windows\Prefetch\N7JN9B0N.EXE-CB1A4B42.pf --------- 24496  
     13.01.2010 19:57     C:\Windows\Prefetch\NOTEPAD.EXE-D8414F97.pf --------- 18562  
     13.01.2010 19:56     C:\Windows\Prefetch\HIJACKTHIS.EXE-33B9AA46.pf --------- 20266  
     13.01.2010 19:56     C:\Windows\Prefetch\TOTALCMD.EXE-5786E633.pf --------- 45772  
     13.01.2010 19:52     C:\Windows\Prefetch\HELPPANE.EXE-FEDC965B.pf --------- 59782  
     13.01.2010 19:48     C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-3CC531E5.pf --------- 193266  
     13.01.2010 19:47     C:\Windows\Prefetch\RUNDLL32.EXE-DAEF8EB2.pf --------- 36254  
     13.01.2010 19:45     C:\Windows\Prefetch\CONTROL.EXE-817F8F1D.pf --------- 24752  
     13.01.2010 19:36     C:\Windows\Prefetch\RUNDLL32.EXE-590C0712.pf --------- 36296  
     13.01.2010 19:33     C:\Windows\Prefetch\OUTLOOK.EXE-C10375AB.pf --------- 209202  
     13.01.2010 19:33     C:\Windows\Prefetch\DLLHOST.EXE-412EAFE6.pf --------- 28988  
     13.01.2010 19:23     C:\Windows\Prefetch\RUNDLL32.EXE-A6251510.pf --------- 2122  
     13.01.2010 19:23     C:\Windows\Prefetch\SNDVOL.EXE-5D4CC7D6.pf --------- 28162  
     13.01.2010 18:09     C:\Windows\Prefetch\PfSvPerfStats.bin --------- 508  
     13.01.2010 18:09     C:\Windows\Prefetch\OSE.EXE-533D8AC9.pf --------- 13718  
     13.01.2010 18:09     C:\Windows\Prefetch\MSOHTMED.EXE-E69B7F27.pf --------- 19930  
     13.01.2010 18:09     C:\Windows\Prefetch\MSIEXEC.EXE-A2D55CB6.pf --------- 219890  
     13.01.2010 18:06     C:\Windows\Prefetch\MRT.EXE-851529F7.pf --------- 153020  
     13.01.2010 18:06     C:\Windows\Prefetch\WINDOWS-KB890830-V3.3-DELTA.E-AE811563.pf --------- 29372  
     13.01.2010 18:06     C:\Windows\Prefetch\MRTSTUB.EXE-154D002C.pf --------- 180246  
     13.01.2010 18:06     C:\Windows\Prefetch\WINLOGON.EXE-B020DC41.pf --------- 33168  
     13.01.2010 18:06     C:\Windows\Prefetch\CSRSS.EXE-3FE41F7E.pf --------- 32296  
     13.01.2010 18:06     C:\Windows\Prefetch\SMSS.EXE-E9C28FC6.pf --------- 1820  
     13.01.2010 18:06     C:\Windows\Prefetch\ACENGSVR.EXE-08694D3D.pf --------- 26986  
     13.01.2010 18:06     C:\Windows\Prefetch\LOGONUI.EXE-09140401.pf --------- 38772  
     13.01.2010 18:06     C:\Windows\Prefetch\CTFMON.EXE-9450846B.pf --------- 6674  
     13.01.2010 18:06     C:\Windows\Prefetch\C.EXE-E0F2CEDA.pf --------- 19476  
     13.01.2010 18:05     C:\Windows\Prefetch\AUSK32.EXE-8BD0DBF1.pf --------- 40778  
     13.01.2010 18:05     C:\Windows\Prefetch\ANOLOG32.EXE-19E7B2A5.pf --------- 82946  
     13.01.2010 18:05     C:\Windows\Prefetch\ANOLDRSVCTRLMNGR.EXE-D2729F11.pf --------- 29170  
     13.01.2010 17:58     C:\Windows\Prefetch\WUDFHOST.EXE-AFFEF87C.pf --------- 23448  
     13.01.2010 17:57     C:\Windows\Prefetch\TASKMGR.EXE-5F5F473D.pf --------- 41908  
     13.01.2010 16:05     C:\Windows\Prefetch\GOOGLEUPDATER.EXE-39628337.pf --------- 53730  
     13.01.2010 14:37     C:\Windows\Prefetch\EXCEL.EXE-804D5D87.pf --------- 82070  
     13.01.2010 14:36     C:\Windows\Prefetch\SMIACORE.EXE-282199E4.pf --------- 71706  
     13.01.2010 14:17     C:\Windows\Prefetch\Layout.ini --------- 1576106  
     13.01.2010 10:54     C:\Windows\Prefetch\ACRORD32.EXE-DE3ACCC1.pf --------- 101404  
     13.01.2010 10:14     C:\Windows\Prefetch\SVCHOST.EXE-7CFEDEA3.pf --------- 25610  
     13.01.2010 10:14     C:\Windows\Prefetch\VSSVC.EXE-B8AFC319.pf --------- 38790  
     13.01.2010 09:56     C:\Windows\Prefetch\DWM.EXE-6FFD3DA8.pf --------- 30662  
     13.01.2010 09:56     C:\Windows\Prefetch\USERINIT.EXE-2257A3E7.pf --------- 19268  
     13.01.2010 09:56     C:\Windows\Prefetch\MPNOTIFY.EXE-83D4091E.pf --------- 20912  
     04.01.2010 18:36     C:\Windows\Prefetch\AgCx_SC1.db --------- 864237  
     04.01.2010 18:35     C:\Windows\Prefetch\AgCx_SC1.db.trx --------- 62464  
     23.12.2009 10:46     C:\Windows\Prefetch\AgCx_SC2.db --------- 915448  
     02.10.2009 14:57     C:\Windows\Prefetch\AgCx_SC3_370D3301.db --------- 396358  
     13.12.2008 10:03     C:\Windows\Prefetch\AgAppLaunch.db --------- 332116  
    ----------------------------------------
    
     
    C:\Windows\Tasks
    
     13.01.2010 21:38     C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job --------- 1096  
     13.01.2010 21:34     C:\Windows\Tasks\Google Software Updater.job --------- 1052  
     13.01.2010 21:32     C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job --------- 1092  
     13.01.2010 21:32     C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job --------- 244  
     13.01.2010 21:31     C:\Windows\Tasks\SA.DAT --------- 6  
     13.01.2010 18:09     C:\Windows\Tasks\SCHEDLGU.TXT --------- 32530  
    ----------------------------------------
    
     
    C:\Windows\Temp
    
     13.01.2010 10:14     C:\Windows\Temp\MpSigStub.log --------- 488422  
     13.01.2010 10:14     C:\Windows\Temp\MPTelemetrySubmit --------- 0  
     11.01.2010 17:13     C:\Windows\Temp\JET13.tmp --------- 0  
     11.01.2010 13:04     C:\Windows\Temp\JET12.tmp --------- 0  
     11.01.2010 12:39     C:\Windows\Temp\JET11.tmp --------- 0  
     11.01.2010 11:45     C:\Windows\Temp\dd_ATL90SP1_KB973924UI0E77.txt --------- 11652  
     11.01.2010 11:45     C:\Windows\Temp\dd_ATL90SP1_KB973924MSI0E77.txt --------- 219798  
     05.01.2010 07:00     C:\Windows\Temp\PCTBD455741 --------- 0  
     05.01.2010 00:41     C:\Windows\Temp\ASPNETSetup_00002.log --------- 775  
     05.01.2010 00:26     C:\Windows\Temp\ASPNETSetup_00001.log --------- 775  
     04.01.2010 10:59     C:\Windows\Temp\JET10.tmp --------- 0  
     23.12.2009 08:40     C:\Windows\Temp\isB4DE.tmp --------- 0  
     23.12.2009 08:39     C:\Windows\Temp\is2E21.tmp --------- 0  
     17.12.2009 10:37     C:\Windows\Temp\JETF.tmp --------- 0  
     16.12.2009 18:39     C:\Windows\Temp\CR_EF2A.tmp --------- 0  
     16.12.2009 18:38     C:\Windows\Temp\chrome_installer.log --------- 0  
     16.12.2009 18:38     C:\Windows\Temp\chrome_23366 --------- 0  
     06.12.2009 21:29     C:\Windows\Temp\JETE.tmp --------- 0  
     06.12.2009 17:53     C:\Windows\Temp\JETF2C0.tmp --------- 0  
     06.12.2009 11:31     C:\Windows\Temp\DWDF7E7.tmp --------- 0  
     30.11.2009 19:00     C:\Windows\Temp\JETBE1D.tmp --------- 0  
     30.11.2009 07:40     C:\Windows\Temp\is6C5A.tmp --------- 0  
     30.11.2009 07:40     C:\Windows\Temp\is6132.tmp --------- 0  
     28.11.2009 18:39     C:\Windows\Temp\GoogleToolbarInstaller1.log --------- 14440  
     28.11.2009 18:31     C:\Windows\Temp\Google Toolbar --------- 0  
     28.11.2009 18:29     C:\Windows\Temp\GoogleToolbarInstaller2.log --------- 13142  
     26.11.2009 07:59     C:\Windows\Temp\JETD.tmp --------- 0  
     20.11.2009 19:11     C:\Windows\Temp\JETF7FA.tmp --------- 0  
     20.11.2009 14:40     C:\Windows\Temp\JETC.tmp --------- 0  
     17.11.2009 08:38     C:\Windows\Temp\CR_F71A.tmp --------- 0  
     17.11.2009 08:38     C:\Windows\Temp\chrome_13753 --------- 0  
     13.11.2009 15:06     C:\Windows\Temp\JETB.tmp --------- 0  
     12.11.2009 08:39     C:\Windows\Temp\CR_C513.tmp --------- 0  
     12.11.2009 08:38     C:\Windows\Temp\chrome_12177 --------- 0  
     05.11.2009 16:52     C:\Windows\Temp\JETFBC6.tmp --------- 0  
     22.10.2009 08:23     C:\Windows\Temp\JETA.tmp --------- 0  
     15.10.2009 18:49     C:\Windows\Temp\JET7B25.tmp --------- 0  
     15.10.2009 18:44     C:\Windows\Temp\RtSigs --------- 0  
     15.10.2009 18:44     C:\Windows\Temp\History --------- 0  
     14.10.2009 07:34     C:\Windows\Temp\CR_219B.tmp --------- 0  
     14.10.2009 07:33     C:\Windows\Temp\chrome_9108 --------- 0  
     07.10.2009 13:02     C:\Windows\Temp\JETEF41.tmp --------- 0  
     07.10.2009 07:34     C:\Windows\Temp\CR_3E09.tmp --------- 0  
     07.10.2009 07:33     C:\Windows\Temp\chrome_186 --------- 0  
     05.10.2009 13:29     C:\Windows\Temp\JET9.tmp --------- 0  
     17.09.2009 17:40     C:\Windows\Temp\JET7A31.tmp --------- 0  
     16.09.2009 14:33     C:\Windows\Temp\JET8.tmp --------- 0  
     14.09.2009 08:28     C:\Windows\Temp\DWDF98B.tmp --------- 0  
     06.09.2009 17:19     C:\Windows\Temp\JET7.tmp --------- 0  
     02.09.2009 11:20     C:\Windows\Temp\Microsoft .NET Framework 3.5-KB963707_20090902_102005266.html --------- 75404  
     02.09.2009 11:20     C:\Windows\Temp\Microsoft .NET Framework 3.5-KB963707_20090902_102005266-Msi0.txt --------- 441958  
     02.09.2009 08:59     C:\Windows\Temp\JET6.tmp --------- 0  
     18.08.2009 15:15     C:\Windows\Temp\dd_dotnetfx35install_lp.txt --------- 67102  
     18.08.2009 15:15     C:\Windows\Temp\uxeventlog.txt --------- 1528  
     18.08.2009 15:15     C:\Windows\Temp\dd_NET_Framework35_LangPack_MSI1FD4.txt --------- 472174  
     18.08.2009 15:15     C:\Windows\Temp\dd_depcheck_NETFX_EXP_35.txt --------- 35830  
     18.08.2009 15:15     C:\Windows\Temp\dd_dotnetfx35error_lp.txt --------- 2  
     18.08.2009 05:59     C:\Windows\Temp\ASPNETSetup_00000.log --------- 775  
     17.08.2009 16:22     C:\Windows\Temp\Microsoft .NET Framework 3.5-KB958484_20090817_152148741.html --------- 93620  
     17.08.2009 16:22     C:\Windows\Temp\Microsoft .NET Framework 3.5-KB958484_20090817_152148741-Msi0.txt --------- 769568  
     17.08.2009 16:20     C:\Windows\Temp\dd_clwireg.txt --------- 7944  
     06.08.2009 10:10     C:\Windows\Temp\JET5.tmp --------- 0  
     15.07.2009 14:14     C:\Windows\Temp\JET4.tmp --------- 0  
     19.05.2009 07:27     C:\Windows\Temp\is27EB.tmp --------- 0  
     19.05.2009 07:27     C:\Windows\Temp\isD596.tmp --------- 0  
     09.04.2009 07:27     C:\Windows\Temp\JET3.tmp --------- 0  
     07.04.2009 16:29     C:\Windows\Temp\JET2.tmp --------- 0  
     27.03.2009 10:01     C:\Windows\Temp\DWD7F0E.tmp --------- 0  
     25.03.2009 08:17     C:\Windows\Temp\gis14ead84 --------- 0  
     23.02.2009 08:43     C:\Windows\Temp\JET1.tmp --------- 0  
     13.12.2008 10:14     C:\Windows\Temp\WinSAT_StorageAsmt.etl --------- 3145728  
     13.12.2008 10:12     C:\Windows\Temp\WinSAT_DX.etl --------- 1048576  
     13.12.2008 10:12     C:\Windows\Temp\WinSAT_KernelLog.etl --------- 3145728  
     13.12.2008 10:06     C:\Windows\Temp\DMI95F7.tmp --------- 0  
     13.12.2008 10:04     C:\Windows\Temp\DMIA14D.tmp --------- 0  
     13.12.2008 10:04     C:\Windows\Temp\DMI9A4B.tmp --------- 0  
     13.12.2008 10:04     C:\Windows\Temp\DMI98B5.tmp --------- 0  
     13.12.2008 10:04     C:\Windows\Temp\FXSAPIDebugLogFile.txt --------- 0  
     13.12.2008 10:04     C:\Windows\Temp\FXSTIFFDebugLogFile.txt --------- 0  
     13.12.2008 10:04     C:\Windows\Temp\DMIC6D7.tmp --------- 0  
    ----------------------------------------
    
