Zurück   Trojaner-Board > Malware entfernen > Überwachung, Datenschutz und Spam

Überwachung, Datenschutz und Spam: Mail Account gehackt? Was ist tokenserver?

Windows 7 Fragen zu Verschlüsselung, Spam, Datenschutz & co. sind hier erwünscht. Hier geht es um Abwehr von Keyloggern oder aderen Spionagesoftware wie Spyware und Adware. Themen zum "Trojaner entfernen" oder "Malware Probleme" dürfen hier nur diskutiert werden. Benötigst du Hilfe beim Trojaner entfernen oder weil du dir einen Virus eingefangen hast, erstelle ein Thema in den oberen Bereinigungsforen.

Antwort
Alt 31.05.2012, 13:33   #16
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



Eine einfache Suche führt dich doch zum Ziel oder kennst du Google nicht?

Umgebungsvariablen in Windows
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 31.05.2012, 14:33   #17
ronze44
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



doch! Danke Arne, habs hingekriegt, ist natürlich ganz einfach, wenn mans weiß.

Habe Java nun drauf und habe danach den Temp Ordner wieder auf die RAM Disk gelegt. Dein Link führt zwar zu Erklärung, was Umgebungsvariablen sind, doch wie man sie wo umstellt, hätte ich auch dort nicht so schnell gefunden.

Fazit:
Mein Mail account wurde massiv, und ohne Java installiert zu haben, von Hackern angegriffen und ich muss davon ausgehen, dass sie es geschafft haben. Mein Pass ist nun mehrmals gewechselt worden, hat ca 20 Zeichen, und die Fehl-Logins werden weniger. Trotzdem ist ein weniger werden eigentlich ein Indiz für den Erfolg der Angreifer, und ich kann nie wissen, ob sie es geschafft haben oder nicht. Wenn jemand den starken Willen hat, anzugreifen, ist das immer was anderes als wenn er es nur mal so aus Spaß tut.
Ich muss davon ausgehen, dass alles erstmal ok ist, ohne wirklich einigermaßen sicher zu sein.
__________________


Alt 31.05.2012, 14:41   #18
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



Hast du jetzt eigentlich schon mit ESET gescannt?
__________________
__________________

Alt 31.05.2012, 15:43   #19
ronze44
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



Nein, bin noch gar nicht dazu gekommen. Also Firewall aus, AV aus, und los. Obwohl mir ESET als Programm auch vorliegt. Müsste nur mal neu starten.

Alt 31.05.2012, 15:44   #20
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



Windows-Firewall kann übrigens an bleiben, die hat noch nie gestört

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 31.05.2012, 18:07   #21
ronze44
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



versteh ich nicht warum ich das nicht schon gestern gemacht habe..7 Funde
Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internetesets_scanner_update returned -1 esets_gle=12
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=9e491272e9344749b5c9029923367a11
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-05-31 04:43:15
# local_time=2012-05-31 06:43:15 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 38533772 90107348 0 0
# compatibility_mode=8192 67108863 100 0 273 273 0 0
# scanned=216826
# found=7
# cleaned=0
# scan_time=6438
C:\Program Files\Yontoo\YontooIEClient.dll	a variant of Win32/Adware.Yontoo.A application (unable to clean)	00000000000000000000000000000000	I
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll	a variant of Win32/Adware.Yontoo.B application (unable to clean)	00000000000000000000000000000000	I
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll	a variant of Win32/Adware.Yontoo.B application (unable to clean)	00000000000000000000000000000000	I
C:\Users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll	a variant of Win32/Adware.Yontoo.B application (unable to clean)	00000000000000000000000000000000	I
C:\Users\All Users\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll	a variant of Win32/Adware.Yontoo.B application (unable to clean)	00000000000000000000000000000000	I
C:\Users\tobi\Downloads\fvdsuite_installer.exe	a variant of Win32/InstallCore.R application (unable to clean)	00000000000000000000000000000000	I
D:\Program Files\Native Instruments\Kontakt Player 2\KontaktPlayer2.exe	a variant of Win32/Packed.Themida application (unable to clean)	00000000000000000000000000000000	I
         

Alt 31.05.2012, 19:35   #22
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



Viel Adware-Schrott dabei, aber keine echten Fieslinge

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:
ATTFilter
 hier steht das Log
         
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Starte bitte die OTL.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Kopiere nun den kompletten Inhalt aus der untenstehenden Codebox in die Textbox von OTL - wenn OTL auf deutsch ist wird sie mit beschriftet
Code:
ATTFilter
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT
         
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Klick auf .
  • Kopiere nun den Inhalt aus OTL.txt hier in Deinen Thread
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 31.05.2012, 20:59   #23
ronze44
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



ok, hier. Diesen Yatoo Quatsch habe ich wohl heute mittag noch nicht drauf gehabt. Hab das auch noch nicht eliminiert, als der scan lief:
OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 31.05.2012 21:14:31 - Run 1
OTL by OldTimer - Version 3.2.44.0     Folder = C:\Users\tobi\Downloads
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,90 Gb Total Physical Memory | 1,63 Gb Available Physical Memory | 56,18% Memory free
5,80 Gb Paging File | 4,25 Gb Available in Paging File | 73,29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 110,94 Gb Total Space | 63,56 Gb Free Space | 57,29% Space Free | Partition Type: NTFS
Drive D: | 110,94 Gb Total Space | 85,68 Gb Free Space | 77,23% Space Free | Partition Type: NTFS
Drive T: | 1024,00 Mb Total Space | 847,42 Mb Free Space | 82,76% Space Free | Partition Type: NTFS
 
