Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Computer Verschlüsselungstrojaner (https://www.trojaner-board.de/117000-computer-verschluesselungstrojaner.html)

magicfortune 10.06.2012 16:23

Computer Verschlüsselungstrojaner
 
Sehr geehrtes Trojaner-Board Team,

ich habe mir vor 2 Tagen versehentlich, den oben genannten Virus eingefangen.
Über Google habe ich mich dann mal schlau gemacht, wegen der paysafecard und ukash Bezahlung. Dabei bin ich durch Zufall auf die Internetseite von paysafecard.com, wo auch auf die Gema oder BKA Trojaner hingewiesen worden.
Darauf hin habe ich nach dem besagten Trojaner gesucht und bin auf eure Seite gelandet.

Als 1. habe ich den DE - Cleaner probiert, aber der hat nicht angeschlagen.
Nach gut 1.15 h Durchlaufzeit hat er nichts gefunden.

Schritt 2 war eben die Kaspersky Rettungsdisc 10, gute 3,5h warten für nichts.
Habe alle Systeme durchchecken lassen.

Also habe ich mich für Schritt 3 entschieden. Habe den Pc im gesicherten Modus gestarten und ihn dann eine Systemwiederherstellung machen lassen.
Bin ca. 1 Woche zurück gegangen.
Anschließend den Pc normal gestartet und siehe da, keine Meldung mehr bzgl. des Trojaners und der Geldaufforderung.

Dies bzgl. habe ich meinen Virenscanner sofort upgegradet und den Malwarbytes runtergeladen.

Malwarebytes hat jetzt 24 infizierte Objekte gefunden. Was mache ich jetzt am besten damit.

Ich hoffe ich habe euch jetzt nicht Erschlagen mit der Infoflut, sollte noch etwas fehlen bitte schreiben.

MfG

magicfortune :)

Nach diversen stöbern habe ich gefunden wie die Maleware funktioniert, hoffe das mit dem einfügen ist so richtig.


Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.10.03

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
Désirée :: DÉSIRÉE-PC [Administrator]

Schutz: Aktiviert

10.06.2012 16:57:36
mbam-log-2012-06-10 (16-57-36).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 219478
Laufzeit: 9 Minute(n), 39 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 5
HKCR\CLSID\{04DFB628-514B-4E68-9076-DC1024F58A96} (Trojan.FakeAlert) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{04DFB628-514B-4E68-9076-DC1024F58A96} (Trojan.FakeAlert) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{04DFB628-514B-4E68-9076-DC1024F58A96} (Trojan.FakeAlert) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PersSecurity (Rogue.PersonalSecurity) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\System\CurrentControlSet\Servises (Malware.Trace) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|PersSecurity (Rogue.PersonalSecurity) -> Daten: C:\Program Files\PersSecurity\psecurity.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 3
C:\Program Files\Common Files\PersSecurityUninstall (Rogue.PersonalSecurity) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\PersSecurity (Rogue.PersonalSecurity) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Microsoft\Windows\Start Menu\PersSecurity (Rogue.PersonalSecurity) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateien: 15
C:\Users\Désirée\AppData\Roaming\AD ON Multimedia\eBay Shortcuts\eBayShortcuts.exe (Adware.ADON) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Désirée\AppData\Local\Temp\jflxphyrdn.pre (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Désirée\AppData\Local\Temp\pzyvjxfnql.pre (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Désirée\AppData\Local\Temp\lsyvowzdna.pre (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Désirée\AppData\Local\Temp\epbhyylaqn.pre (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Désirée\AppData\Local\Temp\rfgimyrjpl.pre (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Désirée\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PersSecurity.lnk (Rogue.PersonalSecurity) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\Common Files\PersSecurityUninstall\Uninstall.lnk (Rogue.PersonalSecurity) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Microsoft\Windows\Start Menu\PersSecurity\Computer Scan.lnk (Rogue.PersonalSecurity) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Microsoft\Windows\Start Menu\PersSecurity\Help.lnk (Rogue.PersonalSecurity) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Microsoft\Windows\Start Menu\PersSecurity\Personal Security.lnk (Rogue.PersonalSecurity) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Microsoft\Windows\Start Menu\PersSecurity\Registration.lnk (Rogue.PersonalSecurity) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Microsoft\Windows\Start Menu\PersSecurity\Security Center.lnk (Rogue.PersonalSecurity) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Microsoft\Windows\Start Menu\PersSecurity\Settings.lnk (Rogue.PersonalSecurity) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Microsoft\Windows\Start Menu\PersSecurity\Update.lnk (Rogue.PersonalSecurity) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)



Ich hoffe Ihr könnt mit dem Daten wust was anfangen

MfG
D. Montag

cosinus 12.06.2012 15:11

Bitte erstmal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

magicfortune 12.06.2012 18:59

So hier ist das Log

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=1b25778922a105448f80b9b4d3d1dcdb
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-06-12 05:51:52
# local_time=2012-06-12 07:51:52 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 164632 164632 0 0
# compatibility_mode=5893 16776573 100 94 161 91148074 0 0
# compatibility_mode=8192 67108863 100 0 111 111 0 0
# scanned=204950
# found=12
# cleaned=0
# scan_time=6628
C:\Program Files\VistaCodecPack\Tools\renderer32.exe        Win32/Packed.Autoit.E.Gen application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files\VistaCodecPack\Tools\Settings32.exe        Win32/Packed.Autoit.C.Gen application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files\Webfetti\bar\2.bin\7dhtml.dll        probably a variant of Win32/Toolbar.MyWebSearch.F application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files\Webfetti\bar\2.bin\7dhtmlmu.dll        probably a variant of Win32/Toolbar.MyWebSearch.B application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files\Webfetti\bar\2.bin\7dPlugin.dll        a variant of Win32/Toolbar.MyWebSearch application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files\Webfetti\bar\2.bin\7dskin.dll        a variant of Win32/Toolbar.MyWebSearch.P application (unable to clean)        00000000000000000000000000000000        I
C:\ProgramData\VistaCodecs\{28B14EDE-7C6B-4A00-9E91-39680470E557}\Vista Codec Package.msi        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\Users\All Users\VistaCodecs\{28B14EDE-7C6B-4A00-9E91-39680470E557}\Vista Codec Package.msi        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\Users\Désirée\AppData\Local\Temp\2012-08-1.zip        Win32/Trustezeb.C trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Désirée\AppData\Local\Temp\2012-08.zip        Win32/Trustezeb.C trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Désirée\AppData\Local\Temp\anLXPkke.exe.part        a variant of Win32/SoftonicDownloader.A application (unable to clean)        00000000000000000000000000000000        I
C:\Users\Désirée\Documents\DVDVideoSoft\Webfetti.exe        a variant of Win32/Toolbar.MyWebSearch.Q application (unable to clean)        00000000000000000000000000000000        I


cosinus 12.06.2012 21:59

Was ist mit dem Malwarebytes Vollscan?

magicfortune 13.06.2012 18:50

siehe 1. Post oder sollte ich das noch mal extra als codetag gestalten???

cosinus 13.06.2012 21:04

Zitat:

Art des Suchlaufs: Quick-Scan
Klingelt's jetzt? ;)

magicfortune 15.06.2012 02:54

Dann ist hier der Vollscan

Code:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.14.09

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
Désirée :: DÉSIRÉE-PC [Administrator]

Schutz: Aktiviert

14.06.2012 21:18:00
mbam-log-2012-06-14 (21-18-00).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 412445
Laufzeit: 2 Stunde(n), 1 Minute(n), 26 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\Désirée\Documents\DVDVideoSoft\Webfetti.exe (PUP.FunWebProducts) -> Keine Aktion durchgeführt.

(Ende)

Hoffe das ist jetzt richtig.

cosinus 15.06.2012 12:01

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

magicfortune 16.06.2012 18:16

Also vermissen tue ich nichts.

Das größte Problem ist das ich auf private Dateien (Bilder, Musik etc.)
keinen Zugriff bekomme.

Dort stehen irgendwelche Buchstaben :(

Ich hoffe das Problem kann behoben werden.

MfG

magicfortune

cosinus 17.06.2012 21:06

Zur Entschlüsselung/Wiederherstellung bitte die fette Hinweisbox oben beachten!

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


magicfortune 18.06.2012 20:59

Hier das OTL log

Code:

OTL logfile created on: 18.06.2012 20:33:47 - Run 1
OTL by OldTimer - Version 3.2.49.0    Folder = C:\Users\Désirée\Desktop
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,97 Gb Total Physical Memory | 1,62 Gb Available Physical Memory | 54,73% Memory free
5,93 Gb Paging File | 4,23 Gb Available in Paging File | 71,28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287,90 Gb Total Space | 204,92 Gb Free Space | 71,18% Space Free | Partition Type: NTFS
 
Computer Name: DÉSIRÉE-PC | User Name: Désirée | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.06.18 20:31:18 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Désirée\Desktop\OTL.exe
PRC - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.02 00:31:35 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.04.24 02:11:55 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.04.09 17:43:42 | 001,557,160 | ---- | M] (Ask) -- C:\Programme\Ask.com\Updater\Updater.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.08.10 21:35:20 | 000,227,184 | ---- | M] () -- C:\Programme\Motorola\MotoHelper\MotoHelperService.exe
PRC - [2011.08.09 00:11:06 | 000,681,840 | ---- | M] () -- C:\Programme\Motorola\MotoHelper\MotoHelperAgent.exe
PRC - [2011.06.24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.04.02 19:42:38 | 000,036,864 | ---- | M] (Webfetti) -- C:\Programme\Webfetti\bar\2.bin\7dbarsvc.exe
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011.01.17 18:50:34 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.exe
PRC - [2011.01.17 18:50:34 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.bin
PRC - [2010.12.09 12:45:58 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\Winamp\winampa.exe
PRC - [2010.11.21 11:49:24 | 000,247,608 | ---- | M] () -- C:\Programme\ICQ6Toolbar\ICQ Service.exe
PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.01.12 09:01:00 | 000,201,216 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGAE.EXE
PRC - [2009.12.03 10:12:12 | 000,976,320 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Programme\Epson Software\Event Manager\EEventManager.exe
PRC - [2009.09.14 07:00:00 | 000,153,600 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Programme\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE
PRC - [2009.09.14 07:00:00 | 000,121,856 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Programme\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
PRC - [2009.08.18 03:36:36 | 000,348,160 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2009.08.18 03:36:08 | 000,176,128 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2009.06.17 10:14:22 | 000,026,624 | ---- | M] (Sony Corporation) -- C:\Programme\sony\Marketing Tools\MarketingTools.exe
PRC - [2009.05.20 15:11:40 | 000,111,928 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Programme\SweetIM\Messenger\SweetIM.exe
PRC - [2009.05.14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) -- C:\Programme\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
PRC - [2009.04.13 22:16:31 | 000,180,224 | ---- | M] (ALPS) -- C:\Programme\Apoint\Apvfb.exe
PRC - [2009.04.13 22:16:30 | 000,155,648 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\Apoint\Apoint.exe
PRC - [2009.04.13 22:16:29 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\Apoint\ApntEx.exe
PRC - [2009.04.13 22:16:28 | 000,050,472 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\Apoint\ApMsgFwd.exe
PRC - [2009.03.01 23:21:32 | 002,329,128 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTStackServer.exe
PRC - [2009.03.01 23:21:32 | 000,789,032 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2009.03.01 23:21:32 | 000,567,848 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\btwdins.exe
PRC - [2009.01.21 10:07:42 | 000,313,264 | ---- | M] (Sony Corporation) -- C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
PRC - [2009.01.21 10:07:42 | 000,192,512 | ---- | M] (Sony Corporation) -- C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
PRC - [2009.01.19 16:43:04 | 000,394,536 | ---- | M] (Sony Corporation) -- C:\Programme\sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
PRC - [2009.01.19 12:49:20 | 000,203,624 | ---- | M] (Sony Corporation) -- C:\Programme\sony\VAIO Event Service\VESMgr.exe
PRC - [2009.01.19 12:49:20 | 000,112,488 | ---- | M] (Sony Corporation) -- C:\Programme\sony\VAIO Event Service\VESMgrSub.exe
PRC - [2009.01.14 13:38:38 | 005,184,872 | ---- | M] (Sony Corporation) -- C:\Programme\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
PRC - [2009.01.06 04:04:54 | 000,109,088 | ---- | M] (Realtek Semiconductor) -- C:\Programme\Realtek\Audio\HDA\RtkAudioService.exe
PRC - [2008.12.21 23:30:32 | 000,274,432 | ---- | M] (Sony Corporation) -- C:\Programme\sony\Network Utility\LANUtil.exe
PRC - [2008.12.21 21:55:06 | 000,303,104 | ---- | M] (Sony Corporation) -- C:\Programme\sony\Network Utility\NSUService.exe
PRC - [2008.12.19 14:02:08 | 001,771,368 | ---- | M] (Sony Corporation) -- C:\Programme\sony\VAIO Power Management\SPMgr.exe
PRC - [2008.12.19 14:02:08 | 000,415,592 | ---- | M] (Sony Corporation) -- C:\Programme\sony\VAIO Power Management\SPMService.exe
PRC - [2008.12.18 12:18:58 | 000,874,344 | ---- | M] (Sony Corporation) -- C:\Programme\sony\VAIO Update 4\VAIOUpdt.exe
PRC - [2008.12.18 10:53:50 | 000,317,288 | ---- | M] (Sony Corporation) -- C:\Programme\sony\ISB Utility\ISBMgr.exe
PRC - [2008.09.18 10:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) -- C:\Programme\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
PRC - [2008.08.20 16:38:30 | 000,860,160 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe
PRC - [2008.08.20 16:08:02 | 000,466,944 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe
PRC - [2007.01.04 19:48:50 | 000,112,152 | ---- | M] (InterVideo) -- C:\Programme\Common Files\InterVideo\RegMgr\iviRegMgr.exe
PRC - [2006.12.19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Programme\Common Files\EPSON\EBAPI\eEBSvc.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.14 21:15:29 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012.06.14 21:15:21 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012.05.14 14:43:09 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\100d39c2f8985cb93e26feef86ba5212\System.IdentityModel.Selectors.ni.dll
MOD - [2012.05.14 14:43:08 | 001,083,392 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\2ce8210219c7123610072357358df470\System.IdentityModel.ni.dll
MOD - [2012.05.14 14:43:06 | 002,347,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\72a24b45e11d64eb2bc840aae9419ba5\System.Runtime.Serialization.ni.dll
MOD - [2012.05.14 14:43:04 | 000,256,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\9e7bf69d97febe4ed1a288c787e5d9ca\SMDiagnostics.ni.dll
MOD - [2012.05.14 14:43:02 | 017,478,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\107779ca2708d2b31b2e1560e47f6d15\System.ServiceModel.ni.dll
MOD - [2012.05.14 14:38:50 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012.05.14 14:38:46 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012.05.14 14:38:45 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012.05.14 14:38:35 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2011.12.25 22:42:15 | 005,255,168 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
MOD - [2011.08.09 00:11:06 | 000,681,840 | ---- | M] () -- C:\Programme\Motorola\MotoHelper\MotoHelperAgent.exe
MOD - [2011.04.21 13:50:21 | 000,985,088 | ---- | M] () -- C:\Programme\OpenOffice.org 3\program\libxml2.dll
MOD - [2010.11.13 02:02:21 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.11.05 04:00:15 | 000,491,520 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.ServiceModel.resources\3.0.0.0_de_b77a5c561934e089\System.ServiceModel.resources.dll
MOD - [2010.11.05 03:58:10 | 000,114,688 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
MOD - [2010.07.30 22:10:20 | 000,034,816 | ---- | M] () -- C:\Programme\Google\Google Desktop Search\gzlib.dll
MOD - [2010.01.01 18:39:41 | 000,086,016 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\SPMCommon\3.1.0.6020__e3c7096ba83f9295\SPMCommon.dll
MOD - [2010.01.01 18:39:41 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\SPMDam\3.1.0.6020__1b3c579b6925895f\SPMDam.dll
MOD - [2006.12.10 22:51:08 | 000,077,824 | R--- | M] () -- C:\Programme\HP\Digital Imaging\bin\crm\xmltok.dll
MOD - [2006.12.10 22:51:08 | 000,065,536 | R--- | M] () -- C:\Programme\HP\Digital Imaging\bin\crm\xmlparse.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012.06.14 21:17:13 | 000,257,224 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.05.06 10:51:27 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Disabled | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.08.10 21:35:20 | 000,227,184 | ---- | M] () [Auto | Running] -- C:\Programme\Motorola\MotoHelper\MotoHelperService.exe -- (MotoHelper)
SRV - [2011.04.02 19:42:38 | 000,036,864 | ---- | M] (Webfetti) [Auto | Running] -- C:\Programme\Webfetti\bar\2.bin\7dbarsvc.exe -- (WebfettiService)
SRV - [2010.11.21 11:49:24 | 000,247,608 | ---- | M] () [Auto | Running] -- C:\Programme\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2010.04.28 08:44:02 | 000,704,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2010.03.18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009.09.14 07:00:00 | 000,153,600 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Programme\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE -- (EPSON_EB_RPCV4_04) EPSON V5 Service4(04)
SRV - [2009.09.14 07:00:00 | 000,121,856 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Programme\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE -- (EPSON_PM_RPCV4_04) EPSON V3 Service4(04)
SRV - [2009.08.18 03:36:08 | 000,176,128 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.05.14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) [Auto | Running] -- C:\Programme\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0)
SRV - [2009.03.01 23:21:32 | 000,567,848 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Programme\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2009.02.05 12:41:46 | 000,091,432 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe -- (SOHPlMgr)
SRV - [2009.02.05 12:41:44 | 000,390,440 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\SOHLib\SOHDms.exe -- (SOHDms)
SRV - [2009.02.05 12:41:44 | 000,120,104 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\SOHLib\SOHCImp.exe -- (SOHCImp)
SRV - [2009.02.05 12:41:44 | 000,075,048 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\SOHLib\SOHDs.exe -- (SOHDs)
SRV - [2009.02.05 12:41:44 | 000,070,952 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe -- (SOHDBSvr)
SRV - [2009.01.21 10:07:44 | 000,069,632 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe -- (VAIO Entertainment TV Device Arbitration Service)
SRV - [2009.01.21 10:07:42 | 000,313,264 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -- (Vcsw)
SRV - [2009.01.21 10:07:42 | 000,192,512 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe -- (VzCdbSvc)
SRV - [2009.01.19 16:43:04 | 000,394,536 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr)
SRV - [2009.01.19 12:49:20 | 000,203,624 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
SRV - [2009.01.16 21:59:08 | 000,083,240 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe -- (VcmXmlIfHelper)
SRV - [2009.01.14 13:38:38 | 005,184,872 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe -- (VCFw)
SRV - [2009.01.08 00:10:32 | 000,114,688 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2009.01.06 04:04:54 | 000,109,088 | ---- | M] (Realtek Semiconductor) [Auto | Running] -- C:\Programme\Realtek\Audio\HDA\RtkAudioService.exe -- (RtkAudioService)
SRV - [2008.12.21 21:55:06 | 000,303,104 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\sony\Network Utility\NSUService.exe -- (NSUService)
SRV - [2008.12.19 14:02:08 | 000,415,592 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\sony\VAIO Power Management\SPMService.exe -- (VAIO Power Management)
SRV - [2008.09.18 10:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) [Auto | Running] -- C:\Programme\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe -- (uCamMonitor)
SRV - [2008.08.20 16:38:30 | 000,860,160 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV - [2008.08.20 16:08:02 | 000,466,944 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV - [2007.01.04 19:48:50 | 000,112,152 | ---- | M] (InterVideo) [Auto | Running] -- C:\Programme\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2006.12.19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Programme\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\HSX_CNXT.sys -- (winachsf)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\motodrv.sys -- (MotDev)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\motccgpfl.sys -- (motccgpfl)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\motccgp.sys -- (motccgp)
DRV - File not found [Kernel | Auto | Stopped] -- system32\DRIVERS\mdmxsdk.sys -- (mdmxsdk)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\HSXHWAZL.sys -- (HSXHWAZL)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\HSX_DPV.sys -- (HSF_DPV)
DRV - [2012.04.27 10:20:04 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.04.25 00:32:27 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.04.16 21:17:40 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011.03.31 14:53:22 | 000,024,064 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motmodem.sys -- (motmodem)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.08.18 04:48:06 | 004,994,560 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2009.07.14 01:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
DRV - [2009.07.14 00:02:53 | 000,311,296 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7)
DRV - [2009.07.14 00:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) Intel(R)
DRV - [2009.04.13 22:16:29 | 000,173,616 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2009.02.23 22:07:18 | 000,155,808 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RtHDMIV.sys -- (RTHDMIAzAudService)
DRV - [2009.02.09 10:42:42 | 000,099,968 | ---- | M] (Guillemot Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hxctlflt.sys -- (hxctlflt)
DRV - [2008.11.24 23:41:52 | 000,010,216 | ---- | M] (Sony Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\DMICall.sys -- (DMICall)
DRV - [2008.11.19 02:08:46 | 000,009,344 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SFEP.sys -- (SFEP)
DRV - [2008.10.23 02:02:23 | 000,046,592 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\risdptsk.sys -- (risdptsk)
DRV - [2008.10.23 02:02:02 | 000,068,608 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2008.06.07 02:02:55 | 000,131,000 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr)
DRV - [2008.04.24 14:06:40 | 000,017,920 | ---- | M] (ArcSoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ArcSoftKsUFilter.sys -- (ArcSoftKsUFilter)
DRV - [2007.08.06 15:29:46 | 000,094,720 | ---- | M] (Guillemot Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\camfilt2.sys -- (camfilt2)
DRV - [2007.07.17 18:07:42 | 010,371,072 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\snpstd3.sys -- (SNPSTD3)
DRV - [2007.04.17 20:09:28 | 000,011,032 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\regi.sys -- (regi)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SNYT&bmod=EU01
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKLM\..\SearchScopes,DefaultScope = {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SNYT
IE - HKLM\..\SearchScopes\{EA6E82DD-9489-4B32-8E7B-5A97F7EF3395}: "URL" = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SNYT&bmod=EU01
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - No CLSID value found
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes,DefaultScope = {6552C7DD-90A4-4387-B795-F8F96747DE19}
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=CDS&o=16225&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=QQ&apn_dtid=YYYYYYYYDE&apn_uid=6789FF94-1B5C-418F-AB67-D056611F19BA&apn_sauid=B0654D97-0C66-4B09-B061-B47EE50BE6D3
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SNYT
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rlz=1I7SNYK_de&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = hxxp://127.0.0.1:4664/search&s=0-PzDPaY_dvVM8njmJBRCbTWtEk?q={searchTerms}
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA74C8}: "URL" = hxxp://www.searchqu.com/web?src=ieb&q={SearchTerms}
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{A2DC3FEF-AB4D-442c-8517-34EC6E125C8D}: "URL" = hxxp://search.webwebweb.com/search.php?query={searchTerms}&lang=de&zip=&town=&site=&country=
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{EA6E82DD-9489-4B32-8E7B-5A97F7EF3395}: "URL" = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\Live Search: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&mkt=de-DE&FORM=MICGLV
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/ig"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.11.3.15590
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1
FF - prefs.js..extensions.enabledItems: {6C8B07BF-0F6D-4EA4-B96F-FF1CCBAAE553}:1.2.8
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.7
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.10
FF - prefs.js..extensions.enabledItems: ffext@webwebweb:1.0.0.449
FF - prefs.js..extensions.enabledItems: 7dffxtbr@Webfetti.com:1.2
FF - prefs.js..keyword.URL: "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=CDS&o=16225&locale=en_US&apn_uid=6789FF94-1B5C-418F-AB67-D056611F19BA&apn_ptnrs=QQ&apn_sauid=B0654D97-0C66-4B09-B061-B47EE50BE6D3&apn_dtid=YYYYYYYYDE&&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://start.icq.com/"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_257.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\VistaCodecPack\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@startpage24.com/npLin64;Version=4: C:\Program Files\Startpage24\Plugin\Version_586\firefox\plugins\nplink64.dll (Link64 GmbH)
FF - HKLM\Software\MozillaPlugins\@Webfetti.com/Plugin: C:\Program Files\Webfetti\bar\2.bin\NP7dStub.dll (Webfetti)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\7dffxtbr@Webfetti.com: C:\Program Files\Webfetti\bar\2.bin [2011.10.16 13:34:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ffext@startpage24: C:\Program Files\Startpage24\Plugin\Version_586\firefox [2011.06.24 22:38:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.10 16:48:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.04.12 21:48:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.05.12 16:03:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
 