     
    C:\Users\Standke\AppData\Local\Temp
    
     13.01.2010 21:47     C:\Users\Standke\AppData\Local\Temp\Temp1_hjtscanlist.zip --------- 0  
     13.01.2010 21:47     C:\Users\Standke\AppData\Local\Temp\~DF2F78.tmp --------- 16384  
     13.01.2010 21:47     C:\Users\Standke\AppData\Local\Temp\~DF29CC.tmp --------- 16384  
     13.01.2010 21:43     C:\Users\Standke\AppData\Local\Temp\ATMmf --------- 20480  
     13.01.2010 21:41     C:\Users\Standke\AppData\Local\Temp\~DF832.tmp --------- 16384  
     13.01.2010 21:37     C:\Users\Standke\AppData\Local\Temp\~DFE85C.tmp --------- 16384  
     13.01.2010 21:34     C:\Users\Standke\AppData\Local\Temp\~DF30E6.tmp --------- 16384  
     13.01.2010 21:34     C:\Users\Standke\AppData\Local\Temp\~DF113B.tmp --------- 16384  
     13.01.2010 21:33     C:\Users\Standke\AppData\Local\Temp\WPDNSE --------- 0  
     13.01.2010 21:32     C:\Users\Standke\AppData\Local\Temp\~DF3DF0.tmp --------- 512  
     13.01.2010 21:32     C:\Users\Standke\AppData\Local\Temp\~DF16D5.tmp --------- 16384  
     13.01.2010 21:32     C:\Users\Standke\AppData\Local\Temp\Standke.bmp --------- 31832  
     13.01.2010 21:32     C:\Users\Standke\AppData\Local\Temp\wmplog06.sqm --------- 1272  
     13.01.2010 21:31     C:\Users\Standke\AppData\Local\Temp\test.reg --------- 11540  
     13.01.2010 21:29     C:\Users\Standke\AppData\Local\Temp\~DF6F2.tmp --------- 0  
     13.01.2010 21:29     C:\Users\Standke\AppData\Local\Temp\~DF111.tmp --------- 0  
     13.01.2010 21:28     C:\Users\Standke\AppData\Local\Temp\~DFA2BA.tmp --------- 0  
     13.01.2010 21:28     C:\Users\Standke\AppData\Local\Temp\~DFA2B1.tmp --------- 0  
     13.01.2010 19:22     C:\Users\Standke\AppData\Local\Temp\~DFD25.tmp --------- 512  
     13.01.2010 19:22     C:\Users\Standke\AppData\Local\Temp\~DFED29.tmp --------- 16384  
     13.01.2010 16:21     C:\Users\Standke\AppData\Local\Temp\tmpmsh.ini --------- 71  
     13.01.2010 10:37     C:\Users\Standke\AppData\Local\Temp\hsperfdata_Standke --------- 0  
     13.01.2010 10:34     C:\Users\Standke\AppData\Local\Temp\java_install_reg.log --------- 18376  
     13.01.2010 09:57     C:\Users\Standke\AppData\Local\Temp\~DFF777.tmp --------- 16384  
     12.01.2010 16:23     C:\Users\Standke\AppData\Local\Temp\tmp931E.tmp --------- 0  
     12.01.2010 16:23     C:\Users\Standke\AppData\Local\Temp\DictaPlusClientTempDir --------- 0  
     12.01.2010 16:18     C:\Users\Standke\AppData\Local\Temp\tmpC36E.tmp --------- 0  
     12.01.2010 15:43     C:\Users\Standke\AppData\Local\Temp\tmpD864.tmp --------- 0  
     12.01.2010 15:32     C:\Users\Standke\AppData\Local\Temp\0019.PDF --------- 1370922  
     12.01.2010 12:22     C:\Users\Standke\AppData\Local\Temp\0285.PDF --------- 869955  
     12.01.2010 12:21     C:\Users\Standke\AppData\Local\Temp\007A.PDF --------- 22749  
     12.01.2010 12:14     C:\Users\Standke\AppData\Local\Temp\0006.PDF --------- 391354  
     12.01.2010 08:06     C:\Users\Standke\AppData\Local\Temp\__SkypeIEToolbar_Cache --------- 0  
     11.01.2010 17:18     C:\Users\Standke\AppData\Local\Temp\mwsqm02.sqm --------- 188  
     11.01.2010 16:29     C:\Users\Standke\AppData\Local\Temp\0005.PDF --------- 230070  
     11.01.2010 15:16     C:\Users\Standke\AppData\Local\Temp\tmp1242.tmp --------- 0  
     11.01.2010 15:16     C:\Users\Standke\AppData\Local\Temp\tmp1243.tmp --------- 0  
     11.01.2010 15:16     C:\Users\Standke\AppData\Local\Temp\tmpF790.tmp --------- 0  
     11.01.2010 15:16     C:\Users\Standke\AppData\Local\Temp\WKspch.ini --------- 3881  
     11.01.2010 14:06     C:\Users\Standke\AppData\Local\Temp\MRG5566.PDF --------- 87167  
     11.01.2010 14:04     C:\Users\Standke\AppData\Local\Temp\000C.PDF --------- 1037082  
     11.01.2010 13:57     C:\Users\Standke\AppData\Local\Temp\tmpE3DD.tmp --------- 0  
     11.01.2010 13:57     C:\Users\Standke\AppData\Local\Temp\tmpE3DE.tmp --------- 0  
     11.01.2010 13:57     C:\Users\Standke\AppData\Local\Temp\tmpD30B.tmp --------- 0  
     11.01.2010 12:54     C:\Users\Standke\AppData\Local\Temp\wmplog05.sqm --------- 1328  
     11.01.2010 12:40     C:\Users\Standke\AppData\Local\Temp\0002.PDF --------- 446340  
     11.01.2010 12:39     C:\Users\Standke\AppData\Local\Temp\~cxd{8D5FCE38-A16A-4D5C-880A-864DD4811719}.tmp --------- 3870  
     11.01.2010 12:39     C:\Users\Standke\AppData\Local\Temp\~cxd{A1A10C6A-6962-4FCA-A26F-227C8A7ADFB2}.tmp --------- 1239  
     11.01.2010 12:39     C:\Users\Standke\AppData\Local\Temp\~cxd{228338F2-DABD-4EFA-BFA0-174A723DFFFB}.tmp --------- 53  
     11.01.2010 12:39     C:\Users\Standke\AppData\Local\Temp\~cxd{F3CDF64C-39A0-4E88-8685-6BE3286A9717}.tmp --------- 111  
     11.01.2010 12:39     C:\Users\Standke\AppData\Local\Temp\~cxd{19B3D8A4-9130-4378-A754-5899FE23F4C8}.tmp --------- 204  
     11.01.2010 12:39     C:\Users\Standke\AppData\Local\Temp\~cxd{1A0B384E-7ABB-4C41-9727-DEF1B7C8DA47}.tmp --------- 0  
     11.01.2010 12:39     C:\Users\Standke\AppData\Local\Temp\~cxd{5D313078-462A-4B65-BEDE-80774DB51D34}.tmp --------- 98  
     11.01.2010 12:39     C:\Users\Standke\AppData\Local\Temp\~cxd{EAECAA20-874B-4991-9A87-F118373EFA10}.tmp --------- 0  
     11.01.2010 12:39     C:\Users\Standke\AppData\Local\Temp\~cxd{33FE58C3-3379-4E8B-A010-A82A5E8E1F36}.tmp --------- 98  
     11.01.2010 12:39     C:\Users\Standke\AppData\Local\Temp\~cxd{AC14AB68-2B3F-44AD-9FD1-45AC2DA937FD}.tmp --------- 0  
     11.01.2010 12:39     C:\Users\Standke\AppData\Local\Temp\~cxd{130A7F2A-7015-44E6-99AF-5D6E4DB1F91B}.tmp --------- 98  
     11.01.2010 12:39     C:\Users\Standke\AppData\Local\Temp\~cxd{D73C7AD9-9AF2-4DBF-8295-CAE34A9C2976}.tmp --------- 0  
     11.01.2010 12:39     C:\Users\Standke\AppData\Local\Temp\~cxd{266F9316-EC3C-41EE-9065-32B9BFC04A1F}.tmp --------- 254  
     11.01.2010 11:50     C:\Users\Standke\AppData\Local\Temp\Uninstall Log 2010-01-11 #001.txt --------- 62875  
     11.01.2010 11:50     C:\Users\Standke\AppData\Local\Temp\Uninstall Log 2010-01-11 #003.txt --------- 6487  
     11.01.2010 11:50     C:\Users\Standke\AppData\Local\Temp\Uninstall Log 2010-01-11 #002.txt --------- 4102  
     11.01.2010 11:50     C:\Users\Standke\AppData\Local\Temp\GenericTdiDll.txt --------- 2  
     11.01.2010 11:49     C:\Users\Standke\AppData\Local\Temp\Kno168C.tmp --------- 0  
     11.01.2010 11:48     C:\Users\Standke\AppData\Local\Temp\KnoFD51.tmp --------- 0  
     11.01.2010 11:47     C:\Users\Standke\AppData\Local\Temp\KnoE38A.tmp --------- 0  
     11.01.2010 11:46     C:\Users\Standke\AppData\Local\Temp\KnoD0C6.tmp --------- 0  
     11.01.2010 11:45     C:\Users\Standke\AppData\Local\Temp\Kno89D7.tmp --------- 0  
     05.01.2010 06:57     C:\Users\Standke\AppData\Local\Temp\wmplog04.sqm --------- 1272  
     05.01.2010 06:56     C:\Users\Standke\AppData\Local\Temp\wmplog03.sqm --------- 1328  
     05.01.2010 06:55     C:\Users\Standke\AppData\Local\Temp\wmplog02.sqm --------- 1536  
     05.01.2010 01:14     C:\Users\Standke\AppData\Local\Temp\LastScan.txt --------- 11476  
     05.01.2010 01:13     C:\Users\Standke\AppData\Local\Temp\a.dat --------- 37216  
     05.01.2010 01:13     C:\Users\Standke\AppData\Local\Temp\Installer.exe --------- 95744  
     05.01.2010 01:10     C:\Users\Standke\AppData\Local\Temp\restart.a2s --------- 482  
     05.01.2010 01:01     C:\Users\Standke\AppData\Local\Temp\Setup Log 2010-01-05 #001.txt --------- 156989  
     05.01.2010 01:01     C:\Users\Standke\AppData\Local\Temp\is-RK44L.tmp --------- 0  
     05.01.2010 01:00     C:\Users\Standke\AppData\Local\Temp\PCTInstaller --------- 0  
     05.01.2010 00:59     C:\Users\Standke\AppData\Local\Temp\Setup Log 2010-01-05 #004.txt --------- 25472  
     05.01.2010 00:57     C:\Users\Standke\AppData\Local\Temp\dd_vcredistUI492C.txt --------- 78534  
     05.01.2010 00:57     C:\Users\Standke\AppData\Local\Temp\Setup Log 2010-01-05 #003.txt --------- 3923  
     05.01.2010 00:57     C:\Users\Standke\AppData\Local\Temp\dd_vcredistMSI492C.txt --------- 324672  
     05.01.2010 00:57     C:\Users\Standke\AppData\Local\Temp\Setup Log 2010-01-05 #002.txt --------- 7312  
     04.01.2010 23:51     C:\Users\Standke\AppData\Local\Temp\dv.dat --------- 136  
     04.01.2010 23:51     C:\Users\Standke\AppData\Local\Temp\av.dat --------- 128  
     04.01.2010 23:51     C:\Users\Standke\AppData\Local\Temp\4otjesjty.mof --------- 455  
     04.01.2010 23:50     C:\Users\Standke\AppData\Local\Temp\uac1a05.tmp --------- 1756088  
     04.01.2010 23:50     C:\Users\Standke\AppData\Local\Temp\uac193a.tmp --------- 32760  
     04.01.2010 23:50     C:\Users\Standke\AppData\Local\Temp\uac186f.tmp --------- 35064  
     04.01.2010 23:50     C:\Users\Standke\AppData\Local\Temp\uacec80.tmp --------- 4546960  
     04.01.2010 23:44     C:\Users\Standke\AppData\Local\Temp\Uninstall Log 2010-01-04 #001.txt --------- 66824  
     04.01.2010 23:44     C:\Users\Standke\AppData\Local\Temp\Uninstall Log 2010-01-04 #004.txt --------- 6488  
     04.01.2010 23:44     C:\Users\Standke\AppData\Local\Temp\Uninstall Log 2010-01-04 #003.txt --------- 4103  
     04.01.2010 23:44     C:\Users\Standke\AppData\Local\Temp\Uninstall Log 2010-01-04 #002.txt --------- 5829  
     04.01.2010 23:38     C:\Users\Standke\AppData\Local\Temp\Setup Log 2010-01-04 #001.txt --------- 139633  
     04.01.2010 23:38     C:\Users\Standke\AppData\Local\Temp\is-88U8I.tmp --------- 0  
     04.01.2010 23:37     C:\Users\Standke\AppData\Local\Temp\Setup Log 2010-01-04 #004.txt --------- 16795  
     04.01.2010 23:35     C:\Users\Standke\AppData\Local\Temp\dd_vcredistUI0AD2.txt --------- 13658  
     04.01.2010 23:35     C:\Users\Standke\AppData\Local\Temp\dd_vcredistMSI0AD2.txt --------- 408238  
     04.01.2010 23:35     C:\Users\Standke\AppData\Local\Temp\Setup Log 2010-01-04 #003.txt --------- 3924  
     04.01.2010 23:35     C:\Users\Standke\AppData\Local\Temp\Setup Log 2010-01-04 #002.txt --------- 7313  
     04.01.2010 23:20     C:\Users\Standke\AppData\Local\Temp\2.ico --------- 15086  
     04.01.2010 23:20     C:\Users\Standke\AppData\Local\Temp\3.ico --------- 15086  
     04.01.2010 23:20     C:\Users\Standke\AppData\Local\Temp\1.ico --------- 15086  
     04.01.2010 23:18     C:\Users\Standke\AppData\Local\Temp\{12345678-1234-5678-0102-030405060708} --------- 314  
     04.01.2010 23:18     C:\Users\Standke\AppData\Local\Temp\{78AE8F47-AA5B-2C4F-2235-F7CF0082F38B}-settdebugx.exe --------- 716800  
     04.01.2010 23:16     C:\Users\Standke\AppData\Local\Temp\mpengine.dllb5a07eb0 --------- 4915024  
     04.01.2010 23:14     C:\Users\Standke\AppData\Local\Temp\{660698E6-265B-3F8D-CD43-B9144947D3E5}-settdebugx.exe --------- 716800  
     04.01.2010 23:12     C:\Users\Standke\AppData\Local\Temp\mpengine.dll --------- 4915024  
     04.01.2010 20:16     C:\Users\Standke\AppData\Local\Temp\a2temp --------- 0  
     04.01.2010 20:12     C:\Users\Standke\AppData\Local\Temp\result.txt --------- 572  
     04.01.2010 19:51     C:\Users\Standke\AppData\Local\Temp\wmplog01.sqm --------- 1272  
     04.01.2010 19:38     C:\Users\Standke\AppData\Local\Temp\tvinfo.ini --------- 45  
     04.01.2010 15:07     C:\Users\Standke\AppData\Local\Temp\DLL_{16C9924C-C42A-4790-BD18-27BDCA4B23C1}.ini --------- 4624  
     04.01.2010 15:07     C:\Users\Standke\AppData\Local\Temp\isB7AA.tmp --------- 0  
     04.01.2010 10:15     C:\Users\Standke\AppData\Local\Temp\uaccfbf.tmp --------- 1756088  
     04.01.2010 10:15     C:\Users\Standke\AppData\Local\Temp\uacce39.tmp --------- 32760  
     04.01.2010 10:15     C:\Users\Standke\AppData\Local\Temp\uaccbd8.tmp --------- 35064  
     04.01.2010 10:15     C:\Users\Standke\AppData\Local\Temp\uac6b90.tmp --------- 4546960  
     04.01.2010 09:44     C:\Users\Standke\AppData\Local\Temp\test.bat --------- 472  
     04.01.2010 08:24     C:\Users\Standke\AppData\Local\Temp\wmplog00.sqm --------- 1538  
     04.01.2010 08:22     C:\Users\Standke\AppData\Local\Temp\wmplog19.sqm --------- 1538  
     04.01.2010 08:19     C:\Users\Standke\AppData\Local\Temp\f.exe --------- 176128  
     04.01.2010 08:19     C:\Users\Standke\AppData\Local\Temp\e.exe --------- 187392  
     04.01.2010 08:19     C:\Users\Standke\AppData\Local\Temp\sshnas.dll --------- 233984  
     04.01.2010 08:19     C:\Users\Standke\AppData\Local\Temp\d.exe --------- 345600  
     04.01.2010 08:19     C:\Users\Standke\AppData\Local\Temp\b.exe --------- 187392  
     04.01.2010 08:19     C:\Users\Standke\AppData\Local\Temp\a.exe --------- 345600  
     04.01.2010 08:15     C:\Users\Standke\AppData\Local\Temp\wmplog18.sqm --------- 1814  
     04.01.2010 08:14     C:\Users\Standke\AppData\Local\Temp\wmplog17.sqm --------- 1538  
     04.01.2010 08:14     C:\Users\Standke\AppData\Local\Temp\wmplog16.sqm --------- 1538  
     04.01.2010 08:05     C:\Users\Standke\AppData\Local\Temp\wmplog15.sqm --------- 1570  
     04.01.2010 08:04     C:\Users\Standke\AppData\Local\Temp\wmplog14.sqm --------- 1538  
     04.01.2010 08:03     C:\Users\Standke\AppData\Local\Temp\wmplog13.sqm --------- 1574  
     02.01.2010 20:09     C:\Users\Standke\AppData\Local\Temp\wmplog12.sqm --------- 1450  
     02.01.2010 19:29     C:\Users\Standke\AppData\Local\Temp\{BD5A1B9A-D044-4F71-BCC0-0BDE947D4C41} --------- 0  
     02.01.2010 19:22     C:\Users\Standke\AppData\Local\Temp\~nsu.tmp --------- 0  
     02.01.2010 17:58     C:\Users\Standke\AppData\Local\Temp\msohtml1 --------- 0  
     02.01.2010 17:45     C:\Users\Standke\AppData\Local\Temp\ge75416 --------- 0  
     02.01.2010 17:18     C:\Users\Standke\AppData\Local\Temp\000a.PDF --------- 250746  
     02.01.2010 17:18     C:\Users\Standke\AppData\Local\Temp\0009.PDF --------- 177758  
     02.01.2010 17:06     C:\Users\Standke\AppData\Local\Temp\0003.PDF --------- 529391  
     02.01.2010 17:04     C:\Users\Standke\AppData\Local\Temp\tmp3CBF.tmp --------- 0  
     02.01.2010 17:04     C:\Users\Standke\AppData\Local\Temp\tmp3CBE.tmp --------- 0  
     02.01.2010 17:04     C:\Users\Standke\AppData\Local\Temp\tmp2AC3.tmp --------- 0  
     02.01.2010 16:54     C:\Users\Standke\AppData\Local\Temp\0001.PDF --------- 1314292  
     02.01.2010 16:50     C:\Users\Standke\AppData\Local\Temp\tmp7C6A.tmp --------- 0  
     02.01.2010 16:50     C:\Users\Standke\AppData\Local\Temp\tmp7C69.tmp --------- 0  
     02.01.2010 16:50     C:\Users\Standke\AppData\Local\Temp\tmp6BF3.tmp --------- 0  
     02.01.2010 16:41     C:\Users\Standke\AppData\Local\Temp\out --------- 0  
     02.01.2010 16:38     C:\Users\Standke\AppData\Local\Temp\MRG3353.DOC --------- 38912  
     02.01.2010 16:28     C:\Users\Standke\AppData\Local\Temp\tmp4ACB.tmp --------- 0  
     02.01.2010 16:28     C:\Users\Standke\AppData\Local\Temp\tmp4ACC.tmp --------- 0  
     02.01.2010 16:28     C:\Users\Standke\AppData\Local\Temp\tmp39D9.tmp --------- 0  
     02.01.2010 14:55     C:\Users\Standke\AppData\Local\Temp\000D.PDF --------- 322024  
     31.12.2009 15:19     C:\Users\Standke\AppData\Local\Temp\wmsetup.log --------- 11022  
     31.12.2009 15:18     C:\Users\Standke\AppData\Local\Temp\wmplog11.sqm --------- 2290  
     31.12.2009 15:16     C:\Users\Standke\AppData\Local\Temp\wmplog10.sqm --------- 1450  
     31.12.2009 15:15     C:\Users\Standke\AppData\Local\Temp\wmplog09.sqm --------- 3442  
     31.12.2009 15:09     C:\Users\Standke\AppData\Local\Temp\wmplog08.sqm --------- 1450  
     30.12.2009 15:44     C:\Users\Standke\AppData\Local\Temp\wmplog07.sqm --------- 1396  
     30.12.2009 15:36     C:\Users\Standke\AppData\Local\Temp\mwsqm01.sqm --------- 200  
     29.12.2009 17:27     C:\Users\Standke\AppData\Local\Temp\~cxd{92A5E872-3964-4F08-B039-B80471333BEA}.tmp --------- 5653  
     29.12.2009 17:27     C:\Users\Standke\AppData\Local\Temp\~cxd{A21051DE-5713-440A-8D99-34169285B00C}.tmp --------- 6770  
     29.12.2009 17:27     C:\Users\Standke\AppData\Local\Temp\~cxd{BFC9EC8D-F259-4D14-A187-6E8C282FADFD}.tmp --------- 5653  
     29.12.2009 17:27     C:\Users\Standke\AppData\Local\Temp\~cxd{A5ACA4EE-A145-4789-98AF-AD065BFFB385}.tmp --------- 6770  
     29.12.2009 16:55     C:\Users\Standke\AppData\Local\Temp\ge10004 --------- 0  
     29.12.2009 16:51     C:\Users\Standke\AppData\Local\Temp\mwsqm00.sqm --------- 188  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{2EACAC6E-38C7-4E29-84A1-8A3BF620A2BD}.tmp --------- 53  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{965E6C3E-172E-40B8-8936-6CB03D4FD1ED}.tmp --------- 474  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{EF193EFB-1B95-4304-919E-FC0E024565B8}.tmp --------- 111  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{72831C47-2C12-4A68-B7D3-68B6042F9B5C}.tmp --------- 111  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{9976AF15-9FB6-47E4-B8CF-926934317D2A}.tmp --------- 474  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{D7F16449-CCB9-4028-8CE3-0D97F0B776F5}.tmp --------- 53  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{7467D64C-F2EA-40FC-9376-FF00A9D98F11}.tmp --------- 0  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{BCD4E013-2A6C-4D8F-B4A4-FC3E4618FEF2}.tmp --------- 98  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{EDDB0E5B-78A0-4342-B86D-8735631F66A8}.tmp --------- 0  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{7CD61873-798F-47CE-A122-9F198FE513E4}.tmp --------- 98  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{3AACB49A-6E0A-4886-AF2D-CF95E76A0ED6}.tmp --------- 0  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{2ABA8479-D195-4A21-9D9E-609516AAEF83}.tmp --------- 98  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{8FEDBA2C-A329-40A3-AF5A-41C5BA9E32FE}.tmp --------- 0  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{381325CF-9157-44A1-BD0E-71FB2C0F57EB}.tmp --------- 318  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{AEA1A1D6-EF3B-4769-B96C-5537B604AE37}.tmp --------- 0  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{E796EF1F-0039-4889-8F17-7D5437D46556}.tmp --------- 98  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{B481F83F-88F8-4DE3-B414-87B60ECC99A3}.tmp --------- 0  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{E38994E4-6067-4EFC-AE42-389AE0B141F6}.tmp --------- 98  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{110FF815-FB7D-48FA-9EAB-253D94CDA961}.tmp --------- 0  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{484C6F23-18B6-4347-A5DE-A63D544DB8F7}.tmp --------- 98  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{3C197988-1356-4321-9FFE-53561B24FD78}.tmp --------- 0  
     29.12.2009 16:40     C:\Users\Standke\AppData\Local\Temp\~cxd{7E41B9FA-3FDD-49BC-A3F2-10DAE2AE2046}.tmp --------- 318  
     25.12.2009 10:30     C:\Users\Standke\AppData\Local\Temp\h2rA6C3.tmp --------- 36723  
     25.12.2009 10:30     C:\Users\Standke\AppData\Local\Temp\h2r9D7D.tmp --------- 36723  
     25.12.2009 10:30     C:\Users\Standke\AppData\Local\Temp\h2r95BD.tmp --------- 36723  
     24.12.2009 20:31     C:\Users\Standke\AppData\Local\Temp\ge9648 --------- 0  
     23.12.2009 16:00     C:\Users\Standke\AppData\Local\Temp\DSC_8517.JPG --------- 65291  
     23.12.2009 15:35     C:\Users\Standke\AppData\Local\Temp\tmp6DF0.tmp --------- 0  
     23.12.2009 15:35     C:\Users\Standke\AppData\Local\Temp\tmp6DEF.tmp --------- 0  
     23.12.2009 15:35     C:\Users\Standke\AppData\Local\Temp\tmp5D8A.tmp --------- 0  
     23.12.2009 15:24     C:\Users\Standke\AppData\Local\Temp\MRGE897.DOC --------- 422912  
     23.12.2009 15:02     C:\Users\Standke\AppData\Local\Temp\tmpF583.tmp --------- 0  
     23.12.2009 15:02     C:\Users\Standke\AppData\Local\Temp\tmpF582.tmp --------- 0  
     23.12.2009 15:02     C:\Users\Standke\AppData\Local\Temp\tmpE3E5.tmp --------- 0  
     23.12.2009 14:56     C:\Users\Standke\AppData\Local\Temp\tmp26B.tmp --------- 0  
     23.12.2009 14:56     C:\Users\Standke\AppData\Local\Temp\tmp26A.tmp --------- 0  
     23.12.2009 14:56     C:\Users\Standke\AppData\Local\Temp\tmpEDE0.tmp --------- 0  
     23.12.2009 09:29     C:\Users\Standke\AppData\Local\Temp\tmp1C5B.tmp --------- 0  
     23.12.2009 09:29     C:\Users\Standke\AppData\Local\Temp\tmp1C5A.tmp --------- 0  
     23.12.2009 09:29     C:\Users\Standke\AppData\Local\Temp\tmpB0A.tmp --------- 0  
     22.12.2009 18:00     C:\Users\Standke\AppData\Local\Temp\tmp9831.tmp --------- 0  
     22.12.2009 18:00     C:\Users\Standke\AppData\Local\Temp\tmp9821.tmp --------- 0  
     22.12.2009 18:00     C:\Users\Standke\AppData\Local\Temp\tmp7B8B.tmp --------- 0  
     22.12.2009 16:55     C:\Users\Standke\AppData\Local\Temp\tmp560A.tmp --------- 0  
     22.12.2009 16:50     C:\Users\Standke\AppData\Local\Temp\SmXAd1261497029.wav --------- 60  
     22.12.2009 16:50     C:\Users\Standke\AppData\Local\Temp\1261497029.csf --------- 88  
     22.12.2009 16:50     C:\Users\Standke\AppData\Local\Temp\SmXAd1261497029.DIR --------- 0  
     22.12.2009 16:50     C:\Users\Standke\AppData\Local\Temp\~$RG9FD0.DOC --------- 162  
     22.12.2009 16:26     C:\Users\Standke\AppData\Local\Temp\tmp25A6.tmp --------- 0  
     22.12.2009 16:26     C:\Users\Standke\AppData\Local\Temp\tmp25A5.tmp --------- 0  
     22.12.2009 16:26     C:\Users\Standke\AppData\Local\Temp\tmp1658.tmp --------- 0  
     22.12.2009 16:21     C:\Users\Standke\AppData\Local\Temp\tmpCE5F.tmp --------- 0  
     22.12.2009 16:21     C:\Users\Standke\AppData\Local\Temp\tmpCE5E.tmp --------- 0  
     22.12.2009 16:21     C:\Users\Standke\AppData\Local\Temp\tmpBF31.tmp --------- 0  
     22.12.2009 16:14     C:\Users\Standke\AppData\Local\Temp\tmpC805.tmp --------- 0  
     22.12.2009 16:14     C:\Users\Standke\AppData\Local\Temp\tmpC804.tmp --------- 0  
     22.12.2009 16:14     C:\Users\Standke\AppData\Local\Temp\tmpB7BD.tmp --------- 0  
     22.12.2009 16:10     C:\Users\Standke\AppData\Local\Temp\IaTemp_0CC222DAC373463E832B860AC859FE61.DIR --------- 0  
     22.12.2009 16:10     C:\Users\Standke\AppData\Local\Temp\IaTemp_0CC222DAC373463E832B860AC859FE61.wav --------- 170  
     22.12.2009 15:17     C:\Users\Standke\AppData\Local\Temp\Excel8.0 --------- 0  
     18.12.2009 15:00     C:\Users\Standke\AppData\Local\Temp\tmp65E6.tmp --------- 0  
     18.12.2009 15:00     C:\Users\Standke\AppData\Local\Temp\tmp65E5.tmp --------- 0  
     18.12.2009 15:00     C:\Users\Standke\AppData\Local\Temp\tmp563B.tmp --------- 0  
     18.12.2009 14:46     C:\Users\Standke\AppData\Local\Temp\tmp4D25.tmp --------- 0  
     18.12.2009 14:46     C:\Users\Standke\AppData\Local\Temp\tmp4D24.tmp --------- 0  
     18.12.2009 14:46     C:\Users\Standke\AppData\Local\Temp\tmp3243.tmp --------- 0  
     18.12.2009 14:35     C:\Users\Standke\AppData\Local\Temp\tmp1263.tmp --------- 0  
     18.12.2009 14:35     C:\Users\Standke\AppData\Local\Temp\tmp1262.tmp --------- 0  
     18.12.2009 14:35     C:\Users\Standke\AppData\Local\Temp\tmpF907.tmp --------- 0  
     18.12.2009 12:17     C:\Users\Standke\AppData\Local\Temp\GEHALTSMITTEILUNG 10-2009.PDF --------- 790399  
     18.12.2009 12:17     C:\Users\Standke\AppData\Local\Temp\ARBEITSVERTRAG HESSING INKL. NACHTR„GE.PDF --------- 1465858  
     18.12.2009 11:23     C:\Users\Standke\AppData\Local\Temp\tmpFE2B.tmp --------- 0  
     18.12.2009 11:23     C:\Users\Standke\AppData\Local\Temp\tmpFE2A.tmp --------- 0  
     18.12.2009 11:23     C:\Users\Standke\AppData\Local\Temp\tmpED96.tmp --------- 0  
     18.12.2009 11:17     C:\Users\Standke\AppData\Local\Temp\tmp6A13.tmp --------- 0  
     18.12.2009 11:17     C:\Users\Standke\AppData\Local\Temp\tmp6A12.tmp --------- 0  
     18.12.2009 11:17     C:\Users\Standke\AppData\Local\Temp\tmp5A49.tmp --------- 0  
     18.12.2009 10:31     C:\Users\Standke\AppData\Local\Temp\tmp21CA.tmp --------- 0  
     18.12.2009 10:31     C:\Users\Standke\AppData\Local\Temp\tmp21C9.tmp --------- 0  
     18.12.2009 10:31     C:\Users\Standke\AppData\Local\Temp\tmp1125.tmp --------- 0  
     18.12.2009 08:41     C:\Users\Standke\AppData\Local\Temp\0016.PDF --------- 256194  
     17.12.2009 17:24     C:\Users\Standke\AppData\Local\Temp\tmp678F.tmp --------- 0  
     17.12.2009 17:24     C:\Users\Standke\AppData\Local\Temp\tmp678E.tmp --------- 0  
     17.12.2009 17:24     C:\Users\Standke\AppData\Local\Temp\tmp5870.tmp --------- 0  
     17.12.2009 17:20     C:\Users\Standke\AppData\Local\Temp\tmpD3B6.tmp --------- 0  
     17.12.2009 17:20     C:\Users\Standke\AppData\Local\Temp\tmpD3B5.tmp --------- 0  
     17.12.2009 17:20     C:\Users\Standke\AppData\Local\Temp\tmpC1C9.tmp --------- 0  
     17.12.2009 16:45     C:\Users\Standke\AppData\Local\Temp\tmp9B54.tmp --------- 0  
     17.12.2009 16:45     C:\Users\Standke\AppData\Local\Temp\tmp9B53.tmp --------- 0  
     17.12.2009 16:45     C:\Users\Standke\AppData\Local\Temp\tmp6E78.tmp --------- 0  
     17.12.2009 15:34     C:\Users\Standke\AppData\Local\Temp\tmp1761.tmp --------- 0  
     17.12.2009 15:34     C:\Users\Standke\AppData\Local\Temp\tmp1751.tmp --------- 0  
     17.12.2009 15:34     C:\Users\Standke\AppData\Local\Temp\tmp48B.tmp --------- 0  
     17.12.2009 14:41     C:\Users\Standke\AppData\Local\Temp\tmp8C3E.tmp --------- 0  
     17.12.2009 14:41     C:\Users\Standke\AppData\Local\Temp\tmp8C3D.tmp --------- 0  
     17.12.2009 14:41     C:\Users\Standke\AppData\Local\Temp\tmp83E3.tmp --------- 0  
     17.12.2009 08:48     C:\Users\Standke\AppData\Local\Temp\tmp1365.tmp --------- 0  
     17.12.2009 08:48     C:\Users\Standke\AppData\Local\Temp\tmp1364.tmp --------- 0  
     17.12.2009 08:48     C:\Users\Standke\AppData\Local\Temp\tmp36C.tmp --------- 0  
     16.12.2009 15:54     C:\Users\Standke\AppData\Local\Temp\tmp51EA.tmp --------- 0  
     16.12.2009 15:54     C:\Users\Standke\AppData\Local\Temp\tmp51E9.tmp --------- 0  
     16.12.2009 15:54     C:\Users\Standke\AppData\Local\Temp\tmp3F81.tmp --------- 0  
     16.12.2009 15:12     C:\Users\Standke\AppData\Local\Temp\tmpC0A0.tmp --------- 0  
     16.12.2009 15:12     C:\Users\Standke\AppData\Local\Temp\tmpC09F.tmp --------- 0  
     16.12.2009 15:11     C:\Users\Standke\AppData\Local\Temp\tmpA07F.tmp --------- 0  
     16.12.2009 14:06     C:\Users\Standke\AppData\Local\Temp\_AnoImp.tmp --------- 676  
     16.12.2009 11:32     C:\Users\Standke\AppData\Local\Temp\MRG8328.DOC --------- 423936  
     16.12.2009 11:03     C:\Users\Standke\AppData\Local\Temp\VIREMENT PB 680?.PDF --------- 10554783  
     16.12.2009 10:47     C:\Users\Standke\AppData\Local\Temp\tmp988E.tmp --------- 0  
     16.12.2009 10:47     C:\Users\Standke\AppData\Local\Temp\tmp988D.tmp --------- 0  
     16.12.2009 10:47     C:\Users\Standke\AppData\Local\Temp\tmp88A6.tmp --------- 0  
     16.12.2009 08:52     C:\Users\Standke\AppData\Local\Temp\tmp95BE.tmp --------- 0  
     16.12.2009 08:52     C:\Users\Standke\AppData\Local\Temp\tmp95BD.tmp --------- 0  
     16.12.2009 08:52     C:\Users\Standke\AppData\Local\Temp\tmp8383.tmp --------- 0  
     15.12.2009 17:36     C:\Users\Standke\AppData\Local\Temp\tmpA427.tmp --------- 0  
     15.12.2009 17:36     C:\Users\Standke\AppData\Local\Temp\tmpA428.tmp --------- 0  
     15.12.2009 17:36     C:\Users\Standke\AppData\Local\Temp\tmp929A.tmp --------- 0  
     15.12.2009 14:58     C:\Users\Standke\AppData\Local\Temp\klein4.tif --------- 326180  
     15.12.2009 10:57     C:\Users\Standke\AppData\Local\Temp\tmp88F9.tmp --------- 0  
     15.12.2009 10:57     C:\Users\Standke\AppData\Local\Temp\tmp88F6.tmp --------- 0  
     15.12.2009 10:57     C:\Users\Standke\AppData\Local\Temp\tmp71ED.tmp --------- 0  
     15.12.2009 09:57     C:\Users\Standke\AppData\Local\Temp\tmp8663.tmp --------- 0  
     15.12.2009 09:57     C:\Users\Standke\AppData\Local\Temp\tmp8662.tmp --------- 0  
     15.12.2009 09:57     C:\Users\Standke\AppData\Local\Temp\tmp7E85.tmp --------- 0  
     15.12.2009 09:11     C:\Users\Standke\AppData\Local\Temp\tmpEAC2.tmp --------- 0  
     15.12.2009 09:10     C:\Users\Standke\AppData\Local\Temp\tmp73DD.tmp --------- 0  
     15.12.2009 09:10     C:\Users\Standke\AppData\Local\Temp\tmp73DC.tmp --------- 0  
     15.12.2009 09:10     C:\Users\Standke\AppData\Local\Temp\tmp62EA.tmp --------- 0  
     15.12.2009 09:08     C:\Users\Standke\AppData\Local\Temp\tmp2251.tmp --------- 0  
     14.12.2009 18:37     C:\Users\Standke\AppData\Local\Temp\tmp3E3F.tmp --------- 0  
     14.12.2009 18:35     C:\Users\Standke\AppData\Local\Temp\SmXAd1260812129.wav --------- 60  
     14.12.2009 18:35     C:\Users\Standke\AppData\Local\Temp\1260812130.csf --------- 88  
     14.12.2009 18:35     C:\Users\Standke\AppData\Local\Temp\SmXAd1260812129.DIR --------- 0  
     14.12.2009 18:35     C:\Users\Standke\AppData\Local\Temp\~$RGF87D.DOC --------- 162  
     14.12.2009 16:56     C:\Users\Standke\AppData\Local\Temp\tmp37C7.tmp --------- 0  
     14.12.2009 16:56     C:\Users\Standke\AppData\Local\Temp\tmp37C6.tmp --------- 0  
     14.12.2009 16:56     C:\Users\Standke\AppData\Local\Temp\tmp2944.tmp --------- 0  
     14.12.2009 16:30     C:\Users\Standke\AppData\Local\Temp\tmp54B5.tmp --------- 0  
     14.12.2009 16:30     C:\Users\Standke\AppData\Local\Temp\tmp54B4.tmp --------- 0  
     14.12.2009 16:30     C:\Users\Standke\AppData\Local\Temp\tmp4420.tmp --------- 0  
     14.12.2009 16:25     C:\Users\Standke\AppData\Local\Temp\tmp6D32.tmp --------- 0  
     14.12.2009 16:25     C:\Users\Standke\AppData\Local\Temp\tmp6D30.tmp --------- 0  
     14.12.2009 16:25     C:\Users\Standke\AppData\Local\Temp\tmp668B.tmp --------- 0  
     14.12.2009 16:09     C:\Users\Standke\AppData\Local\Temp\tmp6909.tmp --------- 0  
     14.12.2009 16:09     C:\Users\Standke\AppData\Local\Temp\tmp6908.tmp --------- 0  
     14.12.2009 16:09     C:\Users\Standke\AppData\Local\Temp\tmp60AE.tmp --------- 0  
     14.12.2009 15:17     C:\Users\Standke\AppData\Local\Temp\tmpDC8F.tmp --------- 0  
     14.12.2009 15:17     C:\Users\Standke\AppData\Local\Temp\tmpDC82.tmp --------- 0  
     14.12.2009 15:17     C:\Users\Standke\AppData\Local\Temp\tmpBC9E.tmp --------- 0  
     14.12.2009 11:13     C:\Users\Standke\AppData\Local\Temp\tmp3476.tmp --------- 0  
     14.12.2009 11:13     C:\Users\Standke\AppData\Local\Temp\tmp3475.tmp --------- 0  
     14.12.2009 11:13     C:\Users\Standke\AppData\Local\Temp\tmp28D0.tmp --------- 0  
     14.12.2009 05:21     C:\Users\Standke\AppData\Local\Temp\tmp2223.tmp --------- 0  
     14.12.2009 05:21     C:\Users\Standke\AppData\Local\Temp\tmp2224.tmp --------- 0  
