Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   GVU Trojaner (mit Webcam?) unter Windows 7 (https://www.trojaner-board.de/118829-gvu-trojaner-webcam-windows-7-a.html)

sebbi86 07.07.2012 23:08

GVU Trojaner (mit Webcam?) unter Windows 7
 
Hallo Leute.

Hallo Leute. Jetzt hat es mich leider auch erwischt. Seit heut morgen wird mein Rechner jedes mal gesperrt, wenn ich versuche ins Internet zu gehen.

Nachdem ich mich hier ein wenig versucht habe durch das Thema durchzulesen, bin ich an einem Punkt angelangt, an dem ich nicht mehr weiterkomme.

Ich habe meinen Rechner über Kaspersky Rescue Disc gestartet und den Windowsunlocker wie beschrieben ausgeführt. Danach wollt ich versuchen ob mein Rechner wieder ins Internet gehen kann, konnte er nicht. Sobald ich den W-Lan Sender am Rechner anschalte und ins Internet gehen wil ist wieder Schluss.

Danach habe ich mir Malwarebytes Antimalware runtergeladen und da den Suchlauf ausgeführt. Dieser fand 2 infizierte Dateien. Ich war nicht sicher ob ich diese löschen soll oder besser erstmal nicht.

Ich habe hier öfters das Programm OTL gesehen, kann aber ehrlich grad nichts damit anfangen.

Da ich seit nun 12h versuche den Trojaner von meinem Rechner zu bekommen hoffe ich, ihr könnt mir weiterhelfen.

Die beiden Berichte von Kaspersky sowie den Bericht von Malwarebytes hänge ich an.

Danke schonmal

Sebastian

sebbi86 08.07.2012 11:56

So ich nochmal.

Ich weiß, man sollte seinen eigenen Posts nicht kommentieren, aber ich kann den Beitrag leider nicht bearbeiten.

Ich habe hier etwas weitergelesen und mir nun das OTL Tool runtergeladen, da es doch recht wichtig zu sein scheint, oder zumindest hilfreich, euch dabei zu helfen mir zu helfen.

Die OTL.txt hab ich als Anhang mit drangehängt. Die Extras.txt ist als Anhang leider zu groß, und ich find irgendwie nicht die Möglichkeit, dass als Textbox einzufügen.

Sebastian

sebbi86 08.07.2012 16:49

Erneutes Update.

Seit heute morgen zeigt mir mein Rechner beim starten immer einen RunDLL Error an.

Er sagt, dass es beim Starten der glom0_og.exe probleme gab. Das angegebene Modul wurde nicht gefunden.

Diese exe ist laut malwarebytes die, welche mir von malewarebytes als infiziert angezeigt wird.

Ich habe die datei aber nicht gelöscht.

hilft das irgendwie weiter?

cosinus 11.07.2012 08:11

Bitte erstmal routinemäßig einen neuen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

sebbi86 12.07.2012 17:44

Hallöli hier der ich mit seinem immernoch infizierten Rechner.

Also der Reihenfolge nach:

Hier ein älterer Malwarebytes Log (Aber erst nach der Infektion erstellt)

Code:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.07.07.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Asus :: ASUS-PC [Administrator]

07.07.2012 23:49:51
mbam-log-2012-07-07 (23-49-51).txt

Art des Suchlaufs: Benutzerdefinierter Suchlauf
Aktivierte Suchlaufeinstellungen: Dateisystem | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Heuristiks/Extra | P2P
Durchsuchte Objekte: 21420
Laufzeit: 9 Minute(n), 59 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 1
C:\Users\Asus\AppData\Local\Temp\glom0_og.exe (Trojan.Inject) -> Löschen bei Neustart.

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\xxx\AppData\Local\Temp\glom0_og.exe (Trojan.Inject) -> Löschen bei Neustart.

(Ende)

So dann das neueste Malwarebytes log

Code:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.07.11.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Asus :: ASUS-PC [Administrator]

Schutz: Aktiviert

11.07.2012 20:42:15
mbam-log-2012-07-11 (20-42-15).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 473227
Laufzeit: 1 Stunde(n), 21 Minute(n), 44 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk (Trojan.Ransom.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Falls es etwas hilft, das Log vom alternativen Benutzer, den ich nach der Infektion angelegt habe, um ins Internet zu kommen

Code:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.07.11.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
xxx :: xxx [Administrator]

Schutz: Aktiviert

11.07.2012 19:14:46
mbam-log-2012-07-11 (19-14-46).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 472472
Laufzeit: 1 Stunde(n), 24 Minute(n), 47 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

und dann als vorerst letztes, das Eset Log.

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=f3730f9c6a92be4e99b3372a7c845f77
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-11 10:06:36
# local_time=2012-07-12 12:06:36 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 4114648 4114648 0 0
# compatibility_mode=5893 16776574 66 85 37848576 93668118 0 0
# compatibility_mode=8192 67108863 100 0 179 179 0 0
# scanned=238539
# found=2
# cleaned=0
# scan_time=6149
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\72183b2a-376d7fe5        Java/Exploit.CVE-2012-0507.CU trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Asus\Downloads\vlc-1.1.9-win32.exe        Win32/StartPage.OIE trojan (unable to clean)        00000000000000000000000000000000        I
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=f3730f9c6a92be4e99b3372a7c845f77
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-12 04:29:39
# local_time=2012-07-12 06:29:39 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 4177957 4177957 0 0
# compatibility_mode=5893 16776574 66 85 37911885 93731427 0 0
# compatibility_mode=8192 67108863 100 0 63488 63488 0 0
# scanned=239073
# found=2
# cleaned=0
# scan_time=9023
C:\Users\xxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\72183b2a-376d7fe5        Java/Exploit.CVE-2012-0507.CU trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\xxx\Downloads\vlc-1.1.9-win32.exe        Win32/StartPage.OIE trojan (unable to clean)        00000000000000000000000000000000        I

Ich hoffe es hilft weiter

Sebastian

cosinus 12.07.2012 19:29

Zitat:

C:\Users\xxx\Downloads\vlc-1.1.9-win32.exe
Ach nee, bist du auch auf die Seite vlc.de reingefallen? :(
Die offizielle Seite vom VLC-Player ist VideoLAN - VLC: Official site - Free multimedia solutions for all OS! !!!

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

sebbi86 12.07.2012 20:23

Hi

Auch wenn das da so dahsteht muss ich ehrlich sagen, dass ich nicht glaube, dass es der VLC Player ist. Den hab ich schon seit nem Jahr drauf und hab da seitdem nix dran verändert. Mein Rechner wurde erst am Samstag gesperrt, als ich mich auf kinox.to rumtrieb.

Zu deinen Fragen:

Also der normale Modus funktioniert soweit ich das bis jetzt beurteilen kann wieder fehlerlos. Hab den bis jetzt aber auch nicht voll genutzt, weil ich nicht wusste, was der Trojaner noch so macht (Passwörter ausspähen o.ä.)

Im Startmenü hab ich auf Anhieb keine leeren Ordner gefunden. Ob was fehlt kann ihc dir ehrlich nicht sagen. Auf den erstenBlick nicht, aber mein Startmenü wird so selten benutzt, wenn sich da Staub ansammeln würde, wären da keine Wollmäuse mehr sondern schon Wollelefanten ^^

cosinus 12.07.2012 21:28

Das ändert aber nichts daran, dass auf vlc.de ein VLC-Player-Setup angeboten wird, dass die Start und evtl auch Suchseiten umbiegt!
Und zu kinox.to braucht man eigentlich nichts zu sagen :headbang:
dass diese dubiosen und offentlichen illegalen Portale Müll und Malware verbreiten sowie auch Abofallen stellen sollte nun wirklich hinlänglich bekannt sein! :pfui:

Also lass einfach die Finger von dubiosen Portalen und alles anderes was illegal/dubios ist ebenfalls! :twak:

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

sebbi86 14.07.2012 13:26

Okay Hinweis ist akzeptiert. Von dubiosen Seiten werden die Finger gelassen. Bin aber anscheinend, wenn ich mich hier so richtig umschaue nicht der einzige, der sich da was eingefangen hat. Sollte öfter bei euch mal reinschauen, um zu sehen wo man sich nicht rumtreiben sollte ^^

Und auf vlc.de wird auch net gegangen :-D

So aber weiter mit meinem Problemchen:

Inhalt der nächsten log datei von adwcleaner

Code:

# AdwCleaner v1.702 - Logfile created 07/14/2012 at 14:21:50
# Updated 13/07/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : xxx - xxx
# Running from : C:\Users\xxx\Desktop\adwcleaner0.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****

Key Found : HKLM\SOFTWARE\Software

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Found : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v12.0 (de)

Profile name : default
File : C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\iskpx8ki.default\prefs.js

[OK] File is clean.