[2010.12.13 21:03:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Désirée\AppData\Roaming\mozilla\Extensions
[2010.12.13 21:03:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Désirée\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.05.18 20:00:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions
[2010.09.16 19:48:38 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010.06.15 17:37:06 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.05.18 20:00:22 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012.03.28 20:46:06 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.12.19 21:52:59 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.10.16 13:34:48 | 000,000,000 | ---D | M] (Webfetti) -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\7dffxtbr@Webfetti.com
[2012.05.24 22:42:22 | 000,000,000 | ---D | M] ("Ask Toolbar") -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\toolbar@ask.com
[2012.06.14 21:48:04 | 000,002,572 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\askcom.xml
[2012.06.10 16:55:55 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-1.xml
[2011.12.18 20:03:20 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-10.xml
[2012.01.02 21:24:32 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-11.xml
[2012.01.18 23:27:21 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-12.xml
[2012.02.18 21:29:21 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-13.xml
[2012.02.26 11:15:12 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-14.xml
[2012.02.26 11:22:54 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-15.xml
[2012.03.28 20:46:12 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-16.xml
[2012.05.06 10:51:49 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-17.xml
[2012.05.13 13:48:01 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-18.xml
[2012.06.08 21:04:19 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-19.xml
[2011.06.16 10:34:03 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-2.xml
[2011.08.02 15:23:19 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-3.xml
[2011.08.26 18:29:56 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-4.xml
[2011.09.11 19:14:01 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-5.xml
[2011.09.15 10:34:20 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-6.xml
[2011.10.01 16:04:14 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-7.xml
[2011.10.11 19:50:07 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-8.xml
[2011.11.09 21:37:04 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-9.xml
[2011.03.30 15:14:34 | 000,001,042 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin.xml
[2009.08.10 21:13:36 | 000,001,836 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\live-search.xml
[2009.08.11 19:23:35 | 000,003,915 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\sweetim.xml
[2011.06.20 23:33:06 | 000,005,218 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\webwebweb.xml
[2009.08.30 16:24:26 | 000,001,201 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\winamp-search.xml
[2012.02.26 11:15:00 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.01.01 18:35:25 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
File not found (No name found) -- C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\EXTENSIONS\{635ABD67-4FE9-1B23-4F01-E679FA7484C1}
File not found (No name found) -- C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\EXTENSIONS\{6C8B07BF-0F6D-4EA4-B96F-FF1CCBAAE553}.XPI
File not found (No name found) -- C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
File not found (No name found) -- C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}.XPI
File not found (No name found) -- C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\EXTENSIONS\7DFFXTBR@WEBFETTI.COM
File not found (No name found) -- C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\EXTENSIONS\PERSONAS@CHRISTOPHER.BEARD.XPI
File not found (No name found) -- C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\EXTENSIONS\TOOLBAR@ASK.COM
[2012.05.06 10:51:27 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.02.25 20:51:05 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010.12.09 12:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012.02.18 21:28:28 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.02.18 21:28:28 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.02.18 21:28:28 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.18 21:28:28 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.18 21:28:28 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.18 21:28:28 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (FastestTubeBHO Class) - {3E532CE8-C6D9-4A10-8ACE-4348C96E8B6A} - C:\Programme\FastestTube\1.2.12\WombatBHO.dll (Kwizzu)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (WebWebWeb) - {BBD43808-9D13-4B0B-B023-178FD1FAE442} - C:\Program Files\WebWebWeb\Plugin\Version_449\link64_plugin.dll File not found
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (ICQ Sparberater) - {FE163F11-1919-4257-A280-FF5AF8DAEECB} - C:\Programme\icq\Internet Explorer\icq.dll (solute gmbh)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [MarketingTools] C:\Programme\sony\Marketing Tools\MarketingTools.exe (Sony Corporation)
O4 - HKLM..\Run: [mumservice] C:\Programme\Motorola\Software Update\mumservice.exe (Motorola)
O4 - HKLM..\Run: [Skytel] C:\Programme\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SweetIM] C:\Programme\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000..\Run: [DriverScanner] C:\Program Files\Uniblue\DriverScanner\launcher.exe (Uniblue Systems Limited)
O4 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000..\Run: [Epson Stylus SX525WD(Netzwerk)] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIGAE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000..\Run: [EPSON SX525WD Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIGAE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000..\Run: [ICQ] C:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000..\Run: [NSUFloatingUI] C:\Program Files\Sony\Network Utility\LANUtil.exe (Sony Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\Désirée\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Programme\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Programme\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Programme\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D3BFA3BB-6C8A-4DC3-A8B1-92FEF5C0C637}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\webwebweb {879506D7-73DF-8D45-BBDD-123467926D12} - C:\Program Files\WebWebWeb\Plugin\Version_449\link64_plugin.dll File not found
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~1\google\google~1\go36f4~1.dll) - c:\Programme\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - Winlogon\Notify\VESWinlogon: DllName - (VESWinlogon.dll) - C:\Windows\System32\VESWinlogon.dll (Sony Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper: C:\Users\Désirée\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Désirée\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{4a250eb5-82ae-11de-87e0-002433d377d6}\Shell - "" = AutoRun
O33 - MountPoints2\{4a250eb5-82ae-11de-87e0-002433d377d6}\Shell\AutoRun\command - "" = G:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Macromedia Shockwave Director 10.1
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Macromedia Shockwave Director 10.1
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.dvsd - C:\Programme\Common Files\Sony Shared\VideoLib\sonydv.dll (Sony Corporation)
Drivers32: VIDC.FFDS - ff_vfw.dll File not found
Drivers32: VIDC.IV41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.06.18 20:31:13 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Désirée\Desktop\OTL.exe
[2012.06.14 21:48:07 | 000,000,000 | ---D | C] -- C:\Users\Désirée\AppData\Local\Macromedia
[2012.06.12 17:59:32 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.06.10 20:23:14 | 000,000,000 | ---D | C] -- C:\Users\Désirée\AppData\Roaming\Avira
[2012.06.10 20:17:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.06.10 20:17:42 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.06.10 20:17:42 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2012.06.10 20:17:41 | 000,137,928 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2012.06.10 20:17:41 | 000,083,392 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2012.06.10 20:17:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012.06.10 20:17:31 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012.06.10 16:56:56 | 000,000,000 | ---D | C] -- C:\Users\Désirée\AppData\Roaming\Malwarebytes
[2012.06.10 16:56:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.06.10 16:56:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.06.10 16:56:49 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.06.10 16:56:49 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.06.08 19:00:30 | 000,000,000 | ---D | C] -- C:\Users\Désirée\AppData\Roaming\Rhiycqnu
[2012.03.08 20:50:16 | 008,862,099 | ---- | C] (InstallShield Software Corporation) -- C:\Program Files\Setup_MHRemake.exe
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.06.18 20:50:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.06.18 20:45:00 | 000,000,298 | ---- | M] () -- C:\Windows\tasks\Updater.job
[2012.06.18 20:31:18 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Désirée\Desktop\OTL.exe
[2012.06.18 20:27:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.14 21:46:59 | 000,009,504 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.06.14 21:46:59 | 000,009,504 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.06.14 21:22:04 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.06.14 21:22:04 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.06.14 21:22:04 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.06.14 21:22:04 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.06.14 21:15:47 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\DriverScanner.job
[2012.06.14 21:13:38 | 000,524,264 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.06.14 21:12:40 | 2389,987,328 | -HS- | M] () -- C:\hiberfil.sys
[2012.06.10 20:17:54 | 000,001,940 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.06.10 16:56:52 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.08 19:01:45 | 000,033,376 | ---- | M] () -- C:\Users\Désirée\Documents\oqlanAJgfGEygudsep
[2012.05.27 22:03:20 | 000,001,093 | ---- | M] () -- C:\Users\Public\Desktop\GAME CENTER.lnk
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.06.10 20:17:54 | 000,001,940 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.06.10 16:56:52 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2010.07.17 21:19:40 | 000,159,454 | ---- | C] () -- C:\Windows\Kaiser - das Erbe Uninstaller.exe
[2010.06.28 00:06:04 | 000,102,400 | ---- | C] () -- C:\Windows\System32\st50220.dll
[2010.06.27 23:58:47 | 003,600,384 | ---- | C] () -- C:\Windows\ffmpeg.exe
[2010.06.27 23:58:23 | 000,057,344 | ---- | C] ( ) -- C:\Windows\System32\vsnpstd3.dll
[2010.06.27 23:58:23 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\csnpstd3.dll
[2010.06.27 23:58:23 | 000,015,478 | ---- | C] () -- C:\Windows\snpstd3.ini
 
========== LOP Check ==========
 
[2011.01.01 13:02:47 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\.purple
[2010.04.24 21:40:48 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\1morebee
[2010.01.01 18:46:26 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\AD ON Multimedia
[2011.10.29 14:13:46 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Alawar Entertainment
[2010.02.11 19:09:05 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Anabel
[2010.03.01 21:31:08 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Ancient Quest of Saqqarah__intenium
[2010.02.10 15:36:19 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Artogon
[2011.06.13 19:18:40 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Awem
[2010.02.20 00:04:09 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\BloodTies
[2010.08.14 14:04:44 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Brunhilda_intenium
[2010.02.05 21:02:02 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\casanova
[2010.01.01 18:46:27 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\DeepBurner
[2010.02.06 14:14:37 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Dekovir
[2010.04.25 11:51:49 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Divo Games
[2012.01.06 21:02:53 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\DivoGames
[2011.10.01 19:00:49 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\DVDVideoSoft
[2010.12.19 21:52:59 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.04.13 18:53:42 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\EleFun Games
[2010.03.26 19:58:12 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\ElementalsTheMagicKey
[2010.03.28 19:57:04 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\EnchantedCavern
[2010.02.24 23:05:41 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Enlightenus
[2011.08.13 12:16:26 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Epson
[2010.05.24 19:05:08 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\EscapeFromParadise2
[2010.07.17 18:03:43 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Flood Light Games
[2012.05.27 22:04:14 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Friday's games
[2010.04.28 19:28:46 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\GamersDigital
[2010.02.20 21:25:28 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Games
[2010.11.27 22:37:56 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Gogii
[2010.05.30 12:20:49 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Gogii Games
[2010.05.14 19:31:31 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\GraveyardShift
[2010.12.23 22:51:49 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\gtk-2.0
[2012.06.14 21:18:11 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\ICQ
[2010.09.17 10:02:21 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Image Zone Express
[2010.02.11 14:49:19 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\iMaxGen
[2010.02.15 20:51:19 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Inteniumv1002
[2010.07.17 21:30:05 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\InterTrust
[2010.01.01 18:46:28 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\IrfanView
[2010.08.08 21:12:38 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Lazy Turtle Games
[2010.02.15 22:08:51 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Legends of pirates
[2010.02.10 19:23:20 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Magic Academy
[2010.02.10 22:20:11 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Magic Academy 2
[2010.07.14 20:27:43 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Magic3
[2010.11.28 19:13:46 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\MagicIndie
[2011.11.22 18:29:34 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\margrave3_full
[2011.02.02 19:12:50 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Meridian93
[2011.06.13 12:38:01 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Merscom
[2010.02.17 23:12:05 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Mysteryville2
[2011.10.30 12:56:06 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Nevosoft Games
[2010.01.01 18:46:41 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\OpenOffice.org
[2010.02.25 21:30:00 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Pingus
[2010.03.07 13:43:34 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Playrix Entertainment
[2010.03.05 20:49:56 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\PoBros
[2010.02.07 13:41:31 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Princess Isabella
[2010.01.01 18:46:43 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Printer Info Cache
[2010.02.28 15:10:32 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Purple Patch Games
[2012.06.10 16:48:21 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Rhiycqnu
[2010.02.17 19:17:45 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\RobinsonCrusoe
[2012.04.19 17:37:48 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Sahmon Games
[2010.02.04 17:20:25 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\SecretIslandDeuBF
[2010.06.12 21:59:55 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Settlement. Colossus
[2011.07.27 17:58:53 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Silverback Productions
[2010.04.10 19:43:58 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\TheFixerUpper
[2010.12.13 21:03:18 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Thunderbird
[2010.03.09 22:36:18 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\TitanicMystery
[2010.02.06 20:03:25 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Total Eclipse
[2011.06.13 17:31:57 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\TripleHippo
[2011.08.03 16:00:58 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Uniblue
[2010.02.03 20:01:58 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\V-Games
[2010.04.11 17:25:11 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\VampireSaga
[2011.10.03 13:48:51 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\VampireSagaHL
[2010.12.25 15:47:01 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Vast Studios
[2010.01.01 18:46:43 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\VistaCodecs
[2011.02.02 18:22:03 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\WebWebWeb
[2010.09.19 12:54:25 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\World-Loom
[2010.01.27 18:09:40 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Wormux
[2010.09.26 17:08:36 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\XLMSoftGames
[2011.06.25 14:18:04 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\YoudaGames
[2012.06.14 21:15:47 | 000,000,332 | ---- | M] () -- C:\Windows\Tasks\DriverScanner.job
[2009.07.14 06:53:46 | 000,023,812 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.06.18 20:45:00 | 000,000,298 | ---- | M] () -- C:\Windows\Tasks\Updater.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.01.01 13:02:47 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\.purple
[2010.04.24 21:40:48 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\1morebee
[2010.01.01 18:46:26 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\AD ON Multimedia
[2011.11.21 03:50:11 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Adobe
[2011.10.29 14:13:46 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Alawar Entertainment
[2010.02.11 19:09:05 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Anabel
[2010.03.01 21:31:08 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Ancient Quest of Saqqarah__intenium
[2010.11.28 18:04:11 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Apple Computer
[2010.01.01 18:46:27 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\ArcSoft
[2010.02.10 15:36:19 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Artogon
[2010.01.01 18:46:27 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\ATI
[2012.06.10 20:23:14 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Avira
[2011.06.13 19:18:40 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Awem
[2010.02.20 00:04:09 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\BloodTies
[2010.08.14 14:04:44 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Brunhilda_intenium
[2010.02.05 21:02:02 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\casanova
[2010.01.01 18:46:27 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\DeepBurner
[2010.02.06 14:14:37 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Dekovir
[2010.04.25 11:51:49 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Divo Games
[2012.01.06 21:02:53 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\DivoGames
[2011.10.01 19:00:49 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\DVDVideoSoft
[2010.12.19 21:52:59 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.04.13 18:53:42 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\EleFun Games
[2010.03.26 19:58:12 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\ElementalsTheMagicKey
[2010.03.28 19:57:04 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\EnchantedCavern
[2010.02.24 23:05:41 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Enlightenus
[2011.08.13 12:16:26 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Epson
[2010.05.24 19:05:08 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\EscapeFromParadise2
[2010.07.17 18:03:43 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Flood Light Games
[2012.05.27 22:04:14 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Friday's games
[2010.04.28 19:28:46 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\GamersDigital
[2010.02.20 21:25:28 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Games
[2010.11.27 22:37:56 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Gogii
[2010.05.30 12:20:49 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Gogii Games
[2010.05.14 19:31:31 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\GraveyardShift
[2010.12.23 22:51:49 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\gtk-2.0
[2010.01.01 18:46:27 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\HP
[2011.02.15 18:25:26 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\HpUpdate
[2012.06.14 21:18:11 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\ICQ
[2012.03.31 16:56:46 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Identities
[2010.09.17 10:02:21 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Image Zone Express
[2010.02.11 14:49:19 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\iMaxGen
[2010.06.27 23:45:10 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\InstallShield
[2011.03.24 21:45:54 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Intel
[2010.02.15 20:51:19 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Inteniumv1002
[2010.07.17 21:30:05 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\InterTrust
[2010.01.01 18:46:28 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\IrfanView
[2010.08.08 21:12:38 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Lazy Turtle Games
[2010.02.15 22:08:51 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Legends of pirates
[2010.10.26 13:24:26 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Macromedia
[2010.02.10 19:23:20 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Magic Academy
[2010.02.10 22:20:11 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Magic Academy 2
[2010.07.14 20:27:43 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Magic3
[2010.11.28 19:13:46 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\MagicIndie
[2012.06.10 16:56:56 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Malwarebytes
[2011.11.22 18:29:34 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\margrave3_full
[2009.07.14 10:56:41 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Media Center Programs
[2011.02.02 19:12:50 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Meridian93
[2011.06.13 12:38:01 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Merscom
[2011.11.21 03:50:11 | 000,000,000 | --SD | M] -- C:\Users\Désirée\AppData\Roaming\Microsoft
[2010.01.01 18:46:38 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Mozilla
[2010.02.17 23:12:05 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Mysteryville2
[2011.10.30 12:56:06 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Nevosoft Games
[2010.01.01 18:46:41 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\OpenOffice.org
[2010.02.25 21:30:00 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Pingus
[2010.03.07 13:43:34 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Playrix Entertainment
[2010.03.05 20:49:56 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\PoBros
[2010.02.07 13:41:31 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Princess Isabella
[2010.01.01 18:46:43 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Printer Info Cache
[2010.02.28 15:10:32 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Purple Patch Games
[2012.06.10 16:48:21 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Rhiycqnu
[2010.02.17 19:17:45 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\RobinsonCrusoe
[2010.01.01 18:46:43 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Roxio
[2012.04.19 17:37:48 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Sahmon Games
[2010.02.04 17:20:25 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\SecretIslandDeuBF
[2010.06.12 21:59:55 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Settlement. Colossus
[2011.07.27 17:58:53 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Silverback Productions
[2010.01.01 18:46:43 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Sony Corporation
[2010.04.10 19:43:58 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\TheFixerUpper
[2010.12.13 21:03:18 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Thunderbird
[2010.03.09 22:36:18 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\TitanicMystery
[2010.02.06 20:03:25 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Total Eclipse
[2011.06.13 17:31:57 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\TripleHippo
[2011.08.03 16:00:58 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Uniblue
[2010.02.03 20:01:58 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\V-Games
[2010.04.11 17:25:11 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\VampireSaga
[2011.10.03 13:48:51 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\VampireSagaHL
[2010.12.25 15:47:01 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Vast Studios
[2010.01.01 18:46:43 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\VistaCodecs
[2011.02.02 18:22:03 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\WebWebWeb
[2012.04.20 21:00:04 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Winamp
[2010.09.19 12:54:25 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\World-Loom
[2010.01.27 18:09:40 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\Wormux
[2010.09.26 17:08:36 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\XLMSoftGames
[2011.06.25 14:18:04 | 000,000,000 | ---D | M] -- C:\Users\Désirée\AppData\Roaming\YoudaGames
 
< %APPDATA%\*.exe /s >
[2011.02.08 20:09:39 | 000,010,134 | R--- | M] () -- C:\Users\Désirée\AppData\Roaming\Microsoft\Installer\{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}\ARPPRODUCTICON.exe
[2012.04.29 19:28:16 | 003,943,592 | ---- | M] (Ask) -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\extensions\toolbar@ask.com\chrome\temp\askToolbar.exe
 
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 09:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2008.04.22 02:20:41 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\Drivers\INF\SATA Driver (Intel) (Non-RAID)\IaStor.sys
[2008.04.22 02:20:41 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\drivers\iaStor.sys
[2008.04.22 02:20:41 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_2d2ec4fd9937ddb4\iaStor.sys
[2008.04.22 02:20:41 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_x86_neutral_950dad68cf8acc20\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\drivers\iaStorV.sys
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys
[2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys
[2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\drivers\nvstor.sys
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys
[2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\System32\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
 
========== Files - Unicode (All) ==========
[2010.05.23 17:04:37 | 000,000,000 | ---D | M](C:\Users\D?sir?e\AppData\Roaming\Silverback Productions) -- C:\Users\D�sir�e\AppData\Roaming\Silverback Productions
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:6017A808
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:6425A235
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:270A3983
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:5E9B629B
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:7FCB9D0D

< End of report >

Ist das OTL personifiziert oder allg. Gültig??

MfG
magicfortune

Da hat sich noch ein txt. Feld geöffnet mit Extra

Code:

OTL Extras logfile created on: 18.06.2012 20:33:47 - Run 1
OTL by OldTimer - Version 3.2.49.0    Folder = C:\Users\Désirée\Desktop
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,97 Gb Total Physical Memory | 1,62 Gb Available Physical Memory | 54,73% Memory free
5,93 Gb Paging File | 4,23 Gb Available in Paging File | 71,28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287,90 Gb Total Space | 204,92 Gb Free Space | 71,18% Space Free | Partition Type: NTFS
 