     14.12.2009 05:21     C:\Users\Standke\AppData\Local\Temp\tmp120C.tmp --------- 0  
     14.12.2009 05:19     C:\Users\Standke\AppData\Local\Temp\IaTemp_8C2AEBEBAF4649268AACEB5291DDABC0.DIR --------- 0  
     14.12.2009 05:19     C:\Users\Standke\AppData\Local\Temp\IaTemp_8C2AEBEBAF4649268AACEB5291DDABC0.wav --------- 170  
     11.12.2009 16:42     C:\Users\Standke\AppData\Local\Temp\tmpA39F.tmp --------- 0  
     11.12.2009 16:42     C:\Users\Standke\AppData\Local\Temp\tmpA39E.tmp --------- 0  
     11.12.2009 16:42     C:\Users\Standke\AppData\Local\Temp\tmp948F.tmp --------- 0  
     11.12.2009 16:18     C:\Users\Standke\AppData\Local\Temp\tmp36E5.tmp --------- 0  
     11.12.2009 16:18     C:\Users\Standke\AppData\Local\Temp\tmp36E4.tmp --------- 0  
     11.12.2009 16:18     C:\Users\Standke\AppData\Local\Temp\tmp26DC.tmp --------- 0  
     11.12.2009 16:00     C:\Users\Standke\AppData\Local\Temp\tmp35E9.tmp --------- 0  
     11.12.2009 16:00     C:\Users\Standke\AppData\Local\Temp\tmp35E7.tmp --------- 0  
     11.12.2009 16:00     C:\Users\Standke\AppData\Local\Temp\tmp7F2.tmp --------- 0  
     11.12.2009 11:43     C:\Users\Standke\AppData\Local\Temp\MRG32C7.DLC --------- 6225  
     11.12.2009 11:42     C:\Users\Standke\AppData\Local\Temp\MRG32C7.DOC --------- 422400  
     11.12.2009 11:42     C:\Users\Standke\AppData\Local\Temp\tmp9C17.tmp --------- 0  
     11.12.2009 11:42     C:\Users\Standke\AppData\Local\Temp\tmp9C16.tmp --------- 0  
     11.12.2009 11:42     C:\Users\Standke\AppData\Local\Temp\tmp8B62.tmp --------- 0  
     11.12.2009 11:33     C:\Users\Standke\AppData\Local\Temp\IaTemp_EA2C798F490D49B083A66062C5314303.DIR --------- 0  
     11.12.2009 11:33     C:\Users\Standke\AppData\Local\Temp\IaTemp_EA2C798F490D49B083A66062C5314303.wav --------- 170  
     11.12.2009 11:33     C:\Users\Standke\AppData\Local\Temp\~$RG32C7.DOC --------- 162  
     11.12.2009 11:33     C:\Users\Standke\AppData\Local\Temp\MRG32C7.ADR --------- 40000  
     10.12.2009 17:13     C:\Users\Standke\AppData\Local\Temp\tmpBFF6.tmp --------- 0  
     10.12.2009 17:13     C:\Users\Standke\AppData\Local\Temp\tmpBFF5.tmp --------- 0  
     10.12.2009 17:13     C:\Users\Standke\AppData\Local\Temp\tmpB46F.tmp --------- 0  
     10.12.2009 16:20     C:\Users\Standke\AppData\Local\Temp\tmpDFA2.tmp --------- 0  
     10.12.2009 16:20     C:\Users\Standke\AppData\Local\Temp\tmpDFA1.tmp --------- 0  
     10.12.2009 16:20     C:\Users\Standke\AppData\Local\Temp\tmpAF8A.tmp --------- 0  
     10.12.2009 14:49     C:\Users\Standke\AppData\Local\Temp\002E.PDF --------- 1274157  
     10.12.2009 14:45     C:\Users\Standke\AppData\Local\Temp\0021.PDF --------- 229597  
     10.12.2009 10:44     C:\Users\Standke\AppData\Local\Temp\tmpD1C5.tmp --------- 0  
     10.12.2009 10:44     C:\Users\Standke\AppData\Local\Temp\tmpD1C4.tmp --------- 0  
     10.12.2009 10:44     C:\Users\Standke\AppData\Local\Temp\tmpC748.tmp --------- 0  
     09.12.2009 12:13     C:\Users\Standke\AppData\Local\Temp\tmp157E.tmp --------- 0  
     09.12.2009 12:13     C:\Users\Standke\AppData\Local\Temp\tmp157C.tmp --------- 0  
     09.12.2009 12:13     C:\Users\Standke\AppData\Local\Temp\tmp6AD.tmp --------- 0  
     09.12.2009 11:34     C:\Users\Standke\AppData\Local\Temp\tmp9948.tmp --------- 0  
     09.12.2009 11:34     C:\Users\Standke\AppData\Local\Temp\tmp9949.tmp --------- 0  
     09.12.2009 11:34     C:\Users\Standke\AppData\Local\Temp\tmp933E.tmp --------- 0  
     09.12.2009 11:27     C:\Users\Standke\AppData\Local\Temp\MRGB26B.DOC --------- 427008  
     08.12.2009 23:39     C:\Users\Standke\AppData\Local\Temp\tmp9353.tmp --------- 0  
     08.12.2009 23:39     C:\Users\Standke\AppData\Local\Temp\tmp9352.tmp --------- 0  
     08.12.2009 23:39     C:\Users\Standke\AppData\Local\Temp\tmp8404.tmp --------- 0  
     08.12.2009 17:57     C:\Users\Standke\AppData\Local\Temp\tmp5C03.tmp --------- 0  
     08.12.2009 17:57     C:\Users\Standke\AppData\Local\Temp\tmp5C02.tmp --------- 0  
     08.12.2009 17:57     C:\Users\Standke\AppData\Local\Temp\tmp495B.tmp --------- 0  
     08.12.2009 16:13     C:\Users\Standke\AppData\Local\Temp\MRG9.DOC --------- 91136  
     08.12.2009 14:33     C:\Users\Standke\AppData\Local\Temp\tmp7807.tmp --------- 0  
     08.12.2009 14:33     C:\Users\Standke\AppData\Local\Temp\tmp7806.tmp --------- 0  
     08.12.2009 14:32     C:\Users\Standke\AppData\Local\Temp\tmp53B4.tmp --------- 0  
     08.12.2009 14:27     C:\Users\Standke\AppData\Local\Temp\MRG5AA1.DOC --------- 462848  
     08.12.2009 13:01     C:\Users\Standke\AppData\Local\Temp\ge36828 --------- 0  
     08.12.2009 11:31     C:\Users\Standke\AppData\Local\Temp\tmp811C.tmp --------- 0  
     08.12.2009 11:31     C:\Users\Standke\AppData\Local\Temp\tmp811B.tmp --------- 0  
     08.12.2009 11:31     C:\Users\Standke\AppData\Local\Temp\tmp2DDC.tmp --------- 0  
     08.12.2009 10:51     C:\Users\Standke\AppData\Local\Temp\tmpA51B.tmp --------- 0  
     08.12.2009 10:51     C:\Users\Standke\AppData\Local\Temp\tmpA50B.tmp --------- 0  
     08.12.2009 10:51     C:\Users\Standke\AppData\Local\Temp\tmp826D.tmp --------- 0  
     08.12.2009 08:15     C:\Users\Standke\AppData\Local\Temp\0025.PDF --------- 990622  
     07.12.2009 16:55     C:\Users\Standke\AppData\Local\Temp\tmpB02C.tmp --------- 0  
     07.12.2009 16:55     C:\Users\Standke\AppData\Local\Temp\tmpB02B.tmp --------- 0  
     07.12.2009 16:54     C:\Users\Standke\AppData\Local\Temp\tmp8EE5.tmp --------- 0  
     07.12.2009 16:38     C:\Users\Standke\AppData\Local\Temp\tmp4CE3.tmp --------- 0  
     07.12.2009 16:38     C:\Users\Standke\AppData\Local\Temp\tmp4CD3.tmp --------- 0  
     07.12.2009 16:38     C:\Users\Standke\AppData\Local\Temp\tmp2B00.tmp --------- 0  
     07.12.2009 11:18     C:\Users\Standke\AppData\Local\Temp\tmp6B98.tmp --------- 0  
     07.12.2009 11:18     C:\Users\Standke\AppData\Local\Temp\tmp6B97.tmp --------- 0  
     07.12.2009 11:18     C:\Users\Standke\AppData\Local\Temp\tmp3588.tmp --------- 0  
     07.12.2009 11:10     C:\Users\Standke\AppData\Local\Temp\tmpADC1.tmp --------- 0  
     07.12.2009 11:10     C:\Users\Standke\AppData\Local\Temp\tmpADC0.tmp --------- 0  
     07.12.2009 11:10     C:\Users\Standke\AppData\Local\Temp\tmp99A3.tmp --------- 0  
     06.12.2009 17:14     C:\Users\Standke\AppData\Local\Temp\0004.PDF --------- 2677371  
     06.12.2009 17:08     C:\Users\Standke\AppData\Local\Temp\004C.PDF --------- 827395  
     06.12.2009 17:01     C:\Users\Standke\AppData\Local\Temp\tmpE104.tmp --------- 0  
     06.12.2009 17:01     C:\Users\Standke\AppData\Local\Temp\tmpE103.tmp --------- 0  
     06.12.2009 17:01     C:\Users\Standke\AppData\Local\Temp\tmpBACB.tmp --------- 0  
     06.12.2009 15:29     C:\Users\Standke\AppData\Local\Temp\0046.PDF --------- 279522  
     06.12.2009 14:31     C:\Users\Standke\AppData\Local\Temp\tmpDA58.tmp --------- 0  
     06.12.2009 14:31     C:\Users\Standke\AppData\Local\Temp\tmpDA57.tmp --------- 0  
     06.12.2009 14:30     C:\Users\Standke\AppData\Local\Temp\tmp9B43.tmp --------- 0  
     06.12.2009 13:43     C:\Users\Standke\AppData\Local\Temp\tmpA5FA.tmp --------- 0  
     06.12.2009 13:43     C:\Users\Standke\AppData\Local\Temp\tmpA5F9.tmp --------- 0  
     06.12.2009 13:43     C:\Users\Standke\AppData\Local\Temp\tmp8629.tmp --------- 0  
     06.12.2009 13:34     C:\Users\Standke\AppData\Local\Temp\tmpBA04.tmp --------- 0  
     06.12.2009 13:34     C:\Users\Standke\AppData\Local\Temp\tmpB9F3.tmp --------- 0  
     06.12.2009 13:34     C:\Users\Standke\AppData\Local\Temp\tmp9BB8.tmp --------- 0  
     06.12.2009 13:27     C:\Users\Standke\AppData\Local\Temp\tmp4E82.tmp --------- 0  
     06.12.2009 13:27     C:\Users\Standke\AppData\Local\Temp\tmp4E71.tmp --------- 0  
     06.12.2009 13:27     C:\Users\Standke\AppData\Local\Temp\tmp2EFF.tmp --------- 0  
     06.12.2009 11:28     C:\Users\Standke\AppData\Local\Temp\tmpEC31.tmp --------- 0  
     06.12.2009 11:28     C:\Users\Standke\AppData\Local\Temp\tmpEC30.tmp --------- 0  
     06.12.2009 11:28     C:\Users\Standke\AppData\Local\Temp\tmpCD1B.tmp --------- 0  
     06.12.2009 11:20     C:\Users\Standke\AppData\Local\Temp\tmpE184.tmp --------- 0  
     06.12.2009 11:20     C:\Users\Standke\AppData\Local\Temp\tmpE183.tmp --------- 0  
     06.12.2009 11:19     C:\Users\Standke\AppData\Local\Temp\tmpD1F8.tmp --------- 0  
     06.12.2009 10:40     C:\Users\Standke\AppData\Local\Temp\tmp9B0E.tmp --------- 0  
     06.12.2009 10:40     C:\Users\Standke\AppData\Local\Temp\tmp9B0D.tmp --------- 0  
     06.12.2009 10:40     C:\Users\Standke\AppData\Local\Temp\tmp7AC0.tmp --------- 0  
     06.12.2009 10:33     C:\Users\Standke\AppData\Local\Temp\tmpE553.tmp --------- 0  
     06.12.2009 10:33     C:\Users\Standke\AppData\Local\Temp\tmpE552.tmp --------- 0  
     06.12.2009 10:32     C:\Users\Standke\AppData\Local\Temp\tmpC68B.tmp --------- 0  
     04.12.2009 16:43     C:\Users\Standke\AppData\Local\Temp\tmp3771.tmp --------- 0  
     04.12.2009 16:43     C:\Users\Standke\AppData\Local\Temp\tmp3770.tmp --------- 0  
     04.12.2009 16:42     C:\Users\Standke\AppData\Local\Temp\tmp182C.tmp --------- 0  
     04.12.2009 15:00     C:\Users\Standke\AppData\Local\Temp\MRG3A3B.DOC --------- 26624  
     04.12.2009 14:12     C:\Users\Standke\AppData\Local\Temp\tmpCB7.tmp --------- 0  
     04.12.2009 14:12     C:\Users\Standke\AppData\Local\Temp\tmpCB6.tmp --------- 0  
     04.12.2009 14:12     C:\Users\Standke\AppData\Local\Temp\tmpF4E1.tmp --------- 0  
     04.12.2009 11:04     C:\Users\Standke\AppData\Local\Temp\MRG8E9B.DOC --------- 427008  
     04.12.2009 10:43     C:\Users\Standke\AppData\Local\Temp\tmp8AD.tmp --------- 0  
     04.12.2009 10:43     C:\Users\Standke\AppData\Local\Temp\tmp8AC.tmp --------- 0  
     04.12.2009 10:43     C:\Users\Standke\AppData\Local\Temp\tmpE6F9.tmp --------- 0  
     04.12.2009 08:29     C:\Users\Standke\AppData\Local\Temp\~$RGFE3C.DOC --------- 162  
     04.12.2009 08:29     C:\Users\Standke\AppData\Local\Temp\tmp699F.tmp --------- 0  
     04.12.2009 08:29     C:\Users\Standke\AppData\Local\Temp\tmp699E.tmp --------- 0  
     04.12.2009 08:29     C:\Users\Standke\AppData\Local\Temp\tmp5D00.tmp --------- 0  
     04.12.2009 08:23     C:\Users\Standke\AppData\Local\Temp\IaTemp_73394DD793DB418D8366392E7D25184B.DIR --------- 0  
     04.12.2009 08:23     C:\Users\Standke\AppData\Local\Temp\IaTemp_73394DD793DB418D8366392E7D25184B.wav --------- 170  
     03.12.2009 17:05     C:\Users\Standke\AppData\Local\Temp\ge65900 --------- 0  
     03.12.2009 17:00     C:\Users\Standke\AppData\Local\Temp\geColladaModelCacheLock --------- 0  
     03.12.2009 17:00     C:\Users\Standke\AppData\Local\Temp\geIconCacheLock --------- 0  
     03.12.2009 16:53     C:\Users\Standke\AppData\Local\Temp\tmpC3C0.tmp --------- 0  
     03.12.2009 16:53     C:\Users\Standke\AppData\Local\Temp\tmpC3BF.tmp --------- 0  
     03.12.2009 16:52     C:\Users\Standke\AppData\Local\Temp\tmpB50E.tmp --------- 0  
     03.12.2009 16:37     C:\Users\Standke\AppData\Local\Temp\tmpF94C.tmp --------- 0  
     03.12.2009 16:37     C:\Users\Standke\AppData\Local\Temp\tmpF94B.tmp --------- 0  
     03.12.2009 16:37     C:\Users\Standke\AppData\Local\Temp\tmpD8A1.tmp --------- 0  
     03.12.2009 14:45     C:\Users\Standke\AppData\Local\Temp\tmpC5E8.tmp --------- 0  
     03.12.2009 14:45     C:\Users\Standke\AppData\Local\Temp\tmpC5E7.tmp --------- 0  
     03.12.2009 14:45     C:\Users\Standke\AppData\Local\Temp\tmpBAA0.tmp --------- 0  
     03.12.2009 11:24     C:\Users\Standke\AppData\Local\Temp\0038.PDF --------- 240886  
     03.12.2009 10:58     C:\Users\Standke\AppData\Local\Temp\tmpA1A6.tmp --------- 0  
     03.12.2009 10:58     C:\Users\Standke\AppData\Local\Temp\tmpA1A5.tmp --------- 0  
     03.12.2009 10:58     C:\Users\Standke\AppData\Local\Temp\tmp7EE8.tmp --------- 0  
     03.12.2009 10:55     C:\Users\Standke\AppData\Local\Temp\~$RG43B2.DOC --------- 162  
     03.12.2009 10:52     C:\Users\Standke\AppData\Local\Temp\tmpC04A.tmp --------- 0  
     03.12.2009 10:52     C:\Users\Standke\AppData\Local\Temp\tmpC049.tmp --------- 0  
     03.12.2009 10:52     C:\Users\Standke\AppData\Local\Temp\tmp9DCA.tmp --------- 0  
     03.12.2009 10:26     C:\Users\Standke\AppData\Local\Temp\IaTemp_1DE3DF0650C34B93B2C8760FC5EA3BDE.DIR --------- 0  
     03.12.2009 10:26     C:\Users\Standke\AppData\Local\Temp\IaTemp_1DE3DF0650C34B93B2C8760FC5EA3BDE.wav --------- 170  
     02.12.2009 18:39     C:\Users\Standke\AppData\Local\Temp\MRG6F4F.DOC --------- 25088  
     02.12.2009 18:33     C:\Users\Standke\AppData\Local\Temp\tmpA9FB.tmp --------- 0  
     02.12.2009 18:33     C:\Users\Standke\AppData\Local\Temp\tmpA9FA.tmp --------- 0  
     02.12.2009 18:33     C:\Users\Standke\AppData\Local\Temp\tmp87B9.tmp --------- 0  
     02.12.2009 17:45     C:\Users\Standke\AppData\Local\Temp\tmp9CFC.tmp --------- 0  
     02.12.2009 17:45     C:\Users\Standke\AppData\Local\Temp\tmp9CFB.tmp --------- 0  
     02.12.2009 17:45     C:\Users\Standke\AppData\Local\Temp\tmp7D2B.tmp --------- 0  
     02.12.2009 16:33     C:\Users\Standke\AppData\Local\Temp\MRG2CF3.DOC --------- 424960  
     02.12.2009 16:17     C:\Users\Standke\AppData\Local\Temp\tmp755B.tmp --------- 0  
     02.12.2009 16:17     C:\Users\Standke\AppData\Local\Temp\tmp755A.tmp --------- 0  
     02.12.2009 16:17     C:\Users\Standke\AppData\Local\Temp\tmp5146.tmp --------- 0  
     02.12.2009 11:34     C:\Users\Standke\AppData\Local\Temp\MRG149D.DOC --------- 424960  
     02.12.2009 11:32     C:\Users\Standke\AppData\Local\Temp\tmpF10A.tmp --------- 0  
     02.12.2009 11:32     C:\Users\Standke\AppData\Local\Temp\tmpF109.tmp --------- 0  
     02.12.2009 11:32     C:\Users\Standke\AppData\Local\Temp\tmpD271.tmp --------- 0  
     01.12.2009 11:38     C:\Users\Standke\AppData\Local\Temp\tmp5906.tmp --------- 0  
     01.12.2009 11:38     C:\Users\Standke\AppData\Local\Temp\tmp58F5.tmp --------- 0  
     01.12.2009 11:38     C:\Users\Standke\AppData\Local\Temp\tmp4A35.tmp --------- 0  
     01.12.2009 09:33     C:\Users\Standke\AppData\Local\Temp\tmp2D6E.tmp --------- 0  
     01.12.2009 09:33     C:\Users\Standke\AppData\Local\Temp\tmp2D6D.tmp --------- 0  
     01.12.2009 09:32     C:\Users\Standke\AppData\Local\Temp\tmp102C.tmp --------- 0  
     01.12.2009 09:23     C:\Users\Standke\AppData\Local\Temp\tmp14CD.tmp --------- 0  
     01.12.2009 09:23     C:\Users\Standke\AppData\Local\Temp\tmp14CC.tmp --------- 0  
     01.12.2009 09:23     C:\Users\Standke\AppData\Local\Temp\tmpF25D.tmp --------- 0  
     30.11.2009 12:35     C:\Users\Standke\AppData\Local\Temp\MRG5425.DOC --------- 423936  
     30.11.2009 12:32     C:\Users\Standke\AppData\Local\Temp\tmp24A0.tmp --------- 0  
     30.11.2009 12:32     C:\Users\Standke\AppData\Local\Temp\tmp249F.tmp --------- 0  
     30.11.2009 12:32     C:\Users\Standke\AppData\Local\Temp\tmp2EB.tmp --------- 0  
     30.11.2009 12:20     C:\Users\Standke\AppData\Local\Temp\tmp246E.tmp --------- 0  
     30.11.2009 12:20     C:\Users\Standke\AppData\Local\Temp\tmp246D.tmp --------- 0  
     30.11.2009 12:20     C:\Users\Standke\AppData\Local\Temp\tmp18E8.tmp --------- 0  
     30.11.2009 12:14     C:\Users\Standke\AppData\Local\Temp\tmp550C.tmp --------- 0  
     30.11.2009 12:14     C:\Users\Standke\AppData\Local\Temp\tmp550B.tmp --------- 0  
     30.11.2009 12:14     C:\Users\Standke\AppData\Local\Temp\tmp4310.tmp --------- 0  
     30.11.2009 11:44     C:\Users\Standke\AppData\Local\Temp\JGP9NVN3.htm --------- 2445  
     29.11.2009 15:33     C:\Users\Standke\AppData\Local\Temp\Google Toolbar --------- 4096  
     27.11.2009 15:50     C:\Users\Standke\AppData\Local\Temp\tmp59D.tmp --------- 0  
     27.11.2009 15:50     C:\Users\Standke\AppData\Local\Temp\tmp58D.tmp --------- 0  
     27.11.2009 15:49     C:\Users\Standke\AppData\Local\Temp\tmpE58E.tmp --------- 0  
     27.11.2009 15:35     C:\Users\Standke\AppData\Local\Temp\tmpA99.tmp --------- 0  
     27.11.2009 15:35     C:\Users\Standke\AppData\Local\Temp\tmpA98.tmp --------- 0  
     27.11.2009 15:35     C:\Users\Standke\AppData\Local\Temp\tmpEC5E.tmp --------- 0  
     27.11.2009 15:30     C:\Users\Standke\AppData\Local\Temp\tmp2A75.tmp --------- 0  
     27.11.2009 15:30     C:\Users\Standke\AppData\Local\Temp\tmp2A74.tmp --------- 0  
     27.11.2009 15:30     C:\Users\Standke\AppData\Local\Temp\tmp853.tmp --------- 0  
     27.11.2009 15:04     C:\Users\Standke\AppData\Local\Temp\tmp9592.tmp --------- 0  
     27.11.2009 15:04     C:\Users\Standke\AppData\Local\Temp\tmp9591.tmp --------- 0  
     27.11.2009 15:04     C:\Users\Standke\AppData\Local\Temp\tmp719E.tmp --------- 0  
     27.11.2009 14:56     C:\Users\Standke\AppData\Local\Temp\~$RGD9BF.DOC --------- 162  
     27.11.2009 14:52     C:\Users\Standke\AppData\Local\Temp\tmpABE.tmp --------- 0  
     27.11.2009 14:52     C:\Users\Standke\AppData\Local\Temp\tmpABD.tmp --------- 0  
     27.11.2009 14:51     C:\Users\Standke\AppData\Local\Temp\tmpCF62.tmp --------- 0  
     27.11.2009 14:22     C:\Users\Standke\AppData\Local\Temp\MRGD065.DOC --------- 423936  
     27.11.2009 14:15     C:\Users\Standke\AppData\Local\Temp\tmp9A9A.tmp --------- 0  
     27.11.2009 14:15     C:\Users\Standke\AppData\Local\Temp\tmp9A8A.tmp --------- 0  
     27.11.2009 14:15     C:\Users\Standke\AppData\Local\Temp\tmp7ABA.tmp --------- 0  
     27.11.2009 12:20     C:\Users\Standke\AppData\Local\Temp\MRG8BF1.DOC --------- 442880  
     27.11.2009 11:44     C:\Users\Standke\AppData\Local\Temp\tmp8292.tmp --------- 0  
     27.11.2009 11:44     C:\Users\Standke\AppData\Local\Temp\tmp8283.tmp --------- 0  
     27.11.2009 11:44     C:\Users\Standke\AppData\Local\Temp\tmp6244.tmp --------- 0  
     27.11.2009 11:24     C:\Users\Standke\AppData\Local\Temp\tmpF7FC.tmp --------- 0  
     27.11.2009 11:24     C:\Users\Standke\AppData\Local\Temp\tmpF7FB.tmp --------- 0  
     27.11.2009 11:24     C:\Users\Standke\AppData\Local\Temp\tmpD7DD.tmp --------- 0  
     27.11.2009 10:47     C:\Users\Standke\AppData\Local\Temp\MRG2C56.DOC --------- 45056  
     27.11.2009 10:40     C:\Users\Standke\AppData\Local\Temp\tmpBE62.tmp --------- 0  
     27.11.2009 10:40     C:\Users\Standke\AppData\Local\Temp\tmpBE61.tmp --------- 0  
     27.11.2009 10:40     C:\Users\Standke\AppData\Local\Temp\tmp9FE8.tmp --------- 0  
     27.11.2009 09:54     C:\Users\Standke\AppData\Local\Temp\tmpD566.tmp --------- 0  
     27.11.2009 09:54     C:\Users\Standke\AppData\Local\Temp\tmpD565.tmp --------- 0  
     27.11.2009 09:54     C:\Users\Standke\AppData\Local\Temp\tmpB97B.tmp --------- 0  
     27.11.2009 09:43     C:\Users\Standke\AppData\Local\Temp\tmpEDF2.tmp --------- 0  
     27.11.2009 09:43     C:\Users\Standke\AppData\Local\Temp\tmpEDE1.tmp --------- 0  
     27.11.2009 09:42     C:\Users\Standke\AppData\Local\Temp\tmpCF97.tmp --------- 0  
     27.11.2009 09:14     C:\Users\Standke\AppData\Local\Temp\tmp6407.tmp --------- 0  
     27.11.2009 09:14     C:\Users\Standke\AppData\Local\Temp\tmp6406.tmp --------- 0  
     27.11.2009 09:13     C:\Users\Standke\AppData\Local\Temp\tmp4771.tmp --------- 0  
     27.11.2009 08:56     C:\Users\Standke\AppData\Local\Temp\tmp802B.tmp --------- 0  
     27.11.2009 08:56     C:\Users\Standke\AppData\Local\Temp\tmp802A.tmp --------- 0  
     27.11.2009 08:56     C:\Users\Standke\AppData\Local\Temp\tmp5F41.tmp --------- 0  
     27.11.2009 08:53     C:\Users\Standke\AppData\Local\Temp\IaTemp_977D6B9EB8F24094860BB5D084633E51.DIR --------- 0  
     27.11.2009 08:53     C:\Users\Standke\AppData\Local\Temp\IaTemp_977D6B9EB8F24094860BB5D084633E51.wav --------- 170  
     26.11.2009 14:07     C:\Users\Standke\AppData\Local\Temp\MRG7BF4.DOC --------- 43008  
     26.11.2009 13:54     C:\Users\Standke\AppData\Local\Temp\tmp590.tmp --------- 0  
     26.11.2009 13:54     C:\Users\Standke\AppData\Local\Temp\tmp58F.tmp --------- 0  
     26.11.2009 13:54     C:\Users\Standke\AppData\Local\Temp\tmpDB44.tmp --------- 0  
     26.11.2009 11:48     C:\Users\Standke\AppData\Local\Temp\tmpD2C8.tmp --------- 0  
     26.11.2009 11:48     C:\Users\Standke\AppData\Local\Temp\tmpD2C7.tmp --------- 0  
     26.11.2009 11:48     C:\Users\Standke\AppData\Local\Temp\tmpB180.tmp --------- 0  
     26.11.2009 11:25     C:\Users\Standke\AppData\Local\Temp\MRGAB11.DOC --------- 23040  
     26.11.2009 11:14     C:\Users\Standke\AppData\Local\Temp\tmp3D68.tmp --------- 0  
     26.11.2009 11:14     C:\Users\Standke\AppData\Local\Temp\tmp3D67.tmp --------- 0  
     26.11.2009 11:13     C:\Users\Standke\AppData\Local\Temp\tmp183A.tmp --------- 0  
     26.11.2009 10:55     C:\Users\Standke\AppData\Local\Temp\tmpF52F.tmp --------- 0  
     26.11.2009 10:55     C:\Users\Standke\AppData\Local\Temp\tmpF52E.tmp --------- 0  
     26.11.2009 10:54     C:\Users\Standke\AppData\Local\Temp\tmp98BD.tmp --------- 0  
     26.11.2009 09:23     C:\Users\Standke\AppData\Local\Temp\h2rFCFB.tmp --------- 0  
     26.11.2009 09:23     C:\Users\Standke\AppData\Local\Temp\r2hFCFA.tmp --------- 1061  
     26.11.2009 09:22     C:\Users\Standke\AppData\Local\Temp\h2r76B9.tmp --------- 0  
     26.11.2009 09:22     C:\Users\Standke\AppData\Local\Temp\r2h76B8.tmp --------- 448  
     25.11.2009 18:09     C:\Users\Standke\AppData\Local\Temp\tmpC2A.tmp --------- 0  
     25.11.2009 18:09     C:\Users\Standke\AppData\Local\Temp\tmpC29.tmp --------- 0  
     25.11.2009 18:08     C:\Users\Standke\AppData\Local\Temp\tmpEC49.tmp --------- 0  
     25.11.2009 17:36     C:\Users\Standke\AppData\Local\Temp\tmp4D7B.tmp --------- 0  
     25.11.2009 17:36     C:\Users\Standke\AppData\Local\Temp\tmp4D7A.tmp --------- 0  
     25.11.2009 17:36     C:\Users\Standke\AppData\Local\Temp\tmp2723.tmp --------- 0  
     25.11.2009 17:15     C:\Users\Standke\AppData\Local\Temp\tmpFE6D.tmp --------- 0  
     25.11.2009 17:15     C:\Users\Standke\AppData\Local\Temp\tmpFE6C.tmp --------- 0  
     25.11.2009 17:15     C:\Users\Standke\AppData\Local\Temp\tmpE975.tmp --------- 0  
     25.11.2009 14:39     C:\Users\Standke\AppData\Local\Temp\tmp24DA.tmp --------- 0  
     25.11.2009 14:39     C:\Users\Standke\AppData\Local\Temp\tmp24C9.tmp --------- 0  
     25.11.2009 14:39     C:\Users\Standke\AppData\Local\Temp\tmp157D.tmp --------- 0  
     25.11.2009 10:02     C:\Users\Standke\AppData\Local\Temp\tmp83B6.tmp --------- 0  
     25.11.2009 10:02     C:\Users\Standke\AppData\Local\Temp\tmp83B5.tmp --------- 0  
     25.11.2009 10:02     C:\Users\Standke\AppData\Local\Temp\tmp6EED.tmp --------- 0  
     24.11.2009 11:23     C:\Users\Standke\AppData\Local\Temp\tmp4795.tmp --------- 0  
     24.11.2009 11:23     C:\Users\Standke\AppData\Local\Temp\tmp4785.tmp --------- 0  
     24.11.2009 11:23     C:\Users\Standke\AppData\Local\Temp\tmp13B8.tmp --------- 0  
     24.11.2009 08:08     C:\Users\Standke\AppData\Local\Temp\tmp40CB.tmp --------- 0  
     24.11.2009 08:08     C:\Users\Standke\AppData\Local\Temp\tmp40CA.tmp --------- 0  
     24.11.2009 08:07     C:\Users\Standke\AppData\Local\Temp\tmp2167.tmp --------- 0  
     24.11.2009 07:54     C:\Users\Standke\AppData\Local\Temp\0290.PDF --------- 40148  
     23.11.2009 18:24     C:\Users\Standke\AppData\Local\Temp\MRG9975.DOC --------- 32768  
     23.11.2009 18:11     C:\Users\Standke\AppData\Local\Temp\tmp989.tmp --------- 0  
     23.11.2009 18:11     C:\Users\Standke\AppData\Local\Temp\tmp988.tmp --------- 0  
     23.11.2009 18:11     C:\Users\Standke\AppData\Local\Temp\tmpE313.tmp --------- 0  
     23.11.2009 13:42     C:\Users\Standke\AppData\Local\Temp\tmp208B.tmp --------- 0  
     23.11.2009 13:42     C:\Users\Standke\AppData\Local\Temp\tmp208A.tmp --------- 0  
     23.11.2009 13:41     C:\Users\Standke\AppData\Local\Temp\tmpFB5D.tmp --------- 0  
     23.11.2009 11:13     C:\Users\Standke\AppData\Local\Temp\MRG948F.DOC --------- 424448  
     23.11.2009 11:10     C:\Users\Standke\AppData\Local\Temp\tmp9B5F.tmp --------- 0  
     23.11.2009 11:10     C:\Users\Standke\AppData\Local\Temp\tmp9B5E.tmp --------- 0  
     23.11.2009 11:10     C:\Users\Standke\AppData\Local\Temp\tmp7853.tmp --------- 0  
     23.11.2009 09:04     C:\Users\Standke\AppData\Local\Temp\tmpF941.tmp --------- 0  
     23.11.2009 09:04     C:\Users\Standke\AppData\Local\Temp\tmpF940.tmp --------- 0  
     23.11.2009 09:04     C:\Users\Standke\AppData\Local\Temp\tmpED5D.tmp --------- 0  
     20.11.2009 19:01     C:\Users\Standke\AppData\Local\Temp\MRGEE57.DOC --------- 18432  
     20.11.2009 18:44     C:\Users\Standke\AppData\Local\Temp\tmp32E1.tmp --------- 0  
     20.11.2009 18:44     C:\Users\Standke\AppData\Local\Temp\tmp32D0.tmp --------- 0  
     20.11.2009 18:43     C:\Users\Standke\AppData\Local\Temp\tmpEC10.tmp --------- 0  
     20.11.2009 17:07     C:\Users\Standke\AppData\Local\Temp\0007.PDF --------- 1597069  
     20.11.2009 17:00     C:\Users\Standke\AppData\Local\Temp\tmp11A6.tmp --------- 0  
     20.11.2009 17:00     C:\Users\Standke\AppData\Local\Temp\tmp11A5.tmp --------- 0  
     20.11.2009 17:00     C:\Users\Standke\AppData\Local\Temp\tmp2B6.tmp --------- 0  
     20.11.2009 15:53     C:\Users\Standke\AppData\Local\Temp\MRGC51F.DOC --------- 18432  
     20.11.2009 15:50     C:\Users\Standke\AppData\Local\Temp\tmp4204.tmp --------- 0  
     20.11.2009 15:50     C:\Users\Standke\AppData\Local\Temp\tmp4203.tmp --------- 0  
     20.11.2009 15:50     C:\Users\Standke\AppData\Local\Temp\tmp2DA8.tmp --------- 0  
     20.11.2009 11:04     C:\Users\Standke\AppData\Local\Temp\tmp156C.tmp --------- 0  
     20.11.2009 11:04     C:\Users\Standke\AppData\Local\Temp\tmp156B.tmp --------- 0  
     20.11.2009 11:04     C:\Users\Standke\AppData\Local\Temp\tmpF6B4.tmp --------- 0  
     20.11.2009 11:00     C:\Users\Standke\AppData\Local\Temp\tmpDC81.tmp --------- 0  
     20.11.2009 11:00     C:\Users\Standke\AppData\Local\Temp\tmpDC7E.tmp --------- 0  
     20.11.2009 11:00     C:\Users\Standke\AppData\Local\Temp\tmpBA3E.tmp --------- 0  
     20.11.2009 10:12     C:\Users\Standke\AppData\Local\Temp\tmpEB1B.tmp --------- 0  
     20.11.2009 10:12     C:\Users\Standke\AppData\Local\Temp\tmpEB1A.tmp --------- 0  
     20.11.2009 10:12     C:\Users\Standke\AppData\Local\Temp\tmpCF4F.tmp --------- 0  
     20.11.2009 10:07     C:\Users\Standke\AppData\Local\Temp\tmp4162.tmp --------- 0  
     20.11.2009 10:07     C:\Users\Standke\AppData\Local\Temp\tmp4161.tmp --------- 0  
     20.11.2009 10:07     C:\Users\Standke\AppData\Local\Temp\tmp2374.tmp --------- 0  
     20.11.2009 09:58     C:\Users\Standke\AppData\Local\Temp\tmpEF1A.tmp --------- 0  
     20.11.2009 09:58     C:\Users\Standke\AppData\Local\Temp\tmpEF19.tmp --------- 0  
     20.11.2009 09:58     C:\Users\Standke\AppData\Local\Temp\tmpD34F.tmp --------- 0  
     20.11.2009 09:51     C:\Users\Standke\AppData\Local\Temp\tmp4928.tmp --------- 0  
     20.11.2009 09:51     C:\Users\Standke\AppData\Local\Temp\tmp4927.tmp --------- 0  
     20.11.2009 09:51     C:\Users\Standke\AppData\Local\Temp\tmp23FA.tmp --------- 0  
     20.11.2009 09:29     C:\Users\Standke\AppData\Local\Temp\tmp939C.tmp --------- 0  
     20.11.2009 09:29     C:\Users\Standke\AppData\Local\Temp\tmp939B.tmp --------- 0  
     20.11.2009 09:29     C:\Users\Standke\AppData\Local\Temp\tmp718B.tmp --------- 0  
     19.11.2009 16:59     C:\Users\Standke\AppData\Local\Temp\tmpD38B.tmp --------- 0  
     19.11.2009 16:59     C:\Users\Standke\AppData\Local\Temp\tmpD38A.tmp --------- 0  
     19.11.2009 16:59     C:\Users\Standke\AppData\Local\Temp\tmpB4A3.tmp --------- 0  
     19.11.2009 15:59     C:\Users\Standke\AppData\Local\Temp\MRG37.DOC --------- 55296  
     19.11.2009 08:24     C:\Users\Standke\AppData\Local\Temp\ge7500 --------- 0  
     18.11.2009 13:16     C:\Users\Standke\AppData\Local\Temp\tmp48FA.tmp --------- 0  
     18.11.2009 13:16     C:\Users\Standke\AppData\Local\Temp\tmp48F9.tmp --------- 0  
     18.11.2009 13:16     C:\Users\Standke\AppData\Local\Temp\tmp348E.tmp --------- 0  
     17.11.2009 16:16     C:\Users\Standke\AppData\Local\Temp\tmpAB55.tmp --------- 0  
     17.11.2009 16:16     C:\Users\Standke\AppData\Local\Temp\tmpAB54.tmp --------- 0  
     17.11.2009 16:16     C:\Users\Standke\AppData\Local\Temp\tmp8C4E.tmp --------- 0  
     17.11.2009 16:12     C:\Users\Standke\AppData\Local\Temp\0008.PDF --------- 471397  
     17.11.2009 16:06     C:\Users\Standke\AppData\Local\Temp\tmpD1D5.tmp --------- 0  
     17.11.2009 16:06     C:\Users\Standke\AppData\Local\Temp\tmpD1D4.tmp --------- 0  
     17.11.2009 16:06     C:\Users\Standke\AppData\Local\Temp\tmpC545.tmp --------- 0  
     17.11.2009 16:03     C:\Users\Standke\AppData\Local\Temp\tmp8BBD.tmp --------- 0  
     17.11.2009 16:03     C:\Users\Standke\AppData\Local\Temp\tmp8BBC.tmp --------- 0  
     17.11.2009 16:03     C:\Users\Standke\AppData\Local\Temp\tmp6EBA.tmp --------- 0  
     17.11.2009 15:59     C:\Users\Standke\AppData\Local\Temp\tmp4CF6.tmp --------- 0  
     17.11.2009 15:59     C:\Users\Standke\AppData\Local\Temp\tmp4CF5.tmp --------- 0  
     17.11.2009 15:59     C:\Users\Standke\AppData\Local\Temp\tmp2F95.tmp --------- 0  
     17.11.2009 15:56     C:\Users\Standke\AppData\Local\Temp\tmp42B6.tmp --------- 0  
     17.11.2009 15:56     C:\Users\Standke\AppData\Local\Temp\tmp42B5.tmp --------- 0  
     17.11.2009 15:56     C:\Users\Standke\AppData\Local\Temp\tmp3627.tmp --------- 0  
     17.11.2009 10:58     C:\Users\Standke\AppData\Local\Temp\tmpCB95.tmp --------- 0  
     17.11.2009 10:58     C:\Users\Standke\AppData\Local\Temp\tmpCB94.tmp --------- 0  
     17.11.2009 10:58     C:\Users\Standke\AppData\Local\Temp\tmpAA5D.tmp --------- 0  
     17.11.2009 10:44     C:\Users\Standke\AppData\Local\Temp\tmpC7BB.tmp --------- 0  
     17.11.2009 10:44     C:\Users\Standke\AppData\Local\Temp\tmpC7AA.tmp --------- 0  
     17.11.2009 10:44     C:\Users\Standke\AppData\Local\Temp\tmpBA03.tmp --------- 0  
     17.11.2009 09:44     C:\Users\Standke\AppData\Local\Temp\MRGCB6E.DOC --------- 423936  
     17.11.2009 09:41     C:\Users\Standke\AppData\Local\Temp\tmp92D2.tmp --------- 0  
     17.11.2009 09:41     C:\Users\Standke\AppData\Local\Temp\tmp92D1.tmp --------- 0  
     17.11.2009 09:40     C:\Users\Standke\AppData\Local\Temp\tmp7310.tmp --------- 0  
     17.11.2009 09:23     C:\Users\Standke\AppData\Local\Temp\0017.PDF --------- 85762  
     16.11.2009 16:45     C:\Users\Standke\AppData\Local\Temp\tmp1ED0.tmp --------- 0  
