Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   "BKA" Trojaner (https://www.trojaner-board.de/108360-bka-trojaner.html)

sebastian356 20.01.2012 21:51

"BKA" Trojaner
 
Guten Tag,

gestern Abend tauchte plötzlich das altbekannte BKA-fake-Bild auf meinem Rechner auf, ich startet daraufhin mein System neu. Frisch hochgefahren sprang spybot an und checkte die Datei wpbt0.dll und zeigte not found dahinter an. Daraufhin checkte ich mein System mit dem frisch upgedatetem spybot und dem antivir Programm, ohne Fund! In diesem Forum fand ich den Hinweis auf Malewarebytes, ich startete damit einen Suchlauf. Das Programm fand 2 infizierte Dateien, ich hab sie aber nicht gelöscht, da davon hier abgeraten wurde. Hier die log-Datei:

Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.20.02

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19170
Sebastian :: SEBASTIAN-PC [Administrator]

20.01.2012 17:48:53
mbam-log-2012-01-20 (20-39-07).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 291918
Laufzeit: 2 Stunde(n), 49 Minute(n), 8 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|vasja (Trojan.RansomP.Gen) -> Daten: C:\Users\SEBAST~1\AppData\Local\Temp\wpbt0.dll -> Keine Aktion durchgeführt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\Sebastian\AppData\Roaming\igfxtray.dat (Malware.Trace) -> Keine Aktion durchgeführt.

(Ende)


Desweiteren habe ich OTL mit den entsprechenden Anweisungen durchlaufen lassen, hier das Ergebnis:OTL Logfile:
Code:

OTL logfile created on: 20.01.2012 20:52:03 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Sebastian\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,99 Gb Total Physical Memory | 1,61 Gb Available Physical Memory | 53,93% Memory free
6,21 Gb Paging File | 4,85 Gb Available in Paging File | 78,07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,88 Gb Total Space | 66,91 Gb Free Space | 59,80% Space Free | Partition Type: NTFS
Drive D: | 111,00 Gb Total Space | 59,01 Gb Free Space | 53,16% Space Free | Partition Type: NTFS
Drive F: | 175,68 Mb Total Space | 62,05 Mb Free Space | 35,32% Space Free | Partition Type: FAT
Drive G: | 3,74 Gb Total Space | 3,65 Gb Free Space | 97,48% Space Free | Partition Type: FAT32
 
Computer Name: SEBASTIAN-PC | User Name: Sebastian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.01.20 20:43:39 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Sebastian\Downloads\OTL.exe
PRC - [2011.10.11 14:00:02 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.10.11 13:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2011.10.11 13:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.10.11 13:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.06.20 17:05:30 | 000,040,960 | ---- | M] () -- C:\Programme\dradio-Recorder\phonostarTimer.exe
PRC - [2011.03.09 10:18:06 | 001,060,864 | ---- | M] () -- C:\Programme\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe
PRC - [2011.03.09 10:16:56 | 000,484,352 | ---- | M] () -- C:\Programme\Western Digital\WD SmartWare\Front Parlor\WDSC.exe
PRC - [2011.03.09 10:09:54 | 003,986,944 | ---- | M] (Western Digital Technologies, Inc.) -- C:\Programme\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
PRC - [2011.03.09 10:07:54 | 000,238,592 | ---- | M] (WDC) -- C:\Programme\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
PRC - [2010.12.14 15:49:23 | 001,169,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sdclt.exe
PRC - [2009.04.11 07:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.03.05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Programme\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008.05.23 06:11:56 | 000,819,200 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe
PRC - [2008.05.23 05:43:52 | 000,466,944 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe
PRC - [2008.05.22 09:33:54 | 000,688,128 | ---- | M] (SAMSUNG Electronics) -- C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2008.05.13 01:13:28 | 000,085,672 | ---- | M] () -- C:\Programme\Samsung\Samsung Update Plus\SLUTrayNotifier.exe
PRC - [2008.04.25 13:31:34 | 000,565,248 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2008.04.17 07:26:46 | 000,352,256 | ---- | M] (SAMSUNG Electronics co., LTD.) -- C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe
PRC - [2008.04.17 03:50:00 | 006,111,232 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008.02.12 05:19:52 | 000,723,496 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2008.01.21 03:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2008.01.21 03:25:33 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
PRC - [2008.01.21 03:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Defender\MSASCui.exe
PRC - [2007.07.04 23:41:42 | 000,045,056 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.06.20 17:05:30 | 000,040,960 | ---- | M] () -- C:\Programme\dradio-Recorder\phonostarTimer.exe
MOD - [2011.06.15 14:07:10 | 002,293,248 | ---- | M] () -- C:\Programme\dradio-Recorder\QtCore4.dll
MOD - [2011.03.30 11:46:40 | 000,416,256 | ---- | M] () -- C:\Programme\dradio-Recorder\plugins\sqldrivers\qsqlite4.dll
MOD - [2011.03.30 08:16:34 | 008,173,568 | ---- | M] () -- C:\Programme\dradio-Recorder\QtGui4.dll
MOD - [2011.03.30 07:59:40 | 000,191,488 | ---- | M] () -- C:\Programme\dradio-Recorder\QtSql4.dll
MOD - [2008.05.13 01:13:28 | 000,085,672 | ---- | M] () -- C:\Programme\Samsung\Samsung Update Plus\SLUTrayNotifier.exe
MOD - [2007.05.10 23:50:00 | 000,017,024 | ---- | M] () -- C:\Programme\Adobe\Reader 8.0\Reader\ViewerPS.dll
MOD - [2006.08.12 04:48:40 | 000,049,152 | ---- | M] () -- C:\Programme\Samsung\Samsung Magic Doctor\HookDllPS2.dll
MOD - [2006.08.12 04:48:40 | 000,049,152 | ---- | M] () -- C:\Programme\Samsung\EasySpeedUpManager\HookDllPS2.dll
MOD - [2006.08.12 04:48:40 | 000,049,152 | ---- | M] () -- C:\Programme\Samsung\Easy Display Manager\HookDllPS2.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.10.11 13:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.10.11 13:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.06.29 14:59:18 | 000,155,344 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe -- (Sony Ericsson PCCompanion)
SRV - [2011.03.09 10:18:06 | 001,060,864 | ---- | M] () [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe -- (WDFME)
SRV - [2011.03.09 10:16:56 | 000,484,352 | ---- | M] () [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe -- (WDSC)
SRV - [2011.03.09 10:07:54 | 000,238,592 | ---- | M] (WDC) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe -- (WDDMService)
SRV - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Programme\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008.05.23 06:11:56 | 000,819,200 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV - [2008.05.23 05:43:52 | 000,466,944 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV - [2008.05.13 00:47:20 | 000,077,480 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe -- (Samsung Update Plus)
SRV - [2008.01.21 03:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.12.09 11:44:05 | 000,134,856 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.10.11 14:00:01 | 000,074,640 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.10.11 14:00:01 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011.02.16 15:52:46 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2011.01.18 16:39:00 | 000,081,408 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\SSHDRV86.sys -- (SSHDRV86)
DRV - [2010.06.17 14:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.03.25 16:48:00 | 000,114,728 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018mdm.sys -- (s1018mdm)
DRV - [2009.03.25 16:48:00 | 000,109,864 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018unic.sys -- (s1018unic) Sony Ericsson Device 1018 USB Ethernet Emulation (WDM)
DRV - [2009.03.25 16:48:00 | 000,106,208 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018mgmt.sys -- (s1018mgmt) Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM)
DRV - [2009.03.25 16:48:00 | 000,104,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018obex.sys -- (s1018obex)
DRV - [2009.03.25 16:48:00 | 000,086,824 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018bus.sys -- (s1018bus) Sony Ericsson Device 1018 driver (WDM)
DRV - [2009.03.25 16:48:00 | 000,026,024 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018nd5.sys -- (s1018nd5) Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS)
DRV - [2009.03.25 16:48:00 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018mdfl.sys -- (s1018mdfl)
DRV - [2008.07.30 06:51:30 | 000,277,736 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2008.06.08 23:23:00 | 007,522,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008.05.20 20:36:12 | 003,663,360 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32) Intel(R)
DRV - [2008.04.05 06:56:26 | 000,242,560 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vmc302.sys -- (VMC302)
DRV - [2008.01.21 03:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2008.01.21 03:23:20 | 002,225,664 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32) Intel(R)
DRV - [2008.01.09 12:28:34 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\seehcri.sys -- (seehcri)
DRV - [2007.09.13 07:17:58 | 000,755,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2007.05.23 09:13:10 | 000,013,312 | ---- | M] (SAMSUNG ELECTRONICS CO., LTD.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\KMDFMEMIO.sys -- (KMDFMEMIO)
DRV - [2006.11.28 08:11:00 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006.11.02 08:30:53 | 000,045,056 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006.07.24 16:05:00 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http:\\www.samsungcomputer.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: de-DE@dictionaries.addons.mozilla.org:2.0.2
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\VistaCodecPack\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: c:\Program Files\Sony\Media Go\npmediago.dll (Sony Creative Software Inc)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.3: C:\Program Files\VLC-Player\npvlc.dll (the VideoLAN Team)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.12.30 20:58:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.07.22 16:04:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011.10.17 14:53:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
 
[2011.05.16 12:48:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Extensions
[2011.05.16 12:48:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.01.11 16:52:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions
[2010.07.28 17:15:23 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.01.08 22:41:43 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012.01.07 18:58:16 | 000,000,000 | ---D | M] (PriceGong) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
[2011.12.24 21:29:26 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010.11.20 19:30:29 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2009.04.07 14:33:55 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\moveplayer@movenetworks.com
[2011.03.16 19:51:38 | 000,000,000 | ---D | M] (Personas) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\personas@christopher.beard
[2011.12.30 21:32:21 | 000,000,933 | ---- | M] () -- C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\bfgej6rs.default\searchplugins\11-suche.xml
[2011.12.30 21:32:21 | 000,002,419 | ---- | M] () -- C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\bfgej6rs.default\searchplugins\englische-ergebnisse.xml
[2011.12.30 21:32:21 | 000,010,525 | ---- | M] () -- C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\bfgej6rs.default\searchplugins\gmx-suche.xml
[2011.12.30 21:32:21 | 000,002,457 | ---- | M] () -- C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\bfgej6rs.default\searchplugins\lastminute.xml
[2011.12.30 21:32:21 | 000,005,508 | ---- | M] () -- C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\bfgej6rs.default\searchplugins\webde-suche.xml
[2011.12.30 20:58:32 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.11.04 08:31:18 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
() (No name found) -- C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\EXTENSIONS\TOOLBAR@WEB.DE.XPI
[2011.12.30 20:58:30 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.04 18:54:06 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.04 18:54:06 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.10.04 18:54:06 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.04 18:54:06 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.04 18:54:06 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.04 18:54:06 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.10.09 14:27:18 | 000,438,184 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        www.0scan.com
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        123topsearch.com
O1 - Hosts: 127.0.0.1        www.123topsearch.com
O1 - Hosts: 127.0.0.1        132.com
O1 - Hosts: 127.0.0.1        www.132.com
O1 - Hosts: 127.0.0.1        www.136136.net
O1 - Hosts: 15073 more lines...
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Programme\PriceGong\2.5.4\PriceGongIE.dll (PriceGong)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [dradio-RecorderTimer] C:\Programme\dradio-Recorder\phonostarTimer.exe ()
O4 - HKCU..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent File not found
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden File not found
O4 - HKCU..\Run: [Sony Ericsson PC Companion] C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe (Sony Ericsson)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [vasja] C:\Users\SEBAST~1\AppData\Local\Temp\wpbt0.dll File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1150600.exe -Update -1150600 -"Mozilla/5.0_(Windows_NT_6.0;_rv:6.0)_Gecko/20100101_Firefox/6.0" -"hxxp://cc.porsche.com/icc_euro/ui/pva/application/bpModules/interior_3D.jsp;jsessionid=6AFCEEFEA0D1FE4785165A1CAC41C5A1?RT=1314713697690" File not found
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Programs\PartyPoker\PartyPokerNet\RunPF.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Programs\PartyPoker\PartyPokerNet\RunPF.exe File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7BDFCF9E-F356-427F-853E-604C5BF6E37D}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DECB8486-47A8-4DB0-A326-AAD9748969B5}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{3c325060-917a-11df-b067-0013779ffed3}\Shell - "" = AutoRun
O33 - MountPoints2\{3c325060-917a-11df-b067-0013779ffed3}\Shell\AutoRun\command - "" = F:\setup.exe AUTORUN=1
O33 - MountPoints2\{e43923ef-11b9-11df-8e97-0013779ffed3}\Shell - "" = AutoRun
O33 - MountPoints2\{e43923ef-11b9-11df-8e97-0013779ffed3}\Shell\AutoRun\command - "" = F:\Startme.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.01.20 17:47:28 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\Malwarebytes
[2012.01.20 17:45:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.01.20 17:45:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.01.20 17:45:47 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.01.20 17:45:47 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.01.18 17:34:40 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Animake
[2012.01.18 17:34:37 | 000,000,000 | ---D | C] -- C:\Program Files\Animake
[2012.01.12 12:15:39 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\Desktop\ConfirmationMail.aspx-Dateien
[2012.01.07 18:58:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong
[2012.01.07 18:58:15 | 000,000,000 | ---D | C] -- C:\Program Files\PriceGong
[2011.12.31 13:10:56 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\Desktop\RR Bilder
[2009.11.30 20:05:51 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\ProgramData\hpe9CCB.dll
[2009.07.31 09:30:15 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\ProgramData\hpe9AEF.dll
[2006.11.24 06:14:44 | 000,139,264 | ---- | C] ( ) -- C:\Windows\System32\MACSSDK_wiz.dll
[2006.11.24 06:14:44 | 000,126,976 | ---- | C] ( ) -- C:\Windows\System32\MACSSDK.dll
 
========== Files - Modified Within 30 Days ==========
 
[2012.01.20 21:01:00 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.01.20 20:26:23 | 000,000,426 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{79EFB1BF-C914-49BB-A75F-232FC7288BAD}.job
[2012.01.20 19:31:48 | 000,618,442 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.01.20 19:31:48 | 000,587,178 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.01.20 19:31:48 | 000,122,842 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.01.20 19:31:48 | 000,101,250 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.01.20 19:17:02 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.01.20 19:17:02 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.01.20 17:45:51 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.20 17:17:42 | 000,242,173 | ---- | M] () -- C:\ProgramData\nvModes.001
[2012.01.20 17:17:19 | 000,242,173 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2012.01.20 17:16:57 | 000,001,100 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.01.20 17:16:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.01.20 16:13:21 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.01.20 13:30:38 | 000,116,224 | ---- | M] () -- C:\Users\Sebastian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.01.12 12:15:40 | 000,031,931 | ---- | M] () -- C:\Users\Sebastian\Desktop\ConfirmationMail.aspx.htm
[2012.01.03 21:28:50 | 245,308,330 | ---- | M] () -- C:\Windows\MEMORY.DMP
 
========== Files Created - No Company Name ==========
 
[2012.01.20 17:45:51 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.13 11:10:29 | 000,937,326 | ---- | C] () -- C:\Users\Sebastian\Desktop\Pathologie_Altklausuren_speziellePathologie.pdf
[2012.01.13 11:10:29 | 000,679,262 | ---- | C] () -- C:\Users\Sebastian\Desktop\Klausur_Pathologie_Orofaciales_System.pdf
[2012.01.12 12:15:37 | 000,031,931 | ---- | C] () -- C:\Users\Sebastian\Desktop\ConfirmationMail.aspx.htm
[2012.01.03 21:28:50 | 245,308,330 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011.05.05 14:29:48 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib
[2011.01.18 16:39:00 | 000,081,408 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV86.sys
[2010.12.27 18:35:20 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.03.10 16:33:31 | 000,000,551 | ---- | C] () -- C:\Users\Sebastian\AppData\Roaming\AutoGK.ini
[2009.09.23 23:46:04 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009.09.12 20:32:54 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.12 20:32:54 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.09.12 20:32:22 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009.09.12 20:32:17 | 001,271,989 | R-S- | C] () -- C:\Users\Sebastian\AppData\Roaming\igfxtray.dat
[2009.06.03 21:03:12 | 000,000,680 | ---- | C] () -- C:\Users\Sebastian\AppData\Local\d3d9caps.dat
[2009.05.30 01:37:40 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009.05.30 01:31:52 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009.01.29 19:16:17 | 000,005,381 | ---- | C] () -- C:\Windows\System32\dmlg.dat
[2008.12.06 20:00:20 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
[2008.12.06 19:51:07 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2008.10.02 08:52:48 | 000,116,224 | ---- | C] () -- C:\Users\Sebastian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.10.01 17:27:19 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2008.07.09 07:09:20 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2008.07.08 15:50:18 | 000,000,684 | ---- | C] () -- C:\Windows\HotFixList.ini
[2008.07.08 15:39:09 | 000,242,173 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2008.07.08 15:39:09 | 000,242,173 | ---- | C] () -- C:\ProgramData\nvModes.001
[2008.07.08 15:32:17 | 000,307,200 | ---- | C] () -- C:\Windows\SetDisplayResolution.exe
[2008.07.08 15:31:32 | 000,000,135 | R--- | C] () -- C:\Windows\System32\lngEng.ini
[2008.07.08 15:31:32 | 000,000,117 | ---- | C] () -- C:\Windows\System32\lngKor.ini
[2008.07.08 15:18:03 | 000,040,960 | ---- | C] () -- C:\Windows\System32\IhDEV.exe
[2008.07.08 15:18:02 | 000,024,576 | ---- | C] () -- C:\Windows\System32\IhINF.exe
[2008.07.08 13:54:14 | 000,618,442 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008.07.08 13:54:14 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008.07.08 13:54:14 | 000,122,842 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008.07.08 13:54:14 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2008.07.08 13:45:50 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008.02.09 17:03:07 | 000,024,576 | ---- | C] () -- C:\Windows\System32\drivers\Marker.exe
[2007.02.26 08:49:12 | 006,139,774 | ---- | C] () -- C:\Windows\System32\imagine digital freedom.dat
[2007.02.15 08:51:02 | 000,274,432 | ---- | C] () -- C:\Windows\System32\NDADLL.dll
[2007.02.05 19:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2006.11.29 09:00:30 | 000,045,056 | ---- | C] () -- C:\Windows\System32\MAWebControl.exe
[2006.11.29 09:00:28 | 000,307,200 | ---- | C] () -- C:\Windows\System32\LDBGenWizView.dll
[2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:47:37 | 000,376,368 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 11:33:01 | 000,587,178 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,101,250 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:25:21 | 000,061,440 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.10.09 02:01:28 | 000,061,440 | ---- | C] () -- C:\Windows\System32\AVSAudioWideStereoDMO.dll
[2003.02.20 16:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
[2001.11.14 04:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
 