Computer Name: DÉSIRÉE-PC | User Name: Désirée | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-2186960431-4147355705-1044024285-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView] -- "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AntiVirusDisableNotify" = 
"AntiVirusOverride" = 
"FirewallDisableNotify" = 
"FirewallOverride" = 
"FirstRunDisabled" = 
"UpdatesDisableNotify" = 
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A856A96-0E60-4FF6-887D-22DC0461EFB1}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1C78DD65-B0AD-42B7-B590-15CF0212BAD6}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{241281B4-B2F1-4D41-90B6-32ACB1F69CFF}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{299F60D4-9F34-4AAB-83FD-91B2F998279A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3AB1C18D-ED1C-4822-9E7A-832AA9D7C092}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{474DE441-0A05-4B5C-9220-C9A193C630D0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{51CD27CE-2C39-4C1D-94D3-3C1DA7998738}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7962C641-E45E-407F-8AB1-3DE86620C803}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{A5B53AC2-4C69-4F47-97E7-BF0522A759DC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{EBEE25F0-FAB7-47DE-8D25-22974A95CBC9}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{F271E040-887A-47C2-A592-5A8291CA86BB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F6F1751A-A79F-4F79-930E-685ED93F82C0}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{114F3F74-B256-4787-97BC-33827AD07C96}" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires ii\empires2.exe |
"{115EBC29-15F3-4CF6-9550-5DA94AB0CB28}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbtray.exe |
"{1867819E-4D61-47F8-8825-9509B9F442EF}" = protocol=17 | dir=in | app=c:\program files\icq7.6\icq.exe |
"{2A6AAC85-7912-42FD-B6B5-45F3FC3DDE03}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{3C29F58C-BFF1-4427-A241-4CB262E1D303}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbtray.exe |
"{4445923A-51C9-4B99-8C81-B7D23094FC43}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbstreamerclient.exe |
"{4F4AA147-B235-4931-B079-E177F943A1D6}" = protocol=6 | dir=in | app=c:\program files\epsonnet\epsonnet setup\tool10\eneasyapp.exe |
"{5BA90539-4F92-445C-BAB9-C0801AC145B0}" = protocol=17 | dir=in | app=c:\program files\icq7.6\icq.exe |
"{63BC782B-C125-4093-A414-40CFF5C3B216}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orb.exe |
"{74ADD526-B956-45C1-858C-E3DC5ECE2CFC}" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires ii\empires2.exe |
"{7D35A6F3-97D3-4351-A45E-D6598F33B205}" = protocol=6 | dir=in | app=c:\program files\icq7.6\icq.exe |
"{7E8F8FE6-7156-44BF-86BE-A1C383625CD0}" = protocol=6 | dir=in | app=c:\program files\icq7.6\icq.exe |
"{7E958B4C-9F80-48E7-9D3A-39ABE32A05DF}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbstreamerclient.exe |
"{AAB11701-0E4C-4C76-952C-8B8BDA4EB2A7}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orb.exe |
"{AAF98277-BE3F-44BB-9D3C-8D6F80257043}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{ACE93134-483C-4EE4-9FC5-D12966439BF3}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbir.exe |
"{ACEBA1BD-2559-454F-92C6-F270A595697D}" = protocol=17 | dir=in | app=c:\program files\epsonnet\epsonnet setup\tool10\eneasyapp.exe |
"{E0A14A05-9F7C-40F4-9675-A1558DFD3725}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbir.exe |
"{F62FFA5D-A169-4DC2-90C5-A1BAA8A1069F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"TCP Query User{207A4643-581A-4694-974B-B9FC1E750F1A}C:\program files\hercules\classic silver\station2.exe" = protocol=6 | dir=in | app=c:\program files\hercules\classic silver\station2.exe |
"TCP Query User{22ED64D2-09D3-443A-8A51-82F2789A39B2}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe |
"TCP Query User{2D2273A4-92CB-4C65-A98E-8E9F2A4721F9}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{514C700C-BF01-4EC2-98B7-19AAF645B7C0}C:\program files\icq7.6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.6\icq.exe |
"TCP Query User{6AD76A7A-B702-4E69-9378-760B8D72A423}C:\program files\microsoft games\age of mythology\aomx.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of mythology\aomx.exe |
"TCP Query User{7D6B50BB-9502-40DA-8ABA-5EC8B2907E31}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"TCP Query User{7E4247D9-C96B-4B94-AF25-4D228F28BD6E}C:\program files\pidgin\pidgin.exe" = protocol=6 | dir=in | app=c:\program files\pidgin\pidgin.exe |
"TCP Query User{9B52853B-82A0-47D1-978B-5655DE7EF442}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe |
"TCP Query User{A22EC8F5-7010-4FDA-91C8-561B62BDE518}C:\program files\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files\winamp\winamp.exe |
"TCP Query User{B8FA938C-0F4F-4370-B170-A24B3C7DCBDF}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"TCP Query User{BF0792BC-80AC-44D6-934E-308321740632}C:\program files\microsoft games\age of empires ii\empires2.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires ii\empires2.exe |
"TCP Query User{BFEB01EB-5738-452B-A3B2-217F78D37644}C:\program files\motorola\software update\msu.exe" = protocol=6 | dir=in | app=c:\program files\motorola\software update\msu.exe |
"TCP Query User{CD858252-F0F4-4E31-8E27-50099B21D38F}C:\program files\icq7.2\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe |
"TCP Query User{E2CB4EA1-C690-47F8-BBF0-F7C83C0CFF76}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{EDF4C77E-97C0-4303-A378-EBE8906F01F0}C:\sierra\empire earth\empire earth.exe" = protocol=6 | dir=in | app=c:\sierra\empire earth\empire earth.exe |
"UDP Query User{07D303A8-43D9-454A-8F2B-B3B7C40292A4}C:\program files\icq7.6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.6\icq.exe |
"UDP Query User{2243B06C-8CA2-4BAC-9164-5700253D3DD1}C:\program files\microsoft games\age of empires ii\empires2.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires ii\empires2.exe |
"UDP Query User{296A90CC-8063-4861-A285-6A2434155589}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{3F79BD21-BE4F-4B8B-90B6-4DA58FD6F11F}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"UDP Query User{4A187488-D37F-464C-B710-A5C19F17D420}C:\program files\icq7.2\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe |
"UDP Query User{56166790-0F64-40B4-9205-B53F2F0C3F45}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"UDP Query User{570BF5E4-73B5-465F-BCCB-F61D64674457}C:\program files\hercules\classic silver\station2.exe" = protocol=17 | dir=in | app=c:\program files\hercules\classic silver\station2.exe |
"UDP Query User{5E0FDF54-CEAD-419F-B46E-BC5B7407C784}C:\sierra\empire earth\empire earth.exe" = protocol=17 | dir=in | app=c:\sierra\empire earth\empire earth.exe |
"UDP Query User{71C4D9FA-12D3-4FE3-82FB-7A1DAA138291}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe |
"UDP Query User{887CB083-7C1B-4A3D-AAF1-474D830EF529}C:\program files\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files\winamp\winamp.exe |
"UDP Query User{9C37C768-393A-4F7F-BD9E-B5996A80B336}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{BA975B7F-1ED4-40C4-8DDA-FEA8E9176CB3}C:\program files\motorola\software update\msu.exe" = protocol=17 | dir=in | app=c:\program files\motorola\software update\msu.exe |
"UDP Query User{D6D73627-2FB8-4919-BC3A-BF397A474FBD}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe |
"UDP Query User{F086935D-13BC-4BEC-8C11-1665CFF080B3}C:\program files\microsoft games\age of mythology\aomx.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of mythology\aomx.exe |
"UDP Query User{F8D58265-8FAE-41AB-9672-588D22338997}C:\program files\pidgin\pidgin.exe" = protocol=17 | dir=in | app=c:\program files\pidgin\pidgin.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony Video Shared Library
"{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}" = Epson Event Manager
"{0534F8BF-EBFD-004B-5DED-1010CBF353B8}" = CCC Help Dutch
"{068F037B-2723-48E3-85F1-4D7D93A29D2A}" = VAIO Content Metadata Intelligent Analyzing Manager
"{0A1B60E0-F250-BD91-79C9-C29B9C05A5AA}" = Catalyst Control Center InstallProxy
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{13C5C85D-3CD9-DF9C-77A9-8173781CD170}" = CCC Help Spanish
"{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}" = Primo
"{16BAB4DD-34F6-EBC5-F40B-72146464CDE0}" = Catalyst Control Center Core Implementation
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{190CD8ED-D83B-EB89-9BE9-8CC04569A4CB}" = CCC Help Thai
"{19B683DF-B562-4C0B-8AAA-2A92409D190A}" = Sony Home Network Library
"{1D76A52C-87A6-4AB0-A7B0-08C8D5DF1D75}" = Motorola Mobile Drivers Installation 5.2.0
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2018C019-30D9-4240-8C01-0865C10DCF5A}" = Unterstützung für VAIO-Präsentation
"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for VAIO
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{209DF55F-5E5C-48A3-BC3D-A7CB1224458C}" = HP Print Diagnostic Utility
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23825B69-36DF-4DAD-9CFD-118D11D80F16}" = VAIO Content Folder Setting
"{2447500B-22D7-47BD-9B13-1A927F43A267}" = Empire Earth
"{24504135-0D50-4842-A3AE-CC44CFA4FF74}_is1" = Dr. Watson - Katakomben
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{26C05EE9-C5C7-F22C-A298-B97926F36E3E}" = CCC Help Turkish
"{2878C3C9-9D91-430F-8F50-885BB23DB001}" = VAIO Content Folder Watcher
"{2B5DDB2D-053E-F1C8-3234-DAE9FCF4B318}" = CCC Help Finnish
"{2EF15529-A351-FDFA-C393-491483B04784}" = CCC Help Italian
"{310C1558-F6B5-4889-98B0-7471966BA7F2}" = Epson Easy Photo Print 2
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{327B75F0-92AF-420A-988F-FA596A218E0B}" = VAIO Content Folder Watcher
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3B659FAD-E772-44A3-B7E7-560FF084669F}" = VAIO Smart Network
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{43112A37-7CDD-745A-6EB4-9A9BA982DB2A}" = CCC Help English
"{47A2CE5C-EA1F-4F58-8A0A-9452CBA795CD}" = Click to Disc
"{486CC64F-030A-4C9A-8716-87E26D28FKQ1}_is1" = King's Quest I: Quest for the Crown (4.1c)
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4DCB123A-6DD2-8436-2FBA-0244ADF65F42}" = CCC Help Russian
"{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}" = Click to Disc Editor
"{52210D57-0B1F-4681-90DD-8659DF4BCC40}" = Moorhuhn Remake
"{52A7C6A6-6B88-47D1-922E-9F8A7E089E6A}" = Intel(R) PROSet/Wireless WiFi-Software
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{52D93C83-FDEA-D1B2-5185-D1271DC15C6C}" = Catalyst Control Center Localization All
"{52E51086-747D-AEB9-B440-14B84CC247E0}" = Catalyst Control Center Graphics Light
"{54CC8FFD-0F64-07B4-EFC1-40C0449F4B85}" = ccc-utility
"{568D1DC1-4038-BF79-E58D-81311FD41F91}" = CCC Help Greek
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync
"{596BED91-A1D8-4DF1-8CD1-1C777F7588AC}" = VAIO DVD Menu Data Basic
"{5E6D6161-5509-4f55-9372-1E01792F843A}" = F300_Help
"{5F5867F0-2D23-4338-A206-01A76C823924}" = VAIO Energie Verwaltung
"{62F7DA7E-CCCB-439C-A760-00C3926E761F}" = Microsoft Works
"{64DBE9FE-A07D-41A0-B81A-8D416D9647FF}" = VAIO Content Folder Watcher
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{68A69CFF-130D-4CDE-AB0E-7374ECB144C8}" = Click to Disc
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69C8B1E3-2665-4A0F-B049-67746E5C4CE3}" = Software Info for Me&My VAIO
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6FA8BA2C-052B-4072-B8E2-2302C268BE9E}" = VAIO Movie Story Template Data
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72042FA6-5609-489F-A8EA-3C2DD650F667}" = VAIO Control Center
"{7644E42D-B096-457F-8B5B-901238FC81AE}" = ICQ7.6
"{76D7CCD6-8369-405C-B494-5F34FAE67249}" = Me&My VAIO
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77217D44-363B-9BF6-04F8-FE432D9AFE35}" = CCC Help Czech
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7B79CD75-F848-4B33-83E3-0EE1A1805A8C}" = VAIO Movie Story
"{7BB90344-0647-468E-925A-7F69F7983421}" = ArcSoft Magic-i Visual Effects 2
"{7C3228AC-BDE5-448E-8C01-E39BB0782DE8}" = Motorola Software Update
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83CDA18E-0BF3-4ACA-872C-B4CDABF2360E}" = VAIO Update 4
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie
"{8678BD65-D66E-48BB-8531-91D0EF8998A1}" = Hercules Classic Silver
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{88E1A4BD-995D-EB00-26E5-9BEFA9E213A6}" = CCC Help Polish
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A120CC0-95C6-DEEF-F60B-8B0866660920}" = CCC Help Hungarian
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8DE50158-80AA-4FF2-9E9F-0A7C46F71FCD}" = VAIO Media plus
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90124382-85E3-DE67-F0F7-4C37B7040BF4}" = CCC Help Chinese Standard
"{914B46A6-7C4B-3AA2-DFF7-E39EB5F7141E}" = Skins
"{9238E8A4-BEBA-43A3-B926-769BDBF194C5}" = VAIO Media plus Opening Movie
"{948FD689-B34E-5A26-F926-111A1A74A43D}" = CCC Help Japanese
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{96D0B6C6-5A72-4B47-8583-A87E55F5FE81}" =
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{98FC7A64-774B-49B5-B046-4B4EBC053FA9}" = VAIO MusicBox Sample Music
"{9973498D-EA29-4A68-BE0B-C88D6E03E928}" = ArcSoft WebCam Companion 2
"{99A9CE2D-DFB1-3277-D1C7-5C34C21179EF}" = ccc-core-static
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A44DC8C-13C7-6ADE-3516-C1FEDC0267F8}" = CCC Help Swedish
"{9A4FBD51-811D-33E9-116B-D26C662B588C}" = CCC Help Norwegian
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{9EAC0E21-510E-4259-A9C6-F5D5B8969036}" = Catalyst Control Center - Branding
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Alps Pointing-device for VAIO
"{A17E786D-ACC6-8D11-8B25-D83AB85B6534}" = CCC Help German
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
"{A63E7492-A0BC-4BB9-89A7-352965222380}" = VAIO Original Function Setting
"{A7496F46-78AE-4DB2-BCF5-95F210FA6F96}" = Windows Live Movie Maker
"{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}" = Setting Utility Series
"{A9D3D707-4A1A-4227-BE6E-F16448B4CB63}" = VAIO Entertainment Platform
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player
"{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B0A8D303-1077-43FF-B8E0-E69E0516BEAA}" = Power-Druckstudio
"{B12F3362-A328-9499-949A-A95C6EF21CB6}" = Catalyst Control Center Graphics Previews Vista
"{B25563A0-41F4-4A81-A6C1-6DBC0911B1F3}" = VAIO Movie Story
"{B2D55EB8-32C5-4B43-9006-9E97DECBA178}" = Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{BFD85D24-D4F3-4CCC-B518-D7C4FC29C76D}" = VAIO Content Metadata Intelligent Analyzing Manager
"{C144CB60-EE5D-B625-C672-176AC5B488D2}" = ATI Catalyst Install Manager
"{C1555BC5-88B1-466B-BC79-062B5715DF92}" = VAIO Content Metadata XML Interface Library
"{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1" = Uniblue DriverScanner
"{C4567E61-7997-5F6A-0A4B-F667328D3ED3}" = Catalyst Control Center Graphics Previews Common
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C62AEA0E-90B0-4049-9780-8499A18A34D7}" = VAIO Content Metadata Manager Setting
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C7477742-DDB4-43E5-AC8D-0259E1E661B1}" = VAIO Event Service
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{C9D8A041-2963-4B31-8FFC-1500F3DB9293}" = EpsonNet Setup 3.3
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{CD77F1C7-9A53-0883-F660-2FE859B47BAA}" = Catalyst Control Center Graphics Full Existing
"{CD7E6232-D41D-4E5B-ABE1-0264B6260309}" = VAIO Content Metadata Intelligent Analyzing Manager
"{CE2121C6-C94D-4A73-8EA4-6943F33EE335}" = Music Transfer
"{D03D02D8-AB64-4785-A48E-5AA8B0FB8C14}" = Sony Home Network Library
"{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{D60F97EC-EF06-4E1E-B0D1-C2CBABA62FA3}" = VAIO Wallpaper Contents
"{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime
"{DEF97A70-C67D-41E1-837C-6462C97A6F65}" = OpenMG Secure Module 5.3.00
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E3453B1B-C91B-4C48-B046-8DF635DD46F2}" = VAIO Content Metadata XML Interface Library
"{E3E86D88-6370-73DA-29F9-D09D43337688}" = CCC Help Korean
"{E412146D-4D11-3363-804E-096D51988B69}" = CCC Help Portuguese
"{E6FE96CE-99C3-42DE-AD9B-E0A63BD7805D}_is1" = FastestTube-1.2.8.7
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{E848C9C0-E6FF-4A3F-9D67-AE53AC3628FE}" = SweetIM for Messenger 2.7
"{E9F6CD2A-CF41-6442-CB8A-34665511BFC8}" = CCC Help Chinese Traditional
"{EADE97A7-E7AA-43FD-A042-92A68E0187A6}" = VAIO Content Metadata Manager Setting
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{EBF8380D-8B72-6938-923A-5891703BCB4E}" = CCC Help Danish
"{ED0CFA85-9E9F-67B4-89C4-A07C42D51FB3}" = Catalyst Control Center Graphics Full New
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EEFE8A83-8D7E-21AF-F1C6-D617DC6D5455}" = CCC Help French
"{EFCEF949-9821-4759-A573-3EB8C857DF46}" = Windows Live Family Safety
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1568757-E564-4cb5-8980-9333119A4384}" = F300
"{F570A6CC-53ED-4AA9-8B08-551CD3E38D8B}" =
"{F6AC5364-2FB7-437a-811A-D645F22AA6AC}" = F300Trb
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F9000000-0018-0000-0000-074957833700}" = ABBYY FineReader 9.0 Sprint
"{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}" = Vista Codec Package
"{FB1AC1F1-8F47-4DCE-A1ED-0DFBA0F455B4}" = Driver Mender
"{FD4FE0F7-91FC-43A2-9C3A-187553991FFF}" = Hercules Classic Silver Webcam
"{FE163F11-1919-4257-A280-FF5AF8DAEECB}" = ICQ Sparberater
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 4.65
"ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Aerie: Seele des Waldes" = Aerie: Seele des Waldes
"Age of Empires" = Microsoft Age of Empires
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires Expansion 1.0" = Microsoft Age of Empires Expansion
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"Age of Mythology 1.0" = Age of Mythology
"Age of Mythology Expansion Pack 1.0" = Age of Mythology - The Titans Expansion
"Age Of Oracles: Tara’s Journey" = Age Of Oracles: Tara’s Journey
"Alamandi" = Alamandi
"Alice im Wunderland" = Alice im Wunderland
"Annabel" = Annabel
"Avira AntiVir Desktop" = Avira Free Antivirus
"Brunhilda" = Brunhilda
"Dark Strokes: Die Sünden der Väter" = Dark Strokes: Die Sünden der Väter
"Das Reich des Drachen" = Das Reich des Drachen
"Das Verlorene Königreich: Die Prophezeiung" = Das Verlorene Königreich: Die Prophezeiung
"Das Vermächtnis des Einhorns" = Das Vermächtnis des Einhorns
"Deadtime Stories" = Deadtime Stories
"Der Blutschwur" = Der Blutschwur
"Die Sage von Kolossus" = Die Sage von Kolossus
"Die Wiege Olympias 2" = Die Wiege Olympias 2
"Die Wiege Roms 2" = Die Wiege Roms 2
"Dr. Lynch: Grave Secrets" = Dr. Lynch: Grave Secrets
"DSGPlayer" = DEUTSCHLAND SPIELT GAME CENTER
"dt icon module" =
"Echos des Kummers" = Echos des Kummers
"Empress of the Deep" = Empress of the Deep
"Empress of the Deep 2 Sammleredition" = Empress of the Deep 2 Sammleredition
"EPSON Scanner" = EPSON Scan
"EPSON SX525WD Series" = EPSON SX525WD Series Printer Uninstall
"EPSON SX525WD Series Manual" = EPSON SX525WD Series Handbuch
"EPSON SX525WD Series Network Guide" = EPSON SX525WD Series Netzwerk-Handbuch
"ESET Online Scanner" = ESET Online Scanner v3
"Eternity" = Eternity
"Farm Craft" = Farm Craft
"FastestTube" = FastestTube
"Fiona Finch" = Fiona Finch
"Fluch der Pharaonen" = Fluch der Pharaonen
"Flucht aus dem Paradies" = Flucht aus dem Paradies
"Flucht aus dem Paradies 2" = Flucht aus dem Paradies 2
"Free Image Convert and Resize_is1" = Free Image Convert and Resize version 2.1.13.920
"Free Studio_is1" = Free Studio version 4.2
"Free Video to Motorola Phones Converter_is1" = Free Video to Motorola Phones Converter version 2.3.1.727
"Free Video to MP3 Converter_is1" = Free Video to MP3 Converter version 3.2
"Free YouTube Download_is1" = Free YouTube Download version 2.10.29
"Garten-Glück" = Garten-Glück
"Google Desktop" = Google Desktop
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"ICQToolbar" = ICQ Toolbar
"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for VAIO
"InstallShield_{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}" = Click to Disc Editor
"InstallShield_{DEF97A70-C67D-41E1-837C-6462C97A6F65}" = OpenMG Secure Module 5.3.00
"IrfanView" = IrfanView (remove only)
"Jack of all Tribes" = Jack of all Tribes
"Kaiser - das Erbe" = Kaiser - das Erbe
"Mad Robots_is1" = Mad Robots 3000
"Magic Encyclopedia: Illusionen" = Magic Encyclopedia: Illusionen
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400
"Maniac Mansion Deluxe" = Maniac Mansion Deluxe
"Margrave: Der Fluch des gebrochenen Herzens" = Margrave: Der Fluch des gebrochenen Herzens
"MarketingTools" = VAIO Marketing Tools
"Masquerade Mysteries" = Masquerade Mysteries
"Mein Gartenparadies" = Mein Gartenparadies
"Mein Gartenparadies: Frühlingserwachen" = Mein Gartenparadies: Frühlingserwachen
"Meine kleine Farm" = Meine kleine Farm
"Meine kleine Farm 3: Russisches Roulette" = Meine kleine Farm 3: Russisches Roulette
"MFU Module" =
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Midnight Mysteries" = Midnight Mysteries
"Midnight Mysteries: Salem Witch Trials" = Midnight Mysteries: Salem Witch Trials
"Miriel" = Miriel
"MotoHelper" = MotoHelper 2.0.53 Driver 5.2.0
"Mozilla Firefox 12.0 (x86 de)" = Mozilla Firefox 12.0 (x86 de)
"Mozilla Thunderbird 12.0.1 (x86 de)" = Mozilla Thunderbird 12.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Mr. Jones Grabgeflüster" = Mr. Jones Grabgeflüster
"Nightfall Mysteries: Der Fluch der Oper" = Nightfall Mysteries: Der Fluch der Oper
"Nightfall Mysteries: Die Ashburg-Verschwörung" = Nightfall Mysteries: Die Ashburg-Verschwörung
"Pidgin" = Pidgin
"Pingus" = Pingus
"Pioneer Lands" = Pioneer Lands
"Pixillion" = Pixillion Imagedatei-Konverter
"PokerStars.net" = PokerStars.net
"ProInst" = Intel PROSet Wireless
"Robbox_is1" = Robbox
"Robin’s Quest: Aufstieg einer Legende" = Robin’s Quest: Aufstieg einer Legende
"Robinson Crusoe und der Piratenfluch" = Robinson Crusoe und der Piratenfluch
"Sacra Terra: Nacht der Engel" = Sacra Terra: Nacht der Engel
"Sarah’s Ranch" = Sarah’s Ranch
"Spirit of Wandering" = Spirit of Wandering
"Startpage24" = Startpage24
"SuperTux_is1" = SuperTux 0.1.3
"SYBEX-Verlag GmbH - Zitate" = SYBEX-Verlag GmbH - Zitate
"Tarot des Schicksals" = Tarot des Schicksals
"The Enchanted Kingdom: Elisa’s Adventure" = The Enchanted Kingdom: Elisa’s Adventure
"The Island: Castaway" = The Island: Castaway
"The Island: Castaway 2" = The Island: Castaway 2
"Twisted Lands: Die Schattenstadt" = Twisted Lands: Die Schattenstadt
"Uninstall_is1" = Uninstall 1.0.0.1
"VAIO Help and Support" =
"Vampireville" = Vampireville
"Vampirsaga: Willkommen in Hell Lock" = Vampirsaga: Willkommen in Hell Lock
"wdfs2008_is1" = WISSEN DIGITAL 3D Führerschein Trainer 2009
"Webfettibar Uninstall" = Webfetti
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar
"WinLiveSuite_Wave3" = Windows Live Essentials
"Wormux" = Wormux
"Youda Fairy" = Youda Fairy
"Youda Survivor" = Youda Survivor
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-2186960431-4147355705-1044024285-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater
"Winamp Detect" = Winamp Erkennungs-Plug-in
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 18.02.2012 15:23:59 | Computer Name = Désirée-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 18.02.2012 15:24:08 | Computer Name = Désirée-PC | Source = VzCdbSvc | ID = 7
Description = Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})
 (Fehlercode = 0x80042019)
 
Error - 26.02.2012 05:44:05 | Computer Name = Désirée-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 26.02.2012 05:44:11 | Computer Name = Désirée-PC | Source = VzCdbSvc | ID = 7
Description = Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})
 (Fehlercode = 0x80042019)
 
Error - 26.02.2012 08:33:04 | Computer Name = Désirée-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: VcmIAlzMgr.exe, Version: 3.4.0.13190,
 Zeitstempel: 0x4973f725  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0,
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0152ec21  ID des fehlerhaften
 Prozesses: 0xbd0  Startzeit der fehlerhaften Anwendung: 0x01ccf46b290289a9  Pfad der
 fehlerhaften Anwendung: C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
Pfad
 des fehlerhaften Moduls: unknown  Berichtskennung: 0701916f-6076-11e1-9480-002433d377d6
 
Error - 09.03.2012 13:06:19 | Computer Name = Désirée-PC | Source = Application Hang | ID = 1002
Description = Programm firefox.exe, Version 10.0.2.4428 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 154    Startzeit:
01ccf483142f48ea    Endzeit: 170    Anwendungspfad: C:\Program Files\Mozilla Firefox\firefox.exe

Berichts-ID:
 2810c737-6a0a-11e1-9480-002433d377d6 
 
Error - 14.03.2012 15:26:37 | Computer Name = Désirée-PC | Source = System Restore | ID = 8193
Description =
 
Error - 15.03.2012 12:21:22 | Computer Name = Désirée-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 15.03.2012 12:21:30 | Computer Name = Désirée-PC | Source = VzCdbSvc | ID = 7
Description = Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})
 (Fehlercode = 0x80042019)
 
Error - 31.03.2012 03:01:43 | Computer Name = Désirée-PC | Source = Application Hang | ID = 1002
Description = Programm VAIOUpdt.exe, Version 4.1.0.12040 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 120c    Startzeit:
 01cd02c7b6c74719    Endzeit: 61    Anwendungspfad: C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe

Berichts-ID:
 4c03a961-7aff-11e1-9526-002433d377d6 
 
Error - 12.04.2012 15:43:00 | Computer Name = Désirée-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 12.04.2012 15:43:09 | Computer Name = Désirée-PC | Source = VzCdbSvc | ID = 7
Description = Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})
 (Fehlercode = 0x80042019)
 
[ Media Center Events ]
Error - 17.01.2010 07:21:43 | Computer Name = Désirée-PC | Source = MCUpdate | ID = 0
Description = 12:21:42 - Fehler beim Herstellen der Internetverbindung.  12:21:42
-    Serververbindung konnte nicht hergestellt werden.. 
 