     16.11.2009 16:45     C:\Users\Standke\AppData\Local\Temp\tmp1ECF.tmp --------- 0  
     16.11.2009 16:45     C:\Users\Standke\AppData\Local\Temp\tmpFB47.tmp --------- 0  
     16.11.2009 10:35     C:\Users\Standke\AppData\Local\Temp\tmp3929.tmp --------- 0  
     16.11.2009 10:35     C:\Users\Standke\AppData\Local\Temp\tmp3928.tmp --------- 0  
     16.11.2009 10:35     C:\Users\Standke\AppData\Local\Temp\tmp12D2.tmp --------- 0  
     16.11.2009 10:20     C:\Users\Standke\AppData\Local\Temp\tmpCABA.tmp --------- 0  
     16.11.2009 10:20     C:\Users\Standke\AppData\Local\Temp\tmpCAB9.tmp --------- 0  
     16.11.2009 10:20     C:\Users\Standke\AppData\Local\Temp\tmpA676.tmp --------- 0  
     16.11.2009 10:04     C:\Users\Standke\AppData\Local\Temp\tmpD773.tmp --------- 0  
     16.11.2009 10:04     C:\Users\Standke\AppData\Local\Temp\tmpD772.tmp --------- 0  
     16.11.2009 10:04     C:\Users\Standke\AppData\Local\Temp\tmpCC4B.tmp --------- 0  
     16.11.2009 09:57     C:\Users\Standke\AppData\Local\Temp\tmpB782.tmp --------- 0  
     16.11.2009 09:57     C:\Users\Standke\AppData\Local\Temp\tmpB781.tmp --------- 0  
     16.11.2009 09:57     C:\Users\Standke\AppData\Local\Temp\tmp9688.tmp --------- 0  
     16.11.2009 09:13     C:\Users\Standke\AppData\Local\Temp\MRGF5F5.PDF --------- 129298  
     13.11.2009 15:19     C:\Users\Standke\AppData\Local\Temp\tmp3098.tmp --------- 0  
     13.11.2009 15:19     C:\Users\Standke\AppData\Local\Temp\tmp3097.tmp --------- 0  
     13.11.2009 15:19     C:\Users\Standke\AppData\Local\Temp\tmp10D7.tmp --------- 0  
     13.11.2009 15:14     C:\Users\Standke\AppData\Local\Temp\tmpEAFE.tmp --------- 0  
     13.11.2009 15:14     C:\Users\Standke\AppData\Local\Temp\tmpEAED.tmp --------- 0  
     13.11.2009 15:13     C:\Users\Standke\AppData\Local\Temp\tmpC8EB.tmp --------- 0  
     12.11.2009 17:48     C:\Users\Standke\AppData\Local\Temp\MRGD34A.DOC --------- 425984  
     12.11.2009 17:46     C:\Users\Standke\AppData\Local\Temp\tmpD020.tmp --------- 0  
     12.11.2009 17:46     C:\Users\Standke\AppData\Local\Temp\tmpD01F.tmp --------- 0  
     12.11.2009 17:45     C:\Users\Standke\AppData\Local\Temp\tmp9426.tmp --------- 0  
     12.11.2009 15:13     C:\Users\Standke\AppData\Local\Temp\tmp923F.tmp --------- 0  
     12.11.2009 15:13     C:\Users\Standke\AppData\Local\Temp\tmp922E.tmp --------- 0  
     12.11.2009 15:13     C:\Users\Standke\AppData\Local\Temp\tmp6B4C.tmp --------- 0  
     12.11.2009 14:18     C:\Users\Standke\AppData\Local\Temp\tmp7587.tmp --------- 0  
     12.11.2009 14:18     C:\Users\Standke\AppData\Local\Temp\tmp7586.tmp --------- 0  
     12.11.2009 14:18     C:\Users\Standke\AppData\Local\Temp\tmp68CA.tmp --------- 0  
     12.11.2009 12:26     C:\Users\Standke\AppData\Local\Temp\tmp68F0.tmp --------- 0  
     12.11.2009 12:26     C:\Users\Standke\AppData\Local\Temp\tmp68EF.tmp --------- 0  
     12.11.2009 12:26     C:\Users\Standke\AppData\Local\Temp\tmp4A08.tmp --------- 0  
     12.11.2009 09:37     C:\Users\Standke\AppData\Local\Temp\tmpB449.tmp --------- 0  
     12.11.2009 09:37     C:\Users\Standke\AppData\Local\Temp\tmpB448.tmp --------- 0  
     12.11.2009 09:37     C:\Users\Standke\AppData\Local\Temp\tmp93FB.tmp --------- 0  
     12.11.2009 09:30     C:\Users\Standke\AppData\Local\Temp\tmp9938.tmp --------- 0  
     12.11.2009 09:30     C:\Users\Standke\AppData\Local\Temp\tmp9937.tmp --------- 0  
     12.11.2009 09:30     C:\Users\Standke\AppData\Local\Temp\tmp7A41.tmp --------- 0  
     11.11.2009 10:11     C:\Users\Standke\AppData\Local\Temp\tmpE21A.tmp --------- 0  
     11.11.2009 10:11     C:\Users\Standke\AppData\Local\Temp\tmpE219.tmp --------- 0  
     11.11.2009 10:11     C:\Users\Standke\AppData\Local\Temp\tmpBAF9.tmp --------- 0  
     10.11.2009 15:50     C:\Users\Standke\AppData\Local\Temp\tmpFBBE.tmp --------- 0  
     10.11.2009 15:50     C:\Users\Standke\AppData\Local\Temp\tmpFBBD.tmp --------- 0  
     10.11.2009 15:50     C:\Users\Standke\AppData\Local\Temp\tmpDDB1.tmp --------- 0  
     10.11.2009 12:23     C:\Users\Standke\AppData\Local\Temp\tmp719D.tmp --------- 0  
     10.11.2009 12:23     C:\Users\Standke\AppData\Local\Temp\tmp719C.tmp --------- 0  
     10.11.2009 12:23     C:\Users\Standke\AppData\Local\Temp\tmp4AF8.tmp --------- 0  
     10.11.2009 10:15     C:\Users\Standke\AppData\Local\Temp\MRG48ED.DOC --------- 78848  
     09.11.2009 15:25     C:\Users\Standke\AppData\Local\Temp\MRGBB9A.PDF --------- 445936  
     09.11.2009 10:17     C:\Users\Standke\AppData\Local\Temp\0011.PDF --------- 158452  
     06.11.2009 12:13     C:\Users\Standke\AppData\Local\Temp\MRGC7BB.DOC --------- 32256  
     05.11.2009 12:01     C:\Users\Standke\AppData\Local\Temp\tmp83AD.tmp --------- 0  
     05.11.2009 12:01     C:\Users\Standke\AppData\Local\Temp\tmp83AC.tmp --------- 0  
     05.11.2009 12:00     C:\Users\Standke\AppData\Local\Temp\tmp6052.tmp --------- 0  
     05.11.2009 11:52     C:\Users\Standke\AppData\Local\Temp\tmp4C06.tmp --------- 0  
     05.11.2009 11:52     C:\Users\Standke\AppData\Local\Temp\tmp4C05.tmp --------- 0  
     05.11.2009 11:51     C:\Users\Standke\AppData\Local\Temp\tmpF4A1.tmp --------- 0  
     05.11.2009 10:16     C:\Users\Standke\AppData\Local\Temp\028F.PDF --------- 129298  
     04.11.2009 10:00     C:\Users\Standke\AppData\Local\Temp\001E.PDF --------- 683853  
     04.11.2009 09:49     C:\Users\Standke\AppData\Local\Temp\tmpC1F1.tmp --------- 0  
     04.11.2009 09:49     C:\Users\Standke\AppData\Local\Temp\tmpC1E0.tmp --------- 0  
     04.11.2009 09:49     C:\Users\Standke\AppData\Local\Temp\tmpA2DB.tmp --------- 0  
     04.11.2009 09:40     C:\Users\Standke\AppData\Local\Temp\tmpFFD7.tmp --------- 0  
     04.11.2009 09:40     C:\Users\Standke\AppData\Local\Temp\tmpFFD6.tmp --------- 0  
     04.11.2009 09:39     C:\Users\Standke\AppData\Local\Temp\tmpDB17.tmp --------- 0  
     03.11.2009 16:17     C:\Users\Standke\AppData\Local\Temp\ge53000 --------- 0  
     03.11.2009 16:02     C:\Users\Standke\AppData\Local\Temp\tmp3A4F.tmp --------- 0  
     03.11.2009 16:02     C:\Users\Standke\AppData\Local\Temp\tmp3A3E.tmp --------- 0  
     03.11.2009 16:02     C:\Users\Standke\AppData\Local\Temp\tmpF41A.tmp --------- 0  
     03.11.2009 15:08     C:\Users\Standke\AppData\Local\Temp\ge36724 --------- 0  
     02.11.2009 17:12     C:\Users\Standke\AppData\Local\Temp\tmp1F58.tmp --------- 0  
     02.11.2009 17:12     C:\Users\Standke\AppData\Local\Temp\tmp1F57.tmp --------- 0  
     02.11.2009 17:12     C:\Users\Standke\AppData\Local\Temp\tmpE18C.tmp --------- 0  
     02.11.2009 12:06     C:\Users\Standke\AppData\Local\Temp\tmp8668.tmp --------- 0  
     02.11.2009 12:06     C:\Users\Standke\AppData\Local\Temp\tmp8658.tmp --------- 0  
     02.11.2009 12:06     C:\Users\Standke\AppData\Local\Temp\tmp7009.tmp --------- 0  
     02.11.2009 09:25     C:\Users\Standke\AppData\Local\Temp\MRG8D16.DOC --------- 450560  
     30.10.2009 12:22     C:\Users\Standke\AppData\Local\Temp\tmpABAA.tmp --------- 0  
     30.10.2009 12:22     C:\Users\Standke\AppData\Local\Temp\tmpABA9.tmp --------- 0  
     30.10.2009 12:22     C:\Users\Standke\AppData\Local\Temp\tmp8B2D.tmp --------- 0  
     30.10.2009 12:16     C:\Users\Standke\AppData\Local\Temp\tmp2CA8.tmp --------- 0  
     30.10.2009 12:16     C:\Users\Standke\AppData\Local\Temp\tmp2CA7.tmp --------- 0  
     30.10.2009 12:16     C:\Users\Standke\AppData\Local\Temp\tmpC98.tmp --------- 0  
     30.10.2009 10:50     C:\Users\Standke\AppData\Local\Temp\tmp4C42.tmp --------- 0  
     30.10.2009 10:50     C:\Users\Standke\AppData\Local\Temp\tmp4C31.tmp --------- 0  
     30.10.2009 10:50     C:\Users\Standke\AppData\Local\Temp\tmp2B58.tmp --------- 0  
     29.10.2009 15:59     C:\Users\Standke\AppData\Local\Temp\{711B03BC-95FF-46DA-815B-9BA1191DAB85} --------- 0  
     29.10.2009 15:24     C:\Users\Standke\AppData\Local\Temp\tmp93B.tmp --------- 0  
     29.10.2009 15:24     C:\Users\Standke\AppData\Local\Temp\tmp93A.tmp --------- 0  
     29.10.2009 15:23     C:\Users\Standke\AppData\Local\Temp\tmpA1EE.tmp --------- 0  
     29.10.2009 11:39     C:\Users\Standke\AppData\Local\Temp\1256812765.csf --------- 88  
     29.10.2009 11:39     C:\Users\Standke\AppData\Local\Temp\SmXAd1256812765.wav --------- 60  
     29.10.2009 11:39     C:\Users\Standke\AppData\Local\Temp\SmXAd1256812765.DIR --------- 0  
     29.10.2009 11:39     C:\Users\Standke\AppData\Local\Temp\~$RGBE5E.DOC --------- 162  
     29.10.2009 11:32     C:\Users\Standke\AppData\Local\Temp\tmp7575.tmp --------- 0  
     29.10.2009 11:32     C:\Users\Standke\AppData\Local\Temp\tmp7574.tmp --------- 0  
     29.10.2009 11:32     C:\Users\Standke\AppData\Local\Temp\tmp4D79.tmp --------- 0  
     29.10.2009 11:16     C:\Users\Standke\AppData\Local\Temp\IaTemp_219B6BA27B514677ABD3762E366AFA45.DIR --------- 0  
     29.10.2009 11:16     C:\Users\Standke\AppData\Local\Temp\IaTemp_219B6BA27B514677ABD3762E366AFA45.wav --------- 170  
     28.10.2009 12:36     C:\Users\Standke\AppData\Local\Temp\tmpFF4E.tmp --------- 0  
     28.10.2009 12:36     C:\Users\Standke\AppData\Local\Temp\tmpFF3D.tmp --------- 0  
     28.10.2009 12:35     C:\Users\Standke\AppData\Local\Temp\tmp78DD.tmp --------- 0  
     27.10.2009 16:21     C:\Users\Standke\AppData\Local\Temp\MRG57D4.DOC --------- 424448  
     27.10.2009 16:18     C:\Users\Standke\AppData\Local\Temp\tmpCCE2.tmp --------- 0  
     27.10.2009 16:18     C:\Users\Standke\AppData\Local\Temp\tmpCCD1.tmp --------- 0  
     27.10.2009 16:18     C:\Users\Standke\AppData\Local\Temp\tmpAD10.tmp --------- 0  
     27.10.2009 14:58     C:\Users\Standke\AppData\Local\Temp\tmpE08B.tmp --------- 0  
     27.10.2009 14:58     C:\Users\Standke\AppData\Local\Temp\tmpE08A.tmp --------- 0  
     27.10.2009 14:57     C:\Users\Standke\AppData\Local\Temp\tmpC1D2.tmp --------- 0  
     27.10.2009 09:34     C:\Users\Standke\AppData\Local\Temp\tmpB039.tmp --------- 0  
     27.10.2009 09:34     C:\Users\Standke\AppData\Local\Temp\tmpB038.tmp --------- 0  
     27.10.2009 09:34     C:\Users\Standke\AppData\Local\Temp\tmp4DBC.tmp --------- 0  
     27.10.2009 08:42     C:\Users\Standke\AppData\Local\Temp\tmpC163.tmp --------- 0  
     27.10.2009 08:42     C:\Users\Standke\AppData\Local\Temp\tmpC162.tmp --------- 0  
     27.10.2009 08:42     C:\Users\Standke\AppData\Local\Temp\tmp9F03.tmp --------- 0  
     27.10.2009 08:14     C:\Users\Standke\AppData\Local\Temp\tmp74A8.tmp --------- 0  
     27.10.2009 08:14     C:\Users\Standke\AppData\Local\Temp\tmp74A7.tmp --------- 0  
     27.10.2009 08:14     C:\Users\Standke\AppData\Local\Temp\tmp51DA.tmp --------- 0  
     24.10.2009 11:47     C:\Users\Standke\AppData\Local\Temp\~cxd{79EB98A4-E2D9-43E9-BF4F-B8C7517B91D5}.tmp --------- 12369  
     24.10.2009 11:47     C:\Users\Standke\AppData\Local\Temp\~cxd{76288419-27F7-4F6A-97E1-98EAFFEAE18E}.tmp --------- 1326  
     24.10.2009 11:47     C:\Users\Standke\AppData\Local\Temp\~cxd{7D94E2FC-0AEB-4132-A471-947C70DAE64F}.tmp --------- 10434  
     24.10.2009 11:47     C:\Users\Standke\AppData\Local\Temp\~cxd{39B7F00C-E548-4C53-8266-EB16B5941FF5}.tmp --------- 12369  
     24.10.2009 11:47     C:\Users\Standke\AppData\Local\Temp\~cxd{E4493D31-F53D-404C-B75B-D1055893B2FD}.tmp --------- 1326  
     24.10.2009 11:47     C:\Users\Standke\AppData\Local\Temp\~cxd{F2EE3BC5-774F-44C5-A11D-9295C0E0710C}.tmp --------- 10434  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{7E2F05B8-23EA-4686-B25E-5975D8AFEAC3}.tmp --------- 53  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{78D25E42-821B-4A50-B795-7A26B73AAA06}.tmp --------- 111  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{7DE83D8C-476A-48E0-B95A-173340715C06}.tmp --------- 111  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{28FC3182-927B-4963-84B1-6F89FDC91B8C}.tmp --------- 53  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{5A00BEBA-63A6-4A41-8F16-1D818BF46BED}.tmp --------- 0  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{29BC909B-E911-41DF-8625-F36499364028}.tmp --------- 98  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{2DBDBC58-08D9-45E3-BBA3-25E8340D8CC0}.tmp --------- 0  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{F0C3D62F-9094-4A1C-83A1-A8D36BF63CA6}.tmp --------- 98  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{C2D1E8B8-1FDF-403F-BB42-D73A68EA8C36}.tmp --------- 0  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{156617D3-5EF4-41F7-8DAB-B71E1D6F2D29}.tmp --------- 98  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{895496F6-7817-47A7-BCB0-6F8001FBE4CE}.tmp --------- 0  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{590D5C4A-F998-4527-B567-3BD88BA8B417}.tmp --------- 318  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{AA48CBB7-F55C-4129-9454-2D5ED2B0AEA3}.tmp --------- 0  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{90EF33DE-54A6-4485-9E95-50BCDEDCDE40}.tmp --------- 98  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{AA6DA023-E32D-4165-8891-6E33A28EF395}.tmp --------- 0  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{63BC38ED-E44A-43BF-9D45-A2C6A48F4242}.tmp --------- 98  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{BAB8C6D9-E0C2-455B-BC3C-00A94A57DB3C}.tmp --------- 0  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{F5664F63-0CD1-44EB-A87D-545EBF6AAE69}.tmp --------- 98  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{9F67D0DA-978C-4B52-A8A9-D16CCF5ADC06}.tmp --------- 0  
     24.10.2009 11:46     C:\Users\Standke\AppData\Local\Temp\~cxd{A3834791-1DD9-48A1-9314-3357BB140BC1}.tmp --------- 318  
     24.10.2009 11:17     C:\Users\Standke\AppData\Local\Temp\~$RGFAD3.DOC --------- 162  
     23.10.2009 16:24     C:\Users\Standke\AppData\Local\Temp\tmp2DD8.tmp --------- 0  
     23.10.2009 16:24     C:\Users\Standke\AppData\Local\Temp\tmp2DD7.tmp --------- 0  
     23.10.2009 16:24     C:\Users\Standke\AppData\Local\Temp\tmp1556.tmp --------- 0  
     23.10.2009 14:15     C:\Users\Standke\AppData\Local\Temp\tmp5B06.tmp --------- 0  
     23.10.2009 14:15     C:\Users\Standke\AppData\Local\Temp\tmp5B05.tmp --------- 0  
     23.10.2009 14:15     C:\Users\Standke\AppData\Local\Temp\tmp3BC1.tmp --------- 0  
     23.10.2009 13:58     C:\Users\Standke\AppData\Local\Temp\Microsoft Office Basic Edition 2003_repair_log(0003).txt --------- 2415450  
     23.10.2009 13:16     C:\Users\Standke\AppData\Local\Temp\MRG4461.DOC --------- 425984  
     23.10.2009 11:37     C:\Users\Standke\AppData\Local\Temp\tmp72D3.tmp --------- 0  
     23.10.2009 11:37     C:\Users\Standke\AppData\Local\Temp\tmp72D2.tmp --------- 0  
     23.10.2009 11:37     C:\Users\Standke\AppData\Local\Temp\tmp54A7.tmp --------- 0  
     23.10.2009 10:43     C:\Users\Standke\AppData\Local\Temp\0284.PDF --------- 82853  
     23.10.2009 10:42     C:\Users\Standke\AppData\Local\Temp\16206-001.PDF --------- 53435  
     23.10.2009 10:41     C:\Users\Standke\AppData\Local\Temp\02D7.PDF --------- 89469  
     23.10.2009 10:19     C:\Users\Standke\AppData\Local\Temp\tmpFBBC.tmp --------- 0  
     23.10.2009 10:19     C:\Users\Standke\AppData\Local\Temp\tmpFBBB.tmp --------- 0  
     23.10.2009 10:19     C:\Users\Standke\AppData\Local\Temp\tmpDA65.tmp --------- 0  
     23.10.2009 09:50     C:\Users\Standke\AppData\Local\Temp\MRG8C42.DOC --------- 429568  
     23.10.2009 08:51     C:\Users\Standke\AppData\Local\Temp\tmpD91.tmp --------- 0  
     23.10.2009 08:51     C:\Users\Standke\AppData\Local\Temp\tmpD8F.tmp --------- 0  
     23.10.2009 08:51     C:\Users\Standke\AppData\Local\Temp\tmpEDBF.tmp --------- 0  
     23.10.2009 08:43     C:\Users\Standke\AppData\Local\Temp\tmp3191.tmp --------- 0  
     23.10.2009 08:43     C:\Users\Standke\AppData\Local\Temp\tmp3190.tmp --------- 0  
     23.10.2009 08:43     C:\Users\Standke\AppData\Local\Temp\tmp129A.tmp --------- 0  
     22.10.2009 15:58     C:\Users\Standke\AppData\Local\Temp\tmpA2E0.tmp --------- 0  
     22.10.2009 15:58     C:\Users\Standke\AppData\Local\Temp\tmpA2CF.tmp --------- 0  
     22.10.2009 15:58     C:\Users\Standke\AppData\Local\Temp\tmp8282.tmp --------- 0  
     21.10.2009 16:19     C:\Users\Standke\AppData\Local\Temp\tmp93BA.tmp --------- 0  
     21.10.2009 16:19     C:\Users\Standke\AppData\Local\Temp\tmp93B9.tmp --------- 0  
     21.10.2009 16:19     C:\Users\Standke\AppData\Local\Temp\tmp76C6.tmp --------- 0  
     21.10.2009 16:12     C:\Users\Standke\AppData\Local\Temp\tmpC5D.tmp --------- 0  
     21.10.2009 16:12     C:\Users\Standke\AppData\Local\Temp\tmpC5C.tmp --------- 0  
     21.10.2009 16:12     C:\Users\Standke\AppData\Local\Temp\tmpD8BE.tmp --------- 0  
     21.10.2009 14:08     C:\Users\Standke\AppData\Local\Temp\13606us9.tif --------- 66642  
     21.10.2009 13:57     C:\Users\Standke\AppData\Local\Temp\DOC080829-011.PDF --------- 141156  
     21.10.2009 10:37     C:\Users\Standke\AppData\Local\Temp\tmp24C6.tmp --------- 0  
     21.10.2009 10:37     C:\Users\Standke\AppData\Local\Temp\tmp24C5.tmp --------- 0  
     21.10.2009 10:37     C:\Users\Standke\AppData\Local\Temp\tmp228.tmp --------- 0  
     20.10.2009 14:33     C:\Users\Standke\AppData\Local\Temp\tmp8D45.tmp --------- 0  
     20.10.2009 14:33     C:\Users\Standke\AppData\Local\Temp\tmp8D44.tmp --------- 0  
     20.10.2009 14:33     C:\Users\Standke\AppData\Local\Temp\tmp6BCF.tmp --------- 0  
     20.10.2009 14:08     C:\Users\Standke\AppData\Local\Temp\tmp4731.tmp --------- 0  
     20.10.2009 14:08     C:\Users\Standke\AppData\Local\Temp\tmp4730.tmp --------- 0  
     20.10.2009 14:07     C:\Users\Standke\AppData\Local\Temp\tmp2953.tmp --------- 0  
     20.10.2009 13:10     C:\Users\Standke\AppData\Local\Temp\0012.PDF --------- 429012  
     20.10.2009 11:17     C:\Users\Standke\AppData\Local\Temp\tmpC3F9.tmp --------- 0  
     20.10.2009 11:17     C:\Users\Standke\AppData\Local\Temp\tmpC3F8.tmp --------- 0  
     20.10.2009 11:16     C:\Users\Standke\AppData\Local\Temp\tmp9FB5.tmp --------- 0  
     20.10.2009 11:04     C:\Users\Standke\AppData\Local\Temp\tmp31F4.tmp --------- 0  
     20.10.2009 11:04     C:\Users\Standke\AppData\Local\Temp\tmp31F3.tmp --------- 0  
     20.10.2009 11:04     C:\Users\Standke\AppData\Local\Temp\tmpA75.tmp --------- 0  
     20.10.2009 09:00     C:\Users\Standke\AppData\Local\Temp\tmp7084.tmp --------- 0  
     20.10.2009 09:00     C:\Users\Standke\AppData\Local\Temp\tmp7083.tmp --------- 0  
     20.10.2009 09:00     C:\Users\Standke\AppData\Local\Temp\tmp4FD8.tmp --------- 0  
     19.10.2009 10:51     C:\Users\Standke\AppData\Local\Temp\tmpFD7C.tmp --------- 0  
     19.10.2009 10:51     C:\Users\Standke\AppData\Local\Temp\tmpFD7B.tmp --------- 0  
     19.10.2009 10:51     C:\Users\Standke\AppData\Local\Temp\tmpDE76.tmp --------- 0  
     19.10.2009 10:12     C:\Users\Standke\AppData\Local\Temp\tmpFCAE.tmp --------- 0  
     19.10.2009 10:12     C:\Users\Standke\AppData\Local\Temp\tmpFCAD.tmp --------- 0  
     19.10.2009 10:12     C:\Users\Standke\AppData\Local\Temp\tmpCC39.tmp --------- 0  
     19.10.2009 07:57     C:\Users\Standke\AppData\Local\Temp\000B.PDF --------- 3479622  
     16.10.2009 13:45     C:\Users\Standke\AppData\Local\Temp\tmp5472.tmp --------- 0  
     16.10.2009 13:45     C:\Users\Standke\AppData\Local\Temp\tmp5471.tmp --------- 0  
     16.10.2009 13:45     C:\Users\Standke\AppData\Local\Temp\tmp1DA6.tmp --------- 0  
     16.10.2009 10:56     C:\Users\Standke\AppData\Local\Temp\tmp8807.tmp --------- 0  
     16.10.2009 10:56     C:\Users\Standke\AppData\Local\Temp\tmp8806.tmp --------- 0  
     16.10.2009 10:56     C:\Users\Standke\AppData\Local\Temp\tmp5929.tmp --------- 0  
     16.10.2009 09:58     C:\Users\Standke\AppData\Local\Temp\tmp9D57.tmp --------- 0  
     16.10.2009 09:58     C:\Users\Standke\AppData\Local\Temp\tmp9D47.tmp --------- 0  
     16.10.2009 09:58     C:\Users\Standke\AppData\Local\Temp\tmp90E7.tmp --------- 0  
     16.10.2009 09:52     C:\Users\Standke\AppData\Local\Temp\tmp8265.tmp --------- 0  
     16.10.2009 09:52     C:\Users\Standke\AppData\Local\Temp\tmp8254.tmp --------- 0  
     16.10.2009 09:51     C:\Users\Standke\AppData\Local\Temp\tmp63EB.tmp --------- 0  
     16.10.2009 09:45     C:\Users\Standke\AppData\Local\Temp\tmpD0C0.tmp --------- 0  
     16.10.2009 09:45     C:\Users\Standke\AppData\Local\Temp\tmpD0BF.tmp --------- 0  
     16.10.2009 09:45     C:\Users\Standke\AppData\Local\Temp\tmpAB82.tmp --------- 0  
     16.10.2009 09:24     C:\Users\Standke\AppData\Local\Temp\tmpB032.tmp --------- 0  
     16.10.2009 09:24     C:\Users\Standke\AppData\Local\Temp\tmpB031.tmp --------- 0  
     16.10.2009 09:24     C:\Users\Standke\AppData\Local\Temp\tmp8A0A.tmp --------- 0  
     16.10.2009 09:00     C:\Users\Standke\AppData\Local\Temp\IaTemp_53A96EE07D1749BA90F9253E67217EFD.DIR --------- 0  
     16.10.2009 09:00     C:\Users\Standke\AppData\Local\Temp\IaTemp_53A96EE07D1749BA90F9253E67217EFD.wav --------- 170  
     15.10.2009 15:38     C:\Users\Standke\AppData\Local\Temp\tmpEAB6.tmp --------- 0  
     15.10.2009 15:38     C:\Users\Standke\AppData\Local\Temp\tmpEAB5.tmp --------- 0  
     15.10.2009 15:38     C:\Users\Standke\AppData\Local\Temp\tmpCBBF.tmp --------- 0  
     15.10.2009 15:32     C:\Users\Standke\AppData\Local\Temp\tmp64C2.tmp --------- 0  
     15.10.2009 15:32     C:\Users\Standke\AppData\Local\Temp\tmp64C1.tmp --------- 0  
     15.10.2009 15:32     C:\Users\Standke\AppData\Local\Temp\tmp46C5.tmp --------- 0  
     15.10.2009 15:26     C:\Users\Standke\AppData\Local\Temp\tmp27BF.tmp --------- 0  
     15.10.2009 15:26     C:\Users\Standke\AppData\Local\Temp\tmp27BE.tmp --------- 0  
     15.10.2009 15:26     C:\Users\Standke\AppData\Local\Temp\tmp8D8.tmp --------- 0  
     15.10.2009 15:20     C:\Users\Standke\AppData\Local\Temp\tmpB8E4.tmp --------- 0  
     15.10.2009 15:20     C:\Users\Standke\AppData\Local\Temp\tmpB8E3.tmp --------- 0  
     15.10.2009 15:20     C:\Users\Standke\AppData\Local\Temp\tmp9970.tmp --------- 0  
     15.10.2009 14:27     C:\Users\Standke\AppData\Local\Temp\tmp624.tmp --------- 0  
     15.10.2009 14:27     C:\Users\Standke\AppData\Local\Temp\tmp623.tmp --------- 0  
     15.10.2009 14:27     C:\Users\Standke\AppData\Local\Temp\tmpE03A.tmp --------- 0  
     15.10.2009 13:07     C:\Users\Standke\AppData\Local\Temp\image.PDF --------- 5557283  
     13.10.2009 15:45     C:\Users\Standke\AppData\Local\Temp\tmp497B.tmp --------- 0  
     13.10.2009 15:45     C:\Users\Standke\AppData\Local\Temp\tmp497A.tmp --------- 0  
     13.10.2009 15:45     C:\Users\Standke\AppData\Local\Temp\tmp39C0.tmp --------- 0  
     13.10.2009 13:13     C:\Users\Standke\AppData\Local\Temp\tmp4206.tmp --------- 0  
     13.10.2009 13:13     C:\Users\Standke\AppData\Local\Temp\tmp4205.tmp --------- 0  
     13.10.2009 13:13     C:\Users\Standke\AppData\Local\Temp\tmp20FD.tmp --------- 0  
     12.10.2009 16:07     C:\Users\Standke\AppData\Local\Temp\tmpD4C0.tmp --------- 0  
     12.10.2009 16:07     C:\Users\Standke\AppData\Local\Temp\tmpD4BF.tmp --------- 0  
     12.10.2009 16:07     C:\Users\Standke\AppData\Local\Temp\tmpB185.tmp --------- 0  
     12.10.2009 15:45     C:\Users\Standke\AppData\Local\Temp\tmpDC99.tmp --------- 0  
     12.10.2009 15:45     C:\Users\Standke\AppData\Local\Temp\tmpDC98.tmp --------- 0  
     12.10.2009 15:45     C:\Users\Standke\AppData\Local\Temp\tmpB623.tmp --------- 0  
     12.10.2009 14:11     C:\Users\Standke\AppData\Local\Temp\tmp7BEE.tmp --------- 0  
     12.10.2009 14:11     C:\Users\Standke\AppData\Local\Temp\tmp7BDE.tmp --------- 0  
     12.10.2009 14:11     C:\Users\Standke\AppData\Local\Temp\tmp599E.tmp --------- 0  
     12.10.2009 13:43     C:\Users\Standke\AppData\Local\Temp\tmpB987.tmp --------- 0  
     12.10.2009 13:43     C:\Users\Standke\AppData\Local\Temp\tmpB976.tmp --------- 0  
     12.10.2009 13:43     C:\Users\Standke\AppData\Local\Temp\tmp9A51.tmp --------- 0  
     12.10.2009 11:09     C:\Users\Standke\AppData\Local\Temp\MRG526A.DOC --------- 55808  
     12.10.2009 10:36     C:\Users\Standke\AppData\Local\Temp\tmpA4DC.tmp --------- 0  
     12.10.2009 10:36     C:\Users\Standke\AppData\Local\Temp\tmpA4DB.tmp --------- 0  
     12.10.2009 10:36     C:\Users\Standke\AppData\Local\Temp\tmp8401.tmp --------- 0  
     12.10.2009 10:13     C:\Users\Standke\AppData\Local\Temp\IaTemp_CE09E8782AA242749AE0883D2AE1BE7E.DIR --------- 0  
     12.10.2009 10:13     C:\Users\Standke\AppData\Local\Temp\IaTemp_CE09E8782AA242749AE0883D2AE1BE7E.wav --------- 170  
     12.10.2009 10:13     C:\Users\Standke\AppData\Local\Temp\~$RGA46A.DOC --------- 162  
     12.10.2009 10:07     C:\Users\Standke\AppData\Local\Temp\000E.PDF --------- 431873  
     11.10.2009 12:53     C:\Users\Standke\AppData\Local\Temp\tmpDC51.tmp --------- 0  
     11.10.2009 12:53     C:\Users\Standke\AppData\Local\Temp\tmpDC50.tmp --------- 0  
     11.10.2009 12:53     C:\Users\Standke\AppData\Local\Temp\tmpB86A.tmp --------- 0  
     09.10.2009 15:19     C:\Users\Standke\AppData\Local\Temp\tmp3F1F.tmp --------- 0  
     09.10.2009 15:19     C:\Users\Standke\AppData\Local\Temp\tmp3F1E.tmp --------- 0  
     09.10.2009 15:19     C:\Users\Standke\AppData\Local\Temp\tmp1C03.tmp --------- 0  
     09.10.2009 13:45     C:\Users\Standke\AppData\Local\Temp\tmp8BD8.tmp --------- 0  
     09.10.2009 13:45     C:\Users\Standke\AppData\Local\Temp\tmp8BD7.tmp --------- 0  
     09.10.2009 13:45     C:\Users\Standke\AppData\Local\Temp\tmp6DFA.tmp --------- 0  
     09.10.2009 13:38     C:\Users\Standke\AppData\Local\Temp\tmpE328.tmp --------- 0  
     09.10.2009 13:38     C:\Users\Standke\AppData\Local\Temp\tmpE327.tmp --------- 0  
     09.10.2009 13:38     C:\Users\Standke\AppData\Local\Temp\tmpC05B.tmp --------- 0  
     09.10.2009 10:45     C:\Users\Standke\AppData\Local\Temp\tmpD341.tmp --------- 0  
     09.10.2009 10:45     C:\Users\Standke\AppData\Local\Temp\tmpD340.tmp --------- 0  
     09.10.2009 10:45     C:\Users\Standke\AppData\Local\Temp\tmpC79C.tmp --------- 0  
     09.10.2009 10:26     C:\Users\Standke\AppData\Local\Temp\tmp285F.tmp --------- 0  
     09.10.2009 10:26     C:\Users\Standke\AppData\Local\Temp\tmp285E.tmp --------- 0  
     09.10.2009 10:26     C:\Users\Standke\AppData\Local\Temp\tmpE5E1.tmp --------- 0  
     08.10.2009 15:18     C:\Users\Standke\AppData\Local\Temp\tmp6E2E.tmp --------- 0  
     08.10.2009 15:18     C:\Users\Standke\AppData\Local\Temp\tmp6E1E.tmp --------- 0  
     08.10.2009 15:17     C:\Users\Standke\AppData\Local\Temp\tmp3E37.tmp --------- 0  
     08.10.2009 11:43     C:\Users\Standke\AppData\Local\Temp\MRGA8F8.DOC --------- 428032  
     08.10.2009 10:59     C:\Users\Standke\AppData\Local\Temp\tmp43DC.tmp --------- 0  
     08.10.2009 10:59     C:\Users\Standke\AppData\Local\Temp\tmp43DB.tmp --------- 0  
     08.10.2009 10:58     C:\Users\Standke\AppData\Local\Temp\tmp1E50.tmp --------- 0  
     07.10.2009 16:08     C:\Users\Standke\AppData\Local\Temp\tmp55E5.tmp --------- 0  
     07.10.2009 16:08     C:\Users\Standke\AppData\Local\Temp\tmp55E4.tmp --------- 0  
     07.10.2009 16:08     C:\Users\Standke\AppData\Local\Temp\tmp323C.tmp --------- 0  
     07.10.2009 07:39     C:\Users\Standke\AppData\Local\Temp\MRGDAAE.DOC --------- 424448  
     06.10.2009 10:31     C:\Users\Standke\AppData\Local\Temp\tmp9798.tmp --------- 0  
     06.10.2009 10:31     C:\Users\Standke\AppData\Local\Temp\tmp9797.tmp --------- 0  
     06.10.2009 10:31     C:\Users\Standke\AppData\Local\Temp\tmp7A17.tmp --------- 0  
     06.10.2009 10:19     C:\Users\Standke\AppData\Local\Temp\tmp1BB3.tmp --------- 0  
     06.10.2009 10:19     C:\Users\Standke\AppData\Local\Temp\tmp1BB2.tmp --------- 0  
     06.10.2009 10:19     C:\Users\Standke\AppData\Local\Temp\tmpF922.tmp --------- 0  
     05.10.2009 16:07     C:\Users\Standke\AppData\Local\Temp\tmp3D45.tmp --------- 0  
     05.10.2009 16:07     C:\Users\Standke\AppData\Local\Temp\tmp3D44.tmp --------- 0  
     05.10.2009 16:07     C:\Users\Standke\AppData\Local\Temp\tmp19FB.tmp --------- 0  
     05.10.2009 15:14     C:\Users\Standke\AppData\Local\Temp\tmpB756.tmp --------- 0  
     05.10.2009 15:14     C:\Users\Standke\AppData\Local\Temp\tmpB755.tmp --------- 0  
     05.10.2009 15:14     C:\Users\Standke\AppData\Local\Temp\tmp9B1D.tmp --------- 0  
     05.10.2009 11:00     C:\Users\Standke\AppData\Local\Temp\RECHNUNG 40 UND 32.PDF --------- 1882673  
     05.10.2009 09:39     C:\Users\Standke\AppData\Local\Temp\tmp3284.tmp --------- 0  
     05.10.2009 09:39     C:\Users\Standke\AppData\Local\Temp\tmp3283.tmp --------- 0  
     05.10.2009 09:39     C:\Users\Standke\AppData\Local\Temp\tmp1248.tmp --------- 0  
     01.10.2009 15:07     C:\Users\Standke\AppData\Local\Temp\tmpD324.tmp --------- 0  
     01.10.2009 15:07     C:\Users\Standke\AppData\Local\Temp\tmpD323.tmp --------- 0  
     01.10.2009 15:07     C:\Users\Standke\AppData\Local\Temp\tmpA223.tmp --------- 0  
     01.10.2009 13:56     C:\Users\Standke\AppData\Local\Temp\0023.PDF --------- 690793  
     01.10.2009 13:42     C:\Users\Standke\AppData\Local\Temp\0029.PDF --------- 664807  
     01.10.2009 13:36     C:\Users\Standke\AppData\Local\Temp\7606.PDF --------- 252381  
     01.10.2009 13:09     C:\Users\Standke\AppData\Local\Temp\002B.PDF --------- 787216  
     01.10.2009 12:59     C:\Users\Standke\AppData\Local\Temp\0018.PDF --------- 6259841  
     01.10.2009 10:26     C:\Users\Standke\AppData\Local\Temp\tmp599B.tmp --------- 0  
     01.10.2009 10:26     C:\Users\Standke\AppData\Local\Temp\tmp599A.tmp --------- 0  
     01.10.2009 10:26     C:\Users\Standke\AppData\Local\Temp\tmp33A2.tmp --------- 0  
     30.09.2009 10:30     C:\Users\Standke\AppData\Local\Temp\tmp283F.tmp --------- 0  
     30.09.2009 10:30     C:\Users\Standke\AppData\Local\Temp\tmp283E.tmp --------- 0  
     30.09.2009 10:30     C:\Users\Standke\AppData\Local\Temp\tmp717.tmp --------- 0  
     29.09.2009 11:33     C:\Users\Standke\AppData\Local\Temp\tmpD374.tmp --------- 0  
     29.09.2009 11:33     C:\Users\Standke\AppData\Local\Temp\tmpD373.tmp --------- 0  
     29.09.2009 11:33     C:\Users\Standke\AppData\Local\Temp\tmpB410.tmp --------- 0  
     29.09.2009 10:23     C:\Users\Standke\AppData\Local\Temp\tmpA668.tmp --------- 0  
     29.09.2009 10:23     C:\Users\Standke\AppData\Local\Temp\tmpA667.tmp --------- 0  
     29.09.2009 10:22     C:\Users\Standke\AppData\Local\Temp\tmp858D.tmp --------- 0  
    ----------------------------------------
    
