Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Rechner gesperrt (https://www.trojaner-board.de/123911-rechner-gesperrt.html)

traudel769 11.09.2012 18:53

Rechner gesperrt
 
Guten Abend in die Runde,

ich habe mir am Samstag beim Surfen offensichtlich einen Trojaner zugelegt :heulen: Meine Antiviren-Software (Avira Free Antivirus) hat nicht angeschlagen. Plötzlich war der Bildschirm weiß und gesperrt, weil ich angeblich auf verbotenen Seiten unterwegs gewesen sein soll und ich bei Zahlung von 100 Euro per ucash würde einen Code zum Entsperren erhalten.
Ich habe dann meinen Rechner im abgesicherten Modus gestartet und ein wenig gegoogelt.
Als erstes hab ich mir Kaspersky windows unlocker geholt und nach Anleitung ausgeführt. Es hat aber nichts bewirkt.
Also weitergegoogelt. Dann hab ich einen Hinweis gefunden, dass man in der msconfig Autostartprogramme blockieren soll. Ich bin blond! :pfeiff: Ich bin Anwender. Aber schlimmer konnte es wohl kaum werden, also hab ich mich da ran gewagt und ich hab da was verdächtiges gefunden und deaktiviert. Siehe da, ich konnte wieder normal starten. Mir ist klar, dass mein Problem damit nicht behoben ist.
Der Suchlauf von Antivir hat nix ergeben.
Heute (!) - 4 Tage nach dem "crash" hat avira eine Meldung gebracht
2 Objekte
C:\ProgrammData\hweyvbr.exe
user\ich\0.470257039331059.exe
in Quarantäne verschoben.
Dann hab ich alles gemäß eurer Anleitung durchgeführt
defogger
otl
gmer
Die entsprechenden txt.dateien sind im Anhang.

Da Avira inzwischen (wenn auch viel zu spät) gewarnt hab, hab ich Malwarebytes noch nicht verwendet.

Ich hoffe, ihr könnt mir helfen mit entgültig clean zu werden.
Schon mal vielen Dank vorab.

edit
Ich hatte vergessen zu erwähnen, dass ich noch meine Fotos vom Rechner auf eine externe FP verschoben habe. Hab ich damit meine externe jetzt auch infiziert? Ich weiß inzwischen, dass das vlt. sehr dumm war, aber ich bin Hobbyfotograf und wollte einfach nur retten was zu retten ist.

cosinus 12.09.2012 11:02

Bitte erstmal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

traudel769 14.09.2012 03:37

Danke für die schnelle Antwort. Das Scannen hat natürlich einige Zeit bei mir in Anspruch genommen
Hier die Ergebnisse.
Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.12.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 7.0.6002.18005
Susan :: LAPTOP [Administrator]

Schutz: Aktiviert

13.09.2012 03:43:43
mbam-log-2012-09-13 (03-43-43).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 385850
Laufzeit: 2 Stunde(n), 17 Minute(n), 11 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


Code:

C:\ProgramData\yleehzpzdovhrsn\main.html        HTML/Ransom.B trojan
C:\Users\All Users\yleehzpzdovhrsn\main.html        HTML/Ransom.B trojan

Ich hoffe, dass ich das richtig poste.

Vielen Dank und schönen Tag.

cosinus 14.09.2012 14:51

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

traudel769 14.09.2012 16:09

Ich hatte ein paar mal abgebrochen, weil ich gemerkt hatte, dass ich auch externe Datenträger angeschlossen hatte, bzw. dass die Zeit nicht reicht.

Sorry, ich wusste nicht, dass bei den Abbrüchen auch Daten entstanden sein könnten, die zur Analyse benötigt werden.

Anbei jetzt alles, was ich unter Logdateien gefunden habe.

Danke für deine/eure Nachsicht.


mbam-log-2012-09-13 (03-43-43)-editor
Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.12.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 7.0.6002.18005
Susan :: LAPTOP [Administrator]

Schutz: Aktiviert

13.09.2012 03:43:43
mbam-log-2012-09-13 (03-43-43).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 385850
Laufzeit: 2 Stunde(n), 17 Minute(n), 11 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

mbam-log-2012-09-12 (17-42-14)-Editor
Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.12.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 7.0.6002.18005
Susan :: LAPTOP [Administrator]

Schutz: Aktiviert

12.09.2012 17:42:14
mbam-log-2012-09-12 (17-42-14).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|G:\|H:\|M:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 44996
Laufzeit: 5 Minute(n), 12 Sekunde(n) [Abgebrochen]

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

protection-log-2012-09-12-Editor
Code:

2012/09/12 17:30:40 +0200        LAPTOP        Susan        MESSAGE        Starting protection
2012/09/12 17:30:45 +0200        LAPTOP        Susan        MESSAGE        Protection started successfully
2012/09/12 17:30:48 +0200        LAPTOP        Susan        MESSAGE        Starting IP protection
2012/09/12 17:30:54 +0200        LAPTOP        Susan        MESSAGE        IP Protection started successfully
2012/09/12 17:31:19 +0200        LAPTOP        Susan        MESSAGE        Executing scheduled update:  Daily
2012/09/12 17:32:11 +0200        LAPTOP        Susan        MESSAGE        Database already up-to-date
2012/09/12 17:38:19 +0200        LAPTOP        Susan        MESSAGE        Starting protection
2012/09/12 17:38:19 +0200        LAPTOP        Susan        MESSAGE        Protection started successfully
2012/09/12 17:38:19 +0200        LAPTOP        Susan        MESSAGE        Starting IP protection
2012/09/12 17:38:25 +0200        LAPTOP        Susan        MESSAGE        IP Protection started successfully
2012/09/12 17:41:05 +0200        LAPTOP        Susan        MESSAGE        Starting database refresh
2012/09/12 17:41:05 +0200        LAPTOP        Susan        MESSAGE        Stopping IP protection
2012/09/12 17:41:06 +0200        LAPTOP        Susan        MESSAGE        IP Protection stopped successfully
2012/09/12 17:41:10 +0200        LAPTOP        Susan        MESSAGE        Database refreshed successfully
2012/09/12 17:41:10 +0200        LAPTOP        Susan        MESSAGE        Starting IP protection
2012/09/12 17:41:18 +0200        LAPTOP        Susan        MESSAGE        IP Protection started successfully
2012/09/12 18:05:27 +0200        LAPTOP        Susan        MESSAGE        Starting protection
2012/09/12 18:05:27 +0200        LAPTOP        Susan        MESSAGE        Protection started successfully
2012/09/12 18:05:27 +0200        LAPTOP        Susan        MESSAGE        Starting IP protection
2012/09/12 18:05:36 +0200        LAPTOP        Susan        MESSAGE        IP Protection started successfully

protection-log-2012-09-13-editor
Code:


2012/09/13 03:22:40 +0200        LAPTOP        Susan        MESSAGE        Stopping IP protection
2012/09/13 03:22:45 +0200        LAPTOP        Susan        MESSAGE        IP Protection stopped successfully
2012/09/13 03:22:45 +0200        LAPTOP        Susan        MESSAGE        Starting IP protection
2012/09/13 03:22:52 +0200        LAPTOP        Susan        MESSAGE        IP Protection started successfully
2012/09/13 06:33:29 +0200        LAPTOP        Susan        MESSAGE        Starting protection
2012/09/13 06:33:29 +0200        LAPTOP        Susan        MESSAGE        Protection started successfully
2012/09/13 06:33:29 +0200        LAPTOP        Susan        MESSAGE        Starting IP protection
2012/09/13 06:33:35 +0200        LAPTOP        Susan        MESSAGE        IP Protection started successfully
2012/09/13 17:35:48 +0200        LAPTOP        Susan        MESSAGE        Starting protection
2012/09/13 17:35:48 +0200        LAPTOP        Susan        MESSAGE        Protection started successfully
2012/09/13 17:35:48 +0200        LAPTOP        Susan        MESSAGE        Starting IP protection
2012/09/13 17:35:55 +0200        LAPTOP        Susan        MESSAGE        IP Protection started successfully
2012/09/13 17:40:51 +0200        LAPTOP        Susan        MESSAGE        Executing scheduled update:  Daily
2012/09/13 17:40:52 +0200        LAPTOP        Susan        ERROR        Scheduled update failed:  Host not found failed with error code 0

protection-log-2012-09-14 - Editor
Code:


2012/09/14 16:42:23 +0200        LAPTOP        Susan        MESSAGE        Starting protection
2012/09/14 16:42:23 +0200        LAPTOP        Susan        MESSAGE        Protection started successfully
2012/09/14 16:42:23 +0200        LAPTOP        Susan        MESSAGE        Starting IP protection
2012/09/14 16:42:29 +0200        LAPTOP        Susan        MESSAGE        IP Protection started successfully
2012/09/14 16:49:35 +0200        LAPTOP        Susan        MESSAGE        Executing scheduled update:  Daily
2012/09/14 16:49:55 +0200        LAPTOP        Susan        MESSAGE        Starting database refresh
2012/09/14 16:49:55 +0200        LAPTOP        Susan        MESSAGE        Scheduled update executed successfully:  database updated from version v2012.09.12.05 to version v2012.09.14.04
2012/09/14 16:49:55 +0200        LAPTOP        Susan        MESSAGE        Stopping IP protection
2012/09/14 16:49:56 +0200        LAPTOP        Susan        MESSAGE        IP Protection stopped successfully
2012/09/14 16:50:00 +0200        LAPTOP        Susan        MESSAGE        Database refreshed successfully
2012/09/14 16:50:00 +0200        LAPTOP        Susan        MESSAGE        Starting IP protection
2012/09/14 16:50:06 +0200        LAPTOP        Susan        MESSAGE        IP Protection started successfully

Sorry, ich wusste nicht, dass bei den Abbrüchen auch Daten entstanden sein könnten, die zur Analyse benötigt werden.

cosinus 14.09.2012 20:17

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.

Falls der adwCleaner schon mal in der runtergeladen wurde, bitte die alte adwcleaner.exe löschen und neu runterladen!!
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Rx].txt. (x=fortlaufende Nummer)

traudel769 14.09.2012 23:39

Code:


# AdwCleaner v2.001 - Datei am 09/15/2012 um 00:37:06 erstellt
# Aktualisiert am 09/09/2012 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : Susan - LAPTOP
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Susan\Desktop\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gefunden : C:\Program Files\Conduit
Ordner Gefunden : C:\Users\Susan\AppData\Local\Conduit
Ordner Gefunden : C:\Users\Susan\AppData\LocalLow\Conduit
Ordner Gefunden : C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\efjwbygu.default\ConduitCommon
Ordner Gefunden : C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\efjwbygu.default\CT2269050
Ordner Gefunden : C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\efjwbygu.default\CT3228856
Ordner Gefunden : C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\efjwbygu.default\extensions\{81fae9c9-cfbd-4cb3-8322-412e72f55f65}
Ordner Gefunden : C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\efjwbygu.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
Ordner Gefunden : C:\Users\Susan\AppData\Roaming\OpenCandy

***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT3228856
Schlüssel Gefunden : HKLM\Software\Conduit
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gefunden : HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}

***** [Internet Browser] *****

-\\ Internet Explorer v7.0.6002.18005

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v14.0.1 (de)

Profilname : default
Datei : C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\efjwbygu.default\prefs.js

