Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: files indexation process failed

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 27.03.2012, 19:08   #16
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
files indexation process failed - Standard

files indexation process failed



Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 27.03.2012, 20:49   #17
Yvonette
 
files indexation process failed - Standard

files indexation process failed



OSAM Logfile:
Code:
ATTFilter
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 21:48:01 on 27.03.2012

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 11.0

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[AppInit DLLs]
-----( HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows )-----
"AppInit_DLLs" - "Google" - C:\PROGRA~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll

[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-2426209709-3695512336-22860695-1000Core.job" - "Google Inc." - C:\Users\Yvonne\AppData\Local\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-2426209709-3695512336-22860695-1000UA.job" - "Google Inc." - C:\Users\Yvonne\AppData\Local\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"LocalCOM.cpl" - "TOSHIBA CORPORATION" - C:\Windows\system32\LocalCOM.cpl
"TOSCDSPD.cpl" - "TOSHIBA" - C:\Windows\system32\TOSCDSPD.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\Users\Yvonne\AppData\Local\Temp\catchme.sys  (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"mbr" (mbr) - ? - C:\ComboFix\mbr.sys  (Hidden registry entry, rootkit activity | File not found)
"PC Tools Browser Defender Driver" (PCTBD) - "PC Tools" - C:\Windows\System32\Drivers\PCTBD.sys
"PC Tools Data Store" (pctDS) - "PC Tools" - C:\Windows\System32\drivers\pctDS.sys
"PC Tools Extended File Attributes" (pctEFA) - "PC Tools" - C:\Windows\System32\drivers\pctEFA.sys
"PC Tools Spyware Doctor Driver" (PCTSD) - "PC Tools" - C:\Windows\System32\Drivers\PCTSD.sys
"PCTools KDS" (PCTCore) - "PC Tools" - C:\Windows\System32\drivers\PCTCore.sys
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\Windows\System32\Drivers\PxHelp20.sys
"pxliapog" (pxliapog) - ? - C:\Users\Yvonne\AppData\Local\Temp\pxliapog.sys  (Hidden registry entry, rootkit activity | File not found)
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"Tosrfcom" (Tosrfcom) - ? - C:\Windows\system32\drivers\Tosrfcom.sys  (File not found)

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -   (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -   (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -   (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -   (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL
{00020d75-0000-0000-c000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - ? - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -   (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Program Files\WinRAR\rarext.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} "Java Plug-in 1.6.0_06" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} "Java Plug-in 1.6.0_07" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_30" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} "Java Plug-in 1.6.0_30" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_30" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_30.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10p.ocx / hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? -   (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"Amazon.de" - ? - hxxp://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home  (HTTP value)
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
"eBay - Der weltweite Online Marktplatz" - ? - hxxp://rover.ebay.com/rover/1/707-44556-9400-3/4  (HTTP value)
"ICQ7.5" - "ICQ, LLC." - C:\Program Files\ICQ7.5\ICQ.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\ssv.dll
{2A0F3D1B-0909-4FF4-B272-609CCE6054E7} "PC Tools Browser Defender BHO" - ? - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll  (File not found)
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{5C255C8A-E604-49b4-9D64-90988571CECB} "{5C255C8A-E604-49b4-9D64-90988571CECB}" - ? -   (File not found | COM-object registry key not found)