[ System Events ]
Error - 14.06.2012 14:41:29 | Computer Name = Désirée-PC | Source = atikmdag | ID = 43029
Description = Display is not active
 
Error - 14.06.2012 15:13:29 | Computer Name = Désirée-PC | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter
 
Error - 14.06.2012 15:13:29 | Computer Name = Désirée-PC | Source = atikmdag | ID = 43029
Description = Display is not active
 
Error - 14.06.2012 21:49:38 | Computer Name = Désirée-PC | Source = DCOM | ID = 10010
Description =
 
Error - 14.06.2012 21:49:36 | Computer Name = Désirée-PC | Source = atikmdag | ID = 43029
Description = Display is not active
 
Error - 15.06.2012 15:56:06 | Computer Name = Désirée-PC | Source = atikmdag | ID = 43029
Description = Display is not active
 
Error - 16.06.2012 13:10:53 | Computer Name = Désirée-PC | Source = atikmdag | ID = 43029
Description = Display is not active
 
Error - 17.06.2012 09:33:07 | Computer Name = Désirée-PC | Source = atikmdag | ID = 43029
Description = Display is not active
 
Error - 18.06.2012 14:27:56 | Computer Name = Désirée-PC | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst AntiVirSchedulerService erreicht.
 
Error - 18.06.2012 14:27:57 | Computer Name = Désirée-PC | Source = atikmdag | ID = 43029
Description = Display is not active
 
 
< End of report >


cosinus 18.06.2012 21:44

Zitat:

Ist das OTL personifiziert oder allg. Gültig??
Ist diese Frage ernst gemeint? Was verstehst du unter allgemein gültig bzw. personifiziert?
Nur mal so, falls du das meinst: jeder Rechner hat ein anderes OTL-Log!
Wenn jedes System immer dasselbe Log ausspuckt, würde es auch nciht viel Sinn machen, jedem das Log erstellen zu lassen weil es ja eh vorhersagbar ist was drinsteht - oder hab ich dich völlig falsch verstanden?

magicfortune 19.06.2012 18:10

Das habe ich ja gemeint.

Wollte nur ein wenig verstehen was Ihr da macht. So gut kenne ich mich mit Viren etc auch nicht aus. :P

MfG
magicfortunge

cosinus 19.06.2012 23:07

Naja es versteht sich schon von selbst. Wenn jedes OTL-Log auf jedem Rechner identisch wäre, müssten wir kaum den Aufwand betreiben auch auf jedem Rechner so ein Log neu zu erstellen das Log stünde ja von vornherein fest! :uglyhammer:


Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKLM\..\SearchScopes,DefaultScope = {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - No CLSID value found
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes,DefaultScope = {6552C7DD-90A4-4387-B795-F8F96747DE19}
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=CDS&o=16225&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=QQ&apn_dtid=YYYYYYYYDE&apn_uid=6789FF94-1B5C-418F-AB67-D056611F19BA&apn_sauid=B0654D97-0C66-4B09-B061-B47EE50BE6D3
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = http://127.0.0.1:4664/search&s=0-PzDPaY_dvVM8njmJBRCbTWtEk?q={searchTerms}
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA74C8}: "URL" = http://www.searchqu.com/web?src=ieb&q={SearchTerms}
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{A2DC3FEF-AB4D-442c-8517-34EC6E125C8D}: "URL" = http://search.webwebweb.com/search.php?query={searchTerms}&lang=de&zip=&town=&site=&country=
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
IE - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\SearchScopes\Live Search: "URL" = http://search.live.com/results.aspx?q={searchTerms}&mkt=de-DE&FORM=MICGLV
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.11.3.15590
FF - prefs.js..extensions.enabledItems: ffext@webwebweb:1.0.0.449
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=CDS&o=16225&locale=en_US&apn_uid=6789FF94-1B5C-418F-AB67-D056611F19BA&apn_ptnrs=QQ&apn_sauid=B0654D97-0C66-4B09-B061-B47EE50BE6D3&apn_dtid=YYYYYYYYDE&&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "http://start.icq.com/"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&q="
[2010.09.16 19:48:38 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010.06.15 17:37:06 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.05.18 20:00:22 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012.03.28 20:46:06 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.12.19 21:52:59 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.10.16 13:34:48 | 000,000,000 | ---D | M] (Webfetti) -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\7dffxtbr@Webfetti.com
[2012.05.24 22:42:22 | 000,000,000 | ---D | M] ("Ask Toolbar") -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\toolbar@ask.com
[2012.06.14 21:48:04 | 000,002,572 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\askcom.xml
[2012.06.10 16:55:55 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-1.xml
[2011.12.18 20:03:20 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-10.xml
[2012.01.02 21:24:32 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-11.xml
[2012.01.18 23:27:21 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-12.xml
[2012.02.18 21:29:21 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-13.xml
[2012.02.26 11:15:12 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-14.xml
[2012.02.26 11:22:54 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-15.xml
[2012.03.28 20:46:12 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-16.xml
[2012.05.06 10:51:49 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-17.xml
[2012.05.13 13:48:01 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-18.xml
[2012.06.08 21:04:19 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-19.xml
[2011.06.16 10:34:03 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-2.xml
[2011.08.02 15:23:19 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-3.xml
[2011.08.26 18:29:56 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-4.xml
[2011.09.11 19:14:01 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-5.xml
[2011.09.15 10:34:20 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-6.xml
[2011.10.01 16:04:14 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-7.xml
[2011.10.11 19:50:07 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-8.xml
[2011.11.09 21:37:04 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-9.xml
[2011.03.30 15:14:34 | 000,001,042 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin.xml
[2009.08.11 19:23:35 | 000,003,915 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\sweetim.xml
[2011.06.20 23:33:06 | 000,005,218 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\webwebweb.xml
[2009.08.30 16:24:26 | 000,001,201 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\winamp-search.xml
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (WebWebWeb) - {BBD43808-9D13-4B0B-B023-178FD1FAE442} - C:\Program Files\WebWebWeb\Plugin\Version_449\link64_plugin.dll File not found
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (ICQ Sparberater) - {FE163F11-1919-4257-A280-FF5AF8DAEECB} - C:\Programme\icq\Internet Explorer\icq.dll (solute gmbh)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{4a250eb5-82ae-11de-87e0-002433d377d6}\Shell - "" = AutoRun
O33 - MountPoints2\{4a250eb5-82ae-11de-87e0-002433d377d6}\Shell\AutoRun\command - "" = G:\autorun.exe
[2012.06.08 19:00:30 | 000,000,000 | ---D | C] -- C:\Users\Désirée\AppData\Roaming\Rhiycqnu
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:6017A808
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:6425A235
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:270A3983
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:5E9B629B
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:7FCB9D0D
:Files
C:\Programme\ICQ6Toolbar
C:\Programme\Ask.com
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

magicfortune 21.06.2012 19:11

Habe deine Anweisungen befolgt.

Es kommt aber immer wieder zu einen Absturz, kurz nach dem ich Fix gedrückt habe.


A Problem has been detected and windows has been shut down to previos to your computer.
A process or thread crucial to system has unexpedtly end terminated.
This is the first time you´ve seen the stop error screen, Start your computer if you see this errer again.


Habe ich was falsch gemacht???

cosinus 21.06.2012 19:47

Starte Windows neu im abgesicherten Modus (mit Netzwerktreibern nach Möglichkeit), manchmal hakt das Fixen mit OTL im normalen Modus aber sehr oft funktioniert der Fix im abgesicherte Modus.

magicfortune 23.06.2012 08:46

Habe den Pc im abgesicherten Modus mit und ohne Netzwerkfreigabe gestartet.

Bei beiden ist das System kurz nach dem Klick auf dem Fix-Button abgestürzt, wieder mit der Fehlermeldung.

Hätte ich beim OTL noch irgenwelche Häkchen o.ä machen müssen.
Habe nur alle Benutzer haken gemacht.

mfg
magicfortune

cosinus 24.06.2012 16:10

Probier es bitte mit diesem Sckript aus

Code:

:OTL
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.11.3.15590
FF - prefs.js..extensions.enabledItems: ffext@webwebweb:1.0.0.449
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=CDS&o=16225&locale=en_US&apn_uid=6789FF94-1B5C-418F-AB67-D056611F19BA&apn_ptnrs=QQ&apn_sauid=B0654D97-0C66-4B09-B061-B47EE50BE6D3&apn_dtid=YYYYYYYYDE&&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "http://start.icq.com/"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&q="
[2010.09.16 19:48:38 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010.06.15 17:37:06 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.05.18 20:00:22 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012.03.28 20:46:06 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.12.19 21:52:59 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.10.16 13:34:48 | 000,000,000 | ---D | M] (Webfetti) -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\7dffxtbr@Webfetti.com
[2012.05.24 22:42:22 | 000,000,000 | ---D | M] ("Ask Toolbar") -- C:\Users\Désirée\AppData\Roaming\mozilla\Firefox\Profiles\gjpz37rw.default\extensions\toolbar@ask.com
[2012.06.14 21:48:04 | 000,002,572 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\askcom.xml
[2012.06.10 16:55:55 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-1.xml
[2011.12.18 20:03:20 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-10.xml
[2012.01.02 21:24:32 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-11.xml
[2012.01.18 23:27:21 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-12.xml
[2012.02.18 21:29:21 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-13.xml
[2012.02.26 11:15:12 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-14.xml
[2012.02.26 11:22:54 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-15.xml
[2012.03.28 20:46:12 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-16.xml
[2012.05.06 10:51:49 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-17.xml
[2012.05.13 13:48:01 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-18.xml
[2012.06.08 21:04:19 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-19.xml
[2011.06.16 10:34:03 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-2.xml
[2011.08.02 15:23:19 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-3.xml
[2011.08.26 18:29:56 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-4.xml
[2011.09.11 19:14:01 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-5.xml
[2011.09.15 10:34:20 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-6.xml
[2011.10.01 16:04:14 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-7.xml
[2011.10.11 19:50:07 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-8.xml
[2011.11.09 21:37:04 | 000,000,950 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin-9.xml
[2011.03.30 15:14:34 | 000,001,042 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\icqplugin.xml
[2009.08.11 19:23:35 | 000,003,915 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\sweetim.xml
[2011.06.20 23:33:06 | 000,005,218 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\webwebweb.xml
[2009.08.30 16:24:26 | 000,001,201 | ---- | M] () -- C:\Users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\searchplugins\winamp-search.xml
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (WebWebWeb) - {BBD43808-9D13-4B0B-B023-178FD1FAE442} - C:\Program Files\WebWebWeb\Plugin\Version_449\link64_plugin.dll File not found
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (ICQ Sparberater) - {FE163F11-1919-4257-A280-FF5AF8DAEECB} - C:\Programme\icq\Internet Explorer\icq.dll (solute gmbh)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{4a250eb5-82ae-11de-87e0-002433d377d6}\Shell - "" = AutoRun
O33 - MountPoints2\{4a250eb5-82ae-11de-87e0-002433d377d6}\Shell\AutoRun\command - "" = G:\autorun.exe
[2012.06.08 19:00:30 | 000,000,000 | ---D | C] -- C:\Users\Désirée\AppData\Roaming\Rhiycqnu
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:6017A808
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:6425A235
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:270A3983
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:5E9B629B
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:7FCB9D0D
:Files
C:\Programme\ICQ6Toolbar
C:\Programme\Ask.com
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]


magicfortune 24.06.2012 17:39

Habe es probiert aber wieder Systemabsturz im normalen und im abgesicherten Modus.

Hier die Fehlermeldung Windows.

Code:

Problemsignatur:
  Problemereignisname:        BlueScreen
  Betriebsystemversion:        6.1.7601.2.1.0.768.3
  Gebietsschema-ID:        1031

Zusatzinformationen zum Problem:
  BCCode:        f4
  BCP1:        00000003
  BCP2:        88151C08
  BCP3:        88151D74
  BCP4:        82A19DF0
  OS Version:        6_1_7601
  Service Pack:        1_0
  Product:        768_1

Dateien, die bei der Beschreibung des Problems hilfreich sind:
  C:\Windows\Minidump\062412-33836-01.dmp
  C:\Users\Désirée\AppData\Local\Temp\WER-61323-0.sysdata.xml

Lesen Sie unsere Datenschutzbestimmungen online:
  hxxp://go.microsoft.com/fwlink/?linkid=104288&clcid=0x0407

Wenn die Onlinedatenschutzbestimmungen nicht verfügbar sind, lesen Sie unsere Datenschutzbestimmungen offline:
  C:\Windows\system32\de-DE\erofflps.txt

vllt. hilft es.

Mfg

magicfortune

cosinus 24.06.2012 17:49

Neuer Versuch:

Code:

:OTL
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (WebWebWeb) - {BBD43808-9D13-4B0B-B023-178FD1FAE442} - C:\Program Files\WebWebWeb\Plugin\Version_449\link64_plugin.dll File not found
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (ICQ Sparberater) - {FE163F11-1919-4257-A280-FF5AF8DAEECB} - C:\Programme\icq\Internet Explorer\icq.dll (solute gmbh)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-2186960431-4147355705-1044024285-1000\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{4a250eb5-82ae-11de-87e0-002433d377d6}\Shell - "" = AutoRun
O33 - MountPoints2\{4a250eb5-82ae-11de-87e0-002433d377d6}\Shell\AutoRun\command - "" = G:\autorun.exe
[2012.06.08 19:00:30 | 000,000,000 | ---D | C] -- C:\Users\Désirée\AppData\Roaming\Rhiycqnu
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:6017A808
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:6425A235
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:270A3983
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:5E9B629B
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:7FCB9D0D
:Files
C:\Programme\ICQ6Toolbar
C:\Programme\Ask.com
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]


magicfortune 24.06.2012 18:14

Hat funktioniert :)

Hier das Log

Code:

========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}\ deleted successfully.
C:\Programme\Winamp Toolbar\winamptb.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBD43808-9D13-4B0B-B023-178FD1FAE442}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBD43808-9D13-4B0B-B023-178FD1FAE442}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
C:\Programme\Ask.com\GenericAskToolbar.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE163F11-1919-4257-A280-FF5AF8DAEECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE163F11-1919-4257-A280-FF5AF8DAEECB}\ deleted successfully.
C:\Programme\icq\Internet Explorer\icq.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully.
C:\Programme\ICQ6Toolbar\ICQToolBar.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}\ deleted successfully.
C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Programme\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}\ deleted successfully.
File C:\Programme\Winamp Toolbar\winamptb.dll not found.
Registry value HKEY_USERS\S-1-5-21-2186960431-4147355705-1044024285-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
Registry value HKEY_USERS\S-1-5-21-2186960431-4147355705-1044024285-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Programme\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_USERS\S-1-5-21-2186960431-4147355705-1044024285-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}\ not found.
File C:\Programme\Winamp Toolbar\winamptb.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater deleted successfully.
C:\Programme\Ask.com\Updater\Updater.exe moved successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4a250eb5-82ae-11de-87e0-002433d377d6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4a250eb5-82ae-11de-87e0-002433d377d6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4a250eb5-82ae-11de-87e0-002433d377d6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4a250eb5-82ae-11de-87e0-002433d377d6}\ not found.
File G:\autorun.exe not found.
C:\Users\Désirée\AppData\Roaming\Rhiycqnu folder moved successfully.
ADS C:\ProgramData\TEMP:6017A808 deleted successfully.
ADS C:\ProgramData\TEMP:6425A235 deleted successfully.
ADS C:\ProgramData\TEMP:270A3983 deleted successfully.
ADS C:\ProgramData\TEMP:5E9B629B deleted successfully.
ADS C:\ProgramData\TEMP:7FCB9D0D deleted successfully.
========== FILES ==========
File\Folder C:\Programme\ICQ6Toolbar not found.
File\Folder C:\Programme\Ask.com not found.
 
OTL by OldTimer - Version 3.2.49.0 log created on 06242012_191335

MfG

magicfortune

cosinus 24.06.2012 18:16

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

magicfortune 24.06.2012 18:37

Ok hier das TDSS Log

Code:

19:32:52.0848 6056        TDSS rootkit removing tool 2.7.41.0 Jun 20 2012 20:53:32
19:32:53.0051 6056        ============================================================
19:32:53.0051 6056        Current date / time: 2012/06/24 19:32:53.0051
19:32:53.0051 6056        SystemInfo:
19:32:53.0051 6056       
19:32:53.0051 6056        OS Version: 6.1.7601 ServicePack: 1.0
19:32:53.0051 6056        Product type: Workstation
19:32:53.0051 6056        ComputerName: DÉSIRÉE-PC
19:32:53.0051 6056        UserName: Désirée
19:32:53.0051 6056        Windows directory: C:\Windows
19:32:53.0051 6056        System windows directory: C:\Windows
19:32:53.0051 6056        Processor architecture: Intel x86
19:32:53.0051 6056        Number of processors: 2
19:32:53.0051 6056        Page size: 0x1000
19:32:53.0051 6056        Boot type: Normal boot
19:32:53.0051 6056        ============================================================
19:32:53.0659 6056        Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
19:32:53.0659 6056        ============================================================
19:32:53.0659 6056        \Device\Harddisk0\DR0:
19:32:53.0659 6056        MBR partitions:
19:32:53.0659 6056        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1462800, BlocksNum 0x23FCBAB0
19:32:53.0659 6056        ============================================================
19:32:53.0722 6056        C: <-> \Device\Harddisk0\DR0\Partition0
19:32:53.0722 6056        ============================================================
19:32:53.0722 6056        Initialize success
19:32:53.0722 6056        ============================================================
19:33:27.0230 6020        ============================================================
19:33:27.0230 6020        Scan started
19:33:27.0230 6020        Mode: Manual; SigCheck; TDLFS;
19:33:27.0230 6020        ============================================================
19:33:27.0666 6020        1394ohci        (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
19:33:27.0776 6020        1394ohci - ok
19:33:27.0932 6020        ABBYY.Licensing.FineReader.Sprint.9.0 (b33cf4de909a5b30f526d82053a63c8e) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
19:33:27.0963 6020        ABBYY.Licensing.FineReader.Sprint.9.0 - ok
19:33:28.0056 6020        ACDaemon        (adc420616c501b45d26c0fd3ef1e54e4) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
19:33:28.0072 6020        ACDaemon - ok
19:33:28.0150 6020        ACPI            (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
19:33:28.0166 6020        ACPI - ok
19:33:28.0228 6020        AcpiPmi        (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
19:33:28.0322 6020        AcpiPmi - ok
19:33:28.0431 6020        AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
19:33:28.0446 6020        AdobeARMservice - ok
19:33:28.0571 6020        AdobeFlashPlayerUpdateSvc (990dc6edc9f933194d7cd4e65146bc94) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
19:33:28.0587 6020        AdobeFlashPlayerUpdateSvc - ok
19:33:28.0680 6020        adp94xx        (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
19:33:28.0712 6020        adp94xx - ok
19:33:28.0758 6020        adpahci        (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
19:33:28.0790 6020        adpahci - ok
19:33:28.0836 6020        adpu320        (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
19:33:28.0852 6020        adpu320 - ok
19:33:28.0899 6020        AeLookupSvc    (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll
19:33:28.0961 6020        AeLookupSvc - ok
19:33:29.0055 6020        AFD            (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
19:33:29.0180 6020        AFD - ok
19:33:29.0258 6020        agp440          (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
19:33:29.0273 6020        agp440 - ok
19:33:29.0351 6020        aic78xx        (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
19:33:29.0382 6020        aic78xx - ok
19:33:29.0445 6020        ALG            (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe
19:33:29.0507 6020        ALG - ok
19:33:29.0554 6020        aliide          (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
19:33:29.0570 6020        aliide - ok
19:33:29.0648 6020        AMD External Events Utility (b19505648f033393e907e2e419fde8b3) C:\Windows\system32\atiesrxx.exe
19:33:29.0726 6020        AMD External Events Utility - ok
19:33:29.0788 6020        amdagp          (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
19:33:29.0804 6020        amdagp - ok
19:33:29.0835 6020        amdide          (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
19:33:29.0866 6020        amdide - ok
19:33:29.0928 6020        AmdK8          (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
19:33:29.0991 6020        AmdK8 - ok
19:33:30.0038 6020        AmdPPM          (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
19:33:30.0084 6020        AmdPPM - ok
19:33:30.0162 6020        amdsata        (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
19:33:30.0178 6020        amdsata - ok
19:33:30.0240 6020        amdsbs          (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
19:33:30.0256 6020        amdsbs - ok
19:33:30.0272 6020        amdxata        (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
19:33:30.0287 6020        amdxata - ok
19:33:30.0396 6020        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files\Avira\AntiVir Desktop\sched.exe
19:33:30.0412 6020        AntiVirSchedulerService - ok
19:33:30.0459 6020        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
19:33:30.0474 6020        AntiVirService - ok
19:33:30.0537 6020        ApfiltrService  (9159bd0b3f93f4a22264fb3895b4f3f9) C:\Windows\system32\DRIVERS\Apfiltr.sys
19:33:30.0552 6020        ApfiltrService - ok
19:33:30.0615 6020        AppID          (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
19:33:30.0771 6020        AppID - ok
19:33:30.0802 6020        AppIDSvc        (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll
19:33:30.0880 6020        AppIDSvc - ok
19:33:30.0927 6020        Appinfo        (fb1959012294d6ad43e5304df65e3c26) C:\Windows\System32\appinfo.dll
19:33:30.0974 6020        Appinfo - ok
19:33:31.0020 6020        arc            (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
19:33:31.0036 6020        arc - ok
19:33:31.0052 6020        arcsas          (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
19:33:31.0067 6020        arcsas - ok
19:33:31.0114 6020        ArcSoftKsUFilter (857b48965a0503b7ab795d4bfe7cbd8b) C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys
19:33:31.0130 6020        ArcSoftKsUFilter - ok
19:33:31.0145 6020        AsyncMac        (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
19:33:31.0270 6020        AsyncMac - ok
19:33:31.0317 6020        atapi          (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
19:33:31.0332 6020        atapi - ok
19:33:31.0754 6020        atikmdag        (04f09923a393e4e0e8453a8f78361e73) C:\Windows\system32\DRIVERS\atikmdag.sys
19:33:31.0910 6020        atikmdag - ok
19:33:32.0112 6020        AudioEndpointBuilder (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll
19:33:32.0175 6020        AudioEndpointBuilder - ok
19:33:32.0175 6020        Audiosrv        (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll
19:33:32.0206 6020        Audiosrv - ok
19:33:32.0315 6020        avgntflt        (d5541f0afb767e85fc412fc609d96a74) C:\Windows\system32\DRIVERS\avgntflt.sys
19:33:32.0346 6020        avgntflt - ok
19:33:32.0409 6020        avipbb          (7d967a682d4694df7fa57d63a2db01fe) C:\Windows\system32\DRIVERS\avipbb.sys
19:33:32.0424 6020        avipbb - ok
19:33:32.0456 6020        avkmgr          (53e56450da16a1a7f0d002f511113f67) C:\Windows\system32\DRIVERS\avkmgr.sys
19:33:32.0471 6020        avkmgr - ok
19:33:32.0534 6020        AxInstSV        (6e30d02aac9cac84f421622e3a2f6178) C:\Windows\System32\AxInstSV.dll
19:33:32.0612 6020        AxInstSV - ok
19:33:32.0690 6020        b06bdrv        (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
19:33:32.0752 6020        b06bdrv - ok
19:33:32.0814 6020        b57nd60x        (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
19:33:32.0846 6020        b57nd60x - ok
19:33:32.0908 6020        BDESVC          (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll
19:33:32.0955 6020        BDESVC - ok
19:33:32.0970 6020        Beep            (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
19:33:33.0017 6020        Beep - ok
19:33:33.0080 6020        BFE            (1e2bac209d184bb851e1a187d8a29136) C:\Windows\System32\bfe.dll
19:33:33.0142 6020        BFE - ok
19:33:33.0204 6020        BITS            (e585445d5021971fae10393f0f1c3961) C:\Windows\System32\qmgr.dll
19:33:33.0282 6020        BITS - ok
19:33:33.0329 6020        blbdrive        (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
19:33:33.0345 6020        blbdrive - ok
19:33:33.0407 6020        bowser          (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
19:33:33.0454 6020        bowser - ok
19:33:33.0470 6020        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
19:33:33.0548 6020        BrFiltLo - ok
19:33:33.0579 6020        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
19:33:33.0594 6020        BrFiltUp - ok
19:33:33.0641 6020        Browser        (6e11f33d14d020f58d5e02e4d67dfa19) C:\Windows\System32\browser.dll
19:33:33.0704 6020        Browser - ok
19:33:33.0750 6020        Brserid        (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
19:33:33.0797 6020        Brserid - ok
19:33:33.0813 6020        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
19:33:33.0828 6020        BrSerWdm - ok
19:33:33.0844 6020        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
19:33:33.0875 6020        BrUsbMdm - ok
19:33:33.0891 6020        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
19:33:33.0906 6020        BrUsbSer - ok
19:33:33.0969 6020        BthEnum        (2865a5c8e98c70c605f417908cebb3a4) C:\Windows\system32\drivers\BthEnum.sys
19:33:34.0031 6020        BthEnum - ok
19:33:34.0078 6020        BTHMODEM        (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
19:33:34.0125 6020        BTHMODEM - ok
19:33:34.0156 6020        BthPan          (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\Windows\system32\DRIVERS\bthpan.sys
19:33:34.0187 6020        BthPan - ok
19:33:34.0250 6020        BTHPORT        (c2fbf6d271d9a94d839c416bf186ead9) C:\Windows\system32\Drivers\BTHport.sys
19:33:34.0312 6020        BTHPORT - ok
19:33:34.0374 6020        bthserv        (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll
19:33:34.0421 6020        bthserv - ok
19:33:34.0437 6020        BTHUSB          (c81e9413a25a439f436b1d4b6a0cf9e9) C:\Windows\system32\Drivers\BTHUSB.sys
19:33:34.0468 6020        BTHUSB - ok
19:33:34.0499 6020        btwaudio        (cd956dd816d9959748eb787a5121d1e4) C:\Windows\system32\drivers\btwaudio.sys
19:33:34.0499 6020        btwaudio - ok
19:33:34.0562 6020        btwavdt        (4ca1cc3d13466a3e2e9e9119d00aec78) C:\Windows\system32\DRIVERS\btwavdt.sys
19:33:34.0577 6020        btwavdt - ok
19:33:34.0686 6020        btwdins        (fe7fcace3678200ae202eb29c9b6a8e8) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
19:33:34.0718 6020        btwdins - ok
19:33:34.0749 6020        btwl2cap        (54c2ee0a3cec586629035d771aacae67) C:\Windows\system32\DRIVERS\btwl2cap.sys
19:33:34.0749 6020        btwl2cap - ok
19:33:34.0780 6020        btwrchid        (f857ef2d941530772ae828ecd6d71b22) C:\Windows\system32\DRIVERS\btwrchid.sys
19:33:34.0780 6020        btwrchid - ok
19:33:34.0827 6020        camfilt2        (088c0978203d59425a12b2a53fccd02b) C:\Windows\system32\DRIVERS\camfilt2.sys
19:33:34.0858 6020        camfilt2 - ok
19:33:34.0889 6020        cdfs            (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
19:33:34.0952 6020        cdfs - ok
19:33:35.0014 6020        cdrom          (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys
19:33:35.0045 6020        cdrom - ok
19:33:35.0108 6020        CertPropSvc    (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll
19:33:35.0154 6020        CertPropSvc - ok
19:33:35.0186 6020        circlass        (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
19:33:35.0186 6020        circlass - ok
19:33:35.0248 6020        CLFS            (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
19:33:35.0264 6020        CLFS - ok
19:33:35.0342 6020        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:33:35.0373 6020        clr_optimization_v2.0.50727_32 - ok
19:33:35.0435 6020        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:33:35.0482 6020        clr_optimization_v4.0.30319_32 - ok
19:33:35.0513 6020        CmBatt          (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
19:33:35.0544 6020        CmBatt - ok
19:33:35.0607 6020        cmdide          (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
19:33:35.0622 6020        cmdide - ok
19:33:35.0700 6020        CNG            (6427525d76f61d0c519b008d3680e8e7) C:\Windows\system32\Drivers\cng.sys
19:33:35.0747 6020        CNG - ok
19:33:35.0778 6020        Compbatt        (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
19:33:35.0794 6020        Compbatt - ok
19:33:35.0856 6020        CompositeBus    (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
19:33:35.0888 6020        CompositeBus - ok
19:33:35.0919 6020        COMSysApp - ok
19:33:35.0934 6020        crcdisk        (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
19:33:35.0950 6020        crcdisk - ok
19:33:35.0997 6020        CryptSvc        (06e771aa596b8761107ab57e99f128d7) C:\Windows\system32\cryptsvc.dll
19:33:36.0059 6020        CryptSvc - ok
19:33:36.0122 6020        DcomLaunch      (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll
19:33:36.0168 6020        DcomLaunch - ok
19:33:36.0215 6020        defragsvc      (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll
19:33:36.0293 6020        defragsvc - ok
19:33:36.0340 6020        DfsC            (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
19:33:36.0402 6020        DfsC - ok
19:33:36.0465 6020        Dhcp            (e9e01eb683c132f7fa27cd607b8a2b63) C:\Windows\system32\dhcpcore.dll
19:33:36.0512 6020        Dhcp - ok
19:33:36.0558 6020        discache        (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
19:33:36.0605 6020        discache - ok
19:33:36.0652 6020        Disk            (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
19:33:36.0668 6020        Disk - ok
19:33:36.0699 6020        DMICall        (f206e28ed74c491fd5d7c0a1119ce37f) C:\Windows\system32\DRIVERS\DMICall.sys
19:33:36.0699 6020        DMICall - ok
19:33:36.0746 6020        Dnscache        (33ef4861f19a0736b11314aad9ae28d0) C:\Windows\System32\dnsrslvr.dll
19:33:36.0792 6020        Dnscache - ok
19:33:36.0839 6020        dot3svc        (366ba8fb4b7bb7435e3b9eacb3843f67) C:\Windows\System32\dot3svc.dll
19:33:36.0917 6020        dot3svc - ok
19:33:36.0964 6020        Dot4            (b5e479eb83707dd698f66953e922042c) C:\Windows\system32\DRIVERS\Dot4.sys
19:33:37.0011 6020        Dot4 - ok
19:33:37.0058 6020        Dot4Print      (caefd09b6a6249c53a67d55a9a9fcabf) C:\Windows\system32\drivers\Dot4Prt.sys
19:33:37.0104 6020        Dot4Print - ok
19:33:37.0120 6020        dot4usb        (cf491ff38d62143203c065260567e2f7) C:\Windows\system32\DRIVERS\dot4usb.sys
19:33:37.0151 6020        dot4usb - ok
19:33:37.0198 6020        DPS            (8ec04ca86f1d68da9e11952eb85973d6) C:\Windows\system32\dps.dll
19:33:37.0245 6020        DPS - ok
19:33:37.0292 6020        drmkaud        (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
19:33:37.0323 6020        drmkaud - ok
19:33:37.0416 6020        DXGKrnl        (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
19:33:37.0448 6020        DXGKrnl - ok
19:33:37.0494 6020        EapHost        (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll
19:33:37.0557 6020        EapHost - ok
19:33:37.0822 6020        ebdrv          (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
19:33:37.0916 6020        ebdrv - ok
19:33:38.0056 6020        EFS            (81951f51e318aecc2d68559e47485cc4) C:\Windows\System32\lsass.exe
19:33:38.0103 6020        EFS - ok
19:33:38.0212 6020        ehRecvr        (a8c362018efc87beb013ee28f29c0863) C:\Windows\ehome\ehRecvr.exe
19:33:38.0290 6020        ehRecvr - ok
19:33:38.0321 6020        ehSched        (d389bff34f80caede417bf9d1507996a) C:\Windows\ehome\ehsched.exe
19:33:38.0368 6020        ehSched - ok
19:33:38.0493 6020        elxstor        (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
19:33:38.0524 6020        elxstor - ok
19:33:38.0633 6020        EpsonBidirectionalService (abdd5ad016affd34ad40e944ce94bf59) C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
19:33:38.0633 6020        EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - warning
19:33:38.0633 6020        EpsonBidirectionalService - detected UnsignedFile.Multi.Generic (1)
19:33:38.0696 6020        EPSON_EB_RPCV4_04 (b92f2b3247f0a99490c1298a1d3d7b4c) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE
19:33:38.0742 6020        EPSON_EB_RPCV4_04 - ok
19:33:38.0758 6020        EPSON_PM_RPCV4_04 (651336b99c75fb54e4b5971cf458f9bd) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
19:33:38.0805 6020        EPSON_PM_RPCV4_04 - ok
19:33:38.0836 6020        ErrDev          (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
19:33:38.0867 6020        ErrDev - ok
19:33:38.0945 6020        EventSystem    (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll
19:33:39.0008 6020        EventSystem - ok
19:33:39.0148 6020        EvtEng          (ba6063e3375f9bc11a9c8450a7f61e70) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
19:33:39.0195 6020        EvtEng ( UnsignedFile.Multi.Generic ) - warning
19:33:39.0195 6020        EvtEng - detected UnsignedFile.Multi.Generic (1)
19:33:39.0226 6020        exfat          (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
19:33:39.0288 6020        exfat - ok
19:33:39.0304 6020        fastfat        (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
19:33:39.0351 6020        fastfat - ok
19:33:39.0460 6020        Fax            (967ea5b213e9984cbe270205df37755b) C:\Windows\system32\fxssvc.exe
19:33:39.0522 6020        Fax - ok
19:33:39.0538 6020        fdc            (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
19:33:39.0569 6020        fdc - ok
19:33:39.0600 6020        fdPHost        (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll
19:33:39.0647 6020        fdPHost - ok
19:33:39.0663 6020        FDResPub        (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll
19:33:39.0710 6020        FDResPub - ok
19:33:39.0725 6020        FileInfo        (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
19:33:39.0741 6020        FileInfo - ok
19:33:39.0756 6020        Filetrace      (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
19:33:39.0788 6020        Filetrace - ok
19:33:39.0803 6020        flpydisk        (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
19:33:39.0834 6020        flpydisk - ok
19:33:39.0897 6020        FltMgr          (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
19:33:39.0912 6020        FltMgr - ok
19:33:39.0990 6020        FontCache      (b3a5ec6b6b6673db7e87c2bcdbddc074) C:\Windows\system32\FntCache.dll
19:33:40.0068 6020        FontCache - ok
19:33:40.0178 6020        FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
19:33:40.0193 6020        FontCache3.0.0.0 - ok
19:33:40.0240 6020        FsDepends      (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
19:33:40.0256 6020        FsDepends - ok
19:33:40.0302 6020        fssfltr        (b74b0578fd1d3f897e95f2a2b69ea051) C:\Windows\system32\DRIVERS\fssfltr.sys
19:33:40.0318 6020        fssfltr - ok
19:33:40.0443 6020        fsssvc          (45b52394f9624237f33a8a3d73c0b221) C:\Program Files\Windows Live\Family Safety\fsssvc.exe
19:33:40.0474 6020        fsssvc - ok
19:33:40.0505 6020        Fs_Rec          (7dae5ebcc80e45d3253f4923dc424d05) C:\Windows\system32\drivers\Fs_Rec.sys
19:33:40.0521 6020        Fs_Rec - ok
19:33:40.0583 6020        fvevol          (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
19:33:40.0614 6020        fvevol - ok
19:33:40.0646 6020        gagp30kx        (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
19:33:40.0661 6020        gagp30kx - ok
19:33:40.0724 6020        GoogleDesktopManager-051210-111108 (9f5f2f0fb0a7f5aa9f16b9a7b6dad89f) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
19:33:40.0739 6020        GoogleDesktopManager-051210-111108 - ok
19:33:40.0848 6020        gpsvc          (e897eaf5ed6ba41e081060c9b447a673) C:\Windows\System32\gpsvc.dll
19:33:40.0895 6020        gpsvc - ok
19:33:40.0911 6020        hcw85cir        (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
19:33:40.0973 6020        hcw85cir - ok
19:33:41.0036 6020        HDAudBus        (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
19:33:41.0082 6020        HDAudBus - ok
19:33:41.0098 6020        HidBatt        (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
19:33:41.0129 6020        HidBatt - ok
19:33:41.0145 6020        HidBth          (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
19:33:41.0192 6020        HidBth - ok
19:33:41.0223 6020        HidIr          (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
19:33:41.0238 6020        HidIr - ok
19:33:41.0285 6020        hidserv        (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\system32\hidserv.dll
19:33:41.0316 6020        hidserv - ok
19:33:41.0332 6020        HidUsb          (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\drivers\hidusb.sys
19:33:41.0348 6020        HidUsb - ok
19:33:41.0394 6020        hkmsvc          (196b4e3f4cccc24af836ce58facbb699) C:\Windows\system32\kmsvc.dll
19:33:41.0457 6020        hkmsvc - ok
19:33:41.0504 6020        HomeGroupListener (6658f4404de03d75fe3ba09f7aba6a30) C:\Windows\system32\ListSvc.dll
19:33:41.0550 6020        HomeGroupListener - ok
19:33:41.0613 6020        HomeGroupProvider (dbc02d918fff1cad628acbe0c0eaa8e8) C:\Windows\system32\provsvc.dll
19:33:41.0660 6020        HomeGroupProvider - ok
19:33:41.0784 6020        hpqcxs08        (fcb563b0a23643e5f80b6ff1e60f610f) C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
19:33:41.0816 6020        hpqcxs08 ( UnsignedFile.Multi.Generic ) - warning
19:33:41.0816 6020        hpqcxs08 - detected UnsignedFile.Multi.Generic (1)
19:33:41.0847 6020        hpqddsvc        (25e443e27165c652723a92d9bdfd4649) C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
19:33:41.0862 6020        hpqddsvc ( UnsignedFile.Multi.Generic ) - warning
19:33:41.0862 6020        hpqddsvc - detected UnsignedFile.Multi.Generic (1)
19:33:41.0925 6020        HpSAMD          (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
19:33:41.0940 6020        HpSAMD - ok
19:33:41.0956 6020        HSF_DPV - ok
19:33:41.0956 6020        HSXHWAZL - ok
19:33:42.0034 6020        HTTP            (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
19:33:42.0081 6020        HTTP - ok
19:33:42.0112 6020        hwpolicy        (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
19:33:42.0128 6020        hwpolicy - ok
19:33:42.0159 6020        hxctlflt        (f02ea43ae8f936124debf5b87f12c795) C:\Windows\system32\DRIVERS\hxctlflt.sys
19:33:42.0206 6020        hxctlflt - ok
19:33:42.0268 6020        i8042prt        (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
19:33:42.0284 6020        i8042prt - ok
19:33:42.0346 6020        iaStor          (db0cc620b27a928d968c1a1e9cd9cb87) C:\Windows\system32\DRIVERS\iaStor.sys
19:33:42.0362 6020        iaStor - ok
19:33:42.0424 6020        iaStorV        (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
19:33:42.0440 6020        iaStorV - ok
19:33:42.0564 6020        ICQ Service    (7a95a3ad931b97fec5067e40636ce37f) C:\Program Files\ICQ6Toolbar\ICQ Service.exe
19:33:42.0596 6020        ICQ Service - ok
19:33:42.0767 6020        idsvc          (c521d7eb6497bb1af6afa89e322fb43c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
19:33:42.0814 6020        idsvc - ok
19:33:42.0970 6020        iirsp          (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
19:33:43.0001 6020        iirsp - ok
19:33:43.0110 6020        IKEEXT          (f95622f161474511b8d80d6b093aa610) C:\Windows\System32\ikeext.dll
19:33:43.0188 6020        IKEEXT - ok
19:33:43.0391 6020        IntcAzAudAddService (3aa1f82efa2b0454af163124c9920d16) C:\Windows\system32\drivers\RTKVHDA.sys
19:33:43.0438 6020        IntcAzAudAddService - ok
19:33:43.0641 6020        intelide        (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
19:33:43.0672 6020        intelide - ok
19:33:43.0703 6020        intelppm        (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
19:33:43.0750 6020        intelppm - ok
19:33:43.0781 6020        IPBusEnum      (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll
19:33:43.0828 6020        IPBusEnum - ok
19:33:43.0844 6020        IpFilterDriver  (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:33:43.0906 6020        IpFilterDriver - ok
19:33:43.0984 6020        iphlpsvc        (4d65a07b795d6674312f879d09aa7663) C:\Windows\System32\iphlpsvc.dll
19:33:44.0031 6020        iphlpsvc - ok
19:33:44.0062 6020        IPMIDRV        (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
19:33:44.0109 6020        IPMIDRV - ok
19:33:44.0140 6020        IPNAT          (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
19:33:44.0202 6020        IPNAT - ok
19:33:44.0234 6020        IRENUM          (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
19:33:44.0249 6020        IRENUM - ok
19:33:44.0280 6020        isapnp          (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
19:33:44.0296 6020        isapnp - ok
19:33:44.0327 6020        iScsiPrt        (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
19:33:44.0358 6020        iScsiPrt - ok
19:33:44.0452 6020        IviRegMgr      (213822072085b5bbad9af30ab577d817) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
19:33:44.0468 6020        IviRegMgr - ok
19:33:44.0499 6020        kbdclass        (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
19:33:44.0514 6020        kbdclass - ok
19:33:44.0546 6020        kbdhid          (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
19:33:44.0592 6020        kbdhid - ok
19:33:44.0624 6020        KeyIso          (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
19:33:44.0639 6020        KeyIso - ok
19:33:44.0655 6020        KSecDD          (f4647bb23db9038a7536cf6b68f4207f) C:\Windows\system32\Drivers\ksecdd.sys
19:33:44.0670 6020        KSecDD - ok
19:33:44.0686 6020        KSecPkg        (e73cae53bbb72ba26918492c6b4c229d) C:\Windows\system32\Drivers\ksecpkg.sys
19:33:44.0702 6020        KSecPkg - ok
19:33:44.0748 6020        KtmRm          (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll
19:33:44.0780 6020        KtmRm - ok
19:33:44.0826 6020        LanmanServer    (d64af876d53eca3668bb97b51b4e70ab) C:\Windows\system32\srvsvc.dll
19:33:44.0873 6020        LanmanServer - ok
19:33:44.0920 6020        LanmanWorkstation (58405e4f68ba8e4057c6e914f326aba2) C:\Windows\System32\wkssvc.dll
19:33:44.0982 6020        LanmanWorkstation - ok
19:33:45.0045 6020        lltdio          (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
19:33:45.0107 6020        lltdio - ok
19:33:45.0154 6020        lltdsvc        (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll
19:33:45.0185 6020        lltdsvc - ok
19:33:45.0185 6020        lmhosts        (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll
19:33:45.0216 6020        lmhosts - ok
19:33:45.0248 6020        LSI_FC          (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
19:33:45.0263 6020        LSI_FC - ok
19:33:45.0310 6020        LSI_SAS        (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
19:33:45.0326 6020        LSI_SAS - ok
19:33:45.0357 6020        LSI_SAS2        (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
19:33:45.0388 6020        LSI_SAS2 - ok
19:33:45.0435 6020        LSI_SCSI        (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
19:33:45.0466 6020        LSI_SCSI - ok
19:33:45.0497 6020        luafv          (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
19:33:45.0528 6020        luafv - ok
19:33:45.0591 6020        MBAMProtector  (fb097bbc1a18f044bd17bd2fccf97865) C:\Windows\system32\drivers\mbam.sys
19:33:45.0606 6020        MBAMProtector - ok
19:33:45.0731 6020        MBAMService    (ba400ed640bca1eae5c727ae17c10207) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
19:33:45.0762 6020        MBAMService - ok
19:33:45.0794 6020        Mcx2Svc        (bfb9ee8ee977efe85d1a3105abef6dd1) C:\Windows\system32\Mcx2Svc.dll
19:33:45.0809 6020        Mcx2Svc - ok
19:33:45.0809 6020        mdmxsdk - ok
19:33:45.0825 6020        megasas        (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
19:33:45.0840 6020        megasas - ok
19:33:45.0872 6020        MegaSR          (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
19:33:45.0887 6020        MegaSR - ok
19:33:45.0934 6020        MMCSS          (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll
19:33:45.0981 6020        MMCSS - ok
19:33:45.0996 6020        Modem          (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
19:33:46.0043 6020        Modem - ok
19:33:46.0074 6020        monitor        (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
19:33:46.0106 6020        monitor - ok
19:33:46.0152 6020        motccgp - ok
19:33:46.0152 6020        motccgpfl - ok
19:33:46.0168 6020        MotDev - ok
19:33:46.0199 6020        motmodem        (69814acd50a9d6d28296050ef6215d46) C:\Windows\system32\DRIVERS\motmodem.sys
19:33:46.0262 6020        motmodem - ok
19:33:46.0340 6020        MotoHelper      (98a10ac4257a3ba48c9611338544ee49) C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
19:33:46.0371 6020        MotoHelper - ok
19:33:46.0418 6020        mouclass        (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\drivers\mouclass.sys
19:33:46.0433 6020        mouclass - ok
19:33:46.0480 6020        mouhid          (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
19:33:46.0511 6020        mouhid - ok
19:33:46.0542 6020        mountmgr        (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
19:33:46.0574 6020        mountmgr - ok
19:33:46.0636 6020        MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
19:33:46.0667 6020        MozillaMaintenance - ok
19:33:46.0698 6020        mpio            (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
19:33:46.0714 6020        mpio - ok
19:33:46.0730 6020        mpsdrv          (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
19:33:46.0761 6020        mpsdrv - ok
19:33:46.0823 6020        MpsSvc          (9835584e999d25004e1ee8e5f3e3b881) C:\Windows\system32\mpssvc.dll
19:33:46.0901 6020        MpsSvc - ok
19:33:46.0932 6020        MRxDAV          (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
19:33:46.0948 6020        MRxDAV - ok
19:33:47.0010 6020        mrxsmb          (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
19:33:47.0088 6020        mrxsmb - ok
19:33:47.0120 6020        mrxsmb10        (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:33:47.0166 6020        mrxsmb10 - ok
19:33:47.0198 6020        mrxsmb20        (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:33:47.0229 6020        mrxsmb20 - ok
19:33:47.0276 6020        msahci          (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
19:33:47.0291 6020        msahci - ok
19:33:47.0354 6020        msdsm          (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
19:33:47.0385 6020        msdsm - ok
19:33:47.0432 6020        MSDTC          (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe
19:33:47.0463 6020        MSDTC - ok
19:33:47.0510 6020        Msfs            (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
19:33:47.0541 6020        Msfs - ok
19:33:47.0556 6020        mshidkmdf      (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
19:33:47.0588 6020        mshidkmdf - ok
19:33:47.0603 6020        msisadrv        (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
19:33:47.0603 6020        msisadrv - ok
19:33:47.0650 6020        MSiSCSI        (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll
19:33:47.0681 6020        MSiSCSI - ok
19:33:47.0681 6020        msiserver - ok
19:33:47.0712 6020        MSKSSRV        (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
19:33:47.0775 6020        MSKSSRV - ok
19:33:47.0806 6020        MSPCLOCK        (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
19:33:47.0837 6020        MSPCLOCK - ok
19:33:47.0868 6020        MSPQM          (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
19:33:47.0915 6020        MSPQM - ok
19:33:47.0931 6020        MsRPC          (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
19:33:47.0978 6020        MsRPC - ok
19:33:48.0009 6020        mssmbios        (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
19:33:48.0040 6020        mssmbios - ok
19:33:48.0056 6020        MSTEE          (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
19:33:48.0071 6020        MSTEE - ok
19:33:48.0087 6020        MTConfig        (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
19:33:48.0102 6020        MTConfig - ok
19:33:48.0118 6020        Mup            (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
19:33:48.0118 6020        Mup - ok
19:33:48.0180 6020        napagent        (61d57a5d7c6d9afe10e77dae6e1b445e) C:\Windows\system32\qagentRT.dll
19:33:48.0227 6020        napagent - ok
19:33:48.0274 6020        NativeWifiP    (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
19:33:48.0321 6020        NativeWifiP - ok
19:33:48.0368 6020        NDIS            (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
19:33:48.0399 6020        NDIS - ok
19:33:48.0430 6020        NdisCap        (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
19:33:48.0477 6020        NdisCap - ok
19:33:48.0492 6020        NdisTapi        (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
19:33:48.0539 6020        NdisTapi - ok
19:33:48.0586 6020        Ndisuio        (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
19:33:48.0648 6020        Ndisuio - ok
19:33:48.0680 6020        NdisWan        (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
19:33:48.0758 6020        NdisWan - ok
19:33:48.0804 6020        NDProxy        (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
19:33:48.0851 6020        NDProxy - ok
19:33:48.0851 6020        NetBIOS        (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
19:33:48.0898 6020        NetBIOS - ok
19:33:48.0945 6020        NetBT          (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