========== LOP Check ==========
 
[2010.03.22 19:35:23 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Degener
[2011.11.05 10:31:12 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\DVDVideoSoft
[2011.11.05 10:30:23 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.03.22 19:35:36 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Ebner
[2011.12.01 20:53:43 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\go
[2012.01.18 18:23:02 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\ICQ
[2011.10.31 14:52:44 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\MicroST
[2011.03.05 18:30:55 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\phonostar GmbH
[2011.01.05 21:46:24 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\ProtectDisc
[2011.03.30 13:18:12 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Samsung
[2010.02.04 22:10:55 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Sony
[2010.02.04 22:10:55 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Sony Setup
[2011.05.16 12:48:21 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Thunderbird
[2010.01.22 00:34:15 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\VistaCodecs
[2012.01.20 16:13:21 | 000,032,530 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.01.20 20:26:23 | 000,000,426 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{79EFB1BF-C914-49BB-A75F-232FC7288BAD}.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*. >
[2008.09.30 21:28:51 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2008.07.08 15:56:07 | 000,000,000 | ---D | M] -- C:\avs contents
[2010.06.19 13:09:14 | 000,000,000 | -HSD | M] -- C:\Boot
[2006.11.02 14:02:03 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2008.09.30 21:24:41 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2009.03.05 21:02:35 | 000,000,000 | ---D | M] -- C:\DVDVideoSoft
[2008.07.08 15:11:45 | 000,000,000 | ---D | M] -- C:\Intel
[2011.04.04 07:58:11 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2008.07.08 15:26:32 | 000,000,000 | ---D | M] -- C:\MyWorks
[2008.01.21 03:32:31 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2012.01.20 17:45:47 | 000,000,000 | R--D | M] -- C:\Program Files
[2012.01.20 17:45:49 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2008.09.30 21:24:41 | 000,000,000 | -HSD | M] -- C:\Programme
[2008.07.08 15:36:25 | 000,000,000 | ---D | M] -- C:\Samsung
[2012.01.20 20:54:44 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2008.09.30 21:25:19 | 000,000,000 | R--D | M] -- C:\Users
[2012.01.20 14:38:06 | 000,000,000 | ---D | M] -- C:\Windows
 
< %PROGRAMFILES%\*.exe >
 
< %LOCALAPPDATA%\*.exe >
 
< %systemroot%\*. /mp /s >
 
 
< MD5 for: AGP440.SYS  >
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\drivers\atapi.sys
[2008.01.21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EXPLORER.EXE  >
[2008.10.29 07:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008.10.29 07:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008.10.30 04:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008.10.28 03:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008.01.21 03:24:24 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
 
< MD5 for: IASTOR.SYS  >
[2008.06.16 13:38:28 | 000,396,312 | ---- | M] (Intel Corporation) MD5=DB0C1076AB442C09D2A3AB0410DBEA0D -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2008.06.16 13:38:10 | 000,318,488 | ---- | M] (Intel Corporation) MD5=F263A9036F8897FFA2AE54685E03AD60 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008.06.16 13:38:10 | 000,318,488 | ---- | M] (Intel Corporation) MD5=F263A9036F8897FFA2AE54685E03AD60 -- C:\Windows\System32\drivers\iaStor.sys
[2008.06.16 13:38:10 | 000,318,488 | ---- | M] (Intel Corporation) MD5=F263A9036F8897FFA2AE54685E03AD60 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_3506096f\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 03:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008.01.21 03:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.21 03:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.21 03:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.21 03:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008.01.21 03:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.21 03:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 03:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2008.01.21 03:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 03:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.21 03:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2011.12.24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.01.21 03:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 03:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.21 03:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2008.01.21 04:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008.01.21 04:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008.01.21 04:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 11:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 11:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\system32\*.dll /lockedfiles >
 
< %USERPROFILE%\*.* >
[2011.01.18 11:36:40 | 000,000,375 | ---- | M] () -- C:\Users\Sebastian\Dokumente - Verknüpfung.lnk
[2012.01.20 20:51:57 | 007,077,888 | -HS- | M] () -- C:\Users\Sebastian\NTUSER.DAT
[2012.01.20 20:51:57 | 000,262,144 | -H-- | M] () -- C:\Users\Sebastian\ntuser.dat.LOG1
[2008.09.30 21:25:20 | 000,000,000 | -H-- | M] () -- C:\Users\Sebastian\ntuser.dat.LOG2
[2012.01.20 17:16:07 | 000,065,536 | -HS- | M] () -- C:\Users\Sebastian\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2011.05.25 08:16:51 | 000,524,288 | -HS- | M] () -- C:\Users\Sebastian\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2012.01.20 17:16:07 | 000,524,288 | -HS- | M] () -- C:\Users\Sebastian\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2008.09.30 21:25:22 | 000,000,020 | -HS- | M] () -- C:\Users\Sebastian\ntuser.ini
 
< %USERPROFILE%\Local Settings\Temp\*.exe >
 
< %USERPROFILE%\Local Settings\Temp\*.dll >
 
< %USERPROFILE%\Application Data\*.exe >
 
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
 
<          >
 
========== Files - Unicode (All) ==========
[2011.12.20 12:45:38 | 000,000,000 | ---D | M](C:\Users\Sebastian\Desktop\2011?12?15_Weihnachtsfeier der Kleinen) -- C:\Users\Sebastian\Desktop\20111215_Weihnachtsfeier der Kleinen
[2011.12.19 19:27:35 | 000,000,000 | ---D | C](C:\Users\Sebastian\Desktop\2011?12?15_Weihnachtsfeier der Kleinen) -- C:\Users\Sebastian\Desktop\20111215_Weihnachtsfeier der Kleinen

< End of report >

--- --- ---




Und hier die Extras:

OTL Logfile:
Code:

OTL Extras logfile created on: 20.01.2012 20:52:03 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Sebastian\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,99 Gb Total Physical Memory | 1,61 Gb Available Physical Memory | 53,93% Memory free
6,21 Gb Paging File | 4,85 Gb Available in Paging File | 78,07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,88 Gb Total Space | 66,91 Gb Free Space | 59,80% Space Free | Partition Type: NTFS
Drive D: | 111,00 Gb Total Space | 59,01 Gb Free Space | 53,16% Space Free | Partition Type: NTFS
Drive F: | 175,68 Mb Total Space | 62,05 Mb Free Space | 35,32% Space Free | Partition Type: FAT
Drive G: | 3,74 Gb Total Space | 3,65 Gb Free Space | 97,48% Space Free | Partition Type: FAT32
 
Computer Name: SEBASTIAN-PC | User Name: Sebastian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VLC-Player\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VLC-Player\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A877D03-721D-41C6-A733-87A46B4F8CE6}" = rport=10243 | protocol=6 | dir=out | app=system |
"{13BAB6E1-5E72-496B-BCF3-CBDC0875A288}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2A65F6B3-B1F2-4BBE-9212-166369723E1F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4DD2CA32-8710-4154-9ADB-E3B5A014FD87}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{854172A8-3A50-4DA1-A147-65F7934772F1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{856B4972-BB0D-4948-971B-5FB53B63B93F}" = lport=2869 | protocol=6 | dir=in | app=system |
"{986D3A26-EAC9-4B39-B0E9-5642EB9ABBC6}" = lport=10243 | protocol=6 | dir=in | app=system |
"{B03AA3E2-1C8D-4558-A7C2-0370292150BE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BCCDD253-F72E-47CD-AF81-05F22F5B6D91}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0AA04D24-C54C-40A7-9A61-154472E367AF}" = protocol=17 | dir=in | app=c:\program files\icq7.4\icq.exe |
"{0BB73B86-0A51-4435-A810-05C389A43A4E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1E06100E-9E96-4B34-9769-AF317795888A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{259134DC-6E3F-4C92-B41A-94CCB85FA0A0}" = protocol=17 | dir=in | app=c:\program files\icq7.4\icq.exe |
"{2B215F58-FCC5-4201-B018-7D5A460217DB}" = protocol=6 | dir=in | app=c:\program files\icq7.4\icq.exe |
"{308793C0-9797-4E7F-956B-27E1088BE048}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3B3D5A16-5AC7-465B-8A15-89D8967A6522}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4BEC3D94-8502-4E1A-B3FA-536EC82967BE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4FB2096D-355A-4A6D-A4F6-DEDEEA979BF7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{83101E8C-D212-4A5B-AC8A-164BE49D44DC}" = protocol=6 | dir=in | app=c:\program files\icq7.4\icq.exe |
"{8371EF81-45B8-41E7-BA3F-6418D2906A95}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8D4EE8F6-3202-4463-BC65-D33DC715D8F0}" = protocol=17 | dir=in | app=c:\program files\icq7.4\icq.exe |
"{9237853D-D0F4-4378-BA25-C7C7A09FAD26}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A8284383-B7CE-4D2A-B5B3-2D5344D354B7}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{C1DFFEA9-E13B-4D27-837C-084E8E7D62FF}" = protocol=6 | dir=in | app=c:\program files\icq7.4\icq.exe |
"{C2D467CA-D0B1-48A0-95C1-AF093722C107}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D7A3F52E-317E-4A88-B9BC-580BD7F45F29}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E42499E9-429B-423D-8D31-72BCCB49AE0A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E75CBF35-506F-418D-825D-14AC26E40972}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe |
"{EC3C7761-B41F-4927-8567-5D0AB007ED0F}" = protocol=6 | dir=out | app=system |
"{FFE802C9-B147-4651-9BE1-5B48A6CDC045}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"TCP Query User{00B38D76-B5A2-47FC-B9E6-C1571892E8D4}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{0A07B8C2-4DB5-4B7A-AF49-692386947145}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{B06676D2-2EEE-4EEC-8C81-BFBC66948C70}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{B2FFAD81-0268-49E6-BD34-1ADFB084BDBA}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{C5EE0BC3-34D5-4DD7-A029-E01C6B2EB22C}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{CB85EAA3-5927-41C1-B869-4A648A5A6D7A}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{E9F9A413-3E93-4F51-A55D-3CF40F56E203}C:\users\sebastian\desktop\cod 1.5\cod 1.5\codmp.exe" = protocol=6 | dir=in | app=c:\users\sebastian\desktop\cod 1.5\cod 1.5\codmp.exe |
"TCP Query User{FC83A74C-1DD8-4305-A5D1-FEFA7143B583}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{034D1930-2770-44D8-B6D6-0AF5C0616D7C}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{09C4ECD7-FE4F-4A8D-8DE4-D01D70C7090A}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{23E8407B-2924-400F-A3C4-2E3E09C15DFB}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{34509D7B-EAD4-45F1-AC3B-98054F111FA8}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{378C5A77-0395-48AE-A9E2-9FBDD6914975}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{6E4BF4D9-A780-4467-A885-2D74CFA487D9}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{8C504034-1F84-4896-A78C-FE4B2C82F2DD}C:\users\sebastian\desktop\cod 1.5\cod 1.5\codmp.exe" = protocol=17 | dir=in | app=c:\users\sebastian\desktop\cod 1.5\cod 1.5\codmp.exe |
"UDP Query User{F4B8F368-85FF-4876-A17A-A66AE096F098}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00AF10C1-44BD-4862-9D7F-24E6BA3E87FD}" = imagine digital freedom - Samsung
"{0138F525-6C8A-333F-A105-14AE030B9A54}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.6300
"{04983D37-2202-4295-94A2-8B547C66133F}" = Atheros WLAN Client
"{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch)
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation(R)Store
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP620_series" = Canon MP620 series MP Drivers
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution III
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 29
"{2DFB5485-A3EF-4298-9280-4AF80C9F4BE9}" = Microsoft SQL Server VSS Writer
"{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Samsung Magic Doctor
"{36BEAD11-8577-49AD-9250-E06A50AE87B0}" = Microsoft SOAP Toolkit 2.0 SP2
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"{547DCEC7-DD2A-47E9-82C7-5CF1EAB526DA}" = Microsoft SQL Server Native Client
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Easy Battery Manager
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71A51B09-E7D3-11DB-A386-005056C00008}" = Vimicro UVC Camera
"{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37}" = ICQ7.4
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{804F1285-8CBF-408D-8CDC-D4D40003B2E4}" = PlayCamera
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90A40407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1031-7B44-A81300000003}" = Adobe Reader 8.1.3 - Deutsch
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation(R)Network Downloader
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BA5F3E0E-8F3E-47BD-88E4-AD3EB5225F51}" = Intel(R) PROSet/Wireless WiFi-Software
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{BC3804E5-77CC-47A0-8BD5-797355A26BA3}" = WD SmartWare
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony Ericsson PC Companion 2.02.002
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}" = Vista Codec Package
"{FBE5AA96-22F0-4C4A-8E92-4BE3498D4CCB}" = Media Go
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Avira AntiVir Desktop" = Avira Free Antivirus
"Avira UnErase Personal" = Avira UnErase Personal
"CamStudio" = CamStudio
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"dradio-Recorder_is1" = dradio-Recorder Version 3.02.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"InstallShield_{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.0.1800
"Mediscript-CD GK1" = Mediscript-CD GK1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 9.0.1 (x86 de)" = Mozilla Firefox 9.0.1 (x86 de)
"Mozilla Thunderbird 9.0.1 (x86 de)" = Mozilla Thunderbird 9.0.1 (x86 de)
"NVIDIA Drivers" = NVIDIA Drivers
"PriceGong" = PriceGong 2.5.4
"ProInst" = Intel PROSet Wireless
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TIPP10_is1" = TIPP10 Version 2.1.0
"Uninstall_is1" = Uninstall 1.0.0.0
"VLC media player" = VLC media player 1.0.3
"WinRAR archiver" = WinRAR
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 19.01.2012 12:59:59 | Computer Name = Sebastian-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 19.01.2012 18:15:04 | Computer Name = Sebastian-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 20.01.2012 03:48:40 | Computer Name = Sebastian-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 20.01.2012 06:23:47 | Computer Name = Sebastian-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 20.01.2012 09:11:44 | Computer Name = Sebastian-PC | Source = VSS | ID = 8194
Description =
 
Error - 20.01.2012 09:41:27 | Computer Name = Sebastian-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 20.01.2012 10:20:07 | Computer Name = Sebastian-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 20.01.2012 11:14:41 | Computer Name = Sebastian-PC | Source = EventSystem | ID = 4609
Description =
 
Error - 20.01.2012 11:15:20 | Computer Name = Sebastian-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 20.01.2012 12:17:34 | Computer Name = Sebastian-PC | Source = WinMgmt | ID = 10
Description =
 
[ System Events ]
Error - 20.01.2012 11:15:20 | Computer Name = Sebastian-PC | Source = Service Control Manager | ID = 7001
Description =
 
Error - 20.01.2012 11:15:20 | Computer Name = Sebastian-PC | Source = Service Control Manager | ID = 7001
Description =
 
Error - 20.01.2012 11:15:30 | Computer Name = Sebastian-PC | Source = Service Control Manager | ID = 7001
Description =
 
Error - 20.01.2012 11:16:29 | Computer Name = Sebastian-PC | Source = Service Control Manager | ID = 7001
Description =
 
Error - 20.01.2012 12:17:35 | Computer Name = Sebastian-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 20.01.2012 12:18:15 | Computer Name = Sebastian-PC | Source = DCOM | ID = 10016
Description =
 