Computer Name: TOBI-PC | User Name: tobi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.05.31 21:00:45 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\tobi\Downloads\OTL.exe
PRC - [2012.05.09 20:08:16 | 006,592,000 | ---- | M] (Buyertools Ltd.) -- C:\Programme\Buyertools Reminder\Reminder.exe
PRC - [2012.03.26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\msseces.exe
PRC - [2012.03.26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\MsMpEng.exe
PRC - [2012.03.19 13:38:47 | 002,666,880 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2012.02.15 01:03:14 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Users\tobi\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2012.01.23 08:38:24 | 006,321,016 | ---- | M] (Wacom Technology, Corp.) -- C:\Programme\Tablet\Wacom\Wacom_Tablet.exe
PRC - [2012.01.23 08:38:24 | 003,591,544 | ---- | M] (Wacom Technology, Corp.) -- C:\Programme\Tablet\Wacom\Wacom_TouchUser.exe
PRC - [2012.01.23 08:38:24 | 001,609,080 | ---- | M] (Wacom Technology, Corp.) -- C:\Programme\Tablet\Wacom\Wacom_TabletUser.exe
PRC - [2012.01.23 08:38:24 | 000,470,904 | ---- | M] (Wacom Technology, Corp.) -- C:\Programme\Tablet\Wacom\Wacom_TouchService.exe
PRC - [2011.10.24 09:53:38 | 002,565,632 | ---- | M] (Deutsche Telekom AG) -- C:\Programme\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
PRC - [2011.10.07 11:40:42 | 001,387,288 | ---- | M] (Logitech, Inc.) -- C:\Programme\Logitech\SetPointP\SetPoint.exe
PRC - [2011.09.27 21:05:24 | 000,149,784 | ---- | M] (Logitech, Inc.) -- C:\Programme\Common Files\Logishrd\KHAL3\KHALMNPR.exe
PRC - [2011.08.02 09:33:30 | 004,910,912 | ---- | M] (DT Soft Ltd) -- C:\Programme\DAEMON Tools Lite\DTLite.exe
PRC - [2011.08.02 09:33:22 | 002,998,592 | ---- | M] (DT Soft Ltd) -- C:\Programme\DAEMON Tools Lite\DTShellHlp.exe
PRC - [2011.07.29 11:30:28 | 000,399,416 | ---- | M] (Secunia) -- C:\Programme\Secunia\PSI\sua.exe
PRC - [2011.03.28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011.02.12 07:43:02 | 000,660,576 | ---- | M] (Acronis) -- C:\Programme\Common Files\Acronis\Schedule2\schedul2.exe
PRC - [2011.02.12 07:40:50 | 000,365,632 | ---- | M] (Acronis) -- C:\Programme\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2011.01.02 21:29:50 | 000,009,216 | ---- | M] (www.shadowexplorer.com) -- C:\Programme\ShadowExplorer\sesvc.exe
PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.11.01 18:09:12 | 000,802,816 | ---- | M] (Sphinx Software) -- C:\Programme\Windows7FirewallControl\Windows7FirewallControl.exe
PRC - [2010.11.01 17:49:58 | 000,401,408 | ---- | M] (Sphinx Software) -- C:\Programme\Windows7FirewallControl\Windows7FirewallService.exe
PRC - [2010.10.12 10:04:20 | 004,142,448 | ---- | M] (Stardock) -- C:\Programme\Stardock\ObjectDockPlus2\ObjectDock.exe
PRC - [2010.10.04 16:02:00 | 000,249,856 | ---- | M] (troubadix) -- C:\Programme\ACFanControl\ACFanControl.exe
PRC - [2010.10.01 03:50:23 | 000,296,448 | ---- | M] (Microsoft) -- C:\Programme\Stardock\ObjectDockPlus2\ObjectDockTray.exe
PRC - [2010.07.09 16:43:15 | 000,016,016 | ---- | M] (Deutsche Telekom AG) -- C:\Programme\Telekom\Mediencenter\WebDAV.AdminService.exe
PRC - [2009.11.12 14:48:56 | 000,071,096 | ---- | M] () -- C:\Programme\CDBurnerXP\NMSAccessU.exe
PRC - [2009.07.14 03:14:42 | 000,181,760 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\ink\TabTip.exe
PRC - [2009.06.07 14:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\System32\NlsSrv32.exe
PRC - [2009.05.20 11:58:44 | 000,180,224 | ---- | M] (Ours Technology Inc.) -- C:\Programme\GO! Suite\Deployment\Functions\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\OMEA.exe
PRC - [2009.04.30 11:23:26 | 000,090,112 | ---- | M] () -- C:\Programme\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
PRC - [2007.12.03 12:26:02 | 000,498,792 | ---- | M] () -- C:\Programme\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
PRC - [2006.11.02 20:40:12 | 000,174,656 | ---- | M] () -- C:\Windows\System32\PSIService.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.05.11 03:46:28 | 000,440,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\RenderPanel\206be09306fe0ee06ea4c5fe608e4a7f\RenderPanel.ni.dll
MOD - [2012.05.11 03:46:26 | 000,440,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\ObjectDockTray\6f287cf521ace0f172b00bcdc8652c44\ObjectDockTray.ni.exe
MOD - [2012.05.11 03:32:55 | 012,433,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\90555968565afd59bce4b0974e9903bd\System.Windows.Forms.ni.dll
MOD - [2012.05.11 03:32:46 | 001,590,784 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\69f6e582cb79f107c61308b468c1a215\System.Drawing.ni.dll
MOD - [2012.05.11 03:32:23 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012.05.11 03:32:19 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012.05.11 03:32:18 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012.05.11 03:32:09 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2012.01.23 08:38:24 | 000,963,448 | ---- | M] () -- C:\Programme\Tablet\Wacom\libxml2.dll
MOD - [2012.01.08 15:41:12 | 000,093,696 | ---- | M] () -- C:\Programme\FileZilla\FileZilla FTP Client\fzshellext.dll
MOD - [2011.10.07 11:41:16 | 000,879,896 | ---- | M] () -- C:\Programme\Logitech\SetPointP\Macros\MacroCore.dll
MOD - [2010.11.13 01:19:04 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.10.06 17:55:44 | 000,091,544 | ---- | M] () -- C:\Programme\Stardock\ObjectDockPlus2\Docklets\Calendar\Calendar.dll
MOD - [2010.10.01 03:50:23 | 000,675,840 | ---- | M] () -- C:\Programme\Stardock\ObjectDockPlus2\DockShellHook.dll
MOD - [2010.03.09 23:58:30 | 000,807,936 | ---- | M] () -- C:\Programme\Stardock\ObjectDockPlus2\CrashRpt.dll
MOD - [2010.03.09 23:58:30 | 000,053,760 | ---- | M] () -- C:\Programme\Stardock\ObjectDockPlus2\zlib.dll
MOD - [2006.05.31 16:47:42 | 000,684,032 | ---- | M] () -- C:\Programme\Buyertools Reminder\libeay32.dll
MOD - [2006.05.31 16:47:42 | 000,626,688 | ---- | M] () -- C:\Programme\Buyertools Reminder\ex_parser.dll
MOD - [2006.05.31 16:47:42 | 000,155,648 | ---- | M] () -- C:\Programme\Buyertools Reminder\ssleay32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012.05.04 19:53:14 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.04.25 02:30:41 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.03.26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012.03.26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012.03.19 13:38:47 | 002,666,880 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012.01.23 08:38:24 | 006,321,016 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Programme\Tablet\Wacom\Wacom_Tablet.exe -- (TabletServiceWacom)
SRV - [2012.01.23 08:38:24 | 000,470,904 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Programme\Tablet\Wacom\Wacom_TouchService.exe -- (TouchServiceWacom)
SRV - [2011.12.22 14:20:01 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011.10.24 09:53:38 | 002,565,632 | ---- | M] (Deutsche Telekom AG) [Auto | Running] -- C:\Programme\Netzmanager\NMInfraIS2\Netzmanager_Service.exe -- (Netzmanager Service)
SRV - [2011.09.27 21:03:28 | 000,295,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2011.07.29 11:30:30 | 000,994,360 | ---- | M] (Secunia) [On_Demand | Stopped] -- C:\Programme\Secunia\PSI\psia.exe -- (Secunia PSI Agent)
SRV - [2011.07.29 11:30:28 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Programme\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2011.02.12 07:43:02 | 000,660,576 | ---- | M] (Acronis) [Auto | Running] -- C:\Programme\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2011.01.02 21:29:50 | 000,009,216 | ---- | M] (www.shadowexplorer.com) [Auto | Running] -- C:\Programme\ShadowExplorer\sesvc.exe -- (sesvc)
SRV - [2010.11.20 14:21:36 | 000,351,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2010.11.20 14:19:33 | 000,068,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\Mcx2Svc.dll -- (Mcx2Svc)
SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2010.11.01 17:49:58 | 000,401,408 | ---- | M] (Sphinx Software) [Auto | Running] -- C:\Programme\Windows7FirewallControl\Windows7FirewallService.exe -- (Windows7FirewallService)
SRV - [2010.09.22 17:33:04 | 000,051,040 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010.07.09 16:43:15 | 000,016,016 | ---- | M] (Deutsche Telekom AG) [Auto | Running] -- C:\Programme\Telekom\Mediencenter\WebDAV.AdminService.exe -- (MCSWASVR)
SRV - [2010.06.08 21:23:01 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010.03.18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2010.03.18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpActivator)
SRV - [2010.03.18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetPipeActivator)
SRV - [2010.03.18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetMsmqActivator)
SRV - [2009.11.12 14:48:56 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Programme\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
SRV - [2009.07.14 03:16:18 | 000,065,024 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\wersvc.dll -- (WerSvc)
SRV - [2009.07.14 03:16:17 | 000,266,752 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\upnphost.dll -- (upnphost)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.07.14 03:15:41 | 000,075,264 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\mprdim.dll -- (RemoteAccess)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.06.07 14:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\Windows\System32\NlsSrv32.exe -- (nlsX86cc)
SRV - [2009.04.30 11:23:26 | 000,090,112 | ---- | M] () [Auto | Running] -- C:\Programme\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe -- (OMSI download service)
SRV - [2007.12.03 12:26:02 | 000,498,792 | ---- | M] () [Auto | Running] -- C:\Programme\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe -- (TryAndDecideService)
SRV - [2006.11.02 20:40:12 | 000,174,656 | ---- | M] () [Auto | Running] -- C:\Windows\System32\PSIService.exe -- (ProtexisLicensing)
SRV - [2003.07.28 20:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\WacomVKHid.sys -- (WacomVKHid)
DRV - File not found [Kernel | Auto | Stopped] -- C:\Windows\system32\Drivers\DgiVecp.sys -- (DgiVecp)
DRV - File not found [Kernel | On_Demand | Stopped] -- T:\TEMP\catchme.sys -- (catchme)
DRV - [2012.04.10 12:19:52 | 000,441,760 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\timntr.sys -- (timounter)
DRV - [2012.04.10 12:19:52 | 000,044,384 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\Windows\System32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2012.04.10 12:19:50 | 000,132,224 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\snapman.sys -- (snapman)
DRV - [2012.03.20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011.11.14 10:29:54 | 000,010,752 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV - [2011.10.27 12:59:37 | 000,232,512 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011.09.02 08:31:28 | 000,039,192 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2011.09.02 08:31:20 | 000,041,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2011.07.29 14:54:56 | 000,014,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\epmntdrv.sys -- (epmntdrv)
DRV - [2011.07.29 14:54:56 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2011.07.20 02:54:06 | 000,047,104 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\iBtFltCoex.sys -- (iBtFltCoex)
DRV - [2011.07.19 23:12:22 | 000,225,280 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btmhsf.sys -- (btmhsf)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.09.16 17:02:33 | 000,035,040 | ---- | M] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) [Kernel | On_Demand | Stopped] -- C:\Programme\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys -- (TelekomNM3)
DRV - [2010.09.15 11:03:02 | 000,011,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV - [2010.09.15 11:02:58 | 000,014,120 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wacomvhid.sys -- (wacomvhid)
DRV - [2010.09.05 15:04:09 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2010.09.05 15:04:09 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt)
DRV - [2010.09.01 10:30:58 | 000,015,544 | ---- | M] (Secunia) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\psi_mf.sys -- (PSI)
DRV - [2010.08.17 13:35:36 | 000,782,840 | ---- | M] (TerraTec Electronic GmbH.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TerraTecUsbBda.sys -- (UDST7000BDA)
DRV - [2010.08.04 13:14:14 | 000,022,136 | ---- | M] (TerraTec Electronic GmbH.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TerraTecUsbHid.sys -- (UDST7000HID)
DRV - [2010.05.15 16:55:14 | 000,265,800 | ---- | M] (EldoS Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\cbfs3.sys -- (cbfs3)
DRV - [2010.01.18 09:55:08 | 000,585,920 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\emBDA.sys -- (USB28xxBGA)
DRV - [2010.01.18 09:55:08 | 000,549,952 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\emOEM.sys -- (USB28xxOEM)
DRV - [2009.12.09 01:07:58 | 000,132,544 | ---- | M] (Echo Digital Audio Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\echondgo.sys -- (echondgo)
DRV - [2009.12.09 01:07:58 | 000,132,544 | ---- | M] (Echo Digital Audio Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\echondgo.sys -- (EchoIndigo)
DRV - [2009.11.12 14:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009.10.05 16:31:50 | 001,221,632 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009.07.14 03:20:28 | 000,022,096 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\crcdisk.sys -- (crcdisk)
DRV - [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ws2ifsl.sys -- (ws2ifsl)
DRV - [2009.07.14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009.04.30 23:07:15 | 000,012,288 | ---- | M] (gavotte) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\rramdisk.sys -- (RRamdisk)
DRV - [2008.10.21 09:22:48 | 000,114,600 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017mdm.sys -- (s0017mdm)
DRV - [2008.10.21 09:22:48 | 000,109,736 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017unic.sys -- (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM)
DRV - [2008.10.21 09:22:48 | 000,108,328 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017mgmt.sys -- (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM)
DRV - [2008.10.21 09:22:48 | 000,104,616 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017obex.sys -- (s0017obex)
DRV - [2008.10.21 09:22:48 | 000,086,824 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017bus.sys -- (s0017bus) Sony Ericsson Device 0017 driver (WDM)
DRV - [2008.10.21 09:22:48 | 000,026,024 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017nd5.sys -- (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS)
DRV - [2008.10.21 09:22:48 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017mdfl.sys -- (s0017mdfl)
DRV - [2008.01.09 12:28:34 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\seehcri.sys -- (seehcri)
DRV - [2007.11.30 02:46:52 | 000,005,120 | ---- | M] (Samsung Electronics) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\SSPORT.SYS -- (SSPORT)
DRV - [2007.11.02 15:22:38 | 000,105,896 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217unic.sys -- (s217unic) Sony Ericsson Device 217 USB Ethernet Emulation SEMC217 (WDM)
DRV - [2007.11.02 15:22:38 | 000,103,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217mgmt.sys -- (s217mgmt) Sony Ericsson Device 217 USB WMC Device Management Drivers (WDM)
DRV - [2007.11.02 15:22:38 | 000,100,008 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217obex.sys -- (s217obex)
DRV - [2007.11.02 15:22:38 | 000,024,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217nd5.sys -- (s217nd5) Sony Ericsson Device 217 USB Ethernet Emulation SEMC217 (NDIS)
DRV - [2007.11.02 15:22:36 | 000,109,992 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217mdm.sys -- (s217mdm)
DRV - [2007.11.02 15:22:36 | 000,083,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217bus.sys -- (s217bus) Sony Ericsson Device 217 driver (WDM)
DRV - [2007.11.02 15:22:36 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217mdfl.sys -- (s217mdfl)
DRV - [2007.10.24 12:47:26 | 000,023,288 | ---- | M] (SIA Syncrosoft) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\synasUSB.sys -- (SynasUSB)
DRV - [2006.10.13 03:21:00 | 000,020,512 | ---- | M] (EnTech Taiwan) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\TVicPort.sys -- (TVicPort)
DRV - [2002.07.17 09:53:02 | 000,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ASPI32.SYS -- (Aspi32)
DRV - [2001.04.09 13:45:00 | 000,008,138 | ---- | M] (Wacom Technology Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\PenClass.sys -- (PenClass)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/
IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 39 48 C5 2F 76 F2 CA 01  [binary data]
IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\..\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}: "URL" = hxxp://www.crawler.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=60446
IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "hxxp://www.bing.com/search?FORM=IEFM1&q="
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://google.de"
FF - prefs.js..extensions.enabledItems: {411F2F11-830F-4AB5-B7F0-FBC77B870B5A}:1.0.6.1
FF - prefs.js..extensions.enabledItems: de-DE@dictionaries.addons.mozilla.org:2.0.2
FF - prefs.js..extensions.enabledItems: dictlookup@arnhold.com:0.0.4
FF - prefs.js..extensions.enabledItems: dictionary-switcher@design-noir.de:1.3.1
FF - prefs.js..extensions.enabledItems: {53A03D43-5363-4669-8190-99061B2DEBA5}:1.4.7
FF - prefs.js..extensions.enabledItems: {EF522540-89F5-46b9-B6FE-1829E2B572C6}:5.0.9
FF - prefs.js..extensions.enabledItems: en-US@dictionaries.addons.mozilla.org:5.0.1
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110704
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: foxmarks@kei.com:4.0.2
FF - prefs.js..extensions.enabledItems: VacuumPlacesImproved@lultimouomo-gmail.com:1.2
FF - prefs.js..extensions.enabledItems: smarterwiki@wikiatic.com:4.6.4
FF - prefs.js..extensions.enabledItems: lazarus@interclue.com:2.3
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.2
FF - prefs.js..extensions.enabledItems: FasterFox_Lite@BigRedBrent:3.9.1Lite
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {37fa1426-b82d-11db-8314-0800200c9a66}:2.8
FF - prefs.js..extensions.enabledItems: {ca0849e8-2c76-42ae-9abe-34e14d337acf}:1.96
FF - prefs.js..keyword.URL: "hxxp://go.gmx.net/tb/mff_keyurl_search/?su="
FF - prefs.js..network.proxy.type: 0
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.10: C:\Program Files\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.0.0.4: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\tobi\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll File not found
FF - HKCU\Software\MozillaPlugins\@sun.com/npsopluginmi;version=1.0: C:\Program Files\OpenOffice.org 3\program [2011.02.02 17:57:34 | 000,000,000 | ---D | M]
FF - HKCU\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.04.25 02:30:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.05.31 14:37:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010.12.14 21:30:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
 