     
    C:\Program Files
    
     13.01.2010 18:08     C:\Program Files\Windows Mail --------- 4096  
     13.01.2010 09:52     C:\Program Files\SPAMfighter --------- 4096  
     13.01.2010 09:52     C:\Program Files\LogMeIn --------- 40960  
     11.01.2010 11:52     C:\Program Files\Common Files --------- 4096  
     11.01.2010 11:49     C:\Program Files\Comodo --------- 0  
     11.01.2010 11:48     C:\Program Files\a-squared Anti-Malware --------- 8192  
     05.01.2010 00:34     C:\Program Files\Windows Calendar --------- 0  
     05.01.2010 00:34     C:\Program Files\Movie Maker --------- 4096  
     05.01.2010 00:34     C:\Program Files\Windows Sidebar --------- 4096  
     05.01.2010 00:34     C:\Program Files\Internet Explorer --------- 4096  
     05.01.2010 00:34     C:\Program Files\Windows Media Player --------- 4096  
     05.01.2010 00:34     C:\Program Files\Windows Collaboration --------- 4096  
     05.01.2010 00:34     C:\Program Files\Windows Journal --------- 4096  
     05.01.2010 00:34     C:\Program Files\Windows Photo Gallery --------- 4096  
     05.01.2010 00:34     C:\Program Files\Windows Defender --------- 4096  
     04.01.2010 19:39     C:\Program Files\QS --------- 0  
     29.12.2009 16:41     C:\Program Files\VR-NetWorld --------- 24576  
     23.12.2009 08:41     C:\Program Files\Google --------- 4096  
     15.10.2009 18:41     C:\Program Files\Microsoft SQL Server --------- 0  
     29.09.2009 20:18     C:\Program Files\XnView --------- 4096  
     29.09.2009 20:08     C:\Program Files\IrfanView --------- 4096  
     06.08.2009 09:01     C:\Program Files\Microsoft Office --------- 4096  
     05.08.2009 17:14     C:\Program Files\MSECache --------- 0  
     15.06.2009 14:17     C:\Program Files\iTunes --------- 4096  
     12.04.2009 20:30     C:\Program Files\VideoLAN --------- 0  
     01.02.2009 12:06     C:\Program Files\Skype --------- 0  
     01.01.2009 16:04     C:\Program Files\Canon --------- 4096  
     01.01.2009 16:04     C:\Program Files\InstallShield Installation Information --------- 12288  
     23.12.2008 06:08     C:\Program Files\Microsoft IntelliPoint --------- 8192  
     13.12.2008 18:32     C:\Program Files\MSXML 4.0 --------- 0  
     13.12.2008 16:10     C:\Program Files\iPod --------- 0  
     13.12.2008 16:10     C:\Program Files\Bonjour --------- 0  
     13.12.2008 16:10     C:\Program Files\QuickTime --------- 4096  
     13.12.2008 16:09     C:\Program Files\Apple Software Update --------- 4096  
     13.12.2008 15:09     C:\Program Files\Nero --------- 0  
     13.12.2008 14:08     C:\Program Files\DIFX --------- 0  
     13.12.2008 13:59     C:\Program Files\AnNoText GmbH --------- 0  
     13.12.2008 13:51     C:\Program Files\Microsoft.NET --------- 0  
     13.12.2008 13:25     C:\Program Files\Microsoft Works --------- 0  
     13.12.2008 13:11     C:\Program Files\Microsoft Visual Studio --------- 0  
     13.12.2008 13:00     C:\Program Files\Business Objects --------- 0  
     13.12.2008 12:54     C:\Program Files\Java --------- 0  
     13.12.2008 10:46     C:\Program Files\Adobe --------- 0  
     13.12.2008 10:46     C:\Program Files\ASUS --------- 4096  
     13.12.2008 10:45     C:\Program Files\ATKGFNEX --------- 4096  
     13.12.2008 10:44     C:\Program Files\PowerForPhone --------- 0  
     13.12.2008 10:43     C:\Program Files\P4G --------- 4096  
     13.12.2008 10:43     C:\Program Files\Power4Gear eXtreme --------- 0  
     13.12.2008 10:40     C:\Program Files\Atheros --------- 0  
     13.12.2008 10:39     C:\Program Files\Wireless Console 2 --------- 0  
     13.12.2008 10:35     C:\Program Files\Synaptics --------- 0  
     13.12.2008 10:34     C:\Program Files\Motorola --------- 0  
     13.12.2008 10:33     C:\Program Files\Realtek --------- 0  
     13.12.2008 10:30     C:\Program Files\ATKOSD2 --------- 0  
     13.12.2008 10:30     C:\Program Files\ATK Hotkey --------- 4096  
     13.12.2008 10:12     C:\Program Files\Windows NT --------- 4096  
     13.12.2008 10:12     C:\Program Files\Gemeinsame Dateien --------- 0  
     21.01.2008 03:43     C:\Program Files\desktop.ini --------- 174  
     02.11.2006 14:01     C:\Program Files\Uninstall Information --------- 0  
     02.11.2006 13:37     C:\Program Files\MSBuild --------- 0  
     02.11.2006 13:37     C:\Program Files\Reference Assemblies --------- 0  
    ----------------------------------------
    
     
    C:\ProgramData\.. 
    