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE  (Shortcut exists | File exists)
"desktop.ini" - ? - C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Dropbox.lnk" - "Dropbox, Inc." - C:\Users\Yvonne\AppData\Roaming\Dropbox\bin\Dropbox.exe  (Shortcut exists | File exists)
"TRDCReminder.lnk" - "TOSHIBA Europe" - C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe  (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"ICQ" - "ICQ, LLC." - "C:\Program Files\ICQ7.5\ICQ.exe" silent loginmode=4
"TOSCDSPD" - "TOSHIBA" - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"00TCrdMain" - "TOSHIBA Corporation" - %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"ApnUpdater" - "{StringFileInfo_CompanyName}" - "C:\Program Files\Ask.com\Updater\Updater.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"Camera Assistant Software" - "Chicony" - "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
"Google Desktop Search" - "Google" - "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"HDMICtrlMan" - "TOSHIBA Corporation." - C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
"HSON" - "TOSHIBA Corporation" - %ProgramFiles%\TOSHIBA\TBS\HSON.exe
"ITSecMng" - " TOSHIBA CORPORATION" - %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"NDSTray.exe" - ? - NDSTray.exe  (File not found)
"Picasa Media Detector" - "Google Inc." - C:\Program Files\Picasa2\PicasaMediaDetector.exe
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"topi" - "TOSHIBA" - C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
"Toshiba Registration" - "Toshiba" - C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
"Toshiba TEMPRO" - "Toshiba Europe GmbH" - C:\Program Files\Toshiba TEMPRO\TemproTray.exe
"TPwrMain" - "TOSHIBA Corporation" - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll
"Toshiba Bluetooth Monitor" - "TOSHIBA CORPORATION." - C:\Windows\system32\tbtmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Avira Browser Schutz" (AntiVirWebService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"Browser Defender Update Service" (Browser Defender Update Service) - "Threat Expert Ltd." - C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
"ConfigFree Service" (ConfigFree Service) - "TOSHIBA CORPORATION" - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
"Google Desktop Manager 5.9.1005.12335" (GoogleDesktopManager-051210-111108) - "Google" - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Updater Service" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Notebook Performance Tuning Service (TEMPRO)" (TemproMonitoringService) - "Toshiba Europe GmbH" - C:\Program Files\Toshiba TEMPRO\TemproSvc.exe
"O2Micro Flash Memory Card Service" (o2flash) - "O2Micro International" - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"PC Tools Auxiliary Service" (sdAuxService) - "PC Tools" - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe
"PC Tools Security Service" (sdCoreService) - "PC Tools" - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe
"SmartFaceVWatchSrv" (SmartFaceVWatchSrv) - "Toshiba" - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe
"TOSHIBA Bluetooth Service" (TOSHIBA Bluetooth Service) - "TOSHIBA CORPORATION" - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
"TOSHIBA Navi Support Service" (TNaviSrv) - "TOSHIBA Corporation" - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
"TOSHIBA Optical Disc Drive Service" (TODDSrv) - "TOSHIBA Corporation" - C:\Windows\system32\TODDSrv.exe
"TOSHIBA Power Saver" (TosCoSrv) - "TOSHIBA Corporation" - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
"TOSHIBA SMART Log Service" (TOSHIBA SMART Log Service) - "TOSHIBA Corporation" - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
"Ulead Burning Helper" (UleadBurningHelper) - "Ulead Systems, Inc." - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries )-----
"AVSDA" - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\avsda.dll
"PCTOOLS CONTENT FILTER PROVIDER" - "PC Tools Research Pty Ltd." - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll

===[ Logfile end ]=========================================[ Logfile end ]===
         
--- --- ---
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
[/code]