[2009.12.29 12:37:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\tobi\AppData\Roaming\mozilla\Extensions
[2009.12.29 12:37:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\tobi\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.05.21 01:43:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions
[2012.05.02 00:12:11 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2012.03.06 13:52:52 | 000,000,000 | ---D | M] (Buyertools) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A}
[2012.05.08 23:57:41 | 000,000,000 | ---D | M] ("FVD Suite Addon") -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{9051303c-7e41-4311-a783-d6fe5ef2832d}
[2012.05.21 01:43:08 | 000,000,000 | ---D | M] (WOT) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2012.02.04 21:29:11 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010.09.24 23:26:49 | 000,000,000 | ---D | M] (Password Exporter) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2011.11.05 03:36:19 | 000,000,000 | ---D | M] ("BabelFish") -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{ca0849e8-2c76-42ae-9abe-34e14d337acf}
[2010.11.18 20:34:48 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2012.02.22 19:53:37 | 000,000,000 | ---D | M] (Dictionary Switcher) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\dictionary-switcher@design-noir.de
[2009.11.16 01:39:21 | 000,000,000 | ---D | M] (Dictionary (EN/DE)) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\dictlookup@arnhold.com
[2010.12.22 13:09:18 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\en-GB@dictionaries.addons.mozilla.org
[2012.05.21 01:43:08 | 000,000,000 | ---D | M] (United States English Spellchecker) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\en-US@dictionaries.addons.mozilla.org
[2012.05.02 00:12:09 | 000,000,000 | ---D | M] (Fasterfox Lite) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\FasterFox_Lite@BigRedBrent
[2012.03.13 10:45:08 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\foxmarks@kei.com
[2012.05.21 01:43:08 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\ich@maltegoetz.de
[2011.10.18 11:15:29 | 000,000,000 | ---D | M] (Lazarus: Form Recovery) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\lazarus@interclue.com
[2011.03.12 03:57:47 | 000,000,000 | ---D | M] (Personas) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\personas@christopher.beard
[2012.05.08 23:07:42 | 000,000,000 | ---D | M] (Yontoo) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\plugin@yontoo.com
[2012.04.11 14:08:34 | 000,000,000 | ---D | M] (loadtbs) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\software@loadtubes.com
[2011.01.16 00:47:46 | 000,000,000 | ---D | M] (Vacuum Places Improved) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\VacuumPlacesImproved@lultimouomo-gmail.com
[2012.04.10 02:42:43 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2009.11.27 17:15:59 | 000,000,000 | ---D | M] (Buyertools) -- C:\Programme\Mozilla Firefox\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A}
[2011.01.09 15:28:15 | 000,000,000 | ---D | M] (Skype extension) -- C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2012.04.18 12:00:26 | 000,193,744 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\{37FA1426-B82D-11DB-8314-0800200C9A66}.XPI
[2012.04.05 00:52:59 | 000,399,561 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\{53A03D43-5363-4669-8190-99061B2DEBA5}.XPI
[2012.01.08 15:20:19 | 000,634,964 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012.03.09 00:42:38 | 000,138,614 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI
[2012.05.21 01:43:08 | 000,045,066 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\{EF522540-89F5-46B9-B6FE-1829E2B572C6}.XPI
[2012.05.11 03:50:11 | 000,185,022 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\ARTUR.DUBOVOY@GMAIL.COM.XPI
[2012.02.22 19:53:37 | 000,322,566 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\SMARTERWIKI@WIKIATIC.COM.XPI
[2012.04.25 02:30:41 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.04.11 14:08:19 | 000,378,880 | ---- | M] (InfiniAd GmbH) -- C:\Program Files\mozilla firefox\plugins\npmieze.dll
[2012.04.10 02:42:36 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.04.10 02:42:36 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2007.07.26 13:05:16 | 000,001,329 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\crawlersrch.xml
[2012.04.10 02:42:36 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.04.10 02:42:36 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.04.10 02:42:36 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.04.10 02:42:36 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin:  Wacom Dynamic Link Library (Enabled) = C:\Program Files\TabletPlugins\npwacom.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
 