    Standke    
    WKSMService    
    Public    
    Default    
    desktop.ini    
    Default User    
    All Users    
    ----------------------------------------
    
     
    C:\Windows\system32\drivers\etc\hosts
    
    127.0.0.1       localhost
    ::1             localhost
    192.168.0.1	server-rae.rae.local	
    server-rae.rae.local	192.168.0.1
    
    ----------------------------------------
    
     
    
    Abbildname                     PID Sitzungsname       Sitz.-Nr. Speichernutzung
    ========================= ======== ================ =========== ===============
    System Idle Process              0 Services                   0            24 K
    System                           4 Services                   0        14.852 K
    smss.exe                       492 Services                   0           736 K
    csrss.exe                      568 Services                   0         6.116 K
    wininit.exe                    620 Services                   0         5.012 K
    csrss.exe                      628 Console                    1         9.080 K
    services.exe                   664 Services                   0         7.612 K
    winlogon.exe                   720 Console                    1         6.336 K
    lsass.exe                      748 Services                   0         9.944 K
    lsm.exe                        756 Services                   0         5.000 K
    svchost.exe                    892 Services                   0         9.928 K
    svchost.exe                    976 Services                   0         8.324 K
    svchost.exe                   1068 Services                   0        13.492 K
    svchost.exe                   1112 Services                   0        16.048 K
    svchost.exe                   1160 Services                   0        11.352 K
    svchost.exe                   1188 Services                   0        44.844 K
    svchost.exe                   1208 Services                   0        31.580 K
    audiodg.exe                   1300 Services                   0        17.540 K
    svchost.exe                   1356 Services                   0         5.832 K
    SLsvc.exe                     1408 Services                   0        10.764 K
    ADSMSrv.exe                   1728 Services                   0         3.388 K
    ASLDRSrv.exe                  1748 Services                   0         4.220 K
    GFNEXSrv.exe                  1760 Services                   0         3.412 K
    spoolsv.exe                   1844 Services                   0        16.596 K
    svchost.exe                   1868 Services                   0        16.764 K
    AppleMobileDeviceService.      500 Services                   0         4.436 K
    anoldrsv.exe                   560 Services                   0         4.720 K
    mDNSResponder.exe              744 Services                   0         4.576 K
    WK.OutboxService.exe           688 Services                   0        25.220 K
    WK.ThirdPartyCommunicatio     1292 Services                   0        16.264 K
    WK.WorkflowServer.exe         1568 Services                   0        26.568 K
    LSSrvc.exe                    2272 Services                   0         4.304 K
    dwm.exe                       2300 Console                    1        55.388 K
    ramaint.exe                   2312 Services                   0         4.980 K
    LogMeIn.exe                   2340 Services                   0        15.568 K
    LMIGuardian.exe               2364 Services                   0         3.492 K
    explorer.exe                  2376 Console                    1        54.032 K
    MDM.EXE                       2392 Services                   0         4.732 K
    sqlservr.exe                  2408 Services                   0        54.500 K
    svchost.exe                   2472 Services                   0         6.044 K
    sfus.exe                      2488 Services                   0         8.256 K
    SmNTService.exe               2516 Services                   0        22.056 K
    sqlbrowser.exe                2588 Services                   0         4.316 K
    HControl.exe                  2688 Console                    1         7.564 K
    ATKOSD2.exe                   2696 Console                    1         4.880 K
    wcourier.exe                  2704 Console                    1         6.528 K
    BatteryLife.exe               2712 Console                    1         4.812 K
    ACMON.exe                     2724 Console                    1         7.120 K
    LogMeInSystray.exe            2868 Console                    1        10.188 K
    sqlwriter.exe                 2876 Services                   0         8.124 K
    svchost.exe                   2892 Services                   0         7.364 K
    svchost.exe                   2924 Services                   0         4.752 K
    ACEngSvr.exe                  2944 Console                    1         8.888 K
    taskeng.exe                   3060 Console                    1        11.644 K
    ATKOSD.exe                    3096 Console                    1         5.860 K
    WUDFHost.exe                  3104 Services                   0         6.060 K
    LMIGuardian.exe               3148 Console                    1         3.536 K
    rundll32.exe                  3392 Console                    1         5.848 K
    KBFiltr.exe                   3484 Console                    1         4.044 K
    RtHDVCpl.exe                  3508 Console                    1         7.964 K
    sm56hlpr.exe                  3524 Console                    1         5.488 K
    SynTPEnh.exe                  3532 Console                    1         7.496 K
    DMedia.exe                    3540 Console                    1         4.248 K
    ASUSTPE.exe                   3548 Console                    1         4.712 K
    PowerForPhone.exe             3556 Console                    1         7.416 K
    WK.MobileDevices.exe          3580 Console                    1        24.440 K
    ipoint.exe                    3588 Console                    1        13.884 K
    w3dbsmgr.exe                  3604 Console                    1        15.832 K
    taskeng.exe                   3744 Services                   0         5.944 K
    ALU.exe                       3892 Console                    1         7.588 K
    GoogleToolbarNotifier.exe     3136 Console                    1         2.352 K
    MultiFrame.exe                3444 Console                    1        10.916 K
    WmiPrvSE.exe                  3932 Services                   0        11.012 K
    SearchIndexer.exe              940 Services                   0        43.788 K
    SmCtxSysTask.ngn              2228 Services                   0        22.320 K
    SmPurgeSysTask.ngn            1636 Services                   0        21.540 K
    SmRcgSysTask.ngn              3472 Services                   0        21.624 K
    rundll32.exe                  2820 Console                    1         6.996 K
    SmIPCSrv.exe                  3828 Services                   0        10.916 K
    iexplore.exe                  4236 Console                    1       102.648 K
    mobsync.exe                   5908 Console                    1         7.640 K
    wmpnscfg.exe                  4600 Console                    1         5.844 K
    wmpnetwk.exe                  2932 Services                   0        10.840 K
    conime.exe                    7860 Console                    1         4.216 K
    SearchFilterHost.exe          6232 Services                   0         6.636 K
    taskeng.exe                   3732 Services                   0         4.472 K
    SearchProtocolHost.exe        5312 Services                   0         8.948 K
    iexplore.exe                  8472 Console                    1        45.944 K
    SearchProtocolHost.exe        8828 Console                    1         7.100 K
    cmd.exe                       9192 Console                    1         4.440 K
    tasklist.exe                  9520 Console                    1         5.408 K
    
     
    ***** Ende des Scans 13.01.2010 um 21:48:27,40 ***

  5. #5
    Einsteiger
    Registriert seit
    13.01.2010
    Beiträge
    15

    AW: Internet Explorer öffnet sich selbst

    Hier ist noch die Textdatei - Cleaner:

    Code:
    Adobe Flash Player 10 ActiveX	Adobe Systems Incorporated	01.01.2010		10.0.42.34
    Adobe Reader 8	Adobe Systems Incorporated	12.12.2008	77,1MB	8.0.0
    AnNoText AnwVS Client	AnNoText	12.12.2008	81,4MB	2.01.0000
    AnNoText Arbeitsplatz	AnNoText	12.12.2008	460,9MB	4.8.0.100
    AnNoText Elster Schnittstelle	AnNoText GmbH	01.01.2010	86,6MB	5.2.0
    AnNoText Mobileakte	AnNoText	12.12.2008	0,13MB	4.7.8.100
    AnNoText Pdf Druckertreiber	AnNoText	12.12.2008	12,7MB	10.24.0000
    AnNoText Tiff Druckertreiber 	AnNoText	12.12.2008	5,03MB	10.24.0000
    Apple Mobile Device Support	Apple Inc.	12.12.2008	42,1MB	2.0.1.5
    Apple Software Update	Apple Inc.	12.12.2008	2,14MB	2.1.0.110
    ASUS Data Security Manager	ASUS	12.12.2008	4,95MB	1.00.0006
    ASUS InstantFun	ASUS	12.12.2008	14,6MB	1.0.0014
    ASUS Live Update	ASUS	12.12.2008	0,45MB	2.5.3
    ASUS MultiFrame		12.12.2008	1,12MB	1.0.0014
    ASUS Splendid Video Enhancement Technology	ASUSTeK	12.12.2008	16,3MB	1.02.18
    ASUS Touch Pad Extra		12.12.2008	0,78MB	
    ASUS Virtual Camera	asus	12.12.2008	1,64MB	1.1.11
    Asus_Camera_ScreenSaver	ASUS	12.12.2008		2.0.0006
    Atheros Driver Installation Program	Atheros	12.12.2008	4,00KB	7.1
    ATK Generic Function Service	ATK	12.12.2008	0,45MB	1.00.0008
    ATK Hotkey	ATK	12.12.2008	5,05MB	1.00.0012
    ATK Media		12.12.2008	0,63MB	
    ATKOSD2	ATK	12.12.2008	7,35MB	6.64.1.4
    Bonjour	Apple Inc.	12.12.2008	0,47MB	1.0.104
    Canon Camera TWAIN Driver 6.0	Ihr Firmenname	31.12.2008		6.0
    Canon G.726 WMP-Decoder	Canon Inc.	31.12.2008	0,23MB	1.1.0.4
    CANON iMAGE GATEWAY Task for ZoomBrowser EX	Canon Inc.	31.12.2008	53,1MB	1.5.0.3
    Canon Internet Library for ZoomBrowser EX	Canon Inc.	31.12.2008	53,1MB	1.6.1.6
    Canon MovieEdit Task for ZoomBrowser EX	Canon Inc.	31.12.2008	53,1MB	2.6.0.4
    Canon PhotoRecord		31.12.2008	36,8MB	
    Canon PowerShot G3 TWAIN-Treiber	Canon	31.12.2008	5,05MB	5.0
    Canon RAW Codec		31.12.2008	69,3MB	1.4.0.43
    Canon RAW Image Task for ZoomBrowser EX	Canon Inc.	31.12.2008	19,1MB	3.3.0.5
    Canon Utilities CameraWindow	Canon Inc.	31.12.2008	2,27MB	7.1.0.2
    Canon Utilities CameraWindow DC	Canon Inc.	31.12.2008	5,63MB	7.1.0.7
    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX	Canon Inc.	31.12.2008	18,4MB	6.4.2.16
    Canon Utilities File Viewer Utility 1.2	Canon	31.12.2008		1.2.2
    Canon Utilities MyCamera	Canon Inc.	31.12.2008	15,5MB	6.4.0.5
    Canon Utilities MyCamera DC	Canon Inc.	31.12.2008	15,4MB	7.0.1.8
    Canon Utilities PhotoStitch 3.1	Canon	31.12.2008		3.1.10
    Canon Utilities RemoteCapture 2.7	Canon	31.12.2008		2.7.2
    Canon Utilities RemoteCapture DC	Canon Inc.	31.12.2008	16,2MB	3.0.1.8
    Canon Utilities RemoteCapture Task for ZoomBrowser EX	Canon Inc.	31.12.2008	16,3MB	1.7.1.9
    Canon Utilities ZoomBrowser EX	Canon Inc.	31.12.2008	53,1MB	6.1.1.21
    Canon ZoomBrowser EX Memory Card Utility	Canon Inc.	31.12.2008	19,7MB	1.1.0.8
    CCleaner	Piriform	12.01.2010	2,88MB	2.27
    DictaPlus	AnNoText GmbH	12.12.2008	434,4MB	6.10.0100
    DictaPlus PDF	AnNoText GmbH	12.12.2008	1,14MB	10.00.0000
    Google Chrome	Google Inc.	10.02.2009	52,6MB	3.0.195.38
    Google Earth	Google	22.12.2009	69,6MB	5.1.7894.7252
    Google Toolbar for Internet Explorer	Google Inc.	27.11.2009	7,80MB	
    Google Updater	Google Inc.	23.03.2009	3,43MB	2.4.1536.6592
    HijackThis 2.0.2	TrendMicro	12.01.2010		2.0.2
    iTunes	Apple Inc.	14.06.2009	83,2MB	7.7.1.11
    J2SE Runtime Environment 5.0	Sun Microsystems, Inc.	12.12.2008	98,0MB	1.5.0
    LifeFrame2	ASUS	12.12.2008	9,87MB	2.0.15
    LogMeIn	LogMeIn, Inc.	12.12.2008	23,7MB	4.0.784
    Microsoft .NET Framework 3.5 Language Pack SP1 - DEU	Microsoft Corporation	17.08.2009	37,1MB	
    Microsoft .NET Framework 3.5 SP1	Microsoft Corporation	16.08.2009	37,1MB	
    Microsoft IntelliPoint 6.3	Microsoft	22.12.2008	19,9MB	6.30.191.0
    Microsoft Office Basic Edition 2003	Microsoft Corporation	12.01.2010		11.0.8173.0
    Microsoft Office XP Professional	Microsoft Corporation	09.12.2009		10.0.6626.0
    Microsoft SQL Server 2005	Microsoft Corporation	12.12.2008	232,9MB	
    Microsoft SQL Server Native Client	Microsoft Corporation	22.03.2009	2,61MB	9.00.4035.00
    Microsoft SQL Server Setup Support Files (English)	Microsoft Corporation	22.03.2009	20,2MB	9.00.4035.00
    Microsoft SQL Server VSS Writer	Microsoft Corporation	22.03.2009	0,66MB	9.00.4035.00
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148	Microsoft Corporation	10.01.2010	0,19MB	9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17	Microsoft Corporation	03.01.2010	0,58MB	9.0.30729
    Motorola SM56 Speakerphone Modem		12.12.2008	1,91MB	
    MSXML 4.0 SP2 (KB954430)	Microsoft Corporation	12.12.2008	1,28MB	4.20.9870.0
    MSXML 4.0 SP2 (KB973688)	Microsoft Corporation	24.11.2009	1,34MB	4.20.9876.0
    Nero 7 Essentials	Nero AG	12.12.2008	714,0MB	7.03.0188
    NVIDIA Drivers		04.01.2010		
    Pervasive System Analyzer		12.12.2008		
    Pervasive.SQL 9 SP2 Workgroup for Windows (9.5)	Pervasive Software Inc. 	12.12.2008	125,1MB	9.50.077.002
    Philips Device Driver	Philips Speech Recognition Systems	17.02.2009	3,67MB	13.543.2.2
    Power4Gear eXtreme	ATK	12.12.2008		1.00.0014
    PowerForPhone	PowerForPhone	12.12.2008	0,75MB	1.0.0.14
    QuickTime	Apple Inc.	12.12.2008	77,9MB	7.50.61.0
    Realtek High Definition Audio Driver	Realtek Semiconductor Corp.	12.12.2008	15,3MB	6.0.1.5449
    Realtek USB 2.0 Card Reader	Realtek	12.12.2008	1,80MB	
    Shared Add-in Extensibility Update for Microsoft .NET Framework 2.0 (KB908002)	Microsoft	12.12.2008	0,29MB	1.0.0
    Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002)	Microsoft	12.12.2008	56,00KB	1.0.0
    Skype™ 3.8	Skype Technologies S.A.	31.01.2009	30,1MB	3.8.188
    SPAMfighter	SPAMfighter ApS	12.05.2009	12,7MB	6.6.25
    SpeechMagic InitialTraining	Philips Speech Recognition Systems	17.02.2009	21,5MB	13.543.2.2
    SpeechMagic InterActive	Philips Speech Recognition Systems	17.02.2009	78,8MB	4.7.65.0
    SpeechMagic Workstation 6.1		12.12.2008	572,5MB	
    SpeechMagic-Datenserver 6.1		12.12.2008	572,5MB	
    Synaptics Pointing Device Driver	Synaptics	12.12.2008	13,0MB	9.1.19.0
    Total Commander (Remove or Repair)		12.12.2008	4,45MB	
    USB2.0 UVC 1.3M WebCam		12.12.2008		
    Visual C++ 9.0 WinSXS CRT	Microsoft	12.12.2008	3,15MB	9.00.0000
    Visual Studio 2005 Tools for Office Second Edition Runtime	Microsoft Corporation	12.12.2008	6,48MB	
    Visual Studio Tools for the Office system 3.0 Runtime	Microsoft Corporation	12.12.2008	4,89MB	
    VLC media player 0.9.8a	VideoLAN Team	11.04.2009	60,4MB	0.9.8a
    VR-NetWorld		12.12.2008	2,10MB	
    Windows-Treiberpaket - Grundig Business Systems GmbH (UacCtl2) USB  (12/19/2006 2.0.3.3)	Grundig Business Systems GmbH	12.12.2008		12/19/2006 2.0.3.3
    WinFlash		12.12.2008	1,36MB	
    Wireless Console 2	ATK	12.12.2008	1,59MB	2.0.8
    XnView 1.96.5	Gougelet Pierre-e	28.09.2009	8,91MB	1.96.5
    Yahoo! Toolbar		12.01.2010	3,33MB
    Geändert von kira (13.01.2010 um 23:07 Uhr)

  6. #6
    Moderator Team-Mitglied Benutzerbild von kira
    Registriert seit
    28.03.2006
    Ort
    Wien/Sprachen: Deutsch-Ungarisch
    Beiträge
    25.767

    AW: Internet Explorer öffnet sich selbst

    hi


    vermutlich hat sich ein Rootkit auf Deinem Rechner eingenistet

    Lade und installiere das Tool RootRepeal herunter

    - setze einen Hacken bei: "Drivers", "Stealth Objects" und "Hidden Services" dann klick auf "OK"
    - nach der Scan, klick auf "Save Report"
    - speichere das Logfile als RootRepeal.txt auf dem Desktop und Kopiere den Inhalt hier in den Thread
    Neuaufsetzen (Windows XP, Vista und Windows 7) - Anleitungen
    Virenscanner
    Wie man seinen Rechner von Viren befreit

    *Der beste Schutz ist immer noch der verantwortungsvolle Umgang mit dem Internet!*

  7. #7
    Einsteiger
    Registriert seit
    13.01.2010
    Beiträge
    15

    AW: Internet Explorer öffnet sich selbst

    Code:
    ROOTREPEAL (c) AD, 2007-2009
    ==================================================
    Scan Start Time:		2010/01/13 23:16
    Program Version:		Version 1.3.5.0
    Windows Version:		Windows Vista SP1
    ==================================================
    
    Drivers
    -------------------
    Name: acpi.sys
    Image Path: C:\Windows\system32\drivers\acpi.sys
    Address: 0x80604000	Size: 286720	File Visible: -	Signed: -
    Status: -
    
    Name: ACPI_HAL
    Image Path: \Driver\ACPI_HAL
    Address: 0x82608000	Size: 3903488	File Visible: -	Signed: -
    Status: -
    
    Name: afd.sys
    Image Path: C:\Windows\system32\drivers\afd.sys
    Address: 0x903B7000	Size: 294912	File Visible: -	Signed: -
    Status: -
    
    Name: amdk8.sys
    Image Path: C:\Windows\system32\DRIVERS\amdk8.sys
    Address: 0x8AD10000	Size: 65536	File Visible: -	Signed: -
    Status: -
    
    Name: AsDsm.sys
    Image Path: C:\Windows\System32\Drivers\AsDsm.sys
    Address: 0x80784000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: ASMMAP.sys
    Image Path: C:\Program Files\ATKGFNEX\ASMMAP.sys
    Address: 0x905F7000	Size: 28672	File Visible: -	Signed: -
    Status: -
    
    Name: asyncmac.sys
    Image Path: C:\Windows\system32\DRIVERS\asyncmac.sys
    Address: 0x9DCE5000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: atapi.sys
    Image Path: C:\Windows\system32\drivers\atapi.sys
    Address: 0x8071C000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: ataport.SYS
    Image Path: C:\Windows\system32\drivers\ataport.SYS
    Address: 0x80724000	Size: 122880	File Visible: -	Signed: -
    Status: -
    
    Name: athr.sys
    Image Path: C:\Windows\system32\DRIVERS\athr.sys
    Address: 0x8F10A000	Size: 765952	File Visible: -	Signed: -
    Status: -
    
    Name: ATKACPI.sys
    Image Path: C:\Windows\system32\DRIVERS\ATKACPI.sys
    Address: 0x8AFF8000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: ATMFD.DLL
    Image Path: C:\Windows\System32\ATMFD.DLL
    Address: 0x98110000	Size: 311296	File Visible: -	Signed: -
    Status: -
    
    Name: BATTC.SYS
    Image Path: C:\Windows\system32\DRIVERS\BATTC.SYS
    Address: 0x80694000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: Beep.SYS
    Image Path: C:\Windows\System32\Drivers\Beep.SYS
    Address: 0x9031B000	Size: 28672	File Visible: -	Signed: -
    Status: -
    
    Name: BOOTVID.dll
    Image Path: C:\Windows\system32\BOOTVID.dll
    Address: 0x8041E000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: bowser.sys
    Image Path: C:\Windows\system32\DRIVERS\bowser.sys
    Address: 0x881E7000	Size: 102400	File Visible: -	Signed: -
    Status: -
    
    Name: cdd.dll
    Image Path: C:\Windows\System32\cdd.dll
    Address: 0x98100000	Size: 57344	File Visible: -	Signed: -
    Status: -
    
    Name: cdfs.sys
    Image Path: C:\Windows\system32\DRIVERS\cdfs.sys
    Address: 0xA1034000	Size: 90112	File Visible: -	Signed: -
    Status: -
    
    Name: cdrom.sys
    Image Path: C:\Windows\system32\DRIVERS\cdrom.sys
    Address: 0x8ADD0000	Size: 98304	File Visible: -	Signed: -
    Status: -
    
    Name: CI.dll
    Image Path: C:\Windows\system32\CI.dll
    Address: 0x80467000	Size: 917504	File Visible: -	Signed: -
    Status: -
    
    Name: CLASSPNP.SYS
    Image Path: C:\Windows\system32\drivers\CLASSPNP.SYS
    Address: 0x8AFA3000	Size: 135168	File Visible: -	Signed: -
    Status: -
    
    Name: CLFS.SYS
    Image Path: C:\Windows\system32\CLFS.SYS
    Address: 0x80426000	Size: 266240	File Visible: -	Signed: -
    Status: -
    
    Name: CmBatt.sys
    Image Path: C:\Windows\system32\DRIVERS\CmBatt.sys
    Address: 0x8FD7D000	Size: 14208	File Visible: -	Signed: -
    Status: -
    
    Name: compbatt.sys
    Image Path: C:\Windows\system32\DRIVERS\compbatt.sys
    Address: 0x80691000	Size: 10496	File Visible: -	Signed: -
    Status: -
    
    Name: crashdmp.sys
    Image Path: C:\Windows\System32\Drivers\crashdmp.sys
    Address: 0x905BE000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: crcdisk.sys
    Image Path: C:\Windows\system32\drivers\crcdisk.sys
    Address: 0x8AFC4000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: csc.sys
    Image Path: C:\Windows\system32\drivers\csc.sys
    Address: 0x88003000	Size: 368640	File Visible: -	Signed: -
    Status: -
    
    Name: dfsc.sys
    Image Path: C:\Windows\System32\Drivers\dfsc.sys
    Address: 0x8805D000	Size: 94208	File Visible: -	Signed: -
    Status: -
    
    Name: disk.sys
    Image Path: C:\Windows\system32\drivers\disk.sys
    Address: 0x8AF92000	Size: 69632	File Visible: -	Signed: -
    Status: -
    
    Name: drmk.sys
    Image Path: C:\Windows\system32\drivers\drmk.sys
    Address: 0x8F327000	Size: 151552	File Visible: -	Signed: -
    Status: -
    
    Name: dump_atapi.sys
    Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
    Address: 0x905D6000	Size: 32768	File Visible: No	Signed: -
    Status: -
    
    Name: dump_dumpata.sys
    Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
    Address: 0x905CB000	Size: 45056	File Visible: No	Signed: -
    Status: -
    
    Name: Dxapi.sys
    Image Path: C:\Windows\System32\drivers\Dxapi.sys
    Address: 0x905DE000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: dxgkrnl.sys
    Image Path: C:\Windows\System32\drivers\dxgkrnl.sys
    Address: 0x8FCD1000	Size: 651264	File Visible: -	Signed: -
    Status: -
    
    Name: ecache.sys
    Image Path: C:\Windows\System32\drivers\ecache.sys
    Address: 0x8AF6B000	Size: 159744	File Visible: -	Signed: -
    Status: -
    
    Name: fastfat.SYS
    Image Path: C:\Windows\System32\Drivers\fastfat.SYS
    Address: 0x9DCEE000	Size: 163840	File Visible: -	Signed: -
    Status: -
    
    Name: fileinfo.sys
    Image Path: C:\Windows\system32\drivers\fileinfo.sys
    Address: 0x80774000	Size: 65536	File Visible: -	Signed: -
    Status: -
    
    Name: fltmgr.sys
    Image Path: C:\Windows\system32\drivers\fltmgr.sys
    Address: 0x80742000	Size: 204800	File Visible: -	Signed: -
    Status: -
    
    Name: Fs_Rec.SYS
    Image Path: C:\Windows\System32\Drivers\Fs_Rec.SYS
    Address: 0x9030B000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: fwpkclnt.sys
    Image Path: C:\Windows\System32\drivers\fwpkclnt.sys
    Address: 0x8ACF5000	Size: 110592	File Visible: -	Signed: -
    Status: -
    
    Name: GEARAspiWDM.sys
    Image Path: C:\Windows\System32\Drivers\GEARAspiWDM.sys
    Address: 0x8ADE8000	Size: 9472	File Visible: -	Signed: -
    Status: -
    
    Name: H8SRTxvgnxejltr.sys
    Image Path: C:\Windows\system32\drivers\H8SRTxvgnxejltr.sys
    Address: 0x9034E000	Size: 118784	File Visible: -	Signed: -
    Status: Hidden from the Windows API!
    