Gefunden : user_pref("CT2269050..clientLogIsEnabled", true);
Gefunden : user_pref("CT2269050..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Gefunden : user_pref("CT2269050..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Gefunden : user_pref("CT2269050.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Gefunden : user_pref("CT2269050.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Gefunden : user_pref("CT2269050.AppTrackingLastCheckTime", "Wed Jan 18 2012 20:51:39 GMT+0100");
Gefunden : user_pref("CT2269050.BrowserCompStateIsOpen_129681780741097243", true);
Gefunden : user_pref("CT2269050.BrowserCompStateIsOpen_129705015340022508", true);
Gefunden : user_pref("CT2269050.CTID", "CT2269050");
Gefunden : user_pref("CT2269050.CurrentServerDate", "18-1-2012");
Gefunden : user_pref("CT2269050.DSInstall", false);
Gefunden : user_pref("CT2269050.DialogsAlignMode", "LTR");
Gefunden : user_pref("CT2269050.DialogsGetterLastCheckTime", "Wed Jan 18 2012 20:50:31 GMT+0100");
Gefunden : user_pref("CT2269050.DownloadReferralCookieData", "");
Gefunden : user_pref("CT2269050.EMailNotifierPollDate", "Wed Jan 18 2012 20:50:27 GMT+0100");
Gefunden : user_pref("CT2269050.EnableClickToSearchBox", false);
Gefunden : user_pref("CT2269050.EnableSearchHistory", false);
Gefunden : user_pref("CT2269050.EnableSearchSuggest", false);
Gefunden : user_pref("CT2269050.FirstServerDate", "18-1-2012");
Gefunden : user_pref("CT2269050.FirstTime", true);
Gefunden : user_pref("CT2269050.FirstTimeFF3", true);
Gefunden : user_pref("CT2269050.FixPageNotFoundErrors", false);
Gefunden : user_pref("CT2269050.GroupingServerCheckInterval", 1440);
Gefunden : user_pref("CT2269050.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Gefunden : user_pref("CT2269050.HPInstall", false);
Gefunden : user_pref("CT2269050.HasUserGlobalKeys", true);
Gefunden : user_pref("CT2269050.HomePageProtectorEnabled", false);
Gefunden : user_pref("CT2269050.HomepageBeforeUnload", "hxxp://takinus-blog.blogspot.com/");
Gefunden : user_pref("CT2269050.Initialize", true);
Gefunden : user_pref("CT2269050.InitializeCommonPrefs", true);
Gefunden : user_pref("CT2269050.InstallationAndCookieDataSentCount", 1);
Gefunden : user_pref("CT2269050.InstallationType", "UnknownIntegration");
Gefunden : user_pref("CT2269050.InstalledDate", "Wed Jan 18 2012 20:50:27 GMT+0100");
Gefunden : user_pref("CT2269050.InvalidateCache", false);
Gefunden : user_pref("CT2269050.IsAlertDBUpdated", true);
Gefunden : user_pref("CT2269050.IsGrouping", false);
Gefunden : user_pref("CT2269050.IsInitSetupIni", true);
Gefunden : user_pref("CT2269050.IsMulticommunity", false);
Gefunden : user_pref("CT2269050.IsOpenThankYouPage", false);
Gefunden : user_pref("CT2269050.IsOpenUninstallPage", false);
Gefunden : user_pref("CT2269050.LanguagePackLastCheckTime", "Wed Jan 18 2012 20:50:39 GMT+0100");
Gefunden : user_pref("CT2269050.LanguagePackReloadIntervalMM", 1440);
Gefunden : user_pref("CT2269050.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Gefunden : user_pref("CT2269050.LastLogin_3.9.0.3", "Wed Jan 18 2012 20:50:39 GMT+0100");
Gefunden : user_pref("CT2269050.LatestVersion", "3.9.0.3");
Gefunden : user_pref("CT2269050.Locale", "en");
Gefunden : user_pref("CT2269050.MCDetectTooltipHeight", "83");
Gefunden : user_pref("CT2269050.MCDetectTooltipShow", false);
Gefunden : user_pref("CT2269050.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Gefunden : user_pref("CT2269050.MCDetectTooltipWidth", "295");
Gefunden : user_pref("CT2269050.MyStuffEnabledAtInstallation", true);
Gefunden : user_pref("CT2269050.OriginalFirstVersion", "3.9.0.3");
Gefunden : user_pref("CT2269050.RadioIsPodcast", false);
Gefunden : user_pref("CT2269050.RadioLastCheckTime", "Wed Jan 18 2012 20:50:39 GMT+0100");
Gefunden : user_pref("CT2269050.RadioLastUpdateIPServer", "3");
Gefunden : user_pref("CT2269050.RadioLastUpdateServer", "129132338014870000");
Gefunden : user_pref("CT2269050.RadioMediaID", "12473383");
Gefunden : user_pref("CT2269050.RadioMediaType", "Media Player");
Gefunden : user_pref("CT2269050.RadioMenuSelectedID", "EBRadioMenu_CT226905012473383");
Gefunden : user_pref("CT2269050.RadioShrinkedFromSetup", false);
Gefunden : user_pref("CT2269050.RadioStationName", "Hotmix%20108");
Gefunden : user_pref("CT2269050.RadioStationURL", "hxxp://67.202.67.18:8082");
Gefunden : user_pref("CT2269050.SHRINK_TOOLBAR", 1);
Gefunden : user_pref("CT2269050.SearchBackToDefaultEngine", false);
Gefunden : user_pref("CT2269050.SearchCaption", "DVDVideoSoftTB Customized Web Search");
Gefunden : user_pref("CT2269050.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");
Gefunden : user_pref("CT2269050.SearchFromAddressBarIsInit", true);
Gefunden : user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT226[...]
Gefunden : user_pref("CT2269050.SearchInNewTabEnabled", true);
Gefunden : user_pref("CT2269050.SearchInNewTabIntervalMM", 1440);
Gefunden : user_pref("CT2269050.SearchInNewTabLastCheckTime", "Wed Jan 18 2012 20:50:39 GMT+0100");
Gefunden : user_pref("CT2269050.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Gefunden : user_pref("CT2269050.SearchInNewTabUserEnabled", false);
Gefunden : user_pref("CT2269050.SearchProtectorEnabled", false);
Gefunden : user_pref("CT2269050.SearchProtectorToolbarDisabled", false);
Gefunden : user_pref("CT2269050.SendProtectorDataViaLogin", true);
Gefunden : user_pref("CT2269050.ServiceMapLastCheckTime", "Wed Jan 18 2012 20:50:23 GMT+0100");
Gefunden : user_pref("CT2269050.SettingsLastCheckTime", "Wed Jan 18 2012 20:50:23 GMT+0100");
Gefunden : user_pref("CT2269050.SettingsLastUpdate", "1326723880");
Gefunden : user_pref("CT2269050.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=13");
Gefunden : user_pref("CT2269050.ThirdPartyComponentsInterval", 504);
Gefunden : user_pref("CT2269050.ThirdPartyComponentsLastCheck", "Wed Jan 18 2012 20:50:23 GMT+0100");
Gefunden : user_pref("CT2269050.ThirdPartyComponentsLastUpdate", "1312887586");
Gefunden : user_pref("CT2269050.ToolbarShrinkedFromSetup", false);
Gefunden : user_pref("CT2269050.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2269050");
Gefunden : user_pref("CT2269050.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Gefunden : user_pref("CT2269050.UserID", "UN24871950856370964");
Gefunden : user_pref("CT2269050.ValidationData_Toolbar", 2);
Gefunden : user_pref("CT2269050.WeatherNetwork", "");
Gefunden : user_pref("CT2269050.WeatherPollDate", "Wed Jan 18 2012 20:51:22 GMT+0100");
Gefunden : user_pref("CT2269050.WeatherUnit", "C");
Gefunden : user_pref("CT2269050.alertChannelId", "666138");
Gefunden : user_pref("CT2269050.approveUntrustedApps", false);
Gefunden : user_pref("CT2269050.autoDisableScopes", -1);
Gefunden : user_pref("CT2269050.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e.:2z527", "2423");
Gefunden : user_pref("CT2269050.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e06cg5el8:", "6E6D6F6C6A736F737673");
Gefunden : user_pref("CT2269050.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737572707975797C79242F4B4947[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e31;cjc<=fbj#ncf", "247E61393F236B25757677712A212C6E414F444[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Gefunden : user_pref("CT2269050.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Gefunden : user_pref("CT2269050.backendstorage./9b-0?3g>d", "686E6E413E3F6D717A7145717720754D4C78254C217C202A21[...]
Gefunden : user_pref("CT2269050.backendstorage./9b-0?3g@6:5;", "");
Gefunden : user_pref("CT2269050.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
Gefunden : user_pref("CT2269050.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E424[...]
Gefunden : user_pref("CT2269050.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Gefunden : user_pref("CT2269050.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484776213F3E484F4E4D464[...]
Gefunden : user_pref("CT2269050.backendstorage./9b5ba==9cjag", "6C3D3B40423E6F747A7145484A734A794D794D2250");
Gefunden : user_pref("CT2269050.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6F6C6A736F737675717775");
Gefunden : user_pref("CT2269050.backendstorage./9b9643g3/9e", "6A");
Gefunden : user_pref("CT2269050.backendstorage./9b<:222h64<", "393F352F3E");
Gefunden : user_pref("CT2269050.backendstorage./9b=+03eh8h8j?:", "4443");
Gefunden : user_pref("CT2269050.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Gefunden : user_pref("CT2269050.backendstorage./9b?b0d:8aj62<h", "6D");
Gefunden : user_pref("CT2269050.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Gefunden : user_pref("CT2269050.backendstorage.autocompletepro_enable", "31");
Gefunden : user_pref("CT2269050.backendstorage.autocompletepro_enable_auto", "31");
Gefunden : user_pref("CT2269050.backendstorage.shoppingapp.gk.exipres", "4D6F6E204A616E20323320323031322032303A[...]
Gefunden : user_pref("CT2269050.backendstorage.shoppingapp.gk.geolocation", "6272617A696C");
Gefunden : user_pref("CT2269050.components.1000034", false);
Gefunden : user_pref("CT2269050.components.1000082", false);
Gefunden : user_pref("CT2269050.components.1000234", false);
Gefunden : user_pref("CT2269050.components.129023235807856892", false);
Gefunden : user_pref("CT2269050.components.129121052374999726", false);
Gefunden : user_pref("CT2269050.components.129351672002618989", false);
Gefunden : user_pref("CT2269050.components.129351776130744254", false);
Gefunden : user_pref("CT2269050.components.129391330693125668", false);
Gefunden : user_pref("CT2269050.components.129466585396013141", false);
Gefunden : user_pref("CT2269050.components.129681780741097243", false);
Gefunden : user_pref("CT2269050.components.129705015340022508", false);
Gefunden : user_pref("CT2269050.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Gefunden : user_pref("CT2269050.globalFirstTimeInfoLastCheckTime", "Wed Jan 18 2012 20:50:24 GMT+0100");
Gefunden : user_pref("CT2269050.homepageProtectorEnableByLogin", true);
Gefunden : user_pref("CT2269050.initDone", true);
Gefunden : user_pref("CT2269050.isAppTrackingManagerOn", true);
Gefunden : user_pref("CT2269050.isFirstRadioInstallation", false);
Gefunden : user_pref("CT2269050.isSearchProtectorNotifyChanges", false);
Gefunden : user_pref("CT2269050.myStuffEnabled", true);
Gefunden : user_pref("CT2269050.myStuffPublihserMinWidth", 400);
Gefunden : user_pref("CT2269050.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Gefunden : user_pref("CT2269050.myStuffServiceIntervalMM", 1440);
Gefunden : user_pref("CT2269050.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Gefunden : user_pref("CT2269050.revertSettingsEnabled", true);
Gefunden : user_pref("CT2269050.searchProtectorDialogDelayInSec", 10);
Gefunden : user_pref("CT2269050.searchProtectorEnableByLogin", true);
Gefunden : user_pref("CT2269050.testingCtid", "");
Gefunden : user_pref("CT2269050.toolbarAppMetaDataLastCheckTime", "Wed Jan 18 2012 20:50:31 GMT+0100");
Gefunden : user_pref("CT2269050.toolbarContextMenuLastCheckTime", "Wed Jan 18 2012 20:50:40 GMT+0100");
Gefunden : user_pref("CT2269050.usageEnabled", false);
Gefunden : user_pref("CT2269050.usagesFlag", 2);
Gefunden : user_pref("CT3228856..clientLogIsEnabled", false);
Gefunden : user_pref("CT3228856..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Gefunden : user_pref("CT3228856..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Gefunden : user_pref("CT3228856.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Gefunden : user_pref("CT3228856.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Gefunden : user_pref("CT3228856.BrowserCompStateIsOpen_5861880409663125392", true);
Gefunden : user_pref("CT3228856.CT3228856", "CT3228856");
Gefunden : user_pref("CT3228856.CommunitiesChangesLastCheckTime", "0");
Gefunden : user_pref("CT3228856.CurrentServerDate", "15-9-2012");
Gefunden : user_pref("CT3228856.DSInstall", false);
Gefunden : user_pref("CT3228856.DialogsAlignMode", "LTR");
Gefunden : user_pref("CT3228856.DialogsGetterLastCheckTime", "Sat Sep 15 2012 00:33:42 GMT+0200");
Gefunden : user_pref("CT3228856.DownloadReferralCookieData", "");
Gefunden : user_pref("CT3228856.EMailNotifierPollDate", "Tue Jul 03 2012 18:34:58 GMT+0200");
Gefunden : user_pref("CT3228856.EnableClickToSearchBox", false);
Gefunden : user_pref("CT3228856.EnableSearchHistory", false);
Gefunden : user_pref("CT3228856.EnableSearchSuggest", false);
Gefunden : user_pref("CT3228856.FirstServerDate", "3-7-2012");
Gefunden : user_pref("CT3228856.FirstTime", true);
Gefunden : user_pref("CT3228856.FirstTimeFF3", true);
Gefunden : user_pref("CT3228856.FirstTimeHiddenVer", true);
Gefunden : user_pref("CT3228856.FixPageNotFoundErrors", true);
Gefunden : user_pref("CT3228856.GroupingInvalidateCache", false);
Gefunden : user_pref("CT3228856.GroupingLastCheckTime", "0");
Gefunden : user_pref("CT3228856.GroupingLastServerUpdateTime", "0");
Gefunden : user_pref("CT3228856.GroupingServerCheckInterval", 1440);
Gefunden : user_pref("CT3228856.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Gefunden : user_pref("CT3228856.HPInstall", false);
Gefunden : user_pref("CT3228856.HasUserGlobalKeys", true);
Gefunden : user_pref("CT3228856.HomePageProtectorEnabled", false);
Gefunden : user_pref("CT3228856.HomepageBeforeUnload", "hxxp://takinus-blog.blogspot.com/");
Gefunden : user_pref("CT3228856.Initialize", true);
Gefunden : user_pref("CT3228856.InitializeCommonPrefs", true);
Gefunden : user_pref("CT3228856.InstallationAndCookieDataSentCount", 3);
Gefunden : user_pref("CT3228856.InstallationId", "ConduitNSISIntegration");
Gefunden : user_pref("CT3228856.InstallationType", "ConduitNSISIntegration");
Gefunden : user_pref("CT3228856.InstalledDate", "Tue Jul 03 2012 18:37:03 GMT+0200");
Gefunden : user_pref("CT3228856.InvalidateCache", false);
Gefunden : user_pref("CT3228856.IsGrouping", false);
Gefunden : user_pref("CT3228856.IsInitSetupIni", true);
Gefunden : user_pref("CT3228856.IsMulticommunity", false);
Gefunden : user_pref("CT3228856.IsOpenThankYouPage", true);
Gefunden : user_pref("CT3228856.IsOpenUninstallPage", true);
Gefunden : user_pref("CT3228856.IsProtectorsInit", true);
Gefunden : user_pref("CT3228856.LanguagePackLastCheckTime", "Fri Sep 14 2012 16:52:51 GMT+0200");
Gefunden : user_pref("CT3228856.LanguagePackReloadIntervalMM", 1440);
Gefunden : user_pref("CT3228856.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Gefunden : user_pref("CT3228856.LastLogin_3.14.1.0", "Tue Aug 21 2012 19:01:12 GMT+0200");
Gefunden : user_pref("CT3228856.LastLogin_3.15.1.0", "Sat Sep 15 2012 00:33:42 GMT+0200");
Gefunden : user_pref("CT3228856.LatestVersion", "3.15.1.0");
Gefunden : user_pref("CT3228856.Locale", "en");
Gefunden : user_pref("CT3228856.MCDetectTooltipHeight", "83");
Gefunden : user_pref("CT3228856.MCDetectTooltipShow", false);
Gefunden : user_pref("CT3228856.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Gefunden : user_pref("CT3228856.MCDetectTooltipWidth", "295");
Gefunden : user_pref("CT3228856.MyStuffEnabledAtInstallation", true);
Gefunden : user_pref("CT3228856.OriginalFirstVersion", "3.14.1.0");
Gefunden : user_pref("CT3228856.RadioLastCheckTime", "Tue Jul 03 2012 18:38:19 GMT+0200");
Gefunden : user_pref("CT3228856.RadioLastUpdateIPServer", "0");
Gefunden : user_pref("CT3228856.RadioShrinkedFromSetup", false);
Gefunden : user_pref("CT3228856.SHRINK_TOOLBAR", 1);
Gefunden : user_pref("CT3228856.SearchBackToDefaultEngine", false);
Gefunden : user_pref("CT3228856.SearchCaption", "FreemakeVideoConverterTB Customized Web Search");
Gefunden : user_pref("CT3228856.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");
Gefunden : user_pref("CT3228856.SearchFromAddressBarIsInit", true);
Gefunden : user_pref("CT3228856.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT322[...]
Gefunden : user_pref("CT3228856.SearchInNewTabEnabled", true);
Gefunden : user_pref("CT3228856.SearchInNewTabIntervalMM", 1440);
Gefunden : user_pref("CT3228856.SearchInNewTabLastCheckTime", "Fri Sep 14 2012 16:52:50 GMT+0200");
Gefunden : user_pref("CT3228856.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Gefunden : user_pref("CT3228856.SearchInNewTabUserEnabled", false);
Gefunden : user_pref("CT3228856.SearchProtectorEnabled", false);
Gefunden : user_pref("CT3228856.SearchProtectorToolbarDisabled", false);
Gefunden : user_pref("CT3228856.SendProtectorDataViaLogin", true);
Gefunden : user_pref("CT3228856.ServiceMapLastCheckTime", "Fri Sep 14 2012 16:52:51 GMT+0200");
Gefunden : user_pref("CT3228856.SettingsLastCheckTime", "Sat Sep 15 2012 00:33:41 GMT+0200");
Gefunden : user_pref("CT3228856.SettingsLastUpdate", "1347287073");
Gefunden : user_pref("CT3228856.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT3228856&SearchSource=13");
Gefunden : user_pref("CT3228856.ThirdPartyComponentsInterval", 504);
Gefunden : user_pref("CT3228856.ThirdPartyComponentsLastCheck", "Tue Jul 03 2012 18:34:55 GMT+0200");
Gefunden : user_pref("CT3228856.ThirdPartyComponentsLastUpdate", "1331805997");
Gefunden : user_pref("CT3228856.ToolbarShrinkedFromSetup", false);
Gefunden : user_pref("CT3228856.TrusteLinkUrl", "hxxp://trust.conduit.com/CT3228856");
Gefunden : user_pref("CT3228856.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Gefunden : user_pref("CT3228856.UserID", "UN58184482552275060");
Gefunden : user_pref("CT3228856.ValidationData_Toolbar", 1);
Gefunden : user_pref("CT3228856.WeatherNetwork", "");
Gefunden : user_pref("CT3228856.WeatherPollDate", "Tue Jul 03 2012 18:36:36 GMT+0200");
Gefunden : user_pref("CT3228856.WeatherUnit", "C");
Gefunden : user_pref("CT3228856.alertChannelId", "1665544");
Gefunden : user_pref("CT3228856.approveUntrustedApps", false);
Gefunden : user_pref("CT3228856.autoDisableScopes", -1);
Gefunden : user_pref("CT3228856.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e.:2z527", "247E707571777278333228702A7B797B7B7E30273224262[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e06cg5el8:", "6E6D6D71707172727578");
Gefunden : user_pref("CT3228856.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737377767778787B7E242F4B4947[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Gefunden : user_pref("CT3228856.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Gefunden : user_pref("CT3228856.backendstorage./9b-0?3g>d", "6B6B68416B3E41737A4674777B204C4C797A25797C7C532A22[...]
Gefunden : user_pref("CT3228856.backendstorage./9b-0?3g@6:5;", "");
Gefunden : user_pref("CT3228856.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E424[...]
Gefunden : user_pref("CT3228856.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Gefunden : user_pref("CT3228856.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484775213F3E484F4E4D464[...]
Gefunden : user_pref("CT3228856.backendstorage./9b5ba==9cjag", "6B6E406A406C3F727A7572794A77777C7C7B227B7A");
Gefunden : user_pref("CT3228856.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6D71707172727674757978");
Gefunden : user_pref("CT3228856.backendstorage./9b9643g3/9e", "6A");
Gefunden : user_pref("CT3228856.backendstorage./9b<:222h64<", "393F352F3E");
Gefunden : user_pref("CT3228856.backendstorage./9b=+03eh8h8j?:", "4443");
Gefunden : user_pref("CT3228856.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Gefunden : user_pref("CT3228856.backendstorage./9b?b0d:8aj62<h", "6D");
Gefunden : user_pref("CT3228856.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Gefunden : user_pref("CT3228856.backendstorage.shoppingapp.gk.exipres", "53756E204A756C20303820323031322031383A[...]
Gefunden : user_pref("CT3228856.backendstorage.shoppingapp.gk.geolocation", "6765726D616E79");
Gefunden : user_pref("CT3228856.components.1000034", false);
Gefunden : user_pref("CT3228856.components.1000082", false);
Gefunden : user_pref("CT3228856.components.1000234", false);
Gefunden : user_pref("CT3228856.components.1000515", false);
Gefunden : user_pref("CT3228856.components.129840633550036918", false);
Gefunden : user_pref("CT3228856.components.129840633550349419", false);
Gefunden : user_pref("CT3228856.components.129840633550349420", false);
Gefunden : user_pref("CT3228856.components.129840633551286921", false);
Gefunden : user_pref("CT3228856.components.129840633552849422", false);
Gefunden : user_pref("CT3228856.components.129840633553474424", false);
Gefunden : user_pref("CT3228856.components.129840633553943175", false);
Gefunden : user_pref("CT3228856.components.129852807254541663", false);
Gefunden : user_pref("CT3228856.components.5861880409663125392", false);
Gefunden : user_pref("CT3228856.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Gefunden : user_pref("CT3228856.globalFirstTimeInfoLastCheckTime", "Tue Jul 03 2012 18:34:58 GMT+0200");
Gefunden : user_pref("CT3228856.homepageProtectorEnableByLogin", true);
Gefunden : user_pref("CT3228856.initDone", true);
Gefunden : user_pref("CT3228856.isAppTrackingManagerOn", true);
Gefunden : user_pref("CT3228856.isFirstRadioInstallation", false);
Gefunden : user_pref("CT3228856.isSearchProtectorNotifyChanges", false);
Gefunden : user_pref("CT3228856.myStuffEnabled", true);
Gefunden : user_pref("CT3228856.myStuffPublihserMinWidth", 400);
Gefunden : user_pref("CT3228856.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Gefunden : user_pref("CT3228856.myStuffServiceIntervalMM", 1440);
Gefunden : user_pref("CT3228856.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Gefunden : user_pref("CT3228856.navigateToUrlOnSearch", false);
Gefunden : user_pref("CT3228856.revertSettingsEnabled", true);
Gefunden : user_pref("CT3228856.searchProtectorDialogDelayInSec", 10);
Gefunden : user_pref("CT3228856.searchProtectorEnableByLogin", true);
Gefunden : user_pref("CT3228856.testingCtid", "");
Gefunden : user_pref("CT3228856.toolbarAppMetaDataLastCheckTime", "Fri Sep 14 2012 16:52:51 GMT+0200");
Gefunden : user_pref("CT3228856.toolbarContextMenuLastCheckTime", "Tue Jul 03 2012 18:35:12 GMT+0200");
Gefunden : user_pref("CT3228856.usageEnabled", false);
Gefunden : user_pref("CT3228856.usagesFlag", 2);
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2269050/CT2269050[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3228856/CT3228856[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1665544/1658042/DE", "\"0\"[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/666138/661999/DE", "\"0\"")[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2269050", [...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3228856", [...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2269050",[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3228856",[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"018[...]
Gefunden : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Susan\\AppData\\Roaming\\Mozilla\\F[...]
Gefunden : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.14.1.0");
Gefunden : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...]
Gefunden : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
Gefunden : user_pref("CommunityToolbar.ToolbarsList", "CT2269050,CT3228856");
Gefunden : user_pref("CommunityToolbar.ToolbarsList2", "CT2269050,CT3228856");
Gefunden : user_pref("CommunityToolbar.ToolbarsList4", "CT2269050,CT3228856");
Gefunden : user_pref("CommunityToolbar.globalUserId", "e686c8e9-4fc8-401e-92ae-8cffc69a5ad9");
Gefunden : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Gefunden : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Gefunden : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Jul 03 2012 18:35:1[...]
Gefunden : user_pref("CommunityToolbar.notifications.alertEnabled", false);
Gefunden : user_pref("CommunityToolbar.notifications.alertInfoInterval", 60);
Gefunden : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue Jul 03 2012 18:36:48 GMT+020[...]
Gefunden : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Gefunden : user_pref("CommunityToolbar.notifications.locale", "en");
Gefunden : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Gefunden : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Tue Jul 03 2012 18:34:58 GMT+0200");
Gefunden : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Gefunden : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Gefunden : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Gefunden : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Gefunden : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Gefunden : user_pref("CommunityToolbar.notifications.userId", "2b46e421-51d3-4da9-a638-504bb11008d1");
Gefunden : user_pref("CommunityToolbar.originalHomepage", "hxxp://takinus-blog.blogspot.com/");
Gefunden : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties[...]

Profilname : default
Datei : C:\Users\Saskia\AppData\Roaming\Mozilla\Firefox\Profiles\4sbds9ll.default\prefs.js

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [36610 octets] - [15/09/2012 00:37:06]

########## EOF - C:\AdwCleaner[R1].txt - [36671 octets] ##########


cosinus 15.09.2012 13:27

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Sx].txt. (x=fortlaufende Nummer)

traudel769 15.09.2012 13:41

Code:


# AdwCleaner v2.001 - Datei am 09/15/2012 um 14:34:42 erstellt
# Aktualisiert am 09/09/2012 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : Susan - LAPTOP
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Susan\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\Program Files\Conduit
Ordner Gelöscht : C:\Users\Susan\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\Susan\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\efjwbygu.default\ConduitCommon
Ordner Gelöscht : C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\efjwbygu.default\CT2269050
Ordner Gelöscht : C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\efjwbygu.default\CT3228856
Ordner Gelöscht : C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\efjwbygu.default\extensions\{81fae9c9-cfbd-4cb3-8322-412e72f55f65}
Ordner Gelöscht : C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\efjwbygu.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
Ordner Gelöscht : C:\Users\Susan\AppData\Roaming\OpenCandy

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3228856
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}

***** [Internet Browser] *****

-\\ Internet Explorer v7.0.6002.18005

Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

-\\ Mozilla Firefox v14.0.1 (de)

Profilname : default
Datei : C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\efjwbygu.default\prefs.js