Profile name : default
File : C:\Users\Versuch\AppData\Roaming\Mozilla\Firefox\Profiles\n5toj1ra.default\prefs.js

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [1229 octets] - [14/07/2012 14:21:50]

########## EOF - C:\AdwCleaner[R1].txt - [1357 octets] ##########

Gute grüße und n geiles Wochenende.

Sebastian

cosinus 14.07.2012 15:24

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

sebbi86 14.07.2012 17:11

So done

Code:

# AdwCleaner v1.702 - Logfile created 07/14/2012 at 18:05:52
# Updated 13/07/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Asus - ASUS-PC
# Running from : C:\Users\xxx\Desktop\adwcleaner0.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****

Key Deleted : HKLM\SOFTWARE\Software

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v12.0 (de)

Profile name : default
File : C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\iskpx8ki.default\prefs.js

[OK] File is clean.

Profile name : default
File : C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\n5toj1ra.default\prefs.js

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [1354 octets] - [14/07/2012 14:21:50]
AdwCleaner[S1].txt - [1299 octets] - [14/07/2012 18:05:52]

########## EOF - C:\AdwCleaner[S1].txt - [1427 octets] ##########

Und nun? Alles gut?

cosinus 14.07.2012 20:58

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


sebbi86 15.07.2012 21:15

So neues otl log gemacht. das kam dabei raus.

Code:

OTL logfile created on: 15.07.2012 21:21:53 - Run 2
OTL by OldTimer - Version 3.2.54.0    Folder = C:\Users\xxx\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7,91 Gb Total Physical Memory | 5,93 Gb Available Physical Memory | 74,94% Memory free
15,82 Gb Paging File | 13,64 Gb Available in Paging File | 86,20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 197,55 Gb Total Space | 11,04 Gb Free Space | 5,59% Space Free | Partition Type: NTFS
Drive D: | 243,21 Gb Total Space | 178,00 Gb Free Space | 73,19% Space Free | Partition Type: NTFS
Drive E: | 232,88 Gb Total Space | 106,47 Gb Free Space | 45,72% Space Free | Partition Type: NTFS
Drive F: | 232,87 Gb Total Space | 9,86 Gb Free Space | 4,24% Space Free | Partition Type: NTFS
 
Computer Name: ASUS-PC | User Name: Asus | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Asus\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Windows\AsScrPro.exe (ASUS)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\ExpressGateUtil\VAWinAgent.exe ()
PRC - C:\ExpressGateUtil\VAWinService.exe ()
PRC - C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe ()
PRC - C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe ()
PRC - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()
PRC - C:\Program Files (x86)\ASUS\SonicMaster\SonicMasterTray.exe (Virage Logic Corporation / Sonic Focus)
PRC - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
PRC - C:\Windows\vsnp2uvc.exe (Sonix Technology Co., Ltd.)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe ()
 
 
========== Modules (No Company Name) ==========

und was heißt das jetzt

cosinus 16.07.2012 13:54

Log ist unvollständig!
Schonmal was von STRG+A (alles markieren) gehört? :confused:

sebbi86 16.07.2012 20:08

Srtg+a Hab ich schonmal gehört lang lang ists her ^^

so hier dann Versuch Nummer 2. Heute neues Log gemacht.

Code:

OTL logfile created on: 16.07.2012 20:53:47 - Run 3
OTL by OldTimer - Version 3.2.54.0    Folder = C:\Users\Asus\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7,91 Gb Total Physical Memory | 5,67 Gb Available Physical Memory | 71,63% Memory free
15,82 Gb Paging File | 13,46 Gb Available in Paging File | 85,08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 197,55 Gb Total Space | 10,57 Gb Free Space | 5,35% Space Free | Partition Type: NTFS
Drive D: | 243,21 Gb Total Space | 178,00 Gb Free Space | 73,19% Space Free | Partition Type: NTFS
Drive E: | 232,88 Gb Total Space | 106,47 Gb Free Space | 45,72% Space Free | Partition Type: NTFS
Drive F: | 232,87 Gb Total Space | 9,86 Gb Free Space | 4,24% Space Free | Partition Type: NTFS
 
Computer Name: ASUS-PC | User Name: Asus | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Asus\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Windows\AsScrPro.exe (ASUS)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\ExpressGateUtil\VAWinAgent.exe ()
PRC - C:\ExpressGateUtil\VAWinService.exe ()
PRC - C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe ()
PRC - C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe ()
PRC - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()
PRC - C:\Program Files (x86)\ASUS\SonicMaster\SonicMasterTray.exe (Virage Logic Corporation / Sonic Focus)
PRC - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
PRC - C:\Windows\vsnp2uvc.exe (Sonix Technology Co., Ltd.)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe ()
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\ExpressGateUtil\VAWinAgent.exe ()
MOD - C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe ()
MOD - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll ()
MOD - C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll ()
MOD - C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (AFBAgent) -- C:\Windows\SysNative\FBAgent.exe (ASUSTeK Computer Inc.)
SRV:64bit: - (TurboBoost) Intel(R) -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel(R) Corporation)
SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (EvtEng) Intel(R) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) Intel(R) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
SRV:64bit: - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (Futuremark SystemInfo Service) -- C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS)
SRV - (ATKGFNEXSrv) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (VideAceWindowsService) -- C:\ExpressGateUtil\VAWinService.exe ()
SRV - (CLKMSVC10_38F51D56) -- C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe (CyberLink)
SRV - (UI Assistant Service) -- C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (BrYNSvc) -- C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys (Nokia)
DRV:64bit: - (upperdev) -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia)
DRV:64bit: - (nmwcdc) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:64bit: - (nmwcd) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (nvpciflt) -- C:\Windows\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV:64bit: - (FLxHCIc) Fresco Logic xHCI (USB3) -- C:\Windows\SysNative\drivers\FLxHCIc.sys (Fresco Logic)
DRV:64bit: - (FLxHCIh) Fresco Logic xHCI (USB3) -- C:\Windows\SysNative\drivers\FLxHCIh.sys (Fresco Logic)
DRV:64bit: - (TurboB) -- C:\Windows\SysNative\drivers\TurboB.sys (Intel(R) Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) Intel(R) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel(R) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronic Corp.)
DRV:64bit: - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) -- C:\Windows\SysNative\drivers\snp2uvc.sys (Sonix Technology Co., Ltd.)
DRV:64bit: - (L1C) -- C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (NETwNs64) ___ Intel(R) -- C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (wdkmd) -- C:\Windows\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (AmUStor) -- C:\Windows\SysNative\drivers\AmUStor.sys (Alcor Micro, Corp.)
DRV:64bit: - (ZTEusbser6k) -- C:\Windows\SysNative\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV:64bit: - (ZTEusbnmea) -- C:\Windows\SysNative\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV:64bit: - (ZTEusbmdm6k) -- C:\Windows\SysNative\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV:64bit: - (massfilter) -- C:\Windows\SysNative\drivers\massfilter.sys (ZTE Incorporated)
DRV:64bit: - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( )
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (btusbflt) -- C:\Windows\SysNative\drivers\btusbflt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) -- C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (SiSGbeLH) -- C:\Windows\SysNative\drivers\SiSG664.sys (Silicon Integrated Systems Corp.)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (btwl2cap) -- C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (ATKWMIACPIIO) -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ASUS)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (ASMMAP64) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ASUT_deDE491
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.useDBForOrder: true
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.05.06 21:04:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files (x86)\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012.03.05 20:22:36 | 000,000,000 | ---D | M]
 