Error - 20.01.2012 12:20:14 | Computer Name = Sebastian-PC | Source = Service Control Manager | ID = 7009
Description =
 
Error - 20.01.2012 12:20:14 | Computer Name = Sebastian-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 20.01.2012 12:23:27 | Computer Name = Sebastian-PC | Source = Service Control Manager | ID = 7022
Description =
 
Error - 20.01.2012 12:35:59 | Computer Name = Sebastian-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
 
 
< End of report >

--- --- ---


Ich danke im schon im voraus für Ihre Bemühungen!

cosinus 23.01.2012 14:08

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

sebastian356 23.01.2012 16:32

nein, ich habe malewarebytes zum ersten Mal benutzt (diese Seite hatte mich auf das Programm gebracht), ich dachte immer antivir in Kombination mit spybot wäre ausreichend..

cosinus 23.01.2012 16:46

Führ bitte auch ESET aus, danach sehen wir weiter:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


sebastian356 23.01.2012 20:18

danke erstmal für die schnelle hilfe!

ich hab eine externe festplatte, nur war diese nicht während des vorfalls und auch an dem tag nicht angeschlossen..hätte ich sie trotzdem mit anschließen müssen? bitte halte mich nicht für paranoid, aber wenn ich alles ausschalte und dann die festplatte auch noch ansteck, dann verlängert sich doch die ungeschütze zeit..von den daten auf der platte mal zu schweigen..
denn malwarebytes hatte doch angezeigt das ich da irgendwas drauf hab.

hier die log-file:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=ccff2162f96cb34fb05acc16abcd6586
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-23 07:06:11
# local_time=2012-01-23 08:06:11 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 7895736 7895736 0 0
# compatibility_mode=5892 16776573 100 100 79374 164877696 0 0
# compatibility_mode=8192 67108863 100 0 3872 3872 0 0
# scanned=17655
# found=0
# cleaned=0
# scan_time=603


hoffe sie ist hilfreich für dich.

besten gruß

cosinus 23.01.2012 21:51

Ja, mitscannen wäre besser gewesen

sebastian356 24.01.2012 20:09

ich habe es nochmal mit Festplatte durchlaufen lassen, komsicher weise hat er jetzt was gefunden, allerdings nicht auf der Festplatte..

hier die file:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=ccff2162f96cb34fb05acc16abcd6586
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-23 07:06:11
# local_time=2012-01-23 08:06:11 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 7895736 7895736 0 0
# compatibility_mode=5892 16776573 100 100 79374 164877696 0 0
# compatibility_mode=8192 67108863 100 0 3872 3872 0 0
# scanned=17655
# found=0
# cleaned=0
# scan_time=603
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=ccff2162f96cb34fb05acc16abcd6586
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-24 07:05:00
# local_time=2012-01-24 08:05:00 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 7975349 7975349 0 0
# compatibility_mode=5892 16776573 100 100 158987 164957309 0 0
# compatibility_mode=8192 67108863 100 0 83485 83485 0 0
# scanned=149958
# found=4
# cleaned=0
# scan_time=7318
C:\Program Files\VistaCodecPack\Tools\Settings32.exe Win32/Packed.Autoit.C.Gen application (unable to clean) 00000000000000000000000000000000 I
C:\ProgramData\VistaCodecs\{3161B7F4-69FC-4FB6-9842-BC00F231CBEF}\Vista Codec Package.msi Win32/Packed.Autoit.C.Gen application (unable to clean) 00000000000000000000000000000000 I
C:\Users\All Users\VistaCodecs\{3161B7F4-69FC-4FB6-9842-BC00F231CBEF}\Vista Codec Package.msi Win32/Packed.Autoit.C.Gen application (unable to clean) 00000000000000000000000000000000 I
C:\Users\Sebastian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\3952cc99-4ed09678 Java/Exploit.CVE-2011-3544.AB trojan (unable to clean) 00000000000000000000000000000000 I


hoffe du kannst mir jetzt helfen.

cosinus 24.01.2012 20:57

Hattest du mit Malwarebytes die ext. Platte mit durchsuchen lassen?

Offensichtlich hast du auch nicht die Funde entfernt mit Malwarebytes...bzgl Malwarebytes lt. Anleitung die FUnde immer löschen, nur bei den anderen hier eingesetzten Tools hier nicht.

sebastian356 24.01.2012 21:50

nein, malewarebytes hab ich auf dem Rechner laufen lassen.
Okay, dann lass ich malewarebytes die infizierten Dateien entfernen, ich hatte nur in einem anderen Beitrag gelesen das man das nicht machen soll, da die Sicherheitslücken dann immer noch da sind (ich hatte vermutet Ihr braucht die Namen damit Ihr wisst wo das Problem ist).
Nachdem malewarebytes seine Arbeit getan hat wie sehen die nächsten Schritte aus?

cosinus 24.01.2012 22:17

Zitat:

nein, malewarebytes hab ich auf dem Rechner laufen lassen.
Wenn nur die Platte des Rechners, dann mach auch einen Vollscan auf die externe Platte. Also nachholen falls nicht gemacht.

Zitat:

ich hatte nur in einem anderen Beitrag gelesen das man das nicht machen soll, da die Sicherheitslücken dann immer noch da sind (ich hatte vermutet Ihr braucht die Namen damit Ihr wisst wo das Problem ist).
Wie auch immer, was Malwarebytes findet, kann getrost gelöscht werden (Malwarebytes hat eine eigene Q und notfalls kann man gelöschte Dateien wiederherstellen)

sebastian356 25.01.2012 15:33

ich habe malewarebytes seine arbeit machen lassen (mit Festplatte) hier die Daten:

Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.20.02

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19170
Sebastian :: SEBASTIAN-PC [Administrator]

24.01.2012 21:51:51
mbam-log-2012-01-24 (21-51-51).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 304382
Laufzeit: 2 Stunde(n), 1 Minute(n), 19 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|vasja (Trojan.RansomP.Gen) -> Daten: C:\Users\SEBAST~1\AppData\Local\Temp\wpbt0.dll -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\Sebastian\AppData\Roaming\igfxtray.dat (Malware.Trace) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


Danach hab ich nochmal den eset scanner durchlaufen lassen:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=ccff2162f96cb34fb05acc16abcd6586
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-23 07:06:11
# local_time=2012-01-23 08:06:11 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 7895736 7895736 0 0
# compatibility_mode=5892 16776573 100 100 79374 164877696 0 0
# compatibility_mode=8192 67108863 100 0 3872 3872 0 0
# scanned=17655
# found=0
# cleaned=0
# scan_time=603
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=ccff2162f96cb34fb05acc16abcd6586
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-24 07:05:00
# local_time=2012-01-24 08:05:00 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 7975349 7975349 0 0
# compatibility_mode=5892 16776573 100 100 158987 164957309 0 0
# compatibility_mode=8192 67108863 100 0 83485 83485 0 0
# scanned=149958
# found=4
# cleaned=0
# scan_time=7318
C:\Program Files\VistaCodecPack\Tools\Settings32.exe Win32/Packed.Autoit.C.Gen application (unable to clean) 00000000000000000000000000000000 I
C:\ProgramData\VistaCodecs\{3161B7F4-69FC-4FB6-9842-BC00F231CBEF}\Vista Codec Package.msi Win32/Packed.Autoit.C.Gen application (unable to clean) 00000000000000000000000000000000 I
C:\Users\All Users\VistaCodecs\{3161B7F4-69FC-4FB6-9842-BC00F231CBEF}\Vista Codec Package.msi Win32/Packed.Autoit.C.Gen application (unable to clean) 00000000000000000000000000000000 I
C:\Users\Sebastian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\3952cc99-4ed09678 Java/Exploit.CVE-2011-3544.AB trojan (unable to clean) 00000000000000000000000000000000 I
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=ccff2162f96cb34fb05acc16abcd6586
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-25 11:32:41
# local_time=2012-01-25 12:32:41 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 8034305 8034305 0 0
# compatibility_mode=5892 16776573 100 100 41464 165016265 0 0
# compatibility_mode=8192 67108863 100 0 142441 142441 0 0
# scanned=150158
# found=4
# cleaned=0
# scan_time=7623
C:\Program Files\VistaCodecPack\Tools\Settings32.exe Win32/Packed.Autoit.C.Gen application (unable to clean) 00000000000000000000000000000000 I
C:\ProgramData\VistaCodecs\{3161B7F4-69FC-4FB6-9842-BC00F231CBEF}\Vista Codec Package.msi Win32/Packed.Autoit.C.Gen application (unable to clean) 00000000000000000000000000000000 I
C:\Users\All Users\VistaCodecs\{3161B7F4-69FC-4FB6-9842-BC00F231CBEF}\Vista Codec Package.msi Win32/Packed.Autoit.C.Gen application (unable to clean) 00000000000000000000000000000000 I
C:\Users\Sebastian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\3952cc99-4ed09678 Java/Exploit.CVE-2011-3544.AB trojan (unable to clean) 00000000000000000000000000000000 I


wie schauen die nächsten Schritte aus?

cosinus 25.01.2012 16:21

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


sebastian356 25.01.2012 18:31

oh, sorry.. hier die Daten in platzsparender Form:

OTL Logfile:
Code:

OTL logfile created on: 25.01.2012 18:13:22 - Run 2
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Sebastian\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,99 Gb Total Physical Memory | 1,84 Gb Available Physical Memory | 61,41% Memory free
6,18 Gb Paging File | 5,03 Gb Available in Paging File | 81,36% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,88 Gb Total Space | 67,06 Gb Free Space | 59,94% Space Free | Partition Type: NTFS
Drive D: | 111,00 Gb Total Space | 58,61 Gb Free Space | 52,80% Space Free | Partition Type: NTFS
Drive E: | 7,50 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
 
Computer Name: SEBASTIAN-PC | User Name: Sebastian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.01.20 20:43:39 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Sebastian\Downloads\OTL.exe
PRC - [2011.10.11 14:00:02 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.10.11 13:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2011.10.11 13:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.10.11 13:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.06.20 17:05:30 | 000,040,960 | ---- | M] () -- C:\Programme\dradio-Recorder\phonostarTimer.exe
PRC - [2011.03.09 10:18:06 | 001,060,864 | ---- | M] () -- C:\Programme\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe
PRC - [2011.03.09 10:16:56 | 000,484,352 | ---- | M] () -- C:\Programme\Western Digital\WD SmartWare\Front Parlor\WDSC.exe
PRC - [2011.03.09 10:09:54 | 003,986,944 | ---- | M] (Western Digital Technologies, Inc.) -- C:\Programme\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
PRC - [2011.03.09 10:07:54 | 000,238,592 | ---- | M] (WDC) -- C:\Programme\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
PRC - [2009.04.11 07:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.03.05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Programme\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008.05.23 06:11:56 | 000,819,200 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe
PRC - [2008.05.23 05:43:52 | 000,466,944 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe
PRC - [2008.05.22 09:33:54 | 000,688,128 | ---- | M] (SAMSUNG Electronics) -- C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2008.05.13 00:47:20 | 000,077,480 | ---- | M] () -- C:\Programme\Samsung\Samsung Update Plus\SLUBackgroundService.exe
PRC - [2008.04.25 13:31:34 | 000,565,248 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2008.04.17 07:26:46 | 000,352,256 | ---- | M] (SAMSUNG Electronics co., LTD.) -- C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe
PRC - [2008.04.17 03:50:00 | 006,111,232 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008.02.12 05:19:52 | 000,723,496 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2008.01.21 03:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2008.01.21 03:25:33 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
PRC - [2008.01.21 03:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Defender\MSASCui.exe
PRC - [2007.07.04 23:41:42 | 000,045,056 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.06.20 17:05:30 | 000,040,960 | ---- | M] () -- C:\Programme\dradio-Recorder\phonostarTimer.exe
MOD - [2011.06.15 14:07:10 | 002,293,248 | ---- | M] () -- C:\Programme\dradio-Recorder\QtCore4.dll
MOD - [2011.03.30 11:46:40 | 000,416,256 | ---- | M] () -- C:\Programme\dradio-Recorder\plugins\sqldrivers\qsqlite4.dll
MOD - [2011.03.30 08:16:34 | 008,173,568 | ---- | M] () -- C:\Programme\dradio-Recorder\QtGui4.dll
MOD - [2011.03.30 07:59:40 | 000,191,488 | ---- | M] () -- C:\Programme\dradio-Recorder\QtSql4.dll
MOD - [2006.08.12 04:48:40 | 000,049,152 | ---- | M] () -- C:\Programme\Samsung\Samsung Magic Doctor\HookDllPS2.dll
MOD - [2006.08.12 04:48:40 | 000,049,152 | ---- | M] () -- C:\Programme\Samsung\EasySpeedUpManager\HookDllPS2.dll
MOD - [2006.08.12 04:48:40 | 000,049,152 | ---- | M] () -- C:\Programme\Samsung\Easy Display Manager\HookDllPS2.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.10.11 13:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.10.11 13:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.06.29 14:59:18 | 000,155,344 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe -- (Sony Ericsson PCCompanion)
SRV - [2011.03.09 10:18:06 | 001,060,864 | ---- | M] () [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe -- (WDFME)
SRV - [2011.03.09 10:16:56 | 000,484,352 | ---- | M] () [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe -- (WDSC)
SRV - [2011.03.09 10:07:54 | 000,238,592 | ---- | M] (WDC) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe -- (WDDMService)
SRV - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Programme\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008.05.23 06:11:56 | 000,819,200 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV - [2008.05.23 05:43:52 | 000,466,944 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV - [2008.05.13 00:47:20 | 000,077,480 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe -- (Samsung Update Plus)
SRV - [2008.01.21 03:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.12.09 11:44:05 | 000,134,856 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.10.11 14:00:01 | 000,074,640 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.10.11 14:00:01 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011.02.16 15:52:46 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2011.01.18 16:39:00 | 000,081,408 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\SSHDRV86.sys -- (SSHDRV86)
DRV - [2010.06.17 14:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.03.25 16:48:00 | 000,114,728 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018mdm.sys -- (s1018mdm)
DRV - [2009.03.25 16:48:00 | 000,109,864 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018unic.sys -- (s1018unic) Sony Ericsson Device 1018 USB Ethernet Emulation (WDM)
DRV - [2009.03.25 16:48:00 | 000,106,208 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018mgmt.sys -- (s1018mgmt) Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM)
DRV - [2009.03.25 16:48:00 | 000,104,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018obex.sys -- (s1018obex)
DRV - [2009.03.25 16:48:00 | 000,086,824 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018bus.sys -- (s1018bus) Sony Ericsson Device 1018 driver (WDM)
DRV - [2009.03.25 16:48:00 | 000,026,024 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018nd5.sys -- (s1018nd5) Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS)
DRV - [2009.03.25 16:48:00 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018mdfl.sys -- (s1018mdfl)
DRV - [2008.07.30 06:51:30 | 000,277,736 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2008.06.08 23:23:00 | 007,522,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008.05.20 20:36:12 | 003,663,360 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32) Intel(R)
DRV - [2008.04.05 06:56:26 | 000,242,560 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vmc302.sys -- (VMC302)
DRV - [2008.01.21 03:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2008.01.21 03:23:20 | 002,225,664 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32) Intel(R)
DRV - [2008.01.09 12:28:34 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\seehcri.sys -- (seehcri)
DRV - [2007.09.13 07:17:58 | 000,755,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2007.05.23 09:13:10 | 000,013,312 | ---- | M] (SAMSUNG ELECTRONICS CO., LTD.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\KMDFMEMIO.sys -- (KMDFMEMIO)
DRV - [2006.11.28 08:11:00 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006.11.02 08:30:53 | 000,045,056 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006.07.24 16:05:00 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http:\\www.samsungcomputer.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: de-DE@dictionaries.addons.mozilla.org:2.0.2
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\VistaCodecPack\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: c:\Program Files\Sony\Media Go\npmediago.dll (Sony Creative Software Inc)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.3: C:\Program Files\VLC-Player\npvlc.dll (the VideoLAN Team)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.12.30 20:58:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.07.22 16:04:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011.10.17 14:53:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
 