Gelöscht : user_pref("CT2269050..clientLogIsEnabled", true);
Gelöscht : user_pref("CT2269050..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Gelöscht : user_pref("CT2269050..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Gelöscht : user_pref("CT2269050.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Gelöscht : user_pref("CT2269050.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Gelöscht : user_pref("CT2269050.AppTrackingLastCheckTime", "Wed Jan 18 2012 20:51:39 GMT+0100");
Gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_129681780741097243", true);
Gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_129705015340022508", true);
Gelöscht : user_pref("CT2269050.CTID", "CT2269050");
Gelöscht : user_pref("CT2269050.CurrentServerDate", "18-1-2012");
Gelöscht : user_pref("CT2269050.DSInstall", false);
Gelöscht : user_pref("CT2269050.DialogsAlignMode", "LTR");
Gelöscht : user_pref("CT2269050.DialogsGetterLastCheckTime", "Wed Jan 18 2012 20:50:31 GMT+0100");
Gelöscht : user_pref("CT2269050.DownloadReferralCookieData", "");
Gelöscht : user_pref("CT2269050.EMailNotifierPollDate", "Wed Jan 18 2012 20:50:27 GMT+0100");
Gelöscht : user_pref("CT2269050.EnableClickToSearchBox", false);
Gelöscht : user_pref("CT2269050.EnableSearchHistory", false);
Gelöscht : user_pref("CT2269050.EnableSearchSuggest", false);
Gelöscht : user_pref("CT2269050.FirstServerDate", "18-1-2012");
Gelöscht : user_pref("CT2269050.FirstTime", true);
Gelöscht : user_pref("CT2269050.FirstTimeFF3", true);
Gelöscht : user_pref("CT2269050.FixPageNotFoundErrors", false);
Gelöscht : user_pref("CT2269050.GroupingServerCheckInterval", 1440);
Gelöscht : user_pref("CT2269050.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Gelöscht : user_pref("CT2269050.HPInstall", false);
Gelöscht : user_pref("CT2269050.HasUserGlobalKeys", true);
Gelöscht : user_pref("CT2269050.HomePageProtectorEnabled", false);
Gelöscht : user_pref("CT2269050.HomepageBeforeUnload", "hxxp://takinus-blog.blogspot.com/");
Gelöscht : user_pref("CT2269050.Initialize", true);
Gelöscht : user_pref("CT2269050.InitializeCommonPrefs", true);
Gelöscht : user_pref("CT2269050.InstallationAndCookieDataSentCount", 1);
Gelöscht : user_pref("CT2269050.InstallationType", "UnknownIntegration");
Gelöscht : user_pref("CT2269050.InstalledDate", "Wed Jan 18 2012 20:50:27 GMT+0100");
Gelöscht : user_pref("CT2269050.InvalidateCache", false);
Gelöscht : user_pref("CT2269050.IsAlertDBUpdated", true);
Gelöscht : user_pref("CT2269050.IsGrouping", false);
Gelöscht : user_pref("CT2269050.IsInitSetupIni", true);
Gelöscht : user_pref("CT2269050.IsMulticommunity", false);
Gelöscht : user_pref("CT2269050.IsOpenThankYouPage", false);
Gelöscht : user_pref("CT2269050.IsOpenUninstallPage", false);
Gelöscht : user_pref("CT2269050.LanguagePackLastCheckTime", "Wed Jan 18 2012 20:50:39 GMT+0100");
Gelöscht : user_pref("CT2269050.LanguagePackReloadIntervalMM", 1440);
Gelöscht : user_pref("CT2269050.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Gelöscht : user_pref("CT2269050.LastLogin_3.9.0.3", "Wed Jan 18 2012 20:50:39 GMT+0100");
Gelöscht : user_pref("CT2269050.LatestVersion", "3.9.0.3");
Gelöscht : user_pref("CT2269050.Locale", "en");
Gelöscht : user_pref("CT2269050.MCDetectTooltipHeight", "83");
Gelöscht : user_pref("CT2269050.MCDetectTooltipShow", false);
Gelöscht : user_pref("CT2269050.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Gelöscht : user_pref("CT2269050.MCDetectTooltipWidth", "295");
Gelöscht : user_pref("CT2269050.MyStuffEnabledAtInstallation", true);
Gelöscht : user_pref("CT2269050.OriginalFirstVersion", "3.9.0.3");
Gelöscht : user_pref("CT2269050.RadioIsPodcast", false);
Gelöscht : user_pref("CT2269050.RadioLastCheckTime", "Wed Jan 18 2012 20:50:39 GMT+0100");
Gelöscht : user_pref("CT2269050.RadioLastUpdateIPServer", "3");
Gelöscht : user_pref("CT2269050.RadioLastUpdateServer", "129132338014870000");
Gelöscht : user_pref("CT2269050.RadioMediaID", "12473383");
Gelöscht : user_pref("CT2269050.RadioMediaType", "Media Player");
Gelöscht : user_pref("CT2269050.RadioMenuSelectedID", "EBRadioMenu_CT226905012473383");
Gelöscht : user_pref("CT2269050.RadioShrinkedFromSetup", false);
Gelöscht : user_pref("CT2269050.RadioStationName", "Hotmix%20108");
Gelöscht : user_pref("CT2269050.RadioStationURL", "hxxp://67.202.67.18:8082");
Gelöscht : user_pref("CT2269050.SHRINK_TOOLBAR", 1);
Gelöscht : user_pref("CT2269050.SearchBackToDefaultEngine", false);
Gelöscht : user_pref("CT2269050.SearchCaption", "DVDVideoSoftTB Customized Web Search");
Gelöscht : user_pref("CT2269050.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");
Gelöscht : user_pref("CT2269050.SearchFromAddressBarIsInit", true);
Gelöscht : user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT226[...]
Gelöscht : user_pref("CT2269050.SearchInNewTabEnabled", true);
Gelöscht : user_pref("CT2269050.SearchInNewTabIntervalMM", 1440);
Gelöscht : user_pref("CT2269050.SearchInNewTabLastCheckTime", "Wed Jan 18 2012 20:50:39 GMT+0100");
Gelöscht : user_pref("CT2269050.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Gelöscht : user_pref("CT2269050.SearchInNewTabUserEnabled", false);
Gelöscht : user_pref("CT2269050.SearchProtectorEnabled", false);
Gelöscht : user_pref("CT2269050.SearchProtectorToolbarDisabled", false);
Gelöscht : user_pref("CT2269050.SendProtectorDataViaLogin", true);
Gelöscht : user_pref("CT2269050.ServiceMapLastCheckTime", "Wed Jan 18 2012 20:50:23 GMT+0100");
Gelöscht : user_pref("CT2269050.SettingsLastCheckTime", "Wed Jan 18 2012 20:50:23 GMT+0100");
Gelöscht : user_pref("CT2269050.SettingsLastUpdate", "1326723880");
Gelöscht : user_pref("CT2269050.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=13");
Gelöscht : user_pref("CT2269050.ThirdPartyComponentsInterval", 504);
Gelöscht : user_pref("CT2269050.ThirdPartyComponentsLastCheck", "Wed Jan 18 2012 20:50:23 GMT+0100");
Gelöscht : user_pref("CT2269050.ThirdPartyComponentsLastUpdate", "1312887586");
Gelöscht : user_pref("CT2269050.ToolbarShrinkedFromSetup", false);
Gelöscht : user_pref("CT2269050.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2269050");
Gelöscht : user_pref("CT2269050.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Gelöscht : user_pref("CT2269050.UserID", "UN24871950856370964");
Gelöscht : user_pref("CT2269050.ValidationData_Toolbar", 2);
Gelöscht : user_pref("CT2269050.WeatherNetwork", "");
Gelöscht : user_pref("CT2269050.WeatherPollDate", "Wed Jan 18 2012 20:51:22 GMT+0100");
Gelöscht : user_pref("CT2269050.WeatherUnit", "C");
Gelöscht : user_pref("CT2269050.alertChannelId", "666138");
Gelöscht : user_pref("CT2269050.approveUntrustedApps", false);
Gelöscht : user_pref("CT2269050.autoDisableScopes", -1);
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e.:2z527", "2423");
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e06cg5el8:", "6E6D6F6C6A736F737673");
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737572707975797C79242F4B4947[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e31;cjc<=fbj#ncf", "247E61393F236B25757677712A212C6E414F444[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b-0?3g>d", "686E6E413E3F6D717A7145717720754D4C78254C217C202A21[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b-0?3g@6:5;", "");
Gelöscht : user_pref("CT2269050.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
Gelöscht : user_pref("CT2269050.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E424[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Gelöscht : user_pref("CT2269050.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484776213F3E484F4E4D464[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b5ba==9cjag", "6C3D3B40423E6F747A7145484A734A794D794D2250");
Gelöscht : user_pref("CT2269050.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6F6C6A736F737675717775");
Gelöscht : user_pref("CT2269050.backendstorage./9b9643g3/9e", "6A");
Gelöscht : user_pref("CT2269050.backendstorage./9b<:222h64<", "393F352F3E");
Gelöscht : user_pref("CT2269050.backendstorage./9b=+03eh8h8j?:", "4443");
Gelöscht : user_pref("CT2269050.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Gelöscht : user_pref("CT2269050.backendstorage./9b?b0d:8aj62<h", "6D");
Gelöscht : user_pref("CT2269050.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Gelöscht : user_pref("CT2269050.backendstorage.autocompletepro_enable", "31");
Gelöscht : user_pref("CT2269050.backendstorage.autocompletepro_enable_auto", "31");
Gelöscht : user_pref("CT2269050.backendstorage.shoppingapp.gk.exipres", "4D6F6E204A616E20323320323031322032303A[...]
Gelöscht : user_pref("CT2269050.backendstorage.shoppingapp.gk.geolocation", "6272617A696C");
Gelöscht : user_pref("CT2269050.components.1000034", false);
Gelöscht : user_pref("CT2269050.components.1000082", false);
Gelöscht : user_pref("CT2269050.components.1000234", false);
Gelöscht : user_pref("CT2269050.components.129023235807856892", false);
Gelöscht : user_pref("CT2269050.components.129121052374999726", false);
Gelöscht : user_pref("CT2269050.components.129351672002618989", false);
Gelöscht : user_pref("CT2269050.components.129351776130744254", false);
Gelöscht : user_pref("CT2269050.components.129391330693125668", false);
Gelöscht : user_pref("CT2269050.components.129466585396013141", false);
Gelöscht : user_pref("CT2269050.components.129681780741097243", false);
Gelöscht : user_pref("CT2269050.components.129705015340022508", false);
Gelöscht : user_pref("CT2269050.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Gelöscht : user_pref("CT2269050.globalFirstTimeInfoLastCheckTime", "Wed Jan 18 2012 20:50:24 GMT+0100");
Gelöscht : user_pref("CT2269050.homepageProtectorEnableByLogin", true);
Gelöscht : user_pref("CT2269050.initDone", true);
Gelöscht : user_pref("CT2269050.isAppTrackingManagerOn", true);
Gelöscht : user_pref("CT2269050.isFirstRadioInstallation", false);
Gelöscht : user_pref("CT2269050.isSearchProtectorNotifyChanges", false);
Gelöscht : user_pref("CT2269050.myStuffEnabled", true);
Gelöscht : user_pref("CT2269050.myStuffPublihserMinWidth", 400);
Gelöscht : user_pref("CT2269050.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Gelöscht : user_pref("CT2269050.myStuffServiceIntervalMM", 1440);
Gelöscht : user_pref("CT2269050.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Gelöscht : user_pref("CT2269050.revertSettingsEnabled", true);
Gelöscht : user_pref("CT2269050.searchProtectorDialogDelayInSec", 10);
Gelöscht : user_pref("CT2269050.searchProtectorEnableByLogin", true);
Gelöscht : user_pref("CT2269050.testingCtid", "");
Gelöscht : user_pref("CT2269050.toolbarAppMetaDataLastCheckTime", "Wed Jan 18 2012 20:50:31 GMT+0100");
Gelöscht : user_pref("CT2269050.toolbarContextMenuLastCheckTime", "Wed Jan 18 2012 20:50:40 GMT+0100");
Gelöscht : user_pref("CT2269050.usageEnabled", false);
Gelöscht : user_pref("CT2269050.usagesFlag", 2);
Gelöscht : user_pref("CT3228856..clientLogIsEnabled", false);
Gelöscht : user_pref("CT3228856..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Gelöscht : user_pref("CT3228856..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Gelöscht : user_pref("CT3228856.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Gelöscht : user_pref("CT3228856.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Gelöscht : user_pref("CT3228856.BrowserCompStateIsOpen_5861880409663125392", true);
Gelöscht : user_pref("CT3228856.CT3228856", "CT3228856");
Gelöscht : user_pref("CT3228856.CommunitiesChangesLastCheckTime", "0");
Gelöscht : user_pref("CT3228856.CurrentServerDate", "15-9-2012");
Gelöscht : user_pref("CT3228856.DSInstall", false);
Gelöscht : user_pref("CT3228856.DialogsAlignMode", "LTR");
Gelöscht : user_pref("CT3228856.DialogsGetterLastCheckTime", "Sat Sep 15 2012 00:33:42 GMT+0200");
Gelöscht : user_pref("CT3228856.DownloadReferralCookieData", "");
Gelöscht : user_pref("CT3228856.EMailNotifierPollDate", "Tue Jul 03 2012 18:34:58 GMT+0200");
Gelöscht : user_pref("CT3228856.EnableClickToSearchBox", false);
Gelöscht : user_pref("CT3228856.EnableSearchHistory", false);
Gelöscht : user_pref("CT3228856.EnableSearchSuggest", false);
Gelöscht : user_pref("CT3228856.FirstServerDate", "3-7-2012");
Gelöscht : user_pref("CT3228856.FirstTime", true);
Gelöscht : user_pref("CT3228856.FirstTimeFF3", true);
Gelöscht : user_pref("CT3228856.FirstTimeHiddenVer", true);
Gelöscht : user_pref("CT3228856.FixPageNotFoundErrors", true);
Gelöscht : user_pref("CT3228856.GroupingInvalidateCache", false);
Gelöscht : user_pref("CT3228856.GroupingLastCheckTime", "0");
Gelöscht : user_pref("CT3228856.GroupingLastServerUpdateTime", "0");
Gelöscht : user_pref("CT3228856.GroupingServerCheckInterval", 1440);
Gelöscht : user_pref("CT3228856.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Gelöscht : user_pref("CT3228856.HPInstall", false);
Gelöscht : user_pref("CT3228856.HasUserGlobalKeys", true);
Gelöscht : user_pref("CT3228856.HomePageProtectorEnabled", false);
Gelöscht : user_pref("CT3228856.HomepageBeforeUnload", "hxxp://takinus-blog.blogspot.com/");
Gelöscht : user_pref("CT3228856.Initialize", true);
Gelöscht : user_pref("CT3228856.InitializeCommonPrefs", true);
Gelöscht : user_pref("CT3228856.InstallationAndCookieDataSentCount", 3);
Gelöscht : user_pref("CT3228856.InstallationId", "ConduitNSISIntegration");
Gelöscht : user_pref("CT3228856.InstallationType", "ConduitNSISIntegration");
Gelöscht : user_pref("CT3228856.InstalledDate", "Tue Jul 03 2012 18:37:03 GMT+0200");
Gelöscht : user_pref("CT3228856.InvalidateCache", false);
Gelöscht : user_pref("CT3228856.IsGrouping", false);
Gelöscht : user_pref("CT3228856.IsInitSetupIni", true);
Gelöscht : user_pref("CT3228856.IsMulticommunity", false);
Gelöscht : user_pref("CT3228856.IsOpenThankYouPage", true);
Gelöscht : user_pref("CT3228856.IsOpenUninstallPage", true);
Gelöscht : user_pref("CT3228856.IsProtectorsInit", true);
Gelöscht : user_pref("CT3228856.LanguagePackLastCheckTime", "Fri Sep 14 2012 16:52:51 GMT+0200");
Gelöscht : user_pref("CT3228856.LanguagePackReloadIntervalMM", 1440);
Gelöscht : user_pref("CT3228856.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Gelöscht : user_pref("CT3228856.LastLogin_3.14.1.0", "Tue Aug 21 2012 19:01:12 GMT+0200");
Gelöscht : user_pref("CT3228856.LastLogin_3.15.1.0", "Sat Sep 15 2012 14:24:04 GMT+0200");
Gelöscht : user_pref("CT3228856.LatestVersion", "3.15.1.0");
Gelöscht : user_pref("CT3228856.Locale", "en");
Gelöscht : user_pref("CT3228856.MCDetectTooltipHeight", "83");
Gelöscht : user_pref("CT3228856.MCDetectTooltipShow", false);
Gelöscht : user_pref("CT3228856.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Gelöscht : user_pref("CT3228856.MCDetectTooltipWidth", "295");
Gelöscht : user_pref("CT3228856.MyStuffEnabledAtInstallation", true);
Gelöscht : user_pref("CT3228856.OriginalFirstVersion", "3.14.1.0");
Gelöscht : user_pref("CT3228856.RadioLastCheckTime", "Tue Jul 03 2012 18:38:19 GMT+0200");
Gelöscht : user_pref("CT3228856.RadioLastUpdateIPServer", "0");
Gelöscht : user_pref("CT3228856.RadioShrinkedFromSetup", false);
Gelöscht : user_pref("CT3228856.SHRINK_TOOLBAR", 1);
Gelöscht : user_pref("CT3228856.SearchBackToDefaultEngine", false);
Gelöscht : user_pref("CT3228856.SearchCaption", "FreemakeVideoConverterTB Customized Web Search");
Gelöscht : user_pref("CT3228856.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");
Gelöscht : user_pref("CT3228856.SearchFromAddressBarIsInit", true);
Gelöscht : user_pref("CT3228856.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT322[...]
Gelöscht : user_pref("CT3228856.SearchInNewTabEnabled", true);
Gelöscht : user_pref("CT3228856.SearchInNewTabIntervalMM", 1440);
Gelöscht : user_pref("CT3228856.SearchInNewTabLastCheckTime", "Fri Sep 14 2012 16:52:50 GMT+0200");
Gelöscht : user_pref("CT3228856.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Gelöscht : user_pref("CT3228856.SearchInNewTabUserEnabled", false);
Gelöscht : user_pref("CT3228856.SearchProtectorEnabled", false);
Gelöscht : user_pref("CT3228856.SearchProtectorToolbarDisabled", false);
Gelöscht : user_pref("CT3228856.SendProtectorDataViaLogin", true);
Gelöscht : user_pref("CT3228856.ServiceMapLastCheckTime", "Fri Sep 14 2012 16:52:51 GMT+0200");
Gelöscht : user_pref("CT3228856.SettingsLastCheckTime", "Sat Sep 15 2012 14:24:03 GMT+0200");
Gelöscht : user_pref("CT3228856.SettingsLastUpdate", "1347287073");
Gelöscht : user_pref("CT3228856.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT3228856&SearchSource=13");
Gelöscht : user_pref("CT3228856.ThirdPartyComponentsInterval", 504);
Gelöscht : user_pref("CT3228856.ThirdPartyComponentsLastCheck", "Tue Jul 03 2012 18:34:55 GMT+0200");
Gelöscht : user_pref("CT3228856.ThirdPartyComponentsLastUpdate", "1331805997");
Gelöscht : user_pref("CT3228856.ToolbarShrinkedFromSetup", false);
Gelöscht : user_pref("CT3228856.TrusteLinkUrl", "hxxp://trust.conduit.com/CT3228856");
Gelöscht : user_pref("CT3228856.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Gelöscht : user_pref("CT3228856.UserID", "UN58184482552275060");
Gelöscht : user_pref("CT3228856.ValidationData_Toolbar", 1);
Gelöscht : user_pref("CT3228856.WeatherNetwork", "");
Gelöscht : user_pref("CT3228856.WeatherPollDate", "Tue Jul 03 2012 18:36:36 GMT+0200");
Gelöscht : user_pref("CT3228856.WeatherUnit", "C");
Gelöscht : user_pref("CT3228856.alertChannelId", "1665544");
Gelöscht : user_pref("CT3228856.approveUntrustedApps", false);
Gelöscht : user_pref("CT3228856.autoDisableScopes", -1);
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e.:2z527", "247E707571777278333228702A7B797B7B7E30273224262[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e06cg5el8:", "6E6D6D71707172727578");
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737377767778787B7E242F4B4947[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b-0?3g>d", "6B6B68416B3E41737A4674777B204C4C797A25797C7C532A22[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b-0?3g@6:5;", "");
Gelöscht : user_pref("CT3228856.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E424[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Gelöscht : user_pref("CT3228856.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484775213F3E484F4E4D464[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b5ba==9cjag", "6B6E406A406C3F727A7572794A77777C7C7B227B7A");
Gelöscht : user_pref("CT3228856.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6D71707172727674757978");
Gelöscht : user_pref("CT3228856.backendstorage./9b9643g3/9e", "6A");
Gelöscht : user_pref("CT3228856.backendstorage./9b<:222h64<", "393F352F3E");
Gelöscht : user_pref("CT3228856.backendstorage./9b=+03eh8h8j?:", "4443");
Gelöscht : user_pref("CT3228856.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Gelöscht : user_pref("CT3228856.backendstorage./9b?b0d:8aj62<h", "6D");
Gelöscht : user_pref("CT3228856.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Gelöscht : user_pref("CT3228856.backendstorage.shoppingapp.gk.exipres", "53756E204A756C20303820323031322031383A[...]
Gelöscht : user_pref("CT3228856.backendstorage.shoppingapp.gk.geolocation", "6765726D616E79");
Gelöscht : user_pref("CT3228856.components.1000034", false);
Gelöscht : user_pref("CT3228856.components.1000082", false);
Gelöscht : user_pref("CT3228856.components.1000234", false);
Gelöscht : user_pref("CT3228856.components.1000515", false);
Gelöscht : user_pref("CT3228856.components.129840633550036918", false);
Gelöscht : user_pref("CT3228856.components.129840633550349419", false);
Gelöscht : user_pref("CT3228856.components.129840633550349420", false);
Gelöscht : user_pref("CT3228856.components.129840633551286921", false);
Gelöscht : user_pref("CT3228856.components.129840633552849422", false);
Gelöscht : user_pref("CT3228856.components.129840633553474424", false);
Gelöscht : user_pref("CT3228856.components.129840633553943175", false);
Gelöscht : user_pref("CT3228856.components.129852807254541663", false);
Gelöscht : user_pref("CT3228856.components.5861880409663125392", false);
Gelöscht : user_pref("CT3228856.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Gelöscht : user_pref("CT3228856.globalFirstTimeInfoLastCheckTime", "Tue Jul 03 2012 18:34:58 GMT+0200");
Gelöscht : user_pref("CT3228856.homepageProtectorEnableByLogin", true);
Gelöscht : user_pref("CT3228856.initDone", true);
Gelöscht : user_pref("CT3228856.isAppTrackingManagerOn", true);
Gelöscht : user_pref("CT3228856.isFirstRadioInstallation", false);
Gelöscht : user_pref("CT3228856.isSearchProtectorNotifyChanges", false);
Gelöscht : user_pref("CT3228856.myStuffEnabled", true);
Gelöscht : user_pref("CT3228856.myStuffPublihserMinWidth", 400);
Gelöscht : user_pref("CT3228856.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Gelöscht : user_pref("CT3228856.myStuffServiceIntervalMM", 1440);
Gelöscht : user_pref("CT3228856.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Gelöscht : user_pref("CT3228856.navigateToUrlOnSearch", false);
Gelöscht : user_pref("CT3228856.revertSettingsEnabled", true);
Gelöscht : user_pref("CT3228856.searchProtectorDialogDelayInSec", 10);
Gelöscht : user_pref("CT3228856.searchProtectorEnableByLogin", true);
Gelöscht : user_pref("CT3228856.testingCtid", "");
Gelöscht : user_pref("CT3228856.toolbarAppMetaDataLastCheckTime", "Fri Sep 14 2012 16:52:51 GMT+0200");
Gelöscht : user_pref("CT3228856.toolbarContextMenuLastCheckTime", "Tue Jul 03 2012 18:35:12 GMT+0200");
Gelöscht : user_pref("CT3228856.usageEnabled", false);
Gelöscht : user_pref("CT3228856.usagesFlag", 2);
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2269050/CT2269050[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3228856/CT3228856[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1665544/1658042/DE", "\"0\"[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/666138/661999/DE", "\"0\"")[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2269050", [...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3228856", [...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2269050",[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3228856",[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"018[...]
Gelöscht : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Susan\\AppData\\Roaming\\Mozilla\\F[...]
Gelöscht : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.14.1.0");
Gelöscht : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...]
Gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
Gelöscht : user_pref("CommunityToolbar.ToolbarsList", "CT2269050,CT3228856");
Gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "CT2269050,CT3228856");
Gelöscht : user_pref("CommunityToolbar.ToolbarsList4", "CT2269050,CT3228856");
Gelöscht : user_pref("CommunityToolbar.globalUserId", "e686c8e9-4fc8-401e-92ae-8cffc69a5ad9");
Gelöscht : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Gelöscht : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Gelöscht : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Jul 03 2012 18:35:1[...]
Gelöscht : user_pref("CommunityToolbar.notifications.alertEnabled", false);
Gelöscht : user_pref("CommunityToolbar.notifications.alertInfoInterval", 60);
Gelöscht : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue Jul 03 2012 18:36:48 GMT+020[...]
Gelöscht : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Gelöscht : user_pref("CommunityToolbar.notifications.locale", "en");
Gelöscht : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Gelöscht : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Tue Jul 03 2012 18:34:58 GMT+0200");
Gelöscht : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Gelöscht : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Gelöscht : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Gelöscht : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Gelöscht : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Gelöscht : user_pref("CommunityToolbar.notifications.userId", "2b46e421-51d3-4da9-a638-504bb11008d1");
Gelöscht : user_pref("CommunityToolbar.originalHomepage", "hxxp://takinus-blog.blogspot.com/");
Gelöscht : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties[...]

Profilname : default
Datei : C:\Users\Saskia\AppData\Roaming\Mozilla\Firefox\Profiles\4sbds9ll.default\prefs.js

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [36741 octets] - [15/09/2012 00:37:06]
AdwCleaner[S1].txt - [36954 octets] - [15/09/2012 14:34:42]

########## EOF - C:\AdwCleaner[S1].txt - [37015 octets] ##########


cosinus 16.09.2012 15:08

Hätte da mal zwei Fragen bevor es weiter geht (wir sind noch nicht fertig!)

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

traudel769 16.09.2012 15:49

Ja, seit ich in der ms config die mir suspekt vorkommende exe deaktiviert habe, kann ich wieder normal starten. Vermisst hab ich bisher nichts, ich muss dazu aber auch sagen, dass ich fast alle Aktivitäten am Rechner eingestellt habe, da ich nicht weiß, wie sich das Zeugs verbreitet und wo es alles "hinschauen" kann.

Der Ordner Sony Ericsson ist leer, Carpo ist leer. Autostart ist leer. 4MusicxWMAtoWAVconvertert ebenfalls.

Beim Durchschauen ist mir nichts aufgefallen, was ich vermisse.
Ich starte aber eigentlich auch immer alles was ich brauche über ein Icon auf dem Desktop. Hab mal durchprobiert. Es wird alles gestartet.

cosinus 16.09.2012 18:54

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


traudel769 16.09.2012 21:02

hier kommt das log

[/code]OTL Logfile:
Code:

OTL logfile created on: 16.09.2012 21:34:29 - Run 2
OTL by OldTimer - Version 3.2.61.5    Folder = C:\Users\Susan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,87 Gb Total Physical Memory | 1,05 Gb Available Physical Memory | 56,27% Memory free
8,83 Gb Paging File | 7,71 Gb Available in Paging File | 87,25% Paging File free
Paging file location(s): c:\pagefile.sys 3084 3084e:\pagef [Binary data over 200 bytes]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 24,10 Gb Free Space | 32,34% Space Free | Partition Type: NTFS
Drive E: | 73,06 Gb Total Space | 55,30 Gb Free Space | 75,69% Space Free | Partition Type: NTFS
 
Computer Name: LAPTOP | User Name: Susan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.09.16 21:32:03 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Susan\Desktop\OTL.exe
PRC - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.07 17:04:44 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.08.08 19:00:35 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.05.08 17:43:25 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.08 17:43:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.08 17:43:24 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.03.07 15:33:08 | 000,089,456 | ---- | M] (Elaborate Bytes AG) -- E:\Programme\VirtualCloneDrive\VCDDaemon.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.03.20 07:36:58 | 000,210,216 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynToshiba.exe
PRC - [2008.01.19 09:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007.06.26 21:27:46 | 000,312,320 | ---- | M] (shbox.de) -- C:\Program Files\FreePDF_XP\fpassist.exe
PRC - [2007.05.22 16:32:00 | 000,538,744 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
PRC - [2007.04.27 21:15:46 | 000,114,688 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
PRC - [2007.04.25 11:14:16 | 004,444,160 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007.03.29 10:39:00 | 000,427,576 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2007.03.29 10:39:00 | 000,411,192 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
PRC - [2006.11.14 22:02:36 | 001,372,160 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2006.11.14 21:19:42 | 000,405,504 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2006.11.14 20:33:10 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2006.11.06 17:14:44 | 000,034,352 | ---- | M] () -- C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
PRC - [2006.08.23 16:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
PRC - [2006.05.25 19:30:16 | 000,114,688 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.14 18:08:48 | 000,519,168 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\TCrdMain\b26d1c6ae98a3fafd08a70f2d719af08\TCrdMain.ni.exe
MOD - [2012.06.14 18:05:52 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012.06.14 18:05:38 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012.06.14 18:05:11 | 014,329,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7343fbab1ba137db2f8b284047ef3f3c\PresentationFramework.ni.dll
MOD - [2012.06.14 18:03:22 | 012,219,392 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b6293b0c23321c255c2530aea8e32bb\PresentationCore.ni.dll
MOD - [2012.05.12 18:59:40 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c8c3ab08933fef9fb6657da871395c46\PresentationFramework.Aero.ni.dll
MOD - [2012.05.12 18:58:55 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\54426ee1881b42af5b090e223f43823c\WindowsBase.ni.dll
MOD - [2012.05.12 18:58:50 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012.05.12 18:58:40 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2009.03.30 06:42:11 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2007.09.20 19:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007.05.25 12:25:38 | 000,958,464 | ---- | M] () -- C:\Program Files\TOSHIBA\FlashCards\de\TCrdMain.resources.dll
MOD - [2007.04.24 21:57:36 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
MOD - [2007.04.23 10:38:08 | 000,009,216 | ---- | M] () -- C:\Program Files\TOSHIBA\ConfigFree\NotifyCFF.dll
MOD - [2006.12.01 18:55:42 | 000,009,216 | ---- | M] () -- C:\Program Files\TOSHIBA\TBS\NotifyTBS.dll
MOD - [2006.11.09 18:27:06 | 000,090,112 | ---- | M] () -- C:\Program Files\TOSHIBA\FlashCards\TWarnMsg\TWarnMsg.dll
MOD - [2006.11.08 18:08:30 | 000,009,216 | ---- | M] () -- C:\Program Files\TOSHIBA\PCDiag\NotifyPCD.dll
MOD - [2006.11.06 17:14:44 | 000,034,352 | ---- | M] () -- C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
MOD - [2006.10.10 11:44:16 | 000,009,728 | ---- | M] () -- C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll
MOD - [2006.10.07 12:57:04 | 000,053,248 | ---- | M] () -- C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll
 