    Name: hal.dll
    Image Path: C:\Windows\system32\hal.dll
    Address: 0x829C1000	Size: 208896	File Visible: -	Signed: -
    Status: -
    
    Name: HDAudBus.sys
    Image Path: C:\Windows\system32\DRIVERS\HDAudBus.sys
    Address: 0x8ADEB000	Size: 73728	File Visible: -	Signed: -
    Status: -
    
    Name: HIDPARSE.SYS
    Image Path: C:\Windows\system32\DRIVERS\HIDPARSE.SYS
    Address: 0x9032B000	Size: 28672	File Visible: -	Signed: -
    Status: -
    
    Name: HTTP.sys
    Image Path: C:\Windows\system32\drivers\HTTP.sys
    Address: 0x8817A000	Size: 446464	File Visible: -	Signed: -
    Status: -
    
    Name: i8042prt.sys
    Image Path: C:\Windows\system32\DRIVERS\i8042prt.sys
    Address: 0x8AD20000	Size: 77824	File Visible: -	Signed: -
    Status: -
    
    Name: kbdclass.sys
    Image Path: C:\Windows\system32\DRIVERS\kbdclass.sys
    Address: 0x8AD33000	Size: 45056	File Visible: -	Signed: -
    Status: -
    
    Name: kbfiltr.sys
    Image Path: C:\Windows\system32\DRIVERS\kbfiltr.sys
    Address: 0x8AE09000	Size: 5632	File Visible: -	Signed: -
    Status: -
    
    Name: kdcom.dll
    Image Path: C:\Windows\system32\kdcom.dll
    Address: 0x80405000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: ks.sys
    Image Path: C:\Windows\system32\DRIVERS\ks.sys
    Address: 0x8F2A1000	Size: 172032	File Visible: -	Signed: -
    Status: -
    
    Name: ksecdd.sys
    Image Path: C:\Windows\System32\Drivers\ksecdd.sys
    Address: 0x8078E000	Size: 462848	File Visible: -	Signed: -
    Status: -
    
    Name: lltdio.sys
    Image Path: C:\Windows\system32\DRIVERS\lltdio.sys
    Address: 0x88123000	Size: 65536	File Visible: -	Signed: -
    Status: -
    
    Name: lmimirr.sys
    Image Path: C:\Windows\system32\DRIVERS\lmimirr.sys
    Address: 0x8FD81000	Size: 3200	File Visible: -	Signed: -
    Status: -
    
    Name: LMIRfsDriver.sys
    Image Path: C:\Windows\system32\drivers\LMIRfsDriver.sys
    Address: 0x9DD18000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: modem.sys
    Image Path: C:\Windows\system32\drivers\modem.sys
    Address: 0x902F4000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: MODEMCSA.sys
    Image Path: C:\Windows\system32\drivers\MODEMCSA.sys
    Address: 0x90301000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: monitor.sys
    Image Path: C:\Windows\system32\DRIVERS\monitor.sys
    Address: 0x905E8000	Size: 61440	File Visible: -	Signed: -
    Status: -
    
    Name: mouclass.sys
    Image Path: C:\Windows\system32\DRIVERS\mouclass.sys
    Address: 0x8AD6B000	Size: 45056	File Visible: -	Signed: -
    Status: -
    
    Name: mountmgr.sys
    Image Path: C:\Windows\System32\drivers\mountmgr.sys
    Address: 0x8070C000	Size: 65536	File Visible: -	Signed: -
    Status: -
    
    Name: mpsdrv.sys
    Image Path: C:\Windows\System32\drivers\mpsdrv.sys
    Address: 0x8ABDC000	Size: 86016	File Visible: -	Signed: -
    Status: -
    
    Name: mrxdav.sys
    Image Path: C:\Windows\system32\drivers\mrxdav.sys
    Address: 0x805D0000	Size: 131072	File Visible: -	Signed: -
    Status: -
    
    Name: mrxsmb.sys
    Image Path: C:\Windows\system32\DRIVERS\mrxsmb.sys
    Address: 0x9DC02000	Size: 126976	File Visible: -	Signed: -
    Status: -
    
    Name: mrxsmb10.sys
    Image Path: C:\Windows\system32\DRIVERS\mrxsmb10.sys
    Address: 0x9DC21000	Size: 233472	File Visible: -	Signed: -
    Status: -
    
    Name: mrxsmb20.sys
    Image Path: C:\Windows\system32\DRIVERS\mrxsmb20.sys
    Address: 0x9DC5A000	Size: 98304	File Visible: -	Signed: -
    Status: -
    
    Name: Msfs.SYS
    Image Path: C:\Windows\System32\Drivers\Msfs.SYS
    Address: 0x9036B000	Size: 45056	File Visible: -	Signed: -
    Status: -
    
    Name: msisadrv.sys
    Image Path: C:\Windows\system32\drivers\msisadrv.sys
    Address: 0x80653000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: msiscsi.sys
    Image Path: C:\Windows\system32\DRIVERS\msiscsi.sys
    Address: 0x8FDA3000	Size: 188416	File Visible: -	Signed: -
    Status: -
    
    Name: msrpc.sys
    Image Path: C:\Windows\system32\drivers\msrpc.sys
    Address: 0x8AB0D000	Size: 176128	File Visible: -	Signed: -
    Status: -
    
    Name: mssmbios.sys
    Image Path: C:\Windows\system32\DRIVERS\mssmbios.sys
    Address: 0x8F2CB000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: mup.sys
    Image Path: C:\Windows\System32\Drivers\mup.sys
    Address: 0x8AF5C000	Size: 61440	File Visible: -	Signed: -
    Status: -
    
    Name: ndis.sys
    Image Path: C:\Windows\system32\drivers\ndis.sys
    Address: 0x8AA02000	Size: 1093632	File Visible: -	Signed: -
    Status: -
    
    Name: ndistapi.sys
    Image Path: C:\Windows\system32\DRIVERS\ndistapi.sys
    Address: 0x8FDF3000	Size: 45056	File Visible: -	Signed: -
    Status: -
    
    Name: ndisuio.sys
    Image Path: C:\Windows\system32\DRIVERS\ndisuio.sys
    Address: 0x8815D000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: ndiswan.sys
    Image Path: C:\Windows\system32\DRIVERS\ndiswan.sys
    Address: 0x8F1C5000	Size: 143360	File Visible: -	Signed: -
    Status: -
    
    Name: NDProxy.SYS
    Image Path: C:\Windows\System32\Drivers\NDProxy.SYS
    Address: 0x8F316000	Size: 69632	File Visible: -	Signed: -
    Status: -
    
    Name: netbios.sys
    Image Path: C:\Windows\system32\DRIVERS\netbios.sys
    Address: 0x8F394000	Size: 57344	File Visible: -	Signed: -
    Status: -
    
    Name: netbt.sys
    Image Path: C:\Windows\System32\DRIVERS\netbt.sys
    Address: 0x8F34C000	Size: 204800	File Visible: -	Signed: -
    Status: -
    
    Name: NETIO.SYS
    Image Path: C:\Windows\system32\drivers\NETIO.SYS
    Address: 0x8AB38000	Size: 237568	File Visible: -	Signed: -
    Status: -
    
    Name: Npfs.SYS
    Image Path: C:\Windows\System32\Drivers\Npfs.SYS
    Address: 0x90376000	Size: 57344	File Visible: -	Signed: -
    Status: -
    
    Name: nsiproxy.sys
    Image Path: C:\Windows\system32\drivers\nsiproxy.sys
    Address: 0x8F3F1000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: Ntfs.sys
    Image Path: C:\Windows\System32\Drivers\Ntfs.sys
    Address: 0x8AE0C000	Size: 1110016	File Visible: -	Signed: -
    Status: -
    
    Name: ntkrnlpa.exe
    Image Path: C:\Windows\system32\ntkrnlpa.exe
    Address: 0x82608000	Size: 3903488	File Visible: -	Signed: -
    Status: -
    
    Name: Null.SYS
    Image Path: C:\Windows\System32\Drivers\Null.SYS
    Address: 0x90314000	Size: 28672	File Visible: -	Signed: -
    Status: -
    
    Name: nvlddmkm.sys
    Image Path: C:\Windows\system32\DRIVERS\nvlddmkm.sys
    Address: 0x8F607000	Size: 7115264	File Visible: -	Signed: -
    Status: -
    
    Name: nvmfdx32.sys
    Image Path: C:\Windows\system32\DRIVERS\nvmfdx32.sys
    Address: 0x8F00D000	Size: 1033856	File Visible: -	Signed: -
    Status: -
    
    Name: nvsmu.sys
    Image Path: C:\Windows\system32\DRIVERS\nvsmu.sys
    Address: 0x8AD76000	Size: 12032	File Visible: -	Signed: -
    Status: -
    
    Name: nwifi.sys
    Image Path: C:\Windows\system32\DRIVERS\nwifi.sys
    Address: 0x88133000	Size: 172032	File Visible: -	Signed: -
    Status: -
    
    Name: pacer.sys
    Image Path: C:\Windows\system32\DRIVERS\pacer.sys
    Address: 0x8F37E000	Size: 90112	File Visible: -	Signed: -
    Status: -
    
    Name: partmgr.sys
    Image Path: C:\Windows\System32\drivers\partmgr.sys
    Address: 0x80682000	Size: 61440	File Visible: -	Signed: -
    Status: -
    
    Name: pci.sys
    Image Path: C:\Windows\system32\drivers\pci.sys
    Address: 0x8065B000	Size: 159744	File Visible: -	Signed: -
    Status: -
    
    Name: pciide.sys
    Image Path: C:\Windows\system32\drivers\pciide.sys
    Address: 0x806F7000	Size: 28672	File Visible: -	Signed: -
    Status: -
    
    Name: PCIIDEX.SYS
    Image Path: C:\Windows\system32\drivers\PCIIDEX.SYS
    Address: 0x806FE000	Size: 57344	File Visible: -	Signed: -
    Status: -
    
    Name: peauth.sys
    Image Path: C:\Windows\system32\drivers\peauth.sys
    Address: 0x9DD22000	Size: 909312	File Visible: -	Signed: -
    Status: -
    
    Name: PnpManager
    Image Path: \Driver\PnpManager
    Address: 0x82608000	Size: 3903488	File Visible: -	Signed: -
    Status: -
    
    Name: portcls.sys
    Image Path: C:\Windows\system32\drivers\portcls.sys
    Address: 0x901C6000	Size: 184320	File Visible: -	Signed: -
    Status: -
    
    Name: PSHED.dll
    Image Path: C:\Windows\system32\PSHED.dll
    Address: 0x8040D000	Size: 69632	File Visible: -	Signed: -
    Status: -
    
    Name: RaInfo.sys
    Image Path: C:\Program Files\LogMeIn\x86\RaInfo.sys
    Address: 0x9DD16000	Size: 6144	File Visible: -	Signed: -
    Status: -
    
    Name: rasacd.sys
    Image Path: C:\Windows\System32\DRIVERS\rasacd.sys
    Address: 0x90384000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: rasl2tp.sys
    Image Path: C:\Windows\system32\DRIVERS\rasl2tp.sys
    Address: 0x8FDDC000	Size: 94208	File Visible: -	Signed: -
    Status: -
    
    Name: raspppoe.sys
    Image Path: C:\Windows\system32\DRIVERS\raspppoe.sys
    Address: 0x8F1E8000	Size: 61440	File Visible: -	Signed: -
    Status: -
    
    Name: raspptp.sys
    Image Path: C:\Windows\system32\DRIVERS\raspptp.sys
    Address: 0x8ABB3000	Size: 81920	File Visible: -	Signed: -
    Status: -
    
    Name: rassstp.sys
    Image Path: C:\Windows\system32\DRIVERS\rassstp.sys
    Address: 0x8ABC7000	Size: 86016	File Visible: -	Signed: -
    Status: -
    
    Name: RAW
    Image Path: \FileSystem\RAW
    Address: 0x82608000	Size: 3903488	File Visible: -	Signed: -
    Status: -
    
    Name: rdbss.sys
    Image Path: C:\Windows\system32\DRIVERS\rdbss.sys
    Address: 0x8F3B5000	Size: 245760	File Visible: -	Signed: -
    Status: -
    
    Name: RDPCDD.sys
    Image Path: C:\Windows\System32\DRIVERS\RDPCDD.sys
    Address: 0x9033E000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: rdpdr.sys
    Image Path: C:\Windows\system32\DRIVERS\rdpdr.sys
    Address: 0x8F206000	Size: 561152	File Visible: -	Signed: -
    Status: -
    
    Name: rdpencdd.sys
    Image Path: C:\Windows\system32\drivers\rdpencdd.sys
    Address: 0x90346000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: rootrepeal.sys
    Image Path: C:\Windows\system32\drivers\rootrepeal.sys
    Address: 0xA104C000	Size: 49152	File Visible: No	Signed: -
    Status: -
    
    Name: rspndr.sys
    Image Path: C:\Windows\system32\DRIVERS\rspndr.sys
    Address: 0x88167000	Size: 77824	File Visible: -	Signed: -
    Status: -
    
    Name: RTKVHDA.sys
    Image Path: C:\Windows\system32\drivers\RTKVHDA.sys
    Address: 0x90006000	Size: 1834624	File Visible: -	Signed: -
    Status: -
    
    Name: RTSTOR.SYS
    Image Path: C:\Windows\system32\drivers\RTSTOR.SYS
    Address: 0x901F3000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: secdrv.SYS
    Image Path: C:\Windows\System32\Drivers\secdrv.SYS
    Address: 0x8F000000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: smb.sys
    Image Path: C:\Windows\system32\DRIVERS\smb.sys
    Address: 0x903A3000	Size: 81920	File Visible: -	Signed: -
    Status: -
    
    Name: smserial.sys
    Image Path: C:\Windows\system32\DRIVERS\smserial.sys
    Address: 0x90204000	Size: 982272	File Visible: -	Signed: -
    Status: -
    
    Name: sncduvc.SYS
    Image Path: C:\Windows\system32\DRIVERS\sncduvc.SYS
    Address: 0x905B7000	Size: 28672	File Visible: -	Signed: -
    Status: -
    
    Name: snp2uvc.sys
    Image Path: C:\Windows\system32\DRIVERS\snp2uvc.sys
    Address: 0x90401000	Size: 1737984	File Visible: -	Signed: -
    Status: -
    
    Name: spldr.sys
    Image Path: C:\Windows\System32\Drivers\spldr.sys
    Address: 0x8AF54000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: spsys.sys
    Image Path: C:\Windows\system32\drivers\spsys.sys
    Address: 0x88074000	Size: 716800	File Visible: -	Signed: -
    Status: -
    
    Name: srv.sys
    Image Path: C:\Windows\System32\DRIVERS\srv.sys
    Address: 0x9DC99000	Size: 311296	File Visible: -	Signed: -
    Status: -
    
    Name: srv2.sys
    Image Path: C:\Windows\System32\DRIVERS\srv2.sys
    Address: 0x9DC72000	Size: 159744	File Visible: -	Signed: -
    Status: -
    
    Name: srvnet.sys
    Image Path: C:\Windows\System32\DRIVERS\srvnet.sys
    Address: 0x8AFCD000	Size: 118784	File Visible: -	Signed: -
    Status: -
    
    Name: storport.sys
    Image Path: C:\Windows\system32\DRIVERS\storport.sys
    Address: 0x8AB72000	Size: 266240	File Visible: -	Signed: -
    Status: -
    
    Name: STREAM.SYS
    Image Path: C:\Windows\system32\DRIVERS\STREAM.SYS
    Address: 0x905AA000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: swenum.sys
    Image Path: C:\Windows\system32\DRIVERS\swenum.sys
    Address: 0x8F29F000	Size: 4992	File Visible: -	Signed: -
    Status: -
    
    Name: SynTP.sys
    Image Path: C:\Windows\system32\DRIVERS\SynTP.sys
    Address: 0x8AD3E000	Size: 175488	File Visible: -	Signed: -
    Status: -
    
    Name: tcpip.sys
    Image Path: C:\Windows\System32\drivers\tcpip.sys
    Address: 0x8AC0C000	Size: 954368	File Visible: -	Signed: -
    Status: -
    
    Name: tcpipreg.sys
    Image Path: C:\Windows\System32\drivers\tcpipreg.sys
    Address: 0x8AC00000	Size: 49152	File Visible: -	Signed: -
    Status: -
    
    Name: TDI.SYS
    Image Path: C:\Windows\system32\DRIVERS\TDI.SYS
    Address: 0x8FDD1000	Size: 45056	File Visible: -	Signed: -
    Status: -
    
    Name: tdx.sys
    Image Path: C:\Windows\system32\DRIVERS\tdx.sys
    Address: 0x9038D000	Size: 90112	File Visible: -	Signed: -
    Status: -
    
    Name: termdd.sys
    Image Path: C:\Windows\system32\DRIVERS\termdd.sys
    Address: 0x8F28F000	Size: 65536	File Visible: -	Signed: -
    Status: -
    
    Name: TSDDD.dll
    Image Path: C:\Windows\System32\TSDDD.dll
    Address: 0x980E0000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: tunmp.sys
    Image Path: C:\Windows\system32\DRIVERS\tunmp.sys
    Address: 0x8AE00000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: tunnel.sys
    Image Path: C:\Windows\system32\DRIVERS\tunnel.sys
    Address: 0x8AFED000	Size: 45056	File Visible: -	Signed: -
    Status: -
    
    Name: umbus.sys
    Image Path: C:\Windows\system32\DRIVERS\umbus.sys
    Address: 0x8F2D5000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: USBD.SYS
    Image Path: C:\Windows\system32\DRIVERS\USBD.SYS
    Address: 0x8AD69000	Size: 8192	File Visible: -	Signed: -
    Status: -
    
    Name: usbehci.sys
    Image Path: C:\Windows\system32\DRIVERS\usbehci.sys
    Address: 0x8ADC1000	Size: 61440	File Visible: -	Signed: -
    Status: -
    
    Name: usbhub.sys
    Image Path: C:\Windows\system32\DRIVERS\usbhub.sys
    Address: 0x8F2E2000	Size: 212992	File Visible: -	Signed: -
    Status: -
    
    Name: usbohci.sys
    Image Path: C:\Windows\system32\DRIVERS\usbohci.sys
    Address: 0x8AD79000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: USBPORT.SYS
    Image Path: C:\Windows\system32\DRIVERS\USBPORT.SYS
    Address: 0x8AD83000	Size: 253952	File Visible: -	Signed: -
    Status: -
    
    Name: vga.sys
    Image Path: C:\Windows\System32\drivers\vga.sys
    Address: 0x90332000	Size: 49152	File Visible: -	Signed: -
    Status: -
    
    Name: VIDEOPRT.SYS
    Image Path: C:\Windows\system32\DRIVERS\VIDEOPRT.SYS
    Address: 0x8FD82000	Size: 135168	File Visible: -	Signed: -
    Status: -
    
    Name: volmgr.sys
    Image Path: C:\Windows\system32\drivers\volmgr.sys
    Address: 0x8069E000	Size: 61440	File Visible: -	Signed: -
    Status: -
    
    Name: volmgrx.sys
    Image Path: C:\Windows\System32\drivers\volmgrx.sys
    Address: 0x806AD000	Size: 303104	File Visible: -	Signed: -
    Status: -
    
    Name: volsnap.sys
    Image Path: C:\Windows\system32\drivers\volsnap.sys
    Address: 0x8AF1B000	Size: 233472	File Visible: -	Signed: -
    Status: -
    
    Name: wanarp.sys
    Image Path: C:\Windows\system32\DRIVERS\wanarp.sys
    Address: 0x8F3A2000	Size: 77824	File Visible: -	Signed: -
    Status: -
    
    Name: Wanarpv6
    Image Path: \Driver\Wanarpv6
    Address: 0x8F599000	Size: 77824	File Visible: No	Signed: -
    Status: Hidden from the Windows API!
    
    Name: watchdog.sys
    Image Path: C:\Windows\System32\drivers\watchdog.sys
    Address: 0x8FD70000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: Wdf01000.sys
    Image Path: C:\Windows\system32\drivers\Wdf01000.sys
    Address: 0x80547000	Size: 507904	File Visible: -	Signed: -
    Status: -
    
    Name: WDFLDR.SYS
    Image Path: C:\Windows\system32\drivers\WDFLDR.SYS
    Address: 0x805C3000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: Win32k
    Image Path: \Driver\Win32k
    Address: 0x97EC0000	Size: 2105344	File Visible: -	Signed: -
    Status: -
    
    Name: win32k.sys
    Image Path: C:\Windows\System32\win32k.sys
    Address: 0x97EC0000	Size: 2105344	File Visible: -	Signed: -
    Status: -
    
    Name: WMILIB.SYS
    Image Path: C:\Windows\system32\drivers\WMILIB.SYS
    Address: 0x8064A000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: WMIxWDM
    Image Path: \Driver\WMIxWDM
    Address: 0x82608000	Size: 3903488	File Visible: -	Signed: -
    Status: -
    
    Name: WUDFPf.sys
    Image Path: C:\Windows\system32\DRIVERS\WUDFPf.sys
    Address: 0xA1022000	Size: 73728	File Visible: -	Signed: -
    Status: -
    
    Name: WUDFRd.sys
    Image Path: C:\Windows\system32\DRIVERS\WUDFRd.sys
    Address: 0xA100D000	Size: 83328	File Visible: -	Signed: -
    Status: -
    Geändert von kira (14.01.2010 um 00:13 Uhr)

  8. #8
    Moderator Team-Mitglied Benutzerbild von kira
    Registriert seit
    28.03.2006
    Ort
    Wien/Sprachen: Deutsch-Ungarisch
    Beiträge
    25.767

    AW: Internet Explorer öffnet sich selbst

    das ist alles was Du rausgekriegst hast?
    Neuaufsetzen (Windows XP, Vista und Windows 7) - Anleitungen
    Virenscanner
    Wie man seinen Rechner von Viren befreit

    *Der beste Schutz ist immer noch der verantwortungsvolle Umgang mit dem Internet!*

  9. #9
    Einsteiger
    Registriert seit
    13.01.2010
    Beiträge
    15

    AW: Internet Explorer öffnet sich selbst

    Ich habe es nochmals kopiert - nur zur Sicherheit:

    Code:
    ROOTREPEAL (c) AD, 2007-2009
    ==================================================
    Scan Start Time:		2010/01/13 23:16
    Program Version:		Version 1.3.5.0
    Windows Version:		Windows Vista SP1
    ==================================================
    
    Drivers
    -------------------
    Name: acpi.sys
    Image Path: C:\Windows\system32\drivers\acpi.sys
    Address: 0x80604000	Size: 286720	File Visible: -	Signed: -
    Status: -
    
    Name: ACPI_HAL
    Image Path: \Driver\ACPI_HAL
    Address: 0x82608000	Size: 3903488	File Visible: -	Signed: -
    Status: -
    
    Name: afd.sys
    Image Path: C:\Windows\system32\drivers\afd.sys
    Address: 0x903B7000	Size: 294912	File Visible: -	Signed: -
    Status: -
    
    Name: amdk8.sys
    Image Path: C:\Windows\system32\DRIVERS\amdk8.sys
    Address: 0x8AD10000	Size: 65536	File Visible: -	Signed: -
    Status: -
    
    Name: AsDsm.sys
    Image Path: C:\Windows\System32\Drivers\AsDsm.sys
    Address: 0x80784000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: ASMMAP.sys
    Image Path: C:\Program Files\ATKGFNEX\ASMMAP.sys
    Address: 0x905F7000	Size: 28672	File Visible: -	Signed: -
    Status: -
    
    Name: asyncmac.sys
    Image Path: C:\Windows\system32\DRIVERS\asyncmac.sys
    Address: 0x9DCE5000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: atapi.sys
    Image Path: C:\Windows\system32\drivers\atapi.sys
    Address: 0x8071C000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: ataport.SYS
    Image Path: C:\Windows\system32\drivers\ataport.SYS
    Address: 0x80724000	Size: 122880	File Visible: -	Signed: -
    Status: -
    
    Name: athr.sys
    Image Path: C:\Windows\system32\DRIVERS\athr.sys
    Address: 0x8F10A000	Size: 765952	File Visible: -	Signed: -
    Status: -
    
    Name: ATKACPI.sys
    Image Path: C:\Windows\system32\DRIVERS\ATKACPI.sys
    Address: 0x8AFF8000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: ATMFD.DLL
    Image Path: C:\Windows\System32\ATMFD.DLL
    Address: 0x98110000	Size: 311296	File Visible: -	Signed: -
    Status: -
    
    Name: BATTC.SYS
    Image Path: C:\Windows\system32\DRIVERS\BATTC.SYS
    Address: 0x80694000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: Beep.SYS
    Image Path: C:\Windows\System32\Drivers\Beep.SYS
    Address: 0x9031B000	Size: 28672	File Visible: -	Signed: -
    Status: -
    
    Name: BOOTVID.dll
    Image Path: C:\Windows\system32\BOOTVID.dll
    Address: 0x8041E000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: bowser.sys
    Image Path: C:\Windows\system32\DRIVERS\bowser.sys
    Address: 0x881E7000	Size: 102400	File Visible: -	Signed: -
    Status: -
    
    Name: cdd.dll
    Image Path: C:\Windows\System32\cdd.dll
    Address: 0x98100000	Size: 57344	File Visible: -	Signed: -
    Status: -
    
    Name: cdfs.sys
    Image Path: C:\Windows\system32\DRIVERS\cdfs.sys
    Address: 0xA1034000	Size: 90112	File Visible: -	Signed: -
    Status: -
    
    Name: cdrom.sys
    Image Path: C:\Windows\system32\DRIVERS\cdrom.sys
    Address: 0x8ADD0000	Size: 98304	File Visible: -	Signed: -
    Status: -
    
    Name: CI.dll
    Image Path: C:\Windows\system32\CI.dll
    Address: 0x80467000	Size: 917504	File Visible: -	Signed: -
    Status: -
    
    Name: CLASSPNP.SYS
    Image Path: C:\Windows\system32\drivers\CLASSPNP.SYS
    Address: 0x8AFA3000	Size: 135168	File Visible: -	Signed: -
    Status: -
    
    Name: CLFS.SYS
    Image Path: C:\Windows\system32\CLFS.SYS
    Address: 0x80426000	Size: 266240	File Visible: -	Signed: -
    Status: -
    
    Name: CmBatt.sys
    Image Path: C:\Windows\system32\DRIVERS\CmBatt.sys
    Address: 0x8FD7D000	Size: 14208	File Visible: -	Signed: -
    Status: -
    
    Name: compbatt.sys
    Image Path: C:\Windows\system32\DRIVERS\compbatt.sys
    Address: 0x80691000	Size: 10496	File Visible: -	Signed: -
    Status: -
    
    Name: crashdmp.sys
    Image Path: C:\Windows\System32\Drivers\crashdmp.sys
    Address: 0x905BE000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: crcdisk.sys
    Image Path: C:\Windows\system32\drivers\crcdisk.sys
    Address: 0x8AFC4000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: csc.sys
    Image Path: C:\Windows\system32\drivers\csc.sys
    Address: 0x88003000	Size: 368640	File Visible: -	Signed: -
    Status: -
    
    Name: dfsc.sys
    Image Path: C:\Windows\System32\Drivers\dfsc.sys
    Address: 0x8805D000	Size: 94208	File Visible: -	Signed: -
    Status: -
    
    Name: disk.sys
    Image Path: C:\Windows\system32\drivers\disk.sys
    Address: 0x8AF92000	Size: 69632	File Visible: -	Signed: -
    Status: -
    
    Name: drmk.sys
    Image Path: C:\Windows\system32\drivers\drmk.sys
    Address: 0x8F327000	Size: 151552	File Visible: -	Signed: -
    Status: -
    
    Name: dump_atapi.sys
    Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
    Address: 0x905D6000	Size: 32768	File Visible: No	Signed: -
    Status: -
    
    Name: dump_dumpata.sys
    Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
    Address: 0x905CB000	Size: 45056	File Visible: No	Signed: -
    Status: -
    
    Name: Dxapi.sys
    Image Path: C:\Windows\System32\drivers\Dxapi.sys
    Address: 0x905DE000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: dxgkrnl.sys
    Image Path: C:\Windows\System32\drivers\dxgkrnl.sys
    Address: 0x8FCD1000	Size: 651264	File Visible: -	Signed: -
    Status: -
    
    Name: ecache.sys
    Image Path: C:\Windows\System32\drivers\ecache.sys
    Address: 0x8AF6B000	Size: 159744	File Visible: -	Signed: -
    Status: -
    
    Name: fastfat.SYS
    Image Path: C:\Windows\System32\Drivers\fastfat.SYS
    Address: 0x9DCEE000	Size: 163840	File Visible: -	Signed: -
    Status: -
    
    Name: fileinfo.sys
    Image Path: C:\Windows\system32\drivers\fileinfo.sys
    Address: 0x80774000	Size: 65536	File Visible: -	Signed: -
    Status: -
    
    Name: fltmgr.sys
    Image Path: C:\Windows\system32\drivers\fltmgr.sys
    Address: 0x80742000	Size: 204800	File Visible: -	Signed: -
    Status: -
    
    Name: Fs_Rec.SYS
    Image Path: C:\Windows\System32\Drivers\Fs_Rec.SYS
    Address: 0x9030B000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: fwpkclnt.sys
    Image Path: C:\Windows\System32\drivers\fwpkclnt.sys
    Address: 0x8ACF5000	Size: 110592	File Visible: -	Signed: -
    Status: -
    
    Name: GEARAspiWDM.sys
    Image Path: C:\Windows\System32\Drivers\GEARAspiWDM.sys
    Address: 0x8ADE8000	Size: 9472	File Visible: -	Signed: -
    Status: -
    
    Name: H8SRTxvgnxejltr.sys
    Image Path: C:\Windows\system32\drivers\H8SRTxvgnxejltr.sys
    Address: 0x9034E000	Size: 118784	File Visible: -	Signed: -
    Status: Hidden from the Windows API!
    