[2011.05.16 12:48:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Extensions
[2011.05.16 12:48:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.01.11 16:52:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions
[2010.07.28 17:15:23 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.01.08 22:41:43 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012.01.07 18:58:16 | 000,000,000 | ---D | M] (PriceGong) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
[2011.12.24 21:29:26 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010.11.20 19:30:29 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2009.04.07 14:33:55 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\moveplayer@movenetworks.com
[2011.03.16 19:51:38 | 000,000,000 | ---D | M] (Personas) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\personas@christopher.beard
[2011.12.30 21:32:21 | 000,000,933 | ---- | M] () -- C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\bfgej6rs.default\searchplugins\11-suche.xml
[2011.12.30 21:32:21 | 000,002,419 | ---- | M] () -- C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\bfgej6rs.default\searchplugins\englische-ergebnisse.xml
[2011.12.30 21:32:21 | 000,010,525 | ---- | M] () -- C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\bfgej6rs.default\searchplugins\gmx-suche.xml
[2011.12.30 21:32:21 | 000,002,457 | ---- | M] () -- C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\bfgej6rs.default\searchplugins\lastminute.xml
[2011.12.30 21:32:21 | 000,005,508 | ---- | M] () -- C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\bfgej6rs.default\searchplugins\webde-suche.xml
[2011.12.30 20:58:32 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.11.04 08:31:18 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
() (No name found) -- C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\EXTENSIONS\TOOLBAR@WEB.DE.XPI
[2011.12.30 20:58:30 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.04 18:54:06 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.04 18:54:06 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.10.04 18:54:06 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.04 18:54:06 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.04 18:54:06 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.04 18:54:06 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.10.09 14:27:18 | 000,438,184 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        www.0scan.com
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        123topsearch.com
O1 - Hosts: 127.0.0.1        www.123topsearch.com
O1 - Hosts: 127.0.0.1        132.com
O1 - Hosts: 127.0.0.1        www.132.com
O1 - Hosts: 127.0.0.1        www.136136.net
O1 - Hosts: 15073 more lines...
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Programme\PriceGong\2.5.4\PriceGongIE.dll (PriceGong)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [dradio-RecorderTimer] C:\Programme\dradio-Recorder\phonostarTimer.exe ()
O4 - HKCU..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent File not found
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden File not found
O4 - HKCU..\Run: [Sony Ericsson PC Companion] C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe (Sony Ericsson)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1150600.exe -Update -1150600 -"Mozilla/5.0_(Windows_NT_6.0;_rv:6.0)_Gecko/20100101_Firefox/6.0" -"hxxp://cc.porsche.com/icc_euro/ui/pva/application/bpModules/interior_3D.jsp;jsessionid=6AFCEEFEA0D1FE4785165A1CAC41C5A1?RT=1314713697690" File not found
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Programs\PartyPoker\PartyPokerNet\RunPF.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Programs\PartyPoker\PartyPokerNet\RunPF.exe File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7BDFCF9E-F356-427F-853E-604C5BF6E37D}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DECB8486-47A8-4DB0-A326-AAD9748969B5}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{3c325060-917a-11df-b067-0013779ffed3}\Shell - "" = AutoRun
O33 - MountPoints2\{3c325060-917a-11df-b067-0013779ffed3}\Shell\AutoRun\command - "" = F:\setup.exe AUTORUN=1
O33 - MountPoints2\{e43923ef-11b9-11df-8e97-0013779ffed3}\Shell - "" = AutoRun
O33 - MountPoints2\{e43923ef-11b9-11df-8e97-0013779ffed3}\Shell\AutoRun\command - "" = F:\Startme.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.avis - C:\Windows\System32\ff_acm.acm ()
Drivers32: msacm.clmp3enc - C:\Programme\CyberLink\Power2Go\CLMP3Enc.ACM (CyberLink Corp.)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.01.23 19:51:36 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.01.20 17:47:28 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\Malwarebytes
[2012.01.20 17:45:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.01.20 17:45:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.01.20 17:45:47 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.01.20 17:45:47 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.01.18 17:34:40 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Animake
[2012.01.18 17:34:37 | 000,000,000 | ---D | C] -- C:\Program Files\Animake
[2012.01.12 12:15:39 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\Desktop\ConfirmationMail.aspx-Dateien
[2012.01.07 18:58:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong
[2012.01.07 18:58:15 | 000,000,000 | ---D | C] -- C:\Program Files\PriceGong
[2011.12.31 13:10:56 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\Desktop\RR Bilder
[2009.11.30 20:05:51 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\ProgramData\hpe9CCB.dll
[2009.07.31 09:30:15 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\ProgramData\hpe9AEF.dll
[2006.11.24 06:14:44 | 000,139,264 | ---- | C] ( ) -- C:\Windows\System32\MACSSDK_wiz.dll
[2006.11.24 06:14:44 | 000,126,976 | ---- | C] ( ) -- C:\Windows\System32\MACSSDK.dll
 
========== Files - Modified Within 30 Days ==========
 
[2012.01.25 18:11:14 | 000,242,173 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2012.01.25 18:11:14 | 000,242,173 | ---- | M] () -- C:\ProgramData\nvModes.001
[2012.01.25 18:08:55 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.01.25 18:08:55 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.01.25 18:08:54 | 000,005,530 | ---- | M] () -- C:\Windows\System32\dmlg.dat
[2012.01.25 18:08:34 | 000,001,100 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.01.25 18:08:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.01.25 15:53:53 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.01.25 12:01:06 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.01.24 21:55:53 | 000,618,442 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.01.24 21:55:53 | 000,587,178 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.01.24 21:55:53 | 000,122,842 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.01.24 21:55:53 | 000,101,250 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.01.24 21:47:41 | 000,000,426 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{79EFB1BF-C914-49BB-A75F-232FC7288BAD}.job
[2012.01.20 17:45:51 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.20 13:30:38 | 000,116,224 | ---- | M] () -- C:\Users\Sebastian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.01.12 12:15:40 | 000,031,931 | ---- | M] () -- C:\Users\Sebastian\Desktop\ConfirmationMail.aspx.htm
[2012.01.03 21:28:50 | 245,308,330 | ---- | M] () -- C:\Windows\MEMORY.DMP
 
========== Files Created - No Company Name ==========
 
[2012.01.20 17:45:51 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.12 12:15:37 | 000,031,931 | ---- | C] () -- C:\Users\Sebastian\Desktop\ConfirmationMail.aspx.htm
[2012.01.03 21:28:50 | 245,308,330 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011.05.05 14:29:48 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib
[2011.01.18 16:39:00 | 000,081,408 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV86.sys
[2010.12.27 18:35:20 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.03.10 16:33:31 | 000,000,551 | ---- | C] () -- C:\Users\Sebastian\AppData\Roaming\AutoGK.ini
[2009.09.23 23:46:04 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009.09.12 20:32:54 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.12 20:32:54 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.09.12 20:32:22 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009.06.03 21:03:12 | 000,000,680 | ---- | C] () -- C:\Users\Sebastian\AppData\Local\d3d9caps.dat
[2009.05.30 01:37:40 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009.05.30 01:31:52 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009.01.29 19:16:17 | 000,005,530 | ---- | C] () -- C:\Windows\System32\dmlg.dat
[2008.12.06 20:00:20 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
[2008.12.06 19:51:07 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2008.10.02 08:52:48 | 000,116,224 | ---- | C] () -- C:\Users\Sebastian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.10.01 17:27:19 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2008.07.09 07:09:20 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2008.07.08 15:50:18 | 000,000,684 | ---- | C] () -- C:\Windows\HotFixList.ini
[2008.07.08 15:39:09 | 000,242,173 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2008.07.08 15:39:09 | 000,242,173 | ---- | C] () -- C:\ProgramData\nvModes.001
[2008.07.08 15:32:17 | 000,307,200 | ---- | C] () -- C:\Windows\SetDisplayResolution.exe
[2008.07.08 15:31:32 | 000,000,135 | R--- | C] () -- C:\Windows\System32\lngEng.ini
[2008.07.08 15:31:32 | 000,000,117 | ---- | C] () -- C:\Windows\System32\lngKor.ini
[2008.07.08 15:18:03 | 000,040,960 | ---- | C] () -- C:\Windows\System32\IhDEV.exe
[2008.07.08 15:18:02 | 000,024,576 | ---- | C] () -- C:\Windows\System32\IhINF.exe
[2008.07.08 13:54:14 | 000,618,442 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008.07.08 13:54:14 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008.07.08 13:54:14 | 000,122,842 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008.07.08 13:54:14 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2008.07.08 13:45:50 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008.02.09 17:03:07 | 000,024,576 | ---- | C] () -- C:\Windows\System32\drivers\Marker.exe
[2007.02.26 08:49:12 | 006,139,774 | ---- | C] () -- C:\Windows\System32\imagine digital freedom.dat
[2007.02.15 08:51:02 | 000,274,432 | ---- | C] () -- C:\Windows\System32\NDADLL.dll
[2007.02.05 19:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2006.11.29 09:00:30 | 000,045,056 | ---- | C] () -- C:\Windows\System32\MAWebControl.exe
[2006.11.29 09:00:28 | 000,307,200 | ---- | C] () -- C:\Windows\System32\LDBGenWizView.dll
[2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:47:37 | 000,376,368 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 11:33:01 | 000,587,178 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,101,250 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:25:21 | 000,061,440 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.10.09 02:01:28 | 000,061,440 | ---- | C] () -- C:\Windows\System32\AVSAudioWideStereoDMO.dll
[2003.02.20 16:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
[2001.11.14 04:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
 
========== LOP Check ==========
 
[2010.03.22 19:35:23 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Degener
[2011.11.05 10:31:12 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\DVDVideoSoft
[2011.11.05 10:30:23 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.03.22 19:35:36 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Ebner
[2011.12.01 20:53:43 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\go
[2012.01.18 18:23:02 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\ICQ
[2011.10.31 14:52:44 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\MicroST
[2011.03.05 18:30:55 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\phonostar GmbH
[2011.01.05 21:46:24 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\ProtectDisc
[2011.03.30 13:18:12 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Samsung
[2010.02.04 22:10:55 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Sony
[2010.02.04 22:10:55 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Sony Setup
[2011.05.16 12:48:21 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Thunderbird
[2010.01.22 00:34:15 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\VistaCodecs
[2012.01.25 15:53:53 | 000,032,530 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.01.24 21:47:41 | 000,000,426 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{79EFB1BF-C914-49BB-A75F-232FC7288BAD}.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2008.10.10 09:40:35 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Adobe
[2011.10.24 10:41:18 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Avira
[2009.03.01 16:50:18 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\CyberLink
[2010.03.22 19:35:23 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Degener
[2009.11.21 20:49:38 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\DivX
[2012.01.20 13:29:51 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\dvdcss
[2011.11.05 10:31:12 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\DVDVideoSoft
[2011.11.05 10:30:23 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.03.22 19:35:36 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Ebner
[2011.12.01 20:53:43 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\go
[2012.01.18 18:23:02 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\ICQ
[2008.09.30 21:27:46 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Identities
[2008.10.01 16:20:51 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Macromedia
[2012.01.20 17:47:28 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Malwarebytes
[2006.11.02 13:37:34 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Media Center Programs
[2011.10.08 10:09:47 | 000,000,000 | --SD | M] -- C:\Users\Sebastian\AppData\Roaming\Microsoft
[2011.10.31 14:52:44 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\MicroST
[2008.10.25 13:03:29 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Mozilla
[2011.03.05 18:30:55 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\phonostar GmbH
[2011.01.05 21:46:24 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\ProtectDisc
[2011.03.30 13:18:12 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Samsung
[2012.01.25 18:09:47 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Skype
[2011.05.29 10:50:24 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\skypePM
[2010.02.04 22:10:55 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Sony
[2010.02.04 22:10:55 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Sony Setup
[2011.05.16 12:48:21 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\Thunderbird
[2010.01.22 00:34:15 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\VistaCodecs
[2012.01.20 22:43:24 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\vlc
[2008.10.21 21:23:40 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2008.10.03 12:54:48 | 001,526,544 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Sebastian\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
[2010.02.04 22:11:57 | 000,010,134 | R--- | M] () -- C:\Users\Sebastian\AppData\Roaming\Microsoft\Installer\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}\ARPPRODUCTICON.exe
[2011.10.31 17:52:09 | 013,706,928 | ---- | M] (                                                            ) -- C:\Users\Sebastian\AppData\Roaming\phonostar GmbH\dradio-Recorder\update.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\drivers\atapi.sys
[2008.01.21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2008.06.16 13:38:28 | 000,396,312 | ---- | M] (Intel Corporation) MD5=DB0C1076AB442C09D2A3AB0410DBEA0D -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2008.06.16 13:38:10 | 000,318,488 | ---- | M] (Intel Corporation) MD5=F263A9036F8897FFA2AE54685E03AD60 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008.06.16 13:38:10 | 000,318,488 | ---- | M] (Intel Corporation) MD5=F263A9036F8897FFA2AE54685E03AD60 -- C:\Windows\System32\drivers\iaStor.sys
[2008.06.16 13:38:10 | 000,318,488 | ---- | M] (Intel Corporation) MD5=F263A9036F8897FFA2AE54685E03AD60 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_3506096f\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 03:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008.01.21 03:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.21 03:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.21 03:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.21 03:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008.01.21 03:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.21 03:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 03:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2008.01.21 03:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 03:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.21 03:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 03:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.21 03:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2011.12.24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.01.21 03:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 03:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.21 03:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2008.01.21 04:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008.01.21 04:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008.01.21 04:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 11:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 11:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
========== Files - Unicode (All) ==========
[2012.01.24 12:22:26 | 000,000,000 | ---D | M](C:\Users\Sebastian\Desktop\2011?12?15_Weihnachtsfeier der Kleinen) -- C:\Users\Sebastian\Desktop\20111215_Weihnachtsfeier der Kleinen
[2011.12.19 19:27:35 | 000,000,000 | ---D | C](C:\Users\Sebastian\Desktop\2011?12?15_Weihnachtsfeier der Kleinen) -- C:\Users\Sebastian\Desktop\20111215_Weihnachtsfeier der Kleinen

< End of report >

--- --- ---

cosinus 25.01.2012 19:37

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
[2010.07.28 17:15:23 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.01.08 22:41:43 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012.01.07 18:58:16 | 000,000,000 | ---D | M] (PriceGong) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{3c325060-917a-11df-b067-0013779ffed3}\Shell - "" = AutoRun
O33 - MountPoints2\{3c325060-917a-11df-b067-0013779ffed3}\Shell\AutoRun\command - "" = F:\setup.exe AUTORUN=1
O33 - MountPoints2\{e43923ef-11b9-11df-8e97-0013779ffed3}\Shell - "" = AutoRun
O33 - MountPoints2\{e43923ef-11b9-11df-8e97-0013779ffed3}\Shell\AutoRun\command - "" = F:\Startme.exe
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

sebastian356 26.01.2012 13:28

hier die logfile:

Code:



All processes killed
========== OTL ==========
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults\preferences folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\searchplugin folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\modules folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\META-INF folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\defaults folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\components folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\skin folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\locale\en-US folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\locale folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\content folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome folder moved successfully.
C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\bfgej6rs.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829} folder moved successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3c325060-917a-11df-b067-0013779ffed3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3c325060-917a-11df-b067-0013779ffed3}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3c325060-917a-11df-b067-0013779ffed3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3c325060-917a-11df-b067-0013779ffed3}\ not found.
File F:\setup.exe AUTORUN=1 not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e43923ef-11b9-11df-8e97-0013779ffed3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e43923ef-11b9-11df-8e97-0013779ffed3}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e43923ef-11b9-11df-8e97-0013779ffed3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e43923ef-11b9-11df-8e97-0013779ffed3}\ not found.
File F:\Startme.exe not found.
========== COMMANDS ==========
 
[EMPTYTEMP]


cosinus 26.01.2012 16:33

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

sebastian356 26.01.2012 16:49

hier die Daten:

Code:



16:42:54.0809 4392        TDSS rootkit removing tool 2.7.7.0 Jan 24 2012 16:44:27
16:42:54.0934 4392        ============================================================
16:42:54.0934 4392        Current date / time: 2012/01/26 16:42:54.0934
16:42:54.0934 4392        SystemInfo:
16:42:54.0934 4392       
16:42:54.0934 4392        OS Version: 6.0.6002 ServicePack: 2.0
16:42:54.0934 4392        Product type: Workstation
16:42:54.0934 4392        ComputerName: SEBASTIAN-PC
16:42:54.0934 4392        UserName: Sebastian
16:42:54.0934 4392        Windows directory: C:\Windows
16:42:54.0934 4392        System windows directory: C:\Windows
16:42:54.0934 4392        Processor architecture: Intel x86
16:42:54.0934 4392        Number of processors: 2
16:42:54.0934 4392        Page size: 0x1000
16:42:54.0934 4392        Boot type: Normal boot
16:42:54.0934 4392        ============================================================
16:42:55.0417 4392        Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
16:42:55.0636 4392        Initialize success
16:43:09.0067 5968        ============================================================
16:43:09.0067 5968        Scan started
16:43:09.0067 5968        Mode: Manual; SigCheck; TDLFS;
16:43:09.0067 5968        ============================================================
16:43:09.0535 5968        acedrv11        (27f954120babb8a00f8745d8f5bc9b82) C:\Windows\system32\drivers\acedrv11.sys
16:43:09.0691 5968        acedrv11 - ok
16:43:09.0738 5968        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
16:43:09.0754 5968        ACPI - ok
16:43:09.0879 5968        adp94xx        (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
16:43:09.0910 5968        adp94xx - ok
16:43:09.0957 5968        adpahci        (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
16:43:09.0988 5968        adpahci - ok
16:43:10.0081 5968        adpu160m        (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
16:43:10.0113 5968        adpu160m - ok
16:43:10.0128 5968        adpu320        (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
16:43:10.0144 5968        adpu320 - ok
16:43:10.0269 5968        AFD            (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
16:43:10.0331 5968        AFD - ok
16:43:10.0456 5968        AgereSoftModem  (ce91b158fa490cf4c4d487a4130f4660) C:\Windows\system32\DRIVERS\AGRSM.sys
16:43:10.0721 5968        AgereSoftModem - ok
16:43:10.0830 5968        agp440          (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
16:43:10.0846 5968        agp440 - ok
16:43:10.0877 5968        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
16:43:10.0893 5968        aic78xx - ok
16:43:10.0939 5968        aliide          (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
16:43:10.0955 5968        aliide - ok
16:43:11.0080 5968        amdagp          (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
16:43:11.0095 5968        amdagp - ok
16:43:11.0127 5968        amdide          (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
16:43:11.0142 5968        amdide - ok
16:43:11.0173 5968        AmdK7          (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
16:43:11.0298 5968        AmdK7 - ok
16:43:11.0439 5968        AmdK8          (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
16:43:11.0517 5968        AmdK8 - ok
16:43:11.0735 5968        arc            (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
16:43:11.0766 5968        arc - ok
16:43:11.0938 5968        arcsas          (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
16:43:11.0953 5968        arcsas - ok
16:43:12.0063 5968        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
16:43:12.0109 5968        AsyncMac - ok
16:43:12.0156 5968        atapi          (2d9c903dc76a66813d350a562de40ed9) C:\Windows\system32\drivers\atapi.sys
16:43:12.0172 5968        atapi - ok
16:43:12.0265 5968        athr            (91e15b0a1d6f7b99ace55d04c6d1544a) C:\Windows\system32\DRIVERS\athr.sys
16:43:12.0421 5968        athr - ok
16:43:12.0562 5968        avgntflt        (7713e4eb0276702faa08e52a6e23f2a6) C:\Windows\system32\DRIVERS\avgntflt.sys
16:43:12.0577 5968        avgntflt - ok
16:43:12.0609 5968        avipbb          (475fbb85956534720858ae72010c0a43) C:\Windows\system32\DRIVERS\avipbb.sys
16:43:12.0624 5968        avipbb - ok
16:43:12.0671 5968        avkmgr          (271cfd1a989209b1964e24d969552bf7) C:\Windows\system32\DRIVERS\avkmgr.sys
16:43:12.0671 5968        avkmgr - ok
16:43:12.0811 5968        bcm4sbxp        (08015d34f6fdd0b355805bad978497c3) C:\Windows\system32\DRIVERS\bcm4sbxp.sys
16:43:12.0999 5968        bcm4sbxp - ok
16:43:13.0108 5968        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
16:43:13.0155 5968        Beep - ok
16:43:13.0217 5968        blbdrive        (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
16:43:13.0248 5968        blbdrive - ok
16:43:13.0326 5968        bowser          (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
16:43:13.0404 5968        bowser - ok
16:43:13.0513 5968        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
16:43:13.0545 5968        BrFiltLo - ok
16:43:13.0576 5968        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
16:43:13.0623 5968        BrFiltUp - ok
16:43:13.0732 5968        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
16:43:13.0794 5968        Brserid - ok
16:43:13.0810 5968        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
16:43:13.0872 5968        BrSerWdm - ok
16:43:13.0966 5968        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
16:43:14.0044 5968        BrUsbMdm - ok
16:43:14.0059 5968        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
16:43:14.0106 5968        BrUsbSer - ok
16:43:14.0215 5968        BthEnum        (da7b195275bda7f8fcf79b40e0f45dde) C:\Windows\system32\DRIVERS\BthEnum.sys
16:43:14.0262 5968        BthEnum - ok
16:43:14.0309 5968        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
16:43:14.0356 5968        BTHMODEM - ok
16:43:14.0465 5968        BthPan          (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
16:43:14.0496 5968        BthPan - ok
16:43:14.0590 5968        BTHPORT        (671134053d59e23704f08db19f11e10b) C:\Windows\system32\Drivers\BTHport.sys
16:43:14.0637 5968        BTHPORT - ok
16:43:14.0839 5968        BTHUSB          (93d7007e2c660dfcca6ae72622740b14) C:\Windows\system32\Drivers\BTHUSB.sys
16:43:14.0902 5968        BTHUSB - ok
16:43:15.0042 5968        btwaudio        (3ea1a20dc0ca1ad23e7aa8c37a91bcd1) C:\Windows\system32\drivers\btwaudio.sys
16:43:15.0058 5968        btwaudio - ok
16:43:15.0073 5968        btwavdt        (195872e48a7fb01f8bc9b800f70f4054) C:\Windows\system32\drivers\btwavdt.sys
16:43:15.0089 5968        btwavdt - ok
16:43:15.0198 5968        btwrchid        (0724e7d6c9b6a289eddda33fa8176e80) C:\Windows\system32\DRIVERS\btwrchid.sys
16:43:15.0198 5968        btwrchid - ok
16:43:15.0245 5968        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
16:43:15.0276 5968        cdfs - ok
16:43:15.0385 5968        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
16:43:15.0417 5968        cdrom - ok
16:43:15.0448 5968        circlass        (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
16:43:15.0479 5968        circlass - ok
16:43:15.0573 5968        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
16:43:15.0588 5968        CLFS - ok
16:43:15.0666 5968        CmBatt          (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
16:43:15.0713 5968        CmBatt - ok
16:43:15.0791 5968        cmdide          (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
16:43:15.0807 5968        cmdide - ok
16:43:15.0838 5968        Compbatt        (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
16:43:15.0853 5968        Compbatt - ok
16:43:15.0853 5968        crcdisk        (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
16:43:15.0869 5968        crcdisk - ok
16:43:15.0900 5968        Crusoe          (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
16:43:15.0947 5968        Crusoe - ok
16:43:16.0056 5968        DfsC            (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
16:43:16.0087 5968        DfsC - ok
16:43:16.0243 5968        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
16:43:16.0259 5968        disk - ok
16:43:16.0306 5968        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
16:43:16.0353 5968        drmkaud - ok
16:43:16.0462 5968        DXGKrnl        (fb85f7f69e9b109820409243f578cc4d) C:\Windows\System32\drivers\dxgkrnl.sys
16:43:16.0540 5968        DXGKrnl - ok
16:43:16.0665 5968        E1G60          (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
16:43:16.0696 5968        E1G60 - ok
16:43:16.0821 5968        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
16:43:16.0836 5968        Ecache - ok
16:43:16.0899 5968        elxstor        (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
16:43:16.0930 5968        elxstor - ok
16:43:17.0023 5968        ErrDev          (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
16:43:17.0055 5968        ErrDev - ok
16:43:17.0117 5968        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
16:43:17.0164 5968        exfat - ok
16:43:17.0257 5968        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
16:43:17.0304 5968        fastfat - ok
16:43:17.0335 5968        fdc            (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
16:43:17.0382 5968        fdc - ok
16:43:17.0476 5968        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
16:43:17.0491 5968        FileInfo - ok
16:43:17.0507 5968        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
16:43:17.0554 5968        Filetrace - ok
16:43:17.0569 5968        flpydisk        (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
16:43:17.0616 5968        flpydisk - ok
16:43:17.0725 5968        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
16:43:17.0741 5968        FltMgr - ok
16:43:17.0772 5968        Fs_Rec          (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
16:43:17.0788 5968        Fs_Rec - ok
16:43:17.0819 5968        gagp30kx        (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
16:43:17.0835 5968        gagp30kx - ok
16:43:17.0928 5968        HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
16:43:17.0991 5968        HdAudAddService - ok
16:43:18.0037 5968        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
16:43:18.0100 5968        HDAudBus - ok
16:43:18.0178 5968        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
16:43:18.0240 5968        HidBth - ok
16:43:18.0303 5968        HidIr          (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
16:43:18.0381 5968        HidIr - ok
16:43:18.0459 5968        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
16:43:18.0505 5968        HidUsb - ok
16:43:18.0552 5968        HpCISSs        (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
16:43:18.0568 5968        HpCISSs - ok
16:43:18.0677 5968        HTTP            (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
16:43:18.0739 5968        HTTP - ok
16:43:18.0817 5968        i2omp          (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
16:43:18.0833 5968        i2omp - ok
16:43:18.0911 5968        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
16:43:18.0942 5968        i8042prt - ok
16:43:19.0051 5968        ialm            (496db78e6a0c4c44023d9a92b4a7ac31) C:\Windows\system32\DRIVERS\igdkmd32.sys
16:43:19.0145 5968        ialm - ok
16:43:19.0254 5968        iaStor          (f263a9036f8897ffa2ae54685e03ad60) C:\Windows\system32\DRIVERS\iaStor.sys
16:43:19.0270 5968        iaStor - ok
16:43:19.0301 5968        iaStorV        (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
16:43:19.0332 5968        iaStorV - ok
16:43:19.0363 5968        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
16:43:19.0379 5968        iirsp - ok
16:43:19.0535 5968        IntcAzAudAddService (ffd2b3bc042596abe785d3c15f51ab46) C:\Windows\system32\drivers\RTKVHDA.sys
16:43:19.0629 5968        IntcAzAudAddService - ok
16:43:19.0738 5968        intelide        (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
16:43:19.0753 5968        intelide - ok
16:43:19.0785 5968        intelppm        (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
16:43:19.0800 5968        intelppm - ok
16:43:19.0925 5968        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:43:19.0972 5968        IpFilterDriver - ok
16:43:19.0972 5968        IpInIp - ok
16:43:20.0003 5968        IPMIDRV        (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
16:43:20.0034 5968        IPMIDRV - ok
16:43:20.0050 5968        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
16:43:20.0081 5968        IPNAT - ok
16:43:20.0175 5968        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
16:43:20.0206 5968        IRENUM - ok
16:43:20.0221 5968        isapnp          (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
16:43:20.0237 5968        isapnp - ok
16:43:20.0268 5968        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
16:43:20.0284 5968        iScsiPrt - ok
16:43:20.0299 5968        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
16:43:20.0315 5968        iteatapi - ok
16:43:20.0409 5968        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
16:43:20.0424 5968        iteraid - ok
16:43:20.0455 5968        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
16:43:20.0471 5968        kbdclass - ok
16:43:20.0487 5968        kbdhid          (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
16:43:20.0533 5968        kbdhid - ok
16:43:20.0643 5968        KMDFMEMIO      (ebc507f129df8f0e0ca270dcfc0cf87f) C:\Windows\system32\DRIVERS\kmdfmemio.sys
16:43:20.0674 5968        KMDFMEMIO - ok
16:43:20.0705 5968        KSecDD          (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
16:43:20.0752 5968        KSecDD - ok
16:43:20.0861 5968        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
16:43:20.0908 5968        lltdio - ok
16:43:20.0939 5968        LSI_FC          (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
16:43:20.0955 5968        LSI_FC - ok
16:43:20.0986 5968        LSI_SAS        (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
16:43:21.0001 5968        LSI_SAS - ok
16:43:21.0095 5968        LSI_SCSI        (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
16:43:21.0111 5968        LSI_SCSI - ok
16:43:21.0126 5968        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
16:43:21.0157 5968        luafv - ok
16:43:21.0189 5968        megasas        (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
16:43:21.0204 5968        megasas - ok
16:43:21.0313 5968        MegaSR          (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
16:43:21.0360 5968        MegaSR - ok
16:43:21.0407 5968        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
16:43:21.0438 5968        Modem - ok
16:43:21.0547 5968        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
16:43:21.0579 5968        monitor - ok
16:43:21.0594 5968        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
16:43:21.0610 5968        mouclass - ok
16:43:21.0625 5968        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
16:43:21.0672 5968        mouhid - ok
16:43:21.0766 5968        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
16:43:21.0781 5968        MountMgr - ok
16:43:21.0813 5968        mpio            (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
16:43:21.0828 5968        mpio - ok
16:43:21.0844 5968        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
16:43:21.0891 5968        mpsdrv - ok
16:43:22.0000 5968        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
16:43:22.0015 5968        Mraid35x - ok
16:43:22.0047 5968        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
16:43:22.0093 5968        MRxDAV - ok
16:43:22.0187 5968        mrxsmb          (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
16:43:22.0218 5968        mrxsmb - ok
16:43:22.0265 5968        mrxsmb10        (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:43:22.0281 5968        mrxsmb10 - ok
16:43:22.0390 5968        mrxsmb20        (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:43:22.0405 5968        mrxsmb20 - ok
16:43:22.0452 5968        msahci          (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
16:43:22.0468 5968        msahci - ok
16:43:22.0561 5968        msdsm          (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
16:43:22.0577 5968        msdsm - ok
16:43:22.0593 5968        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
16:43:22.0624 5968        Msfs - ok
16:43:22.0655 5968        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
16:43:22.0671 5968        msisadrv - ok
16:43:22.0764 5968        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
16:43:22.0811 5968        MSKSSRV - ok
16:43:22.0842 5968        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
16:43:22.0858 5968        MSPCLOCK - ok
16:43:22.0967 5968        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
16:43:22.0998 5968        MSPQM - ok
16:43:23.0029 5968        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
16:43:23.0045 5968        MsRPC - ok
16:43:23.0154 5968        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
16:43:23.0154 5968        mssmbios - ok
16:43:23.0201 5968        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
16:43:23.0232 5968        MSTEE - ok
16:43:23.0263 5968        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
16:43:23.0279 5968        Mup - ok
16:43:23.0388 5968        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
16:43:23.0404 5968        NativeWifiP - ok
16:43:23.0482 5968        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
16:43:23.0513 5968        NDIS - ok
16:43:23.0607 5968        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
16:43:23.0638 5968        NdisTapi - ok
16:43:23.0669 5968        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
16:43:23.0700 5968        Ndisuio - ok
16:43:23.0731 5968        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
16:43:23.0763 5968        NdisWan - ok
16:43:23.0856 5968        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
16:43:23.0887 5968        NDProxy - ok
16:43:23.0887 5968        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
16:43:23.0934 5968        NetBIOS - ok
16:43:23.0965 5968        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
16:43:24.0012 5968        netbt - ok
16:43:24.0184 5968        NETw3v32        (35d5458d9a1b26b2005abffbf4c1c5e7) C:\Windows\system32\DRIVERS\NETw3v32.sys
16:43:24.0371 5968        NETw3v32 - ok
16:43:24.0574 5968        NETw5v32        (0b214c6a4728f085fb64a29ed9c4de94) C:\Windows\system32\DRIVERS\NETw5v32.sys
16:43:24.0839 5968        NETw5v32 - ok
16:43:24.0933 5968        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
16:43:24.0948 5968        nfrd960 - ok
16:43:24.0979 5968        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
16:43:25.0026 5968        Npfs - ok
16:43:25.0042 5968        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
16:43:25.0057 5968        nsiproxy - ok
16:43:25.0120 5968        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
16:43:25.0213 5968        Ntfs - ok
16:43:25.0338 5968        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
16:43:25.0385 5968        ntrigdigi - ok
16:43:25.0416 5968        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
16:43:25.0447 5968        Null - ok
16:43:25.0666 5968        nvlddmkm        (440690da4358d9682dbcc56da7d419ab) C:\Windows\system32\DRIVERS\nvlddmkm.sys
16:43:26.0134 5968        nvlddmkm - ok
16:43:26.0243 5968        nvraid          (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
16:43:26.0259 5968        nvraid - ok
16:43:26.0290 5968        nvstor          (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
16:43:26.0305 5968        nvstor - ok
16:43:26.0337 5968        nv_agp          (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
16:43:26.0352 5968        nv_agp - ok
16:43:26.0430 5968        NwlnkFlt - ok
16:43:26.0446 5968        NwlnkFwd - ok
16:43:26.0524 5968        ohci1394        (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys
16:43:26.0555 5968        ohci1394 - ok
16:43:26.0680 5968        Parport        (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
16:43:26.0742 5968        Parport - ok
16:43:26.0773 5968        partmgr        (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
16:43:26.0789 5968        partmgr - ok
16:43:26.0805 5968        Parvdm          (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
16:43:26.0851 5968        Parvdm - ok
16:43:26.0961 5968        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
16:43:26.0976 5968        pci - ok
16:43:27.0007 5968        pciide          (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
16:43:27.0023 5968        pciide - ok
16:43:27.0070 5968        pcmcia          (b7c5a8769541900f6dfa6fe0c5e4d513) C:\Windows\system32\DRIVERS\pcmcia.sys
16:43:27.0101 5968        pcmcia - ok
16:43:27.0226 5968        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
16:43:27.0288 5968        PEAUTH - ok
16:43:27.0413 5968        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
16:43:27.0444 5968        PptpMiniport - ok
16:43:27.0460 5968        Processor      (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
16:43:27.0507 5968        Processor - ok
16:43:27.0600 5968        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
16:43:27.0631 5968        PSched - ok
16:43:27.0709 5968        ql2300          (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
16:43:27.0819 5968        ql2300 - ok
16:43:27.0928 5968        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
16:43:27.0943 5968        ql40xx - ok
16:43:27.0990 5968        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
16:43:28.0037 5968        QWAVEdrv - ok
16:43:28.0131 5968        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
16:43:28.0177 5968        RasAcd - ok
16:43:28.0193 5968        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
16:43:28.0224 5968        Rasl2tp - ok
16:43:28.0271 5968        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
16:43:28.0302 5968        RasPppoe - ok
16:43:28.0396 5968        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
16:43:28.0411 5968        RasSstp - ok
16:43:28.0458 5968        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
16:43:28.0505 5968        rdbss - ok
16:43:28.0599 5968        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
16:43:28.0630 5968        RDPCDD - ok
16:43:28.0661 5968        rdpdr          (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
16:43:28.0692 5968        rdpdr - ok
16:43:28.0708 5968        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
16:43:28.0755 5968        RDPENCDD - ok
16:43:28.0848 5968        RDPWD          (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
16:43:28.0879 5968        RDPWD - ok
16:43:28.0957 5968        RFCOMM          (10536b0ad6f416fc7f1149977c28ccdc) C:\Windows\system32\DRIVERS\rfcomm.sys
16:43:28.0989 5968        RFCOMM - ok
16:43:29.0082 5968        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
16:43:29.0098 5968        rspndr - ok
16:43:29.0176 5968        s1018bus        (1c5c2cb892553d2cf3f45a4bb323fcd6) C:\Windows\system32\DRIVERS\s1018bus.sys
16:43:29.0191 5968        s1018bus - ok
16:43:29.0269 5968        s1018mdfl      (38f5ea219593f19b6b3a1b9c169e3b61) C:\Windows\system32\DRIVERS\s1018mdfl.sys
16:43:29.0269 5968        s1018mdfl - ok
16:43:29.0332 5968        s1018mdm        (666af6b64fc7df92d3ca4819ea91631d) C:\Windows\system32\DRIVERS\s1018mdm.sys
16:43:29.0332 5968        s1018mdm - ok
16:43:29.0394 5968        s1018mgmt      (f4ceda6e2ddff2af8bd745615a7ca9c0) C:\Windows\system32\DRIVERS\s1018mgmt.sys
16:43:29.0441 5968        s1018mgmt - ok
16:43:29.0519 5968        s1018nd5        (3622d9ff2253dcbe885b10736609a4ca) C:\Windows\system32\DRIVERS\s1018nd5.sys
16:43:29.0519 5968        s1018nd5 - ok
16:43:29.0581 5968        s1018obex      (49431efda842b474531c29ffae9f5d09) C:\Windows\system32\DRIVERS\s1018obex.sys
16:43:29.0597 5968        s1018obex - ok
16:43:29.0628 5968        s1018unic      (ac6b514cb4474f4c867d7cdc9cd54f05) C:\Windows\system32\DRIVERS\s1018unic.sys
16:43:29.0644 5968        s1018unic - ok
16:43:29.0737 5968        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
16:43:29.0753 5968        sbp2port - ok
16:43:29.0831 5968        sdbus          (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
16:43:29.0862 5968        sdbus - ok
16:43:29.0940 5968        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
16:43:30.0003 5968        secdrv - ok
16:43:30.0065 5968        seehcri        (e5b56569a9f79b70314fede6c953641e) C:\Windows\system32\DRIVERS\seehcri.sys
16:43:30.0112 5968        seehcri - ok
16:43:30.0190 5968        Serenum        (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
16:43:30.0237 5968        Serenum - ok
16:43:30.0299 5968        Serial          (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
16:43:30.0361 5968        Serial - ok
16:43:30.0439 5968        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
16:43:30.0471 5968        sermouse - ok
16:43:30.0533 5968        sffdisk        (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
16:43:30.0549 5968        sffdisk - ok
16:43:30.0580 5968        sffp_mmc        (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
16:43:30.0611 5968        sffp_mmc - ok
16:43:30.0689 5968        sffp_sd        (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
16:43:30.0720 5968        sffp_sd - ok
16:43:30.0767 5968        sfloppy        (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
16:43:30.0829 5968        sfloppy - ok
16:43:30.0907 5968        sisagp          (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
16:43:30.0923 5968        sisagp - ok
16:43:30.0985 5968        SiSRaid2        (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
16:43:31.0001 5968        SiSRaid2 - ok
16:43:31.0032 5968        SiSRaid4        (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
16:43:31.0048 5968        SiSRaid4 - ok
16:43:31.0126 5968        Smb            (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
16:43:31.0173 5968        Smb - ok
16:43:31.0297 5968        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
16:43:31.0313 5968        spldr - ok
16:43:31.0391 5968        srv            (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
16:43:31.0438 5968        srv - ok
16:43:31.0516 5968        srv2            (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
16:43:31.0547 5968        srv2 - ok
16:43:31.0594 5968        srvnet          (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
16:43:31.0609 5968        srvnet - ok
16:43:31.0719 5968        SSHDRV86        (b9e31f2a3640403b0ea3a867bb73b9f4) C:\Windows\system32\drivers\SSHDRV86.sys
16:43:31.0781 5968        SSHDRV86 ( UnsignedFile.Multi.Generic ) - warning
16:43:31.0781 5968        SSHDRV86 - detected UnsignedFile.Multi.Generic (1)
16:43:31.0828 5968        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
16:43:31.0843 5968        ssmdrv - ok
16:43:31.0968 5968        StarOpen        (306521935042fc0a6988d528643619b3) C:\Windows\system32\drivers\StarOpen.sys
16:43:31.0984 5968        StarOpen ( UnsignedFile.Multi.Generic ) - warning
16:43:31.0984 5968        StarOpen - detected UnsignedFile.Multi.Generic (1)
16:43:32.0046 5968        StillCam        (ef70b3d22b4bffda6ea851ecb063efaa) C:\Windows\system32\DRIVERS\serscan.sys
16:43:32.0062 5968        StillCam - ok
16:43:32.0155 5968        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
16:43:32.0171 5968        swenum - ok
16:43:32.0202 5968        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
16:43:32.0218 5968        Symc8xx - ok
16:43:32.0233 5968        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
16:43:32.0249 5968        Sym_hi - ok
16:43:32.0265 5968        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
16:43:32.0280 5968        Sym_u3 - ok
16:43:32.0374 5968        SynTP          (451e8037e2eb6da6bdf0a66f65d1810b) C:\Windows\system32\DRIVERS\SynTP.sys
16:43:32.0389 5968        SynTP - ok
16:43:32.0467 5968        Tcpip          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys
16:43:32.0623 5968        Tcpip - ok
16:43:32.0764 5968        Tcpip6          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys
16:43:32.0873 5968        Tcpip6 - ok
16:43:32.0982 5968        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
16:43:33.0013 5968        tcpipreg - ok
16:43:33.0060 5968        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
16:43:33.0076 5968        TDPIPE - ok
16:43:33.0107 5968        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
16:43:33.0138 5968        TDTCP - ok
16:43:33.0232 5968        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
16:43:33.0263 5968        tdx - ok
16:43:33.0294 5968        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
16:43:33.0310 5968        TermDD - ok
16:43:33.0372 5968        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
16:43:33.0419 5968        tssecsrv - ok
16:43:33.0513 5968        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
16:43:33.0559 5968        tunmp - ok
16:43:33.0575 5968        tunnel          (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
16:43:33.0606 5968        tunnel - ok
16:43:33.0715 5968        uagp35          (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
16:43:33.0731 5968        uagp35 - ok
16:43:33.0762 5968        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
16:43:33.0809 5968        udfs - ok
16:43:33.0840 5968        uliagpkx        (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
16:43:33.0856 5968        uliagpkx - ok
16:43:33.0965 5968        uliahci        (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
16:43:33.0981 5968        uliahci - ok
16:43:34.0012 5968        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
16:43:34.0027 5968        UlSata - ok
16:43:34.0059 5968        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
16:43:34.0074 5968        ulsata2 - ok
16:43:34.0074 5968        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
16:43:34.0121 5968        umbus - ok
16:43:34.0215 5968        usbccgp        (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
16:43:34.0261 5968        usbccgp - ok
16:43:34.0277 5968        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
16:43:34.0339 5968        usbcir - ok
16:43:34.0449 5968        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
16:43:34.0495 5968        usbehci - ok
16:43:34.0527 5968        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
16:43:34.0573 5968        usbhub - ok
16:43:34.0683 5968        usbohci        (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
16:43:34.0729 5968        usbohci - ok
16:43:34.0761 5968        usbprint        (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys
16:43:34.0807 5968        usbprint - ok
16:43:34.0839 5968        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:43:34.0885 5968        USBSTOR - ok
16:43:34.0979 5968        usbuhci        (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
16:43:35.0010 5968        usbuhci - ok
16:43:35.0073 5968        usbvideo        (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
16:43:35.0119 5968        usbvideo - ok
16:43:35.0229 5968        vga            (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
16:43:35.0275 5968        vga - ok
16:43:35.0307 5968        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
16:43:35.0338 5968        VgaSave - ok
16:43:35.0447 5968        viaagp          (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
16:43:35.0463 5968        viaagp - ok
16:43:35.0478 5968        ViaC7          (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
16:43:35.0525 5968        ViaC7 - ok
16:43:35.0556 5968        viaide          (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
16:43:35.0556 5968        viaide - ok
16:43:35.0681 5968        VMC302          (2b0970a8c0a65874eff4aa436e651d85) C:\Windows\system32\Drivers\VMC302.sys
16:43:35.0728 5968        VMC302 - ok
16:43:35.0759 5968        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
16:43:35.0775 5968        volmgr - ok
16:43:35.0868 5968        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
16:43:35.0899 5968        volmgrx - ok
16:43:35.0946 5968        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
16:43:35.0977 5968        volsnap - ok
16:43:36.0009 5968        vsmraid        (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
16:43:36.0024 5968        vsmraid - ok
16:43:36.0133 5968        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
16:43:36.0196 5968        WacomPen - ok
16:43:36.0211 5968        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
16:43:36.0243 5968        Wanarp - ok
16:43:36.0258 5968        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
16:43:36.0289 5968        Wanarpv6 - ok
16:43:36.0383 5968        Wd              (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
16:43:36.0399 5968        Wd - ok
16:43:36.0430 5968        WDC_SAM        (d6efaf429fd30c5df613d220e344cce7) C:\Windows\system32\DRIVERS\wdcsam.sys
16:43:36.0461 5968        WDC_SAM - ok
16:43:36.0570 5968        Wdf01000        (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
16:43:36.0617 5968        Wdf01000 - ok
16:43:36.0679 5968        WmiAcpi        (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
16:43:36.0695 5968        WmiAcpi - ok
16:43:36.0820 5968        WpdUsb          (0cec23084b51b8288099eb710224e955) C:\Windows\system32\DRIVERS\wpdusb.sys
16:43:36.0867 5968        WpdUsb - ok
16:43:36.0945 5968        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
16:43:36.0976 5968        ws2ifsl - ok
16:43:37.0069 5968        WSDPrintDevice  (4422ac5ed8d4c2f0db63e71d4c069dd7) C:\Windows\system32\DRIVERS\WSDPrint.sys
16:43:37.0085 5968        WSDPrintDevice - ok
16:43:37.0179 5968        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
16:43:37.0210 5968        WUDFRd - ok
16:43:37.0288 5968        yukonwlh        (04e268adfc81964c49dc0c082d520f7e) C:\Windows\system32\DRIVERS\yk60x86.sys
16:43:37.0350 5968        yukonwlh - ok
16:43:37.0381 5968        MBR (0x1B8)    (61a349592c4728853f4a90ff78f7628e) \Device\Harddisk0\DR0
16:43:37.0771 5968        \Device\Harddisk0\DR0 - ok
16:43:37.0771 5968        Boot (0x1200)  (0c3933c34ab94407951b9c9795fad978) \Device\Harddisk0\DR0\Partition0
16:43:37.0771 5968        \Device\Harddisk0\DR0\Partition0 - ok
16:43:37.0803 5968        Boot (0x1200)  (b59f5c32f5e65a15628c3a39888e0dc7) \Device\Harddisk0\DR0\Partition1
16:43:37.0803 5968        \Device\Harddisk0\DR0\Partition1 - ok
16:43:37.0803 5968        ============================================================
16:43:37.0803 5968        Scan finished
16:43:37.0803 5968        ============================================================
16:43:37.0803 0744        Detected object count: 2
16:43:37.0803 0744        Actual detected object count: 2
16:43:56.0835 0744        SSHDRV86 ( UnsignedFile.Multi.Generic ) - skipped by user
16:43:56.0835 0744        SSHDRV86 ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:43:56.0835 0744        StarOpen ( UnsignedFile.Multi.Generic ) - skipped by user
16:43:56.0835 0744        StarOpen ( UnsignedFile.Multi.Generic ) - User select action: Skip