 
========== Services (SafeList) ==========
 
SRV - File not found [Auto | Stopped] -- c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.08.15 18:13:53 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.07.19 19:31:16 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.05.08 17:43:25 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.08 17:43:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2008.10.21 18:04:58 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008.01.19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.04.27 21:15:46 | 000,114,688 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2007.03.29 10:39:00 | 000,427,576 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2006.11.14 20:33:10 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (CFSvcs)
SRV - [2006.10.05 13:10:12 | 000,009,216 | ---- | M] (Agere Systems) [Disabled | Stopped] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2006.08.23 16:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
SRV - [2006.05.25 19:30:16 | 000,114,688 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2005.11.17 14:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\VcommMgr.sys -- (VcommMgr)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\VComm.sys -- (VComm)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\TpChoice.sys -- (TpChoice)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (Tosrfcom)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\pccsmcfd.sys -- (pccsmcfd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\IvtBtBus.sys -- (IvtBtBUs)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard)
DRV - File not found [Kernel | Boot | Stopped] -- System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - File not found [Kernel | Boot | Stopped] -- System32\Drivers\vbtenum.sys -- (BTHidEnum)
DRV - File not found [Kernel | Boot | Stopped] -- System32\Drivers\BtHidBus.sys -- (BtHidBus)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\btcusb.sys -- (Btcsrusb)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\btcombus.sys -- (BTCOMBUS)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btcomport.sys -- (BTCOM)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btnetdrv.sys -- (BT)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\blueletaudio.sys -- (BlueletAudio)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.07.19 23:21:19 | 000,039,016 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tbhsd.sys -- (tbhsd)
DRV - [2012.05.21 04:09:00 | 000,181,432 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2012.05.21 04:09:00 | 000,080,824 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2012.05.08 17:43:25 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.05.08 17:43:25 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.11.17 15:37:16 | 000,441,608 | ---- | M] (Paragon) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\Uim_IM.sys -- (Uim_IM)
DRV - [2011.11.17 15:37:16 | 000,277,576 | ---- | M] (Paragon) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\Uim_Vim.sys -- (Uim_Vim)
DRV - [2011.11.17 15:37:16 | 000,045,240 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\UimBus.sys -- (UimBus)
DRV - [2011.10.11 15:00:01 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.04.06 18:33:10 | 000,025,864 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btnetBus.sys -- (btnetBUs)
DRV - [2009.08.07 17:09:39 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2009.08.07 17:09:39 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt)
DRV - [2009.06.19 21:44:14 | 000,290,816 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tifm21.sys -- (tifm21)
DRV - [2008.11.04 10:52:38 | 000,114,472 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018mdm.sys -- (s1018mdm)
DRV - [2008.11.04 10:52:38 | 000,108,328 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018mgmt.sys -- (s1018mgmt)
DRV - [2008.11.04 10:52:38 | 000,086,696 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018bus.sys -- (s1018bus)
DRV - [2008.11.04 10:52:38 | 000,026,024 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018nd5.sys -- (s1018nd5)
DRV - [2008.11.04 10:52:38 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018mdfl.sys -- (s1018mdfl)
DRV - [2008.11.04 10:52:36 | 000,109,736 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018unic.sys -- (s1018unic)
DRV - [2008.11.04 10:52:36 | 000,104,616 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1018obex.sys -- (s1018obex)
DRV - [2008.07.29 05:05:04 | 000,919,552 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2007.11.09 05:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TVALZ_O.SYS -- (TVALZ)
DRV - [2007.04.27 21:13:58 | 000,285,184 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\tos_sps32.sys -- (tos_sps32)
DRV - [2007.04.24 22:07:14 | 002,590,720 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2007.03.01 16:53:12 | 000,073,728 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV - [2007.02.28 22:27:06 | 000,041,344 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2007.02.22 19:56:24 | 000,113,920 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfbd.sys -- (tosrfbd)
DRV - [2007.01.18 16:47:18 | 000,211,072 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\KR10N.sys -- (KR10N)
DRV - [2007.01.18 16:40:56 | 000,219,392 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\KR10I.sys -- (KR10I)
DRV - [2006.12.25 18:35:08 | 000,067,072 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2006.11.28 16:11:00 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006.10.18 12:50:04 | 000,016,128 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2006.08.30 10:35:58 | 000,140,800 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2006.07.28 16:25:26 | 000,019,456 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\LPCFilter.sys -- (LPCFilter)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Upgrade to Google Chrome
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Google
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Takinu´s Blog
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Upgrade to Google Chrome
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Upgrade to Google Chrome
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\..\URLSearchHook: {81fae9c9-cfbd-4cb3-8322-412e72f55f65} - No CLSID value found
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_de
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://takinus-blog.blogspot.com/"
FF - prefs.js..network.proxy.backup.ftp: "        93.97.50.33"
FF - prefs.js..network.proxy.backup.ftp_port: 80
FF - prefs.js..network.proxy.backup.socks: "        93.97.50.33"
FF - prefs.js..network.proxy.backup.socks_port: 80
FF - prefs.js..network.proxy.backup.ssl: "        93.97.50.33"
FF - prefs.js..network.proxy.backup.ssl_port: 80
FF - prefs.js..network.proxy.ftp: "        93.97.50.33"
FF - prefs.js..network.proxy.ftp_port: 80
FF - prefs.js..network.proxy.http: "        93.97.50.33"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "        93.97.50.33"
FF - prefs.js..network.proxy.socks_port: 80
FF - prefs.js..network.proxy.ssl: "        93.97.50.33"
FF - prefs.js..network.proxy.ssl_port: 80
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.07.19 19:31:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.08.15 06:54:55 | 000,000,000 | ---D | M]
 
[2011.06.05 17:04:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Susan\AppData\Roaming\mozilla\Extensions
[2012.09.15 14:34:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Susan\AppData\Roaming\mozilla\Firefox\Profiles\efjwbygu.default\extensions
[2011.11.13 14:31:14 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Users\Susan\AppData\Roaming\mozilla\Firefox\Profiles\efjwbygu.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012.09.09 06:42:49 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Susan\AppData\Roaming\mozilla\Firefox\Profiles\efjwbygu.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.08.11 12:23:47 | 000,526,409 | ---- | M] () (No name found) -- C:\Users\Susan\AppData\Roaming\mozilla\firefox\profiles\efjwbygu.default\extensions\toolbar@web.de.xpi
[2011.12.20 22:29:00 | 000,000,933 | ---- | M] () -- C:\Users\Susan\AppData\Roaming\mozilla\firefox\profiles\efjwbygu.default\searchplugins\11-suche.xml
[2011.12.20 22:29:00 | 000,002,419 | ---- | M] () -- C:\Users\Susan\AppData\Roaming\mozilla\firefox\profiles\efjwbygu.default\searchplugins\englische-ergebnisse.xml
[2011.12.20 22:29:00 | 000,010,525 | ---- | M] () -- C:\Users\Susan\AppData\Roaming\mozilla\firefox\profiles\efjwbygu.default\searchplugins\gmx-suche.xml
[2011.12.20 22:29:00 | 000,002,457 | ---- | M] () -- C:\Users\Susan\AppData\Roaming\mozilla\firefox\profiles\efjwbygu.default\searchplugins\lastminute.xml
[2011.12.20 22:28:59 | 000,005,508 | ---- | M] () -- C:\Users\Susan\AppData\Roaming\mozilla\firefox\profiles\efjwbygu.default\searchplugins\webde-suche.xml
[2011.06.05 17:04:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.07.19 19:31:17 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.06.22 19:51:11 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.22 19:51:11 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.06.22 19:51:11 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.22 19:51:11 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.22 19:51:11 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.22 19:51:11 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2010.04.04 21:50:25 | 000,385,902 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: ::1            localhost
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        全讯网,åšå½©ä¼˜æƒ*,皇å†*æ*£ç½‘cr67com,皇å†*比分,皇å†*峿—¶æŒ‡æ•°,太阳城代ç†112scg,tt娱ä¹åŸŽ8bc8,网上真钱娱
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        1001namen.com
O1 - Hosts: 127.0.0.1        1001namen.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        ²©²Êͨ,²©²ÊÍø,½ð±¦²©188,²©²ÊͨÆÀ¼¶,°Ù¼ÒÀÖ,°ÂÃî°Ù¼ÒÀÖ
O1 - Hosts: 127.0.0.1        100sexlinks.com - Informationen zum Thema Sex links. Diese Website steht zum Verkauf!
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        1-2005-search.com
O1 - Hosts: 127.0.0.1        1-2005-search.com
O1 - Hosts: 13312 more lines...
O2 - BHO: (no name) - {0124123D-61B4-456f-AF86-78C53A0790C5} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - {0124123D-61B4-456f-AF86-78C53A0790C5} - No CLSID value found.
O3 - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de)
O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (TOSHIBA)
O4 - HKLM..\Run: [Toshiba Registration] C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe (Toshiba)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [VirtualCloneDrive] E:\Programme\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil32_11_3_300_271_Plugin.exe (Adobe Systems Incorporated)
O7 - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Susan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 File not found
O9 - Extra Button: eBay - Der weltweite Online Marktplatz - {76577871-04EC-495E-A12B-91F7C3600AFA} - eBay - eine der größten deutschen Shopping-Websites File not found
O9 - Extra Button: Amazon.de - {8A918C1D-E123-4E36-B562-5C1519E434CE} - hxxp://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{34CF1E10-6FBD-4CBA-8BB1-6500B1E86B54}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Windows\System32\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Susan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Susan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0996168d-e70c-11e1-aaa9-001b381b4222}\Shell - "" = AutoRun
O33 - MountPoints2\{0996168d-e70c-11e1-aaa9-001b381b4222}\Shell\AutoRun\command - "" = H:\start.exe
O33 - MountPoints2\{1f7599ab-bd29-11e0-abf4-001b381b4222}\Shell - "" = AutoRun
O33 - MountPoints2\{1f7599ab-bd29-11e0-abf4-001b381b4222}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{1f7599ae-bd29-11e0-abf4-001b381b4222}\Shell - "" = AutoRun
O33 - MountPoints2\{1f7599ae-bd29-11e0-abf4-001b381b4222}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{68dbe344-e6f8-11e1-a0d8-001b381b4222}\Shell - "" = AutoRun
O33 - MountPoints2\{68dbe344-e6f8-11e1-a0d8-001b381b4222}\Shell\AutoRun\command - "" = H:\start.exe
O33 - MountPoints2\{da7322eb-c36e-11e0-a98c-001b381b4222}\Shell - "" = AutoRun
O33 - MountPoints2\{da7322eb-c36e-11e0-a98c-001b381b4222}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpReg: Apoint - hkey= - key= - C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
MsConfig - StartUpReg: Garmin Lifetime Updater - hkey= - key= - C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe (Garmin)
MsConfig - StartUpReg: hweyvybrdvmqiuw - hkey= - key= -  File not found
MsConfig - StartUpReg: HWSetup - hkey= - key= -  File not found
MsConfig - State: "services" - 2
MsConfig - State: "startup" - 2
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {0fde1f56-0d59-4fd7-9624-e3df6b419d0f} - IEEX
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {8A585B97-6DF3-377C-1C4D-0D3D89A5B665} - Internet Explorer
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\Windows\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.13 17:43:43 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Susan\Desktop\esetsmartinstaller_enu.exe
[2012.09.13 06:25:34 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.09.12 17:30:22 | 000,000,000 | ---D | C] -- C:\Users\Susan\AppData\Roaming\Malwarebytes
[2012.09.12 17:30:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.09.12 17:30:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.09.12 17:29:59 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.12 17:29:59 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.09.12 17:28:09 | 010,652,120 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\Susan\Desktop\mbam-setup-1.62.0.1300.exe
[2012.09.11 17:33:55 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\Susan\Desktop\OTL.exe
[2012.09.09 09:47:12 | 000,000,000 | ---D | C] -- C:\Users\Susan\AppData\Local\Lupinho.Net
[2012.09.08 20:39:14 | 000,000,000 | ---D | C] -- C:\ProgramData\backup
[2012.09.08 20:39:05 | 000,000,000 | ---D | C] -- C:\ProgramData\explauncher
[2012.09.08 20:39:02 | 000,000,000 | ---D | C] -- C:\ProgramData\launcher
[2012.09.08 16:31:00 | 000,000,000 | ---D | C] -- C:\ProgramData\yleehzpzdovhrsn
[2012.09.07 18:27:26 | 000,000,000 | ---D | C] -- C:\Users\Susan\Documents\Adobe
[2012.09.01 18:02:07 | 000,000,000 | ---D | C] -- C:\Users\Susan\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.09.01 18:01:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
[2012.09.01 18:01:53 | 000,405,152 | ---- | C] (Newtonsoft) -- C:\Windows\System32\Newtonsoft.Json.Net20.dll
[2012.09.01 18:01:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DVDVideoSoft
[2009.12.15 20:25:11 | 001,924,200 | ---- | C] (Adobe Systems Incorporated) -- C:\Program Files\install_flash_player10.0.42.34.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.16 21:32:03 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Susan\Desktop\OTL.exe
[2012.09.16 21:28:35 | 000,000,431 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
[2012.09.16 21:27:57 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.16 21:27:56 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.16 21:27:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.16 21:27:32 | 2011,217,920 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.16 17:13:15 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.16 16:47:59 | 000,002,591 | ---- | M] () -- C:\Users\Susan\Desktop\Microsoft Office Word 2007.lnk
[2012.09.16 16:46:57 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLdw.DAT
[2012.09.15 14:52:40 | 000,000,392 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{BD71E7E2-ECDB-4F93-B0DC-4A2B232F98A8}.job
[2012.09.15 00:35:09 | 000,512,399 | ---- | M] () -- C:\Users\Susan\Desktop\adwcleaner.exe
[2012.09.13 17:43:53 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Susan\Desktop\esetsmartinstaller_enu.exe
[2012.09.13 17:38:24 | 000,632,492 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.09.13 17:38:24 | 000,599,150 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.09.13 17:38:24 | 000,127,528 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.09.13 17:38:24 | 000,105,164 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.09.12 17:32:50 | 000,000,871 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.11 17:32:47 | 000,000,000 | ---- | M] () -- C:\Users\Susan\defogger_reenable
[2012.09.10 09:19:40 | 000,302,592 | ---- | M] () -- C:\Users\Susan\Desktop\gpkdnwpv.exe
[2012.09.10 09:19:11 | 000,050,477 | ---- | M] () -- C:\Users\Susan\Desktop\Defogger.exe
[2012.09.10 09:17:23 | 010,652,120 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\Susan\Desktop\mbam-setup-1.62.0.1300.exe
[2012.09.09 11:03:09 | 000,238,592 | ---- | M] () -- C:\Users\Susan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.09.09 09:46:19 | 000,001,874 | ---- | M] () -- C:\Users\Public\Desktop\HardlinkBackup.lnk
[2012.09.09 06:56:16 | 000,002,593 | ---- | M] () -- C:\Users\Susan\Desktop\Microsoft Office Excel 2007.lnk
[2012.09.08 16:31:00 | 000,000,051 | ---- | M] () -- C:\ProgramData\ffgduormlbmggjj
[2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.01 18:01:57 | 000,000,770 | ---- | M] () -- C:\Users\Susan\Desktop\Free YouTube to MP3 Converter.lnk
[2012.09.01 15:40:17 | 000,000,659 | ---- | M] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk
[2012.09.01 15:37:18 | 000,000,748 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2012.09.01 15:24:19 | 000,001,650 | ---- | M] () -- C:\Users\Public\Desktop\Lightroom 4.1.lnk
[2012.08.24 15:58:36 | 000,405,152 | ---- | M] (Newtonsoft) -- C:\Windows\System32\Newtonsoft.Json.Net20.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.09.15 00:34:54 | 000,512,399 | ---- | C] () -- C:\Users\Susan\Desktop\adwcleaner.exe
[2012.09.12 17:30:01 | 000,000,871 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.11 18:33:57 | 000,302,592 | ---- | C] () -- C:\Users\Susan\Desktop\gpkdnwpv.exe
[2012.09.11 17:32:47 | 000,000,000 | ---- | C] () -- C:\Users\Susan\defogger_reenable
[2012.09.11 17:32:21 | 000,050,477 | ---- | C] () -- C:\Users\Susan\Desktop\Defogger.exe
[2012.09.09 09:46:19 | 000,001,874 | ---- | C] () -- C:\Users\Public\Desktop\HardlinkBackup.lnk
[2012.09.09 09:46:19 | 000,001,874 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HardlinkBackup.lnk
[2012.09.09 07:44:50 | 2011,217,920 | -HS- | C] () -- C:\hiberfil.sys
[2012.09.08 16:30:54 | 000,000,051 | ---- | C] () -- C:\ProgramData\ffgduormlbmggjj
[2012.09.01 18:01:57 | 000,000,770 | ---- | C] () -- C:\Users\Susan\Desktop\Free YouTube to MP3 Converter.lnk
[2012.09.01 15:40:17 | 000,000,659 | ---- | C] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk
[2012.09.01 15:37:18 | 000,000,748 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2012.09.01 15:24:19 | 000,001,650 | ---- | C] () -- C:\Users\Public\Desktop\Lightroom 4.1.lnk
[2012.09.01 15:24:19 | 000,001,638 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Lightroom 4.1.lnk
[2012.05.23 18:49:32 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2012.05.23 18:49:32 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2012.05.23 18:49:32 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2012.05.23 18:49:32 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2011.06.05 17:04:38 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.05.11 19:38:52 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011.04.15 20:59:17 | 000,000,680 | ---- | C] () -- C:\Users\Susan\AppData\Local\d3d9caps.dat
[2011.01.21 21:18:07 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2009.10.12 10:55:13 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Woodwinds
[2009.10.12 10:55:13 | 000,000,268 | RH-- | C] () -- C:\Users\Susan\AppData\Roaming\Vocals
[2009.10.12 10:55:13 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLdw.DAT
[2009.07.17 20:52:53 | 000,171,941 | ---- | C] () -- C:\Users\Susan\AppData\Roaming\mdbu.bin
[2009.06.29 21:06:30 | 000,000,680 | RHS- | C] () -- C:\Users\Susan\ntuser.pol
[2008.02.09 14:20:59 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2007.11.11 22:51:16 | 000,238,592 | ---- | C] () -- C:\Users\Susan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.11.10 18:00:06 | 000,019,658 | ---- | C] () -- C:\Users\Susan\AppData\Local\internal.grp
[2007.11.09 20:40:46 | 000,000,016 | -H-- | C] () -- C:\Users\Susan\AppData\Roaming\mxfilerelatedcache.mxc2
[2007.11.09 20:40:46 | 000,000,016 | -H-- | C] () -- C:\Users\Susan\AppData\Local\mxfilerelatedcache.mxc2
[2007.11.09 20:40:45 | 000,000,016 | -H-- | C] () -- C:\Users\Susan\mxfilerelatedcache.mxc2
[2002.07.02 03:10:00 | 000,002,485 | ---- | C] () -- C:\Program Files\winsave.bpr
 
========== LOP Check ==========
 
[2012.09.08 21:13:47 | 000,000,000 | ---D | M] -- C:\Users\Saskia\AppData\Roaming\Canneverbe Limited
[2012.03.25 17:58:44 | 000,000,000 | ---D | M] -- C:\Users\Saskia\AppData\Roaming\Garmin
[2011.11.14 15:57:11 | 000,000,000 | ---D | M] -- C:\Users\Saskia\AppData\Roaming\TIPP10
[2007.11.20 21:49:14 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\ASCON Installer
[2007.12.25 19:33:42 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\bhv-Edu
[2008.03.29 16:28:21 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Buhl Data Service
[2012.05.09 19:13:32 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Canneverbe Limited
[2009.05.31 10:08:20 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\cerasus.media
[2007.12.28 10:39:58 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Chromeflower
[2007.12.28 10:39:40 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\CrystalSpace
[2012.08.05 11:13:27 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Dropbox
[2012.09.01 18:02:20 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\DVDVideoSoft
[2012.09.01 18:02:07 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.05.21 15:38:24 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Fighters
[2012.02.26 15:15:45 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Garmin
[2010.07.09 23:20:45 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Goober
[2009.10.12 11:04:49 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Nikon
[2008.06.05 17:48:07 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Pixum
[2009.10.12 18:30:18 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\RawTherapee
[2012.07.01 15:26:31 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Samsung
[2008.07.15 21:38:36 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Toshiba
[2012.07.03 19:05:43 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\TuneUp Software
[2007.11.21 17:14:22 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Ulead Systems
[2009.07.19 17:48:33 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Wildlife Park 2
[2009.07.19 16:45:05 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Wildlife Park 2 - Abenteuer auf der Ranch
[2012.09.16 17:55:07 | 000,032,530 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.09.15 14:52:40 | 000,000,392 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{BD71E7E2-ECDB-4F93-B0DC-4A2B232F98A8}.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.09.07 18:27:31 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Adobe
[2011.12.18 16:47:26 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Apple Computer
[2007.11.20 21:49:14 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\ASCON Installer
[2007.11.09 20:15:01 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\ATI
[2011.10.14 18:31:47 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Avira
[2007.12.25 19:33:42 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\bhv-Edu
[2008.01.31 13:32:32 | 000,000,000 | R--D | M] -- C:\Users\Susan\AppData\Roaming\Brother
[2008.03.29 16:28:21 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Buhl Data Service
[2012.05.09 19:13:32 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Canneverbe Limited
[2009.05.31 10:08:20 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\cerasus.media
[2007.12.28 10:39:58 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Chromeflower
[2007.12.28 10:39:40 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\CrystalSpace
[2012.08.05 11:13:27 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Dropbox
[2012.09.01 18:02:20 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\DVDVideoSoft
[2012.09.01 18:02:07 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.05.21 15:38:24 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Fighters
[2012.02.26 15:15:45 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Garmin
[2010.07.09 23:20:45 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Goober
[2009.08.29 12:03:49 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Google
[2007.11.09 20:14:26 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Identities
[2007.11.09 20:13:30 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\InstallShield
[2007.11.11 22:32:18 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Macromedia
[2012.09.12 17:30:22 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Malwarebytes
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Media Center Programs
[2011.11.11 19:39:19 | 000,000,000 | --SD | M] -- C:\Users\Susan\AppData\Roaming\Microsoft
[2011.06.05 17:04:53 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Mozilla
[2009.10.12 11:04:49 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Nikon
[2008.06.05 17:48:07 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Pixum
[2009.10.12 18:30:18 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\RawTherapee
[2012.07.01 15:26:31 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Samsung
[2008.07.15 21:38:36 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Toshiba
[2012.07.03 19:05:43 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\TuneUp Software
[2007.11.21 17:14:22 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Ulead Systems
[2009.07.19 17:48:33 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Wildlife Park 2
[2009.07.19 16:45:05 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\Wildlife Park 2 - Abenteuer auf der Ranch
[2007.11.10 19:36:04 | 000,000,000 | ---D | M] -- C:\Users\Susan\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2010.03.15 16:48:22 | 000,335,872 | R--- | M] (InstallShield Software Corp.) -- C:\Users\Susan\AppData\Roaming\Microsoft\Installer\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}\ARPPRODUCTICON.exe
[2010.03.15 16:47:48 | 000,057,344 | R--- | M] (InstallShield Software Corp.) -- C:\Users\Susan\AppData\Roaming\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
[2009.10.12 10:59:31 | 000,049,152 | R--- | M] (InstallShield Software Corp.) -- C:\Users\Susan\AppData\Roaming\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
[2012.06.08 04:02:14 | 000,371,128 | ---- | M] (ml) -- C:\Users\Susan\AppData\Roaming\Samsung\Kies\UpdateTemp\Temp\Kies.Update.exe
[2012.06.08 04:02:14 | 000,371,128 | ---- | M] (ml) -- C:\Users\Susan\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe
 
< %SYSTEMDRIVE%\*.exe >
[2008.04.22 17:05:18 | 002,648,768 | ---- | M] (Microsoft Corporation) -- C:\vcredist_x86.exe
 
< MD5 for: AGP440.SYS  >
[2008.01.19 09:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.19 09:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.19 09:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.19 09:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.19 09:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.19 09:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.02.14 10:59:54 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.02.14 10:59:54 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008.02.14 10:59:53 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.19 09:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.19 09:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: KR10N.SYS  >
[2007.01.18 16:47:18 | 000,211,072 | ---- | M] (TOSHIBA CORPORATION) MD5=6E9922332386C2A49936B30B2B6FD298 -- C:\Toshiba\Drivers\Raid\Kr10i\KR10N.sys
[2007.01.18 16:47:18 | 000,211,072 | ---- | M] (TOSHIBA CORPORATION) MD5=6E9922332386C2A49936B30B2B6FD298 -- C:\Toshiba\Drivers\Raid\Kr10n\KR10N.sys
[2007.01.18 16:47:18 | 000,211,072 | ---- | M] (TOSHIBA CORPORATION) MD5=6E9922332386C2A49936B30B2B6FD298 -- C:\Windows\System32\drivers\KR10N.sys
[2007.01.18 16:47:18 | 000,211,072 | ---- | M] (TOSHIBA CORPORATION) MD5=6E9922332386C2A49936B30B2B6FD298 -- C:\Windows\System32\DriverStore\FileRepository\kr10.inf_95888b8d\KR10N.sys
 