Code:
ATTFilter
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-03-27 21:50:42
-----------------------------
21:50:42.308    OS Version: Windows 6.0.6002 Service Pack 2
21:50:42.308    Number of processors: 2 586 0x301
21:50:42.308    ComputerName: YVONNE-PC  UserName: Yvonne
21:50:44.555    Initialize success
21:51:45.063    AVAST engine defs: 12032701
21:52:07.730    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
21:52:07.745    Disk 0 Vendor: TOSHIBA_MK3252GSX LV010M Size: 305245MB BusType: 3
21:52:07.823    Disk 0 MBR read successfully
21:52:07.839    Disk 0 MBR scan
21:52:07.855    Disk 0 Windows VISTA default MBR code
21:52:07.870    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS         1500 MB offset 2048
21:52:07.901    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS       154273 MB offset 3074048
21:52:07.948    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       149471 MB offset 319025152
21:52:07.995    Disk 0 scanning sectors +625141760
21:52:08.120    Disk 0 scanning C:\Windows\system32\drivers
21:52:27.870    Service scanning
21:53:13.610    Modules scanning
21:53:29.771    Disk 0 trace - called modules:
21:53:29.834    ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys ataport.SYS hal.dll PCIIDEX.SYS msahci.sys 
21:53:29.849    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x852dd450]
21:53:29.880    3 CLASSPNP.SYS[8b3798b3] -> nt!IofCallDriver -> [0x85dad188]
21:53:29.912    5 PCTCore.sys[82a14407] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85d3a030]
21:53:31.394    AVAST engine scan C:\Windows
21:53:42.735    AVAST engine scan C:\Windows\system32
22:00:34.238    AVAST engine scan C:\Windows\system32\drivers
22:01:22.994    AVAST engine scan C:\Users\Yvonne
22:02:01.807    File: C:\Users\Yvonne\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe  **INFECTED** Win32:Malware-gen
22:02:01.979    File: C:\Users\Yvonne\AppData\Local\Google\Update\1.3.21.111\GoogleUpdate.exe  **INFECTED** Win32:Trojan-gen
22:04:17.153    File: C:\Users\Yvonne\AppData\Local\Temp\_av4_\data\aswar0.dll  **INFECTED** Win32:Malware-gen
22:04:17.683    File: C:\Users\Yvonne\AppData\Local\Temp\_av4_\data\updldr0.bin  **INFECTED** Win32:Malware-gen
22:40:31.081    AVAST engine scan C:\ProgramData
22:45:05.905    Scan finished successfully
22:46:33.900    Disk 0 MBR has been saved successfully to "C:\Users\Yvonne\Desktop\MBR.dat"
22:46:33.912    The log file has been saved successfully to "C:\Users\Yvonne\Desktop\aswMBR.txt"
         
GMER stürzt leider immer wieder ab.
__________________


Geändert von Yvonette (27.03.2012 um 21:41 Uhr)

Alt 30.03.2012, 10:16   #18
Yvonette
 
files indexation process failed - Standard

files indexation process failed



bekomme von system check jetzt die nachricht über ein verknüpfungsproblem.

"Das Element "8HaWtjvalLWn8y.exe", auf das sich die Verknüpfung bezieht, wurde verändert oder verschoben.
Soll die Verknüpfung gelöscht werden?"

ich trau mich aber momentan gar nichts mehr anzuklicken.
was soll ich tun?
__________________

Alt 30.03.2012, 14:43   #19
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
files indexation process failed - Standard

files indexation process failed



Lösch die Verknüpfung! Ist doch klar dass die Mist ist und nun ins Leere führt!

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 03.04.2012, 16:16   #20
Yvonette
 
files indexation process failed - Standard

files indexation process failed



Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.04.03.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Yvonne :: YVONNE-PC [Administrator]

Schutz: Aktiviert

03.04.2012 13:29:02
mbam-log-2012-04-03 (13-29-02).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 364863
Laufzeit: 3 Stunde(n), 43 Minute(n), 23 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         


Alt 03.04.2012, 18:38   #21
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
files indexation process failed - Standard

files indexation process failed



Ok, fehlt noch das andere Log
__________________
--> files indexation process failed

Alt 03.04.2012, 20:26   #22
Yvonette
 
files indexation process failed - Standard

files indexation process failed



sorry, das hat etwas länger gedauert ...