[2011.04.28 20:31:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\Extensions
[2012.06.28 16:43:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\Firefox\Profiles\iskpx8ki.default\extensions
[2011.05.11 10:15:38 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Asus\AppData\Roaming\mozilla\Firefox\Profiles\iskpx8ki.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.06.28 16:43:58 | 000,000,853 | ---- | M] () -- C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\iskpx8ki.default\searchplugins\11-suche.xml
[2012.06.28 16:43:58 | 000,002,209 | ---- | M] () -- C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\iskpx8ki.default\searchplugins\englische-ergebnisse.xml
[2012.06.28 16:43:58 | 000,010,506 | ---- | M] () -- C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\iskpx8ki.default\searchplugins\gmx-suche.xml
[2012.06.28 16:43:58 | 000,002,368 | ---- | M] () -- C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\iskpx8ki.default\searchplugins\lastminute.xml
[2012.06.28 16:43:58 | 000,005,489 | ---- | M] () -- C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\iskpx8ki.default\searchplugins\webde-suche.xml
[2012.03.26 19:40:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.05.05 20:23:47 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.06.28 16:43:57 | 000,575,217 | ---- | M] () (No name found) -- C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\EXTENSIONS\TOOLBAR@GMX.NET.XPI
[2012.05.06 21:04:24 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.02.13 08:20:42 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.02.13 08:20:42 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.02.13 08:20:42 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.13 08:20:42 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.13 08:20:42 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.13 08:20:42 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd File not found
O4:64bit: - HKLM..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe (Sonix Technology Co., Ltd.)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [FLxHCIm] C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe (Windows (R) Win 7 DDK provider)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Nuance PDF Reader-reminder] C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\SonicMaster\SonicMasterTray.exe (Virage Logic Corporation / Sonic Focus)
O4 - HKLM..\Run: [UIExec] C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe ()
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VAWinAgent] C:\ExpressGateUtil\VAWinAgent.exe ()
O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000..\Run: []  File not found
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000..\Run: [ICQ] C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001..\Run: []  File not found
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001..\Run: [ICQ] C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p File not found
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Versuch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Überwachungstool für die Intel® Turbo-Boost-Technik 2.0.lnk =  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2EA5B419-5589-46C0-8493-6F92D4C0ED6B}: DhcpNameServer = 192.168.2.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A658CF3C-152A-4012-9255-8A1934FA0622}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe - ()
MsConfig:64bit - StartUpReg: ASUS Screen Saver Protector - hkey= - key= - C:\Windows\AsScrPro.exe (ASUS)
MsConfig:64bit - StartUpReg: ASUS WebStorage - hkey= - key= - C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe ()
MsConfig:64bit - StartUpReg: CLMLServer - hkey= - key= - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
MsConfig:64bit - StartUpReg: ControlCenter3 - hkey= - key= - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
MsConfig:64bit - StartUpReg: EKIJ5000StatusMonitor - hkey= - key= - C:\Windows\SysNative\spool\drivers\x64\3\EKIJ5000MUI.exe (Eastman Kodak Company)
MsConfig:64bit - StartUpReg: NokiaMServer - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: RtHDVCpl - hkey= - key= - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
MsConfig:64bit - State: "startup" - Reg Error: Key error.
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.16 20:51:08 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Asus\Desktop\OTL.exe
[2012.07.14 14:46:05 | 000,000,000 | ---D | C] -- C:\Users\Asus\Desktop\Steinberg
[2012.07.11 22:21:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.07.07 22:19:35 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Roaming\Malwarebytes
[2012.07.07 22:19:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.07 22:19:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.07 22:19:08 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.07 22:19:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.07.07 11:25:34 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
[2012.07.07 11:11:38 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Roaming\Google
[2012.07.05 21:25:09 | 000,405,144 | ---- | C] (Newtonsoft) -- C:\Windows\SysWow64\Newtonsoft.Json.Net20.dll
[2012.06.24 12:13:31 | 000,000,000 | ---D | C] -- C:\Users\Asus\Documents\Ovi
[2012.06.24 12:13:24 | 000,000,000 | ---D | C] -- C:\Users\Asus\Documents\Nokia Suite
[2012.06.17 23:52:27 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Local\ElevatedDiagnostics
[2012.06.17 23:17:03 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2012.06.17 11:02:27 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Roaming\Epson
[2012.06.17 11:02:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Epson Software
[2012.06.17 11:01:58 | 000,000,000 | ---D | C] -- C:\Program Files\EpsonNet
[2012.06.17 11:01:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\EPSON
[2012.06.17 11:00:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EpsonNet
[2012.06.17 10:59:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\EPSON
[2012.06.17 10:58:59 | 000,000,000 | ---D | C] -- C:\ProgramData\EPSON
[2012.06.17 10:58:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
[2012.06.17 10:58:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\epson
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.16 20:53:24 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.16 20:53:24 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.16 20:51:09 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Asus\Desktop\OTL.exe
[2012.07.16 20:49:03 | 001,529,502 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.07.16 20:49:03 | 000,665,812 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.07.16 20:49:03 | 000,627,654 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.07.16 20:49:03 | 000,133,992 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.07.16 20:49:03 | 000,110,374 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.07.16 20:44:32 | 000,045,056 | ---- | M] () -- C:\Windows\SysNative\acovcnt.exe
[2012.07.16 20:44:32 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.16 20:43:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.16 20:43:29 | 2077,265,919 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.15 23:23:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.14 14:36:41 | 000,001,245 | ---- | M] () -- C:\Users\Asus\Desktop\DVDVideoSoft Free Studio.lnk
[2012.07.14 14:21:22 | 000,624,883 | ---- | M] () -- C:\Users\Asus\Desktop\adwcleaner0.exe
[2012.07.12 17:13:40 | 000,405,144 | ---- | M] (Newtonsoft) -- C:\Windows\SysWow64\Newtonsoft.Json.Net20.dll
[2012.07.12 03:24:04 | 000,305,184 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.07.11 20:41:28 | 000,001,437 | ---- | M] () -- C:\Windows\SysNative\ServiceFilter.ini
[2012.07.07 22:19:43 | 004,503,728 | ---- | M] () -- C:\ProgramData\go_0molg.pad
[2012.07.03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.06.24 12:21:08 | 001,316,788 | ---- | M] () -- C:\Users\Asus\Documents\SMS Nokia 5800.csv
[2012.06.17 11:06:40 | 000,002,486 | ---- | M] () -- C:\Windows\SysNative\AutoRunFilter.ini
[2012.06.17 10:52:31 | 000,027,537 | ---- | M] () -- C:\Users\Asus\Documents\Carli 2.odt
 
========== Files Created - No Company Name ==========
 
[2012.07.14 18:05:41 | 000,624,883 | ---- | C] () -- C:\Users\Asus\Desktop\adwcleaner0.exe
[2012.07.14 14:36:41 | 000,001,245 | ---- | C] () -- C:\Users\Asus\Desktop\DVDVideoSoft Free Studio.lnk
[2012.07.07 11:13:14 | 000,001,110 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.07 11:13:12 | 000,001,106 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.07 11:11:33 | 004,503,728 | ---- | C] () -- C:\ProgramData\go_0molg.pad
[2012.06.24 12:21:08 | 001,316,788 | ---- | C] () -- C:\Users\Asus\Documents\SMS Nokia 5800.csv
[2012.06.17 23:41:05 | 000,002,062 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
[2012.06.17 11:17:55 | 000,001,445 | ---- | C] () -- C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.06.17 10:52:28 | 000,027,537 | ---- | C] () -- C:\Users\Asus\Documents\Carli 2.odt
[2012.02.18 17:15:52 | 000,000,241 | ---- | C] () -- C:\Windows\Brpfx04a.ini
[2012.02.18 17:15:52 | 000,000,093 | ---- | C] () -- C:\Windows\brpcfx.ini
[2012.02.18 17:13:14 | 000,000,000 | ---- | C] () -- C:\Windows\brdfxspd.dat
[2012.02.04 14:04:18 | 000,026,779 | ---- | C] () -- C:\Windows\DIIUnin.dat
[2011.10.21 18:27:54 | 000,217,536 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.10.21 18:22:54 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2011.10.21 18:03:04 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011.09.10 13:39:14 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2011.09.10 13:39:14 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2011.05.05 20:24:43 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.05.05 19:53:52 | 000,280,976 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011.05.05 19:53:50 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011.04.30 11:27:22 | 000,011,264 | ---- | C] () -- C:\Users\Asus\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.03.26 01:16:10 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.02.12 04:19:28 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.01.26 12:22:43 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini
[2011.01.12 18:02:43 | 000,131,472 | ---- | C] () -- C:\ProgramData\FullRemove.exe
 