< MD5 for: NETLOGON.DLL  >
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.19 09:35:36 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.19 09:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.19 09:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.19 09:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2007.05.31 14:22:56 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=63B4F59D7C89B1BF5277F1FFEFD491CD -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_cb39bc5b7047127e\user32.dll
[2007.05.31 14:22:57 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=9D9F061EDA75425FC67F0365E3467C86 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_cbc258dc896598f1\user32.dll
[2008.01.19 09:36:46 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2006.11.02 11:46:13 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=E698A5437B89A285ACA3FF022356810A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_cb01aa4570716e5e\user32.dll
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.19 09:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.19 09:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.19 09:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.19 09:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2006.11.02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 09:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2006.11.02 10:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_4d4fded8cae2956d\ws2ifsl.sys
[2008.01.19 07:56:49 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.19 07:56:49 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2007.05.31 13:46:51 | 006,664,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2007.05.31 13:46:49 | 000,102,400 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2007.05.31 13:46:52 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2007.05.31 13:47:02 | 015,720,448 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2007.05.31 13:47:04 | 006,008,832 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:054B9966

< End of report >

--- --- ---

cosinus 17.09.2012 11:10

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
FF - user.js - File not found
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Upgrade to Google Chrome
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Upgrade to Google Chrome
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Upgrade to Google Chrome
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\..\URLSearchHook: {81fae9c9-cfbd-4cb3-8322-412e72f55f65} - No CLSID value found
IE - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
FF - prefs.js..network.proxy.backup.ftp: "        93.97.50.33"
FF - prefs.js..network.proxy.backup.ftp_port: 80
FF - prefs.js..network.proxy.backup.socks: "        93.97.50.33"
FF - prefs.js..network.proxy.backup.socks_port: 80
FF - prefs.js..network.proxy.backup.ssl: "        93.97.50.33"
FF - prefs.js..network.proxy.backup.ssl_port: 80
FF - prefs.js..network.proxy.ftp: "        93.97.50.33"
FF - prefs.js..network.proxy.ftp_port: 80
FF - prefs.js..network.proxy.http: "        93.97.50.33"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "        93.97.50.33"
FF - prefs.js..network.proxy.socks_port: 80
FF - prefs.js..network.proxy.ssl: "        93.97.50.33"
FF - prefs.js..network.proxy.ssl_port: 80
FF - prefs.js..network.proxy.type: 0
[2012.08.11 12:23:47 | 000,526,409 | ---- | M] () (No name found) -- C:\Users\Susan\AppData\Roaming\mozilla\firefox\profiles\efjwbygu.default\extensions\toolbar@web.de.xpi
O2 - BHO: (no name) - {0124123D-61B4-456f-AF86-78C53A0790C5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0124123D-61B4-456f-AF86-78C53A0790C5} - No CLSID value found.
O3 - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O7 - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0996168d-e70c-11e1-aaa9-001b381b4222}\Shell - "" = AutoRun
O33 - MountPoints2\{0996168d-e70c-11e1-aaa9-001b381b4222}\Shell\AutoRun\command - "" = H:\start.exe
O33 - MountPoints2\{1f7599ab-bd29-11e0-abf4-001b381b4222}\Shell - "" = AutoRun
O33 - MountPoints2\{1f7599ab-bd29-11e0-abf4-001b381b4222}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{1f7599ae-bd29-11e0-abf4-001b381b4222}\Shell - "" = AutoRun
O33 - MountPoints2\{1f7599ae-bd29-11e0-abf4-001b381b4222}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{68dbe344-e6f8-11e1-a0d8-001b381b4222}\Shell - "" = AutoRun
O33 - MountPoints2\{68dbe344-e6f8-11e1-a0d8-001b381b4222}\Shell\AutoRun\command - "" = H:\start.exe
O33 - MountPoints2\{da7322eb-c36e-11e0-a98c-001b381b4222}\Shell - "" = AutoRun
O33 - MountPoints2\{da7322eb-c36e-11e0-a98c-001b381b4222}\Shell\AutoRun\command - "" = D:\AutoRun.exe
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:054B9966
:Files
C:\ProgramData\yleehzpzdovhrsn
C:\Users\All Users\yleehzpzdovhrsn
C:\ProgramData\ffgduormlbmggjj
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

traudel769 17.09.2012 16:30

weil nichts verlangt war, hab ich keinen Haken bei alle Benutzer gemacht. Ich hoffe, das war richtig so. Der Rechner wurde neu gestartet und nach dem Neustart öffnete sich folgendes Logfile

Code:



All processes killed
========== OTL ==========
HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E : value set successfully!
HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully!
HKU\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-4082368651-1888938053-1609379735-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{81fae9c9-cfbd-4cb3-8322-412e72f55f65} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{81fae9c9-cfbd-4cb3-8322-412e72f55f65}\ not found.
Registry value HKEY_USERS\S-1-5-21-4082368651-1888938053-1609379735-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found.
Prefs.js: "        93.97.50.33" removed from network.proxy.backup.ftp
Prefs.js: 80 removed from network.proxy.backup.ftp_port
Prefs.js: "        93.97.50.33" removed from network.proxy.backup.socks
Prefs.js: 80 removed from network.proxy.backup.socks_port
Prefs.js: "        93.97.50.33" removed from network.proxy.backup.ssl
Prefs.js: 80 removed from network.proxy.backup.ssl_port
Prefs.js: "        93.97.50.33" removed from network.proxy.ftp
Prefs.js: 80 removed from network.proxy.ftp_port
Prefs.js: "        93.97.50.33" removed from network.proxy.http
Prefs.js: 80 removed from network.proxy.http_port
Prefs.js: "*.local" removed from network.proxy.no_proxies_on
Prefs.js: true removed from network.proxy.share_proxy_settings
Prefs.js: "        93.97.50.33" removed from network.proxy.socks
Prefs.js: 80 removed from network.proxy.socks_port
Prefs.js: "        93.97.50.33" removed from network.proxy.ssl
Prefs.js: 80 removed from network.proxy.ssl_port
Prefs.js: 0 removed from network.proxy.type
C:\Users\Susan\AppData\Roaming\mozilla\firefox\profiles\efjwbygu.default\extensions\toolbar@web.de.xpi moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0124123D-61B4-456f-AF86-78C53A0790C5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0124123D-61B4-456f-AF86-78C53A0790C5}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{0124123D-61B4-456f-AF86-78C53A0790C5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0124123D-61B4-456f-AF86-78C53A0790C5}\ not found.
Registry value HKEY_USERS\S-1-5-21-4082368651-1888938053-1609379735-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_USERS\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\LogonHoursAction deleted successfully.
Registry value HKEY_USERS\S-1-5-21-4082368651-1888938053-1609379735-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DontDisplayLogonHoursWarnings deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0996168d-e70c-11e1-aaa9-001b381b4222}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0996168d-e70c-11e1-aaa9-001b381b4222}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0996168d-e70c-11e1-aaa9-001b381b4222}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0996168d-e70c-11e1-aaa9-001b381b4222}\ not found.
File H:\start.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1f7599ab-bd29-11e0-abf4-001b381b4222}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f7599ab-bd29-11e0-abf4-001b381b4222}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1f7599ab-bd29-11e0-abf4-001b381b4222}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f7599ab-bd29-11e0-abf4-001b381b4222}\ not found.
File D:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1f7599ae-bd29-11e0-abf4-001b381b4222}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f7599ae-bd29-11e0-abf4-001b381b4222}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1f7599ae-bd29-11e0-abf4-001b381b4222}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f7599ae-bd29-11e0-abf4-001b381b4222}\ not found.
File D:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{68dbe344-e6f8-11e1-a0d8-001b381b4222}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{68dbe344-e6f8-11e1-a0d8-001b381b4222}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{68dbe344-e6f8-11e1-a0d8-001b381b4222}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{68dbe344-e6f8-11e1-a0d8-001b381b4222}\ not found.
File H:\start.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{da7322eb-c36e-11e0-a98c-001b381b4222}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{da7322eb-c36e-11e0-a98c-001b381b4222}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{da7322eb-c36e-11e0-a98c-001b381b4222}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{da7322eb-c36e-11e0-a98c-001b381b4222}\ not found.
File D:\AutoRun.exe not found.
ADS C:\ProgramData\TEMP:054B9966 deleted successfully.
========== FILES ==========
C:\ProgramData\yleehzpzdovhrsn folder moved successfully.
File\Folder C:\Users\All Users\yleehzpzdovhrsn not found.
C:\ProgramData\ffgduormlbmggjj moved successfully.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Susan\Desktop\cmd.bat deleted successfully.
C:\Users\Susan\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: Saskia
->Temp folder emptied: 211552340 bytes
->Temporary Internet Files folder emptied: 4149915 bytes
->Java cache emptied: 1609712 bytes
->FireFox cache emptied: 179507143 bytes
->Flash cache emptied: 1256 bytes
 
User: Susan
->Temp folder emptied: 70230421 bytes
->Temporary Internet Files folder emptied: 73631386 bytes
->Java cache emptied: 46129124 bytes
->FireFox cache emptied: 198556518 bytes
->Flash cache emptied: 12471 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 104386954 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 849,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.61.5 log created on 09172012_171558

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


cosinus 17.09.2012 20:36

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

traudel769 17.09.2012 21:30

Scan ist mit der Version 2.8.8.0 erfolgt
die aktuellste Version ist wohl 2.8.9.0
Hätte ich aktuallisieren sollen?

Code:


22:25:34.0001 3360  TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
22:26:13.0157 3360  ============================================================
22:26:13.0157 3360  Current date / time: 2012/09/17 22:26:13.0157
22:26:13.0157 3360  SystemInfo:
22:26:13.0157 3360 
22:26:13.0157 3360  OS Version: 6.0.6002 ServicePack: 2.0
22:26:13.0157 3360  Product type: Workstation
22:26:13.0157 3360  ComputerName: LAPTOP
22:26:13.0157 3360  UserName: Susan
22:26:13.0157 3360  Windows directory: C:\Windows
22:26:13.0157 3360  System windows directory: C:\Windows
22:26:13.0157 3360  Processor architecture: Intel x86
22:26:13.0157 3360  Number of processors: 2
22:26:13.0157 3360  Page size: 0x1000
22:26:13.0157 3360  Boot type: Normal boot
22:26:13.0157 3360  ============================================================
22:26:14.0405 3360  Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:26:14.0421 3360  ============================================================
22:26:14.0421 3360  \Device\Harddisk0\DR0:
22:26:14.0421 3360  MBR partitions:
22:26:14.0421 3360  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x950C800
22:26:14.0421 3360  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x97FB000, BlocksNum 0x921E800
22:26:14.0421 3360  ============================================================
22:26:14.0452 3360  C: <-> \Device\Harddisk0\DR0\Partition1
22:26:14.0499 3360  E: <-> \Device\Harddisk0\DR0\Partition2
22:26:14.0499 3360  ============================================================
22:26:14.0499 3360  Initialize success
22:26:14.0499 3360  ============================================================
22:26:28.0804 5576  ============================================================
22:26:28.0804 5576  Scan started
22:26:28.0804 5576  Mode: Manual; SigCheck; TDLFS;
22:26:28.0804 5576  ============================================================
22:26:30.0801 5576  ================ Scan system memory ========================
22:26:30.0801 5576  System memory - ok
22:26:30.0801 5576  ================ Scan services =============================
22:26:31.0035 5576  [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI            C:\Windows\system32\drivers\acpi.sys
22:26:31.0191 5576  ACPI - ok
22:26:31.0362 5576  [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
22:26:31.0378 5576  AdobeARMservice - ok
22:26:31.0440 5576  [ A9D3B95E8466BD58EEB8A1154654E162 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
22:26:31.0472 5576  AdobeFlashPlayerUpdateSvc - ok
22:26:31.0518 5576  [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
22:26:31.0581 5576  adp94xx - ok
22:26:31.0628 5576  [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci        C:\Windows\system32\drivers\adpahci.sys
22:26:31.0643 5576  adpahci - ok
22:26:31.0674 5576  [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
22:26:31.0690 5576  adpu160m - ok
22:26:31.0721 5576  [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320        C:\Windows\system32\drivers\adpu320.sys
22:26:31.0737 5576  adpu320 - ok
22:26:31.0799 5576  [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
22:26:31.0955 5576  AeLookupSvc - ok
22:26:32.0064 5576  [ 3911B972B55FEA0478476B2E777B29FA ] AFD            C:\Windows\system32\drivers\afd.sys
22:26:32.0174 5576  AFD - ok
22:26:32.0220 5576  [ 39E435C90C9C4F780FA0ED05CA3C3A1B ] AgereModemAudio C:\Windows\system32\agrsmsvc.exe
22:26:32.0267 5576  AgereModemAudio - ok
22:26:32.0345 5576  [ CE91B158FA490CF4C4D487A4130F4660 ] AgereSoftModem  C:\Windows\system32\DRIVERS\AGRSM.sys
22:26:32.0454 5576  AgereSoftModem - ok
22:26:32.0517 5576  [ EF23439CDD587F64C2C1B8825CEAD7D8 ] agp440          C:\Windows\system32\drivers\agp440.sys
22:26:32.0532 5576  agp440 - ok
22:26:32.0579 5576  [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
22:26:32.0595 5576  aic78xx - ok
22:26:32.0642 5576  [ A1545B731579895D8CC44FC0481C1192 ] ALG            C:\Windows\System32\alg.exe
22:26:32.0766 5576  ALG - ok
22:26:32.0798 5576  [ 90395B64600EBB4552E26E178C94B2E4 ] aliide          C:\Windows\system32\drivers\aliide.sys
22:26:32.0829 5576  aliide - ok
22:26:32.0891 5576  [ 2B13E304C9DFDFA5EB582F6A149FA2C7 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
22:26:32.0907 5576  amdagp - ok
22:26:32.0922 5576  [ 0577DF1D323FE75A739C787893D300EA ] amdide          C:\Windows\system32\drivers\amdide.sys
22:26:32.0938 5576  amdide - ok
22:26:32.0954 5576  [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7          C:\Windows\system32\drivers\amdk7.sys
22:26:33.0125 5576  AmdK7 - ok
22:26:33.0156 5576  [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8          C:\Windows\system32\DRIVERS\amdk8.sys
22:26:33.0219 5576  AmdK8 - ok
22:26:33.0328 5576  [ 466A0D95960DAD3222C896D2CEA99993 ] AntiVirSchedulerService C:\Program Files\Avira\AntiVir Desktop\sched.exe
22:26:33.0344 5576  AntiVirSchedulerService - ok
22:26:33.0422 5576  [ A489BE6BB0AA1FF406B488B60542314B ] AntiVirService  C:\Program Files\Avira\AntiVir Desktop\avguard.exe
22:26:33.0437 5576  AntiVirService - ok
22:26:33.0484 5576  [ 7C2F57BCE81FA74933F0E1C84A97C9DB ] ApfiltrService  C:\Windows\system32\DRIVERS\Apfiltr.sys
22:26:33.0546 5576  ApfiltrService - ok
22:26:33.0593 5576  [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo        C:\Windows\System32\appinfo.dll
22:26:33.0656 5576  Appinfo - ok
22:26:33.0687 5576  [ 5F673180268BB1FDB69C99B6619FE379 ] arc            C:\Windows\system32\drivers\arc.sys
22:26:33.0702 5576  arc - ok
22:26:33.0718 5576  [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
22:26:33.0734 5576  arcsas - ok
22:26:33.0780 5576  [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
22:26:33.0858 5576  AsyncMac - ok
22:26:33.0905 5576  [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi          C:\Windows\system32\drivers\atapi.sys
22:26:33.0921 5576  atapi - ok
22:26:33.0999 5576  [ 8BE56F8300E1C37B578DA23C71816B7A ] athr            C:\Windows\system32\DRIVERS\athr.sys
22:26:34.0155 5576  athr - ok
22:26:34.0233 5576  [ 826C36EF415E0A0AF7A78BA435AEFD86 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
22:26:34.0373 5576  Ati External Event Utility - ok
22:26:34.0529 5576  [ 462A206DDA06FB77AF792A009375C899 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
22:26:34.0701 5576  atikmdag - ok
22:26:34.0748 5576  [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
22:26:34.0794 5576  AudioEndpointBuilder - ok
22:26:34.0794 5576  [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv        C:\Windows\System32\Audiosrv.dll
22:26:34.0826 5576  Audiosrv - ok
22:26:34.0872 5576  [ D5541F0AFB767E85FC412FC609D96A74 ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
22:26:35.0340 5576  avgntflt - ok
22:26:35.0387 5576  [ 7D967A682D4694DF7FA57D63A2DB01FE ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
22:26:35.0403 5576  avipbb - ok
22:26:35.0434 5576  [ 271CFD1A989209B1964E24D969552BF7 ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
22:26:35.0450 5576  avkmgr - ok
22:26:35.0496 5576  [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep            C:\Windows\system32\drivers\Beep.sys
22:26:35.0559 5576  Beep - ok
22:26:35.0621 5576  [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE            C:\Windows\System32\bfe.dll
22:26:35.0684 5576  BFE - ok
22:26:35.0762 5576  [ 93952506C6D67330367F7E7934B6A02F ] BITS            C:\Windows\System32\qmgr.dll
22:26:35.0840 5576  BITS - ok
22:26:35.0840 5576  blbdrive - ok
22:26:35.0871 5576  BlueletAudio - ok
22:26:35.0886 5576  BlueletSCOAudio - ok
22:26:35.0949 5576  [ 3F56903E124E820AEECE6D471583C6C1 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
22:26:35.0964 5576  Bonjour Service - ok
22:26:35.0996 5576  [ 35F376253F687BDE63976CCB3F2108CA ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
22:26:36.0058 5576  bowser - ok
22:26:36.0105 5576  [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
22:26:36.0152 5576  BrFiltLo - ok
22:26:36.0183 5576  [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
22:26:36.0214 5576  BrFiltUp - ok
22:26:36.0261 5576  [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser        C:\Windows\System32\browser.dll
22:26:36.0323 5576  Browser - ok
22:26:36.0354 5576  [ B304E75CFF293029EDDF094246747113 ] Brserid        C:\Windows\system32\drivers\brserid.sys
22:26:36.0448 5576  Brserid - ok
22:26:36.0479 5576  [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
22:26:36.0557 5576  BrSerWdm - ok
22:26:36.0573 5576  [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
22:26:36.0651 5576  BrUsbMdm - ok
22:26:36.0666 5576  [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
22:26:36.0744 5576  BrUsbSer - ok
22:26:36.0760 5576  BT - ok
22:26:36.0776 5576  BTCOM - ok
22:26:36.0776 5576  BTCOMBUS - ok
22:26:36.0807 5576  Btcsrusb - ok
22:26:36.0822 5576  BtHidBus - ok
22:26:36.0854 5576  BTHidEnum - ok
22:26:36.0869 5576  BTHidMgr - ok
22:26:36.0885 5576  [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
22:26:36.0978 5576  BTHMODEM - ok
22:26:37.0041 5576  [ 7BB8AC22BC9E6A1E7707DAECADA95CD9 ] btnetBUs        C:\Windows\system32\Drivers\btnetBus.sys
22:26:37.0041 5576  btnetBUs - ok
22:26:37.0088 5576  [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
22:26:37.0134 5576  cdfs - ok
22:26:37.0197 5576  [ 6B4BFFB9BECD728097024276430DB314 ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
22:26:37.0228 5576  cdrom - ok
22:26:37.0290 5576  [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc    C:\Windows\System32\certprop.dll
22:26:37.0337 5576  CertPropSvc - ok
22:26:37.0431 5576  [ C82162949BBA6CC5D006C7BD008F3CF1 ] CFSvcs          C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
22:26:37.0446 5576  CFSvcs ( UnsignedFile.Multi.Generic ) - warning
22:26:37.0446 5576  CFSvcs - detected UnsignedFile.Multi.Generic (1)
22:26:37.0478 5576  [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass        C:\Windows\system32\drivers\circlass.sys
22:26:37.0556 5576  circlass - ok
22:26:37.0602 5576  [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS            C:\Windows\system32\CLFS.sys
22:26:37.0618 5576  CLFS - ok
22:26:37.0680 5576  [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:26:37.0696 5576  clr_optimization_v2.0.50727_32 - ok
22:26:37.0790 5576  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:26:37.0852 5576  clr_optimization_v4.0.30319_32 - ok
22:26:37.0899 5576  [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
22:26:37.0977 5576  CmBatt - ok
22:26:38.0024 5576  [ 45201046C776FFDAF3FC8A0029C581C8 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
22:26:38.0039 5576  cmdide - ok
22:26:38.0070 5576  [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
22:26:38.0086 5576  Compbatt - ok
22:26:38.0102 5576  COMSysApp - ok
22:26:38.0102 5576  [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
22:26:38.0117 5576  crcdisk - ok
22:26:38.0148 5576  [ 22A7F883508176489F559EE745B5BF5D ] Crusoe          C:\Windows\system32\drivers\crusoe.sys
22:26:38.0211 5576  Crusoe - ok
22:26:38.0273 5576  [ 75C6A297E364014840B48ECCD7525E30 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
22:26:38.0320 5576  CryptSvc - ok
22:26:38.0398 5576  [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch      C:\Windows\system32\rpcss.dll
22:26:38.0445 5576  DcomLaunch - ok
22:26:38.0476 5576  [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
22:26:38.0507 5576  DfsC - ok
22:26:38.0632 5576  [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR            C:\Windows\system32\DFSR.exe
22:26:38.0882 5576  DFSR - ok
22:26:38.0960 5576  [ F9F31A9F2A8C0DD0CEB6E380BF0985D4 ] dg_ssudbus      C:\Windows\system32\DRIVERS\ssudbus.sys
22:26:38.0991 5576  dg_ssudbus - ok
22:26:39.0069 5576  [ 9028559C132146FB75EB7ACF384B086A ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
22:26:39.0100 5576  Dhcp - ok
22:26:39.0147 5576  [ 5D4AEFC3386920236A548271F8F1AF6A ] disk            C:\Windows\system32\drivers\disk.sys
22:26:39.0162 5576  disk - ok
22:26:39.0209 5576  [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache        C:\Windows\System32\dnsrslvr.dll
22:26:39.0256 5576  Dnscache - ok
22:26:39.0287 5576  [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc        C:\Windows\System32\dot3svc.dll
22:26:39.0334 5576  dot3svc - ok
22:26:39.0381 5576  [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS            C:\Windows\system32\dps.dll
22:26:39.0428 5576  DPS - ok
22:26:39.0459 5576  [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
22:26:39.0506 5576  drmkaud - ok
22:26:39.0568 5576  [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
22:26:39.0646 5576  DXGKrnl - ok
22:26:39.0693 5576  [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60          C:\Windows\system32\DRIVERS\E1G60I32.sys
22:26:39.0755 5576  E1G60 - ok
22:26:39.0786 5576  [ C0B95E40D85CD807D614E264248A45B9 ] EapHost        C:\Windows\System32\eapsvc.dll
22:26:39.0833 5576  EapHost - ok
22:26:39.0896 5576  [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache          C:\Windows\system32\drivers\ecache.sys
22:26:39.0911 5576  Ecache - ok
22:26:40.0005 5576  [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
22:26:40.0036 5576  ehRecvr - ok
22:26:40.0067 5576  [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched        C:\Windows\ehome\ehsched.exe
22:26:40.0145 5576  ehSched - ok
22:26:40.0161 5576  [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart        C:\Windows\ehome\ehstart.dll
22:26:40.0192 5576  ehstart - ok
22:26:40.0239 5576  [ D71233D7CCC2E64F8715A20428D5A33B ] ElbyCDIO        C:\Windows\system32\Drivers\ElbyCDIO.sys
22:26:40.0254 5576  ElbyCDIO - ok
22:26:40.0301 5576  [ E8F3F21A71720C84BCF423B80028359F ] elxstor        C:\Windows\system32\drivers\elxstor.sys
22:26:40.0317 5576  elxstor - ok
22:26:40.0457 5576  [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt        C:\Windows\system32\emdmgmt.dll
22:26:40.0785 5576  EMDMgmt - ok
22:26:40.0878 5576  [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem    C:\Windows\system32\es.dll
22:26:40.0925 5576  EventSystem - ok
22:26:41.0003 5576  [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat          C:\Windows\system32\drivers\exfat.sys
22:26:41.0050 5576  exfat - ok
22:26:41.0097 5576  [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
22:26:41.0159 5576  fastfat - ok
22:26:41.0175 5576  [ 63BDADA84951B9C03E641800E176898A ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
22:26:41.0253 5576  fdc - ok
22:26:41.0300 5576  [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost        C:\Windows\system32\fdPHost.dll
22:26:41.0331 5576  fdPHost - ok
22:26:41.0362 5576  [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub        C:\Windows\system32\fdrespub.dll
22:26:41.0440 5576  FDResPub - ok
22:26:41.0487 5576  [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
22:26:41.0502 5576  FileInfo - ok
22:26:41.0534 5576  [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
22:26:41.0580 5576  Filetrace - ok
22:26:41.0674 5576  [ 167D24A045499EBEF438F231976158DF ] FirebirdServerMAGIXInstance C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
22:26:41.0799 5576  FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - warning
22:26:41.0799 5576  FirebirdServerMAGIXInstance - detected UnsignedFile.Multi.Generic (1)
22:26:41.0877 5576  [ 227846995AFEEFA70D328BF5334A86A5 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
22:26:41.0970 5576  FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - warning
22:26:41.0970 5576  FLEXnet Licensing Service - detected UnsignedFile.Multi.Generic (1)
22:26:42.0002 5576  [ 6603957EFF5EC62D25075EA8AC27DE68 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
22:26:42.0095 5576  flpydisk - ok
22:26:42.0126 5576  [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
22:26:42.0158 5576  FltMgr - ok
22:26:42.0220 5576  [ 8CE364388C8ECA59B14B539179276D44 ] FontCache      C:\Windows\system32\FntCache.dll
22:26:42.0376 5576  FontCache - ok
22:26:42.0454 5576  [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
22:26:42.0470 5576  FontCache3.0.0.0 - ok
22:26:42.0501 5576  [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
22:26:42.0563 5576  Fs_Rec - ok
22:26:42.0594 5576  [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
22:26:42.0610 5576  gagp30kx - ok
22:26:42.0657 5576  [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
22:26:42.0672 5576  GEARAspiWDM - ok
22:26:42.0719 5576  [ 007AEA2E06E7CEF7372E40C277163959 ] ggflt          C:\Windows\system32\DRIVERS\ggflt.sys
22:26:42.0735 5576  ggflt - ok
22:26:42.0750 5576  [ C73DE35960CA75C5AB4AE636B127C64E ] ggsemc          C:\Windows\system32\DRIVERS\ggsemc.sys
22:26:42.0766 5576  ggsemc - ok
22:26:42.0828 5576  [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc          C:\Windows\System32\gpsvc.dll
22:26:42.0953 5576  gpsvc - ok
22:26:43.0047 5576  [ CC839E8D766CC31A7710C9F38CF3E375 ] gusvc          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
22:26:43.0062 5576  gusvc - ok
22:26:43.0125 5576  [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
22:26:43.0203 5576  HdAudAddService - ok
22:26:43.0265 5576  [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
22:26:43.0406 5576  HDAudBus - ok
22:26:43.0437 5576  [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth          C:\Windows\system32\drivers\hidbth.sys
22:26:43.0515 5576  HidBth - ok
22:26:43.0530 5576  [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr          C:\Windows\system32\drivers\hidir.sys
22:26:43.0608 5576  HidIr - ok
22:26:43.0655 5576  [ 84067081F3318162797385E11A8F0582 ] hidserv        C:\Windows\system32\hidserv.dll
22:26:43.0686 5576  hidserv - ok
22:26:43.0718 5576  [ CCA4B519B17E23A00B826C55716809CC ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
22:26:43.0764 5576  HidUsb - ok
22:26:43.0796 5576  [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc          C:\Windows\system32\kmsvc.dll
22:26:43.0858 5576  hkmsvc - ok
22:26:43.0874 5576  [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs        C:\Windows\system32\drivers\hpcisss.sys
22:26:43.0889 5576  HpCISSs - ok
22:26:43.0952 5576  [ F870AA3E254628EBEAFE754108D664DE ] HTTP            C:\Windows\system32\drivers\HTTP.sys
22:26:44.0061 5576  HTTP - ok
22:26:44.0076 5576  hwdatacard - ok
22:26:44.0123 5576  [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp          C:\Windows\system32\drivers\i2omp.sys
22:26:44.0139 5576  i2omp - ok
22:26:44.0217 5576  [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
22:26:44.0248 5576  i8042prt - ok
22:26:44.0279 5576  [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV        C:\Windows\system32\drivers\iastorv.sys
22:26:44.0310 5576  iaStorV - ok
22:26:44.0373 5576  [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT        C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
22:26:44.0388 5576  IDriverT ( UnsignedFile.Multi.Generic ) - warning
22:26:44.0388 5576  IDriverT - detected UnsignedFile.Multi.Generic (1)
22:26:44.0466 5576  [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc          C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
22:26:44.0576 5576  idsvc - ok
22:26:44.0607 5576  [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
22:26:44.0622 5576  iirsp - ok
22:26:44.0669 5576  [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT          C:\Windows\System32\ikeext.dll
22:26:44.0747 5576  IKEEXT - ok
22:26:44.0841 5576  [ B84732D9F8459ABF6323D28A3270DC19 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
22:26:44.0981 5576  IntcAzAudAddService - ok
22:26:45.0044 5576  [ 97469037714070E45194ED318D636401 ] intelide        C:\Windows\system32\drivers\intelide.sys
22:26:45.0044 5576  intelide - ok
22:26:45.0075 5576  [ CE44CC04262F28216DD4341E9E36A16F ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
22:26:45.0137 5576  intelppm - ok
22:26:45.0184 5576  [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
22:26:45.0231 5576  IPBusEnum - ok
22:26:45.0262 5576  [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:26:45.0309 5576  IpFilterDriver - ok
22:26:45.0356 5576  [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
22:26:45.0402 5576  iphlpsvc - ok
22:26:45.0402 5576  IpInIp - ok
22:26:45.0449 5576  [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV        C:\Windows\system32\drivers\ipmidrv.sys
22:26:45.0527 5576  IPMIDRV - ok
22:26:45.0574 5576  [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT          C:\Windows\system32\DRIVERS\ipnat.sys
22:26:45.0636 5576  IPNAT - ok
22:26:45.0668 5576  [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
22:26:45.0714 5576  IRENUM - ok
22:26:45.0777 5576  [ 350FCA7E73CF65BCEF43FAE1E4E91293 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
22:26:45.0792 5576  isapnp - ok
22:26:45.0855 5576  [ 232FA340531D940AAC623B121A595034 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
22:26:45.0870 5576  iScsiPrt - ok
22:26:45.0902 5576  [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
22:26:45.0917 5576  iteatapi - ok
22:26:45.0948 5576  [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid        C:\Windows\system32\drivers\iteraid.sys
22:26:45.0964 5576  iteraid - ok
22:26:45.0995 5576  IvtBtBUs - ok
22:26:46.0042 5576  [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
22:26:46.0058 5576  kbdclass - ok
22:26:46.0073 5576  [ D2600CB17B7408B4A83F231DC9A11AC3 ] kbdhid          C:\Windows\system32\drivers\kbdhid.sys
22:26:46.0151 5576  kbdhid - ok
22:26:46.0182 5576  [ A3E186B4B935905B829219502557314E ] KeyIso          C:\Windows\system32\lsass.exe
22:26:46.0229 5576  KeyIso - ok
22:26:46.0276 5576  [ A383F2CEA0A8F4E76E71ABC869BD5748 ] KR10I          C:\Windows\system32\drivers\kr10i.sys
22:26:46.0323 5576  KR10I - ok
22:26:46.0354 5576  [ 6E9922332386C2A49936B30B2B6FD298 ] KR10N          C:\Windows\system32\drivers\kr10n.sys
22:26:46.0385 5576  KR10N - ok
22:26:46.0432 5576  [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
22:26:46.0479 5576  KSecDD - ok
22:26:46.0541 5576  [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm          C:\Windows\system32\msdtckrm.dll
22:26:46.0619 5576  KtmRm - ok
22:26:46.0650 5576  [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer    C:\Windows\system32\srvsvc.dll
22:26:46.0697 5576  LanmanServer - ok
22:26:46.0744 5576  [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
22:26:46.0806 5576  LanmanWorkstation - ok
22:26:46.0838 5576  [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
22:26:46.0884 5576  lltdio - ok
22:26:46.0916 5576  [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
22:26:46.0962 5576  lltdsvc - ok
22:26:47.0009 5576  [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts        C:\Windows\System32\lmhsvc.dll
22:26:47.0072 5576  lmhosts - ok
22:26:47.0087 5576  [ 515FC18CABEE0158A324B08B1C2667CF ] LPCFilter      C:\Windows\system32\DRIVERS\LPCFilter.sys
22:26:47.0118 5576  LPCFilter - ok
22:26:47.0150 5576  [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
22:26:47.0165 5576  LSI_FC - ok
22:26:47.0196 5576  [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
22:26:47.0212 5576  LSI_SAS - ok
22:26:47.0228 5576  [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
22:26:47.0243 5576  LSI_SCSI - ok
22:26:47.0290 5576  [ 8F5C7426567798E62A3B3614965D62CC ] luafv          C:\Windows\system32\drivers\luafv.sys
22:26:47.0337 5576  luafv - ok
22:26:47.0368 5576  [ 65E794E86468B61F2BC79ABC48BC4433 ] MBAMProtector  C:\Windows\system32\drivers\mbam.sys
22:26:47.0384 5576  MBAMProtector - ok
22:26:47.0462 5576  [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler  C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
22:26:47.0493 5576  MBAMScheduler - ok
22:26:47.0540 5576  [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
22:26:47.0586 5576  MBAMService - ok
22:26:47.0649 5576  [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
22:26:47.0680 5576  Mcx2Svc - ok
22:26:47.0711 5576  [ D153B14FC6598EAE8422A2037553ADCE ] megasas        C:\Windows\system32\drivers\megasas.sys
22:26:47.0727 5576  megasas - ok
22:26:47.0742 5576  [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS          C:\Windows\system32\mmcss.dll
22:26:47.0805 5576  MMCSS - ok
22:26:47.0836 5576  [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem          C:\Windows\system32\drivers\modem.sys
22:26:47.0883 5576  Modem - ok
22:26:47.0930 5576  [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
22:26:47.0976 5576  monitor - ok
22:26:48.0008 5576  [ 5BF6A1326A335C5298477754A506D263 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
22:26:48.0023 5576  mouclass - ok
22:26:48.0070 5576  [ 93B8D4869E12CFBE663915502900876F ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
22:26:48.0132 5576  mouhid - ok
22:26:48.0195 5576  [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
22:26:48.0210 5576  MountMgr - ok
22:26:48.0273 5576  [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
22:26:48.0304 5576  MozillaMaintenance - ok
22:26:48.0351 5576  [ 583A41F26278D9E0EA548163D6139397 ] mpio            C:\Windows\system32\drivers\mpio.sys
22:26:48.0382 5576  mpio - ok
22:26:48.0429 5576  [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
22:26:48.0476 5576  mpsdrv - ok
22:26:48.0522 5576  [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc          C:\Windows\system32\mpssvc.dll
22:26:48.0585 5576  MpsSvc - ok
22:26:48.0616 5576  [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
22:26:48.0647 5576  Mraid35x - ok
22:26:48.0694 5576  [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
22:26:48.0710 5576  MRxDAV - ok
22:26:48.0756 5576  [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
22:26:48.0788 5576  mrxsmb - ok
22:26:48.0834 5576  [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:26:48.0866 5576  mrxsmb10 - ok
22:26:48.0881 5576  [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:26:48.0912 5576  mrxsmb20 - ok
22:26:48.0959 5576  [ 742AED7939E734C36B7E8D6228CE26B7 ] msahci          C:\Windows\system32\drivers\msahci.sys
22:26:48.0975 5576  msahci - ok
22:26:49.0006 5576  [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
22:26:49.0022 5576  msdsm - ok
22:26:49.0053 5576  [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC          C:\Windows\System32\msdtc.exe
22:26:49.0100 5576  MSDTC - ok
22:26:49.0162 5576  [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
22:26:49.0209 5576  Msfs - ok
22:26:49.0256 5576  [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
22:26:49.0271 5576  msisadrv - ok
22:26:49.0302 5576  [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
22:26:49.0365 5576  MSiSCSI - ok
22:26:49.0365 5576  msiserver - ok
22:26:49.0412 5576  [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
22:26:49.0458 5576  MSKSSRV - ok
22:26:49.0521 5576  [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
22:26:49.0568 5576  MSPCLOCK - ok
22:26:49.0583 5576  [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
22:26:49.0646 5576  MSPQM - ok
22:26:49.0677 5576  [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
22:26:49.0708 5576  MsRPC - ok
22:26:49.0755 5576  [ E384487CB84BE41D09711C30CA79646C ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
22:26:49.0770 5576  mssmbios - ok
22:26:49.0786 5576  [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
22:26:49.0833 5576  MSTEE - ok
22:26:49.0848 5576  [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup            C:\Windows\system32\Drivers\mup.sys
22:26:49.0864 5576  Mup - ok
22:26:49.0911 5576  [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent        C:\Windows\system32\qagentRT.dll
22:26:49.0958 5576  napagent - ok
22:26:49.0989 5576  [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
22:26:50.0020 5576  NativeWifiP - ok
22:26:50.0082 5576  [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS            C:\Windows\system32\drivers\ndis.sys
22:26:50.0129 5576  NDIS - ok
22:26:50.0160 5576  [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
22:26:50.0207 5576  NdisTapi - ok
22:26:50.0238 5576  [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
22:26:50.0285 5576  Ndisuio - ok
22:26:50.0316 5576  [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
22:26:50.0348 5576  NdisWan - ok
22:26:50.0394 5576  [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
22:26:50.0441 5576  NDProxy - ok
22:26:50.0441 5576  [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
22:26:50.0488 5576  NetBIOS - ok
22:26:50.0535 5576  [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt          C:\Windows\system32\DRIVERS\netbt.sys
22:26:50.0582 5576  netbt - ok
22:26:50.0597 5576  [ A3E186B4B935905B829219502557314E ] Netlogon        C:\Windows\system32\lsass.exe
22:26:50.0628 5576  Netlogon - ok
22:26:50.0660 5576  [ C8052711DAECC48B982434C5116CA401 ] Netman          C:\Windows\System32\netman.dll
22:26:50.0722 5576  Netman - ok
22:26:50.0753 5576  [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm        C:\Windows\System32\netprofm.dll
22:26:50.0831 5576  netprofm - ok
22:26:50.0878 5576  [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:26:50.0894 5576  NetTcpPortSharing - ok
22:26:50.0909 5576  [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
22:26:50.0925 5576  nfrd960 - ok
22:26:50.0972 5576  [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc          C:\Windows\System32\nlasvc.dll
22:26:51.0018 5576  NlaSvc - ok
22:26:51.0050 5576  [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
22:26:51.0081 5576  Npfs - ok
22:26:51.0112 5576  [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi            C:\Windows\system32\nsisvc.dll