Code:
ATTFilter
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 04/03/2012 at 08:50 PM

Application Version : 5.0.1146

Core Rules Database Version : 8409
Trace Rules Database Version: 6221

Scan type       : Complete Scan
Total Scan Time : 03:23:21

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Limited User (Administrator User)

Memory items scanned      : 941
Memory threats detected   : 0
Registry items scanned    : 36453
Registry threats detected : 0
File items scanned        : 178065
File threats detected     : 278

Adware.Tracking Cookie
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ad.adnet[1].txt [ /ad.adnet ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ad.adserver01[1].txt [ /ad.adserver01 ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ad.yieldmanager[1].txt [ /ad.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ad.yieldmanager[2].txt [ /ad.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ad.yieldmanager[3].txt [ /ad.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ad.yieldmanager[4].txt [ /ad.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ad.yieldmanager[5].txt [ /ad.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ad.zanox[1].txt [ /ad.zanox ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ad2.adfarm1.adition[1].txt [ /ad2.adfarm1.adition ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ad3.adfarm1.adition[2].txt [ /ad3.adfarm1.adition ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@adfarm1.adition[1].txt [ /adfarm1.adition ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@adfarm1.adition[2].txt [ /adfarm1.adition ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@adfarm1.adition[3].txt [ /adfarm1.adition ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@adfarm1.adition[4].txt [ /adfarm1.adition ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@adfarm1.adition[5].txt [ /adfarm1.adition ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@adfarm1.adition[6].txt [ /adfarm1.adition ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@adfarm1.adition[7].txt [ /adfarm1.adition ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ads.medienhaus[1].txt [ /ads.medienhaus ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@adtech[1].txt [ /adtech ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@apmebf[2].txt [ /apmebf ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ar.atwola[1].txt [ /ar.atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ar.atwola[2].txt [ /ar.atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ar.atwola[3].txt [ /ar.atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ar.atwola[4].txt [ /ar.atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@ar.atwola[5].txt [ /ar.atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@at.atwola[1].txt [ /at.atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt.combing[2].txt [ /atdmt.combing ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt.combing[3].txt [ /atdmt.combing ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt.combing[4].txt [ /atdmt.combing ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt.combing[5].txt [ /atdmt.combing ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt.combing[6].txt [ /atdmt.combing ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt.combing[7].txt [ /atdmt.combing ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt.combing[8].txt [ /atdmt.combing ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt.combing[9].txt [ /atdmt.combing ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt[10].txt [ /atdmt ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt[11].txt [ /atdmt ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt[1].txt [ /atdmt ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt[2].txt [ /atdmt ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt[3].txt [ /atdmt ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt[4].txt [ /atdmt ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt[5].txt [ /atdmt ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt[6].txt [ /atdmt ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt[7].txt [ /atdmt ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt[8].txt [ /atdmt ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atdmt[9].txt [ /atdmt ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atwola[10].txt [ /atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atwola[1].txt [ /atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atwola[2].txt [ /atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atwola[3].txt [ /atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atwola[4].txt [ /atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atwola[5].txt [ /atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atwola[6].txt [ /atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atwola[7].txt [ /atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atwola[8].txt [ /atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@atwola[9].txt [ /atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@bs.serving-sys[10].txt [ /bs.serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@bs.serving-sys[11].txt [ /bs.serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@bs.serving-sys[1].txt [ /bs.serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@bs.serving-sys[2].txt [ /bs.serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@bs.serving-sys[3].txt [ /bs.serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@bs.serving-sys[4].txt [ /bs.serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@bs.serving-sys[5].txt [ /bs.serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@bs.serving-sys[6].txt [ /bs.serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@bs.serving-sys[7].txt [ /bs.serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@bs.serving-sys[8].txt [ /bs.serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@bs.serving-sys[9].txt [ /bs.serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@cdn.at.atwola[1].txt [ /cdn.at.atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@cdn.at.atwola[2].txt [ /cdn.at.atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@cdn.at.atwola[3].txt [ /cdn.at.atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@cdn.at.atwola[4].txt [ /cdn.at.atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@cdn.at.atwola[5].txt [ /cdn.at.atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@cdn.at.atwola[6].txt [ /cdn.at.atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@cdn.at.atwola[8].txt [ /cdn.at.atwola ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@content.yieldmanager[10].txt [ /content.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@content.yieldmanager[11].txt [ /content.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@content.yieldmanager[1].txt [ /content.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@content.yieldmanager[2].txt [ /content.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@content.yieldmanager[3].txt [ /content.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@content.yieldmanager[4].txt [ /content.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@content.yieldmanager[5].txt [ /content.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@content.yieldmanager[6].txt [ /content.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@content.yieldmanager[7].txt [ /content.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@content.yieldmanager[8].txt [ /content.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@content.yieldmanager[9].txt [ /content.yieldmanager ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@doubleclick[2].txt [ /doubleclick ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@eaeacom.112.2o7[1].txt [ /eaeacom.112.2o7 ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@mediaplex[2].txt [ /mediaplex ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@mediaplex[3].txt [ /mediaplex ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@mediaplex[4].txt [ /mediaplex ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@mediaplex[5].txt [ /mediaplex ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@questionmarket[2].txt [ /questionmarket ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@revsci[1].txt [ /revsci ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@revsci[3].txt [ /revsci ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@serving-sys[10].txt [ /serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@serving-sys[11].txt [ /serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@serving-sys[1].txt [ /serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@serving-sys[2].txt [ /serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@serving-sys[3].txt [ /serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@serving-sys[4].txt [ /serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@serving-sys[5].txt [ /serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@serving-sys[6].txt [ /serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@serving-sys[7].txt [ /serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@serving-sys[8].txt [ /serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@serving-sys[9].txt [ /serving-sys ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@sevenoneintermedia.112.2o7[1].txt [ /sevenoneintermedia.112.2o7 ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tacoda[1].txt [ /tacoda ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tacoda[2].txt [ /tacoda ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tacoda[4].txt [ /tacoda ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tacoda[5].txt [ /tacoda ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tacoda[6].txt [ /tacoda ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tacoda[7].txt [ /tacoda ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tacoda[8].txt [ /tacoda ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tracking.quisma[1].txt [ /tracking.quisma ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tracking.quisma[2].txt [ /tracking.quisma ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tradedoubler[1].txt [ /tradedoubler ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tradedoubler[2].txt [ /tradedoubler ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tradedoubler[3].txt [ /tradedoubler ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tradedoubler[4].txt [ /tradedoubler ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tradedoubler[5].txt [ /tradedoubler ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tradedoubler[6].txt [ /tradedoubler ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tradedoubler[7].txt [ /tradedoubler ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tradedoubler[8].txt [ /tradedoubler ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@tradedoubler[9].txt [ /tradedoubler ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@traffictrack[1].txt [ /traffictrack ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@vdwp.solution.weborama[2].txt [ /vdwp.solution.weborama ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@webmasterplan[2].txt [ /webmasterplan ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@webmasterplan[3].txt [ /webmasterplan ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@weborama[2].txt [ /weborama ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@www.active-tracking[1].txt [ /www.active-tracking ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\yvonne@zanox[1].txt [ /zanox ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\3QH96Q36.txt [ /ad3.adfarm1.adition.com ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\VC0JU7BT.txt [ /smartadserver.com ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\6ERKOUB7.txt [ /imrworldwide.com ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\Y5JMBDN8.txt [ /bs.serving-sys.com ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\5S4NN84A.txt [ /apmebf.com ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\1LSDA3RR.txt [ /ad2.adfarm1.adition.com ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\Q4YA3F2Q.txt [ /adform.net ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\4NMT61BF.txt [ /adfarm1.adition.com ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\G6OKM7GP.txt [ /c.atdmt.com ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\3D8Q91DN.txt [ /atdmt.combing.com ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\LRZWEIWQ.txt [ /atdmt.com ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\RX5FC814.txt [ /tracking.quisma.com ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\629JHESP.txt [ /fastclick.net ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\YJR8WCZE.txt [ /serving-sys.com ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\DCG3TJTI.txt [ /doubleclick.net ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\0GRRJEQ1.txt [ /track.adform.net ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\KSO7JL8W.txt [ /mediaplex.com ]
	C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Cookies\IKDTMGYZ.txt [ /smartadserver.com ]
	C:\USERS\YVONNE\Cookies\VC0JU7BT.txt [ Cookie:yvonne@smartadserver.com/ ]
	C:\USERS\YVONNE\Cookies\6ERKOUB7.txt [ Cookie:yvonne@imrworldwide.com/cgi-bin ]
	C:\USERS\YVONNE\Cookies\5S4NN84A.txt [ Cookie:yvonne@apmebf.com/ ]
	C:\USERS\YVONNE\Cookies\1LSDA3RR.txt [ Cookie:yvonne@ad2.adfarm1.adition.com/ ]
	C:\USERS\YVONNE\Cookies\Q4YA3F2Q.txt [ Cookie:yvonne@adform.net/ ]
	C:\USERS\YVONNE\Cookies\4NMT61BF.txt [ Cookie:yvonne@adfarm1.adition.com/ ]
	C:\USERS\YVONNE\Cookies\G6OKM7GP.txt [ Cookie:yvonne@c.atdmt.com/ ]
	C:\USERS\YVONNE\Cookies\3D8Q91DN.txt [ Cookie:yvonne@atdmt.combing.com/ ]
	C:\USERS\YVONNE\Cookies\LRZWEIWQ.txt [ Cookie:yvonne@atdmt.com/ ]
	C:\USERS\YVONNE\Cookies\629JHESP.txt [ Cookie:yvonne@fastclick.net/ ]
	C:\USERS\YVONNE\Cookies\YJR8WCZE.txt [ Cookie:yvonne@serving-sys.com/ ]
	C:\USERS\YVONNE\Cookies\DCG3TJTI.txt [ Cookie:yvonne@doubleclick.net/ ]
	C:\USERS\YVONNE\Cookies\0GRRJEQ1.txt [ Cookie:yvonne@track.adform.net/ ]
	.invitemedia.com [ C:\USERS\YVONNE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
	.invitemedia.com [ C:\USERS\YVONNE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
	.invitemedia.com [ C:\USERS\YVONNE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
	.invitemedia.com [ C:\USERS\YVONNE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@ADVERTISING[1].TXT [ /ADVERTISING ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@AD.ZANOX[1].TXT [ /AD.ZANOX ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@TRADEDOUBLER[2].TXT [ /TRADEDOUBLER ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@TRAFFICTRACK[2].TXT [ /TRAFFICTRACK ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@PARTYPOKER[2].TXT [ /PARTYPOKER ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@LSTAT.YOUKU[2].TXT [ /LSTAT.YOUKU ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@ZBOX.ZANOX[2].TXT [ /ZBOX.ZANOX ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@DOUBLECLICK[1].TXT [ /DOUBLECLICK ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@DOUBLECLICK[2].TXT [ /DOUBLECLICK ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@ATDMT[2].TXT [ /ATDMT ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@AD.TRACKBAR[1].TXT [ /AD.TRACKBAR ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@CONTENT.YIELDMANAGER.EDGESUITE[2].TXT [ /CONTENT.YIELDMANAGER.EDGESUITE ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@ADREVOLVER[2].TXT [ /ADREVOLVER ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@ADTECH[1].TXT [ /ADTECH ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@APMEBF[2].TXT [ /APMEBF ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@STATCOUNTER[1].TXT [ /STATCOUNTER ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@2O7[1].TXT [ /2O7 ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@TTO2.TRAFFICTRACK[1].TXT [ /TTO2.TRAFFICTRACK ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@AD.YIELDMANAGER[2].TXT [ /AD.YIELDMANAGER ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@TRACKING.QUISMA[1].TXT [ /TRACKING.QUISMA ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@ADS.REVSCI[1].TXT [ /ADS.REVSCI ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@ADSERVER.EASYAD[1].TXT [ /ADSERVER.EASYAD ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@CONTENT.YIELDMANAGER[1].TXT [ /CONTENT.YIELDMANAGER ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@MEDIA.ADREVOLVER[1].TXT [ /MEDIA.ADREVOLVER ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@CONTENT.YIELDMANAGER[3].TXT [ /CONTENT.YIELDMANAGER ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@ARCOR.122.2O7[1].TXT [ /ARCOR.122.2O7 ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@WWW.ETRACKER[2].TXT [ /WWW.ETRACKER ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@CASALEMEDIA[1].TXT [ /CASALEMEDIA ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@STATS.PAYPAL[2].TXT [ /STATS.PAYPAL ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@MEDIAPLEX[1].TXT [ /MEDIAPLEX ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@ZANOX-AFFILIATE[2].TXT [ /ZANOX-AFFILIATE ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@REALMEDIA[1].TXT [ /REALMEDIA ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@ZANOX[1].TXT [ /ZANOX ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@WWW.ZANOX-AFFILIATE[2].TXT [ /WWW.ZANOX-AFFILIATE ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@ADOPT.SPECIFICCLICK[2].TXT [ /ADOPT.SPECIFICCLICK ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@SEVENONEINTERMEDIA.112.2O7[1].TXT [ /SEVENONEINTERMEDIA.112.2O7 ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@ZEDO[2].TXT [ /ZEDO ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@TACODA[2].TXT [ /TACODA ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@WEBMASTERPLAN[2].TXT [ /WEBMASTERPLAN ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@WWW.ACTIVE-TRACKING[2].TXT [ /WWW.ACTIVE-TRACKING ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@TRIBALFUSION[1].TXT [ /TRIBALFUSION ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@WWW.W3COUNTER[1].TXT [ /WWW.W3COUNTER ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@BURSTNET[2].TXT [ /BURSTNET ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@STAT.YOUKU[1].TXT [ /STAT.YOUKU ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@FASTCLICK[1].TXT [ /FASTCLICK ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@ADSERVER.71I[1].TXT [ /ADSERVER.71I ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@MEDIA6DEGREES[1].TXT [ /MEDIA6DEGREES ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@AD.71I[2].TXT [ /AD.71I ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@PAYPAL.112.2O7[1].TXT [ /PAYPAL.112.2O7 ]
	C:\USERS\YVONNE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\YVONNE@EAEACOM.112.2O7[1].TXT [ /EAEACOM.112.2O7 ]
	.accounts.google.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.accounts.google.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.accounts.google.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	accounts.youtube.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	accounts.google.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	keyword-advertising.web.de [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	keyword-advertising.web.de [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	keyword-advertising.web.de [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	keyword-advertising.web.de [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	ads.saymedia.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	ads.saymedia.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.adserver.adtechus.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.lfstmedia.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.adviva.net [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.lucidmedia.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.ru4.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.ru4.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	adfarm1.adition.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	fashionfinder.asos.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	fashionfinder.asos.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	fashionfinder.asos.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	fashionfinder.asos.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	fashionfinder.asos.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.fashionfinder.asos.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.fashionfinder.asos.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.fashionfinder.asos.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	fashionfinder.asos.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	statse.webtrendslive.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.lfstmedia.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	imagesrv.adition.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	ad1.adfarm1.adition.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	ad2.adfarm1.adition.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\YVONNE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7JRXIWW7.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-FakeAV
	C:\PROGRAM FILES\WINRAR\DEFAULT.SFX
         

