Jaa.... ein Backdoorprgramm hat Antivir auch schonmal gefunden... hab da eigentlich auf überschreiben und löschen geklickt... hat dann wohl nicht geklappt
Aber wie geht das denn über ftp?
Hab zwar nen FTP-Server, aber auf den bekomme ich keinen Zugriff mehr... mein Explorer will nicht mehr drauf zugreifen.
Regsearch:
Print Spool Handler:
REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "Print Spool Handler" 11.09.2005 10:34:57
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_PRINT_SPOOLER\0000]
"DeviceDesc"="Print Spool Handler"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Print Spooler]
"DisplayName"="Print Spool Handler"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PRINT_SPOOLER\0000]
"DeviceDesc"="Print Spool Handler"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Print Spooler]
"DisplayName"="Print Spool Handler"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PRINT_SPOOLER\0000]
"DeviceDesc"="Print Spool Handler"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Print Spooler]
"DisplayName"="Print Spool Handler"
Print Spooler:
REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "Print Spooler" 11.09.2005 10:35:52
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Network\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_PRINT_SPOOLER\0000]
"Service"="Print Spooler"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_PRINT_SPOOLER\0000\Control]
"ActiveService"="Print Spooler"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Print Spooler\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Print Spooler\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Minimal\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Network\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PRINT_SPOOLER\0000]
"Service"="Print Spooler"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Print Spooler\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PRINT_SPOOLER\0000]
"Service"="Print Spooler"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PRINT_SPOOLER\0000\Control]
"ActiveService"="Print Spooler"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Print Spooler\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Print Spooler\Enum]
Nach dem Neustart:
REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "Print Spool Handler" 11.09.2005 10:47:30
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_PRINT_SPOOLER\0000]
"DeviceDesc"="Print Spool Handler"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Print Spooler]
"DisplayName"="Print Spool Handler"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PRINT_SPOOLER\0000]
"DeviceDesc"="Print Spool Handler"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Print Spooler]
"DisplayName"="Print Spool Handler"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PRINT_SPOOLER\0000]
"DeviceDesc"="Print Spool Handler"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Print Spooler]
"DisplayName"="Print Spool Handler"
Print Spooler:
REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "Print Spooler" 11.09.2005 10:49:11
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Network\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_PRINT_SPOOLER\0000]
"Service"="Print Spooler"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Print Spooler\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Print Spooler\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Minimal\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Network\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PRINT_SPOOLER\0000]
"Service"="Print Spooler"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Print Spooler\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PRINT_SPOOLER\0000]
"Service"="Print Spooler"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Print Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Print Spooler\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Print Spooler\Enum]
Hoffe, dass das jetzt das richtige ist