22:26:51.0159 5576  nsi - ok
22:26:51.0190 5576  [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
22:26:51.0237 5576  nsiproxy - ok
22:26:51.0315 5576  [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
22:26:51.0408 5576  Ntfs - ok
22:26:51.0440 5576  [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi      C:\Windows\system32\drivers\ntrigdigi.sys
22:26:51.0502 5576  ntrigdigi - ok
22:26:51.0549 5576  [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null            C:\Windows\system32\drivers\Null.sys
22:26:51.0580 5576  Null - ok
22:26:51.0596 5576  [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid          C:\Windows\system32\drivers\nvraid.sys
22:26:51.0627 5576  nvraid - ok
22:26:51.0627 5576  [ 9E0BA19A28C498A6D323D065DB76DFFC ] nvstor          C:\Windows\system32\drivers\nvstor.sys
22:26:51.0642 5576  nvstor - ok
22:26:51.0674 5576  [ 07C186427EB8FCC3D8D7927187F260F7 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
22:26:51.0689 5576  nv_agp - ok
22:26:51.0689 5576  NwlnkFlt - ok
22:26:51.0705 5576  NwlnkFwd - ok
22:26:51.0798 5576  [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv          C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
22:26:51.0845 5576  odserv - ok
22:26:51.0892 5576  [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
22:26:51.0970 5576  ohci1394 - ok
22:26:52.0048 5576  [ 5A432A042DAE460ABE7199B758E8606C ] ose            C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:26:52.0064 5576  ose - ok
22:26:52.0157 5576  [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc        C:\Windows\system32\p2psvc.dll
22:26:52.0298 5576  p2pimsvc - ok
22:26:52.0313 5576  [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc          C:\Windows\system32\p2psvc.dll
22:26:52.0360 5576  p2psvc - ok
22:26:52.0407 5576  [ 0FA9B5055484649D63C303FE404E5F4D ] Parport        C:\Windows\system32\drivers\parport.sys
22:26:52.0485 5576  Parport - ok
22:26:52.0516 5576  [ B9C2B89F08670E159F7181891E449CD9 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
22:26:52.0532 5576  partmgr - ok
22:26:52.0547 5576  [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm          C:\Windows\system32\drivers\parvdm.sys
22:26:52.0625 5576  Parvdm - ok
22:26:52.0656 5576  [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc          C:\Windows\System32\pcasvc.dll
22:26:52.0719 5576  PcaSvc - ok
22:26:52.0734 5576  pccsmcfd - ok
22:26:52.0781 5576  [ 941DC1D19E7E8620F40BBC206981EFDB ] pci            C:\Windows\system32\drivers\pci.sys
22:26:52.0797 5576  pci - ok
22:26:52.0828 5576  [ 1636D43F10416AEB483BC6001097B26C ] pciide          C:\Windows\system32\drivers\pciide.sys
22:26:52.0844 5576  pciide - ok
22:26:52.0875 5576  [ 3BB2244F343B610C29C98035504C9B75 ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
22:26:52.0890 5576  pcmcia - ok
22:26:52.0953 5576  [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
22:26:53.0124 5576  PEAUTH - ok
22:26:53.0234 5576  [ B1689DF169143F57053F795390C99DB3 ] pla            C:\Windows\system32\pla.dll
22:26:53.0374 5576  pla - ok
22:26:53.0421 5576  [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
22:26:53.0468 5576  PlugPlay - ok
22:26:53.0514 5576  [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg    C:\Windows\system32\p2psvc.dll
22:26:53.0561 5576  PNRPAutoReg - ok
22:26:53.0577 5576  [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc        C:\Windows\system32\p2psvc.dll
22:26:53.0639 5576  PNRPsvc - ok
22:26:53.0702 5576  [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
22:26:53.0795 5576  PolicyAgent - ok
22:26:53.0842 5576  [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
22:26:53.0889 5576  PptpMiniport - ok
22:26:53.0936 5576  [ 0E3CEF5D28B40CF273281D620C50700A ] Processor      C:\Windows\system32\drivers\processr.sys
22:26:54.0014 5576  Processor - ok
22:26:54.0045 5576  [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc        C:\Windows\system32\profsvc.dll
22:26:54.0107 5576  ProfSvc - ok
22:26:54.0123 5576  [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
22:26:54.0138 5576  ProtectedStorage - ok
22:26:54.0170 5576  [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
22:26:54.0216 5576  PSched - ok
22:26:54.0248 5576  [ 153D02480A0A2F45785522E814C634B6 ] PxHelp20        C:\Windows\system32\Drivers\PxHelp20.sys
22:26:54.0263 5576  PxHelp20 - ok
22:26:54.0310 5576  [ CCDAC889326317792480C0A67156A1EC ] ql2300          C:\Windows\system32\drivers\ql2300.sys
22:26:54.0388 5576  ql2300 - ok
22:26:54.0419 5576  [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
22:26:54.0450 5576  ql40xx - ok
22:26:54.0497 5576  [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE          C:\Windows\system32\qwave.dll
22:26:54.0544 5576  QWAVE - ok
22:26:54.0575 5576  [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
22:26:54.0622 5576  QWAVEdrv - ok
22:26:54.0669 5576  [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
22:26:54.0731 5576  RasAcd - ok
22:26:54.0762 5576  [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto        C:\Windows\System32\rasauto.dll
22:26:54.0825 5576  RasAuto - ok
22:26:54.0856 5576  [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
22:26:54.0903 5576  Rasl2tp - ok
22:26:54.0950 5576  [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan          C:\Windows\System32\rasmans.dll
22:26:54.0996 5576  RasMan - ok
22:26:55.0028 5576  [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
22:26:55.0074 5576  RasPppoe - ok
22:26:55.0121 5576  [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
22:26:55.0152 5576  RasSstp - ok
22:26:55.0199 5576  [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
22:26:55.0246 5576  rdbss - ok
22:26:55.0277 5576  [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
22:26:55.0340 5576  RDPCDD - ok
22:26:55.0386 5576  [ E8BD98D46F2ED77132BA927FCCB47D8B ] rdpdr          C:\Windows\system32\drivers\rdpdr.sys
22:26:55.0464 5576  rdpdr - ok
22:26:55.0480 5576  [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
22:26:55.0527 5576  RDPENCDD - ok
22:26:55.0558 5576  [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
22:26:55.0620 5576  RDPWD - ok
22:26:55.0667 5576  [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess    C:\Windows\System32\mprdim.dll
22:26:55.0714 5576  RemoteAccess - ok
22:26:55.0745 5576  [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry  C:\Windows\system32\regsvc.dll
22:26:55.0792 5576  RemoteRegistry - ok
22:26:55.0854 5576  [ 75E8A6BFA7374ABA833AE92BF41AE4E6 ] ROOTMODEM      C:\Windows\system32\Drivers\RootMdm.sys
22:26:55.0886 5576  ROOTMODEM - ok
22:26:55.0917 5576  [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator      C:\Windows\system32\locator.exe
22:26:55.0964 5576  RpcLocator - ok
22:26:55.0995 5576  [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs          C:\Windows\system32\rpcss.dll
22:26:56.0042 5576  RpcSs - ok
22:26:56.0088 5576  [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
22:26:56.0135 5576  rspndr - ok
22:26:56.0151 5576  [ 8AC16411B25E29124F6D421ADD58FBE6 ] RTL8169        C:\Windows\system32\DRIVERS\Rtlh86.sys
22:26:56.0198 5576  RTL8169 - ok
22:26:56.0291 5576  [ 12A851F30853A5A8E7B50341FA4B0FFB ] s1018bus        C:\Windows\system32\DRIVERS\s1018bus.sys
22:26:56.0307 5576  s1018bus - ok
22:26:56.0338 5576  [ A0141D5DC689A892B3F30446CBE52575 ] s1018mdfl      C:\Windows\system32\DRIVERS\s1018mdfl.sys
22:26:56.0354 5576  s1018mdfl - ok
22:26:56.0400 5576  [ 07D430E4B2BFDE6B07F31F1DA6E7CAB0 ] s1018mdm        C:\Windows\system32\DRIVERS\s1018mdm.sys
22:26:56.0416 5576  s1018mdm - ok
22:26:56.0463 5576  [ D73C20D3F0F825C8FD23F841CDCB14C0 ] s1018mgmt      C:\Windows\system32\DRIVERS\s1018mgmt.sys
22:26:56.0478 5576  s1018mgmt - ok
22:26:56.0525 5576  [ 895A1A2812DBD5AFDD5CA4686A89A33C ] s1018nd5        C:\Windows\system32\DRIVERS\s1018nd5.sys
22:26:56.0541 5576  s1018nd5 - ok
22:26:56.0572 5576  [ A986E9683C74FA06456FD2AD34BA1490 ] s1018obex      C:\Windows\system32\DRIVERS\s1018obex.sys
22:26:56.0588 5576  s1018obex - ok
22:26:56.0634 5576  [ DA83525924C23F30F37AC1D1F11D6F15 ] s1018unic      C:\Windows\system32\DRIVERS\s1018unic.sys
22:26:56.0650 5576  s1018unic - ok
22:26:56.0666 5576  [ A3E186B4B935905B829219502557314E ] SamSs          C:\Windows\system32\lsass.exe
22:26:56.0681 5576  SamSs - ok
22:26:56.0728 5576  [ 3CE8F073A557E172B330109436984E30 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
22:26:56.0744 5576  sbp2port - ok
22:26:56.0775 5576  [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
22:26:56.0822 5576  SCardSvr - ok
22:26:56.0884 5576  [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule        C:\Windows\system32\schedsvc.dll
22:26:56.0962 5576  Schedule - ok
22:26:57.0009 5576  [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc    C:\Windows\System32\certprop.dll
22:26:57.0040 5576  SCPolicySvc - ok
22:26:57.0071 5576  [ 8F36B54688C31EED4580129040C6A3D3 ] sdbus          C:\Windows\system32\DRIVERS\sdbus.sys
22:26:57.0102 5576  sdbus - ok
22:26:57.0134 5576  [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
22:26:57.0180 5576  SDRSVC - ok
22:26:57.0212 5576  [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
22:26:57.0290 5576  secdrv - ok
22:26:57.0321 5576  [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon        C:\Windows\system32\seclogon.dll
22:26:57.0352 5576  seclogon - ok
22:26:57.0383 5576  [ A9BBAB5759771E523F55563D6CBE140F ] SENS            C:\Windows\System32\sens.dll
22:26:57.0430 5576  SENS - ok
22:26:57.0461 5576  [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum        C:\Windows\system32\DRIVERS\serenum.sys
22:26:57.0524 5576  Serenum - ok
22:26:57.0555 5576  [ C70D69A918B178D3C3B06339B40C2E1B ] Serial          C:\Windows\system32\drivers\serial.sys
22:26:57.0633 5576  Serial - ok
22:26:57.0664 5576  [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
22:26:57.0695 5576  sermouse - ok
22:26:57.0742 5576  [ D2193326F729B163125610DBF3E17D57 ] SessionEnv      C:\Windows\system32\sessenv.dll
22:26:57.0773 5576  SessionEnv - ok
22:26:57.0820 5576  [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk        C:\Windows\system32\DRIVERS\sffdisk.sys
22:26:57.0867 5576  sffdisk - ok
22:26:57.0882 5576  [ 8FD08A310645FE872EEEC6E08C6BF3EE ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
22:26:57.0976 5576  sffp_mmc - ok
22:26:58.0007 5576  [ 9F66A46C55D6F1CCABC79BB7AFCCC545 ] sffp_sd        C:\Windows\system32\DRIVERS\sffp_sd.sys
22:26:58.0054 5576  sffp_sd - ok
22:26:58.0085 5576  [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
22:26:58.0163 5576  sfloppy - ok
22:26:58.0194 5576  [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
22:26:58.0257 5576  SharedAccess - ok
22:26:58.0288 5576  [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
22:26:58.0350 5576  ShellHWDetection - ok
22:26:58.0366 5576  [ D2A595D6EEBEEAF4334F8E50EFBC9931 ] sisagp          C:\Windows\system32\drivers\sisagp.sys
22:26:58.0382 5576  sisagp - ok
22:26:58.0428 5576  [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
22:26:58.0444 5576  SiSRaid2 - ok
22:26:58.0460 5576  [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
22:26:58.0475 5576  SiSRaid4 - ok
22:26:58.0600 5576  [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc          C:\Windows\system32\SLsvc.exe
22:26:58.0912 5576  slsvc - ok
22:26:58.0959 5576  [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify      C:\Windows\system32\SLUINotify.dll
22:26:59.0006 5576  SLUINotify - ok
22:26:59.0052 5576  [ 7B75299A4D201D6A6533603D6914AB04 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
22:26:59.0099 5576  Smb - ok
22:26:59.0162 5576  [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
22:26:59.0177 5576  SNMPTRAP - ok
22:26:59.0208 5576  [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr          C:\Windows\system32\drivers\spldr.sys
22:26:59.0224 5576  spldr - ok
22:26:59.0271 5576  [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler        C:\Windows\System32\spoolsv.exe
22:26:59.0318 5576  Spooler - ok
22:26:59.0364 5576  [ 41987F9FC0E61ADF54F581E15029AD91 ] srv            C:\Windows\system32\DRIVERS\srv.sys
22:26:59.0411 5576  srv - ok
22:26:59.0442 5576  [ FF33AFF99564B1AA534F58868CBE41EF ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
22:26:59.0474 5576  srv2 - ok
22:26:59.0489 5576  [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
22:26:59.0536 5576  srvnet - ok
22:26:59.0567 5576  [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
22:26:59.0598 5576  SSDPSRV - ok
22:26:59.0645 5576  [ A36EE93698802CD899F98BFD553D8185 ] ssmdrv          C:\Windows\system32\DRIVERS\ssmdrv.sys
22:26:59.0661 5576  ssmdrv - ok
22:26:59.0708 5576  [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc        C:\Windows\system32\sstpsvc.dll
22:26:59.0739 5576  SstpSvc - ok
22:26:59.0786 5576  [ 07318149E102FD9197AB444C27774372 ] ssudmdm        C:\Windows\system32\DRIVERS\ssudmdm.sys
22:26:59.0801 5576  ssudmdm - ok
22:26:59.0864 5576  [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc          C:\Windows\System32\wiaservc.dll
22:26:59.0957 5576  stisvc - ok
22:26:59.0973 5576  [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
22:26:59.0988 5576  swenum - ok
22:27:00.0035 5576  [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv          C:\Windows\System32\swprv.dll
22:27:00.0098 5576  swprv - ok
22:27:00.0113 5576  [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx        C:\Windows\system32\drivers\symc8xx.sys
22:27:00.0129 5576  Symc8xx - ok
22:27:00.0160 5576  [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
22:27:00.0176 5576  Sym_hi - ok
22:27:00.0191 5576  [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
22:27:00.0207 5576  Sym_u3 - ok
22:27:00.0254 5576  [ 5EFCEDCF3DAF5C8D9E8B77A34A4EEC99 ] SynTP          C:\Windows\system32\DRIVERS\SynTP.sys
22:27:00.0285 5576  SynTP - ok
22:27:00.0332 5576  [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain        C:\Windows\system32\sysmain.dll
22:27:00.0441 5576  SysMain - ok
22:27:00.0472 5576  [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
22:27:00.0519 5576  TabletInputService - ok
22:27:00.0566 5576  [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv        C:\Windows\System32\tapisrv.dll
22:27:00.0612 5576  TapiSrv - ok
22:27:00.0659 5576  [ D7F411C5AF992BB44E86083A6AA7B045 ] tbhsd          C:\Windows\system32\drivers\tbhsd.sys
22:27:00.0659 5576  tbhsd - ok
22:27:00.0706 5576  [ CB05822CD9CC6C688168E113C603DBE7 ] TBS            C:\Windows\System32\tbssvc.dll
22:27:00.0753 5576  TBS - ok
22:27:00.0815 5576  [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
22:27:00.0893 5576  Tcpip - ok
22:27:00.0909 5576  [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
22:27:00.0987 5576  Tcpip6 - ok
22:27:01.0018 5576  [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
22:27:01.0065 5576  tcpipreg - ok
22:27:01.0112 5576  [ 1825BCEB47BF41C5A9F0E44DE82FC27A ] tdcmdpst        C:\Windows\system32\DRIVERS\tdcmdpst.sys
22:27:01.0158 5576  tdcmdpst - ok
22:27:01.0221 5576  [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
22:27:01.0268 5576  TDPIPE - ok
22:27:01.0299 5576  [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
22:27:01.0346 5576  TDTCP - ok
22:27:01.0392 5576  [ 76B06EB8A01FC8624D699E7045303E54 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
22:27:01.0439 5576  tdx - ok
22:27:01.0486 5576  [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
22:27:01.0502 5576  TermDD - ok
22:27:01.0517 5576  [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService    C:\Windows\System32\termsrv.dll
22:27:01.0595 5576  TermService - ok
22:27:01.0642 5576  [ C7230FBEE14437716701C15BE02C27B8 ] Themes          C:\Windows\system32\shsvcs.dll
22:27:01.0658 5576  Themes - ok
22:27:01.0673 5576  [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER    C:\Windows\system32\mmcss.dll
22:27:01.0720 5576  THREADORDER - ok
22:27:01.0767 5576  [ 28B7F973C36D157A7885B1AE42A4A2A9 ] tifm21          C:\Windows\system32\drivers\tifm21.sys
22:27:01.0814 5576  tifm21 - ok
22:27:01.0892 5576  [ 38E18DCE385FF2DED57423A279559DBC ] TNaviSrv        C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
22:27:01.0923 5576  TNaviSrv ( UnsignedFile.Multi.Generic ) - warning
22:27:01.0923 5576  TNaviSrv - detected UnsignedFile.Multi.Generic (1)
22:27:01.0970 5576  [ D540858E65BFA6FDED41AD2495ECE344 ] TODDSrv        C:\Windows\system32\TODDSrv.exe
22:27:02.0001 5576  TODDSrv ( UnsignedFile.Multi.Generic ) - warning
22:27:02.0001 5576  TODDSrv - detected UnsignedFile.Multi.Generic (1)
22:27:02.0063 5576  [ 6A54C28B53C6B50D333C8EE974C6B208 ] TosCoSrv        C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
22:27:02.0126 5576  TosCoSrv - ok
22:27:02.0141 5576  TOSHIBA Bluetooth Service - ok
22:27:02.0204 5576  [ 266DF087A8C24DA34FF40CF3DF86CCFB ] tosrfbd        C:\Windows\system32\DRIVERS\tosrfbd.sys
22:27:02.0266 5576  tosrfbd - ok
22:27:02.0266 5576  Tosrfcom - ok
22:27:02.0313 5576  [ 7C807BA9660E2995CC0217A14A24094C ] Tosrfhid        C:\Windows\system32\DRIVERS\Tosrfhid.sys
22:27:02.0344 5576  Tosrfhid - ok
22:27:02.0391 5576  [ CDDA265C7617A2745B48E0DE572012A6 ] Tosrfusb        C:\Windows\system32\DRIVERS\tosrfusb.sys
22:27:02.0438 5576  Tosrfusb - ok
22:27:02.0484 5576  [ 1EA5F27C29405BF49799FECA77186DA9 ] tos_sps32      C:\Windows\system32\DRIVERS\tos_sps32.sys
22:27:02.0547 5576  tos_sps32 - ok
22:27:02.0578 5576  TpChoice - ok
22:27:02.0625 5576  [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks          C:\Windows\System32\trkwks.dll
22:27:02.0687 5576  TrkWks - ok
22:27:02.0750 5576  [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
22:27:02.0796 5576  TrustedInstaller - ok
22:27:02.0828 5576  [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
22:27:02.0890 5576  tssecsrv - ok
22:27:02.0921 5576  [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp          C:\Windows\system32\DRIVERS\tunmp.sys
22:27:02.0952 5576  tunmp - ok
22:27:02.0984 5576  [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
22:27:03.0015 5576  tunnel - ok
22:27:03.0046 5576  [ 792A8B80F8188ABA4B2BE271583F3E46 ] TVALZ          C:\Windows\system32\DRIVERS\TVALZ_O.SYS
22:27:03.0062 5576  TVALZ - ok
22:27:03.0093 5576  [ C3ADE15414120033A36C0F293D4A4121 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
22:27:03.0108 5576  uagp35 - ok
22:27:03.0155 5576  [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
22:27:03.0186 5576  udfs - ok
22:27:03.0233 5576  [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
22:27:03.0280 5576  UI0Detect - ok
22:27:03.0311 5576  [ 0A1822D12CF103633893CAF9CAE4E69D ] UimBus          C:\Windows\system32\DRIVERS\UimBus.sys
22:27:03.0327 5576  UimBus - ok
22:27:03.0358 5576  [ 42F7398A76D279E0F63FC600920AB90C ] Uim_IM          C:\Windows\system32\Drivers\Uim_IM.sys
22:27:03.0405 5576  Uim_IM - ok
22:27:03.0420 5576  [ 48AD04132FCAC71E0EEC3DE5FB22D66E ] Uim_Vim        C:\Windows\system32\Drivers\Uim_Vim.sys
22:27:03.0452 5576  Uim_Vim - ok
22:27:03.0514 5576  [ 332D341D92B933600D41953B08360DFB ] UleadBurningHelper C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
22:27:03.0530 5576  UleadBurningHelper ( UnsignedFile.Multi.Generic ) - warning
22:27:03.0530 5576  UleadBurningHelper - detected UnsignedFile.Multi.Generic (1)
22:27:03.0561 5576  [ 75E6890EBFCE0841D3291B02E7A8BDB0 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
22:27:03.0576 5576  uliagpkx - ok
22:27:03.0592 5576  [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci        C:\Windows\system32\drivers\uliahci.sys
22:27:03.0608 5576  uliahci - ok
22:27:03.0639 5576  [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata          C:\Windows\system32\drivers\ulsata.sys
22:27:03.0654 5576  UlSata - ok
22:27:03.0670 5576  [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2        C:\Windows\system32\drivers\ulsata2.sys
22:27:03.0701 5576  ulsata2 - ok
22:27:03.0732 5576  [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
22:27:03.0764 5576  umbus - ok
22:27:03.0810 5576  [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost        C:\Windows\System32\upnphost.dll
22:27:03.0873 5576  upnphost - ok
22:27:03.0920 5576  [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
22:27:03.0951 5576  usbccgp - ok
22:27:03.0998 5576  [ E9476E6C486E76BC4898074768FB7131 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
22:27:04.0076 5576  usbcir - ok
22:27:04.0107 5576  [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
22:27:04.0154 5576  usbehci - ok
22:27:04.0169 5576  [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
22:27:04.0200 5576  usbhub - ok
22:27:04.0247 5576  [ CE697FEE0D479290D89BEC80DFE793B7 ] usbohci        C:\Windows\system32\DRIVERS\usbohci.sys
22:27:04.0294 5576  usbohci - ok
22:27:04.0325 5576  [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
22:27:04.0388 5576  usbprint - ok
22:27:04.0434 5576  [ A508C9BD8724980512136B039BBA65E9 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
22:27:04.0466 5576  usbscan - ok
22:27:04.0512 5576  [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:27:04.0544 5576  USBSTOR - ok
22:27:04.0575 5576  [ 325DBBACB8A36AF9988CCF40EAC228CC ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
22:27:04.0653 5576  usbuhci - ok
22:27:04.0700 5576  [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms          C:\Windows\System32\uxsms.dll
22:27:04.0731 5576  UxSms - ok
22:27:04.0793 5576  [ FCE98C43B5C5DB8E0DA8EA0E2B45E044 ] VClone          C:\Windows\system32\DRIVERS\VClone.sys
22:27:04.0840 5576  VClone - ok
22:27:04.0856 5576  VComm - ok
22:27:04.0871 5576  VcommMgr - ok
22:27:04.0918 5576  [ CD88D1B7776DC17A119049742EC07EB4 ] vds            C:\Windows\System32\vds.exe
22:27:04.0980 5576  vds - ok
22:27:05.0027 5576  [ 7D92BE0028ECDEDEC74617009084B5EF ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
22:27:05.0090 5576  vga - ok
22:27:05.0121 5576  [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave        C:\Windows\System32\drivers\vga.sys
22:27:05.0168 5576  VgaSave - ok
22:27:05.0199 5576  [ 045D9961E591CF0674A920B6BA3BA5CB ] viaagp          C:\Windows\system32\drivers\viaagp.sys
22:27:05.0214 5576  viaagp - ok
22:27:05.0246 5576  [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7          C:\Windows\system32\drivers\viac7.sys
22:27:05.0308 5576  ViaC7 - ok
22:27:05.0324 5576  [ FD2E3175FCADA350C7AB4521DCA187EC ] viaide          C:\Windows\system32\drivers\viaide.sys
22:27:05.0339 5576  viaide - ok
22:27:05.0355 5576  [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
22:27:05.0386 5576  volmgr - ok
22:27:05.0417 5576  [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
22:27:05.0448 5576  volmgrx - ok
22:27:05.0495 5576  [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
22:27:05.0511 5576  volsnap - ok
22:27:05.0558 5576  [ D984439746D42B30FC65A4C3546C6829 ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
22:27:05.0573 5576  vsmraid - ok
22:27:05.0636 5576  [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS            C:\Windows\system32\vssvc.exe
22:27:05.0792 5576  VSS - ok
22:27:05.0838 5576  [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time        C:\Windows\system32\w32time.dll
22:27:05.0901 5576  W32Time - ok
22:27:05.0932 5576  [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
22:27:06.0010 5576  WacomPen - ok
22:27:06.0041 5576  [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
22:27:06.0072 5576  Wanarp - ok
22:27:06.0072 5576  [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
22:27:06.0104 5576  Wanarpv6 - ok
22:27:06.0135 5576  [ A3CD60FD826381B49F03832590E069AF ] wcncsvc        C:\Windows\System32\wcncsvc.dll
22:27:06.0197 5576  wcncsvc - ok
22:27:06.0228 5576  [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
22:27:06.0275 5576  WcsPlugInService - ok
22:27:06.0322 5576  [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd              C:\Windows\system32\drivers\wd.sys
22:27:06.0338 5576  Wd - ok
22:27:06.0384 5576  [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
22:27:06.0416 5576  Wdf01000 - ok
22:27:06.0478 5576  [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost  C:\Windows\system32\wdi.dll
22:27:06.0525 5576  WdiServiceHost - ok
22:27:06.0525 5576  [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost  C:\Windows\system32\wdi.dll
22:27:06.0572 5576  WdiSystemHost - ok
22:27:06.0603 5576  [ 04C37D8107320312FBAE09926103D5E2 ] WebClient      C:\Windows\System32\webclnt.dll
22:27:06.0634 5576  WebClient - ok
22:27:06.0665 5576  [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc          C:\Windows\system32\wecsvc.dll
22:27:06.0712 5576  Wecsvc - ok
22:27:06.0743 5576  [ 670FF720071ED741206D69BD995EA453 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
22:27:06.0790 5576  wercplsupport - ok
22:27:06.0837 5576  [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc          C:\Windows\System32\WerSvc.dll
22:27:06.0884 5576  WerSvc - ok
22:27:06.0930 5576  [ 4575AA12561C5648483403541D0D7F2B ] WinDefend      C:\Program Files\Windows Defender\mpsvc.dll
22:27:06.0962 5576  WinDefend - ok
22:27:06.0962 5576  WinHttpAutoProxySvc - ok
22:27:07.0008 5576  [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
22:27:07.0040 5576  Winmgmt - ok
22:27:07.0102 5576  [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM          C:\Windows\system32\WsmSvc.dll
22:27:07.0258 5576  WinRM - ok
22:27:07.0320 5576  [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc        C:\Windows\System32\wlansvc.dll
22:27:07.0430 5576  Wlansvc - ok
22:27:07.0461 5576  [ 701A9F884A294327E9141D73746EE279 ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
22:27:07.0539 5576  WmiAcpi - ok
22:27:07.0586 5576  [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
22:27:07.0617 5576  wmiApSrv - ok
22:27:07.0710 5576  [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc  C:\Program Files\Windows Media Player\wmpnetwk.exe
22:27:07.0835 5576  WMPNetworkSvc - ok
22:27:07.0882 5576  [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
22:27:07.0960 5576  WPCSvc - ok
22:27:07.0991 5576  [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
22:27:08.0022 5576  WPDBusEnum - ok
22:27:08.0069 5576  [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
22:27:08.0100 5576  WpdUsb - ok
22:27:08.0241 5576  [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
22:27:08.0350 5576  WPFFontCache_v0400 - ok
22:27:08.0397 5576  [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
22:27:08.0428 5576  ws2ifsl - ok
22:27:08.0459 5576  [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc          C:\Windows\System32\wscsvc.dll
22:27:08.0475 5576  wscsvc - ok
22:27:08.0490 5576  WSearch - ok
22:27:08.0568 5576  [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv        C:\Windows\system32\wuaueng.dll
22:27:08.0724 5576  wuauserv - ok
22:27:08.0771 5576  [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
22:27:08.0802 5576  WUDFRd - ok
22:27:08.0834 5576  [ 575A4190D989F64732119E4114045A4F ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
22:27:08.0865 5576  wudfsvc - ok
22:27:08.0896 5576  ================ Scan global ===============================
22:27:08.0912 5576  [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
22:27:08.0958 5576  [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
22:27:08.0974 5576  [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
22:27:09.0021 5576  [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
22:27:09.0021 5576  [Global] - ok
22:27:09.0021 5576  ================ Scan MBR ==================================
22:27:09.0036 5576  [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
22:27:09.0380 5576  \Device\Harddisk0\DR0 - ok
22:27:09.0380 5576  ================ Scan VBR ==================================
22:27:09.0395 5576  [ BDB5C099E84C3DC435440315BBD1E215 ] \Device\Harddisk0\DR0\Partition1
22:27:09.0395 5576  \Device\Harddisk0\DR0\Partition1 - ok
22:27:09.0411 5576  [ 1EB40DBB2D0319FA613994585909E183 ] \Device\Harddisk0\DR0\Partition2
22:27:09.0411 5576  \Device\Harddisk0\DR0\Partition2 - ok
22:27:09.0426 5576  ============================================================
22:27:09.0426 5576  Scan finished
22:27:09.0426 5576  ============================================================
22:27:09.0442 2408  Detected object count: 7
22:27:09.0442 2408  Actual detected object count: 7
22:27:30.0206 2408  CFSvcs ( UnsignedFile.Multi.Generic ) - skipped by user
22:27:30.0206 2408  CFSvcs ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:27:30.0206 2408  FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - skipped by user
22:27:30.0206 2408  FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:27:30.0206 2408  FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - skipped by user
22:27:30.0206 2408  FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:27:30.0221 2408  IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
22:27:30.0221 2408  IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:27:30.0221 2408  TNaviSrv ( UnsignedFile.Multi.Generic ) - skipped by user
22:27:30.0221 2408  TNaviSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:27:30.0237 2408  TODDSrv ( UnsignedFile.Multi.Generic ) - skipped by user
22:27:30.0237 2408  TODDSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:27:30.0237 2408  UleadBurningHelper ( UnsignedFile.Multi.Generic ) - skipped by user
22:27:30.0237 2408  UleadBurningHelper ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 19.09.2012 09:31