========== LOP Check ==========
 
[2011.04.16 17:16:07 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Asus WebStorage
[2012.01.04 21:44:43 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2012.07.14 14:39:02 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\DVDVideoSoft
[2012.07.05 21:26:15 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.06.17 11:02:27 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Epson
[2011.09.24 23:14:12 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\FreeCommander
[2012.07.16 20:47:43 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\ICQ
[2011.10.04 00:32:01 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Lionhead Studios
[2011.04.28 18:15:20 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\MAXON
[2012.03.05 20:23:33 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Nokia
[2011.04.30 11:21:56 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Nokia Ovi Suite
[2012.03.05 20:24:28 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Nokia Suite
[2011.05.04 19:54:18 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Nuance
[2011.05.04 11:27:40 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\OpenOffice.org
[2011.04.30 11:21:31 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\PC Suite
[2011.05.05 19:53:49 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\PunkBuster
[2011.06.04 15:36:19 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\SpeedProject
[2011.12.21 16:06:09 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Ubisoft
[2011.04.30 09:22:10 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Zeon
[2012.06.17 05:15:22 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.04.28 23:17:20 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Adobe
[2011.04.16 17:16:07 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Asus WebStorage
[2012.05.25 07:32:35 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Avira
[2012.02.19 17:20:41 | 000,000,000 | R--D | M] -- C:\Users\Asus\AppData\Roaming\Brother
[2012.01.04 21:44:43 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2011.06.19 15:22:28 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\CyberLink
[2011.12.21 17:31:35 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\dvdcss
[2012.07.14 14:39:02 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\DVDVideoSoft
[2012.07.05 21:26:15 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.06.17 11:02:27 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Epson
[2011.05.04 19:54:19 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\FLEXnet
[2011.09.24 23:14:12 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\FreeCommander
[2012.07.07 11:11:39 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Google
[2012.07.16 20:47:43 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\ICQ
[2011.04.14 21:02:03 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Identities
[2011.04.21 23:07:19 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\InstallShield
[2011.04.14 21:04:08 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Intel
[2011.10.04 00:32:01 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Lionhead Studios
[2011.04.28 23:17:23 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Macromedia
[2012.07.07 22:19:35 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Malwarebytes
[2011.04.28 18:15:20 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\MAXON
[2009.07.14 09:44:38 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Media Center Programs
[2012.04.17 21:03:05 | 000,000,000 | --SD | M] -- C:\Users\Asus\AppData\Roaming\Microsoft
[2011.04.28 20:31:41 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Mozilla
[2012.03.05 20:23:33 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Nokia
[2011.04.30 11:21:56 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Nokia Ovi Suite
[2012.03.05 20:24:28 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Nokia Suite
[2011.05.04 19:54:18 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Nuance
[2011.12.14 18:59:18 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\NVIDIA
[2011.05.04 11:27:40 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\OpenOffice.org
[2011.04.30 11:21:31 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\PC Suite
[2011.05.05 19:53:49 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\PunkBuster
[2011.07.25 13:47:14 | 000,000,000 | RH-D | M] -- C:\Users\Asus\AppData\Roaming\SecuROM
[2012.07.15 23:30:24 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Skype
[2012.06.07 19:09:00 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\skypePM
[2011.06.04 15:36:19 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\SpeedProject
[2011.12.21 16:06:09 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Ubisoft
[2012.06.01 23:09:12 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\vlc
[2011.04.30 09:22:10 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Zeon
 
< %APPDATA%\*.exe /s >
[2011.10.29 21:56:10 | 008,107,168 | ---- | M] (Adobe Systems, Inc.) -- C:\Users\Asus\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
[2011.02.02 10:26:23 | 075,862,048 | ---- | M] () -- C:\Users\Asus\AppData\Roaming\Nokia\Ovi Suite\Software Updater\NokiaOviSuite2Installer.exe
[2011.02.17 22:39:13 | 000,835,440 | R--- | M] () -- C:\Users\Asus\AppData\Roaming\PunkBuster\pbsetup\pbsvc.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2008.06.06 23:03:52 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll
 
< MD5 for: IASTOR.SYS  >
[2010.09.14 04:24:26 | 000,437,272 | ---- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F -- C:\eSupport\eDriver\Software\IRST\64\IASTOR.SYS
[2010.09.14 04:24:26 | 000,437,272 | ---- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F -- C:\Windows\SysNative\drivers\iaStor.sys
[2010.09.14 04:24:26 | 000,437,272 | ---- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_2b0c50dc63f09dae\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.01.12 18:20:46 | 000,410,504 | ---- | M] (Intel Corporation) MD5=513DC087CFED7D2BB82F005385D3531F -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16592_none_0af87721a183cb70\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
[2011.01.12 18:20:46 | 000,410,496 | ---- | M] (Intel Corporation) MD5=E353CF970C5D4D6A092911E15FB78C07 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20712_none_0bd89532ba6088d9\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.01.12 18:20:46 | 000,166,280 | ---- | M] (NVIDIA Corporation) MD5=0AF7B8136794E23E87BE138992880E64 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16592_none_95c1e7d0d8ba7548\nvstor.sys
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.01.12 18:20:46 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=CE76755AF933E728CEBA6C7A970838A4 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20712_none_96a205e1f19732b1\nvstor.sys
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.07.03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2011.01.12 16:51:11 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2011.01.12 16:51:11 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

Hoffe diesmal ist alles bei. Danke für die Hilfe

Sebastian

cosinus 17.07.2012 10:59

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Hinweis: Falls Du Deinen Benutzernamen unkenntlich gemacht hast, musst Du das Ausgesternte in Deinen richtigen Benutzernamen wieder verwandeln, sonst funktioniert das Script nicht!!

Code:

:OTL
FF - user.js - File not found
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd File not found
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000..\Run: []  File not found
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001..\Run: []  File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p File not found
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Versuch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Überwachungstool für die Intel® Turbo-Boost-Technik 2.0.lnk =  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
:Files
C:\ProgramData\*.pad
C:\Users\xxx\AppData\LocalLow\Sun\Java\Deployment\cache
C:\Users\xxx\Downloads\vlc-1.1.9-win32.exe
:Commands
[purity]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

sebbi86 17.07.2012 20:27

Nabend

Hab das Fix entsprechend den Anweisungen durchgeführt.

PC wurde nicht neu gestartet.

Hier das entsprechende Log dazu

Code:

========== OTL ==========
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Setwallpaper deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1516755417-3234397197-3308580895-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1516755417-3234397197-3308580895-1001\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1516755417-3234397197-3308580895-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\FlashPlayerUpdate deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1516755417-3234397197-3308580895-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
C:\Users\Versuch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Überwachungstool für die Intel® Turbo-Boost-Technik 2.0.lnk moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1516755417-3234397197-3308580895-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1516755417-3234397197-3308580895-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1516755417-3234397197-3308580895-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun deleted successfully.
========== FILES ==========
C:\ProgramData\go_0molg.pad moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Users\Asus\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
C:\Users\Asus\Downloads\vlc-1.1.9-win32.exe moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.54.0 log created on 07172012_212503


cosinus 18.07.2012 15:59

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

sebbi86 18.07.2012 19:35

so scan ist gemacht.

den fund hab ich in quaratäne verschoben. hab zu spät gelesen, dass ich das skippen soll :-(

hier der bericht

Code:

20:17:37.0397 5972        TDSS rootkit removing tool 2.7.46.0 Jul 16 2012 22:10:11
20:17:37.0594 5972        ============================================================
20:17:37.0594 5972        Current date / time: 2012/07/18 20:17:37.0594
20:17:37.0594 5972        SystemInfo:
20:17:37.0594 5972       
20:17:37.0595 5972        OS Version: 6.1.7601 ServicePack: 1.0
20:17:37.0595 5972        Product type: Workstation
20:17:37.0595 5972        ComputerName: ASUS-PC
20:17:37.0595 5972        UserName: Asus
20:17:37.0595 5972        Windows directory: C:\Windows
20:17:37.0595 5972        System windows directory: C:\Windows
20:17:37.0595 5972        Running under WOW64
20:17:37.0595 5972        Processor architecture: Intel x64
20:17:37.0595 5972        Number of processors: 8
20:17:37.0595 5972        Page size: 0x1000
20:17:37.0595 5972        Boot type: Normal boot
20:17:37.0595 5972        ============================================================
20:17:38.0246 5972        Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:17:38.0247 5972        Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:17:38.0252 5972        ============================================================
20:17:38.0252 5972        \Device\Harddisk0\DR0:
20:17:38.0252 5972        MBR partitions:
20:17:38.0252 5972        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3200800, BlocksNum 0x18B19800
20:17:38.0272 5972        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1BD1A800, BlocksNum 0x1E66B800
20:17:38.0272 5972        \Device\Harddisk1\DR1:
20:17:38.0273 5972        MBR partitions:
20:17:38.0622 5972        \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F00, BlocksNum 0x1D1C4542
20:17:38.0644 5972        \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x1D1C8481, BlocksNum 0x1D1BC7C0
20:17:38.0644 5972        ============================================================
20:17:38.0722 5972        C: <-> \Device\Harddisk0\DR0\Partition0
20:17:38.0752 5972        D: <-> \Device\Harddisk0\DR0\Partition1
20:17:38.0793 5972        E: <-> \Device\Harddisk1\DR1\Partition0
20:17:38.0826 5972        F: <-> \Device\Harddisk1\DR1\Partition1
20:17:38.0826 5972        ============================================================
20:17:38.0826 5972        Initialize success
20:17:38.0826 5972        ============================================================
20:20:19.0237 5972        ============================================================
20:20:19.0237 5972        Scan started
20:20:19.0237 5972        Mode: Manual; SigCheck; TDLFS;
20:20:19.0237 5972        ============================================================
20:20:19.0954 5972        1394ohci        (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
20:20:20.0063 5972        1394ohci - ok
20:20:20.0126 5972        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
20:20:20.0141 5972        ACPI - ok
20:20:20.0157 5972        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
20:20:20.0266 5972        AcpiPmi - ok
20:20:20.0344 5972        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
20:20:20.0360 5972        adp94xx - ok
20:20:20.0422 5972        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
20:20:20.0438 5972        adpahci - ok
20:20:20.0469 5972        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
20:20:20.0485 5972        adpu320 - ok
20:20:20.0531 5972        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
20:20:20.0656 5972        AeLookupSvc - ok
20:20:20.0734 5972        AFBAgent        (6e79a119b0ce418fe44e0c824bf3f039) C:\Windows\system32\FBAgent.exe
20:20:20.0750 5972        AFBAgent - ok
20:20:20.0828 5972        AFD            (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
20:20:20.0890 5972        AFD - ok
20:20:20.0937 5972        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
20:20:20.0937 5972        agp440 - ok
20:20:20.0984 5972        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
20:20:21.0046 5972        ALG - ok
20:20:21.0062 5972        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
20:20:21.0077 5972        aliide - ok
20:20:21.0093 5972        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
20:20:21.0093 5972        amdide - ok
20:20:21.0140 5972        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
20:20:21.0187 5972        AmdK8 - ok
20:20:21.0187 5972        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
20:20:21.0218 5972        AmdPPM - ok
20:20:21.0249 5972        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
20:20:21.0249 5972        amdsata - ok
20:20:21.0280 5972        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
20:20:21.0296 5972        amdsbs - ok
20:20:21.0311 5972        amdxata        (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
20:20:21.0311 5972        amdxata - ok
20:20:21.0374 5972        AmUStor        (9c7f164b49cadc658d1b3c575782f346) C:\Windows\system32\drivers\AmUStor.SYS
20:20:21.0405 5972        AmUStor - ok
20:20:21.0514 5972        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
20:20:21.0514 5972        AntiVirSchedulerService - ok
20:20:21.0577 5972        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
20:20:21.0577 5972        AntiVirService - ok
20:20:21.0639 5972        AppID          (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
20:20:21.0826 5972        AppID - ok
20:20:21.0857 5972        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
20:20:21.0904 5972        AppIDSvc - ok
20:20:21.0967 5972        Appinfo        (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
20:20:22.0013 5972        Appinfo - ok
20:20:22.0060 5972        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
20:20:22.0060 5972        arc - ok
20:20:22.0076 5972        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
20:20:22.0091 5972        arcsas - ok
20:20:22.0201 5972        ASLDRService    (a3626c6d3f2dc95497f3f61842d7fd89) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
20:20:22.0216 5972        ASLDRService - ok
20:20:22.0232 5972        ASMMAP64        (4c016fd76ed5c05e84ca8cab77993961) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys
20:20:22.0247 5972        ASMMAP64 - ok
20:20:22.0263 5972        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
20:20:22.0310 5972        AsyncMac - ok
20:20:22.0341 5972        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
20:20:22.0357 5972        atapi - ok
20:20:22.0435 5972        athr            (e857eee6b92aaa473ebb3465add8f7e7) C:\Windows\system32\DRIVERS\athrx.sys
20:20:22.0559 5972        athr - ok
20:20:22.0637 5972        ATKGFNEXSrv    (dbc598e47e7a382e60e2a4745d41fef9) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
20:20:22.0653 5972        ATKGFNEXSrv - ok
20:20:22.0700 5972        ATKWMIACPIIO    (41ceaffcf3550785e59e3ec9bee8d97a) C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys
20:20:22.0715 5972        ATKWMIACPIIO - ok
20:20:22.0840 5972        AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
20:20:22.0918 5972        AudioEndpointBuilder - ok
20:20:22.0918 5972        AudioSrv        (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
20:20:22.0949 5972        AudioSrv - ok
20:20:23.0074 5972        avgntflt        (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys
20:20:23.0074 5972        avgntflt - ok
20:20:23.0121 5972        avipbb          (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys
20:20:23.0121 5972        avipbb - ok
20:20:23.0137 5972        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
20:20:23.0137 5972        avkmgr - ok
20:20:23.0230 5972        AxInstSV        (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
20:20:23.0308 5972        AxInstSV - ok
20:20:23.0371 5972        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
20:20:23.0417 5972        b06bdrv - ok
20:20:23.0464 5972        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
20:20:23.0511 5972        b57nd60a - ok
20:20:23.0542 5972        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
20:20:23.0589 5972        BDESVC - ok
20:20:23.0605 5972        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
20:20:23.0651 5972        Beep - ok
20:20:23.0729 5972        BFE            (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
20:20:23.0792 5972        BFE - ok
20:20:23.0854 5972        BITS            (1ea7969e3271cbc59e1730697dc74682) C:\Windows\System32\qmgr.dll
20:20:23.0932 5972        BITS - ok
20:20:23.0979 5972        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
20:20:24.0010 5972        blbdrive - ok
20:20:24.0057 5972        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
20:20:24.0088 5972        bowser - ok
20:20:24.0119 5972        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
20:20:24.0151 5972        BrFiltLo - ok
20:20:24.0151 5972        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
20:20:24.0166 5972        BrFiltUp - ok
20:20:24.0197 5972        Browser        (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
20:20:24.0244 5972        Browser - ok
20:20:24.0307 5972        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
20:20:24.0353 5972        Brserid - ok
20:20:24.0369 5972        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
20:20:24.0385 5972        BrSerWdm - ok
20:20:24.0400 5972        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
20:20:24.0416 5972        BrUsbMdm - ok
20:20:24.0416 5972        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
20:20:24.0431 5972        BrUsbSer - ok
20:20:24.0525 5972        BrYNSvc        (ea7e57f87d6fee5fd6c5f813c04e8cd2) C:\Program Files (x86)\Browny02\BrYNSvc.exe
20:20:24.0556 5972        BrYNSvc ( UnsignedFile.Multi.Generic ) - warning
20:20:24.0556 5972        BrYNSvc - detected UnsignedFile.Multi.Generic (1)
20:20:24.0619 5972        BthEnum        (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\drivers\BthEnum.sys
20:20:24.0650 5972        BthEnum - ok
20:20:24.0681 5972        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
20:20:24.0712 5972        BTHMODEM - ok
20:20:24.0743 5972        BthPan          (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
20:20:24.0759 5972        BthPan - ok
20:20:24.0853 5972        BTHPORT        (64c198198501f7560ee41d8d1efa7952) C:\Windows\System32\Drivers\BTHport.sys
20:20:24.0899 5972        BTHPORT - ok
20:20:24.0946 5972        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
20:20:24.0977 5972        bthserv - ok
20:20:25.0024 5972        BTHUSB          (f188b7394d81010767b6df3178519a37) C:\Windows\System32\Drivers\BTHUSB.sys
20:20:25.0040 5972        BTHUSB - ok
20:20:25.0087 5972        btusbflt        (6e04458e98daf28826482e41a7a62df5) C:\Windows\system32\drivers\btusbflt.sys
20:20:25.0087 5972        btusbflt - ok
20:20:25.0133 5972        btwaudio        (6bcfdc2b5b7f66d484486d4bd4b39a6b) C:\Windows\system32\drivers\btwaudio.sys
20:20:25.0149 5972        btwaudio - ok
20:20:25.0165 5972        btwavdt        (82dc8b7c626e526681c1bebed2bc3ff9) C:\Windows\system32\DRIVERS\btwavdt.sys
20:20:25.0165 5972        btwavdt - ok
20:20:25.0305 5972        btwdins        (1e08dc82525282e34ad66ffba0782565) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