Alt 03.04.2012, 21:04   #23
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
files indexation process failed - Standard

files indexation process failed



Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 03.04.2012, 21:21   #24
Yvonette
 
files indexation process failed - Standard

files indexation process failed



war das kein richtiger trojaner, den SUPERAntiSpyware gemeldet hat?

naja, die icons in meinem windows startmenü unten links sind immer noch weg.
fehlermeldungen bekomme ich keine mehr und das die desktopicons sind auch wieder da.
allerdings, was irgendwie seltsam ist, das desktophintergrundbild, was ich vorher hatte (von windows) ist nicht mehr auffindbar.

aber ansonsten ist alles tiptop.

Alt 04.04.2012, 11:17   #25
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
files indexation process failed - Standard

files indexation process failed



Das zu WinRAR ist ein Fehlalarm

Die Icons wirst du wohl nicht mehr wiederbekommen, mit etwas Glück mit unhide

Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
Vista und 7 User müssen das Tool per Rechtsklick als Administrator ausführen!
__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu files indexation process failed
acrobat update, avira searchfree toolbar, befolgt, besserung, bli, blink, desktop, desktop leer, device driver, drive, failed, fehlermeldungen, files, folge, folgende, google earth, laufen, leer, lockedfile.multi.generic, malwarebytes, meldungen, menge, nicht mehr, picasa, plug-in, problem, process, rootkit, schwarz, security scan, seite, startmenü, systemwiederherstellung, usb 2.0, virus




Ähnliche Themen: files indexation process failed


  1. Log Files Beurteilung: insb. Vorgehen bei Meldung in Log Files "Files to move or delete:..."
    Log-Analyse und Auswertung - 20.05.2014 (15)
  2. O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSetting
    Mülltonne - 02.07.2012 (0)
  3. files indexation process failed und Fehlermeldungen
    Plagegeister aller Art und deren Bekämpfung - 21.03.2012 (1)
  4. System Check und Files Indexation process failed PROBLEM
    Plagegeister aller Art und deren Bekämpfung - 03.02.2012 (1)
  5. windows 7 gecrasht - "Windows - Delayed Write Failed" "Failed to save all the components..."
    Plagegeister aller Art und deren Bekämpfung - 26.01.2012 (12)
  6. WIN XP:Windows - Delayed Write Failed .. Failed to save all the components for the file \\System32\\
    Log-Analyse und Auswertung - 25.11.2011 (7)
  7. Windows - Delayed Write Failed .. Failed to save all the components for the file \\System32\\0000428
    Log-Analyse und Auswertung - 15.11.2011 (35)
  8. Windows - Delayed Write Failed .. Failed to save all the components for the file \\System32\\ - St
    Plagegeister aller Art und deren Bekämpfung - 13.11.2011 (16)
  9. Windows - Delayed Write Failed .. Failed to save all the components for the file \\System32\\
    Plagegeister aller Art und deren Bekämpfung - 13.11.2011 (101)
  10. Windows - Delayed Write Failed - Failed to save...
    Log-Analyse und Auswertung - 10.11.2011 (7)
  11. Windows - Delayed Write Failed .. Failed to save all the components for the file \\System32\\
    Log-Analyse und Auswertung - 09.11.2011 (25)
  12. Windows - Delayed Write Failed .. Failed to save all the components for the file \\System32\\
    Plagegeister aller Art und deren Bekämpfung - 07.11.2011 (10)
  13. Windows - Delayed Write Failed. Failed to save all the components for the file \\System32\\
    Log-Analyse und Auswertung - 07.11.2011 (12)
  14. C:\Windows\Ctahea.exe (Trojan.FraudPack) -> Failed to unload process.
    Plagegeister aller Art und deren Bekämpfung - 24.03.2010 (1)
  15. C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
    Log-Analyse und Auswertung - 31.05.2009 (1)
  16. Generic Win Process
    Plagegeister aller Art und deren Bekämpfung - 11.06.2007 (1)
  17. Process Explorer
    Alles rund um Windows - 16.06.2006 (1)

Zum Thema files indexation process failed - Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur - files indexation process failed...
Archiv
Du betrachtest: files indexation process failed auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.