Danke schon einmal zwischendurch für die verständlich und nachvollziehbaren Anweisungen!

cosinus 26.01.2012 17:16

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

sebastian356 26.01.2012 17:51

hier die file:

Code:



Combofix Logfile:

       
Code:

       
ComboFix 12-01-26.01 - Sebastian 26.01.2012  17:34:27.1.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.49.1031.18.3066.1973 [GMT 1:00]
ausgeführt von:: c:\users\Sebastian\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Outdated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Outdated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\hpe9AEF.dll
c:\programdata\hpe9CCB.dll
c:\programdata\Roaming
c:\programdata\Roaming\Intel\Wireless\Settings\Settings.ini
c:\users\Sebastian\AppData\Roaming\MicroST
c:\users\Sebastian\AppData\Roaming\MicroST\Dat6A4A.tmp.xsi
c:\users\Sebastian\AppData\Roaming\MicroST\Dat7FE.tmp.xsi
c:\users\Sebastian\AppData\Roaming\MicroST\DatB07C.tmp.xsi
c:\windows\system32\drivers\etc\hosts.ics
.
.
(((((((((((((((((((((((   Dateien erstellt von 2011-12-26 bis 2012-01-26  ))))))))))))))))))))))))))))))
.
.
2012-01-26 12:17 . 2012-01-26 12:17        --------        d-----w-        C:\_OTL
2012-01-24 17:06 . 2012-01-06 04:19        6557240        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{0F8E1D4E-F715-4D70-8C36-A09D81772AA8}\mpengine.dll
2012-01-23 18:51 . 2012-01-23 18:51        --------        d-----w-        c:\program files\ESET
2012-01-20 16:47 . 2012-01-20 16:47        --------        d-----w-        c:\users\Sebastian\AppData\Roaming\Malwarebytes
2012-01-20 16:45 . 2012-01-20 16:45        --------        d-----w-        c:\programdata\Malwarebytes
2012-01-20 16:45 . 2012-01-20 16:45        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2012-01-20 16:45 . 2011-12-10 14:24        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-01-18 16:34 . 2012-01-18 16:34        --------        d-----w-        c:\program files\Animake
2012-01-11 22:54 . 2011-10-14 16:03        189952        ----a-w-        c:\windows\system32\winmm.dll
2012-01-11 22:54 . 2011-10-14 16:00        23552        ----a-w-        c:\windows\system32\mciseq.dll
2012-01-11 22:54 . 2011-11-18 20:23        1205064        ----a-w-        c:\windows\system32\ntdll.dll
2012-01-11 22:54 . 2011-11-18 17:47        66560        ----a-w-        c:\windows\system32\packager.dll
2012-01-11 22:54 . 2011-11-25 15:59        376320        ----a-w-        c:\windows\system32\winsrv.dll
2012-01-11 22:54 . 2011-10-25 15:58        1314816        ----a-w-        c:\windows\system32\quartz.dll
2012-01-11 22:54 . 2011-10-25 15:58        497152        ----a-w-        c:\windows\system32\qdvd.dll
2012-01-07 17:58 . 2012-01-07 17:58        --------        d-----w-        c:\program files\PriceGong
2011-12-30 19:58 . 2011-12-30 19:58        626688        ----a-w-        c:\program files\Mozilla Firefox\msvcr80.dll
2011-12-30 19:58 . 2011-12-30 19:58        548864        ----a-w-        c:\program files\Mozilla Firefox\msvcp80.dll
2011-12-30 19:58 . 2011-12-30 19:58        479232        ----a-w-        c:\program files\Mozilla Firefox\msvcm80.dll
2011-12-30 19:58 . 2011-12-30 19:58        43992        ----a-w-        c:\program files\Mozilla Firefox\mozutils.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-09 10:44 . 2011-10-24 09:40        134856        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2011-11-23 13:37 . 2011-12-14 17:20        2043904        ----a-w-        c:\windows\system32\win32k.sys
2011-11-15 13:29 . 2009-10-03 09:37        222080        ------w-        c:\windows\system32\MpSigStub.exe
2011-11-15 11:06 . 2011-05-19 16:34        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-08 14:42 . 2011-12-14 17:20        2048        ----a-w-        c:\windows\system32\tzres.dll
2011-11-03 06:22 . 2011-12-14 17:20        916992        ----a-w-        c:\windows\system32\wininet.dll
2011-11-03 06:17 . 2011-12-14 17:20        43520        ----a-w-        c:\windows\system32\licmgr10.dll
2011-11-03 06:17 . 2011-12-14 17:20        1469440        ----a-w-        c:\windows\system32\inetcpl.cpl
2011-11-03 06:17 . 2011-12-14 17:20        71680        ----a-w-        c:\windows\system32\iesetup.dll
2011-11-03 06:17 . 2011-12-14 17:20        109056        ----a-w-        c:\windows\system32\iesysprep.dll
2011-11-03 05:22 . 2011-12-14 17:20        385024        ----a-w-        c:\windows\system32\html.iec
2011-11-03 04:45 . 2011-12-14 17:20        133632        ----a-w-        c:\windows\system32\ieUnatt.exe
2011-11-03 04:43 . 2011-12-14 17:20        1638912        ----a-w-        c:\windows\system32\mshtml.tlb
2011-12-30 19:58 . 2011-04-08 18:36        121816        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"dradio-RecorderTimer"="c:\program files\dradio-Recorder\phonostarTimer.exe" [2011-06-20 40960]
"Sony Ericsson PC Companion"="c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" [2011-10-21 433872]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-08 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-08 92704]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-17 6111232]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-10-26 1029416]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-10-11 258512]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-2-12 723496]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2011-3-9 3986944]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2008-07-30 277736]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs        REG_MULTI_SZ           BthServ
.
Inhalt des "geplante Tasks" Ordners
.
2012-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-07 07:03]
.
2012-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-07 07:03]
.
2012-01-26 c:\windows\Tasks\User_Feed_Synchronization-{79EFB1BF-C914-49BB-A75F-232FC7288BAD}.job
- c:\windows\system32\msfeedssync.exe [2011-12-14 04:44]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp:\\www.samsungcomputer.com
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\bfgej6rs.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
HKCU-Run-LightScribe Control Panel - c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
HKCU-Run-ICQ - c:\program files\ICQ6.5\ICQ.exe
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
AddRemove-Uninstall_is1 - c:\program files\Common Files\DVDVideoSoft\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-01-26 17:40
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
  ICQ = "c:\program files\ICQ6.5\ICQ.exe" silent?Q
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2012-01-26  17:43:31
ComboFix-quarantined-files.txt  2012-01-26 16:43
.
Vor Suchlauf: 11 Verzeichnis(se), 72.088.182.784 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 71.790.510.080 Bytes frei
.
- - End Of File - - 43A0665DF8C5D96E727571C07981F36C