20:20:25.0352 5972        btwdins - ok
20:20:25.0352 5972        btwl2cap        (6149301dc3f81d6f9667a3fbac410975) C:\Windows\system32\DRIVERS\btwl2cap.sys
20:20:25.0367 5972        btwl2cap - ok
20:20:25.0383 5972        btwrchid        (28e105ad3b79f440bf94780f507bf66a) C:\Windows\system32\DRIVERS\btwrchid.sys
20:20:25.0399 5972        btwrchid - ok
20:20:25.0445 5972        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
20:20:25.0477 5972        cdfs - ok
20:20:25.0523 5972        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
20:20:25.0555 5972        cdrom - ok
20:20:25.0601 5972        CertPropSvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
20:20:25.0648 5972        CertPropSvc - ok
20:20:25.0695 5972        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
20:20:25.0711 5972        circlass - ok
20:20:25.0757 5972        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
20:20:25.0773 5972        CLFS - ok
20:20:25.0945 5972        CLKMSVC10_38F51D56 (524dc3807cb1746225f9d26add19c319) C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
20:20:25.0960 5972        CLKMSVC10_38F51D56 - ok
20:20:26.0007 5972        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:20:26.0023 5972        clr_optimization_v2.0.50727_32 - ok
20:20:26.0054 5972        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
20:20:26.0054 5972        clr_optimization_v2.0.50727_64 - ok
20:20:26.0116 5972        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:20:26.0132 5972        clr_optimization_v4.0.30319_32 - ok
20:20:26.0163 5972        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
20:20:26.0179 5972        clr_optimization_v4.0.30319_64 - ok
20:20:26.0288 5972        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
20:20:26.0303 5972        CmBatt - ok
20:20:26.0335 5972        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
20:20:26.0350 5972        cmdide - ok
20:20:26.0397 5972        CNG            (9ac4f97c2d3e93367e2148ea940cd2cd) C:\Windows\system32\Drivers\cng.sys
20:20:26.0428 5972        CNG - ok
20:20:26.0491 5972        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
20:20:26.0491 5972        Compbatt - ok
20:20:26.0522 5972        CompositeBus    (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
20:20:26.0553 5972        CompositeBus - ok
20:20:26.0584 5972        COMSysApp - ok
20:20:26.0678 5972        cpuz135 - ok
20:20:26.0709 5972        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
20:20:26.0709 5972        crcdisk - ok
20:20:26.0771 5972        CryptSvc        (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll
20:20:26.0803 5972        CryptSvc - ok
20:20:26.0849 5972        DcomLaunch      (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
20:20:26.0896 5972        DcomLaunch - ok
20:20:26.0943 5972        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
20:20:26.0990 5972        defragsvc - ok
20:20:27.0037 5972        DfsC            (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
20:20:27.0083 5972        DfsC - ok
20:20:27.0130 5972        Dhcp            (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
20:20:27.0177 5972        Dhcp - ok
20:20:27.0208 5972        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
20:20:27.0255 5972        discache - ok
20:20:27.0286 5972        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
20:20:27.0302 5972        Disk - ok
20:20:27.0333 5972        Dnscache        (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
20:20:27.0380 5972        Dnscache - ok
20:20:27.0411 5972        dot3svc        (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
20:20:27.0473 5972        dot3svc - ok
20:20:27.0505 5972        DPS            (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
20:20:27.0551 5972        DPS - ok
20:20:27.0583 5972        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
20:20:27.0614 5972        drmkaud - ok
20:20:27.0676 5972        DXGKrnl        (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
20:20:27.0707 5972        DXGKrnl - ok
20:20:27.0754 5972        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
20:20:27.0785 5972        EapHost - ok
20:20:27.0941 5972        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
20:20:28.0051 5972        ebdrv - ok
20:20:28.0160 5972        EFS            (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
20:20:28.0175 5972        EFS - ok
20:20:28.0238 5972        ehRecvr        (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
20:20:28.0300 5972        ehRecvr - ok
20:20:28.0331 5972        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
20:20:28.0363 5972        ehSched - ok
20:20:28.0472 5972        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
20:20:28.0487 5972        elxstor - ok
20:20:28.0519 5972        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
20:20:28.0534 5972        ErrDev - ok
20:20:28.0612 5972        ETD            (05b0dcda418e297a1b4cd8d7b8ade403) C:\Windows\system32\DRIVERS\ETD.sys
20:20:28.0643 5972        ETD - ok
20:20:28.0675 5972        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
20:20:28.0737 5972        EventSystem - ok
20:20:28.0940 5972        EvtEng          (bdfcb7e8c108d042b213957d2b044e7e) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
20:20:28.0955 5972        EvtEng - ok
20:20:29.0096 5972        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
20:20:29.0127 5972        exfat - ok
20:20:29.0158 5972        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
20:20:29.0205 5972        fastfat - ok
20:20:29.0283 5972        Fax            (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
20:20:29.0330 5972        Fax - ok
20:20:29.0361 5972        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
20:20:29.0392 5972        fdc - ok
20:20:29.0408 5972        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
20:20:29.0439 5972        fdPHost - ok
20:20:29.0455 5972        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
20:20:29.0486 5972        FDResPub - ok
20:20:29.0517 5972        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
20:20:29.0533 5972        FileInfo - ok
20:20:29.0564 5972        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
20:20:29.0611 5972        Filetrace - ok
20:20:29.0642 5972        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
20:20:29.0657 5972        flpydisk - ok
20:20:29.0689 5972        FltMgr          (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
20:20:29.0720 5972        FltMgr - ok
20:20:29.0782 5972        FLxHCIc        (72893dc6f72eabaef5aa1013fd189050) C:\Windows\system32\DRIVERS\FLxHCIc.sys
20:20:29.0813 5972        FLxHCIc - ok
20:20:29.0845 5972        FLxHCIh        (a2156628a86450d490a387b9b06fb17d) C:\Windows\system32\DRIVERS\FLxHCIh.sys
20:20:29.0891 5972        FLxHCIh - ok
20:20:29.0954 5972        FontCache      (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
20:20:30.0016 5972        FontCache - ok
20:20:30.0063 5972        FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:20:30.0079 5972        FontCache3.0.0.0 - ok
20:20:30.0125 5972        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
20:20:30.0125 5972        FsDepends - ok
20:20:30.0172 5972        fssfltr        (6c06701bf1db05405804d7eb610991ce) C:\Windows\system32\DRIVERS\fssfltr.sys
20:20:30.0188 5972        fssfltr - ok
20:20:30.0313 5972        fsssvc          (4ce9dac1518ff7e77bd213e6394b9d77) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
20:20:30.0359 5972        fsssvc - ok
20:20:30.0500 5972        Fs_Rec          (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
20:20:30.0515 5972        Fs_Rec - ok
20:20:30.0593 5972        Futuremark SystemInfo Service (0d015d3584704ec814a58276232f143b) C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
20:20:30.0609 5972        Futuremark SystemInfo Service - ok
20:20:30.0671 5972        fvevol          (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
20:20:30.0671 5972        fvevol - ok
20:20:30.0703 5972        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
20:20:30.0718 5972        gagp30kx - ok
20:20:30.0781 5972        gpsvc          (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
20:20:30.0859 5972        gpsvc - ok
20:20:30.0968 5972        gupdate        (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:20:30.0983 5972        gupdate - ok
20:20:30.0999 5972        gupdatem        (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:20:30.0999 5972        gupdatem - ok
20:20:31.0061 5972        gusvc          (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
20:20:31.0061 5972        gusvc - ok
20:20:31.0124 5972        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
20:20:31.0155 5972        hcw85cir - ok
20:20:31.0202 5972        HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
20:20:31.0233 5972        HdAudAddService - ok
20:20:31.0280 5972        HDAudBus        (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
20:20:31.0311 5972        HDAudBus - ok
20:20:31.0327 5972        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
20:20:31.0358 5972        HidBatt - ok
20:20:31.0373 5972        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
20:20:31.0389 5972        HidBth - ok
20:20:31.0436 5972        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
20:20:31.0451 5972        HidIr - ok
20:20:31.0483 5972        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
20:20:31.0529 5972        hidserv - ok
20:20:31.0576 5972        HidUsb          (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
20:20:31.0576 5972        HidUsb - ok
20:20:31.0623 5972        hkmsvc          (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
20:20:31.0670 5972        hkmsvc - ok
20:20:31.0717 5972        HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
20:20:31.0763 5972        HomeGroupListener - ok
20:20:31.0795 5972        HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
20:20:31.0810 5972        HomeGroupProvider - ok
20:20:31.0857 5972        HpSAMD          (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
20:20:31.0857 5972        HpSAMD - ok
20:20:31.0919 5972        HTTP            (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
20:20:31.0966 5972        HTTP - ok
20:20:31.0997 5972        hwpolicy        (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
20:20:32.0013 5972        hwpolicy - ok
20:20:32.0044 5972        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
20:20:32.0060 5972        i8042prt - ok
20:20:32.0122 5972        iaStor          (f7ce9be72edac499b713eca6dae5d26f) C:\Windows\system32\DRIVERS\iaStor.sys
20:20:32.0138 5972        iaStor - ok
20:20:32.0185 5972        iaStorV        (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
20:20:32.0216 5972        iaStorV - ok
20:20:32.0325 5972        idsvc          (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
20:20:32.0356 5972        idsvc - ok
20:20:32.0918 5972        igfx            (0089b53f1befd34b7d8ca4ab021335fa) C:\Windows\system32\DRIVERS\igdkmd64.sys
20:20:33.0245 5972        igfx - ok
20:20:33.0370 5972        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