    Name: hal.dll
    Image Path: C:\Windows\system32\hal.dll
    Address: 0x829C1000	Size: 208896	File Visible: -	Signed: -
    Status: -
    
    Name: HDAudBus.sys
    Image Path: C:\Windows\system32\DRIVERS\HDAudBus.sys
    Address: 0x8ADEB000	Size: 73728	File Visible: -	Signed: -
    Status: -
    
    Name: HIDPARSE.SYS
    Image Path: C:\Windows\system32\DRIVERS\HIDPARSE.SYS
    Address: 0x9032B000	Size: 28672	File Visible: -	Signed: -
    Status: -
    
    Name: HTTP.sys
    Image Path: C:\Windows\system32\drivers\HTTP.sys
    Address: 0x8817A000	Size: 446464	File Visible: -	Signed: -
    Status: -
    
    Name: i8042prt.sys
    Image Path: C:\Windows\system32\DRIVERS\i8042prt.sys
    Address: 0x8AD20000	Size: 77824	File Visible: -	Signed: -
    Status: -
    
    Name: kbdclass.sys
    Image Path: C:\Windows\system32\DRIVERS\kbdclass.sys
    Address: 0x8AD33000	Size: 45056	File Visible: -	Signed: -
    Status: -
    
    Name: kbfiltr.sys
    Image Path: C:\Windows\system32\DRIVERS\kbfiltr.sys
    Address: 0x8AE09000	Size: 5632	File Visible: -	Signed: -
    Status: -
    
    Name: kdcom.dll
    Image Path: C:\Windows\system32\kdcom.dll
    Address: 0x80405000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: ks.sys
    Image Path: C:\Windows\system32\DRIVERS\ks.sys
    Address: 0x8F2A1000	Size: 172032	File Visible: -	Signed: -
    Status: -
    
    Name: ksecdd.sys
    Image Path: C:\Windows\System32\Drivers\ksecdd.sys
    Address: 0x8078E000	Size: 462848	File Visible: -	Signed: -
    Status: -
    
    Name: lltdio.sys
    Image Path: C:\Windows\system32\DRIVERS\lltdio.sys
    Address: 0x88123000	Size: 65536	File Visible: -	Signed: -
    Status: -
    
    Name: lmimirr.sys
    Image Path: C:\Windows\system32\DRIVERS\lmimirr.sys
    Address: 0x8FD81000	Size: 3200	File Visible: -	Signed: -
    Status: -
    
    Name: LMIRfsDriver.sys
    Image Path: C:\Windows\system32\drivers\LMIRfsDriver.sys
    Address: 0x9DD18000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: modem.sys
    Image Path: C:\Windows\system32\drivers\modem.sys
    Address: 0x902F4000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: MODEMCSA.sys
    Image Path: C:\Windows\system32\drivers\MODEMCSA.sys
    Address: 0x90301000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: monitor.sys
    Image Path: C:\Windows\system32\DRIVERS\monitor.sys
    Address: 0x905E8000	Size: 61440	File Visible: -	Signed: -
    Status: -
    
    Name: mouclass.sys
    Image Path: C:\Windows\system32\DRIVERS\mouclass.sys
    Address: 0x8AD6B000	Size: 45056	File Visible: -	Signed: -
    Status: -
    
    Name: mountmgr.sys
    Image Path: C:\Windows\System32\drivers\mountmgr.sys
    Address: 0x8070C000	Size: 65536	File Visible: -	Signed: -
    Status: -
    
    Name: mpsdrv.sys
    Image Path: C:\Windows\System32\drivers\mpsdrv.sys
    Address: 0x8ABDC000	Size: 86016	File Visible: -	Signed: -
    Status: -
    
    Name: mrxdav.sys
    Image Path: C:\Windows\system32\drivers\mrxdav.sys
    Address: 0x805D0000	Size: 131072	File Visible: -	Signed: -
    Status: -
    
    Name: mrxsmb.sys
    Image Path: C:\Windows\system32\DRIVERS\mrxsmb.sys
    Address: 0x9DC02000	Size: 126976	File Visible: -	Signed: -
    Status: -
    
    Name: mrxsmb10.sys
    Image Path: C:\Windows\system32\DRIVERS\mrxsmb10.sys
    Address: 0x9DC21000	Size: 233472	File Visible: -	Signed: -
    Status: -
    
    Name: mrxsmb20.sys
    Image Path: C:\Windows\system32\DRIVERS\mrxsmb20.sys
    Address: 0x9DC5A000	Size: 98304	File Visible: -	Signed: -
    Status: -
    
    Name: Msfs.SYS
    Image Path: C:\Windows\System32\Drivers\Msfs.SYS
    Address: 0x9036B000	Size: 45056	File Visible: -	Signed: -
    Status: -
    
    Name: msisadrv.sys
    Image Path: C:\Windows\system32\drivers\msisadrv.sys
    Address: 0x80653000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: msiscsi.sys
    Image Path: C:\Windows\system32\DRIVERS\msiscsi.sys
    Address: 0x8FDA3000	Size: 188416	File Visible: -	Signed: -
    Status: -
    
    Name: msrpc.sys
    Image Path: C:\Windows\system32\drivers\msrpc.sys
    Address: 0x8AB0D000	Size: 176128	File Visible: -	Signed: -
    Status: -
    
    Name: mssmbios.sys
    Image Path: C:\Windows\system32\DRIVERS\mssmbios.sys
    Address: 0x8F2CB000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: mup.sys
    Image Path: C:\Windows\System32\Drivers\mup.sys
    Address: 0x8AF5C000	Size: 61440	File Visible: -	Signed: -
    Status: -
    
    Name: ndis.sys
    Image Path: C:\Windows\system32\drivers\ndis.sys
    Address: 0x8AA02000	Size: 1093632	File Visible: -	Signed: -
    Status: -
    
    Name: ndistapi.sys
    Image Path: C:\Windows\system32\DRIVERS\ndistapi.sys
    Address: 0x8FDF3000	Size: 45056	File Visible: -	Signed: -
    Status: -
    
    Name: ndisuio.sys
    Image Path: C:\Windows\system32\DRIVERS\ndisuio.sys
    Address: 0x8815D000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: ndiswan.sys
    Image Path: C:\Windows\system32\DRIVERS\ndiswan.sys
    Address: 0x8F1C5000	Size: 143360	File Visible: -	Signed: -
    Status: -
    
    Name: NDProxy.SYS
    Image Path: C:\Windows\System32\Drivers\NDProxy.SYS
    Address: 0x8F316000	Size: 69632	File Visible: -	Signed: -
    Status: -
    
    Name: netbios.sys
    Image Path: C:\Windows\system32\DRIVERS\netbios.sys
    Address: 0x8F394000	Size: 57344	File Visible: -	Signed: -
    Status: -
    
    Name: netbt.sys
    Image Path: C:\Windows\System32\DRIVERS\netbt.sys
    Address: 0x8F34C000	Size: 204800	File Visible: -	Signed: -
    Status: -
    
    Name: NETIO.SYS
    Image Path: C:\Windows\system32\drivers\NETIO.SYS
    Address: 0x8AB38000	Size: 237568	File Visible: -	Signed: -
    Status: -
    
    Name: Npfs.SYS
    Image Path: C:\Windows\System32\Drivers\Npfs.SYS
    Address: 0x90376000	Size: 57344	File Visible: -	Signed: -
    Status: -
    
    Name: nsiproxy.sys
    Image Path: C:\Windows\system32\drivers\nsiproxy.sys
    Address: 0x8F3F1000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: Ntfs.sys
    Image Path: C:\Windows\System32\Drivers\Ntfs.sys
    Address: 0x8AE0C000	Size: 1110016	File Visible: -	Signed: -
    Status: -
    
    Name: ntkrnlpa.exe
    Image Path: C:\Windows\system32\ntkrnlpa.exe
    Address: 0x82608000	Size: 3903488	File Visible: -	Signed: -
    Status: -
    
    Name: Null.SYS
    Image Path: C:\Windows\System32\Drivers\Null.SYS
    Address: 0x90314000	Size: 28672	File Visible: -	Signed: -
    Status: -
    
    Name: nvlddmkm.sys
    Image Path: C:\Windows\system32\DRIVERS\nvlddmkm.sys
    Address: 0x8F607000	Size: 7115264	File Visible: -	Signed: -
    Status: -
    
    Name: nvmfdx32.sys
    Image Path: C:\Windows\system32\DRIVERS\nvmfdx32.sys
    Address: 0x8F00D000	Size: 1033856	File Visible: -	Signed: -
    Status: -
    
    Name: nvsmu.sys
    Image Path: C:\Windows\system32\DRIVERS\nvsmu.sys
    Address: 0x8AD76000	Size: 12032	File Visible: -	Signed: -
    Status: -
    
    Name: nwifi.sys
    Image Path: C:\Windows\system32\DRIVERS\nwifi.sys
    Address: 0x88133000	Size: 172032	File Visible: -	Signed: -
    Status: -
    
    Name: pacer.sys
    Image Path: C:\Windows\system32\DRIVERS\pacer.sys
    Address: 0x8F37E000	Size: 90112	File Visible: -	Signed: -
    Status: -
    
    Name: partmgr.sys
    Image Path: C:\Windows\System32\drivers\partmgr.sys
    Address: 0x80682000	Size: 61440	File Visible: -	Signed: -
    Status: -
    
    Name: pci.sys
    Image Path: C:\Windows\system32\drivers\pci.sys
    Address: 0x8065B000	Size: 159744	File Visible: -	Signed: -
    Status: -
    
    Name: pciide.sys
    Image Path: C:\Windows\system32\drivers\pciide.sys
    Address: 0x806F7000	Size: 28672	File Visible: -	Signed: -
    Status: -
    
    Name: PCIIDEX.SYS
    Image Path: C:\Windows\system32\drivers\PCIIDEX.SYS
    Address: 0x806FE000	Size: 57344	File Visible: -	Signed: -
    Status: -
    
    Name: peauth.sys
    Image Path: C:\Windows\system32\drivers\peauth.sys
    Address: 0x9DD22000	Size: 909312	File Visible: -	Signed: -
    Status: -
    
    Name: PnpManager
    Image Path: \Driver\PnpManager
    Address: 0x82608000	Size: 3903488	File Visible: -	Signed: -
    Status: -
    
    Name: portcls.sys
    Image Path: C:\Windows\system32\drivers\portcls.sys
    Address: 0x901C6000	Size: 184320	File Visible: -	Signed: -
    Status: -
    
    Name: PSHED.dll
    Image Path: C:\Windows\system32\PSHED.dll
    Address: 0x8040D000	Size: 69632	File Visible: -	Signed: -
    Status: -
    
    Name: RaInfo.sys
    Image Path: C:\Program Files\LogMeIn\x86\RaInfo.sys
    Address: 0x9DD16000	Size: 6144	File Visible: -	Signed: -
    Status: -
    
    Name: rasacd.sys
    Image Path: C:\Windows\System32\DRIVERS\rasacd.sys
    Address: 0x90384000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: rasl2tp.sys
    Image Path: C:\Windows\system32\DRIVERS\rasl2tp.sys
    Address: 0x8FDDC000	Size: 94208	File Visible: -	Signed: -
    Status: -
    
    Name: raspppoe.sys
    Image Path: C:\Windows\system32\DRIVERS\raspppoe.sys
    Address: 0x8F1E8000	Size: 61440	File Visible: -	Signed: -
    Status: -
    
    Name: raspptp.sys
    Image Path: C:\Windows\system32\DRIVERS\raspptp.sys
    Address: 0x8ABB3000	Size: 81920	File Visible: -	Signed: -
    Status: -
    
    Name: rassstp.sys
    Image Path: C:\Windows\system32\DRIVERS\rassstp.sys
    Address: 0x8ABC7000	Size: 86016	File Visible: -	Signed: -
    Status: -
    
    Name: RAW
    Image Path: \FileSystem\RAW
    Address: 0x82608000	Size: 3903488	File Visible: -	Signed: -
    Status: -
    
    Name: rdbss.sys
    Image Path: C:\Windows\system32\DRIVERS\rdbss.sys
    Address: 0x8F3B5000	Size: 245760	File Visible: -	Signed: -
    Status: -
    
    Name: RDPCDD.sys
    Image Path: C:\Windows\System32\DRIVERS\RDPCDD.sys
    Address: 0x9033E000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: rdpdr.sys
    Image Path: C:\Windows\system32\DRIVERS\rdpdr.sys
    Address: 0x8F206000	Size: 561152	File Visible: -	Signed: -
    Status: -
    
    Name: rdpencdd.sys
    Image Path: C:\Windows\system32\drivers\rdpencdd.sys
    Address: 0x90346000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: rootrepeal.sys
    Image Path: C:\Windows\system32\drivers\rootrepeal.sys
    Address: 0xA104C000	Size: 49152	File Visible: No	Signed: -
    Status: -
    
    Name: rspndr.sys
    Image Path: C:\Windows\system32\DRIVERS\rspndr.sys
    Address: 0x88167000	Size: 77824	File Visible: -	Signed: -
    Status: -
    
    Name: RTKVHDA.sys
    Image Path: C:\Windows\system32\drivers\RTKVHDA.sys
    Address: 0x90006000	Size: 1834624	File Visible: -	Signed: -
    Status: -
    
    Name: RTSTOR.SYS
    Image Path: C:\Windows\system32\drivers\RTSTOR.SYS
    Address: 0x901F3000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: secdrv.SYS
    Image Path: C:\Windows\System32\Drivers\secdrv.SYS
    Address: 0x8F000000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: smb.sys
    Image Path: C:\Windows\system32\DRIVERS\smb.sys
    Address: 0x903A3000	Size: 81920	File Visible: -	Signed: -
    Status: -
    
    Name: smserial.sys
    Image Path: C:\Windows\system32\DRIVERS\smserial.sys
    Address: 0x90204000	Size: 982272	File Visible: -	Signed: -
    Status: -
    
    Name: sncduvc.SYS
    Image Path: C:\Windows\system32\DRIVERS\sncduvc.SYS
    Address: 0x905B7000	Size: 28672	File Visible: -	Signed: -
    Status: -
    
    Name: snp2uvc.sys
    Image Path: C:\Windows\system32\DRIVERS\snp2uvc.sys
    Address: 0x90401000	Size: 1737984	File Visible: -	Signed: -
    Status: -
    
    Name: spldr.sys
    Image Path: C:\Windows\System32\Drivers\spldr.sys
    Address: 0x8AF54000	Size: 32768	File Visible: -	Signed: -
    Status: -
    
    Name: spsys.sys
    Image Path: C:\Windows\system32\drivers\spsys.sys
    Address: 0x88074000	Size: 716800	File Visible: -	Signed: -
    Status: -
    
    Name: srv.sys
    Image Path: C:\Windows\System32\DRIVERS\srv.sys
    Address: 0x9DC99000	Size: 311296	File Visible: -	Signed: -
    Status: -
    
    Name: srv2.sys
    Image Path: C:\Windows\System32\DRIVERS\srv2.sys
    Address: 0x9DC72000	Size: 159744	File Visible: -	Signed: -
    Status: -
    
    Name: srvnet.sys
    Image Path: C:\Windows\System32\DRIVERS\srvnet.sys
    Address: 0x8AFCD000	Size: 118784	File Visible: -	Signed: -
    Status: -
    
    Name: storport.sys
    Image Path: C:\Windows\system32\DRIVERS\storport.sys
    Address: 0x8AB72000	Size: 266240	File Visible: -	Signed: -
    Status: -
    
    Name: STREAM.SYS
    Image Path: C:\Windows\system32\DRIVERS\STREAM.SYS
    Address: 0x905AA000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: swenum.sys
    Image Path: C:\Windows\system32\DRIVERS\swenum.sys
    Address: 0x8F29F000	Size: 4992	File Visible: -	Signed: -
    Status: -
    
    Name: SynTP.sys
    Image Path: C:\Windows\system32\DRIVERS\SynTP.sys
    Address: 0x8AD3E000	Size: 175488	File Visible: -	Signed: -
    Status: -
    
    Name: tcpip.sys
    Image Path: C:\Windows\System32\drivers\tcpip.sys
    Address: 0x8AC0C000	Size: 954368	File Visible: -	Signed: -
    Status: -
    
    Name: tcpipreg.sys
    Image Path: C:\Windows\System32\drivers\tcpipreg.sys
    Address: 0x8AC00000	Size: 49152	File Visible: -	Signed: -
    Status: -
    
    Name: TDI.SYS
    Image Path: C:\Windows\system32\DRIVERS\TDI.SYS
    Address: 0x8FDD1000	Size: 45056	File Visible: -	Signed: -
    Status: -
    
    Name: tdx.sys
    Image Path: C:\Windows\system32\DRIVERS\tdx.sys
    Address: 0x9038D000	Size: 90112	File Visible: -	Signed: -
    Status: -
    
    Name: termdd.sys
    Image Path: C:\Windows\system32\DRIVERS\termdd.sys
    Address: 0x8F28F000	Size: 65536	File Visible: -	Signed: -
    Status: -
    
    Name: TSDDD.dll
    Image Path: C:\Windows\System32\TSDDD.dll
    Address: 0x980E0000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: tunmp.sys
    Image Path: C:\Windows\system32\DRIVERS\tunmp.sys
    Address: 0x8AE00000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: tunnel.sys
    Image Path: C:\Windows\system32\DRIVERS\tunnel.sys
    Address: 0x8AFED000	Size: 45056	File Visible: -	Signed: -
    Status: -
    
    Name: umbus.sys
    Image Path: C:\Windows\system32\DRIVERS\umbus.sys
    Address: 0x8F2D5000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: USBD.SYS
    Image Path: C:\Windows\system32\DRIVERS\USBD.SYS
    Address: 0x8AD69000	Size: 8192	File Visible: -	Signed: -
    Status: -
    
    Name: usbehci.sys
    Image Path: C:\Windows\system32\DRIVERS\usbehci.sys
    Address: 0x8ADC1000	Size: 61440	File Visible: -	Signed: -
    Status: -
    
    Name: usbhub.sys
    Image Path: C:\Windows\system32\DRIVERS\usbhub.sys
    Address: 0x8F2E2000	Size: 212992	File Visible: -	Signed: -
    Status: -
    
    Name: usbohci.sys
    Image Path: C:\Windows\system32\DRIVERS\usbohci.sys
    Address: 0x8AD79000	Size: 40960	File Visible: -	Signed: -
    Status: -
    
    Name: USBPORT.SYS
    Image Path: C:\Windows\system32\DRIVERS\USBPORT.SYS
    Address: 0x8AD83000	Size: 253952	File Visible: -	Signed: -
    Status: -
    
    Name: vga.sys
    Image Path: C:\Windows\System32\drivers\vga.sys
    Address: 0x90332000	Size: 49152	File Visible: -	Signed: -
    Status: -
    
    Name: VIDEOPRT.SYS
    Image Path: C:\Windows\system32\DRIVERS\VIDEOPRT.SYS
    Address: 0x8FD82000	Size: 135168	File Visible: -	Signed: -
    Status: -
    
    Name: volmgr.sys
    Image Path: C:\Windows\system32\drivers\volmgr.sys
    Address: 0x8069E000	Size: 61440	File Visible: -	Signed: -
    Status: -
    
    Name: volmgrx.sys
    Image Path: C:\Windows\System32\drivers\volmgrx.sys
    Address: 0x806AD000	Size: 303104	File Visible: -	Signed: -
    Status: -
    
    Name: volsnap.sys
    Image Path: C:\Windows\system32\drivers\volsnap.sys
    Address: 0x8AF1B000	Size: 233472	File Visible: -	Signed: -
    Status: -
    
    Name: wanarp.sys
    Image Path: C:\Windows\system32\DRIVERS\wanarp.sys
    Address: 0x8F3A2000	Size: 77824	File Visible: -	Signed: -
    Status: -
    
    Name: Wanarpv6
    Image Path: \Driver\Wanarpv6
    Address: 0x8F599000	Size: 77824	File Visible: No	Signed: -
    Status: Hidden from the Windows API!
    
    Name: watchdog.sys
    Image Path: C:\Windows\System32\drivers\watchdog.sys
    Address: 0x8FD70000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: Wdf01000.sys
    Image Path: C:\Windows\system32\drivers\Wdf01000.sys
    Address: 0x80547000	Size: 507904	File Visible: -	Signed: -
    Status: -
    
    Name: WDFLDR.SYS
    Image Path: C:\Windows\system32\drivers\WDFLDR.SYS
    Address: 0x805C3000	Size: 53248	File Visible: -	Signed: -
    Status: -
    
    Name: Win32k
    Image Path: \Driver\Win32k
    Address: 0x97EC0000	Size: 2105344	File Visible: -	Signed: -
    Status: -
    
    Name: win32k.sys
    Image Path: C:\Windows\System32\win32k.sys
    Address: 0x97EC0000	Size: 2105344	File Visible: -	Signed: -
    Status: -
    
    Name: WMILIB.SYS
    Image Path: C:\Windows\system32\drivers\WMILIB.SYS
    Address: 0x8064A000	Size: 36864	File Visible: -	Signed: -
    Status: -
    
    Name: WMIxWDM
    Image Path: \Driver\WMIxWDM
    Address: 0x82608000	Size: 3903488	File Visible: -	Signed: -
    Status: -
    
    Name: WUDFPf.sys
    Image Path: C:\Windows\system32\DRIVERS\WUDFPf.sys
    Address: 0xA1022000	Size: 73728	File Visible: -	Signed: -
    Status: -
    
    Name: WUDFRd.sys
    Image Path: C:\Windows\system32\DRIVERS\WUDFRd.sys
    Address: 0xA100D000	Size: 83328	File Visible: -	Signed: -
    Status: -
    Geändert von kira (14.01.2010 um 00:23 Uhr)

  10. #10
    Moderator Team-Mitglied Benutzerbild von kira
    Registriert seit
    28.03.2006
    Ort
    Wien/Sprachen: Deutsch-Ungarisch
    Beiträge
    25.767

    AW: Internet Explorer öffnet sich selbst

    na Ok, dann schauen wir mal weiter:
    Ich habe da das Rootkit entdeckt
    Da eine hundertprozentige Erkennung von Rootkits meist unmöglich ist, ist die beste Methode wäre zur Entfernung die komplette Neuinstallation.
    Falls Du dein System doch reinigen möchtest:

    1.
    Verwende das angehängte Zip als remove.txt-->auf deine Festplatte C:\ entpacken-->Wenn du den Text speicherst, sollte der Pfad C:\remove.txt sein
    ---------------------------------------
    Der remove.txt ist ausschliesslich auf dieses System bezogen.
    Niemand anderes sollte es verwenden.


    (kostenlose Zip-Tools)
    Lade den Avenger herunter und entzippe ihn auf den Desktop. Nicht gezippt direkt als EXE ist der Avenger hier erhältlich.

    Starte die avenger.exe durch Doppelklick und akzeptiere mit OK die Nutzungsbedingungen. Füge den Inhalt des Zip-Archivs C:\remove.txt vollständig und unverändert bei "Input script here" ein und klicke auf "Execute". Beantworte die Frage, ob Du sicher bist, dass das Skript ausgeführt werden soll mit "Ja".

    Beantworte die Frage zum Neustart des Rechners (Reboot now?) ebenfalls mit "Ja". Nachdem der Rechner neu gestartet ist (das kann auch zweimal nötig sein und passieren!) und das DOS-Fenster, das der Avenger geöffnet hat, wieder geschlossen ist, öffnet Avenger Deinen Editor mit dem Avengerlog, zu finden auch unter C:\avenger.txt. Den Inhalt bitte posten. Ein Backup der entfernten Objekte wurde als C:\avenger\backup.zip angelegt.

    2.
    poste erneut - nach der vorgenommenen Reinigungsaktion:
    Trend Micro HijackThis-Logfile - Keine offenen Fenster, solang bis HijackThis läuft!!
    hjtscanlist v2.0 - Dateiliste
    Geändert von kira (14.01.2010 um 22:03 Uhr)
    Neuaufsetzen (Windows XP, Vista und Windows 7) - Anleitungen
    Virenscanner
    Wie man seinen Rechner von Viren befreit

    *Der beste Schutz ist immer noch der verantwortungsvolle Umgang mit dem Internet!*

Seite 1 von 3 1 2 3 LetzteLetzte

Aktive Benutzer

Aktive Benutzer

Aktive Benutzer in diesem Thema: 1 (Registrierte Benutzer: 0, Gäste: 1)

     

Ähnliche Themen

  1. Antworten: 9
    Letzter Beitrag: 23.10.2009, 20:14
  2. Antworten: 5
    Letzter Beitrag: 14.12.2008, 08:34
  3. Antworten: 20
    Letzter Beitrag: 27.10.2007, 21:10
  4. Antworten: 5
    Letzter Beitrag: 30.10.2006, 23:36
  5. Antworten: 19
    Letzter Beitrag: 30.10.2006, 00:15

Forumregeln

  • Es ist Ihnen nicht erlaubt, neue Themen zu verfassen.
  • Es ist Ihnen nicht erlaubt, auf Beiträge zu antworten.
  • Es ist Ihnen nicht erlaubt, Anhänge hochzuladen.
  • Es ist Ihnen nicht erlaubt, Ihre Beiträge zu bearbeiten.