--- --- ---

was mir auf den ersten Blick aufgefallen ist ich hab den internet explorer als icon auf dem desktop und firefox war nicht mehr Standartbrowser, aber das is sicher normal.

cosinus 26.01.2012 18:50

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).


sebastian356 26.01.2012 20:48

und hier die verlangten files:

gmer:

[code]
GMER Logfile:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-01-26 20:06:47
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.BBFO
Running: byfkkrwg.exe; Driver: C:\Users\SEBAST~1\AppData\Local\Temp\kglyauoc.sys


---- System - GMER 1.0.15 ----

SSDT            8E0D9EB6                                                                                        ZwCreateSection
SSDT            8E0D9EC0                                                                                        ZwRequestWaitReplyPort
SSDT            8E0D9EBB                                                                                        ZwSetContextThread
SSDT            8E0D9EC5                                                                                        ZwSetSecurityObject
SSDT            8E0D9ECA                                                                                        ZwSystemDebugControl
SSDT            8E0D9E57                                                                                        ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text          ntoskrnl.exe!KeInsertQueue + 405                                                                824A49FC 4 Bytes  [B6, 9E, 0D, 8E]
.text          ntoskrnl.exe!KeInsertQueue + 729                                                                824A4D20 4 Bytes  [C0, 9E, 0D, 8E]
.text          ntoskrnl.exe!KeInsertQueue + 75D                                                                824A4D54 4 Bytes  [BB, 9E, 0D, 8E]
.text          ntoskrnl.exe!KeInsertQueue + 7C1                                                                824A4DB8 4 Bytes  [C5, 9E, 0D, 8E]
.text          ntoskrnl.exe!KeInsertQueue + 809                                                                824A4E00 4 Bytes  [CA, 9E, 0D, 8E]
.text          ...                                                                                             
.text          C:\Windows\system32\DRIVERS\nvlddmkm.sys                                                        section is writeable [0x8F40C340, 0x3E9407, 0xE8000020]
.text          C:\Windows\system32\drivers\SSHDRV86.sys                                                        section is writeable [0x90A9A000, 0x26354, 0xE8000020]
.pklstb        C:\Windows\system32\drivers\SSHDRV86.sys                                                        entry point in ".pklstb" section [0x90ACF000]
.relo2          C:\Windows\system32\drivers\SSHDRV86.sys                                                        unknown last section [0x90AE6000, 0x8E, 0x42000040]
.reloc          C:\Windows\system32\drivers\acedrv11.sys                                                        section is executable [0x8AF36600, 0x25B0C, 0xE0000060]
?              C:\Windows\system32\Drivers\PROCEXP113.SYS                                                      Das System kann die angegebene Datei nicht finden. !
?              C:\Users\SEBAST~1\AppData\Local\Temp\catchme.sys                                                Das System kann die angegebene Datei nicht finden. !

---- User code sections - GMER 1.0.15 ----

.text          C:\Program Files\Mozilla Firefox\firefox.exe[2820] ntdll.dll!LdrLoadDll                          77349378 5 Bytes  JMP 63D3B750 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text          C:\Program Files\Mozilla Firefox\plugin-container.exe[5804] USER32.dll!GetWindowInfo            76D9428E 5 Bytes  JMP 63EBC909 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text          C:\Program Files\Mozilla Firefox\plugin-container.exe[5804] USER32.dll!TrackPopupMenu            76DA14F3 5 Bytes  JMP 63EBCEBD C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                          Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                          Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0002787923ce                     
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00027879245e                     
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0002787923ce (not active ControlSet) 
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\00027879245e (not active ControlSet) 

---- EOF - GMER 1.0.15 ----

--- --- ---


OSAM:
Code:


OSAM Logfile:

       
Code:

       
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 20:11:51 on 26.01.2012

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 9.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"iproset.cpl" - "Intel(R) Corporation" - C:\Windows\system32\iproset.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"PROSet Tools" - "Intel(R) Corporation" - C:\Windows\System32\iPROSet.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"acedrv11" (acedrv11) - "Protect Software GmbH" - C:\Windows\system32\drivers\acedrv11.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\Users\SEBAST~1\AppData\Local\Temp\catchme.sys  (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"kglyauoc" (kglyauoc) - ? - C:\Users\SEBAST~1\AppData\Local\Temp\kglyauoc.sys  (Hidden registry entry, rootkit activity | File not found)
"mbr" (mbr) - ? - C:\ComboFix\mbr.sys  (Hidden registry entry, rootkit activity | File not found)
"SSHDRV86" (SSHDRV86) - ? - C:\Windows\system32\drivers\SSHDRV86.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"StarOpen" (StarOpen) - ? - C:\Windows\system32\drivers\StarOpen.sys  (File found, but it contains no detailed information)

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{0561EC90-CE54-4f0c-9C55-E226110A740C} "{0561EC90-CE54-4f0c-9C55-E226110A740C}" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807553E5-5146-11D5-A672-00B0D022E945} "text/xml" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -   (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -   (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -   (File not found | COM-object registry key not found)
{327669A0-59A7-4be9-B99E-1C9F3A57611A} "Haali Matroska Thumbnail Exctractor" - ? -   (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -   (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Windows\system32\btncopy.dll
{0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -   (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Program Files\WinRAR\rarext.dll

[Internet Explorer]
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_29.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
{53707962-6F74-2D53-2644-206D7942484F} "ClsidExtension" - "Safer Networking Limited" - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
"ICQ7.4" - "ICQ, LLC." - C:\Program Files\ICQ7.4\ICQ.exe
"PartyPoker.net" - ? - C:\Programs\PartyPoker\PartyPokerNet\RunPF.exe  (File not found)
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Recherchieren" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{53707962-6F74-2D53-2644-206D7942484F} "Spybot-S&D IE Protection" - "Safer Networking Limited" - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"BTTray.lnk" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File exists)
"WDDMStatus.lnk" - "Western Digital Technologies, Inc." - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"dradio-RecorderTimer" - ? - C:\Program Files\dradio-Recorder\phonostarTimer.exe  (File found, but it contains no detailed information)
"Skype" - "Skype Technologies S.A." - "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
"Sony Ericsson PC Companion" - "Sony Ericsson" - "C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background
"SpybotSD TeaTimer" - "Safer-Networking Ltd." - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"LanguageShortcut" - ? - "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"RemoteControl" - "Cyberlink Corp." - "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Canon BJNP Port" - "CANON INC." - C:\Windows\system32\CNMNPPM.DLL
"Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\Windows\system32\mdimon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Intel® PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
"Intel® PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Samsung Update Plus" (Samsung Update Plus) - ? - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe  (File found, but it contains no detailed information)
"SBSD Security Center Service" (SBSDWSCService) - "Safer Networking Ltd." - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
"Sony Ericsson PCCompanion" (Sony Ericsson PCCompanion) - "Avanquest Software" - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
"SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
"WD File Management Engine" (WDFME) - ? - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe
"WD File Management Shadow Engine" (WDSC) - ? - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe
"WDDMService" (WDDMService) - "WDC" - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe

===[ Logfile end ]=========================================[ Logfile end ]===


--- --- ---

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

aswMBR:

Code:


aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software
Run date: 2012-01-26 20:12:46
-----------------------------
20:12:46.142    OS Version: Windows 6.0.6002 Service Pack 2
20:12:46.142    Number of processors: 2 586 0xF0D
20:12:46.143    ComputerName: SEBASTIAN-PC  UserName: Sebastian
20:12:47.050    Initialize success
20:18:34.559    AVAST engine defs: 12012601
20:18:46.398    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
20:18:46.447    Disk 0 Vendor: Hitachi_ BBFO Size: 238475MB BusType: 3
20:18:46.691    Disk 0 MBR read successfully
20:18:46.784    Disk 0 MBR scan
20:18:46.825    Disk 0 unknown MBR code
20:18:46.888    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        10240 MB offset 2048
20:18:46.946    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS      114570 MB offset 20973568
20:18:47.008    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      113663 MB offset 255612928
20:18:47.109    Disk 0 scanning sectors +488394752
20:18:47.612    Disk 0 scanning C:\Windows\system32\drivers
20:20:20.394    Service scanning
20:20:21.818    Modules scanning
20:21:45.734    Disk 0 trace - called modules:
20:21:45.807    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
20:21:45.812    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x865e35b0]
20:21:45.816    3 CLASSPNP.SYS[8aea28b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8543f028]
20:21:46.508    AVAST engine scan C:\Windows
20:22:48.371    AVAST engine scan C:\Windows\system32
20:33:23.271    AVAST engine scan C:\Windows\system32\drivers
20:33:42.495    AVAST engine scan C:\Users\Sebastian
20:38:17.387    AVAST engine scan C:\ProgramData
20:40:41.008    Scan finished successfully
20:42:20.060    Disk 0 MBR has been saved successfully to "C:\Users\Sebastian\Desktop\MBR.dat"
20:42:20.065    The log file has been saved successfully to "C:\Users\Sebastian\Desktop\aswMBR.txt"


cosinus 26.01.2012 21:20

Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.

Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.
Mach den Fix auch dann nicht, wenn du zB mit TrueCrypt oder anderen Verschlüsselungsprogrammen eine Vollverschlüsselung der Windowspartition bzw. gesamten Festplatte hast


Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.
Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

sebastian356 26.01.2012 22:58

Gute Nachricht es ist alles glatt gegangen!

[code]

aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software
Run date: 2012-01-26 22:44:02
-----------------------------
22:44:02.721 OS Version: Windows 6.0.6002 Service Pack 2
22:44:02.722 Number of processors: 2 586 0xF0D
22:44:02.723 ComputerName: SEBASTIAN-PC UserName: Sebastian
22:44:04.208 Initialize success
22:44:13.682 AVAST engine defs: 12012601
22:44:28.081 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:44:28.081 Disk 0 Vendor: Hitachi_ BBFO Size: 238475MB BusType: 3
22:44:28.096 Disk 0 MBR read successfully
22:44:28.096 Disk 0 MBR scan
22:44:28.112 Disk 0 Windows VISTA default MBR code
22:44:28.127 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 10240 MB offset 2048
22:44:28.143 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 114570 MB offset 20973568
22:44:28.159 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 113663 MB offset 255612928
22:44:28.190 Disk 0 scanning sectors +488394752
22:44:28.268 Disk 0 scanning C:\Windows\system32\drivers
22:44:44.149 Service scanning
22:44:45.802 Modules scanning
22:45:12.260 Disk 0 trace - called modules:
22:45:12.275 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
22:45:12.291 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x865b5ac8]
22:45:12.291 3 CLASSPNP.SYS[8aeab8b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8541a028]
22:45:13.087 AVAST engine scan C:\Windows
22:45:21.089 AVAST engine scan C:\Windows\system32
22:48:50.473 AVAST engine scan C:\Windows\system32\drivers
22:49:17.507 AVAST engine scan C:\Users\Sebastian
22:51:40.357 AVAST engine scan C:\ProgramData
22:53:50.289 Scan finished successfully
22:54:51.831 Disk 0 MBR has been saved successfully to "C:\Users\Sebastian\Desktop\MBR.dat"
22:54:51.847 The log file has been saved successfully to "C:\Users\Sebastian\Desktop\aswMBR1.txt"

[\code]

cosinus 27.01.2012 10:29

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!


Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


sebastian356 27.01.2012 19:39

Hier der eset-scan:
Code:


ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=ccff2162f96cb34fb05acc16abcd6586
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-23 07:06:11
# local_time=2012-01-23 08:06:11 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 7895736 7895736 0 0
# compatibility_mode=5892 16776573 100 100 79374 164877696 0 0
# compatibility_mode=8192 67108863 100 0 3872 3872 0 0
# scanned=17655
# found=0
# cleaned=0
# scan_time=603
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=ccff2162f96cb34fb05acc16abcd6586
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-24 07:05:00
# local_time=2012-01-24 08:05:00 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 7975349 7975349 0 0
# compatibility_mode=5892 16776573 100 100 158987 164957309 0 0
# compatibility_mode=8192 67108863 100 0 83485 83485 0 0
# scanned=149958
# found=4
# cleaned=0
# scan_time=7318
C:\Program Files\VistaCodecPack\Tools\Settings32.exe        Win32/Packed.Autoit.C.Gen application (unable to clean)        00000000000000000000000000000000        I
C:\ProgramData\VistaCodecs\{3161B7F4-69FC-4FB6-9842-BC00F231CBEF}\Vista Codec Package.msi        Win32/Packed.Autoit.C.Gen application (unable to clean)        00000000000000000000000000000000        I
C:\Users\All Users\VistaCodecs\{3161B7F4-69FC-4FB6-9842-BC00F231CBEF}\Vista Codec Package.msi        Win32/Packed.Autoit.C.Gen application (unable to clean)        00000000000000000000000000000000        I
C:\Users\Sebastian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\3952cc99-4ed09678        Java/Exploit.CVE-2011-3544.AB trojan (unable to clean)        00000000000000000000000000000000        I
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=ccff2162f96cb34fb05acc16abcd6586
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-25 11:32:41
# local_time=2012-01-25 12:32:41 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 8034305 8034305 0 0
# compatibility_mode=5892 16776573 100 100 41464 165016265 0 0
# compatibility_mode=8192 67108863 100 0 142441 142441 0 0
# scanned=150158
# found=4
# cleaned=0
# scan_time=7623
C:\Program Files\VistaCodecPack\Tools\Settings32.exe        Win32/Packed.Autoit.C.Gen application (unable to clean)        00000000000000000000000000000000        I
C:\ProgramData\VistaCodecs\{3161B7F4-69FC-4FB6-9842-BC00F231CBEF}\Vista Codec Package.msi        Win32/Packed.Autoit.C.Gen application (unable to clean)        00000000000000000000000000000000        I
C:\Users\All Users\VistaCodecs\{3161B7F4-69FC-4FB6-9842-BC00F231CBEF}\Vista Codec Package.msi        Win32/Packed.Autoit.C.Gen application (unable to clean)        00000000000000000000000000000000        I
C:\Users\Sebastian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\3952cc99-4ed09678        Java/Exploit.CVE-2011-3544.AB trojan (unable to clean)        00000000000000000000000000000000        I
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=ccff2162f96cb34fb05acc16abcd6586
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-27 05:37:11
# local_time=2012-01-27 06:37:11 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 8232312 8232312 0 0
# compatibility_mode=5892 16776573 100 100 3819 165214272 0 0
# compatibility_mode=8192 67108863 100 0 340448 340448 0 0
# scanned=129408
# found=3
# cleaned=0
# scan_time=4286
C:\Program Files\VistaCodecPack\Tools\Settings32.exe        Win32/Packed.Autoit.C.Gen application (unable to clean)        00000000000000000000000000000000        I
C:\ProgramData\VistaCodecs\{3161B7F4-69FC-4FB6-9842-BC00F231CBEF}\Vista Codec Package.msi        Win32/Packed.Autoit.C.Gen application (unable to clean)        00000000000000000000000000000000        I
C:\Users\All Users\VistaCodecs\{3161B7F4-69FC-4FB6-9842-BC00F231CBEF}\Vista Codec Package.msi        Win32/Packed.Autoit.C.Gen application (unable to clean)        00000000000000000000000000000000        I

superantispyware:

Code:


SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 01/27/2012 at 07:21 PM

Application Version : 5.0.1142

Core Rules Database Version : 8174
Trace Rules Database Version: 5986

Scan type      : Complete Scan
Total Scan Time : 00:38:29

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Limited User (Administrator User)

Memory items scanned      : 735
Memory threats detected  : 0
Registry items scanned    : 23396
Registry threats detected : 0
File items scanned        : 44897
File threats detected    : 475

Adware.Tracking Cookie
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@2o7[2].txt [ /2o7 ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@ad.71i[1].txt [ /ad.71i ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@ad.zanox[1].txt [ /ad.zanox ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@ad4.adfarm1.adition[1].txt [ /ad4.adfarm1.adition ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@adopt.euroclick[2].txt [ /adopt.euroclick ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@ads.heias[1].txt [ /ads.heias ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@ads.planetactive[2].txt [ /ads.planetactive ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@adserver.71i[1].txt [ /adserver.71i ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@adx.chip[1].txt [ /adx.chip ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@ar.atwola[1].txt [ /ar.atwola ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@ar.atwola[2].txt [ /ar.atwola ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@at.atwola[2].txt [ /at.atwola ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@atwola[1].txt [ /atwola ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@bs.serving-sys[1].txt [ /bs.serving-sys ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@content.yieldmanager[1].txt [ /content.yieldmanager ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@content.yieldmanager[3].txt [ /content.yieldmanager ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@de.at.atwola[1].txt [ /de.at.atwola ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@oberon-media[1].txt [ /oberon-media ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@partygaming.122.2o7[1].txt [ /partygaming.122.2o7 ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@serving-sys[1].txt [ /serving-sys ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@sevenoneintermedia.112.2o7[1].txt [ /sevenoneintermedia.112.2o7 ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@smartadserver[2].txt [ /smartadserver ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@tacoda.at.atwola[1].txt [ /tacoda.at.atwola ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@track.adform[2].txt [ /track.adform ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@tracking.mindshare[1].txt [ /tracking.mindshare ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@tracking.quisma[2].txt [ /tracking.quisma ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@unitymedia[1].txt [ /unitymedia ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@www.windowsmedia[2].txt [ /www.windowsmedia ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@www.zanox-affiliate[1].txt [ /www.zanox-affiliate ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@zanox-affiliate[1].txt [ /zanox-affiliate ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@zanox[2].txt [ /zanox ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@zbox.zanox[2].txt [ /zbox.zanox ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\BYZ3DT9Z.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\FD1X9H8H.txt [ /adfarm1.adition.com ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\JUZ235KL.txt [ /ad.adserver01.de ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\03F2CY01.txt [ /tracking.mlsat02.de ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\HCI3V33T.txt [ /webmasterplan.com ]
        C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Cookies\2UKPPY53.txt [ /ad3.adfarm1.adition.com ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@admax.quisma[1].txt [ Cookie:sebastian@admax.quisma.com/tracking/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\sebastian@admax.quisma[3].txt [ Cookie:sebastian@admax.quisma.com/tracking/view/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@serving-sys[1].txt [ Cookie:sebastian@serving-sys.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@traffictrack[2].txt [ Cookie:sebastian@traffictrack.de/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@www.pro-advertise[2].txt [ Cookie:sebastian@www.pro-advertise.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@zbox.zanox[2].txt [ Cookie:sebastian@zbox.zanox.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@www.googleadservices[1].txt [ Cookie:sebastian@www.googleadservices.com/pagead/conversion/1055417539/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@wunderloop.zanox[2].txt [ Cookie:sebastian@wunderloop.zanox.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\QUZX6MSG.txt [ Cookie:sebastian@at.atwola.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@adopt.euroclick[2].txt [ Cookie:sebastian@adopt.euroclick.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@msnportal.112.2o7[1].txt [ Cookie:sebastian@msnportal.112.2o7.net/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@2o7[1].txt [ Cookie:sebastian@2o7.net/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@adsrv.admediate[2].txt [ Cookie:sebastian@adsrv.admediate.net/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@www.etracker[1].txt [ Cookie:sebastian@www.etracker.de/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@ad.zanox[2].txt [ Cookie:sebastian@ad.zanox.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@adfarm1.adition[1].txt [ Cookie:sebastian@adfarm1.adition.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@partypoker[3].txt [ Cookie:sebastian@partypoker.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@ads.quartermedia[1].txt [ Cookie:sebastian@ads.quartermedia.de/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@ad.adnet[1].txt [ Cookie:sebastian@ad.adnet.de/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@www.googleadservices[2].txt [ Cookie:sebastian@www.googleadservices.com/pagead/conversion/1072331127/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@unitymedia[1].txt [ Cookie:sebastian@unitymedia.de/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@trinitymirror.112.2o7[1].txt [ Cookie:sebastian@trinitymirror.112.2o7.net/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@smartadserver[2].txt [ Cookie:sebastian@smartadserver.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@tracking.quisma[1].txt [ Cookie:sebastian@tracking.quisma.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@track.webtrekk[1].txt [ Cookie:sebastian@track.webtrekk.de/900089555233333/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@de2.komtrack[2].txt [ Cookie:sebastian@de2.komtrack.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@partygaming.122.2o7[1].txt [ Cookie:sebastian@partygaming.122.2o7.net/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@adserver.easyad[1].txt [ Cookie:sebastian@adserver.easyad.info/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@eas.apm.emediate[1].txt [ Cookie:sebastian@eas.apm.emediate.eu/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@ww251.smartadserver[1].txt [ Cookie:sebastian@ww251.smartadserver.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\GW3W18IZ.txt [ Cookie:sebastian@ad.yieldmanager.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@indextools[2].txt [ Cookie:sebastian@indextools.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@ad.adnet[3].txt [ Cookie:sebastian@ad.adnet.biz/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@ads-dev.youporn[1].txt [ Cookie:sebastian@ads-dev.youporn.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@webmasterplan[1].txt [ Cookie:sebastian@webmasterplan.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@komtrack[2].txt [ Cookie:sebastian@komtrack.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@adtech[1].txt [ Cookie:sebastian@adtech.de/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@allesklarcomag.112.2o7[1].txt [ Cookie:sebastian@allesklarcomag.112.2o7.net/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@ad3.adfarm1.adition[2].txt [ Cookie:sebastian@ad3.adfarm1.adition.com/ ]
        C:\USERS\SEBASTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\sebastian@partypoker[2].txt [ Cookie:sebastian@partypoker.net/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@serving-sys[1].txt [ Cookie:sebastian@serving-sys.com/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@ar.atwola[1].txt [ Cookie:sebastian@ar.atwola.com/html ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@zbox.zanox[2].txt [ Cookie:sebastian@zbox.zanox.com/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@at.atwola[2].txt [ Cookie:sebastian@at.atwola.com/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@admax.quisma[1].txt [ Cookie:sebastian@admax.quisma.com/tracking/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@adopt.euroclick[2].txt [ Cookie:sebastian@adopt.euroclick.com/ ]
        C:\USERS\SEBASTIAN\Cookies\BYZ3DT9Z.txt [ Cookie:sebastian@ad2.adfarm1.adition.com/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@2o7[2].txt [ Cookie:sebastian@2o7.net/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@tracking.mindshare[1].txt [ Cookie:sebastian@tracking.mindshare.de/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@ad.zanox[1].txt [ Cookie:sebastian@ad.zanox.com/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@atwola[1].txt [ Cookie:sebastian@atwola.com/ ]
        C:\USERS\SEBASTIAN\Cookies\FD1X9H8H.txt [ Cookie:sebastian@adfarm1.adition.com/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@unitymedia[1].txt [ Cookie:sebastian@unitymedia.de/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@zanox[2].txt [ Cookie:sebastian@zanox.com/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@smartadserver[2].txt [ Cookie:sebastian@smartadserver.com/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@tacoda.at.atwola[1].txt [ Cookie:sebastian@tacoda.at.atwola.com/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@tracking.quisma[2].txt [ Cookie:sebastian@tracking.quisma.com/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@partygaming.122.2o7[1].txt [ Cookie:sebastian@partygaming.122.2o7.net/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@www.windowsmedia[2].txt [ Cookie:sebastian@www.windowsmedia.com/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@zanox-affiliate[1].txt [ Cookie:sebastian@zanox-affiliate.de/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@adx.chip[1].txt [ Cookie:sebastian@adx.chip.de/ ]
        C:\USERS\SEBASTIAN\Cookies\JUZ235KL.txt [ Cookie:sebastian@ad.adserver01.de/ ]
        C:\USERS\SEBASTIAN\Cookies\03F2CY01.txt [ Cookie:sebastian@tracking.mlsat02.de/tmobile/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@de.at.atwola[1].txt [ Cookie:sebastian@de.at.atwola.com/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@oberon-media[1].txt [ Cookie:sebastian@oberon-media.com/ ]
        C:\USERS\SEBASTIAN\Cookies\HCI3V33T.txt [ Cookie:sebastian@webmasterplan.com/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@admax.quisma[3].txt [ Cookie:sebastian@admax.quisma.com/tracking/view/ ]
        C:\USERS\SEBASTIAN\Cookies\sebastian@track.adform[2].txt [ Cookie:sebastian@track.adform.net/ ]
        C:\USERS\SEBASTIAN\Cookies\2UKPPY53.txt [ Cookie:sebastian@ad3.adfarm1.adition.com/ ]
        C:\USERS\SEBASTIAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\SEBASTIAN@ADS.HEIAS[2].TXT [ /ADS.HEIAS ]
        C:\USERS\SEBASTIAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\SEBASTIAN@ADSERVER.71I[1].TXT [ /ADSERVER.71I ]
        C:\USERS\SEBASTIAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\SEBASTIAN@ROTATOR.ADJUGGLER[1].TXT [ /ROTATOR.ADJUGGLER ]
        C:\USERS\SEBASTIAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\SEBASTIAN@SEVENONEINTERMEDIA.112.2O7[1].TXT [ /SEVENONEINTERMEDIA.112.2O7 ]
        C:\USERS\SEBASTIAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\SEBASTIAN@YOUPORN[1].TXT [ /YOUPORN ]
        eas.apm.emediate.eu [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        adserver.71i.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        de.partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .gostats.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .azjmp.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .trafficrevenue.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        wstat.wibiya.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .usenext.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adserver.adtechus.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .nextag.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ibanner.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ads.247activemedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        adsrv1.admediate.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .cunda.122.2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .advert-layer.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .velmedia.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        s3.netxmedia.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ads.rokatraffic.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .server.cpmstar.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .xm.xtendmedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        adservercentral.info [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .game-advertising-online.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        s07.flagcounter.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        s03.flagcounter.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        s03.flagcounter.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        counter.solarcharts.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        stats.realconsulter.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        s08.flagcounter.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        tracking.sim-technik.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        tracking.haribo.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .mediabrandsww.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .wissende.122.2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .aim4media.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .aim4media.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        s06.flagcounter.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        tracking.hostgator.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .advertstream.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .cofidis2.solution.weborama.fr [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.track-visits.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        publishers.domainadvertising.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        trackstatsnow.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        live.realtimewebstats.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .azjmp.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.mediamarkt.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .c.gigcount.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        s04.flagcounter.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .tto2.traffictrack.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        adserver.gb4.motorpresse.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .blogads.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.usenext.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        s2.netxmedia.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        s3.netxmedia.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .nextag.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        pfatracking.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        adserver.yopi.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        s03.flagcounter.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .unrulymedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .click.right-ads.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ad.velmedia.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .ad.velmedia.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        tracking.mobile.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        s07.flagcounter.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        httptrack.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .atrack.allposters.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        httptrack.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        s09.flagcounter.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        s09.flagcounter.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aelyuicjwlp.stats.esomniture.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .mmotraffic.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .mmotraffic.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .server.cpmstar.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        trackingcdn.porsche.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .pornme.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .pornme.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.pornme.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        adserver.doccheck.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .paypal.112.2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wfkicjcpwfo.stats.esomniture.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        adserver2.clipkit.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        findonlinesurveys.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        findonlinesurveys.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        findonlinesurveys.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        findonlinesurveys.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        findonlinesurveys.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        findonlinesurveys.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .de.partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        dc.tremormedia.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.netdebit-counter.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        edates.traffective-tracking.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        edates.traffective-tracking.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        edates.traffective-tracking.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.elitepvpers.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .elitepvpers.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.elitepvpers.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        www.elitepvpers.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .elitepvpers.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .elitepvpers.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SEBASTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BFGEJ6RS.DEFAULT\COOKIES.SQLITE ]


malewarebytes:

Code:



Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.27.03

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19170
Sebastian :: SEBASTIAN-PC [Administrator]

27.01.2012 16:05:49
mbam-log-2012-01-27 (16-05-49).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 287644
Laufzeit: 1 Stunde(n), 14 Minute(n), 11 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

hoffe die Neuentdeckungen sind nicht so schlimm?

cosinus 29.01.2012 18:08

Sieht ok aus, da wurden nur Cookies gefunden. Die können weg. Und offensichtlich hat ESET Fehlalarme im Vista-Codec-pack gemeldet.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ist das System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

sebastian356 29.01.2012 19:28

nein, nix..außer das ich das gefühl hab das er länger braucht um hoch zufahren..ist aber eher subjektiv (denke ich) da ich sonst nie davor sitze wenn er hoch fährt.

aber bitte verrate mir noch wie ich das system in zukunft sicherer machen kann, ich vorher nie probleme hatte bzw. auch immer hinter her war mit aktualisieren und scannen ( mit avira und spybot) ..zählt das nix? soll ich da lieber auf eset und malewarebytes setzen?

ein riesen großes DANKESCHÖN an dieser stelle an dich!
du hast mir sehr geholfen!

cosinus 29.01.2012 19:32

Halte Dich am besten grob an diese Regeln:
  1. Sei misstrauisch im Internet und v.a. bei unbekannten E-Mails, sei vorsichtig bei der Herausgabe persönlicher Daten!!
  2. Halte Windows und alle verwendeten Programme immer aktuell - unterstützen kann dich dabei Secunia PSI
  3. Führe regelmäßig Backups auf externe Medien durch
  4. Arbeite mit eingeschränkten Rechten
  5. Nutze sicherere Programme wie zB Opera oder Firefox zum Surfen statt den IE, zum Mailen Thunderbird statt Outlook Express - E-Mails nur als reinen text anzeigen lassen
  6. automatische Wiedergabe von allen Laufwerken komplett deaktivieren, denn das ist ein unnötiges Sicherheitsrisiko
  7. Bei der Installation von Software möglichst darauf achten, dass die Setups aus offiziellen Quellen stammen und du bei der Installation nach Möglichkeit die benutzerdefinierte Methode wählst - dann hast du die Möglichkeit etwaigen Schrott (wie Toolbars oder sowas wie RegistryBooster) abzuwählen, welcher sonst einfach mitinstalliert wird.
  8. Bösartige bzw. ungewollte Sites von vornherein blockieren lassen mit Hilfe der MVPS Hosts File => Blocking Unwanted Parasites with a Hosts File
  9. Finger weg von: TuneUp, Registry-Cleanern aller Art, Softonic sowie illegalen Cracks/Keygens oder anderen "Tools" um ein kommerzielles Programm ohne Lizenz nutzen zu können
  10. dubiose Seiten bzw. Kinofilm-Streaming-Portale ebenfalls sein lassen, erstens handelt man sich dort schnell Malware ein oder kann in Abofallen geraten und zweitens bewegen sich diese Seiten in einer rechtlichen Grauzone.


Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

sebastian356 01.02.2012 17:05

ein riesengroßes dankeschön nochmal!

wenn ich combofix über das ausführ-fenster schließen will bringt es die fehlermeldung das es es nicht findet.
und es ist auch nicht als installiertes programm aufgeführt.

cosinus 02.02.2012 11:37

Downloade dir bitte CF_UNINST.exe und speichere diese auf deinem Desktop.
  • Starte die CF_UNINST.exe
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Folge den Anweisungen auf dem Desktop.
  • Wenn das Tool fertig ist sollte sich ein Fenster mit folgendem Inhalt öffnen: Done

sebastian356 06.02.2012 19:08

danke, wie du gesagt hattest..ein fenster und darin done!

wie läuft das jetzt ab, da dieses von mir eröffnete thema (oder besser die bearbeitung deinerseits) ja auf mein problem zugeschnitten ist, hilft es ja den anderen nicht. bleibt das dann als datenmüll bei euch auf dem server oder muss ich mich als "eröffner" des themas drum kümmern das das gelöscht wird?

besten gruß

cosinus 06.02.2012 20:04

Hier wird nichts gelöscht!

sebastian356 07.02.2012 16:25

ich weiß, mir wurde geholfen und ich sollte (bin es auch) zufrieden sein, aber was macht es denn für einen sinn das die beiträge nicht gelöscht werden. es wird ja auch immer betont das das jeweils individuelle problemlösungen sind.

cosinus 07.02.2012 19:06

Einfach mal die Hinweise lesen => http://www.trojaner-board.de/108422-...-anfragen.html


Alle Zeitangaben in WEZ +1. Es ist jetzt 06:05 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130