19:33:49.0007 6020        NetBT - ok
19:33:49.0038 6020        Netlogon        (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
19:33:49.0038 6020        Netlogon - ok
19:33:49.0101 6020        Netman          (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll
19:33:49.0163 6020        Netman - ok
19:33:49.0226 6020        netprofm        (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll
19:33:49.0272 6020        netprofm - ok
19:33:49.0382 6020        NetTcpPortSharing (f476ec40033cdb91efbe73eb99b8362d) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
19:33:49.0397 6020        NetTcpPortSharing - ok
19:33:49.0756 6020        netw5v32        (58218ec6b61b1169cf54aab0d00f5fe2) C:\Windows\system32\DRIVERS\netw5v32.sys
19:33:49.0865 6020        netw5v32 - ok
19:33:50.0068 6020        nfrd960        (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
19:33:50.0084 6020        nfrd960 - ok
19:33:50.0146 6020        NlaSvc          (912084381d30d8b89ec4e293053f4710) C:\Windows\System32\nlasvc.dll
19:33:50.0208 6020        NlaSvc - ok
19:33:50.0224 6020        Npfs            (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
19:33:50.0302 6020        Npfs - ok
19:33:50.0333 6020        nsi            (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll
19:33:50.0364 6020        nsi - ok
19:33:50.0380 6020        nsiproxy        (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
19:33:50.0411 6020        nsiproxy - ok
19:33:50.0567 6020        NSUService      (276bff84ad77dd23e1085e191f5a591f) C:\Program Files\sony\Network Utility\NSUService.exe
19:33:50.0598 6020        NSUService ( UnsignedFile.Multi.Generic ) - warning
19:33:50.0598 6020        NSUService - detected UnsignedFile.Multi.Generic (1)
19:33:50.0739 6020        Ntfs            (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
19:33:50.0801 6020        Ntfs - ok
19:33:50.0817 6020        Null            (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
19:33:50.0848 6020        Null - ok
19:33:50.0879 6020        nvraid          (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
19:33:50.0895 6020        nvraid - ok
19:33:50.0957 6020        nvstor          (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
19:33:50.0973 6020        nvstor - ok
19:33:51.0020 6020        nv_agp          (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
19:33:51.0035 6020        nv_agp - ok
19:33:51.0082 6020        ohci1394        (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
19:33:51.0113 6020        ohci1394 - ok
19:33:51.0176 6020        p2pimsvc        (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll
19:33:51.0222 6020        p2pimsvc - ok
19:33:51.0285 6020        p2psvc          (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll
19:33:51.0316 6020        p2psvc - ok
19:33:51.0425 6020        PACSPTISVR      (b8040c5c1fc1fbbbe5c78cb9eda343ec) C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
19:33:51.0456 6020        PACSPTISVR ( UnsignedFile.Multi.Generic ) - warning
19:33:51.0456 6020        PACSPTISVR - detected UnsignedFile.Multi.Generic (1)
19:33:51.0488 6020        Parport        (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
19:33:51.0534 6020        Parport - ok
19:33:51.0566 6020        partmgr        (3f34a1b4c5f6475f320c275e63afce9b) C:\Windows\system32\drivers\partmgr.sys
19:33:51.0597 6020        partmgr - ok
19:33:51.0597 6020        Parvdm          (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
19:33:51.0628 6020        Parvdm - ok
19:33:51.0659 6020        PcaSvc          (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll
19:33:51.0690 6020        PcaSvc - ok
19:33:51.0737 6020        pci            (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
19:33:51.0753 6020        pci - ok
19:33:51.0784 6020        pciide          (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
19:33:51.0800 6020        pciide - ok
19:33:51.0815 6020        pcmcia          (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
19:33:51.0831 6020        pcmcia - ok
19:33:51.0846 6020        pcw            (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
19:33:51.0862 6020        pcw - ok
19:33:51.0940 6020        PEAUTH          (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
19:33:51.0987 6020        PEAUTH - ok
19:33:52.0127 6020        pla            (414bba67a3ded1d28437eb66aeb8a720) C:\Windows\system32\pla.dll
19:33:52.0205 6020        pla - ok
19:33:52.0377 6020        PlugPlay        (ec7bc28d207da09e79b3e9faf8b232ca) C:\Windows\system32\umpnpmgr.dll
19:33:52.0424 6020        PlugPlay - ok
19:33:52.0455 6020        PNRPAutoReg    (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll
19:33:52.0502 6020        PNRPAutoReg - ok
19:33:52.0548 6020        PNRPsvc        (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll
19:33:52.0580 6020        PNRPsvc - ok
19:33:52.0626 6020        PolicyAgent    (53946b69ba0836bd95b03759530c81ec) C:\Windows\System32\ipsecsvc.dll
19:33:52.0673 6020        PolicyAgent - ok
19:33:52.0704 6020        Power          (f87d30e72e03d579a5199ccb3831d6ea) C:\Windows\system32\umpo.dll
19:33:52.0736 6020        Power - ok
19:33:52.0814 6020        PptpMiniport    (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
19:33:52.0876 6020        PptpMiniport - ok
19:33:52.0907 6020        Processor      (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
19:33:52.0938 6020        Processor - ok
19:33:52.0970 6020        ProfSvc        (cadefac453040e370a1bdff3973be00d) C:\Windows\system32\profsvc.dll
19:33:53.0016 6020        ProfSvc - ok
19:33:53.0063 6020        ProtectedStorage (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
19:33:53.0063 6020        ProtectedStorage - ok
19:33:53.0126 6020        Psched          (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
19:33:53.0141 6020        Psched - ok
19:33:53.0188 6020        PxHelp20        (153d02480a0a2f45785522e814c634b6) C:\Windows\system32\Drivers\PxHelp20.sys
19:33:53.0188 6020        PxHelp20 - ok
19:33:53.0313 6020        ql2300          (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
19:33:53.0391 6020        ql2300 - ok
19:33:53.0562 6020        ql40xx          (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
19:33:53.0594 6020        ql40xx - ok
19:33:53.0625 6020        QWAVE          (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll
19:33:53.0656 6020        QWAVE - ok
19:33:53.0687 6020        QWAVEdrv        (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
19:33:53.0703 6020        QWAVEdrv - ok
19:33:53.0703 6020        RasAcd          (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
19:33:53.0750 6020        RasAcd - ok
19:33:53.0812 6020        RasAgileVpn    (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
19:33:53.0859 6020        RasAgileVpn - ok
19:33:53.0890 6020        RasAuto        (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll
19:33:53.0921 6020        RasAuto - ok
19:33:53.0952 6020        Rasl2tp        (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
19:33:53.0984 6020        Rasl2tp - ok
19:33:54.0030 6020        RasMan          (cb9e04dc05eacf5b9a36ca276d475006) C:\Windows\System32\rasmans.dll
19:33:54.0108 6020        RasMan - ok
19:33:54.0140 6020        RasPppoe        (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
19:33:54.0186 6020        RasPppoe - ok
19:33:54.0218 6020        RasSstp        (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
19:33:54.0264 6020        RasSstp - ok
19:33:54.0327 6020        rdbss          (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
19:33:54.0389 6020        rdbss - ok
19:33:54.0405 6020        rdpbus          (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
19:33:54.0420 6020        rdpbus - ok
19:33:54.0452 6020        RDPCDD          (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
19:33:54.0483 6020        RDPCDD - ok
19:33:54.0514 6020        RDPENCDD        (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
19:33:54.0545 6020        RDPENCDD - ok
19:33:54.0576 6020        RDPREFMP        (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
19:33:54.0608 6020        RDPREFMP - ok
19:33:54.0654 6020        RDPWD          (f031683e6d1fea157abb2ff260b51e61) C:\Windows\system32\drivers\RDPWD.sys
19:33:54.0717 6020        RDPWD - ok
19:33:54.0764 6020        rdyboost        (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
19:33:54.0779 6020        rdyboost - ok
19:33:54.0826 6020        regi            (001b4278407f4303efc902a2b16f2453) C:\Windows\system32\drivers\regi.sys
19:33:54.0842 6020        regi - ok
19:33:54.0982 6020        RegSrvc        (7eeeec28a34516e66137f355dcc15bdb) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
19:33:54.0982 6020        RegSrvc ( UnsignedFile.Multi.Generic ) - warning
19:33:54.0998 6020        RegSrvc - detected UnsignedFile.Multi.Generic (1)
19:33:55.0029 6020        RemoteAccess    (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll
19:33:55.0091 6020        RemoteAccess - ok
19:33:55.0122 6020        RemoteRegistry  (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll
19:33:55.0169 6020        RemoteRegistry - ok
19:33:55.0216 6020        RFCOMM          (cb928d9e6daf51879dd6ba8d02f01321) C:\Windows\system32\DRIVERS\rfcomm.sys
19:33:55.0278 6020        RFCOMM - ok
19:33:55.0325 6020        rimsptsk        (f7d9ecf41ebd3cf6c65944368150f66b) C:\Windows\system32\DRIVERS\rimsptsk.sys
19:33:55.0388 6020        rimsptsk - ok
19:33:55.0419 6020        risdptsk        (1be6c42767a7c67ba31ae32b293b37a3) C:\Windows\system32\DRIVERS\risdptsk.sys
19:33:55.0450 6020        risdptsk - ok
19:33:55.0481 6020        RpcEptMapper    (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll
19:33:55.0528 6020        RpcEptMapper - ok
19:33:55.0559 6020        RpcLocator      (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe
19:33:55.0590 6020        RpcLocator - ok
19:33:55.0637 6020        RpcSs          (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll
19:33:55.0684 6020        RpcSs - ok
19:33:55.0715 6020        rspndr          (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
19:33:55.0762 6020        rspndr - ok
19:33:55.0824 6020        RTHDMIAzAudService (a95b16ff762ff217847b97e6f05778ee) C:\Windows\system32\drivers\RtHDMIV.sys
19:33:55.0840 6020        RTHDMIAzAudService - ok
19:33:55.0934 6020        RtkAudioService (4b3795ebecae570def38ba7924c2a3dc) C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe
19:33:55.0949 6020        RtkAudioService - ok
19:33:55.0980 6020        SamSs          (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
19:33:55.0996 6020        SamSs - ok
19:33:56.0058 6020        sbp2port        (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
19:33:56.0074 6020        sbp2port - ok
19:33:56.0121 6020        SCardSvr        (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll
19:33:56.0152 6020        SCardSvr - ok
19:33:56.0199 6020        scfilter        (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
19:33:56.0246 6020        scfilter - ok
19:33:56.0339 6020        Schedule        (a04bb13f8a72f8b6e8b4071723e4e336) C:\Windows\system32\schedsvc.dll
19:33:56.0417 6020        Schedule - ok
19:33:56.0448 6020        SCPolicySvc    (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll
19:33:56.0480 6020        SCPolicySvc - ok
19:33:56.0542 6020        SDRSVC          (08236c4bce5edd0a0318a438af28e0f7) C:\Windows\System32\SDRSVC.dll
19:33:56.0589 6020        SDRSVC - ok
19:33:56.0651 6020        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
19:33:56.0682 6020        secdrv - ok
19:33:56.0729 6020        seclogon        (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll
19:33:56.0776 6020        seclogon - ok
19:33:56.0792 6020        SENS            (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\System32\sens.dll
19:33:56.0823 6020        SENS - ok
19:33:56.0870 6020        SensrSvc        (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll
19:33:56.0885 6020        SensrSvc - ok
19:33:56.0916 6020        Serenum        (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
19:33:56.0948 6020        Serenum - ok
19:33:56.0979 6020        Serial          (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
19:33:57.0010 6020        Serial - ok
19:33:57.0057 6020        sermouse        (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
19:33:57.0088 6020        sermouse - ok
19:33:57.0150 6020        SessionEnv      (4ae380f39a0032eab7dd953030b26d28) C:\Windows\system32\sessenv.dll
19:33:57.0182 6020        SessionEnv - ok
19:33:57.0228 6020        SFEP            (8b7c1768d2cde2e02e09a66563ddfd16) C:\Windows\system32\DRIVERS\SFEP.sys
19:33:57.0275 6020        SFEP - ok
19:33:57.0338 6020        sffdisk        (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
19:33:57.0384 6020        sffdisk - ok
19:33:57.0416 6020        sffp_mmc        (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
19:33:57.0431 6020        sffp_mmc - ok
19:33:57.0462 6020        sffp_sd        (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
19:33:57.0478 6020        sffp_sd - ok
19:33:57.0556 6020        sfloppy        (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
19:33:57.0587 6020        sfloppy - ok
19:33:57.0634 6020        SharedAccess    (d1a079a0de2ea524513b6930c24527a2) C:\Windows\System32\ipnathlp.dll
19:33:57.0681 6020        SharedAccess - ok
19:33:57.0743 6020        ShellHWDetection (414da952a35bf5d50192e28263b40577) C:\Windows\System32\shsvcs.dll
19:33:57.0806 6020        ShellHWDetection - ok
19:33:57.0852 6020        sisagp          (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
19:33:57.0868 6020        sisagp - ok
19:33:57.0899 6020        SiSRaid2        (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
19:33:57.0915 6020        SiSRaid2 - ok
19:33:57.0946 6020        SiSRaid4        (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
19:33:57.0962 6020        SiSRaid4 - ok
19:33:57.0993 6020        Smb            (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
19:33:58.0008 6020        Smb - ok
19:33:58.0071 6020        SNMPTRAP        (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe
19:33:58.0102 6020        SNMPTRAP - ok
19:33:58.0898 6020        SNPSTD3        (9cd6ffc9f5b999eb5df69b9177d9848f) C:\Windows\system32\DRIVERS\snpstd3.sys
19:33:59.0210 6020        SNPSTD3 - ok
19:33:59.0397 6020        SOHCImp        (7b24efa2a60ba7388fecda63ab24560a) C:\Program Files\Common Files\Sony Shared\SOHLib\SOHCImp.exe
19:33:59.0412 6020        SOHCImp - ok
19:33:59.0444 6020        SOHDBSvr        (140fcf5ffae4efba9740a9fd8b49e0bf) C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
19:33:59.0459 6020        SOHDBSvr - ok
19:33:59.0490 6020        SOHDms          (d8c244121a06b581b097d9617d94cff1) C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDms.exe
19:33:59.0522 6020        SOHDms - ok
19:33:59.0537 6020        SOHDs          (2db561887ea122b946bbe2821473edd8) C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDs.exe
19:33:59.0553 6020        SOHDs - ok
19:33:59.0568 6020        SOHPlMgr        (ab9ee246a1eb2c3c7c6cb16e0b9462f7) C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
19:33:59.0568 6020        SOHPlMgr - ok
19:33:59.0740 6020        spldr          (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
19:33:59.0771 6020        spldr - ok
19:33:59.0834 6020        Spooler        (866a43013535dc8587c258e43579c764) C:\Windows\System32\spoolsv.exe
19:33:59.0896 6020        Spooler - ok
19:34:00.0161 6020        sppsvc          (cf87a1de791347e75b98885214ced2b8) C:\Windows\system32\sppsvc.exe
19:34:00.0286 6020        sppsvc - ok
19:34:00.0442 6020        sppuinotify    (b0180b20b065d89232a78a40fe56eaa6) C:\Windows\system32\sppuinotify.dll
19:34:00.0473 6020        sppuinotify - ok
19:34:00.0582 6020        srv            (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
19:34:00.0629 6020        srv - ok
19:34:00.0660 6020        srv2            (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
19:34:00.0707 6020        srv2 - ok
19:34:00.0754 6020        SrvHsfHDA      (e00fdfaff025e94f9821153750c35a6d) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
19:34:00.0816 6020        SrvHsfHDA - ok
19:34:00.0926 6020        SrvHsfV92      (ceb4e3b6890e1e42dca6694d9e59e1a0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
19:34:00.0972 6020        SrvHsfV92 - ok
19:34:01.0050 6020        SrvHsfWinac    (bc0c7ea89194c299f051c24119000e17) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
19:34:01.0082 6020        SrvHsfWinac - ok
19:34:01.0128 6020        srvnet          (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
19:34:01.0144 6020        srvnet - ok
19:34:01.0191 6020        SSDPSRV        (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll
19:34:01.0238 6020        SSDPSRV - ok
19:34:01.0284 6020        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
19:34:01.0300 6020        ssmdrv - ok
19:34:01.0331 6020        SstpSvc        (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll
19:34:01.0362 6020        SstpSvc - ok
19:34:01.0409 6020        stexstor        (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
19:34:01.0425 6020        stexstor - ok
19:34:01.0503 6020        StiSvc          (e1fb3706030fb4578a0d72c2fc3689e4) C:\Windows\System32\wiaservc.dll
19:34:01.0565 6020        StiSvc - ok
19:34:01.0596 6020        swenum          (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
19:34:01.0612 6020        swenum - ok
19:34:01.0643 6020        swprv          (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll
19:34:01.0674 6020        swprv - ok
19:34:01.0799 6020        SysMain        (36650d618ca34c9d357dfd3d89b2c56f) C:\Windows\system32\sysmain.dll
19:34:01.0862 6020        SysMain - ok
19:34:01.0893 6020        TabletInputService (763fecdc3d30c815fe72dd57936c6cd1) C:\Windows\System32\TabSvc.dll
19:34:01.0908 6020        TabletInputService - ok
19:34:01.0955 6020        TapiSrv        (613bf4820361543956909043a265c6ac) C:\Windows\System32\tapisrv.dll
19:34:02.0002 6020        TapiSrv - ok
19:34:02.0033 6020        TBS            (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll
19:34:02.0080 6020        TBS - ok
19:34:02.0283 6020        Tcpip          (7fa2e0f8b072bd04b77b421480b6cc22) C:\Windows\system32\drivers\tcpip.sys
19:34:02.0361 6020        Tcpip - ok
19:34:02.0392 6020        TCPIP6          (7fa2e0f8b072bd04b77b421480b6cc22) C:\Windows\system32\DRIVERS\tcpip.sys
19:34:02.0423 6020        TCPIP6 - ok
19:34:02.0486 6020        tcpipreg        (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
19:34:02.0548 6020        tcpipreg - ok
19:34:02.0595 6020        TDPIPE          (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
19:34:02.0642 6020        TDPIPE - ok
19:34:02.0688 6020        TDTCP          (2c2c5afe7ee4f620d69c23c0617651a8) C:\Windows\system32\drivers\tdtcp.sys
19:34:02.0720 6020        TDTCP - ok
19:34:02.0751 6020        tdx            (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
19:34:02.0813 6020        tdx - ok
19:34:02.0844 6020        TermDD          (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
19:34:02.0860 6020        TermDD - ok
19:34:02.0922 6020        TermService    (382c804c92811be57829d8e550a900e2) C:\Windows\System32\termsrv.dll
19:34:02.0969 6020        TermService - ok
19:34:03.0000 6020        Themes          (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll
19:34:03.0032 6020        Themes - ok
19:34:03.0063 6020        THREADORDER    (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll
19:34:03.0094 6020        THREADORDER - ok
19:34:03.0125 6020        TrkWks          (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll
19:34:03.0172 6020        TrkWks - ok
19:34:03.0234 6020        TrustedInstaller (2c49b175aee1d4364b91b531417fe583) C:\Windows\servicing\TrustedInstaller.exe
19:34:03.0297 6020        TrustedInstaller - ok
19:34:03.0312 6020        tssecsrv        (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
19:34:03.0344 6020        tssecsrv - ok
19:34:03.0390 6020        TsUsbFlt        (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
19:34:03.0453 6020        TsUsbFlt - ok
19:34:03.0515 6020        tunnel          (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
19:34:03.0562 6020        tunnel - ok
19:34:03.0609 6020        uagp35          (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
19:34:03.0609 6020        uagp35 - ok
19:34:03.0718 6020        uCamMonitor    (63f6d08c54d5b3c1b12a6172032055c7) C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
19:34:03.0734 6020        uCamMonitor - ok
19:34:03.0796 6020        udfs            (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
19:34:03.0843 6020        udfs - ok
19:34:03.0890 6020        UI0Detect      (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe
19:34:03.0936 6020        UI0Detect - ok
19:34:03.0983 6020        uliagpkx        (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
19:34:03.0999 6020        uliagpkx - ok
19:34:04.0092 6020        umbus          (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
19:34:04.0124 6020        umbus - ok
19:34:04.0155 6020        UmPass          (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
19:34:04.0202 6020        UmPass - ok
19:34:04.0233 6020        upnphost        (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll
19:34:04.0280 6020        upnphost - ok
19:34:04.0311 6020        usbaudio        (1d9f2bd026e8e2d45033a4df3f16b78c) C:\Windows\system32\drivers\usbaudio.sys
19:34:04.0342 6020        usbaudio - ok
19:34:04.0373 6020        usbccgp        (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys
19:34:04.0420 6020        usbccgp - ok
19:34:04.0451 6020        usbcir          (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
19:34:04.0467 6020        usbcir - ok
19:34:04.0529 6020        usbehci        (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\drivers\usbehci.sys
19:34:04.0545 6020        usbehci - ok
19:34:04.0592 6020        usbhub          (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
19:34:04.0623 6020        usbhub - ok
19:34:04.0654 6020        usbohci        (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\drivers\usbohci.sys
19:34:04.0670 6020        usbohci - ok
19:34:04.0701 6020        usbprint        (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
19:34:04.0716 6020        usbprint - ok
19:34:04.0748 6020        usbscan        (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
19:34:04.0779 6020        usbscan - ok
19:34:04.0810 6020        USBSTOR        (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:34:04.0857 6020        USBSTOR - ok
19:34:04.0919 6020        usbuhci        (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\drivers\usbuhci.sys
19:34:04.0935 6020        usbuhci - ok
19:34:04.0997 6020        usbvideo        (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\System32\Drivers\usbvideo.sys
19:34:05.0044 6020        usbvideo - ok
19:34:05.0075 6020        UxSms          (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll
19:34:05.0122 6020        UxSms - ok
19:34:05.0262 6020        VAIO Entertainment TV Device Arbitration Service (4e7135d6d0127067e4cfee12259f895d) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
19:34:05.0278 6020        VAIO Entertainment TV Device Arbitration Service ( UnsignedFile.Multi.Generic ) - warning
19:34:05.0278 6020        VAIO Entertainment TV Device Arbitration Service - detected UnsignedFile.Multi.Generic (1)
19:34:05.0387 6020        VAIO Event Service (73328c784ecfe7072bd102f370076b50) C:\Program Files\sony\VAIO Event Service\VESMgr.exe
19:34:05.0403 6020        VAIO Event Service - ok
19:34:05.0481 6020        VAIO Power Management (45a9ae4768840830d0239b52dfdc806a) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
19:34:05.0496 6020        VAIO Power Management - ok
19:34:05.0528 6020        VaultSvc        (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
19:34:05.0543 6020        VaultSvc - ok
19:34:05.0980 6020        VCFw            (0ed1d51dcec67f96cc313d02a1741cf3) C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
19:34:06.0120 6020        VCFw - ok
19:34:06.0276 6020        VcmIAlzMgr      (7295a2b5795e7b8aa128e5df5a29b656) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
19:34:06.0292 6020        VcmIAlzMgr - ok
19:34:06.0370 6020        VcmXmlIfHelper  (69c36d2a7b2169c336d9ce193c9b655e) C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
19:34:06.0386 6020        VcmXmlIfHelper - ok
19:34:06.0417 6020        Vcsw - ok
19:34:06.0635 6020        vdrvroot        (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
19:34:06.0666 6020        vdrvroot - ok
19:34:06.0729 6020        vds            (c3cd30495687c2a2f66a65ca6fd89be9) C:\Windows\System32\vds.exe
19:34:06.0776 6020        vds - ok
19:34:06.0822 6020        vga            (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
19:34:06.0854 6020        vga - ok
19:34:06.0885 6020        VgaSave        (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
19:34:06.0916 6020        VgaSave - ok
19:34:06.0947 6020        vhdmp          (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
19:34:06.0963 6020        vhdmp - ok
19:34:06.0978 6020        viaagp          (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
19:34:06.0994 6020        viaagp - ok
19:34:07.0010 6020        ViaC7          (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
19:34:07.0041 6020        ViaC7 - ok
19:34:07.0056 6020        viaide          (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
19:34:07.0072 6020        viaide - ok
19:34:07.0119 6020        volmgr          (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
19:34:07.0134 6020        volmgr - ok
19:34:07.0166 6020        volmgrx        (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
19:34:07.0197 6020        volmgrx - ok
19:34:07.0244 6020        volsnap        (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
19:34:07.0259 6020        volsnap - ok
19:34:07.0306 6020        vsmraid        (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
19:34:07.0322 6020        vsmraid - ok
19:34:07.0446 6020        VSS            (209a3b1901b83aeb8527ed211cce9e4c) C:\Windows\system32\vssvc.exe
19:34:07.0571 6020        VSS - ok
19:34:07.0587 6020        vwifibus        (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
19:34:07.0618 6020        vwifibus - ok
19:34:07.0774 6020        VzCdbSvc        (79eb419f4a694b4514249e0d3db16ecf) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
19:34:07.0805 6020        VzCdbSvc ( UnsignedFile.Multi.Generic ) - warning
19:34:07.0805 6020        VzCdbSvc - detected UnsignedFile.Multi.Generic (1)
19:34:07.0868 6020        W32Time        (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll
19:34:07.0930 6020        W32Time - ok
19:34:07.0961 6020        WacomPen        (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
19:34:07.0992 6020        WacomPen - ok
19:34:08.0055 6020        WANARP          (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
19:34:08.0117 6020        WANARP - ok
19:34:08.0117 6020        Wanarpv6        (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
19:34:08.0133 6020        Wanarpv6 - ok
19:34:08.0258 6020        wbengine        (691e3285e53dca558e1a84667f13e15a) C:\Windows\system32\wbengine.exe
19:34:08.0336 6020        wbengine - ok
19:34:08.0382 6020        WbioSrvc        (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll
19:34:08.0429 6020        WbioSrvc - ok
19:34:08.0492 6020        wcncsvc        (34eee0dfaadb4f691d6d5308a51315dc) C:\Windows\System32\wcncsvc.dll
19:34:08.0538 6020        wcncsvc - ok
19:34:08.0570 6020        WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll
19:34:08.0616 6020        WcsPlugInService - ok
19:34:08.0694 6020        Wd              (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
19:34:08.0710 6020        Wd - ok
19:34:08.0757 6020        Wdf01000        (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
19:34:08.0772 6020        Wdf01000 - ok
19:34:08.0804 6020        WdiServiceHost  (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll
19:34:08.0882 6020        WdiServiceHost - ok
19:34:08.0897 6020        WdiSystemHost  (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll
19:34:08.0913 6020        WdiSystemHost - ok
19:34:08.0960 6020        WebClient      (a9d880f97530d5b8fee278923349929d) C:\Windows\System32\webclnt.dll
19:34:08.0991 6020        WebClient - ok
19:34:09.0100 6020        WebfettiService (98a64d4207d5957a57b3aa8e510a5bfb) C:\PROGRA~1\Webfetti\bar\2.bin\7dbarsvc.exe
19:34:09.0116 6020        WebfettiService ( UnsignedFile.Multi.Generic ) - warning
19:34:09.0116 6020        WebfettiService - detected UnsignedFile.Multi.Generic (1)
19:34:09.0178 6020        Wecsvc          (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll
19:34:09.0225 6020        Wecsvc - ok
19:34:09.0240 6020        wercplsupport  (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll
19:34:09.0287 6020        wercplsupport - ok
19:34:09.0334 6020        WerSvc          (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll
19:34:09.0365 6020        WerSvc - ok
19:34:09.0412 6020        WfpLwf          (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
19:34:09.0443 6020        WfpLwf - ok
19:34:09.0490 6020        WimFltr        (090a2b8f055343815556a01f725f6c35) C:\Windows\system32\DRIVERS\wimfltr.sys
19:34:09.0506 6020        WimFltr - ok
19:34:09.0521 6020        WIMMount        (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
19:34:09.0537 6020        WIMMount - ok
19:34:09.0537 6020        winachsf - ok
19:34:09.0677 6020        WinDefend      (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll
19:34:09.0724 6020        WinDefend - ok
19:34:09.0740 6020        WinHttpAutoProxySvc - ok
19:34:09.0818 6020        Winmgmt        (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll
19:34:09.0880 6020        Winmgmt - ok
19:34:09.0989 6020        WinRM          (1b91cd34ea3a90ab6a4ef0550174f4cc) C:\Windows\system32\WsmSvc.dll
19:34:10.0083 6020        WinRM - ok
19:34:10.0192 6020        WinUsb          (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys
19:34:10.0239 6020        WinUsb - ok
19:34:10.0332 6020        Wlansvc        (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll
19:34:10.0364 6020        Wlansvc - ok
19:34:10.0395 6020        WmiAcpi        (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
19:34:10.0410 6020        WmiAcpi - ok
19:34:10.0488 6020        wmiApSrv        (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe
19:34:10.0535 6020        wmiApSrv - ok
19:34:10.0722 6020        WMPNetworkSvc  (3b40d3a61aa8c21b88ae57c58ab3122e) C:\Program Files\Windows Media Player\wmpnetwk.exe
19:34:10.0769 6020        WMPNetworkSvc - ok
19:34:10.0800 6020        WPCSvc          (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll
19:34:10.0832 6020        WPCSvc - ok
19:34:10.0863 6020        WPDBusEnum      (aa53356d60af47eacc85bc617a4f3f66) C:\Windows\system32\wpdbusenum.dll
19:34:10.0894 6020        WPDBusEnum - ok
19:34:10.0941 6020        ws2ifsl        (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
19:34:10.0988 6020        ws2ifsl - ok
19:34:11.0019 6020        wscsvc          (6f5d49efe0e7164e03ae773a3fe25340) C:\Windows\System32\wscsvc.dll
19:34:11.0066 6020        wscsvc - ok
19:34:11.0066 6020        WSearch - ok
19:34:11.0237 6020        wuauserv        (fc3ec24fce372c89423e015a2ac1a31e) C:\Windows\system32\wuaueng.dll
19:34:11.0331 6020        wuauserv - ok
19:34:11.0487 6020        WudfPf          (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
19:34:11.0534 6020        WudfPf - ok
19:34:11.0565 6020        WUDFRd          (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
19:34:11.0596 6020        WUDFRd - ok
19:34:11.0643 6020        wudfsvc        (8d1e1e529a2c9e9b6a85b55a345f7629) C:\Windows\System32\WUDFSvc.dll
19:34:11.0674 6020        wudfsvc - ok
19:34:11.0721 6020        WwanSvc        (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll
19:34:11.0768 6020        WwanSvc - ok
19:34:11.0846 6020        yukonw7        (b07c5b7efdf936ff93d4f540938725be) C:\Windows\system32\DRIVERS\yk62x86.sys
19:34:11.0861 6020        yukonw7 - ok
19:34:11.0892 6020        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
19:34:12.0298 6020        \Device\Harddisk0\DR0 - ok
19:34:12.0314 6020        Boot (0x1200)  (2b905d939a30e773cfb21b98b962b1bb) \Device\Harddisk0\DR0\Partition0
19:34:12.0314 6020        \Device\Harddisk0\DR0\Partition0 - ok
19:34:12.0314 6020        ============================================================
19:34:12.0314 6020        Scan finished
19:34:12.0314 6020        ============================================================
19:34:12.0392 2244        Detected object count: 10
19:34:12.0392 2244        Actual detected object count: 10
19:34:35.0604 2244        EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - skipped by user
19:34:35.0604 2244        EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:34:35.0604 2244        EvtEng ( UnsignedFile.Multi.Generic ) - skipped by user
19:34:35.0604 2244        EvtEng ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:34:35.0604 2244        hpqcxs08 ( UnsignedFile.Multi.Generic ) - skipped by user
19:34:35.0604 2244        hpqcxs08 ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:34:35.0620 2244        hpqddsvc ( UnsignedFile.Multi.Generic ) - skipped by user
19:34:35.0620 2244        hpqddsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:34:35.0620 2244        NSUService ( UnsignedFile.Multi.Generic ) - skipped by user
19:34:35.0620 2244        NSUService ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:34:35.0620 2244        PACSPTISVR ( UnsignedFile.Multi.Generic ) - skipped by user
19:34:35.0620 2244        PACSPTISVR ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:34:35.0620 2244        RegSrvc ( UnsignedFile.Multi.Generic ) - skipped by user
19:34:35.0620 2244        RegSrvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:34:35.0620 2244        VAIO Entertainment TV Device Arbitration Service ( UnsignedFile.Multi.Generic ) - skipped by user
19:34:35.0620 2244        VAIO Entertainment TV Device Arbitration Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:34:35.0620 2244        VzCdbSvc ( UnsignedFile.Multi.Generic ) - skipped by user
19:34:35.0620 2244        VzCdbSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:34:35.0620 2244        WebfettiService ( UnsignedFile.Multi.Generic ) - skipped by user
19:34:35.0620 2244        WebfettiService ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 25.06.2012 07:52