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

traudel769 19.09.2012 17:07

Wiederherstellungskonsole wurde nicht vorgeschlagen
Ich hoffe es ist richtig, dass ich das wieder i Code-tags poste.

VG


[code] Combofix Logfile:
Code:

ComboFix 12-09-18.07 - Susan 19.09.2012  17:34:45.1.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.1917.947 [GMT 2:00]
ausgeführt von:: c:\users\Susan\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Susan\AppData\Roaming\Microsoft\Windows\Recent\mxfilerelatedcache.mxc2
c:\users\Susan\Favorites\mxfilerelatedcache.mxc2
c:\windows\security\Database\tmp.edb
c:\windows\system32\spool\prtprocs\w32x86\ppbiPr.dll
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-08-19 bis 2012-09-19  ))))))))))))))))))))))))))))))
.
.
2012-09-19 15:45 . 2012-09-19 15:45        --------        dc----w-        c:\users\Saskia\AppData\Local\temp
2012-09-19 15:45 . 2012-09-19 15:45        --------        dc----w-        c:\users\Default\AppData\Local\temp
2012-09-19 15:25 . 2012-08-23 07:15        7022536        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{5F5E50F0-B904-4EB9-B4C7-BB7FB26408A2}\mpengine.dll
2012-09-17 15:15 . 2012-09-17 15:15        --------        dc----w-        C:\_OTL
2012-09-13 04:25 . 2012-09-13 04:25        --------        dc----w-        c:\program files\ESET
2012-09-12 15:30 . 2012-09-12 15:30        --------        dc----w-        c:\users\Susan\AppData\Roaming\Malwarebytes
2012-09-12 15:30 . 2012-09-12 15:30        --------        dc----w-        c:\programdata\Malwarebytes
2012-09-12 15:29 . 2012-09-12 15:36        --------        dc----w-        c:\program files\Malwarebytes' Anti-Malware
2012-09-12 15:29 . 2012-09-07 15:04        22856        -c--a-w-        c:\windows\system32\drivers\mbam.sys
2012-09-09 07:47 . 2012-09-09 07:47        --------        dc----w-        c:\users\Susan\AppData\Local\Lupinho.Net
2012-09-08 19:13 . 2012-09-08 19:13        --------        dc----w-        c:\users\Saskia\AppData\Roaming\Canneverbe Limited
2012-09-08 18:39 . 2012-09-08 18:39        --------        dc----w-        c:\programdata\backup
2012-09-08 18:39 . 2012-09-08 18:39        --------        dc----w-        c:\programdata\explauncher
2012-09-08 18:39 . 2012-09-08 18:39        --------        dc----w-        c:\programdata\launcher
2012-09-01 16:02 . 2012-09-01 16:02        --------        dc----w-        c:\users\Susan\AppData\Roaming\DVDVideoSoftIEHelpers
2012-09-01 16:01 . 2012-08-24 13:58        405152        -c--a-w-        c:\windows\system32\Newtonsoft.Json.Net20.dll
2012-09-01 16:01 . 2012-09-01 16:01        --------        dc----w-        c:\program files\Common Files\DVDVideoSoft
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-15 16:13 . 2012-03-30 18:05        426184        -c--a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-08-15 16:13 . 2011-05-23 16:51        70344        -c--a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-19 21:21 . 2012-07-19 21:21        39016        -c--a-w-        c:\windows\system32\drivers\tbhsd.sys
2012-07-07 14:37 . 2012-07-07 14:37        1207568        -c--a-w-        c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-07-04 14:02 . 2012-08-15 16:24        2047488        -c--a-w-        c:\windows\system32\win32k.sys
2012-06-27 15:59 . 2012-08-15 05:07        834048        -c--a-w-        c:\windows\system32\wininet.dll
2012-06-27 14:15 . 2012-08-15 05:07        389632        -c--a-w-        c:\windows\system32\html.iec
2012-06-27 13:49 . 2012-08-15 05:07        1383424        -c--a-w-        c:\windows\system32\mshtml.tlb
2009-12-10 08:38 . 2009-12-15 18:25        1924200        -c--a-w-        c:\program files\install_flash_player10.0.42.34.exe
2012-07-19 17:31 . 2011-06-05 15:04        136672        -c--a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-25 4444160]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"NDSTray.exe"="NDSTray.exe" [BU]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-04-02 577536]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2007-05-04 571024]
"FreePDF Assistant"="c:\program files\FreePDF_XP\fpassist.exe" [2007-06-26 312320]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-11-24 622592]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-07-19 65536]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"VirtualCloneDrive"="e:\programme\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HWSetup]
\HWSetup.exe hwSetUP [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2006-09-11 14:21        180224        -c--a-w-        c:\program files\Apoint2K\Apoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Garmin Lifetime Updater]
2012-06-04 07:31        1466760        -c--a-w-        c:\program files\Garmin\Lifetime Updater\GarminLifetime.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 16:13]
.
2012-09-19 c:\windows\Tasks\User_Feed_Synchronization-{BD71E7E2-ECDB-4F93-B0DC-4A2B232F98A8}.job
- c:\windows\system32\msfeedssync.exe [2008-06-26 07:33]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.takinus-blog.blogspot.com/
uDefault_Search_URL =
uInternet Settings,ProxyOverride = *.local
uSearchAssistant =
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Free YouTube to MP3 Converter - c:\users\Susan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\wpclsp.dll
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\efjwbygu.default\
FF - prefs.js: browser.startup.homepage - hxxp://takinus-blog.blogspot.com/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
MSConfigStartUp-hweyvybrdvmqiuw - c:\programdata\hweyvybr.exe
AddRemove-dm-Fotowelt - g:\programme\dm-Fotowelt\uninstall.exe
AddRemove-Uninstall_is1 - c:\program files\Common Files\DVDVideoSoft\unins000.exe
AddRemove-{D0795B21-0CDA-4a92-AB9E-6E92D8111E44} - e:\programme\Samsung\USB Drivers\Uninstall.exe
AddRemove-01_Simmental - e:\programme\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - e:\programme\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - e:\programme\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - e:\programme\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - e:\programme\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - e:\programme\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - e:\programme\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - e:\programme\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - e:\programme\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - e:\programme\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - e:\programme\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - e:\programme\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - e:\programme\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - e:\programme\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - e:\programme\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-22_WiBro_WiMAX - e:\programme\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
AddRemove-24_flashusbdriver - e:\programme\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - e:\programme\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-09-19 17:46
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2012-09-19  17:51:29
ComboFix-quarantined-files.txt  2012-09-19 15:51
.
Vor Suchlauf: 10 Verzeichnis(se), 25.537.212.416 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 24.887.525.376 Bytes frei
.
- - End Of File - - 7E1E9E6A588F80A086CDC626EC22CB1C

--- --- ---

cosinus 19.09.2012 21:29

Die Wiederherstellungskonsole gibt es nur bei WinXP

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

traudel769 20.09.2012 19:26

Alle 3 Scans sind problemlos gelaufen, soweit ich das beurteilen kann. Es gab jedenfalls keine Abbrüche.

Hier die logs

VG

[code] GMER Logfile:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-09-20 19:34:55
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS541616J9SA00 rev.SB4OC7DP
Running: gpkdnwpv.exe; Driver: C:\Users\Susan\AppData\Local\Temp\fwddapow.sys


---- System - GMER 1.0.15 ----

SSDT            8A9904AE                                  ZwCreateSection
SSDT            8A9904B8                                  ZwRequestWaitReplyPort
SSDT            8A9904B3                                  ZwSetContextThread
SSDT            8A9904BD                                  ZwSetSecurityObject
SSDT            8A9904C2                                  ZwSystemDebugControl
SSDT            8A99044F                                  ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text          ntkrnlpa.exe!KeSetEvent + 215              82CC98D8 4 Bytes  [AE, 04, 99, 8A]
.text          ntkrnlpa.exe!KeSetEvent + 539              82CC9BFC 4 Bytes  [B8, 04, 99, 8A]
.text          ntkrnlpa.exe!KeSetEvent + 56D              82CC9C30 4 Bytes  [B3, 04, 99, 8A]
.text          ntkrnlpa.exe!KeSetEvent + 5D1              82CC9C94 4 Bytes  [BD, 04, 99, 8A]
.text          ntkrnlpa.exe!KeSetEvent + 619              82CC9CDC 4 Bytes  [C2, 04, 99, 8A]
.text          ...                                       
.text          C:\Windows\system32\DRIVERS\tos_sps32.sys  section is writeable [0x88955000, 0x4036D, 0xE8000020]
.dsrt          C:\Windows\system32\DRIVERS\tos_sps32.sys  unknown last section [0x8899E000, 0x510, 0x40000040]

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0    Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1    Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

--- --- ---



OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 19:51:44 on 20.09.2012

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 14.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"TOSCDSPD.cpl" - ? - C:\Windows\system32\TOSCDSPD.cpl  (File found, but it contains no detailed information)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"Bluetooth Audio Service" (BlueletAudio) - ? - C:\Windows\System32\DRIVERS\blueletaudio.sys  (File not found)
"Bluetooth HID Bus Service" (BtHidBus) - ? - C:\Windows\System32\Drivers\BtHidBus.sys  (File not found)
"Bluetooth HID Enumerator" (BTHidEnum) - ? - C:\Windows\System32\Drivers\vbtenum.sys  (File not found)
"Bluetooth HID Manager Service" (BTHidMgr) - ? - C:\Windows\System32\Drivers\BTHidMgr.sys  (File not found)
"Bluetooth PAN Bus Service" (btnetBUs) - ? - C:\Windows\System32\Drivers\btnetBus.sys  (File signed by Microsoft | File found, but it contains no detailed information)
"Bluetooth PAN Network Adapter" (BT) - ? - C:\Windows\System32\DRIVERS\btnetdrv.sys  (File not found)
"Bluetooth SCO Audio Service" (BlueletSCOAudio) - ? - C:\Windows\System32\DRIVERS\BlueletSCOAudio.sys  (File not found)
"Bluetooth Serial Port Bus Service" (BTCOMBUS) - ? - C:\Windows\System32\Drivers\btcombus.sys  (File not found)
"Bluetooth Serial port driver" (BTCOM) - ? - C:\Windows\System32\DRIVERS\btcomport.sys  (File not found)
"Bluetooth USB For Bluetooth Service" (Btcsrusb) - ? - C:\Windows\System32\Drivers\btcusb.sys  (File not found)
"Bluetooth VComm Manager Service" (VcommMgr) - ? - C:\Windows\System32\Drivers\VcommMgr.sys  (File not found)
"catchme" (catchme) - ? - C:\Users\Susan\AppData\Local\Temp\catchme.sys  (File not found)
"ElbyCDIO Driver" (ElbyCDIO) - "Elaborate Bytes AG" - C:\Windows\System32\Drivers\ElbyCDIO.sys
"Huawei DataCard USB Modem and USB Serial" (hwdatacard) - ? - C:\Windows\System32\DRIVERS\ewusbmdm.sys  (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"IVT Bluetooth Bus Service" (IvtBtBUs) - ? - C:\Windows\System32\Drivers\IvtBtBus.sys  (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"PCCS Mode Change Filter Driver" (pccsmcfd) - ? - C:\Windows\System32\DRIVERS\pccsmcfd.sys  (File not found)
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"Tosrfcom" (Tosrfcom) - ? - C:\Windows\system32\drivers\Tosrfcom.sys  (File not found)
"Touch Pad Detection Filter driver" (TpChoice) - ? - C:\Windows\System32\DRIVERS\TpChoice.sys  (File not found)
"Virtual Serial port driver" (VComm) - ? - C:\Windows\System32\DRIVERS\VComm.sys  (File not found)

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\Windows\system32\Skype4COM.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - ? - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{B7056B8E-4F99-44f8-8CBD-282390FE5428} "VirtualCloneDrive Shell Extension" - "Elaborate Bytes AG" - E:\Programme\VirtualCloneDrive\ElbyVCDShell.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Program Files\WinRAR\rarext.dll  (File found, but it contains no detailed information)

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} "Java Plug-in 1.6.0_25" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 10.5.1" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} "{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}" - ? -  (File not found | COM-object registry key not found) / hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"Amazon.de" - ? - hxxp://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home  (HTTP value)
"eBay - Der weltweite Online Marktplatz" - ? - hxxp://rover.ebay.com/rover/1/707-44556-9400-3/4  (HTTP value)
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"00TCrdMain" - "TOSHIBA Corporation" - %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"BrMfcWnd" - "Brother Industries, Ltd." - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
"ControlCenter3" - "Brother Industries, Ltd." - C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
"FreePDF Assistant" - "shbox.de" - C:\Program Files\FreePDF_XP\fpassist.exe
"HSON" - "TOSHIBA Corporation" - %ProgramFiles%\TOSHIBA\TBS\HSON.exe
"IndexSearch" - "ScanSoft, Inc." - C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
"KeNotify" - ? - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
"NDSTray.exe" - ? - NDSTray.exe  (File not found)
"PaperPort PTD" - "ScanSoft, Inc." - C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"SVPWUTIL" - "TOSHIBA" - C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
"topi" - "TOSHIBA" - C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
"Toshiba Registration" - "Toshiba" - C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
"TPwrMain" - "TOSHIBA Corporation" - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
"VirtualCloneDrive" - "Elaborate Bytes AG" - "E:\Programme\VirtualCloneDrive\VCDDaemon.exe" /s

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Redirected Port" - ? - C:\Windows\system32\redmonnt.dll  (File found, but it contains no detailed information)
"Toshiba Bluetooth Monitor" - "TOSHIBA CORPORATION." - C:\Windows\system32\tbtmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"Bonjour-Dienst" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"ConfigFree Service" (CFSvcs) - "TOSHIBA CORPORATION" - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
"Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Macrovision Europe Ltd." - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
"MBAMScheduler" (MBAMScheduler) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"TOSHIBA Bluetooth Service" (TOSHIBA Bluetooth Service) - ? - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe  (File not found)
"TOSHIBA Navi Support Service" (TNaviSrv) - "TOSHIBA Corporation" - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
"TOSHIBA Optical Disc Drive Service" (TODDSrv) - "TOSHIBA Corporation" - C:\Windows\system32\TODDSrv.exe
"TOSHIBA Power Saver" (TosCoSrv) - "TOSHIBA Corporation" - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
"Ulead Burning Helper" (UleadBurningHelper) - "Ulead Systems, Inc." - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---



Code:


aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-20 19:52:33
-----------------------------
19:52:33.293    OS Version: Windows 6.0.6002 Service Pack 2
19:52:33.293    Number of processors: 2 586 0x4802
19:52:33.293    ComputerName: LAPTOP  UserName: Susan
19:52:34.557    Initialize success
19:56:36.755    AVAST engine defs: 12092000
19:57:15.458    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
19:57:15.458    Disk 0 Vendor: Hitachi_HTS541616J9SA00 SB4OC7DP Size: 152627MB BusType: 3
19:57:15.489    Disk 0 MBR read successfully
19:57:15.489    Disk 0 MBR scan
19:57:15.505    Disk 0 Windows VISTA default MBR code
19:57:15.521    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        1500 MB offset 2048
19:57:15.552    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        76313 MB offset 3074048
19:57:15.583    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        74813 MB offset 159363072
19:57:15.614    Disk 0 scanning sectors +312580096
19:57:15.677    Disk 0 scanning C:\Windows\system32\drivers
19:57:30.372    Service scanning
19:58:10.027    Modules scanning
19:58:20.042    Disk 0 trace - called modules:
19:58:20.058    ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
19:58:20.073    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85d6e120]
19:58:20.073    3 CLASSPNP.SYS[887168b3] -> nt!IofCallDriver -> [0x85b55918]
19:58:20.089    5 acpi.sys[806176bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85b00b98]
19:58:20.838    AVAST engine scan C:\Windows
19:58:25.705    AVAST engine scan C:\Windows\system32
20:03:37.065    AVAST engine scan C:\Windows\system32\drivers
20:04:07.267    AVAST engine scan C:\Users\Susan
20:11:47.327    AVAST engine scan C:\ProgramData
20:14:41.813    Scan finished successfully
20:20:15.793    Disk 0 MBR has been saved successfully to "C:\Users\Susan\Desktop\MBR.dat"
20:20:15.793    The log file has been saved successfully to "C:\Users\Susan\Desktop\aswMBR.txt"


cosinus 21.09.2012 11:43

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

traudel769 21.09.2012 21:40

Code:


Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.21.07

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 7.0.6002.18005
Susan :: LAPTOP [Administrator]

Schutz: Deaktiviert

21.09.2012 17:28:27
mbam-log-2012-09-21 (17-28-27).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 384005
Laufzeit: 2 Stunde(n), 12 Minute(n), 41 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:


SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/21/2012 at 10:16 PM

Application Version : 5.5.1016

Core Rules Database Version : 9268
Trace Rules Database Version: 7080

Scan type      : Complete Scan
Total Scan Time : 02:15:55

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Administrator

Memory items scanned      : 669
Memory threats detected  : 0
Registry items scanned    : 34156
Registry threats detected : 0
File items scanned        : 164020
File threats detected    : 506

Adware.Tracking Cookie
        C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Cookies\I9R3O101.txt [ /adfarm1.adition.com ]
        C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Cookies\WFQ3X4WR.txt [ /imrworldwide.com ]
        C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Cookies\VFLV7P1Q.txt [ /ad.zanox.com ]
        C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Cookies\A0KCBUSN.txt [ /eas.apm.emediate.eu ]
        C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Cookies\D1574GJR.txt [ /amazon-adsystem.com ]
        C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Cookies\4NQDPEDM.txt [ /adform.net ]
        C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Cookies\VX7E5HY7.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Cookies\PR4GRXFI.txt [ /track.adform.net ]
        C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Cookies\CO857K92.txt [ /ad1.adfarm1.adition.com ]
        C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Cookies\1ROL20X9.txt [ /zanox.com ]
        C:\USERS\SASKIA\AppData\Roaming\Microsoft\Windows\Cookies\CQGDQTNC.txt [ Cookie:saskia@fastclick.net/ ]
        C:\USERS\SASKIA\AppData\Roaming\Microsoft\Windows\Cookies\AZS9TDXY.txt [ Cookie:saskia@apmebf.com/ ]
        C:\USERS\SASKIA\AppData\Roaming\Microsoft\Windows\Cookies\AE3H894V.txt [ Cookie:saskia@doubleclick.net/ ]
        C:\USERS\SASKIA\AppData\Roaming\Microsoft\Windows\Cookies\Low\O1KHEB1D.txt [ Cookie:saskia@atdmt.com/ ]
        C:\USERS\SASKIA\AppData\Roaming\Microsoft\Windows\Cookies\Low\O0W28TJG.txt [ Cookie:saskia@apmebf.com/ ]
        C:\USERS\SASKIA\AppData\Roaming\Microsoft\Windows\Cookies\Low\XHU956G3.txt [ Cookie:saskia@fl01.ct2.comclick.com/ ]
        C:\USERS\SASKIA\Cookies\CQGDQTNC.txt [ Cookie:saskia@fastclick.net/ ]
        C:\USERS\SASKIA\Cookies\AZS9TDXY.txt [ Cookie:saskia@apmebf.com/ ]
        C:\USERS\SASKIA\Cookies\AE3H894V.txt [ Cookie:saskia@doubleclick.net/ ]
        C:\USERS\SUSAN\AppData\Roaming\Microsoft\Windows\Cookies\susan@www.google[7].txt [ Cookie:susan@www.google.com/accounts ]
        C:\USERS\SUSAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\susan@www.google[1].txt [ Cookie:susan@www.google.com/accounts ]
        C:\USERS\SUSAN\Cookies\I9R3O101.txt [ Cookie:susan@adfarm1.adition.com/ ]
        C:\USERS\SUSAN\Cookies\WFQ3X4WR.txt [ Cookie:susan@imrworldwide.com/cgi-bin ]
        C:\USERS\SUSAN\Cookies\VFLV7P1Q.txt [ Cookie:susan@ad.zanox.com/ ]
        C:\USERS\SUSAN\Cookies\A0KCBUSN.txt [ Cookie:susan@eas.apm.emediate.eu/ ]
        C:\USERS\SUSAN\Cookies\D1574GJR.txt [ Cookie:susan@amazon-adsystem.com/ ]
        C:\USERS\SUSAN\Cookies\4NQDPEDM.txt [ Cookie:susan@adform.net/ ]
        C:\USERS\SUSAN\Cookies\VX7E5HY7.txt [ Cookie:susan@ad2.adfarm1.adition.com/ ]
        C:\USERS\SUSAN\Cookies\PR4GRXFI.txt [ Cookie:susan@track.adform.net/ ]
        C:\USERS\SUSAN\Cookies\CO857K92.txt [ Cookie:susan@ad1.adfarm1.adition.com/ ]
        C:\USERS\SUSAN\Cookies\1ROL20X9.txt [ Cookie:susan@zanox.com/ ]
        C:\USERS\SUSAN\Cookies\susan@www.google[7].txt [ Cookie:susan@www.google.com/accounts ]
        .getclicky.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .static.getclicky.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        in.getclicky.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .stats4free.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .stats4free.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .stats4free.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .stats4free.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .countomat.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        tracking.mlsat02.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .tracker.vinsight.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .microsoftsto.112.2o7.net [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\SASKIA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4SBDS9LL.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mediafire.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mediafire.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        tracking.sim-technik.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tto2.traffictrack.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .countomat.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        auslieferung.commindo-media-ressourcen.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .aim4media.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        search.freefind.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mmotraffic.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .bizrate.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .secmedia.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mediafire.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .cewecolor.112.2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .pornoeye.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .pornoeye.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adxpansion.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        s09.flagcounter.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tracking.3gnet.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        keyword-advertising.web.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .cracked.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .dmtracker.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .cracked.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .cracked.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .cracked.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .cracked.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .cracked.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        e2.emediate.se [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .cunda.122.2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .countrymusic.about.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .apodiscounter.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .apodiscounter.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .apodiscounter.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .apodiscounter.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .apodiscounter.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        adserver.createoceans.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .microsoftsto.112.2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .blogads.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        adserver.adreactor.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mmotraffic.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .c.gigcount.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .ar.atwola.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        teufel-media.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .linksynergy.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .linksynergy.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .linksynergy.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .prepaid-discounter.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .prepaid-discounter.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        in.getclicky.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        tracker.roitesting.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        adserv.quality-channel.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        adserv.quality-channel.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ads.falkemedia.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        track.zalando.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        account.samsung.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.mediaconverter.org [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mediaconverter.org [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mediaconverter.org [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        click-the-shutter.xobor.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        click-the-shutter.xobor.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .deutschepostag.112.2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        banner.slashcam.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        tracking.tchibo.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mywebsearch.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .c1.atdmt.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .comvelgmbh.112.2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .flagcounter.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .serialcodes.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .serialcodes.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .serialcodes.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .harrenmedianetwork.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        insight.torbit.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .googleads.g.doubleclick.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.discounto.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .discounto.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .discounto.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .discounto.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.discounto.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        targeting.revenuemax.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        tracking.dc-storm.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        tracking.dc-storm.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        tomtailor.dyntracker.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .vodafonegroup.122.2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .ads20.wwe-media.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .myhammer.122.2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mediafire.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mediafire.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .mediafire.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.mediafire.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.mediafire.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.mediafire.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .loyaltypartner.122.2o7.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        auslieferung.commindo-media-ressourcen.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .myroitracking.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tracker.vinsight.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .tradetracker.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\SUSAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EFJWBYGU.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-Malintent
        C:\PROGRAM FILES\WINRAR\DEFAULT.SFX

Leider hab ich nicht gefunden, wie ich nach dem Scan mit SUPERAntiSpyware fortfahren soll. So habe ich nicht auf Remove geklickt, sondern auf abbrechen.
War das richtig so?
Ich werde mal das Programm noch nicht deinstallieren

cosinus 22.09.2012 16:04

Sieht ok aus, da wurden nur Cookies gefunden, der angebliche Fund bei WinRAR ist ein Fehalarm.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

traudel769 22.09.2012 17:26

Jedes Mal einloggen müssen ist nicht so schön. Ich werde mir dann mal CookieCuller anschauen. Danke für den Tipp. Einen 2. Browser fürs Surfen zulegen ist auch eine Überlegung wert. FF hat mich noch nie gefragt, wob ich Cookies speichern will. Ich find auch grad gar nichts, wo ich das einstellen kann.
Für Blockung Unwanted Parasites with a Hosts File ist mein Englisch leider zu schlecht? ;-(


Ansonsten gibt es keine Funde. Probleme? Wie gesagt, ich hab jetzt nichts mit dem Rechner gemacht, außer deine Anleitung abzuarbeiten. Aber dabei ist mir nichts aufgefallen.

Heißt das etwa, dass ich jetzt wieder clean bin und der Trojanaer erfolgreich bekämpft wurde? *freu*
Danke!!!!!!! Danke für die super Hilfe.
Ich kann meine Begeisterung kaum in Worte fassen.

Was mach ich jetzt mit den Funden in der Quarantäne?

cosinus 22.09.2012 20:19

Was habt ihr alle immer nur mit der Quarantäne? :wtf:
Überleg doch mal was eine Quarantäne ist. Ob da die schädliche Datei drinbleibt oder nicht, das hat keine Auswirkungen. Schädlinge in der Quarantäne können nichts mehr anrichten, sie sind dort isoliert. Du solltest grundsätzlich mit der Quarantäne arbeiten, denn falls der Virenscanner durch einen Fehlalarm was wichtiges löscht, kannst Du notfalls noch über die Quarantäne an die Datei ran.


Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

traudel769 22.09.2012 20:35

Oh durch! :Boogie:
Danke :applaus: :applaus::bussi::dankeschoen:

Na, wenn der Kram nicht aus der Quarantäne ausbrechen kann, ist ja gut.
Du siehst, du hattest es hier mit einem Laien zu tun :pfeiff:
Umso größerer Dank, dass du das mit mir durchgestanden hast.

Deine Hinweise werde ich gern befolgen.

Schönen Abend noch.
Ich bin so happy
:Boogie::Boogie::Boogie:


Alle Zeitangaben in WEZ +1. Es ist jetzt 14:16 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131