![]() |
Überwachung, Datenschutz und Spam: Mail Account gehackt? Was ist tokenserver?Windows 7 Fragen zu Verschlüsselung, Spam, Datenschutz & co. sind hier erwünscht. Hier geht es um Abwehr von Keyloggern oder aderen Spionagesoftware wie Spyware und Adware. Themen zum "Trojaner entfernen" oder "Malware Probleme" dürfen hier nur diskutiert werden. Benötigst du Hilfe beim Trojaner entfernen oder weil du dir einen Virus eingefangen hast, erstelle ein Thema in den oberen Bereinigungsforen. |
![]() |
![]() | #16 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? Eine einfache Suche führt dich doch zum Ziel oder kennst du Google nicht? ![]() Umgebungsvariablen in Windows
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #17 |
![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? doch! Danke Arne, habs hingekriegt, ist natürlich ganz einfach, wenn mans weiß.
__________________Habe Java nun drauf und habe danach den Temp Ordner wieder auf die RAM Disk gelegt. Dein Link führt zwar zu Erklärung, was Umgebungsvariablen sind, doch wie man sie wo umstellt, hätte ich auch dort nicht so schnell gefunden. Fazit: Mein Mail account wurde massiv, und ohne Java installiert zu haben, von Hackern angegriffen und ich muss davon ausgehen, dass sie es geschafft haben. Mein Pass ist nun mehrmals gewechselt worden, hat ca 20 Zeichen, und die Fehl-Logins werden weniger. Trotzdem ist ein weniger werden eigentlich ein Indiz für den Erfolg der Angreifer, und ich kann nie wissen, ob sie es geschafft haben oder nicht. Wenn jemand den starken Willen hat, anzugreifen, ist das immer was anderes als wenn er es nur mal so aus Spaß tut. Ich muss davon ausgehen, dass alles erstmal ok ist, ohne wirklich einigermaßen sicher zu sein. |
![]() | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? Hast du jetzt eigentlich schon mit ESET gescannt?
__________________ |
![]() | #19 |
![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? Nein, bin noch gar nicht dazu gekommen. Also Firewall aus, AV aus, und los. Obwohl mir ESET als Programm auch vorliegt. Müsste nur mal neu starten. |
![]() | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? Windows-Firewall kann übrigens an bleiben, die hat noch nie gestört
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #21 |
![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? versteh ich nicht warum ich das nicht schon gestern gemacht habe..7 Funde Code:
ATTFilter ESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internetesets_scanner_update returned -1 esets_gle=12 # version=7 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=9e491272e9344749b5c9029923367a11 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-05-31 04:43:15 # local_time=2012-05-31 06:43:15 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 38533772 90107348 0 0 # compatibility_mode=8192 67108863 100 0 273 273 0 0 # scanned=216826 # found=7 # cleaned=0 # scan_time=6438 C:\Program Files\Yontoo\YontooIEClient.dll a variant of Win32/Adware.Yontoo.A application (unable to clean) 00000000000000000000000000000000 I C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\Users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\Users\All Users\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\Users\tobi\Downloads\fvdsuite_installer.exe a variant of Win32/InstallCore.R application (unable to clean) 00000000000000000000000000000000 I D:\Program Files\Native Instruments\Kontakt Player 2\KontaktPlayer2.exe a variant of Win32/Packed.Themida application (unable to clean) 00000000000000000000000000000000 I |
![]() | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? Viel Adware-Schrott dabei, aber keine echten Fieslinge Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #23 |
![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? ok, hier. Diesen Yatoo Quatsch habe ich wohl heute mittag noch nicht drauf gehabt. Hab das auch noch nicht eliminiert, als der scan lief: OTL Logfile: Code:
ATTFilter OTL logfile created on: 31.05.2012 21:14:31 - Run 1 OTL by OldTimer - Version Folder = C:\Users\tobi\Downloads Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,90 Gb Total Physical Memory | 1,63 Gb Available Physical Memory | 56,18% Memory free 5,80 Gb Paging File | 4,25 Gb Available in Paging File | 73,29% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 110,94 Gb Total Space | 63,56 Gb Free Space | 57,29% Space Free | Partition Type: NTFS Drive D: | 110,94 Gb Total Space | 85,68 Gb Free Space | 77,23% Space Free | Partition Type: NTFS Drive T: | 1024,00 Mb Total Space | 847,42 Mb Free Space | 82,76% Space Free | Partition Type: NTFS Computer Name: TOBI-PC | User Name: tobi | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.05.31 21:00:45 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\tobi\Downloads\OTL.exe PRC - [2012.05.09 20:08:16 | 006,592,000 | ---- | M] (Buyertools Ltd.) -- C:\Programme\Buyertools Reminder\Reminder.exe PRC - [2012.03.26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\msseces.exe PRC - [2012.03.26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\MsMpEng.exe PRC - [2012.03.19 13:38:47 | 002,666,880 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe PRC - [2012.02.15 01:03:14 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Users\tobi\AppData\Roaming\Dropbox\bin\Dropbox.exe PRC - [2012.01.23 08:38:24 | 006,321,016 | ---- | M] (Wacom Technology, Corp.) -- C:\Programme\Tablet\Wacom\Wacom_Tablet.exe PRC - [2012.01.23 08:38:24 | 003,591,544 | ---- | M] (Wacom Technology, Corp.) -- C:\Programme\Tablet\Wacom\Wacom_TouchUser.exe PRC - [2012.01.23 08:38:24 | 001,609,080 | ---- | M] (Wacom Technology, Corp.) -- C:\Programme\Tablet\Wacom\Wacom_TabletUser.exe PRC - [2012.01.23 08:38:24 | 000,470,904 | ---- | M] (Wacom Technology, Corp.) -- C:\Programme\Tablet\Wacom\Wacom_TouchService.exe PRC - [2011.10.24 09:53:38 | 002,565,632 | ---- | M] (Deutsche Telekom AG) -- C:\Programme\Netzmanager\NMInfraIS2\Netzmanager_Service.exe PRC - [2011.10.07 11:40:42 | 001,387,288 | ---- | M] (Logitech, Inc.) -- C:\Programme\Logitech\SetPointP\SetPoint.exe PRC - [2011.09.27 21:05:24 | 000,149,784 | ---- | M] (Logitech, Inc.) -- C:\Programme\Common Files\Logishrd\KHAL3\KHALMNPR.exe PRC - [2011.08.02 09:33:30 | 004,910,912 | ---- | M] (DT Soft Ltd) -- C:\Programme\DAEMON Tools Lite\DTLite.exe PRC - [2011.08.02 09:33:22 | 002,998,592 | ---- | M] (DT Soft Ltd) -- C:\Programme\DAEMON Tools Lite\DTShellHlp.exe PRC - [2011.07.29 11:30:28 | 000,399,416 | ---- | M] (Secunia) -- C:\Programme\Secunia\PSI\sua.exe PRC - [2011.03.28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE PRC - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2011.02.12 07:43:02 | 000,660,576 | ---- | M] (Acronis) -- C:\Programme\Common Files\Acronis\Schedule2\schedul2.exe PRC - [2011.02.12 07:40:50 | 000,365,632 | ---- | M] (Acronis) -- C:\Programme\Common Files\Acronis\Schedule2\schedhlp.exe PRC - [2011.01.02 21:29:50 | 000,009,216 | ---- | M] (www.shadowexplorer.com) -- C:\Programme\ShadowExplorer\sesvc.exe PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2010.11.01 18:09:12 | 000,802,816 | ---- | M] (Sphinx Software) -- C:\Programme\Windows7FirewallControl\Windows7FirewallControl.exe PRC - [2010.11.01 17:49:58 | 000,401,408 | ---- | M] (Sphinx Software) -- C:\Programme\Windows7FirewallControl\Windows7FirewallService.exe PRC - [2010.10.12 10:04:20 | 004,142,448 | ---- | M] (Stardock) -- C:\Programme\Stardock\ObjectDockPlus2\ObjectDock.exe PRC - [2010.10.04 16:02:00 | 000,249,856 | ---- | M] (troubadix) -- C:\Programme\ACFanControl\ACFanControl.exe PRC - [2010.10.01 03:50:23 | 000,296,448 | ---- | M] (Microsoft) -- C:\Programme\Stardock\ObjectDockPlus2\ObjectDockTray.exe PRC - [2010.07.09 16:43:15 | 000,016,016 | ---- | M] (Deutsche Telekom AG) -- C:\Programme\Telekom\Mediencenter\WebDAV.AdminService.exe PRC - [2009.11.12 14:48:56 | 000,071,096 | ---- | M] () -- C:\Programme\CDBurnerXP\NMSAccessU.exe PRC - [2009.07.14 03:14:42 | 000,181,760 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\ink\TabTip.exe PRC - [2009.06.07 14:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\System32\NlsSrv32.exe PRC - [2009.05.20 11:58:44 | 000,180,224 | ---- | M] (Ours Technology Inc.) -- C:\Programme\GO! Suite\Deployment\Functions\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\OMEA.exe PRC - [2009.04.30 11:23:26 | 000,090,112 | ---- | M] () -- C:\Programme\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe PRC - [2007.12.03 12:26:02 | 000,498,792 | ---- | M] () -- C:\Programme\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe PRC - [2006.11.02 20:40:12 | 000,174,656 | ---- | M] () -- C:\Windows\System32\PSIService.exe ========== Modules (No Company Name) ========== MOD - [2012.05.11 03:46:28 | 000,440,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\RenderPanel\206be09306fe0ee06ea4c5fe608e4a7f\RenderPanel.ni.dll MOD - [2012.05.11 03:46:26 | 000,440,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\ObjectDockTray\6f287cf521ace0f172b00bcdc8652c44\ObjectDockTray.ni.exe MOD - [2012.05.11 03:32:55 | 012,433,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\90555968565afd59bce4b0974e9903bd\System.Windows.Forms.ni.dll MOD - [2012.05.11 03:32:46 | 001,590,784 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\69f6e582cb79f107c61308b468c1a215\System.Drawing.ni.dll MOD - [2012.05.11 03:32:23 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll MOD - [2012.05.11 03:32:19 