20:20:33.0386 5972        iirsp - ok
20:20:33.0448 5972        IKEEXT          (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
20:20:33.0526 5972        IKEEXT - ok
20:20:33.0698 5972        IntcAzAudAddService (e22397fb13975ff21be8e6897d7dc584) C:\Windows\system32\drivers\RTKVHD64.sys
20:20:33.0729 5972        IntcAzAudAddService - ok
20:20:33.0916 5972        IntcDAud        (fc727061c0f47c8059e88e05d5c8e381) C:\Windows\system32\DRIVERS\IntcDAud.sys
20:20:33.0963 5972        IntcDAud - ok
20:20:33.0979 5972        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
20:20:33.0994 5972        intelide - ok
20:20:34.0041 5972        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
20:20:34.0057 5972        intelppm - ok
20:20:34.0103 5972        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
20:20:34.0150 5972        IPBusEnum - ok
20:20:34.0197 5972        IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:20:34.0244 5972        IpFilterDriver - ok
20:20:34.0275 5972        iphlpsvc        (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll
20:20:34.0322 5972        iphlpsvc - ok
20:20:34.0369 5972        IPMIDRV        (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
20:20:34.0400 5972        IPMIDRV - ok
20:20:34.0431 5972        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
20:20:34.0462 5972        IPNAT - ok
20:20:34.0493 5972        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
20:20:34.0571 5972        IRENUM - ok
20:20:34.0618 5972        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
20:20:34.0618 5972        isapnp - ok
20:20:34.0649 5972        iScsiPrt        (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
20:20:34.0665 5972        iScsiPrt - ok
20:20:34.0696 5972        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
20:20:34.0696 5972        kbdclass - ok
20:20:34.0727 5972        kbdhid          (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
20:20:34.0743 5972        kbdhid - ok
20:20:34.0774 5972        kbfiltr        (e63ef8c3271d014f14e2469ce75fecb4) C:\Windows\system32\DRIVERS\kbfiltr.sys
20:20:34.0790 5972        kbfiltr - ok
20:20:34.0821 5972        KeyIso          (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:20:34.0837 5972        KeyIso - ok
20:20:34.0868 5972        KSecDD          (97a7070aea4c058b6418519e869a63b4) C:\Windows\system32\Drivers\ksecdd.sys
20:20:34.0883 5972        KSecDD - ok
20:20:34.0915 5972        KSecPkg        (26c43a7c2862447ec59deda188d1da07) C:\Windows\system32\Drivers\ksecpkg.sys
20:20:34.0915 5972        KSecPkg - ok
20:20:34.0946 5972        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
20:20:34.0993 5972        ksthunk - ok
20:20:35.0024 5972        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
20:20:35.0086 5972        KtmRm - ok
20:20:35.0149 5972        L1C            (a4a9ca24e54e81c6c3e469eaeb4b3f42) C:\Windows\system32\DRIVERS\L1C62x64.sys
20:20:35.0164 5972        L1C - ok
20:20:35.0195 5972        LanmanServer    (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll
20:20:35.0227 5972        LanmanServer - ok
20:20:35.0258 5972        LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
20:20:35.0305 5972        LanmanWorkstation - ok
20:20:35.0336 5972        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
20:20:35.0367 5972        lltdio - ok
20:20:35.0414 5972        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
20:20:35.0476 5972        lltdsvc - ok
20:20:35.0492 5972        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
20:20:35.0539 5972        lmhosts - ok
20:20:35.0585 5972        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
20:20:35.0601 5972        LSI_FC - ok
20:20:35.0601 5972        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
20:20:35.0617 5972        LSI_SAS - ok
20:20:35.0632 5972        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
20:20:35.0632 5972        LSI_SAS2 - ok
20:20:35.0663 5972        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
20:20:35.0679 5972        LSI_SCSI - ok
20:20:35.0710 5972        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
20:20:35.0757 5972        luafv - ok
20:20:35.0819 5972        massfilter      (23488767cb18fc3ff39e3af1db3fb02c) C:\Windows\system32\drivers\massfilter.sys
20:20:35.0851 5972        massfilter - ok
20:20:35.0913 5972        MBAMProtector  (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys
20:20:35.0929 5972        MBAMProtector - ok
20:20:36.0022 5972        MBAMService    (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
20:20:36.0038 5972        MBAMService - ok
20:20:36.0069 5972        Mcx2Svc        (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
20:20:36.0100 5972        Mcx2Svc - ok
20:20:36.0116 5972        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
20:20:36.0116 5972        megasas - ok
20:20:36.0147 5972        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
20:20:36.0163 5972        MegaSR - ok
20:20:36.0209 5972        MEIx64          (a6518dcc42f7a6e999bb3bea8fd87567) C:\Windows\system32\DRIVERS\HECIx64.sys
20:20:36.0225 5972        MEIx64 - ok
20:20:36.0256 5972        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
20:20:36.0303 5972        MMCSS - ok
20:20:36.0319 5972        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
20:20:36.0365 5972        Modem - ok
20:20:36.0381 5972        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
20:20:36.0412 5972        monitor - ok
20:20:36.0443 5972        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
20:20:36.0459 5972        mouclass - ok
20:20:36.0490 5972        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
20:20:36.0521 5972        mouhid - ok
20:20:36.0568 5972        mountmgr        (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
20:20:36.0568 5972        mountmgr - ok
20:20:36.0631 5972        MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
20:20:36.0646 5972        MozillaMaintenance - ok
20:20:36.0677 5972        mpio            (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
20:20:36.0677 5972        mpio - ok
20:20:36.0709 5972        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
20:20:36.0740 5972        mpsdrv - ok
20:20:36.0802 5972        MpsSvc          (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll
20:20:36.0865 5972        MpsSvc - ok
20:20:36.0896 5972        MRxDAV          (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
20:20:36.0943 5972        MRxDAV - ok
20:20:36.0974 5972        mrxsmb          (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
20:20:37.0005 5972        mrxsmb - ok
20:20:37.0052 5972        mrxsmb10        (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:20:37.0083 5972        mrxsmb10 - ok
20:20:37.0099 5972        mrxsmb20        (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:20:37.0114 5972        mrxsmb20 - ok
20:20:37.0145 5972        msahci          (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
20:20:37.0145 5972        msahci - ok
20:20:37.0177 5972        msdsm          (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
20:20:37.0192 5972        msdsm - ok
20:20:37.0223 5972        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
20:20:37.0255 5972        MSDTC - ok
20:20:37.0301 5972        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
20:20:37.0333 5972        Msfs - ok
20:20:37.0348 5972        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
20:20:37.0395 5972        mshidkmdf - ok
20:20:37.0411 5972        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
20:20:37.0426 5972        msisadrv - ok
20:20:37.0473 5972        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
20:20:37.0520 5972        MSiSCSI - ok
20:20:37.0520 5972        msiserver - ok
20:20:37.0551 5972        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
20:20:37.0582 5972        MSKSSRV - ok
20:20:37.0598 5972        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
20:20:37.0629 5972        MSPCLOCK - ok
20:20:37.0645 5972        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
20:20:37.0676 5972        MSPQM - ok
20:20:37.0723 5972        MsRPC          (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
20:20:37.0738 5972        MsRPC - ok
20:20:37.0769 5972        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
20:20:37.0785 5972        mssmbios - ok
20:20:37.0816 5972        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
20:20:37.0847 5972        MSTEE - ok
20:20:37.0863 5972        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
20:20:37.0863 5972        MTConfig - ok
20:20:37.0894 5972        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
20:20:37.0894 5972        Mup - ok
20:20:38.0035 5972        MyWiFiDHCPDNS  (93cd1c4ecb8658a35e5e6eba02d43e4f) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
20:20:38.0066 5972        MyWiFiDHCPDNS - ok
20:20:38.0113 5972        napagent        (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
20:20:38.0175 5972        napagent - ok
20:20:38.0222 5972        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
20:20:38.0269 5972        NativeWifiP - ok
20:20:38.0347 5972        NDIS            (c38b8ae57f78915905064a9a24dc1586) C:\Windows\system32\drivers\ndis.sys
20:20:38.0378 5972        NDIS - ok
20:20:38.0409 5972        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
20:20:38.0440 5972        NdisCap - ok
20:20:38.0471 5972        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
20:20:38.0503 5972        NdisTapi - ok
20:20:38.0534 5972        Ndisuio        (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
20:20:38.0565 5972        Ndisuio - ok
20:20:38.0612 5972        NdisWan        (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
20:20:38.0659 5972        NdisWan - ok
20:20:38.0690 5972        NDProxy        (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
20:20:38.0737 5972        NDProxy - ok
20:20:38.0752 5972        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
20:20:38.0799 5972        NetBIOS - ok
20:20:38.0830 5972        NetBT          (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
20:20:38.0893 5972        NetBT - ok
20:20:38.0924 5972        Netlogon        (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:20:38.0939 5972        Netlogon - ok
20:20:38.0986 5972        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
20:20:39.0033 5972        Netman - ok
20:20:39.0064 5972        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
20:20:39.0127 5972        netprofm - ok
20:20:39.0189 5972        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:20:39.0205 5972        NetTcpPortSharing - ok
20:20:39.0563 5972        NETwNs64        (eb43840babf5589e33186d094de7381d) C:\Windows\system32\DRIVERS\NETwNs64.sys
20:20:39.0766 5972        NETwNs64 - ok
20:20:39.0907 5972        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
20:20:39.0922 5972        nfrd960 - ok
20:20:39.0969 5972        NlaSvc          (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
20:20:40.0016 5972        NlaSvc - ok
20:20:40.0063 5972        nmwcd          (5fe6f8c05f0769bbb74afac11453b182) C:\Windows\system32\drivers\ccdcmbx64.sys