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

magicfortune 25.06.2012 10:10

So hier ist der Combofix log

Code:

ComboFix 12-06-25.02 - Désirée 25.06.2012  10:55:55.1.2 - x86
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3039.1682 [GMT 2:00]
ausgeführt von:: c:\users\DÚsirÚe\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files\Webfetti\bar\2.bin\7dBAr.dll
c:\programdata\Roaming
c:\users\Désirée\Kq1vga41c.exe
c:\windows\IsUn0407.exe
c:\windows\security\Database\tmp.edb
c:\windows\system32\SET560C.tmp
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-05-25 bis 2012-06-25  ))))))))))))))))))))))))))))))
.
.
2012-06-25 09:04 . 2012-06-25 09:04        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-06-25 08:47 . 2012-06-25 08:47        --------        d-----w-        C:\c30a2a61f5015bb8fe48004e
2012-06-23 17:24 . 2012-06-25 08:59        56200        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{0C4BD307-405B-41EF-9691-60466410D2AE}\offreg.dll
2012-06-23 17:06 . 2012-06-23 17:06        476936        ----a-w-        c:\windows\system32\npdeployJava1.dll
2012-06-23 07:45 . 2012-05-31 03:41        6762896        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{0C4BD307-405B-41EF-9691-60466410D2AE}\mpengine.dll
2012-06-23 07:27 . 2012-06-23 07:27        --------        d-----w-        C:\fe76a9076969f8e450ab0fd38fee7b
2012-06-23 07:27 . 2012-06-23 07:27        --------        d-----w-        c:\windows\CheckSur
2012-06-21 18:04 . 2012-06-21 18:04        770384        ----a-w-        c:\program files\Mozilla Firefox\msvcr100.dll
2012-06-21 18:04 . 2012-06-21 18:04        421200        ----a-w-        c:\program files\Mozilla Firefox\msvcp100.dll
2012-06-21 17:58 . 2012-06-02 22:19        53784        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-21 17:58 . 2012-06-02 22:19        45080        ----a-w-        c:\windows\system32\wups2.dll
2012-06-21 17:58 . 2012-06-02 22:19        1933848        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-21 17:58 . 2012-06-02 22:12        2422272        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-21 17:57 . 2012-06-02 13:19        171904        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-21 17:57 . 2012-06-02 13:12        33792        ----a-w-        c:\windows\system32\wuapp.exe
2012-06-20 15:08 . 2012-06-20 15:08        --------        d-----w-        C:\found.000
2012-06-20 14:29 . 2012-06-20 14:29        --------        d-----w-        C:\_OTL
2012-06-14 19:48 . 2012-06-14 19:48        --------        d-----w-        c:\users\Désirée\AppData\Local\Macromedia
2012-06-13 18:01 . 2012-04-28 03:17        183808        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-06-12 15:59 . 2012-06-12 15:59        --------        d-----w-        c:\program files\ESET
2012-06-10 18:23 . 2012-06-10 18:23        --------        d-----w-        c:\users\Désirée\AppData\Roaming\Avira
2012-06-10 18:17 . 2012-04-16 19:17        36000        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2012-06-10 18:17 . 2012-04-27 08:20        137928        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-06-10 18:17 . 2012-04-24 22:32        83392        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2012-06-10 18:17 . 2012-06-10 18:17        --------        d-----w-        c:\programdata\Avira
2012-06-10 18:17 . 2012-06-10 18:17        --------        d-----w-        c:\program files\Avira
2012-06-10 14:56 . 2012-06-10 14:56        --------        d-----w-        c:\users\Désirée\AppData\Roaming\Malwarebytes
2012-06-10 14:56 . 2012-06-10 14:56        --------        d-----w-        c:\programdata\Malwarebytes
2012-06-10 14:56 . 2012-06-10 14:56        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2012-06-10 14:56 . 2012-04-04 13:56        22344        ----a-w-        c:\windows\system32\drivers\mbam.sys
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-23 17:06 . 2010-05-02 19:13        472840        ----a-w-        c:\windows\system32\deployJava1.dll
2012-06-23 17:04 . 2012-04-12 19:44        426184        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-06-23 17:04 . 2011-06-15 21:42        70344        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-31 04:39 . 2012-05-12 08:55        3968368        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2012-03-31 04:39 . 2012-05-12 08:55        3913072        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-03-30 10:23 . 2012-05-12 08:55        1291632        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-03-08 18:50 . 2012-03-08 18:50        8862099        ----a-w-        c:\program files\Setup_MHRemake.exe
2012-06-21 18:05 . 2011-04-09 18:24        85472        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
2010-07-30 20:10 . 2010-07-30 20:10        119808        ----a-w-        c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NSUFloatingUI"="c:\program files\Sony\Network Utility\LANUtil.exe" [2008-12-21 274432]
"DriverScanner"="c:\program files\Uniblue\DriverScanner\launcher.exe" [2011-05-16 338296]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2009-04-13 155648]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-01-06 6703648]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-01-06 1833504]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-30 30192]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2008-12-18 317288]
"MarketingTools"="c:\program files\Sony\Marketing Tools\MarketingTools.exe" [2009-06-17 26624]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-05-20 111928]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-12-09 74752]
"mumservice"="c:\program files\Motorola\Software Update\mumservice.exe" [2011-02-02 1066304]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-05-01 348624]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\users\Désirée\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-3-1 789032]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2009-01-19 10:49        98304        ------w-        c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=""
"FirewallOverride"=""
.
R2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [2008-12-19 415592]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-23 250056]
R3 camfilt2;camfilt2;c:\windows\system32\DRIVERS\camfilt2.sys [2007-08-06 94720]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-30 30192]
R3 hxctlflt;hxctlflt;c:\windows\system32\DRIVERS\hxctlflt.sys [2009-02-09 99968]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 22344]
R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [x]
R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [x]
R3 MotDev;Motorola Inc. USB Device;c:\windows\system32\DRIVERS\motodrv.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-21 113120]
R3 SOHCImp;VAIO Media plus Content Importer;c:\program files\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2009-02-05 120104]
R3 SOHDBSvr;VAIO Media plus Database Manager;c:\program files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [2009-02-05 70952]
R3 SOHDms;VAIO Media plus Digital Media Server;c:\program files\Common Files\Sony Shared\SOHLib\SOHDms.exe [2009-02-05 390440]
R3 SOHDs;VAIO Media plus Device Searcher;c:\program files\Common Files\Sony Shared\SOHLib\SOHDs.exe [2009-02-05 75048]
R3 SOHPlMgr;VAIO Media plus Playlist Manager;c:\program files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [2009-02-05 91432]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2009-01-16 83240]
R4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-04-16 36000]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2012-05-01 86224]
S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE [2009-09-14 153600]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [2009-09-14 121856]
S2 MotoHelper;MotoHelper Service;c:\program files\Motorola\MotoHelper\MotoHelperService.exe [2011-08-10 227184]
S2 NSUService;NSUService;c:\program files\sony\Network Utility\NSUService.exe [2008-12-21 303104]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-17 11032]
S2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService.exe [2009-01-06 109088]
S2 uCamMonitor;CamMonitor;c:\program files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2008-09-18 104960]
S2 VCFw;VAIO Content Folder Watcher;c:\program files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2009-01-14 5184872]
S2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2009-01-19 394536]
S2 WebfettiService;Webfetti Service;c:\progra~1\Webfetti\bar\2.bin\7dbarsvc.exe [2011-04-02 36864]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2008-04-24 17920]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-10 29736]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000-Serie - Adaptertreiber für Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys [2008-11-19 9344]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
S3 yukonw7;NDIS6.2-Miniporttreiber für Marvell Yukon-Ethernet-Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-07-13 311296]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 24769774
*Deregistered* - 24769774
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt        REG_MULTI_SZ          hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2012-06-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-12 17:04]
.
2012-06-24 c:\windows\Tasks\DriverScanner.job
- c:\program files\Uniblue\DriverScanner\dsmonitor.exe [2011-08-03 09:22]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://start.icq.com/
mStart Page = hxxp://home.sweetim.com
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Free YouTube Download - c:\users\Désirée\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
Handler: webwebweb - {879506D7-73DF-8D45-BBDD-123467926D12} -
FF - ProfilePath - c:\users\Désirée\AppData\Roaming\Mozilla\Firefox\Profiles\gjpz37rw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=CDS&o=16225&locale=en_US&apn_uid=6789FF94-1B5C-418F-AB67-D056611F19BA&apn_ptnrs=QQ&apn_sauid=B0654D97-0C66-4B09-B061-B47EE50BE6D3&apn_dtid=YYYYYYYYDE&&q=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - c:\program files\Ask.com\GenericAskToolbar.dll
URLSearchHooks-{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - c:\program files\Winamp Toolbar\winamptb.dll
URLSearchHooks-{EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
AddRemove-Adobe Acrobat 5.0 - c:\windows\ISUN0407.EXE
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000004
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-06-25  11:07:21
ComboFix-quarantined-files.txt  2012-06-25 09:07
.
Vor Suchlauf: 15 Verzeichnis(se), 219.246.903.296 Bytes frei
Nach Suchlauf: 24 Verzeichnis(se), 219.706.195.968 Bytes frei
.
- - End Of File - - 03A80E941127607E1C65280131679266

mfg
magicfortune

cosinus 25.06.2012 12:09

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

magicfortune 25.06.2012 13:26

So hier erstmal das gmer Log
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-06-25 14:23:14
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD32 rev.11.0
Running: 6jb2pnmk.exe; Driver: C:\Users\DSIRE~1\AppData\Local\Temp\kxdiifod.sys


---- System - GMER 1.0.15 ----

SSDT  905D4DBE                                                                                          ZwCreateSection
SSDT  905D4DC8                                                                                          ZwRequestWaitReplyPort
SSDT  905D4DC3                                                                                          ZwSetContextThread
SSDT  905D4DCD                                                                                          ZwSetSecurityObject
SSDT  905D4DD2                                                                                          ZwSystemDebugControl
SSDT  905D4D5F                                                                                          ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text  ntkrnlpa.exe!ZwRollbackEnlistment + 140D                                                          834403C9 1 Byte  [06]
.text  ntkrnlpa.exe!KiDispatchInterrupt + 5A2                                                            83479D52 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text  ntkrnlpa.exe!KeRemoveQueueEx + 11F7                                                                83480EAC 4 Bytes  [BE, 4D, 5D, 90]
.text  ntkrnlpa.exe!KeRemoveQueueEx + 1553                                                                83481208 4 Bytes  [C8, 4D, 5D, 90] {ENTER 0x5d4d, 0x90}
.text  ntkrnlpa.exe!KeRemoveQueueEx + 1597                                                                8348124C 4 Bytes  [C3, 4D, 5D, 90] {RET ; DEC EBP; POP EBP; NOP }
.text  ntkrnlpa.exe!KeRemoveQueueEx + 1613                                                                834812C8 4 Bytes  [CD, 4D, 5D, 90] {INT 0x4d; POP EBP; NOP }
.text  ntkrnlpa.exe!KeRemoveQueueEx + 1667                                                                8348131C 4 Bytes  [D2, 4D, 5D, 90] {ROR BYTE [EBP+0x5d], CL; NOP }
.text  ...                                                                                               
.text  C:\Windows\system32\DRIVERS\atikmdag.sys                                                          section is writeable [0x91E1A000, 0x2D5378, 0xE8000020]

---- User IAT/EAT - GMER 1.0.15 ----

IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                    [741424CB] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]              [7412562E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]              [741256EC] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                    [74142546] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]          [741385AA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]            [74134D5E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]            [74135105] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]          [741351DA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP]  [74136707] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]            [74138301] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]      [74138850] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]    [741390B1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]          [7413E254] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT    C:\Windows\Explorer.EXE[2444] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]              [74134C90] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg    HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002433d377d6                       
Reg    HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002433d377d6@0017e6f42513          0xDB 0xB4 0x05 0xC5 ...
Reg    HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings                         
Reg    HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002433d377d6 (not active ControlSet)   
Reg    HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002433d377d6@0017e6f42513              0xDB 0xB4 0x05 0xC5 ...
Reg    HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings (not active ControlSet)     

---- EOF - GMER 1.0.15 ----

So und hier das osam log

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 14:40:35 on 25.06.2012

OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 32-bit
Default Browser: Mozilla Corporation Firefox 13.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[AppInit DLLs]
-----( HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows )-----
"AppInit_DLLs" - "Google" - c:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

[Common]
-----( %SystemRoot%\Tasks )-----
"DriverScanner.job" - "Uniblue Systems Limited" - C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"iproset.cpl" - "Intel(R) Corporation" - C:\Windows\system32\iproset.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"PROSet Tools" - "Intel(R) Corporation" - C:\Windows\System32\iPROSet.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\Users\DSIRE~1\AppData\Local\Temp\catchme.sys  (File not found)
"FssFltr" (fssfltr) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\fssfltr.sys
"HSF_DPV" (HSF_DPV) - ? - C:\Windows\System32\DRIVERS\HSX_DPV.sys  (File not found)
"HSXHWAZL" (HSXHWAZL) - ? - C:\Windows\System32\DRIVERS\HSXHWAZL.sys  (File not found)
"kxdiifod" (kxdiifod) - ? - C:\Users\DSIRE~1\AppData\Local\Temp\kxdiifod.sys  (Hidden registry entry, rootkit activity | File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"mdmxsdk" (mdmxsdk) - ? - C:\Windows\System32\DRIVERS\mdmxsdk.sys  (File not found)
"MotCcgpFlService" (motccgpfl) - ? - C:\Windows\System32\DRIVERS\motccgpfl.sys  (File not found)
"Motorola Inc. USB Device" (MotDev) - ? - C:\Windows\System32\DRIVERS\motodrv.sys  (File not found)
"Motorola USB Composite Device Driver" (motccgp) - ? - C:\Windows\System32\DRIVERS\motccgp.sys  (File not found)
"regi" (regi) - "InterVideo" - C:\Windows\System32\drivers\regi.sys
"Sony DMI Call service" (DMICall) - "Sony Corporation" - C:\Windows\System32\DRIVERS\DMICall.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"WimFltr" (WimFltr) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\wimfltr.sys
"winachsf" (winachsf) - ? - C:\Windows\System32\DRIVERS\HSX_CNXT.sys  (File not found)

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{0561EC90-CE54-4f0c-9C55-E226110A740C} "{0561EC90-CE54-4f0c-9C55-E226110A740C}" - ? -  (File not found | COM-object registry key not found)
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
{B658800C-F66E-4EF3-AB85-6C0C227862A9} "ViProtocolOLE Class" - ? - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll
{879506D7-73DF-8D45-BBDD-123467926D12} "Webwebweb Pluggable Protocol" - ? - C:\Program Files\WebWebWeb\Plugin\Version_449\link64_plugin.dll  (File not found)
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{327669A0-59A7-4be9-B99E-1C9F3A57611A} "Haali Matroska Thumbnail Exctractor" - ? -  (File not found | COM-object registry key not found)
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? -  (File not found | COM-object registry key not found)
{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\btncopy.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{6F5C0F40-1419-4DC8-8D2F-D5EC5FCF07AB} "Sprint.ExplorerIntegration.9" - "ABBYY" - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Integration\SprintIntegration.dll
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{E0D79304-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Program Files\WinZip\wzshlstb.dll
{E0D79305-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Program Files\WinZip\wzshlstb.dll
{E0D79306-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Program Files\WinZip\wzshlstb.dll
{E0D79307-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Program Files\WinZip\wzshlstb.dll
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )-----
 "{855F3B16-6D32-4fe6-8A56-BBB695989046}" - ? -  (File not found | COM-object registry key not found)
{855F3B16-6D32-4fe6-8A56-BBB695989046} "{855F3B16-6D32-4fe6-8A56-BBB695989046}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} "Java Plug-in 1.6.0_07" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_33" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} "Java Plug-in 1.6.0_33" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_33" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_33.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "In Blog veröffentlichen" - "Microsoft Corporation" - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
"PokerStars.net" - "PokerStars" - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "AVG Security Toolbar" - ? - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
{95B7759C-8C7F-4BF1-B163-73684A933233} "AVG Security Toolbar" - ? - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll
{3E532CE8-C6D9-4A10-8ACE-4348C96E8B6A} "FastestTubeBHO Class" - "Kwizzu" - C:\Program Files\FastestTube\1.2.12\WombatBHO.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\ssv.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} "{9421DD08-935F-4701-A9CA-22DF90AC4EA6}" - ? -  (File not found | COM-object registry key not found)