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll MOD - [2012.05.11 03:32:18 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll MOD - [2012.05.11 03:32:09 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll MOD - [2012.01.23 08:38:24 | 000,963,448 | ---- | M] () -- C:\Programme\Tablet\Wacom\libxml2.dll MOD - [2012.01.08 15:41:12 | 000,093,696 | ---- | M] () -- C:\Programme\FileZilla\FileZilla FTP Client\fzshellext.dll MOD - [2011.10.07 11:41:16 | 000,879,896 | ---- | M] () -- C:\Programme\Logitech\SetPointP\Macros\MacroCore.dll MOD - [2010.11.13 01:19:04 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\\mscorlib.resources.dll MOD - [2010.10.06 17:55:44 | 000,091,544 | ---- | M] () -- C:\Programme\Stardock\ObjectDockPlus2\Docklets\Calendar\Calendar.dll MOD - [2010.10.01 03:50:23 | 000,675,840 | ---- | M] () -- C:\Programme\Stardock\ObjectDockPlus2\DockShellHook.dll MOD - [2010.03.09 23:58:30 | 000,807,936 | ---- | M] () -- C:\Programme\Stardock\ObjectDockPlus2\CrashRpt.dll MOD - [2010.03.09 23:58:30 | 000,053,760 | ---- | M] () -- C:\Programme\Stardock\ObjectDockPlus2\zlib.dll MOD - [2006.05.31 16:47:42 | 000,684,032 | ---- | M] () -- C:\Programme\Buyertools Reminder\libeay32.dll MOD - [2006.05.31 16:47:42 | 000,626,688 | ---- | M] () -- C:\Programme\Buyertools Reminder\ex_parser.dll MOD - [2006.05.31 16:47:42 | 000,155,648 | ---- | M] () -- C:\Programme\Buyertools Reminder\ssleay32.dll ========== Win32 Services (SafeList) ========== SRV - [2012.05.04 19:53:14 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.04.25 02:30:41 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.03.26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV - [2012.03.26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV - [2012.03.19 13:38:47 | 002,666,880 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7) SRV - [2012.01.23 08:38:24 | 006,321,016 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Programme\Tablet\Wacom\Wacom_Tablet.exe -- (TabletServiceWacom) SRV - [2012.01.23 08:38:24 | 000,470,904 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Programme\Tablet\Wacom\Wacom_TouchService.exe -- (TouchServiceWacom) SRV - [2011.12.22 14:20:01 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2011.10.24 09:53:38 | 002,565,632 | ---- | M] (Deutsche Telekom AG) [Auto | Running] -- C:\Programme\Netzmanager\NMInfraIS2\Netzmanager_Service.exe -- (Netzmanager Service) SRV - [2011.09.27 21:03:28 | 000,295,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ) SRV - [2011.07.29 11:30:30 | 000,994,360 | ---- | M] (Secunia) [On_Demand | Stopped] -- C:\Programme\Secunia\PSI\psia.exe -- (Secunia PSI Agent) SRV - [2011.07.29 11:30:28 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Programme\Secunia\PSI\sua.exe -- (Secunia Update Agent) SRV - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV - [2011.02.12 07:43:02 | 000,660,576 | ---- | M] (Acronis) [Auto | Running] -- C:\Programme\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc) SRV - [2011.01.02 21:29:50 | 000,009,216 | ---- | M] (www.shadowexplorer.com) [Auto | Running] -- C:\Programme\ShadowExplorer\sesvc.exe -- (sesvc) SRV - [2010.11.20 14:21:36 | 000,351,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc) SRV - [2010.11.20 14:19:33 | 000,068,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\Mcx2Svc.dll -- (Mcx2Svc) SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2010.11.01 17:49:58 | 000,401,408 | ---- | M] (Sphinx Software) [Auto | Running] -- C:\Programme\Windows7FirewallControl\Windows7FirewallService.exe -- (Windows7FirewallService) SRV - [2010.09.22 17:33:04 | 000,051,040 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV - [2010.07.09 16:43:15 | 000,016,016 | ---- | M] (Deutsche Telekom AG) [Auto | Running] -- C:\Programme\Telekom\Mediencenter\WebDAV.AdminService.exe -- (MCSWASVR) SRV - [2010.06.08 21:23:01 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2010.03.18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing) SRV - [2010.03.18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpActivator) SRV - [2010.03.18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetPipeActivator) SRV - [2010.03.18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetMsmqActivator) SRV - [2009.11.12 14:48:56 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Programme\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU) SRV - [2009.07.14 03:16:18 | 000,065,024 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\wersvc.dll -- (WerSvc) SRV - [2009.07.14 03:16:17 | 000,266,752 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\upnphost.dll -- (upnphost) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009.07.14 03:15:41 | 000,075,264 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\mprdim.dll -- (RemoteAccess) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009.06.07 14:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\Windows\System32\NlsSrv32.exe -- (nlsX86cc) SRV - [2009.04.30 11:23:26 | 000,090,112 | ---- | M] () [Auto | Running] -- C:\Programme\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe -- (OMSI download service) SRV - [2007.12.03 12:26:02 | 000,498,792 | ---- | M] () [Auto | Running] -- C:\Programme\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe -- (TryAndDecideService) SRV - [2006.11.02 20:40:12 | 000,174,656 | ---- | M] () [Auto | Running] -- C:\Windows\System32\PSIService.exe -- (ProtexisLicensing) SRV - [2003.07.28 20:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\WacomVKHid.sys -- (WacomVKHid) DRV - File not found [Kernel | Auto | Stopped] -- C:\Windows\system32\Drivers\DgiVecp.sys -- (DgiVecp) DRV - File not found [Kernel | On_Demand | Stopped] -- T:\TEMP\catchme.sys -- (catchme) DRV - [2012.04.10 12:19:52 | 000,441,760 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\timntr.sys -- (timounter) DRV - [2012.04.10 12:19:52 | 000,044,384 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\Windows\System32\drivers\tifsfilt.sys -- (tifsfilter) DRV - [2012.04.10 12:19:50 | 000,132,224 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\snapman.sys -- (snapman) DRV - [2012.03.20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv) DRV - [2011.11.14 10:29:54 | 000,010,752 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wacmoumonitor.sys -- (wacmoumonitor) DRV - [2011.10.27 12:59:37 | 000,232,512 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2011.09.02 08:31:28 | 000,039,192 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt) DRV - [2011.09.02 08:31:20 | 000,041,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt) DRV - [2011.07.29 14:54:56 | 000,014,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\epmntdrv.sys -- (epmntdrv) DRV - [2011.07.29 14:54:56 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\EuGdiDrv.sys -- (EuGdiDrv) DRV - [2011.07.20 02:54:06 | 000,047,104 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\iBtFltCoex.sys -- (iBtFltCoex) DRV - [2011.07.19 23:12:22 | 000,225,280 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btmhsf.sys -- (btmhsf) DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010.09.16 17:02:33 | 000,035,040 | ---- | M] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) [Kernel | On_Demand | Stopped] -- C:\Programme\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys -- (TelekomNM3) DRV - [2010.09.15 11:03:02 | 000,011,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wacommousefilter.sys -- (wacommousefilter) DRV - [2010.09.15 11:02:58 | 000,014,120 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wacomvhid.sys -- (wacomvhid) DRV - [2010.09.05 15:04:09 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc) DRV - [2010.09.05 15:04:09 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt) DRV - [2010.09.01 10:30:58 | 000,015,544 | ---- | M] (Secunia) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\psi_mf.sys -- (PSI) DRV - [2010.08.17 13:35:36 | 000,782,840 | ---- | M] (TerraTec Electronic GmbH.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TerraTecUsbBda.sys -- (UDST7000BDA) DRV - [2010.08.04 13:14:14 | 000,022,136 | ---- | M] (TerraTec Electronic GmbH.