O1 HOSTS File: ([2011.12.22 14:33:10 | 000,612,639 | ---- | M]) - C:\Windows\System32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1  localhost
O1 - Hosts: ::1  localhost #[IPv6]
O1 - Hosts: 127.0.0.1  fr.a2dfp.net
O1 - Hosts: 127.0.0.1  m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1  ad.a8.net
O1 - Hosts: 127.0.0.1  asy.a8ww.net
O1 - Hosts: 127.0.0.1  abcstats.com
O1 - Hosts: 127.0.0.1  a.abv.bg
O1 - Hosts: 127.0.0.1  adserver.abv.bg
O1 - Hosts: 127.0.0.1  adv.abv.bg
O1 - Hosts: 127.0.0.1  bimg.abv.bg
O1 - Hosts: 127.0.0.1  ca.abv.bg
O1 - Hosts: 127.0.0.1  www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1  track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1  accuserveadsystem.com
O1 - Hosts: 127.0.0.1  www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1  achmedia.com
O1 - Hosts: 127.0.0.1  aconti.net
O1 - Hosts: 127.0.0.1  secure.aconti.net
O1 - Hosts: 127.0.0.1  www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1  am1.activemeter.com
O1 - Hosts: 127.0.0.1  www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1  ads.activepower.net
O1 - Hosts: 127.0.0.1  stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1  ad2games.com
O1 - Hosts: 16291 more lines...
O2 - BHO: (Open FVD Suite Toolbar) - {2B171655-A69C-5c18-B693-6CB5DC269D44} - C:\Programme\FVD Suite\addons\IE\FVDToolbar.dll (www.flashvideodownloader.org/fvd-suite/)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Buyertools) - {7C7A8947-5935-4430-AC0E-E7D04697414E} - C:\Programme\Buyertools Reminder\IEButtonBuyertoolsInterface.dll ()
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Programme\Yontoo\YontooIEClient.dll (Yontoo LLC)
O3 - HKLM\..\Toolbar: (FVD Suite Toolbar) - {2B171655-A69C-5c18-B693-6CB5DC269D41} - C:\Programme\FVD Suite\addons\IE\FVDToolbar.dll (www.flashvideodownloader.org/fvd-suite/)
O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Programme\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH)
O3 - HKLM\..\Toolbar: (loadtbs) - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - C:\Users\tobi\AppData\Roaming\loadtbs\toolbar.dll (InfiniAd GmbH)
O4 - HKLM..\Run: [ACFanControl] C:\Programme\ACFanControl\ACFanControl.exe (troubadix)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [emsisoftantimalwaresetup] T:\TEMP\EmsisoftAntiMalwareSetup.exe (Emsisoft GmbH                                               )
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OMEA] C:\Programme\GO! Suite\Deployment\Functions\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\OMEA.exe (Ours Technology Inc.)
O4 - HKLM..\Run: [Windows7FirewallControl] C:\Programme\Windows7FirewallControl\Windows7FirewallControl.exe (Sphinx Software)
O4 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000..\Run: [Buyertools Reminder] C:\Program Files\Buyertools Reminder\Reminder.exe (Buyertools Ltd.)
O4 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKLM..\RunOnce: [InnoSetupRegFile.0000000001] C:\Windows\is-5KESA.exe ()
O4 - HKLM..\RunOnce: [ Malwarebytes Anti-Malware ] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Surfer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk = C:\Programme\Netzmanager\netzmanager.exe (Deutsche Telekom AG)
O4 - Startup: C:\Users\Surfer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Programme\Stardock\ObjectDockPlus2\ObjectDock.exe (Stardock)
O4 - Startup: C:\Users\tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\tobi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Programme\Stardock\ObjectDockPlus2\ObjectDock.exe (Stardock)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O7 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube Download - C:\Users\tobi\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\tobi\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Buyertools Reminder - {27914077-B4D6-4A0E-9763-76B6E9DD9A81} - C:\Programme\Buyertools Reminder\ReminderIE.exe ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O15 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\..Trusted Domains: tobi-lieblein.de ([]https in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{75985961-485B-4110-AC04-A74F011B2709}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Programme\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O22 - SharedTaskScheduler: {1984D045-52CF-49cd-DB77-08F378FEA4DB} - ObjectDockShellExt - C:\Programme\Stardock\ObjectDockPlus2\ODMenu.dll (Stardock)
O22 - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Programme\Stardock\Fences\FencesMenu.dll (Stardock)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (relog_ap) - C:\Windows\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\...com [@ = ComFile] -- Reg Error: Key error. File not found
O37 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\...exe [@ = exefile] -- Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TabUserW.exe.lnk -  - File not found
MsConfig - StartUpFolder: C:^Users^tobi^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Impulse Now.lnk -  - File not found
MsConfig - StartUpReg: Acer ePower Management - hkey= - key= - C:\Programme\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe (Acer Incorporated)
MsConfig - StartUpReg: Acronis Scheduler2 Service - hkey= - key= - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
MsConfig - StartUpReg: AcronisTimounterMonitor - hkey= - key= - C:\Programme\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
MsConfig - StartUpReg: Adobe ARM - hkey= - key= -  File not found
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= -  File not found
MsConfig - StartUpReg: Check Mail - hkey= - key= - C:\Programme\CheckMail V2\CK_Mail.exe (Sebastian Lehn)
MsConfig - StartUpReg: Koma-Mail - hkey= - key= - C:\Programme\KomaMail\Koma_Mail.exe ()
MsConfig - StartUpReg: LManager - hkey= - key= - C:\Programme\Launch Manager\LManager.EXE (Dritek System Inc.)
MsConfig - StartUpReg: MouseExtender - hkey= - key= - C:\Users\tobi\Desktop\MouseExtender.1.9.7.2\MouseExtender.exe ()
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
MsConfig - StartUpReg: Rainlendar2 - hkey= - key= - C:\Programme\Rainlendar2\Rainlendar2.exe ()
MsConfig - StartUpReg: Samsung PanelMgr - hkey= - key= - C:\Windows\Samsung\PanelMgr\ssmmgr.exe ()
MsConfig - StartUpReg: Sony Ericsson PC Suite - hkey= - key= - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig - StartUpReg: Switcher - hkey= - key= - C:\Program Files\Switcher\Switcher.exe (Bao_Nguyen)
MsConfig - StartUpReg: TrueImageMonitor.exe - hkey= - key= - C:\Programme\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
MsConfig - State: "startup" - 2
MsConfig - State: "bootini" - 2
 
SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MsMpSvc - C:\Programme\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: MsMpSvc - C:\Programme\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {1100659A-EB8D-C792-BFB0-2B854E215CC9} - Microsoft Windows Media Player
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\System32\Microsoft
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - C:\Windows\System32\Microsoft
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: aux - wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux2 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux3 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux4 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux5 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux6 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux7 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi - wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - wdmaud.drv (Microsoft Corporation)
Drivers32: MIDI3 - timiditydrv.dll ()
Drivers32: midi4 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi5 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi6 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi7 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi8 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi9 - wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - midimap.dll (Microsoft Corporation)
Drivers32: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer3 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer4 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer5 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer6 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer7 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer8 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer9 - wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
Drivers32: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
Drivers32: wave - wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave3 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave4 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave5 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave6 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave7 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave8 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave9 - wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - msacm32.drv (Microsoft Corporation)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.05.31 16:51:24 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.05.31 14:37:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012.05.31 14:33:46 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Installer Clean Up
[2012.05.29 20:04:05 | 000,000,000 | ---D | C] -- C:\Users\tobi\AppData\Local\{56015ACB-9C51-4DFB-8DF8-77F23DF4FEFB}
[2012.05.21 10:50:06 | 000,000,000 | ---D | C] -- C:\Users\tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gitarrero Notenmeister
[2012.05.21 10:50:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gitarrero Notenmeister
[2012.05.21 10:50:02 | 000,000,000 | ---D | C] -- C:\Program Files\Gitarrero Software
[2012.05.15 01:20:43 | 000,000,000 | ---D | C] -- C:\Users\tobi\Documents\Updater
[2012.05.08 23:08:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FVD Suite
[2012.05.08 23:07:40 | 000,000,000 | ---D | C] -- C:\Program Files\Yontoo
[2012.05.08 23:07:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer
[2012.05.01 22:59:55 | 000,000,000 | ---D | C] -- C:\Users\tobi\AppData\Roaming\Amazon
[2012.05.01 22:54:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon
[2012.05.01 22:54:30 | 000,000,000 | ---D | C] -- C:\Program Files\Amazon
 
========== Files - Modified Within 30 Days ==========
 
[2012.05.31 21:13:00 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.05.31 20:53:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.05.31 16:36:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.05.31 14:44:38 | 000,023,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.05.31 14:44:38 | 000,023,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.05.31 10:52:07 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.05.30 17:02:49 | 000,001,422 | ---- | M] () -- C:\Users\tobi\Desktop\mbam - Verknüpfung.lnk
[2012.05.29 20:47:11 | 000,711,240 | ---- | M] () -- C:\Windows\is-5KESA.exe
[2012.05.29 20:47:11 | 000,012,782 | ---- | M] () -- C:\Windows\is-5KESA.msg
[2012.05.29 20:47:11 | 000,000,441 | ---- | M] () -- C:\Windows\is-5KESA.lst
[2012.05.24 23:28:38 | 000,817,674 | ---- | M] () -- C:\Users\tobi\Documents\POD 2.0 Advanced Guide - German.pdf
[2012.05.24 22:30:06 | 000,364,498 | ---- | M] () -- C:\Users\tobi\Documents\Install_ReWire_1_7_Win.zip
[2012.05.24 22:29:10 | 000,376,525 | ---- | M] () -- C:\Users\tobi\Documents\Cubase_5_Groove_Templates_SX3C4.cpr
[2012.05.24 22:28:04 | 003,037,523 | ---- | M] () -- C:\Users\tobi\Documents\Virtual_Guitarist_2_User_Manual.pdf
[2012.05.24 22:27:35 | 002,597,016 | ---- | M] () -- C:\Users\tobi\Documents\Hypersonic_User_Manual.pdf
[2012.05.24 22:26:45 | 004,581,933 | ---- | M] () -- C:\Users\tobi\Documents\GrooveAgent_Manual.pdf
[2012.05.24 09:17:22 | 000,002,290 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.05.21 14:02:23 | 000,698,470 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.05.21 14:02:23 | 000,653,748 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.05.21 14:02:23 | 000,148,634 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.05.21 14:02:23 | 000,121,580 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.05.21 10:50:06 | 000,001,102 | ---- | M] () -- C:\Users\tobi\Desktop\Gitarrero Notenmeister.lnk
[2012.05.18 12:28:35 | 000,000,016 | ---- | M] () -- C:\Windows\System32\w3data.vss
[2012.05.18 12:28:35 | 000,000,016 | ---- | M] () -- C:\Windows\System32\msvcsv60.dll
[2012.05.18 12:28:35 | 000,000,016 | ---- | M] () -- C:\Windows\msocreg32.dat
[2012.05.17 13:36:37 | 002,228,096 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.05.17 13:36:14 | 2337,955,840 | -HS- | M] () -- C:\hiberfil.sys
[2012.05.16 12:43:54 | 000,097,984 | ---- | M] () -- C:\Users\tobi\Documents\MUS_LA-Sammlung.rtf
[2012.05.12 12:13:05 | 000,109,047 | ---- | M] () -- C:\Users\tobi\Documents\DeutschlandSIM Daten.pdf
[2012.05.10 02:14:37 | 000,018,734 | ---- | M] () -- C:\Users\tobi\Documents\indriz2.odt
[2012.05.08 23:08:56 | 000,001,979 | ---- | M] () -- C:\Users\Public\Desktop\FVD Player.lnk
[2012.05.08 23:08:56 | 000,001,864 | ---- | M] () -- C:\Users\Public\Desktop\FVD Suite.lnk
[2012.05.07 20:22:10 | 000,001,124 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012.05.03 11:54:15 | 000,002,883 | ---- | M] () -- C:\Users\tobi\Documents\Electro Harmonix V256 Tips.rtf
[2012.05.02 13:57:40 | 000,005,152 | ---- | M] () -- C:\Users\tobi\Documents\Indriz-Zeitung.rtf
 