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"OpenOffice.org 3.3.lnk" - ? - C:\Program Files\OpenOffice.org 3\program\quickstart.exe  (Shortcut exists | File found, but it contains no detailed information | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"HP Digital Imaging Monitor.lnk" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe  (Shortcut exists | File exists)
"Bluetooth.lnk" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"DriverScanner" - "Uniblue Systems Limited" - "C:\Program Files\Uniblue\DriverScanner\launcher.exe" delay 20000
"NSUFloatingUI" - "Sony Corporation" - "C:\Program Files\Sony\Network Utility\LANUtil.exe"
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"EEventManager" - "SEIKO EPSON CORPORATION" - "C:\Program Files\Epson Software\Event Manager\EEventManager.exe"
"Google Desktop Search" - "Google" - "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"HP Software Update" - "Hewlett-Packard Co." - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"ISBMgr.exe" - ? - "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
"MarketingTools" - "Sony Corporation" - C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
"mumservice" - "Motorola" - C:\Program Files\Motorola\Software Update\mumservice.exe
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"SweetIM" - "SweetIM Technologies Ltd." - C:\Program Files\SweetIM\Messenger\SweetIM.exe
"vProt" - ? - "C:\Program Files\AVG Secure Search\vprot.exe"
"WinampAgent" - "Nullsoft, Inc." - "C:\Program Files\Winamp\winampa.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"EpsonNet Print Port" - "SEIKO EPSON CORPORATION" - C:\Windows\system32\enppmon.dll
"LIDIL hpzlllhn" - "Hewlett-Packard Company" - C:\Windows\system32\hpzlllhn.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"ABBYY FineReader 9.0 Sprint Licensing Service" (ABBYY.Licensing.FineReader.Sprint.9.0) - "ABBYY" - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"ArcSoft Connect Daemon" (ACDaemon) - "ArcSoft Inc." - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"Bluetooth Service" (btwdins) - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
"CamMonitor" (uCamMonitor) - "ArcSoft, Inc." - C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
"EpsonBidirectionalService" (EpsonBidirectionalService) - "SEIKO EPSON CORPORATION" - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
"Google Desktop Manager 5.9.1005.12335" (GoogleDesktopManager-051210-111108) - "Google" - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
"HP CUE DeviceDiscovery Service" (hpqddsvc) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
"hpqcxs08" (hpqcxs08) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
"Intel® PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
"Intel® PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
"IviRegMgr" (IviRegMgr) - "InterVideo" - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"MotoHelper Service" (MotoHelper) - ? - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
"NSUService" (NSUService) - "Sony Corporation" - C:\Program Files\sony\Network Utility\NSUService.exe
"PACSPTISVR" (PACSPTISVR) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
"VAIO Content Folder Watcher" (VCFw) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
"VAIO Content Metadata Intelligent Analyzing Manager" (VcmIAlzMgr) - "Sony Corporation" - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
"VAIO Content Metadata XML Interface" (VcmXmlIfHelper) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
"VAIO Entertainment Database Service" (VzCdbSvc) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
"VAIO Entertainment TV Device Arbitration Service" (VAIO Entertainment TV Device Arbitration Service) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
"VAIO Entertainment UPnP Client Adapter" (Vcsw) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
"VAIO Event Service" (VAIO Event Service) - "Sony Corporation" - C:\Program Files\sony\VAIO Event Service\VESMgr.exe
"VAIO Media plus Content Importer" (SOHCImp) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHCImp.exe
"VAIO Media plus Database Manager" (SOHDBSvr) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
"VAIO Media plus Device Searcher" (SOHDs) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDs.exe
"VAIO Media plus Digital Media Server" (SOHDms) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDms.exe
"VAIO Media plus Playlist Manager" (SOHPlMgr) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
"VAIO Power Management" (VAIO Power Management) - "Sony Corporation" - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
"vToolbarUpdater11.1.0" (vToolbarUpdater11.1.0) - ? - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe
"Webfetti Service" (WebfettiService) - "Webfetti" - C:\PROGRA~1\Webfetti\bar\2.bin\7dbarsvc.exe
"Windows Live Family Safety-Dienst" (fsssvc) - "Microsoft Corporation" - C:\Program Files\Windows Live\Family Safety\fsssvc.exe

[Winlogon]
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )-----
"VESWinlogon" - "Sony Corporation" - C:\Windows\system32\VESWinlogon.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


cosinus 25.06.2012 14:48

ok fehlt noch aswMBR

magicfortune 25.06.2012 15:24

Und hier endlich das aswlog

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-06-25 14:43:04
-----------------------------
14:43:04.440    OS Version: Windows 6.1.7601 Service Pack 1
14:43:04.440    Number of processors: 2 586 0x170A
14:43:04.440    ComputerName: DÉSIRÉE-PC  UserName: Désirée
14:43:05.750    Initialize success
14:44:09.392    AVAST engine defs: 12062500
14:46:05.391    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
14:46:05.395    Disk 0 Vendor: WDC_WD32 11.0 Size: 305245MB BusType: 3
14:46:05.398    Disk 1  \Device\Harddisk1\DR1 -> \Device\00000069
14:46:05.401    Disk 1 Vendor: RICOH 01 Size: 305245MB BusType: 0
14:46:05.404    Disk 2  \Device\Harddisk2\DR2 -> \Device\0000006a
14:46:05.407    Disk 2 Vendor: RICOH 02 Size: 305245MB BusType: 0
14:46:05.504    Disk 0 MBR read successfully
14:46:05.511    Disk 0 MBR scan
14:46:05.581    Disk 0 Windows 7 default MBR code
14:46:05.696    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        10436 MB offset 2048
14:46:05.766    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS      294807 MB offset 21374976
14:46:05.827    Disk 0 scanning sectors +625140400
14:46:06.252    Disk 0 scanning C:\Windows\system32\drivers
14:47:34.663    Service scanning
14:48:19.384    Modules scanning
14:50:06.320    Disk 0 trace - called modules:
14:50:06.367   
14:50:07.724    AVAST engine scan C:\Windows
14:51:50.778    AVAST engine scan C:\Windows\system32
15:14:44.033    AVAST engine scan C:\Windows\system32\drivers
15:16:52.405    AVAST engine scan C:\Users\Désirée
15:56:40.568    AVAST engine scan C:\ProgramData
15:59:00.326    Scan finished successfully
16:22:56.608    Disk 0 MBR has been saved successfully to "C:\Users\Désirée\Desktop\MBR.dat"
16:22:56.616    The log file has been saved successfully to "C:\Users\Désirée\Desktop\aswMBR.txt"


cosinus 25.06.2012 16:13

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

magicfortune 26.06.2012 17:28

So hier erstmal der malwarebytes log

Code:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.25.07

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
Désirée :: DÉSIRÉE-PC [Administrator]

25.06.2012 17:24:53
mbam-log-2012-06-26 (18-27-24).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 413530
Laufzeit: 1 Stunde(n), 27 Minute(n), 26 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\Désirée\Documents\DVDVideoSoft\Webfetti.exe (PUP.FunWebProducts) -> Keine Aktion durchgeführt.

(Ende)


cosinus 26.06.2012 17:33

Hm, das ist Werbemüll, bitte entfernen!

magicfortune 27.06.2012 13:50

So und hier ist der Super AntiSpyware log

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 06/27/2012 at 02:48 PM

Application Version : 5.1.1002

Core Rules Database Version : 8798
Trace Rules Database Version: 6610

Scan type      : Complete Scan
Total Scan Time : 20:10:16

Operating System Information
Windows 7 Home Premium 32-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 966
Memory threats detected  : 0
Registry items scanned    : 36287
Registry threats detected : 0
File items scanned        : 249709
File threats detected    : 707

Adware.Tracking Cookie
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@ad.360yield[2].txt [ /ad.360yield ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@ad.adition[2].txt [ /ad.adition ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@ad.adserver01[2].txt [ /ad.adserver01 ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@ad4.adfarm1.adition[1].txt [ /ad4.adfarm1.adition ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@adform[1].txt [ /adform ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@adtech[2].txt [ /adtech ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@adx.chip[1].txt [ /adx.chip ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@adxpose[1].txt [ /adxpose ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@ar.atwola[1].txt [ /ar.atwola ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@bluestreak[2].txt [ /bluestreak ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@bs.serving-sys[1].txt [ /bs.serving-sys ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@bs.serving-sys[3].txt [ /bs.serving-sys ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@content.yieldmanager[3].txt [ /content.yieldmanager ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@de.at.atwola[1].txt [ /de.at.atwola ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@eas.apm.emediate[2].txt [ /eas.apm.emediate ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@fl01.ct2.comclick[2].txt [ /fl01.ct2.comclick ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@freeyoupornos[1].txt [ /freeyoupornos ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@freeyouporno[2].txt [ /freeyouporno ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@imrworldwide[2].txt [ /imrworldwide ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@msnportal.112.2o7[1].txt [ /msnportal.112.2o7 ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@overture[2].txt [ /overture ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@questionmarket[1].txt [ /questionmarket ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@rotator.adjuggler[1].txt [ /rotator.adjuggler ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@secmedia[2].txt [ /secmedia ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@sevenoneintermedia.112.2o7[1].txt [ /sevenoneintermedia.112.2o7 ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@specificclick[2].txt [ /specificclick ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@tacoda[1].txt [ /tacoda ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@track.effiliation[1].txt [ /track.effiliation ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@track.effiliation[3].txt [ /track.effiliation ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@tracking.hannoversche[2].txt [ /tracking.hannoversche ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@traffictrack[2].txt [ /traffictrack ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@tto2.traffictrack[1].txt [ /tto2.traffictrack ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@unitymedia[1].txt [ /unitymedia ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@webmasterplan[2].txt [ /webmasterplan ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@weborama[1].txt [ /weborama ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@ww251.smartadserver[1].txt [ /ww251.smartadserver ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@www.freeyoupornos[2].txt [ /www.freeyoupornos ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@www.freeyouporno[1].txt [ /www.freeyouporno ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@www.windowsmedia[2].txt [ /www.windowsmedia ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\désirée@xiti[1].txt [ /xiti ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\7MV2MLR5.txt [ /smartadserver.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\7DN95BBP.txt [ /tradedoubler.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\2WTS9GOO.txt [ /ad.zanox.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\4XU5SQL1.txt [ /atwola.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\9A785LAR.txt [ /tracking.quisma.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\51OHUF4X.txt [ /2o7.net ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\LODJFGRP.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\EQWE6VB2.txt [ /ad1.adfarm1.adition.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\UXQ4JTKL.txt [ /adfarm1.adition.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\ZEF1V797.txt [ /atdmt.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\8NGTI2JX.txt [ /mediaplex.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\ZF0ELMKD.txt [ /googleads.g.doubleclick.net ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\SHYCBTAB.txt [ /ad1.adfarm1.adition.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\43LB0TU9.txt [ /serving-sys.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\BOZ0HOW3.txt [ /track.adform.net ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\HQC3UGO9.txt [ /doubleclick.net ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\XVGTV8FG.txt [ /mediaplex.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\EOA9ZSXD.txt [ /zanox.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\O0AC2VUV.txt [ /fastclick.net ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\QPYYL1D2.txt [ /dyntracker.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\8CSIN29A.txt [ /zanox-affiliate.de ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\Z980KVU2.txt [ /im.banner.t-online.de ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\351A2DUN.txt [ /media.gan-online.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\YWGNX81P.txt [ /mywebsearch.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\8W7M26WM.txt [ /tacoda.at.atwola.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\AL3COHR1.txt [ /ad.yieldmanager.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\G184F24L.txt [ /adviva.net ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\TCW3WOAC.txt [ /advertising.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\N3HA73PF.txt [ /ar.atwola.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\G3NFMH02.txt [ /ad3.adfarm1.adition.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\1HJD3YE0.txt [ /ads.creative-serving.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\3LKK2VPL.txt [ /content.yieldmanager.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\5ZBYP15Q.txt [ /at.atwola.com ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\G5M2OSRV.txt [ /www.zanox-affiliate.de ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\OWNS8ALU.txt [ /ad.dyntracker.de ]
        C:\Users\Désirée\AppData\Roaming\Microsoft\Windows\Cookies\YZM6L124.txt [ /apmebf.com ]
        C:\USERS\DéSIRéE\AppData\Roaming\Microsoft\Windows\Cookies\désirée@www.jappy[2].txt [ Cookie:désirée@www.jappy.de/i/ad/ ]
        C:\USERS\DéSIRéE\AppData\Roaming\Microsoft\Windows\Cookies\Low\désirée@tradedoubler[1].txt [ Cookie:désirée@tradedoubler.com/ ]
        C:\USERS\DéSIRéE\AppData\Roaming\Microsoft\Windows\Cookies\Low\désirée@tracking.quisma[2].txt [ Cookie:désirée@tracking.quisma.com/ ]
        C:\USERS\DéSIRéE\AppData\Roaming\Microsoft\Windows\Cookies\Low\désirée@tto2.traffictrack[1].txt [ Cookie:désirée@tto2.traffictrack.de/ ]
        C:\USERS\DéSIRéE\AppData\Roaming\Microsoft\Windows\Cookies\Low\désirée@sevenoneintermedia.112.2o7[1].txt [ Cookie:désirée@sevenoneintermedia.112.2o7.net/ ]
        C:\USERS\DéSIRéE\AppData\Roaming\Microsoft\Windows\Cookies\Low\désirée@atdmt[2].txt [ Cookie:désirée@atdmt.com/ ]
        C:\USERS\DéSIRéE\AppData\Roaming\Microsoft\Windows\Cookies\Low\désirée@doubleclick[2].txt [ Cookie:désirée@doubleclick.net/ ]
        C:\USERS\DéSIRéE\AppData\Roaming\Microsoft\Windows\Cookies\Low\désirée@zanox[1].txt [ Cookie:désirée@zanox.com/ ]
        C:\USERS\DéSIRéE\AppData\Roaming\Microsoft\Windows\Cookies\Low\désirée@msnportal.112.2o7[1].txt [ Cookie:désirée@msnportal.112.2o7.net/ ]
        C:\USERS\DéSIRéE\AppData\Roaming\Microsoft\Windows\Cookies\Low\désirée@adtech[1].txt [ Cookie:désirée@adtech.de/ ]
        C:\USERS\DéSIRéE\Cookies\7MV2MLR5.txt [ Cookie:désirée@smartadserver.com/ ]
        C:\USERS\DéSIRéE\Cookies\7DN95BBP.txt [ Cookie:désirée@tradedoubler.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@ad.adition[2].txt [ Cookie:désirée@ad.adition.net/ ]
        C:\USERS\DéSIRéE\Cookies\2WTS9GOO.txt [ Cookie:désirée@ad.zanox.com/ ]
        C:\USERS\DéSIRéE\Cookies\4XU5SQL1.txt [ Cookie:désirée@atwola.com/ ]
        C:\USERS\DéSIRéE\Cookies\9A785LAR.txt [ Cookie:désirée@tracking.quisma.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@tto2.traffictrack[1].txt [ Cookie:désirée@tto2.traffictrack.de/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@adx.chip[1].txt [ Cookie:désirée@adx.chip.de/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@de.at.atwola[1].txt [ Cookie:désirée@de.at.atwola.com/ ]
        C:\USERS\DéSIRéE\Cookies\EQWE6VB2.txt [ Cookie:désirée@ad1.adfarm1.adition.com/ ]
        C:\USERS\DéSIRéE\Cookies\UXQ4JTKL.txt [ Cookie:désirée@adfarm1.adition.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@sevenoneintermedia.112.2o7[1].txt [ Cookie:désirée@sevenoneintermedia.112.2o7.net/ ]
        C:\USERS\DéSIRéE\Cookies\ZEF1V797.txt [ Cookie:désirée@atdmt.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@unitymedia[1].txt [ Cookie:désirée@unitymedia.de/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@www.freeyouporno[1].txt [ Cookie:désirée@www.freeyouporno.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@track.effiliation[3].txt [ Cookie:désirée@track.effiliation.com/servlet/ ]
        C:\USERS\DéSIRéE\Cookies\ZF0ELMKD.txt [ Cookie:désirée@googleads.g.doubleclick.net/ ]
        C:\USERS\DéSIRéE\Cookies\SHYCBTAB.txt [ Cookie:désirée@ad1.adfarm1.adition.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@ad4.adfarm1.adition[1].txt [ Cookie:désirée@ad4.adfarm1.adition.com/ ]
        C:\USERS\DéSIRéE\Cookies\43LB0TU9.txt [ Cookie:désirée@serving-sys.com/ ]
        C:\USERS\DéSIRéE\Cookies\BOZ0HOW3.txt [ Cookie:désirée@track.adform.net/ ]
        C:\USERS\DéSIRéE\Cookies\HQC3UGO9.txt [ Cookie:désirée@doubleclick.net/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@www.freeyoupornos[2].txt [ Cookie:désirée@www.freeyoupornos.com/ ]
        C:\USERS\DéSIRéE\Cookies\XVGTV8FG.txt [ Cookie:désirée@mediaplex.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@specificclick[2].txt [ Cookie:désirée@specificclick.net/ ]
        C:\USERS\DéSIRéE\Cookies\EOA9ZSXD.txt [ Cookie:désirée@zanox.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@ar.atwola[1].txt [ Cookie:désirée@ar.atwola.com/html ]
        C:\USERS\DéSIRéE\Cookies\désirée@content.yieldmanager[3].txt [ Cookie:désirée@content.yieldmanager.com/ak/ ]
        C:\USERS\DéSIRéE\Cookies\QPYYL1D2.txt [ Cookie:désirée@dyntracker.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@msnportal.112.2o7[1].txt [ Cookie:désirée@msnportal.112.2o7.net/ ]
        C:\USERS\DéSIRéE\Cookies\8CSIN29A.txt [ Cookie:désirée@zanox-affiliate.de/ ]
        C:\USERS\DéSIRéE\Cookies\Z980KVU2.txt [ Cookie:désirée@im.banner.t-online.de/ ]
        C:\USERS\DéSIRéE\Cookies\351A2DUN.txt [ Cookie:désirée@media.gan-online.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@overture[2].txt [ Cookie:désirée@overture.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@www.jappy[2].txt [ Cookie:désirée@www.jappy.de/i/ad/ ]
        C:\USERS\DéSIRéE\Cookies\YWGNX81P.txt [ Cookie:désirée@mywebsearch.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@ww251.smartadserver[1].txt [ Cookie:désirée@ww251.smartadserver.com/ ]
        C:\USERS\DéSIRéE\Cookies\8W7M26WM.txt [ Cookie:désirée@tacoda.at.atwola.com/ ]
        C:\USERS\DéSIRéE\Cookies\AL3COHR1.txt [ Cookie:désirée@ad.yieldmanager.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@www.windowsmedia[2].txt [ Cookie:désirée@www.windowsmedia.com/ ]
        C:\USERS\DéSIRéE\Cookies\G184F24L.txt [ Cookie:désirée@adviva.net/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@adform[1].txt [ Cookie:désirée@adform.net/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@tacoda[1].txt [ Cookie:désirée@tacoda.net/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@tracking.hannoversche[2].txt [ Cookie:désirée@tracking.hannoversche.de/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@questionmarket[1].txt [ Cookie:désirée@questionmarket.com/ ]
        C:\USERS\DéSIRéE\Cookies\N3HA73PF.txt [ Cookie:désirée@ar.atwola.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@freeyouporno[2].txt [ Cookie:désirée@freeyouporno.com/ ]
        C:\USERS\DéSIRéE\Cookies\3LKK2VPL.txt [ Cookie:désirée@content.yieldmanager.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@track.effiliation[1].txt [ Cookie:désirée@track.effiliation.com/ ]
        C:\USERS\DéSIRéE\Cookies\5ZBYP15Q.txt [ Cookie:désirée@at.atwola.com/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@adtech[2].txt [ Cookie:désirée@adtech.de/ ]
        C:\USERS\DéSIRéE\Cookies\désirée@freeyoupornos[1].txt [ Cookie:désirée@freeyoupornos.com/ ]
        C:\USERS\DéSIRéE\Cookies\OWNS8ALU.txt [ Cookie:désirée@ad.dyntracker.de/ ]
        C:\USERS\DéSIRéE\Cookies\YZM6L124.txt [ Cookie:désirée@apmebf.com/ ]
        cdn.eyewonder.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        delivery.ibanner.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        files.youporn.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        imagesrv.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        media.adxpansion.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        media.gan-online.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        media.mtvnservices.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        media.vagosex.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        mediathek.ffh.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        msnbcmedia.msn.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        objects.tremormedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        s0.2mdn.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        vht.tradedoubler.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        www.manga-pornos.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FZD6SR9P ]
        C:\USERS\DéSIRéE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\DéSIRéE@2O7[1].TXT [ /2O7 ]
        C:\USERS\DéSIRéE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\DéSIRéE@TRAFFICTRACK[2].TXT [ /TRAFFICTRACK ]
        .smartadserver.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .youporn.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ads.crakmedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ads.zeusclicks.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        tradefx.advertserve.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adlegend.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjlokpcjcbo.stats.esomniture.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .alphaporno.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .traffichaus.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.vagosex.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .vagosex.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        adserver.momo-net.ch [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        adserver.momo-net.ch [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.tiniporn.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tiniporn.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .purpleporno.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .youporngay.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .gaiainteractive.112.2o7.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .solvemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .solvemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        urbia.wwe-media.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.webtrekk.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .track.bigcockcrew.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .sexyfuckgames.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .markussexblog.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ads2.zeusclicks.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .nextag.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        counters.gigya.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        wstat.wibiya.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .porno-saboom.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .linksynergy.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .linksynergy.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .linksynergy.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ww251.smartadserver.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .paypal.112.2o7.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .enoratraffic.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wfmyqjajobp.stats.esomniture.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        spenden.wikimedia.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        spenden.wikimedia.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ssl-account.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        stat.dealtime.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        adserv.kwick.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        adserv.kwick.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .moviepilot.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .moviepilot.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wfkyagc5wlp.stats.esomniture.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.servestats.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        servestats.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        servestats.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www8.addfreestats.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .aka-cdn-ns.adtech.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .freeyouporn.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .freeyouporn.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ads.crakmedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .autoscout24.112.2o7.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .girlsteachsex.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .horyzon-media.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .horyzon-media.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .horyzon-media.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .horyzon-media.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .xhamster-sex.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .xhamster-sex.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .reifendiscount.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        e2.emediate.se [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.hentaimedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .hentaimedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .hentaimedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .animesex-videos.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .animesex-videos.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .freaks-toplist.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .www.freaks-toplist.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .manga-pornos.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .manga-pornos.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .nextag.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ads.ventivmedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .syndication.traffichaus.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .syndication.traffichaus.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .rambler.ru [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        adserver2.clipkit.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .server.cpmstar.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .clickandbuy.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .clickandbuy.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.mediamarkt.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        server.adformdsp.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        teufel-media.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .msnportal.112.2o7.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        deutsches-youporn.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        xhamster-porno.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.youporn-deutsch.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .youporn-deutsch.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .youporn-deutsch.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        xhamster-gratis-pornos.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        pornoflitsche.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        xxnx-porno.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .sunporno.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .sunporno.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .sunporno.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .sunporno.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adxpansion.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        dc.tremormedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .komtrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .komtrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.thelabelfinder.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .googleads.g.doubleclick.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track2.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track2.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track2.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track2.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track2.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track2.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track2.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tradetracker.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adserver.adtechus.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        server.adformdsp.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adformdsp.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .mywebsearch.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .mywebsearch.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .mywebsearch.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .mywebsearch.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .mywebsearch.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        mediathek.ffh.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .mediathek.ffh.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .mediathek.ffh.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .mediathek.ffh.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        tomtailor.dyntracker.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DéSIRéE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GJPZ37RW.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-Bifrose
        C:\PROGRAM FILES\VISTACODECPACK\TOOLS\VISTAUSER.EXE

MfG
magicfortune

cosinus 28.06.2012 09:34

Code:

Trojan.Agent/Gen-Bifrose
        C:\PROGRAM FILES\VISTACODECPACK\TOOLS\VISTAUSER.EXE

Hm sieht nach einem Fehlalarm aus

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

magicfortune 29.06.2012 06:52

Nur das meine privaten Dateien unbraubar sind (Bilder, Musik etc)

Die haben alle so ein Buchstaben wirrwar ohne Endung.

Was gibt es da dagegen`??

MfG
magicfortune

cosinus 29.06.2012 12:19

Warum kannst du nicht einfach mal obige Hinweise beachten? :wtf:
Die stehen da extra dick und fett und trotzdem muss man Hinweise zu den Hinweisen ständig nochmal schreiben :pfeiff:

Abgesehen davon wären wir aber durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

magicfortune 30.06.2012 15:47

Danke für deine Hilfe :daumenhoc

Tut mir Leid das ich ein wenig schwer von Begriff bin :D

MfG

magicfortune


Alle Zeitangaben in WEZ +1. Es ist jetzt 09:47 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131