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TerraTecUsbHid.sys -- (UDST7000HID) DRV - [2010.05.15 16:55:14 | 000,265,800 | ---- | M] (EldoS Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\cbfs3.sys -- (cbfs3) DRV - [2010.01.18 09:55:08 | 000,585,920 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\emBDA.sys -- (USB28xxBGA) DRV - [2010.01.18 09:55:08 | 000,549,952 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\emOEM.sys -- (USB28xxOEM) DRV - [2009.12.09 01:07:58 | 000,132,544 | ---- | M] (Echo Digital Audio Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\echondgo.sys -- (echondgo) DRV - [2009.12.09 01:07:58 | 000,132,544 | ---- | M] (Echo Digital Audio Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\echondgo.sys -- (EchoIndigo) DRV - [2009.11.12 14:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen) DRV - [2009.10.05 16:31:50 | 001,221,632 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2009.07.14 03:20:28 | 000,022,096 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\crcdisk.sys -- (crcdisk) DRV - [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ws2ifsl.sys -- (ws2ifsl) DRV - [2009.07.14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp) DRV - [2009.04.30 23:07:15 | 000,012,288 | ---- | M] (gavotte) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\rramdisk.sys -- (RRamdisk) DRV - [2008.10.21 09:22:48 | 000,114,600 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017mdm.sys -- (s0017mdm) DRV - [2008.10.21 09:22:48 | 000,109,736 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017unic.sys -- (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM) DRV - [2008.10.21 09:22:48 | 000,108,328 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017mgmt.sys -- (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM) DRV - [2008.10.21 09:22:48 | 000,104,616 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017obex.sys -- (s0017obex) DRV - [2008.10.21 09:22:48 | 000,086,824 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017bus.sys -- (s0017bus) Sony Ericsson Device 0017 driver (WDM) DRV - [2008.10.21 09:22:48 | 000,026,024 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017nd5.sys -- (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS) DRV - [2008.10.21 09:22:48 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017mdfl.sys -- (s0017mdfl) DRV - [2008.01.09 12:28:34 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\seehcri.sys -- (seehcri) DRV - [2007.11.30 02:46:52 | 000,005,120 | ---- | M] (Samsung Electronics) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\SSPORT.SYS -- (SSPORT) DRV - [2007.11.02 15:22:38 | 000,105,896 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217unic.sys -- (s217unic) Sony Ericsson Device 217 USB Ethernet Emulation SEMC217 (WDM) DRV - [2007.11.02 15:22:38 | 000,103,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217mgmt.sys -- (s217mgmt) Sony Ericsson Device 217 USB WMC Device Management Drivers (WDM) DRV - [2007.11.02 15:22:38 | 000,100,008 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217obex.sys -- (s217obex) DRV - [2007.11.02 15:22:38 | 000,024,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217nd5.sys -- (s217nd5) Sony Ericsson Device 217 USB Ethernet Emulation SEMC217 (NDIS) DRV - [2007.11.02 15:22:36 | 000,109,992 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217mdm.sys -- (s217mdm) DRV - [2007.11.02 15:22:36 | 000,083,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217bus.sys -- (s217bus) Sony Ericsson Device 217 driver (WDM) DRV - [2007.11.02 15:22:36 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s217mdfl.sys -- (s217mdfl) DRV - [2007.10.24 12:47:26 | 000,023,288 | ---- | M] (SIA Syncrosoft) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\synasUSB.sys -- (SynasUSB) DRV - [2006.10.13 03:21:00 | 000,020,512 | ---- | M] (EnTech Taiwan) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\TVicPort.sys -- (TVicPort) DRV - [2002.07.17 09:53:02 | 000,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ASPI32.SYS -- (Aspi32) DRV - [2001.04.09 13:45:00 | 000,008,138 | ---- | M] (Wacom Technology Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\PenClass.sys -- (PenClass) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/ IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 39 48 C5 2F 76 F2 CA 01 [binary data] IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\..\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}: "URL" = hxxp://www.crawler.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=60446 IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Bing" FF - prefs.js..browser.search.defaulturl: "hxxp://www.bing.com/search?FORM=IEFM1&q=" FF - prefs.js..browser.search.suggest.enabled: false FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://google.de" FF - prefs.js..extensions.enabledItems: {411F2F11-830F-4AB5-B7F0-FBC77B870B5A}: FF - prefs.js..extensions.enabledItems: de-DE@dictionaries.addons.mozilla.org:2.0.2 FF - prefs.js..extensions.enabledItems: dictlookup@arnhold.com:0.0.4 FF - prefs.js..extensions.enabledItems: dictionary-switcher@design-noir.de:1.3.1 FF - prefs.js..extensions.enabledItems: {53A03D43-5363-4669-8190-99061B2DEBA5}:1.4.7 FF - prefs.js..extensions.enabledItems: {EF522540-89F5-46b9-B6FE-1829E2B572C6}:5.0.9 FF - prefs.js..extensions.enabledItems: en-US@dictionaries.addons.mozilla.org:5.0.1 FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110704 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledItems: foxmarks@kei.com:4.0.2 FF - prefs.js..extensions.enabledItems: VacuumPlacesImproved@lultimouomo-gmail.com:1.2 FF - prefs.js..extensions.enabledItems: smarterwiki@wikiatic.com:4.6.4 FF - prefs.js..extensions.enabledItems: lazarus@interclue.com:2.3 FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.2 FF - prefs.js..extensions.enabledItems: FasterFox_Lite@BigRedBrent:3.9.1Lite FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: {37fa1426-b82d-11db-8314-0800200c9a66}:2.8 FF - prefs.js..extensions.enabledItems: {ca0849e8-2c76-42ae-9abe-34e14d337acf}:1.96 FF - prefs.js..keyword.URL: "hxxp://go.gmx.net/tb/mff_keyurl_search/?su=" FF - prefs.js..network.proxy.type: 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version= C:\Program Files\TabletPlugins\npwacom.dll (Wacom, Inc.) FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version= C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\tobi\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll File not found FF - HKCU\Software\MozillaPlugins\@sun.com/npsopluginmi;version=1.0: C:\Program Files\OpenOffice.org 3\program [2011.02.02 17:57:34 | 000,000,000 | ---D | M] FF - HKCU\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.04.25 02:30:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.05.31 14:37:11 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010.12.14 21:30:35 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2009.12.29 12:37:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\tobi\AppData\Roaming\mozilla\Extensions [2009.12.29 12:37:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\tobi\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012.05.21 01:43:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions [2012.05.02 00:12:11 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2012.03.06 13:52:52 | 000,000,000 | ---D | M] (Buyertools) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A} [2012.05.08 23:57:41 | 000,000,000 | ---D | M] ("FVD Suite Addon") -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{9051303c-7e41-4311-a783-d6fe5ef2832d} [2012.05.21 01:43:08 | 000,000,000 | ---D | M] (WOT) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2012.02.04 21:29:11 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2010.09.24 23:26:49 | 000,000,000 | ---D | M] (Password Exporter) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492} [2011.11.05 03:36:19 | 000,000,000 | ---D | M] ("BabelFish") -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{ca0849e8-2c76-42ae-9abe-34e14d337acf} [2010.11.18 20:34:48 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\de-DE@dictionaries.addons.mozilla.org [2012.02.22 19:53:37 | 000,000,000 | ---D | M] (Dictionary Switcher) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\dictionary-switcher@design-noir.de [2009.11.16 01:39:21 | 000,000,000 | ---D | M] (Dictionary (EN/DE)) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\dictlookup@arnhold.com [2010.12.22 13:09:18 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\en-GB@dictionaries.addons.mozilla.org [2012.05.21 01:43:08 | 000,000,000 | ---D | M] (United States English Spellchecker) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\en-US@dictionaries.addons.mozilla.org [2012.05.02 00:12:09 | 000,000,000 | ---D | M] (Fasterfox Lite) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\FasterFox_Lite@BigRedBrent [2012.03.13 10:45:08 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\foxmarks@kei.com [2012.05.21 01:43:08 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\ich@maltegoetz.de [2011.10.18 11:15:29 | 000,000,000 | ---D | M] (Lazarus: Form Recovery) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\lazarus@interclue.com [2011.03.12 03:57:47 | 000,000,000 | ---D | M] (Personas) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\personas@christopher.beard [2012.05.08 23:07:42 | 000,000,000 | ---D | M] (Yontoo) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\plugin@yontoo.com [2012.04.11 14:08:34 | 000,000,000 | ---D | M] (loadtbs) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\software@loadtubes.com [2011.01.16 00:47:46 | 000,000,000 | ---D | M] (Vacuum Places Improved) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\tidbt5d5.default\extensions\VacuumPlacesImproved@lultimouomo-gmail.com [2012.04.10 02:42:43 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2009.11.27 17:15:59 | 000,000,000 | ---D | M] (Buyertools) -- C:\Programme\Mozilla Firefox\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A} [2011.01.09 15:28:15 | 000,000,000 | ---D | M] (Skype extension) -- C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2012.04.18 12:00:26 | 000,193,744 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\{37FA1426-B82D-11DB-8314-0800200C9A66}.XPI [2012.04.05 00:52:59 | 000,399,561 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\{53A03D43-5363-4669-8190-99061B2DEBA5}.XPI [2012.01.08 15:20:19 | 000,634,964 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI [2012.03.09 00:42:38 | 000,138,614 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI [2012.05.21 01:43:08 | 000,045,066 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\{EF522540-89F5-46B9-B6FE-1829E2B572C6}.XPI [2012.05.11 03:50:11 | 000,185,022 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\ARTUR.DUBOVOY@GMAIL.COM.XPI [2012.02.22 19:53:37 | 000,322,566 | ---- | M] () (No name found) -- C:\USERS\TOBI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TIDBT5D5.DEFAULT\EXTENSIONS\SMARTERWIKI@WIKIATIC.COM.XPI [2012.04.25 02:30:41 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.04.11 14:08:19 | 000,378,880 | ---- | M] (InfiniAd GmbH) -- C:\Program Files\mozilla firefox\plugins\npmieze.dll [2012.04.10 02:42:36 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.04.10 02:42:36 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2007.07.26 13:05:16 | 000,001,329 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\crawlersrch.xml [2012.04.10 02:42:36 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.04.10 02:42:36 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.04.10 02:42:36 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.04.10 02:42:36 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\19.0.1084.52\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll CHR - plugin: Java Deployment Toolkit (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\19.0.1084.52\pdf.dll CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\\npGoogleUpdate3.dll CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files\TabletPlugins\npwacom.dll CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin O1 HOSTS File: ([2011.12.22 14:33:10 | 000,612,639 | ---- | M]) - C:\Windows\System32\drivers\etc\HOSTS O1 - Hosts: localhost O1 - Hosts: ::1 localhost #[IPv6] O1 - Hosts: fr.a2dfp.net O1 - Hosts: m.fr.a2dfp.net O1 - Hosts: ad.a8.net O1 - Hosts: asy.a8ww.net O1 - Hosts: abcstats.com O1 - Hosts: a.abv.bg O1 - Hosts: adserver.abv.bg O1 - Hosts: adv.abv.bg O1 - Hosts: bimg.abv.bg O1 - Hosts: ca.abv.bg O1 - Hosts: www2.a-counter.kiev.ua O1 - Hosts: track.acclaimnetwork.com O1 - Hosts: accuserveadsystem.com O1 - Hosts: www.accuserveadsystem.com O1 - Hosts: achmedia.com O1 - Hosts: aconti.net O1 - Hosts: secure.aconti.net O1 - Hosts: www.aconti.net #[Dialer.Aconti] O1 - Hosts: am1.activemeter.com O1 - Hosts: www.activemeter.com #[Tracking.Cookie] O1 - Hosts: ads.activepower.net O1 - Hosts: stat.active24stats.nl #[Tracking.Cookie] O1 - Hosts: ad2games.com O1 - Hosts: 16291 more lines... O2 - BHO: (Open FVD Suite Toolbar) - {2B171655-A69C-5c18-B693-6CB5DC269D44} - C:\Programme\FVD Suite\addons\IE\FVDToolbar.dll (www.flashvideodownloader.org/fvd-suite/) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Buyertools) - {7C7A8947-5935-4430-AC0E-E7D04697414E} - C:\Programme\Buyertools Reminder\IEButtonBuyertoolsInterface.dll () O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Programme\Yontoo\YontooIEClient.dll (Yontoo LLC) O3 - HKLM\..\Toolbar: (FVD Suite Toolbar) - {2B171655-A69C-5c18-B693-6CB5DC269D41} - C:\Programme\FVD Suite\addons\IE\FVDToolbar.dll (www.flashvideodownloader.org/fvd-suite/) O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Programme\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH) O3 - HKLM\..\Toolbar: (loadtbs) - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - C:\Users\tobi\AppData\Roaming\loadtbs\toolbar.dll (InfiniAd GmbH) O4 - HKLM..\Run: [ACFanControl] C:\Programme\ACFanControl\ACFanControl.exe (troubadix) O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [emsisoftantimalwaresetup] T:\TEMP\EmsisoftAntiMalwareSetup.exe (Emsisoft GmbH ) O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4 - HKLM..\Run: [OMEA] C:\Programme\GO! Suite\Deployment\Functions\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\OMEA.exe (Ours Technology Inc.) O4 - HKLM..\Run: [Windows7FirewallControl] C:\Programme\Windows7FirewallControl\Windows7FirewallControl.exe (Sphinx Software) O4 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000..\Run: [Buyertools Reminder] C:\Program Files\Buyertools Reminder\Reminder.exe (Buyertools Ltd.) O4 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKLM..\RunOnce: [InnoSetupRegFile.0000000001] C:\Windows\is-5KESA.exe () O4 - HKLM..\RunOnce: [ Malwarebytes Anti-Malware ] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - Startup: C:\Users\Surfer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk = C:\Programme\Netzmanager\netzmanager.exe (Deutsche Telekom AG) O4 - Startup: C:\Users\Surfer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Programme\Stardock\ObjectDockPlus2\ObjectDock.exe (Stardock) O4 - Startup: C:\Users\tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\tobi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O4 - Startup: C:\Users\tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Programme\Stardock\ObjectDockPlus2\ObjectDock.exe (Stardock) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1 O7 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: Free YouTube Download - C:\Users\tobi\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm () O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\tobi\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: Buyertools Reminder - {27914077-B4D6-4A0E-9763-76B6E9DD9A81} - C:\Programme\Buyertools Reminder\ReminderIE.exe () O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O15 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\..Trusted Domains: tobi-lieblein.de ([]https in Trusted sites) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{75985961-485B-4110-AC04-A74F011B2709}: DhcpNameServer = O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation) O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - igfxdev.dll (Intel Corporation) O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Programme\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.) O22 - SharedTaskScheduler: {1984D045-52CF-49cd-DB77-08F378FEA4DB} - ObjectDockShellExt - C:\Programme\Stardock\ObjectDockPlus2\ODMenu.dll (Stardock) O22 - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Programme\Stardock\Fences\FencesMenu.dll (Stardock) O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found. O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation) O30 - LSA: Authentication Packages - (relog_ap) - C:\Windows\System32\relog_ap.dll (Acronis) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\...com [@ = ComFile] -- Reg Error: Key error. File not found O37 - HKU\S-1-5-21-3126326990-1593323250-644049761-1000\...exe [@ = exefile] -- Reg Error: Key error. File not found O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TabUserW.exe.lnk - - File not found MsConfig - StartUpFolder: C:^Users^tobi^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Impulse Now.lnk - - File not found MsConfig - StartUpReg: Acer ePower Management - hkey= - key= - C:\Programme\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe (Acer Incorporated) MsConfig - StartUpReg: Acronis Scheduler2 Service - hkey= - key= - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) MsConfig - StartUpReg: AcronisTimounterMonitor - hkey= - key= - C:\Programme\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis) MsConfig - StartUpReg: Adobe ARM - hkey= - key= - File not found MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - File not found MsConfig - StartUpReg: Check Mail - hkey= - key= - C:\Programme\CheckMail V2\CK_Mail.exe (Sebastian Lehn) MsConfig - StartUpReg: Koma-Mail - hkey= - key= - C:\Programme\KomaMail\Koma_Mail.exe () MsConfig - StartUpReg: LManager - hkey= - key= - C:\Programme\Launch Manager\LManager.EXE (Dritek System Inc.) MsConfig - StartUpReg: MouseExtender - hkey= - key= - C:\Users\tobi\Desktop\MouseExtender.\MouseExtender.exe () MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.) MsConfig - StartUpReg: Rainlendar2 - hkey= - key= - C:\Programme\Rainlendar2\Rainlendar2.exe () MsConfig - StartUpReg: Samsung PanelMgr - hkey= - key= - C:\Windows\Samsung\PanelMgr\ssmmgr.exe () MsConfig - StartUpReg: Sony Ericsson PC Suite - hkey= - key= - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB) MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) MsConfig - StartUpReg: Switcher - hkey= - key= - C:\Program Files\Switcher\Switcher.exe (Bao_Nguyen) MsConfig - StartUpReg: TrueImageMonitor.exe - hkey= - key= - C:\Programme\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) MsConfig - State: "startup" - 2 MsConfig - State: "bootini" - 2 SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: MsMpSvc - C:\Programme\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) SafeBootMin: NTDS - File not found SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vmms - Service SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: MsMpSvc - C:\Programme\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: NTDS - File not found SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vmms - Service SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX: {1100659A-EB8D-C792-BFB0-2B854E215CC9} - Microsoft Windows Media Player ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\System32\Microsoft ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - C:\Windows\System32\Microsoft ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP Drivers32: aux - wdmaud.drv (Microsoft Corporation) Drivers32: aux1 - wdmaud.drv (Microsoft Corporation) Drivers32: aux2 - wdmaud.drv (Microsoft Corporation) Drivers32: aux3 - wdmaud.drv (Microsoft Corporation) Drivers32: aux4 - wdmaud.drv (Microsoft Corporation) Drivers32: aux5 - wdmaud.drv (Microsoft Corporation) Drivers32: aux6 - wdmaud.drv (Microsoft Corporation) Drivers32: aux7 - wdmaud.drv (Microsoft Corporation) Drivers32: midi - wdmaud.drv (Microsoft Corporation) Drivers32: midi1 - wdmaud.drv (Microsoft Corporation) Drivers32: midi2 - wdmaud.drv (Microsoft Corporation) Drivers32: MIDI3 - timiditydrv.dll () Drivers32: midi4 - wdmaud.drv (Microsoft Corporation) Drivers32: midi5 - wdmaud.drv (Microsoft Corporation) Drivers32: midi6 - wdmaud.drv (Microsoft Corporation) Drivers32: midi7 - wdmaud.drv (Microsoft Corporation) Drivers32: midi8 - wdmaud.drv (Microsoft Corporation) Drivers32: midi9 - wdmaud.drv (Microsoft Corporation) Drivers32: midimapper - midimap.dll (Microsoft Corporation) Drivers32: mixer - wdmaud.drv (Microsoft Corporation) Drivers32: mixer1 - wdmaud.drv (Microsoft Corporation) Drivers32: mixer2 - wdmaud.drv (Microsoft Corporation) Drivers32: mixer3 - wdmaud.drv (Microsoft Corporation) Drivers32: mixer4 - wdmaud.drv (Microsoft Corporation) Drivers32: mixer5 - wdmaud.drv (Microsoft Corporation) Drivers32: mixer6 - wdmaud.drv (Microsoft Corporation) Drivers32: mixer7 - wdmaud.drv (Microsoft Corporation) Drivers32: mixer8 - wdmaud.drv (Microsoft Corporation) Drivers32: mixer9 - wdmaud.drv (Microsoft Corporation) Drivers32: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation) Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.msadpcm - msadp32.acm (Microsoft Corporation) Drivers32: msacm.msg711 - msg711.acm (Microsoft Corporation) Drivers32: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation) Drivers32: MSVideo8 - VfWWDM32.dll (Microsoft Corporation) Drivers32: vidc.cvid - iccvid.dll (Radius Inc.) Drivers32: vidc.i420 - iyuv_32.dll (Microsoft Corporation) Drivers32: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation) Drivers32: vidc.mrle - msrle32.dll (Microsoft Corporation) Drivers32: vidc.msvc - msvidc32.dll (Microsoft Corporation) Drivers32: VIDC.UYVY - msyuv.dll (Microsoft Corporation) Drivers32: VIDC.YUY2 - msyuv.dll (Microsoft Corporation) Drivers32: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation) Drivers32: VIDC.YVYU - msyuv.dll (Microsoft Corporation) Drivers32: wave - wdmaud.drv (Microsoft Corporation) Drivers32: wave1 - wdmaud.drv (Microsoft Corporation) Drivers32: wave2 - wdmaud.drv (Microsoft Corporation) Drivers32: wave3 - wdmaud.drv (Microsoft Corporation) Drivers32: wave4 - wdmaud.drv (Microsoft Corporation) Drivers32: wave5 - wdmaud.drv (Microsoft Corporation) Drivers32: wave6 - wdmaud.drv (Microsoft Corporation) Drivers32: wave7 - wdmaud.drv (Microsoft Corporation) Drivers32: wave8 - wdmaud.drv (Microsoft Corporation) Drivers32: wave9 - wdmaud.drv (Microsoft Corporation) Drivers32: wavemapper - msacm32.drv (Microsoft Corporation) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012.05.31 16:51:24 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012.05.31 14:37:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2012.05.31 14:33:46 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Installer Clean Up [2012.05.29 20:04:05 | 000,000,000 | ---D | C] -- C:\Users\tobi\AppData\Local\{56015ACB-9C51-4DFB-8DF8-77F23DF4FEFB} [2012.05.21 10:50:06 | 000,000,000 | ---D | C] -- C:\Users\tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gitarrero Notenmeister [2012.05.21 10:50:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gitarrero Notenmeister [2012.05.21 10:50:02 | 000,000,000 | ---D | C] -- C:\Program Files\Gitarrero Software [2012.05.15 01:20:43 | 000,000,000 | ---D | C] -- C:\Users\tobi\Documents\Updater [2012.05.08 23:08:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FVD Suite [2012.05.08 23:07:40 | 000,000,000 | ---D | C] -- C:\Program Files\Yontoo [2012.05.08 23:07:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer [2012.05.01 22:59:55 | 000,000,000 | ---D | C] -- C:\Users\tobi\AppData\Roaming\Amazon [2012.05.01 22:54:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon [2012.05.01 22:54:30 | 000,000,000 | ---D | C] -- C:\Program Files\Amazon ========== Files - Modified Within 30 Days ========== [2012.05.31 21:13:00 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.05.31 20:53:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.05.31 16:36:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.05.31 14:44:38 | 000,023,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.05.31 14:44:38 | 000,023,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.05.31 10:52:07 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.05.30 17:02:49 | 000,001,422 | ---- | M] () -- C:\Users\tobi\Desktop\mbam - Verknüpfung.lnk [2012.05.29 20:47:11 | 000,711,240 | ---- | M] () -- C:\Windows\is-5KESA.exe [2012.05.29 20:47:11 | 000,012,782 | ---- | M] () -- C:\Windows\is-5KESA.msg [2012.05.29 20:47:11 | 000,000,441 | ---- | M] () -- C:\Windows\is-5KESA.lst [2012.05.24 23:28:38 | 000,817,674 | ---- | M] () -- C:\Users\tobi\Documents\POD 2.0 Advanced Guide - German.pdf [2012.05.24 22:30:06 | 000,364,498 | ---- | M] () -- C:\Users\tobi\Documents\Install_ReWire_1_7_Win.zip [2012.05.24 22:29:10 | 000,376,525 | ---- | M] () -- C:\Users\tobi\Documents\Cubase_5_Groove_Templates_SX3C4.cpr [2012.05.24 22:28:04 | 003,037,523 | ---- | M] () -- C:\Users\tobi\Documents\Virtual_Guitarist_2_User_Manual.pdf [2012.05.24 22:27:35 | 002,597,016 | ---- | M] () -- C:\Users\tobi\Documents\Hypersonic_User_Manual.pdf [2012.05.24 22:26:45 | 004,581,933 | ---- | M] () -- C:\Users\tobi\Documents\GrooveAgent_Manual.pdf [2012.05.24 09:17:22 | 000,002,290 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2012.05.21 14:02:23 | 000,698,470 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.05.21 14:02:23 | 000,653,748 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.05.21 14:02:23 | 000,148,634 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.05.21 14:02:23 | 000,121,580 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.05.21 10:50:06 | 000,001,102 | ---- | M] () -- C:\Users\tobi\Desktop\Gitarrero Notenmeister.lnk [2012.05.18 12:28:35 | 000,000,016 | ---- | M] () -- C:\Windows\System32\w3data.vss [2012.05.18 12:28:35 | 000,000,016 | ---- | M] () -- C:\Windows\System32\msvcsv60.dll [2012.05.18 12:28:35 | 000,000,016 | ---- | M] () -- C:\Windows\msocreg32.dat [2012.05.17 13:36:37 | 002,228,096 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012.05.17 13:36:14 | 2337,955,840 | -HS- | M] () -- C:\hiberfil.sys [2012.05.16 12:43:54 | 000,097,984 | ---- | M] () -- C:\Users\tobi\Documents\MUS_LA-Sammlung.rtf [2012.05.12 12:13:05 | 000,109,047 | ---- | M] () -- C:\Users\tobi\Documents\DeutschlandSIM Daten.pdf [2012.05.10 02:14:37 | 000,018,734 | ---- | M] () -- C:\Users\tobi\Documents\indriz2.odt [2012.05.08 23:08:56 | 000,001,979 | ---- | M] () -- C:\Users\Public\Desktop\FVD Player.lnk [2012.05.08 23:08:56 | 000,001,864 | ---- | M] () -- C:\Users\Public\Desktop\FVD Suite.lnk [2012.05.07 20:22:10 | 000,001,124 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk [2012.05.03 11:54:15 | 000,002,883 | ---- | M] () -- C:\Users\tobi\Documents\Electro Harmonix V256 Tips.rtf [2012.05.02 13:57:40 | 000,005,152 | ---- | M] () -- C:\Users\tobi\Documents\Indriz-Zeitung.rtf ========== Files Created - No Company Name ========== [2012.05.31 14:33:46 | 000,002,849 | ---- | C] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Install Clean Up.lnk [2012.05.30 17:02:49 | 000,001,422 | ---- | C] () -- C:\Users\tobi\Desktop\mbam - Verknüpfung.lnk [2012.05.29 20:47:11 | 000,711,240 | ---- | C] () -- C:\Windows\is-5KESA.exe [2012.05.29 20:47:11 | 000,012,782 | ---- | C] () -- C:\Windows\is-5KESA.msg [2012.05.29 20:47:11 | 000,000,441 | ---- | C] () -- C:\Windows\is-5KESA.lst [2012.05.24 23:28:43 | 000,817,674 | ---- | C] () -- C:\Users\tobi\Documents\POD 2.0 Advanced Guide - German.pdf [2012.05.24 22:30:03 | 000,364,498 | ---- | C] () -- C:\Users\tobi\Documents\Install_ReWire_1_7_Win.zip [2012.05.24 22:29:09 | 000,376,525 | ---- | C] () -- C:\Users\tobi\Documents\Cubase_5_Groove_Templates_SX3C4.cpr [2012.05.24 22:27:59 | 003,037,523 | ---- | C] () -- C:\Users\tobi\Documents\Virtual_Guitarist_2_User_Manual.pdf [2012.05.24 22:27:32 | 002,597,016 | ---- | C] () -- C:\Users\tobi\Documents\Hypersonic_User_Manual.pdf [2012.05.24 22:26:37 | 004,581,933 | ---- | C] () -- C:\Users\tobi\Documents\GrooveAgent_Manual.pdf [2012.05.21 10:50:06 | 000,001,102 | ---- | C] () -- C:\Users\tobi\Desktop\Gitarrero Notenmeister.lnk [2012.05.12 12:13:10 | 000,109,047 | ---- | C] () -- C:\Users\tobi\Documents\DeutschlandSIM Daten.pdf [2012.05.08 23:08:56 | 000,001,979 | ---- | C] () -- C:\Users\Public\Desktop\FVD Player.lnk [2012.05.08 23:08:56 | 000,001,864 | ---- | C] () -- C:\Users\Public\Desktop\FVD Suite.lnk [2012.05.07 20:22:10 | 000,001,136 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk [2012.05.07 20:22:10 | 000,001,124 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk [2012.05.07 03:24:09 | 000,018,734 | ---- | C] () -- C:\Users\tobi\Documents\indriz2.odt [2012.05.03 01:29:25 | 000,002,883 | ---- | C] () -- C:\Users\tobi\Documents\Electro Harmonix V256 Tips.rtf [2012.04.14 14:12:17 | 000,000,952 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys [2012.04.14 14:12:17 | 000,000,008 | RHS- | C] () -- C:\Windows\System32\00285B196A.sys [2012.04.14 01:41:25 | 000,000,000 | ---- | C] () -- C:\Windows\ARTSTU~1.INI [2012.04.11 14:09:13 | 000,000,001 | ---- | C] () -- C:\Users\tobi\AppData\Local\llftool.4.12.agreement [2012.02.26 00:01:56 | 000,000,016 | ---- | C] () -- C:\Windows\System32\msvcsv60.dll [2012.02.26 00:01:56 | 000,000,016 | ---- | C] () -- C:\Windows\msocreg32.dat [2011.10.30 13:37:01 | 002,469,760 | ---- | C] () -- C:\Windows\System32\BootMan.exe [2011.10.30 13:37:01 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe [2011.10.30 13:37:01 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll [2011.10.30 13:37:01 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys [2011.10.30 13:37:01 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys [2011.10.24 19:46:38 | 000,005,632 | ---- | C] () -- C:\Users\tobi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.10.24 19:41:16 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll [2011.04.01 14:48:06 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe [2011.04.01 14:48:06 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2011.04.01 14:48:06 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe [2011.04.01 14:48:06 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2011.04.01 14:48:06 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2011.03.31 23:57:38 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2011.03.26 15:52:05 | 000,185,856 | ---- | C] () -- C:\Windows\System32\Bmp2Jpeg.dll [2011.03.22 01:07:33 | 000,000,005 | ---- | C] () -- C:\Program Files\test.lis [2011.01.09 15:29:56 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2010.12.29 16:17:42 | 000,002,892 | ---- | C] () -- C:\Windows\System32\audcon.sys [2010.11.22 17:00:00 | 000,000,029 | ---- | C] () -- C:\Users\tobi\AppData\Roaming\ga.ga [2010.10.04 20:19:44 | 000,007,617 | ---- | C] () -- C:\Users\tobi\AppData\Local\resmon.resmoncfg [2010.09.17 11:42:46 | 000,482,408 | ---- | C] () -- C:\Windows\ssndii.exe [2010.09.17 11:42:18 | 000,022,723 | ---- | C] () -- C:\Windows\System32\ssa1ml3.dll [2010.09.12 03:50:19 | 000,010,593 | ---- | C] () -- C:\Windows\CSTBox.INI [2010.08.25 19:59:08 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll [2010.08.25 19:57:00 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config [2010.08.25 19:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll [2010.08.25 19:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll ========== LOP Check ========== [2011.10.29 11:53:21 | 000,000,000 | ---D | M] -- C:\Users\Surfer\AppData\Roaming\Stardock [2011.12.14 17:10:49 | 000,000,000 | ---D | M] -- C:\Users\Surfer\AppData\Roaming\SumatraPDF [2011.11.05 00:40:29 | 000,000,000 | ---D | M] -- C:\Users\Surfer\AppData\Roaming\XMedia Recode [2010.05.01 17:51:14 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\7stacks [2011.02.12 00:31:19 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Acoustica [2012.04.25 22:54:54 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Alien Skin [2010.05.31 19:20:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\AllDup [2012.05.01 22:59:55 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Amazon [2012.04.21 21:26:10 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Ambient Design [2011.10.24 21:08:44 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\AnvSoft [2011.01.30 04:47:28 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Ashampoo [2012.04.06 03:27:05 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Audacity [2011.03.07 01:14:20 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\avidemux [2009.11.15 14:12:13 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Bao_Nguyen [2011.03.29 03:46:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\BayHunter [2009.11.19 21:12:32 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\biu software [2009.11.25 12:17:48 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Blaze [2011.03.15 05:03:01 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Blue Cat Audio [2011.03.26 00:03:35 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\BOM [2011.02.02 16:32:00 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Buhl Data Service [2011.10.27 11:48:13 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Buhl Data Service GmbH [2010.02.17 21:36:17 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Canneverbe Limited [2012.04.14 00:39:49 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Canon [2012.05.30 01:01:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DAEMON Tools Lite [2011.03.29 03:46:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\dd_bookmarks [2010.02.17 21:33:22 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DeepBurner [2012.05.30 00:30:58 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Dropbox [2012.02.04 21:29:23 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DVDVideoSoft [2012.02.04 21:29:10 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DVDVideoSoftIEHelpers [2011.02.01 00:16:53 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Easy YouTube to MP3 Converter [2011.03.13 21:46:19 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Echo PCI Console [2011.02.28 12:17:12 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\elsterformular [2012.05.30 01:01:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FileZilla [2010.03.05 00:18:44 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FireShot [2011.12.14 03:13:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FolderSync [2012.05.23 16:00:43 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\foobar2000 [2011.03.26 00:03:35 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\GetRightToGo [2012.04.14 00:41:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\gtk-2.0 [2010.10.30 01:52:01 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Guitar Pro 6 [2010.09.22 23:03:11 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Gutscheinmieze [2011.03.15 12:45:21 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\HighAndes [2011.03.26 01:51:01 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\inkscape [2009.11.15 14:04:02 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Launchy [2012.04.06 04:00:31 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Leadertech [2012.04.11 14:08:34 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\loadtbs [2011.03.27 21:58:14 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\MAGIX [2011.03.23 19:51:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Nitro PDF [2010.09.17 18:49:58 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\OpenOffice.org [2010.10.26 01:54:39 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Opera [2011.12.14 03:13:24 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\OTi [2010.02.28 03:12:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Outerspace Software [2011.12.14 03:18:37 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\OutlookSync [2011.03.26 00:03:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\PhotoScape [2010.04.01 13:47:33 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Sound Quest [2010.10.11 11:15:31 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Stardock [2011.01.28 22:56:16 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Steinberg [2011.10.18 12:55:35 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\SumatraPDF [2010.11.26 01:17:04 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\SynthMaker [2012.05.07 20:22:13 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TeamViewer [2010.05.07 13:31:21 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Teleca [2011.01.14 21:24:52 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TerraTec [2011.01.16 18:51:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TH1 [2011.01.17 21:06:09 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TH2 [2011.03.06 03:49:46 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Thinstall [2009.12.29 12:37:08 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Thunderbird [2011.10.24 19:42:22 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Video DVD Maker FREE [2011.02.02 21:10:16 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\VST3 Presets [2011.03.27 14:48:16 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Web Page Maker [2010.10.22 01:06:17 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Windows Live Writer [2011.03.31 20:41:14 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\www.shadowexplorer.com [2011.11.05 01:21:34 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\XMedia Recode [2010.04.23 15:27:51 | 000,032,630 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2010.05.01 17:51:14 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\7stacks [2011.02.12 00:31:19 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Acoustica [2012.05.15 02:13:32 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Adobe [2011.03.23 01:01:49 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\AdobeUM [2012.04.25 22:54:54 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Alien Skin [2010.05.31 19:20:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\AllDup [2012.05.01 22:59:55 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Amazon [2012.04.21 21:26:10 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Ambient Design [2011.10.24 21:08:44 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\AnvSoft [2010.12.29 11:55:12 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Apple Computer [2011.01.30 04:47:28 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Ashampoo [2012.04.06 03:27:05 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Audacity [2011.03.07 01:14:20 