========== Files Created - No Company Name ==========
 
[2012.05.31 14:33:46 | 000,002,849 | ---- | C] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Install Clean Up.lnk
[2012.05.30 17:02:49 | 000,001,422 | ---- | C] () -- C:\Users\tobi\Desktop\mbam - Verknüpfung.lnk
[2012.05.29 20:47:11 | 000,711,240 | ---- | C] () -- C:\Windows\is-5KESA.exe
[2012.05.29 20:47:11 | 000,012,782 | ---- | C] () -- C:\Windows\is-5KESA.msg
[2012.05.29 20:47:11 | 000,000,441 | ---- | C] () -- C:\Windows\is-5KESA.lst
[2012.05.24 23:28:43 | 000,817,674 | ---- | C] () -- C:\Users\tobi\Documents\POD 2.0 Advanced Guide - German.pdf
[2012.05.24 22:30:03 | 000,364,498 | ---- | C] () -- C:\Users\tobi\Documents\Install_ReWire_1_7_Win.zip
[2012.05.24 22:29:09 | 000,376,525 | ---- | C] () -- C:\Users\tobi\Documents\Cubase_5_Groove_Templates_SX3C4.cpr
[2012.05.24 22:27:59 | 003,037,523 | ---- | C] () -- C:\Users\tobi\Documents\Virtual_Guitarist_2_User_Manual.pdf
[2012.05.24 22:27:32 | 002,597,016 | ---- | C] () -- C:\Users\tobi\Documents\Hypersonic_User_Manual.pdf
[2012.05.24 22:26:37 | 004,581,933 | ---- | C] () -- C:\Users\tobi\Documents\GrooveAgent_Manual.pdf
[2012.05.21 10:50:06 | 000,001,102 | ---- | C] () -- C:\Users\tobi\Desktop\Gitarrero Notenmeister.lnk
[2012.05.12 12:13:10 | 000,109,047 | ---- | C] () -- C:\Users\tobi\Documents\DeutschlandSIM Daten.pdf
[2012.05.08 23:08:56 | 000,001,979 | ---- | C] () -- C:\Users\Public\Desktop\FVD Player.lnk
[2012.05.08 23:08:56 | 000,001,864 | ---- | C] () -- C:\Users\Public\Desktop\FVD Suite.lnk
[2012.05.07 20:22:10 | 000,001,136 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012.05.07 20:22:10 | 000,001,124 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012.05.07 03:24:09 | 000,018,734 | ---- | C] () -- C:\Users\tobi\Documents\indriz2.odt
[2012.05.03 01:29:25 | 000,002,883 | ---- | C] () -- C:\Users\tobi\Documents\Electro Harmonix V256 Tips.rtf
[2012.04.14 14:12:17 | 000,000,952 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys
[2012.04.14 14:12:17 | 000,000,008 | RHS- | C] () -- C:\Windows\System32\00285B196A.sys
[2012.04.14 01:41:25 | 000,000,000 | ---- | C] () -- C:\Windows\ARTSTU~1.INI
[2012.04.11 14:09:13 | 000,000,001 | ---- | C] () -- C:\Users\tobi\AppData\Local\llftool.4.12.agreement
[2012.02.26 00:01:56 | 000,000,016 | ---- | C] () -- C:\Windows\System32\msvcsv60.dll
[2012.02.26 00:01:56 | 000,000,016 | ---- | C] () -- C:\Windows\msocreg32.dat
[2011.10.30 13:37:01 | 002,469,760 | ---- | C] () -- C:\Windows\System32\BootMan.exe
[2011.10.30 13:37:01 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe
[2011.10.30 13:37:01 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll
[2011.10.30 13:37:01 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys
[2011.10.30 13:37:01 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys
[2011.10.24 19:46:38 | 000,005,632 | ---- | C] () -- C:\Users\tobi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.10.24 19:41:16 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2011.04.01 14:48:06 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011.04.01 14:48:06 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.04.01 14:48:06 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011.04.01 14:48:06 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.04.01 14:48:06 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.03.31 23:57:38 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2011.03.26 15:52:05 | 000,185,856 | ---- | C] () -- C:\Windows\System32\Bmp2Jpeg.dll
[2011.03.22 01:07:33 | 000,000,005 | ---- | C] () -- C:\Program Files\test.lis
[2011.01.09 15:29:56 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.12.29 16:17:42 | 000,002,892 | ---- | C] () -- C:\Windows\System32\audcon.sys
[2010.11.22 17:00:00 | 000,000,029 | ---- | C] () -- C:\Users\tobi\AppData\Roaming\ga.ga
[2010.10.04 20:19:44 | 000,007,617 | ---- | C] () -- C:\Users\tobi\AppData\Local\resmon.resmoncfg
[2010.09.17 11:42:46 | 000,482,408 | ---- | C] () -- C:\Windows\ssndii.exe
[2010.09.17 11:42:18 | 000,022,723 | ---- | C] () -- C:\Windows\System32\ssa1ml3.dll
[2010.09.12 03:50:19 | 000,010,593 | ---- | C] () -- C:\Windows\CSTBox.INI
[2010.08.25 19:59:08 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2010.08.25 19:57:00 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
[2010.08.25 19:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll
[2010.08.25 19:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll
 
========== LOP Check ==========
 
[2011.10.29 11:53:21 | 000,000,000 | ---D | M] -- C:\Users\Surfer\AppData\Roaming\Stardock
[2011.12.14 17:10:49 | 000,000,000 | ---D | M] -- C:\Users\Surfer\AppData\Roaming\SumatraPDF
[2011.11.05 00:40:29 | 000,000,000 | ---D | M] -- C:\Users\Surfer\AppData\Roaming\XMedia Recode
[2010.05.01 17:51:14 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\7stacks
[2011.02.12 00:31:19 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Acoustica
[2012.04.25 22:54:54 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Alien Skin
[2010.05.31 19:20:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\AllDup
[2012.05.01 22:59:55 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Amazon
[2012.04.21 21:26:10 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Ambient Design
[2011.10.24 21:08:44 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\AnvSoft
[2011.01.30 04:47:28 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Ashampoo
[2012.04.06 03:27:05 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Audacity
[2011.03.07 01:14:20 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\avidemux
[2009.11.15 14:12:13 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Bao_Nguyen
[2011.03.29 03:46:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\BayHunter
[2009.11.19 21:12:32 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\biu software
[2009.11.25 12:17:48 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Blaze
[2011.03.15 05:03:01 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Blue Cat Audio
[2011.03.26 00:03:35 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\BOM
[2011.02.02 16:32:00 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Buhl Data Service
[2011.10.27 11:48:13 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Buhl Data Service GmbH
[2010.02.17 21:36:17 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Canneverbe Limited
[2012.04.14 00:39:49 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Canon
[2012.05.30 01:01:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DAEMON Tools Lite
[2011.03.29 03:46:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\dd_bookmarks
[2010.02.17 21:33:22 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DeepBurner
[2012.05.30 00:30:58 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Dropbox
[2012.02.04 21:29:23 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DVDVideoSoft
[2012.02.04 21:29:10 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.02.01 00:16:53 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Easy YouTube to MP3 Converter
[2011.03.13 21:46:19 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Echo PCI Console
[2011.02.28 12:17:12 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\elsterformular
[2012.05.30 01:01:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FileZilla
[2010.03.05 00:18:44 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FireShot
[2011.12.14 03:13:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FolderSync
[2012.05.23 16:00:43 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\foobar2000
[2011.03.26 00:03:35 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\GetRightToGo
[2012.04.14 00:41:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\gtk-2.0
[2010.10.30 01:52:01 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Guitar Pro 6
[2010.09.22 23:03:11 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Gutscheinmieze
[2011.03.15 12:45:21 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\HighAndes
[2011.03.26 01:51:01 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\inkscape
[2009.11.15 14:04:02 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Launchy
[2012.04.06 04:00:31 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Leadertech
[2012.04.11 14:08:34 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\loadtbs
[2011.03.27 21:58:14 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\MAGIX
[2011.03.23 19:51:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Nitro PDF
[2010.09.17 18:49:58 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\OpenOffice.org
[2010.10.26 01:54:39 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Opera
[2011.12.14 03:13:24 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\OTi
[2010.02.28 03:12:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Outerspace Software
[2011.12.14 03:18:37 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\OutlookSync
[2011.03.26 00:03:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\PhotoScape
[2010.04.01 13:47:33 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Sound Quest
[2010.10.11 11:15:31 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Stardock
[2011.01.28 22:56:16 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Steinberg
[2011.10.18 12:55:35 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\SumatraPDF
[2010.11.26 01:17:04 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\SynthMaker
[2012.05.07 20:22:13 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TeamViewer
[2010.05.07 13:31:21 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Teleca
[2011.01.14 21:24:52 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TerraTec
[2011.01.16 18:51:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TH1
[2011.01.17 21:06:09 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TH2
[2011.03.06 03:49:46 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Thinstall
[2009.12.29 12:37:08 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Thunderbird
[2011.10.24 19:42:22 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Video DVD Maker FREE
[2011.02.02 21:10:16 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\VST3 Presets
[2011.03.27 14:48:16 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Web Page Maker
[2010.10.22 01:06:17 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Windows Live Writer
[2011.03.31 20:41:14 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\www.shadowexplorer.com
[2011.11.05 01:21:34 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\XMedia Recode
[2010.04.23 15:27:51 | 000,032,630 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.05.01 17:51:14 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\7stacks
[2011.02.12 00:31:19 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Acoustica
[2012.05.15 02:13:32 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Adobe
[2011.03.23 01:01:49 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\AdobeUM
[2012.04.25 22:54:54 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Alien Skin
[2010.05.31 19:20:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\AllDup
[2012.05.01 22:59:55 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Amazon
[2012.04.21 21:26:10 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Ambient Design
[2011.10.24 21:08:44 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\AnvSoft
[2010.12.29 11:55:12 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Apple Computer
[2011.01.30 04:47:28 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Ashampoo
[2012.04.06 03:27:05 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Audacity
[2011.03.07 01:14:20 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\avidemux
[2009.11.15 14:12:13 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Bao_Nguyen
[2011.03.29 03:46:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\BayHunter
[2009.11.19 21:12:32 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\biu software
[2009.11.25 12:17:48 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Blaze
[2011.03.15 05:03:01 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Blue Cat Audio
[2011.03.26 00:03:35 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\BOM
[2011.02.02 16:32:00 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Buhl Data Service
[2011.10.27 11:48:13 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Buhl Data Service GmbH
[2010.02.17 21:36:17 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Canneverbe Limited
[2012.04.14 00:39:49 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Canon
[2012.04.14 14:12:17 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Corel
[2012.05.30 01:01:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DAEMON Tools Lite
[2011.03.29 03:46:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\dd_bookmarks
[2010.02.17 21:33:22 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DeepBurner
[2012.05.30 00:30:58 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Dropbox
[2011.12.27 16:33:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\dvdcss
[2012.02.04 21:29:23 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DVDVideoSoft
[2012.02.04 21:29:10 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.02.01 00:16:53 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Easy YouTube to MP3 Converter
[2011.03.13 21:46:19 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Echo PCI Console
[2011.02.28 12:17:12 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\elsterformular
[2010.10.04 19:16:54 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FastStone
[2012.05.30 01:01:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FileZilla
[2010.03.05 00:18:44 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FireShot
[2011.12.14 03:13:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FolderSync
[2012.05.23 16:00:43 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\foobar2000
[2011.03.26 00:03:35 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\GetRightToGo
[2012.04.14 00:41:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\gtk-2.0
[2010.10.30 01:52:01 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Guitar Pro 6
[2010.09.22 23:03:11 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Gutscheinmieze
[2011.03.15 12:45:21 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\HighAndes
[2009.11.13 14:20:28 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Identities
[2011.03.26 01:51:01 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\inkscape
[2009.11.14 02:24:11 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\InstallShield
[2009.11.15 14:04:02 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Launchy
[2012.04.06 04:00:31 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Leadertech
[2012.04.11 14:08:34 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\loadtbs
[2012.04.06 03:53:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Logishrd
[2012.04.06 04:00:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Logitech
[2011.03.23 22:39:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Macromedia
[2011.03.27 21:58:14 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\MAGIX
[2011.03.28 01:56:59 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Malwarebytes
[2009.07.14 10:56:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Media Center Programs
[2012.02.20 10:12:26 | 000,000,000 | --SD | M] -- C:\Users\tobi\AppData\Roaming\Microsoft
[2009.11.13 14:36:20 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Mozilla
[2011.03.26 14:07:21 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\NCH Software
[2011.03.23 19:51:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Nitro PDF
[2010.09.17 18:49:58 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\OpenOffice.org
[2010.10.26 01:54:39 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Opera
[2011.12.14 03:13:24 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\OTi
[2010.02.28 03:12:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Outerspace Software
[2011.12.14 03:18:37 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\OutlookSync
[2011.03.26 00:03:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\PhotoScape
[2012.05.30 01:01:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Skype
[2011.02.11 17:01:51 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\skypePM
[2010.05.07 13:18:03 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Sony Ericsson
[2010.04.01 13:47:33 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Sound Quest
[2010.10.11 11:15:31 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Stardock
[2011.01.28 22:56:16 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Steinberg
[2011.10.18 12:55:35 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\SumatraPDF
[2011.04.03 19:03:07 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\SUPERAntiSpyware.com
[2010.11.26 01:17:04 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\SynthMaker
[2012.05.07 20:22:13 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TeamViewer
[2010.05.07 13:31:21 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Teleca
[2011.01.14 21:24:52 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TerraTec
[2011.01.16 18:51:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TH1
[2011.01.17 21:06:09 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TH2
[2011.03.06 03:49:46 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Thinstall
[2009.12.29 12:37:08 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Thunderbird
[2011.10.24 19:42:22 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Video DVD Maker FREE
[2011.11.06 12:55:22 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\vlc
[2011.02.02 21:10:16 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\VST3 Presets
[2011.03.27 14:48:16 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Web Page Maker
[2010.10.22 01:06:17 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Windows Live Writer
[2012.04.14 14:41:43 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\WTablet
[2011.03.31 20:41:14 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\www.shadowexplorer.com
[2011.11.05 01:21:34 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\XMedia Recode
 
< %APPDATA%\*.exe /s >
[2001.09.28 16:00:28 | 000,128,608 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\Ambient Design\ArtRage 3\Resources\Filters\Alien Skin\Alien Skin\Eye Candy 5 Nature\UNWISE.EXE
[2001.09.28 17:00:28 | 000,164,864 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\Ambient Design\ArtRage 3\Resources\Filters\Alien Skin\Eye Candy 5 Impact\Unwise32.exe
[2011.12.06 15:40:44 | 009,483,600 | ---- | M] (Buhl Data Service GmbH) -- C:\Users\tobi\AppData\Roaming\Buhl Data Service GmbH\WISO Mein Geld 2012 Standard\Updates\LT2Update2011-12-02.exe
[2012.02.08 01:42:08 | 009,504,992 | ---- | M] (Buhl Data Service GmbH) -- C:\Users\tobi\AppData\Roaming\Buhl Data Service GmbH\WISO Mein Geld 2012 Standard\Updates\LT2Update2012-01-26.exe
[2012.03.24 14:41:33 | 009,492,760 | ---- | M] (Buhl Data Service GmbH) -- C:\Users\tobi\AppData\Roaming\Buhl Data Service GmbH\WISO Mein Geld 2012 Standard\Updates\LT2Update2012-03-22.exe
[2012.05.12 12:36:50 | 009,547,024 | ---- | M] (Buhl Data Service GmbH) -- C:\Users\tobi\AppData\Roaming\Buhl Data Service GmbH\WISO Mein Geld 2012 Standard\Updates\LT2Update2012-04-11.exe
[2012.02.15 01:03:14 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Users\tobi\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2012.02.15 01:03:44 | 000,174,752 | ---- | M] (Dropbox, Inc.) -- C:\Users\tobi\AppData\Roaming\Dropbox\bin\Uninstall.exe
[2012.04.11 14:08:18 | 012,697,088 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\loadtbs\ffmpeg.exe
[2012.04.11 14:08:18 | 001,243,136 | ---- | M] (InfiniAd GmbH) -- C:\Users\tobi\AppData\Roaming\loadtbs\uninstall.exe
[2012.04.11 14:08:21 | 000,694,784 | ---- | M] (InfiniAd GmbH) -- C:\Users\tobi\AppData\Roaming\loadtbs\ytdl.exe
[2012.05.31 14:33:46 | 000,003,584 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
[2010.02.14 03:38:38 | 000,001,078 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_16496df1.exe
[2010.02.14 03:38:38 | 000,001,078 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_18be6784.exe
[2010.02.14 03:38:38 | 000,001,078 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_294823.exe
[2010.02.14 03:38:38 | 000,001,078 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_2cd672ae.exe
[2010.02.14 03:38:38 | 000,001,078 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_4ae13d6c.exe
[2010.02.14 03:38:38 | 000,002,238 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_5af141bb.exe
[2010.02.14 03:38:38 | 000,001,078 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_69525f90.exe
[2012.04.06 04:00:30 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2009.11.15 13:58:01 | 000,015,086 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{F7DB6677-661D-4835-AAD8-1B7F4C98D7CE}\SwitcherIcon.exe
[2012.04.18 23:43:30 | 000,056,320 | ---- | M] (getfireshot.com) -- C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\crashreporter.exe
[2012.04.18 23:42:50 | 000,141,312 | ---- | M] (getfireshot.com) -- C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fireshot-container.exe
[2012.04.18 23:42:34 | 000,070,144 | ---- | M] (getfireshot.com) -- C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fireshot-deploy.exe
[2008.04.15 14:49:02 | 000,127,488 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A}\chrome\buyertools.exe
[2008.02.13 09:07:36 | 000,393,216 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\NCH Software\Components\aacenc3\aacenc3.exe
[2007.11.27 09:41:32 | 000,405,504 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\NCH Software\Components\mp3el2\lame.exe
[2009.05.27 13:08:46 | 000,303,104 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{3736403A-A3EB-477f-AA96-00EEA43C76E6}\FileSync.exe
[2009.02.16 11:26:48 | 000,326,144 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{3736403A-A3EB-477f-AA96-00EEA43C76E6}\GoTip.exe
[2009.02.16 11:26:48 | 000,326,144 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{5E24AB31-F734-48ec-879E-C4B8C30F9ACD}\GoTip.exe
[2009.05.13 12:50:56 | 000,133,632 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{5E24AB31-F734-48ec-879E-C4B8C30F9ACD}\OutlookSyncM.exe
[2009.04.13 10:32:40 | 000,024,576 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\CreateSN.exe
[2009.05.26 15:38:58 | 000,851,968 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\GO!Bridge.exe
[2009.05.27 19:06:48 | 000,290,816 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\GO!Net.exe
[2009.05.25 20:01:08 | 000,086,016 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\GoNetDispatch.exe
[2009.02.16 11:26:48 | 000,326,144 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\GoTip.exe
[2009.05.20 11:58:22 | 000,298,496 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\LinkEngine.exe
[2009.05.18 18:50:58 | 000,032,256 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\ntrights.exe
[2009.05.20 11:58:44 | 000,180,224 | ---- | M] (Ours Technology Inc.) -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\OMEA.exe
[2009.03.02 13:33:58 | 000,233,472 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\OMEA_ERROR_MESSAGE.exe
[2009.02.16 11:26:48 | 000,018,944 | ---- | M] (Ours Technology Inc.) -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\StopLE.exe
[2009.05.26 14:37:22 | 000,836,608 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\MainExe\GSLoader.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\ERDNT\cache\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\ERDNT\cache\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\ERDNT\cache\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\drivers\iaStor.sys
[2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_4f144d6467fc7c22\iaStor.sys
[2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_x86_neutral_10aa509d6843c6fc\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\drivers\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\ERDNT\cache\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\drivers\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\ERDNT\cache\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\ERDNT\cache\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\System32\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\ERDNT\cache\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\ERDNT\cache\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\ERDNT\cache\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<           >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:8CE646EE