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\avidemux [2009.11.15 14:12:13 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Bao_Nguyen [2011.03.29 03:46:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\BayHunter [2009.11.19 21:12:32 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\biu software [2009.11.25 12:17:48 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Blaze [2011.03.15 05:03:01 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Blue Cat Audio [2011.03.26 00:03:35 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\BOM [2011.02.02 16:32:00 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Buhl Data Service [2011.10.27 11:48:13 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Buhl Data Service GmbH [2010.02.17 21:36:17 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Canneverbe Limited [2012.04.14 00:39:49 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Canon [2012.04.14 14:12:17 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Corel [2012.05.30 01:01:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DAEMON Tools Lite [2011.03.29 03:46:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\dd_bookmarks [2010.02.17 21:33:22 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DeepBurner [2012.05.30 00:30:58 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Dropbox [2011.12.27 16:33:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\dvdcss [2012.02.04 21:29:23 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DVDVideoSoft [2012.02.04 21:29:10 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\DVDVideoSoftIEHelpers [2011.02.01 00:16:53 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Easy YouTube to MP3 Converter [2011.03.13 21:46:19 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Echo PCI Console [2011.02.28 12:17:12 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\elsterformular [2010.10.04 19:16:54 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FastStone [2012.05.30 01:01:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FileZilla [2010.03.05 00:18:44 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FireShot [2011.12.14 03:13:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\FolderSync [2012.05.23 16:00:43 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\foobar2000 [2011.03.26 00:03:35 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\GetRightToGo [2012.04.14 00:41:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\gtk-2.0 [2010.10.30 01:52:01 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Guitar Pro 6 [2010.09.22 23:03:11 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Gutscheinmieze [2011.03.15 12:45:21 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\HighAndes [2009.11.13 14:20:28 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Identities [2011.03.26 01:51:01 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\inkscape [2009.11.14 02:24:11 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\InstallShield [2009.11.15 14:04:02 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Launchy [2012.04.06 04:00:31 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Leadertech [2012.04.11 14:08:34 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\loadtbs [2012.04.06 03:53:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Logishrd [2012.04.06 04:00:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Logitech [2011.03.23 22:39:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Macromedia [2011.03.27 21:58:14 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\MAGIX [2011.03.28 01:56:59 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Malwarebytes [2009.07.14 10:56:41 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Media Center Programs [2012.02.20 10:12:26 | 000,000,000 | --SD | M] -- C:\Users\tobi\AppData\Roaming\Microsoft [2009.11.13 14:36:20 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Mozilla [2011.03.26 14:07:21 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\NCH Software [2011.03.23 19:51:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Nitro PDF [2010.09.17 18:49:58 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\OpenOffice.org [2010.10.26 01:54:39 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Opera [2011.12.14 03:13:24 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\OTi [2010.02.28 03:12:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Outerspace Software [2011.12.14 03:18:37 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\OutlookSync [2011.03.26 00:03:38 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\PhotoScape [2012.05.30 01:01:57 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Skype [2011.02.11 17:01:51 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\skypePM [2010.05.07 13:18:03 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Sony Ericsson [2010.04.01 13:47:33 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Sound Quest [2010.10.11 11:15:31 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Stardock [2011.01.28 22:56:16 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Steinberg [2011.10.18 12:55:35 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\SumatraPDF [2011.04.03 19:03:07 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\SUPERAntiSpyware.com [2010.11.26 01:17:04 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\SynthMaker [2012.05.07 20:22:13 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TeamViewer [2010.05.07 13:31:21 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Teleca [2011.01.14 21:24:52 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TerraTec [2011.01.16 18:51:18 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TH1 [2011.01.17 21:06:09 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\TH2 [2011.03.06 03:49:46 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Thinstall [2009.12.29 12:37:08 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Thunderbird [2011.10.24 19:42:22 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Video DVD Maker FREE [2011.11.06 12:55:22 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\vlc [2011.02.02 21:10:16 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\VST3 Presets [2011.03.27 14:48:16 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Web Page Maker [2010.10.22 01:06:17 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\Windows Live Writer [2012.04.14 14:41:43 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\WTablet [2011.03.31 20:41:14 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\www.shadowexplorer.com [2011.11.05 01:21:34 | 000,000,000 | ---D | M] -- C:\Users\tobi\AppData\Roaming\XMedia Recode < %APPDATA%\*.exe /s > [2001.09.28 16:00:28 | 000,128,608 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\Ambient Design\ArtRage 3\Resources\Filters\Alien Skin\Alien Skin\Eye Candy 5 Nature\UNWISE.EXE [2001.09.28 17:00:28 | 000,164,864 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\Ambient Design\ArtRage 3\Resources\Filters\Alien Skin\Eye Candy 5 Impact\Unwise32.exe [2011.12.06 15:40:44 | 009,483,600 | ---- | M] (Buhl Data Service GmbH) -- C:\Users\tobi\AppData\Roaming\Buhl Data Service GmbH\WISO Mein Geld 2012 Standard\Updates\LT2Update2011-12-02.exe [2012.02.08 01:42:08 | 009,504,992 | ---- | M] (Buhl Data Service GmbH) -- C:\Users\tobi\AppData\Roaming\Buhl Data Service GmbH\WISO Mein Geld 2012 Standard\Updates\LT2Update2012-01-26.exe [2012.03.24 14:41:33 | 009,492,760 | ---- | M] (Buhl Data Service GmbH) -- C:\Users\tobi\AppData\Roaming\Buhl Data Service GmbH\WISO Mein Geld 2012 Standard\Updates\LT2Update2012-03-22.exe [2012.05.12 12:36:50 | 009,547,024 | ---- | M] (Buhl Data Service GmbH) -- C:\Users\tobi\AppData\Roaming\Buhl Data Service GmbH\WISO Mein Geld 2012 Standard\Updates\LT2Update2012-04-11.exe [2012.02.15 01:03:14 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Users\tobi\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012.02.15 01:03:44 | 000,174,752 | ---- | M] (Dropbox, Inc.) -- C:\Users\tobi\AppData\Roaming\Dropbox\bin\Uninstall.exe [2012.04.11 14:08:18 | 012,697,088 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\loadtbs\ffmpeg.exe [2012.04.11 14:08:18 | 001,243,136 | ---- | M] (InfiniAd GmbH) -- C:\Users\tobi\AppData\Roaming\loadtbs\uninstall.exe [2012.04.11 14:08:21 | 000,694,784 | ---- | M] (InfiniAd GmbH) -- C:\Users\tobi\AppData\Roaming\loadtbs\ytdl.exe [2012.05.31 14:33:46 | 000,003,584 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe [2010.02.14 03:38:38 | 000,001,078 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_16496df1.exe [2010.02.14 03:38:38 | 000,001,078 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_18be6784.exe [2010.02.14 03:38:38 | 000,001,078 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_294823.exe [2010.02.14 03:38:38 | 000,001,078 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_2cd672ae.exe [2010.02.14 03:38:38 | 000,001,078 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_4ae13d6c.exe [2010.02.14 03:38:38 | 000,002,238 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_5af141bb.exe [2010.02.14 03:38:38 | 000,001,078 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{14FD296F-6D38-4C06-A6E1-6AD9CDE67AC2}\_69525f90.exe [2012.04.06 04:00:30 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe [2009.11.15 13:58:01 | 000,015,086 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Installer\{F7DB6677-661D-4835-AAD8-1B7F4C98D7CE}\SwitcherIcon.exe [2012.04.18 23:43:30 | 000,056,320 | ---- | M] (getfireshot.com) -- C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\crashreporter.exe [2012.04.18 23:42:50 | 000,141,312 | ---- | M] (getfireshot.com) -- C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fireshot-container.exe [2012.04.18 23:42:34 | 000,070,144 | ---- | M] (getfireshot.com) -- C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fireshot-deploy.exe [2008.04.15 14:49:02 | 000,127,488 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\Mozilla\Firefox\Profiles\tidbt5d5.default\extensions\{411F2F11-830F-4AB5-B7F0-FBC77B870B5A}\chrome\buyertools.exe [2008.02.13 09:07:36 | 000,393,216 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\NCH Software\Components\aacenc3\aacenc3.exe [2007.11.27 09:41:32 | 000,405,504 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\NCH Software\Components\mp3el2\lame.exe [2009.05.27 13:08:46 | 000,303,104 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{3736403A-A3EB-477f-AA96-00EEA43C76E6}\FileSync.exe [2009.02.16 11:26:48 | 000,326,144 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{3736403A-A3EB-477f-AA96-00EEA43C76E6}\GoTip.exe [2009.02.16 11:26:48 | 000,326,144 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{5E24AB31-F734-48ec-879E-C4B8C30F9ACD}\GoTip.exe [2009.05.13 12:50:56 | 000,133,632 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{5E24AB31-F734-48ec-879E-C4B8C30F9ACD}\OutlookSyncM.exe [2009.04.13 10:32:40 | 000,024,576 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\CreateSN.exe [2009.05.26 15:38:58 | 000,851,968 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\GO!Bridge.exe [2009.05.27 19:06:48 | 000,290,816 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\GO!Net.exe [2009.05.25 20:01:08 | 000,086,016 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\GoNetDispatch.exe [2009.02.16 11:26:48 | 000,326,144 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\GoTip.exe [2009.05.20 11:58:22 | 000,298,496 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\LinkEngine.exe [2009.05.18 18:50:58 | 000,032,256 | R--- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\ntrights.exe [2009.05.20 11:58:44 | 000,180,224 | ---- | M] (Ours Technology Inc.) -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\OMEA.exe [2009.03.02 13:33:58 | 000,233,472 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\OMEA_ERROR_MESSAGE.exe [2009.02.16 11:26:48 | 000,018,944 | ---- | M] (Ours Technology Inc.) -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\FunctModules\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\StopLE.exe [2009.05.26 14:37:22 | 000,836,608 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\OTi\GoExpress\MainExe\GSLoader.exe < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS > [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\ERDNT\cache\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys < MD5 for: ATAPI.SYS > [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\ERDNT\cache\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys < MD5 for: CNGAUDIT.DLL > [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\ERDNT\cache\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll < MD5 for: IASTOR.SYS > [2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\drivers\iaStor.sys [2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_4f144d6467fc7c22\iaStor.sys [2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_x86_neutral_10aa509d6843c6fc\iaStor.sys < MD5 for: IASTORV.SYS > [2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\drivers\iaStorV.sys [2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys [2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys < MD5 for: NETLOGON.DLL > [2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\ERDNT\cache\netlogon.dll [2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll [2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll < MD5 for: NVSTOR.SYS > [2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\drivers\nvstor.sys [2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys [2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys < MD5 for: SCECLI.DLL > [2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\ERDNT\cache\scecli.dll [2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll [2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll < MD5 for: USER32.DLL > [2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\ERDNT\cache\user32.dll [2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\System32\user32.dll [2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll < MD5 for: USERINIT.EXE > [2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\ERDNT\cache\userinit.exe [2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe [2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\ERDNT\cache\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe [2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\ERDNT\cache\winlogon.exe [2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe [2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe < MD5 for: WS2IFSL.SYS > [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < > ========== Alternate Data Streams ========== @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:8CE646EE < End of report > [code/] |
![]() | #24 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL O3 - HKLM\..\Toolbar: (loadtbs) - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - C:\Users\tobi\AppData\Roaming\loadtbs\toolbar.dll (InfiniAd GmbH) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:8CE646EE :Commands [purity] [emptytemp] [emptyflash] [resethosts] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #25 |
![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? einige sich wiederholende Fehlermeldungen, weil Dateien angeblich beschädigt sind, die sich auf der RAM Disk im Temp Ordner befinden, Musste oft klicken, bis alle weg waren.(kommt auch sonst ab und an vor, es steht dann da "führen Sie CHKDSK aus) Nach Neustart lässt sich Securitiy Essentials nicht mehr anschalten (Echtzeitschutz) Hier der Fix: Code:
ATTFilter All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{DFEFCDEE-CF1A-4FC8-88AD-129872198372} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}\ deleted successfully. C:\Users\tobi\AppData\Roaming\loadtbs\toolbar.dll moved successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\autoexec.bat moved successfully. ADS C:\ProgramData\TEMP:8CE646EE deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes User: Surfer ->Temp folder emptied: 68479363 bytes ->Temporary Internet Files folder emptied: 17460230 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 25470253 bytes ->Flash cache emptied: 456 bytes User: tobi ->Temp folder emptied: 39771 bytes ->Temporary Internet Files folder emptied: 2220474 bytes ->Java cache emptied: 189151 bytes ->FireFox cache emptied: 777157474 bytes ->Google Chrome cache emptied: 6792627 bytes ->Opera cache emptied: 0 bytes ->Flash cache emptied: 1138 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 15990 bytes Session Manager Temp folder emptied: 161049608 bytes Session Manager Tmp folder emptied: 242408 bytes RecycleBin emptied: 166823 bytes Total Files Cleaned = 1.010,00 mb [EMPTYFLASH] User: All Users User: Default User: Default User User: Public User: Surfer ->Flash cache emptied: 0 bytes User: tobi ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0,00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version log created on 06012012_120541 Files\Folders moved on Reboot... T:\TEMP\MpCmdRun.log moved successfully. File move failed. T:\TEMP\RtkBtMnt.exe scheduled to be moved on reboot. Registry entries deleted on Reboot... |
![]() | #26 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? Hast du den TEMP-Pfad jetzt zurückgedreht und die RAM-Disk entfernt?
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #27 |
![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? -Hatte ich zurückgedreht, aber nach der Inst von Java (das viele für DIE Sicherheitslücke an sich halten und es deshalb ablehnen?) wieder auf RAM Disk gesetzt. Ist wohl ein anderes Thema...... -Konnte über Umwege SE wieder aktivieren. (Fehlermeldung beim Anschalten des Echtzeitschutzes????) Mein Konto ist auf Standard, das bringt viele Umstände mit sich, aber mit dem will ich ja surfen. -Ist sicherheitstechnisch noch etwas zu beanstanden? danke |
![]() | #28 | ||
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver?Zitat:
Ich hatte deutlich gemacht, dass du die RAM-Disk deaktivieren sollst! Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #29 |
![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? Wieder umgestellt. Erbarme dich meiner. alles wieder %USERPROFILE%\AppData\Local\Temp |
![]() | #30 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Mail Account gehackt? Was ist tokenserver? Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm! Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet, Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C ![]() Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten! ![]()
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() |
Themen zu Mail Account gehackt? Was ist tokenserver? |
account, anderes, angriffe, anzahl, bereits, bild, eintrag, entdeck, entdeckt, firefox, gehackt, gmx, grund, https, ide, kontakt, mail, mails, markiert, nichts, private, server, speicher, stelle, würde |