< End of report >
         
--- --- ---
[code/]

Alt 01.06.2012, 10:48   #24
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:
ATTFilter
:OTL
O3 - HKLM\..\Toolbar: (loadtbs) - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - C:\Users\tobi\AppData\Roaming\loadtbs\toolbar.dll (InfiniAd GmbH)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:8CE646EE
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]
         
Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 01.06.2012, 11:27   #25
ronze44
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



einige sich wiederholende Fehlermeldungen, weil Dateien angeblich beschädigt sind, die sich auf der RAM Disk im Temp Ordner befinden, Musste oft klicken, bis alle weg waren.(kommt auch sonst ab und an vor, es steht dann da "führen Sie CHKDSK aus)
Nach Neustart lässt sich Securitiy Essentials nicht mehr anschalten (Echtzeitschutz)
Hier der Fix:
Code:
ATTFilter
All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{DFEFCDEE-CF1A-4FC8-88AD-129872198372} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}\ deleted successfully.
C:\Users\tobi\AppData\Roaming\loadtbs\toolbar.dll moved successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
ADS C:\ProgramData\TEMP:8CE646EE deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
User: Surfer
->Temp folder emptied: 68479363 bytes
->Temporary Internet Files folder emptied: 17460230 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 25470253 bytes
->Flash cache emptied: 456 bytes
 
User: tobi
->Temp folder emptied: 39771 bytes
->Temporary Internet Files folder emptied: 2220474 bytes
->Java cache emptied: 189151 bytes
->FireFox cache emptied: 777157474 bytes
->Google Chrome cache emptied: 6792627 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 1138 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 15990 bytes
Session Manager Temp folder emptied: 161049608 bytes
Session Manager Tmp folder emptied: 242408 bytes
RecycleBin emptied: 166823 bytes
 
Total Files Cleaned = 1.010,00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
 
User: Default User
 
User: Public
 
User: Surfer
->Flash cache emptied: 0 bytes
 
User: tobi
->Flash cache emptied: 0 bytes
 
Total Flash Files Cleaned = 0,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.44.0 log created on 06012012_120541

Files\Folders moved on Reboot...
T:\TEMP\MpCmdRun.log moved successfully.
File move failed. T:\TEMP\RtkBtMnt.exe scheduled to be moved on reboot.

Registry entries deleted on Reboot...
         

Alt 01.06.2012, 14:14   #26
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



Hast du den TEMP-Pfad jetzt zurückgedreht und die RAM-Disk entfernt?
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 01.06.2012, 14:20   #27
ronze44
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



-Hatte ich zurückgedreht, aber nach der Inst von Java (das viele für DIE Sicherheitslücke an sich halten und es deshalb ablehnen?) wieder auf RAM Disk gesetzt. Ist wohl ein anderes Thema......

-Konnte über Umwege SE wieder aktivieren. (Fehlermeldung beim Anschalten des Echtzeitschutzes????) Mein Konto ist auf Standard, das bringt viele Umstände mit sich, aber mit dem will ich ja surfen.

-Ist sicherheitstechnisch noch etwas zu beanstanden?
danke

Alt 01.06.2012, 14:25   #28
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



Zitat:
-Hatte ich zurückgedreht, aber nach der Inst von Java (das viele für DIE Sicherheitslücke an sich halten und es deshalb ablehnen?) wieder auf RAM Disk gesetzt. Ist wohl ein anderes Thema......
Meine Güte, was hat denn das eine mit dem anderen zu tun?
Ich hatte deutlich gemacht, dass du die RAM-Disk deaktivieren sollst!

Zitat:
-Ist sicherheitstechnisch noch etwas zu beanstanden?
Das versuch ich ja rauszufinden wenn du mal endlich diese fast sinnfreie RAM-Disk erstmal wieder wegnimmst!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 01.06.2012, 14:48   #29
ronze44
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



Wieder umgestellt. Erbarme dich meiner.
alles wieder %USERPROFILE%\AppData\Local\Temp

Alt 01.06.2012, 14:59   #30
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Mail Account gehackt? Was ist tokenserver? - Standard

Mail Account gehackt? Was ist tokenserver?



Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu Mail Account gehackt? Was ist tokenserver?
account, anderes, angriffe, anzahl, bereits, bild, eintrag, entdeck, entdeckt, firefox, gehackt, gmx, grund, https, ide, kontakt, mail, mails, markiert, nichts, private, server, speicher, stelle, würde




Ähnliche Themen: Mail Account gehackt? Was ist tokenserver?


  1. E-Mail Account gehackt?
    Überwachung, Datenschutz und Spam - 28.10.2015 (57)
  2. Spam Mail vom eigenen Yahoo Account erhalten - Account gehackt?
    Log-Analyse und Auswertung - 28.08.2015 (8)
  3. E-Mail Account gehackt - Rechner betroffen?
    Log-Analyse und Auswertung - 24.06.2014 (5)
  4. Email Account gehackt? Mail Delivery
    Plagegeister aller Art und deren Bekämpfung - 29.05.2014 (24)
  5. E-Mail Account gehackt - unauthorisierte Mails von meinem Account werden verschickt
    Log-Analyse und Auswertung - 19.04.2014 (5)
  6. E-Mail-Account auf Mac gehackt ?
    Plagegeister aller Art und deren Bekämpfung - 12.12.2013 (5)
  7. Mail account gehackt?
    Plagegeister aller Art und deren Bekämpfung - 31.07.2013 (11)
  8. E-Mail Account gehackt? mailer-daemon@gmx.de
    Plagegeister aller Art und deren Bekämpfung - 24.07.2013 (17)
  9. AOL E-Mail Account gehackt?
    Überwachung, Datenschutz und Spam - 08.07.2013 (23)
  10. Mail Account gehackt?
    Plagegeister aller Art und deren Bekämpfung - 30.04.2013 (23)
  11. Gmx Mail Account gehackt? Virus?
    Plagegeister aller Art und deren Bekämpfung - 10.04.2013 (38)
  12. Amazon + E-mail account gehackt
    Log-Analyse und Auswertung - 26.02.2013 (13)
  13. E- Mail Account gehackt?
    Plagegeister aller Art und deren Bekämpfung - 29.11.2012 (82)
  14. AOL E-Mail Account gehackt? Nr. 2
    Überwachung, Datenschutz und Spam - 14.02.2012 (0)
  15. In Yahoo Mail Account gehackt
    Log-Analyse und Auswertung - 18.01.2012 (18)
  16. E-Mail Account gehackt
    Plagegeister aller Art und deren Bekämpfung - 13.05.2011 (28)
  17. Amazon Account gehackt + E-mail gehackt !
    Plagegeister aller Art und deren Bekämpfung - 05.05.2008 (16)

Zum Thema Mail Account gehackt? Was ist tokenserver? - Eine einfache Suche führt dich doch zum Ziel oder kennst du Google nicht? Umgebungsvariablen in Windows - Mail Account gehackt? Was ist tokenserver?...
Archiv
Du betrachtest: Mail Account gehackt? Was ist tokenserver? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.