20:20:40.0094 5972        nmwcd - ok
20:20:40.0141 5972        nmwcdc          (73c929945c0850b8d1fe2fea05fdf05d) C:\Windows\system32\drivers\ccdcmbox64.sys
20:20:40.0156 5972        nmwcdc - ok
20:20:40.0187 5972        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
20:20:40.0219 5972        Npfs - ok
20:20:40.0234 5972        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
20:20:40.0281 5972        nsi - ok
20:20:40.0297 5972        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
20:20:40.0343 5972        nsiproxy - ok
20:20:40.0421 5972        Ntfs            (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
20:20:40.0484 5972        Ntfs - ok
20:20:40.0609 5972        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
20:20:40.0655 5972        Null - ok
20:20:41.0295 5972        nvlddmkm        (db4f01aba1ff1379e64e997d9fc5c08b) C:\Windows\system32\DRIVERS\nvlddmkm.sys
20:20:41.0451 5972        nvlddmkm - ok
20:20:41.0576 5972        nvpciflt        (6fcf6d9b3c149c7cee6fef8b622765c5) C:\Windows\system32\DRIVERS\nvpciflt.sys
20:20:41.0591 5972        nvpciflt - ok
20:20:41.0623 5972        nvraid          (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
20:20:41.0638 5972        nvraid - ok
20:20:41.0669 5972        nvstor          (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
20:20:41.0685 5972        nvstor - ok
20:20:41.0763 5972        NVSvc          (529153d4c83e6631b303ae183a34fbdb) C:\Windows\system32\nvvsvc.exe
20:20:41.0810 5972        NVSvc - ok
20:20:41.0935 5972        nvUpdatusService (e06dbb528ebb66c10bdda799af2cab37) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
20:20:41.0966 5972        nvUpdatusService - ok
20:20:42.0106 5972        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
20:20:42.0106 5972        nv_agp - ok
20:20:42.0137 5972        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
20:20:42.0153 5972        ohci1394 - ok
20:20:42.0200 5972        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
20:20:42.0247 5972        p2pimsvc - ok
20:20:42.0293 5972        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
20:20:42.0325 5972        p2psvc - ok
20:20:42.0356 5972        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
20:20:42.0371 5972        Parport - ok
20:20:42.0403 5972        partmgr        (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
20:20:42.0418 5972        partmgr - ok
20:20:42.0449 5972        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
20:20:42.0465 5972        PcaSvc - ok
20:20:42.0512 5972        pccsmcfd        (bc0018c2d29f655188a0ed3fa94fdb24) C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
20:20:42.0543 5972        pccsmcfd - ok
20:20:42.0590 5972        pci            (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
20:20:42.0605 5972        pci - ok
20:20:42.0621 5972        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
20:20:42.0621 5972        pciide - ok
20:20:42.0668 5972        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
20:20:42.0683 5972        pcmcia - ok
20:20:42.0699 5972        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
20:20:42.0715 5972        pcw - ok
20:20:42.0746 5972        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
20:20:42.0808 5972        PEAUTH - ok
20:20:42.0902 5972        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
20:20:42.0917 5972        PerfHost - ok
20:20:43.0073 5972        pla            (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
20:20:43.0183 5972        pla - ok
20:20:43.0354 5972        PlugPlay        (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
20:20:43.0417 5972        PlugPlay - ok
20:20:43.0448 5972        PnkBstrA - ok
20:20:43.0463 5972        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
20:20:43.0495 5972        PNRPAutoReg - ok
20:20:43.0526 5972        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
20:20:43.0541 5972        PNRPsvc - ok
20:20:43.0588 5972        PolicyAgent    (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
20:20:43.0635 5972        PolicyAgent - ok
20:20:43.0682 5972        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
20:20:43.0713 5972        Power - ok
20:20:43.0791 5972        PptpMiniport    (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
20:20:43.0838 5972        PptpMiniport - ok
20:20:43.0869 5972        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
20:20:43.0885 5972        Processor - ok
20:20:43.0916 5972        ProfSvc        (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll
20:20:43.0947 5972        ProfSvc - ok
20:20:43.0978 5972        ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:20:43.0978 5972        ProtectedStorage - ok
20:20:44.0009 5972        Psched          (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
20:20:44.0041 5972        Psched - ok
20:20:44.0134 5972        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
20:20:44.0197 5972        ql2300 - ok
20:20:44.0337 5972        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
20:20:44.0337 5972        ql40xx - ok
20:20:44.0384 5972        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
20:20:44.0415 5972        QWAVE - ok
20:20:44.0431 5972        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
20:20:44.0446 5972        QWAVEdrv - ok
20:20:44.0462 5972        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
20:20:44.0493 5972        RasAcd - ok
20:20:44.0524 5972        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
20:20:44.0571 5972        RasAgileVpn - ok
20:20:44.0618 5972        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
20:20:44.0649 5972        RasAuto - ok
20:20:44.0680 5972        Rasl2tp        (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
20:20:44.0727 5972        Rasl2tp - ok
20:20:44.0774 5972        RasMan          (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
20:20:44.0821 5972        RasMan - ok
20:20:44.0867 5972        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
20:20:44.0899 5972        RasPppoe - ok
20:20:44.0930 5972        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
20:20:44.0977 5972        RasSstp - ok
20:20:45.0023 5972        rdbss          (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
20:20:45.0055 5972        rdbss - ok
20:20:45.0070 5972        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
20:20:45.0101 5972        rdpbus - ok
20:20:45.0133 5972        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
20:20:45.0164 5972        RDPCDD - ok
20:20:45.0195 5972        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
20:20:45.0242 5972        RDPENCDD - ok
20:20:45.0273 5972        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
20:20:45.0320 5972        RDPREFMP - ok
20:20:45.0351 5972        RDPWD          (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys
20:20:45.0382 5972        RDPWD - ok
20:20:45.0445 5972        rdyboost        (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
20:20:45.0445 5972        rdyboost - ok
20:20:45.0601 5972        RegSrvc        (a6baea839cc888d4961ab5fe16bb8c4a) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
20:20:45.0632 5972        RegSrvc - ok
20:20:45.0663 5972        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
20:20:45.0710 5972        RemoteAccess - ok
20:20:45.0741 5972        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
20:20:45.0772 5972        RemoteRegistry - ok
20:20:45.0835 5972        RFCOMM          (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
20:20:45.0866 5972        RFCOMM - ok
20:20:45.0991 5972        RichVideo      (616f6e52cae254727a886ba8eda1beea) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
20:20:45.0991 5972        RichVideo - ok
20:20:46.0022 5972        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
20:20:46.0053 5972        RpcEptMapper - ok
20:20:46.0084 5972        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
20:20:46.0100 5972        RpcLocator - ok
20:20:46.0147 5972        RpcSs          (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
20:20:46.0178 5972        RpcSs - ok
20:20:46.0225 5972        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
20:20:46.0271 5972        rspndr - ok
20:20:46.0287 5972        SamSs          (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:20:46.0287 5972        SamSs - ok
20:20:46.0318 5972        sbp2port        (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
20:20:46.0334 5972        sbp2port - ok
20:20:46.0381 5972        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
20:20:46.0427 5972        SCardSvr - ok
20:20:46.0474 5972        scfilter        (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
20:20:46.0505 5972        scfilter - ok
20:20:46.0599 5972        Schedule        (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
20:20:46.0646 5972        Schedule - ok
20:20:46.0693 5972        SCPolicySvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
20:20:46.0708 5972        SCPolicySvc - ok
20:20:46.0739 5972        SDRSVC          (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
20:20:46.0771 5972        SDRSVC - ok
20:20:46.0833 5972        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
20:20:46.0880 5972        secdrv - ok
20:20:46.0911 5972        seclogon        (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
20:20:46.0942 5972        seclogon - ok
20:20:46.0989 5972        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
20:20:47.0036 5972        SENS - ok
20:20:47.0051 5972        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
20:20:47.0083 5972        SensrSvc - ok
20:20:47.0114 5972        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
20:20:47.0129 5972        Serenum - ok
20:20:47.0176 5972        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
20:20:47.0207 5972        Serial - ok
20:20:47.0254 5972        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
20:20:47.0285 5972        sermouse - ok
20:20:47.0395 5972        ServiceLayer    (f31e9531af225ca25350d5e87e999b31) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
20:20:47.0426 5972        ServiceLayer - ok
20:20:47.0473 5972        SessionEnv      (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
20:20:47.0504 5972        SessionEnv - ok
20:20:47.0551 5972        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
20:20:47.0566 5972        sffdisk - ok
20:20:47.0582 5972        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
20:20:47.0613 5972        sffp_mmc - ok
20:20:47.0629 5972        sffp_sd        (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
20:20:47.0644 5972        sffp_sd - ok
20:20:47.0675 5972        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
20:20:47.0691 5972        sfloppy - ok
20:20:47.0753 5972        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
20:20:47.0816 5972        SharedAccess - ok
20:20:47.0863 5972        ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
20:20:47.0909 5972        ShellHWDetection - ok
20:20:47.0956 5972        SiSGbeLH        (1bc348cf6baa90ec8e533ef6e6a69933) C:\Windows\system32\DRIVERS\SiSG664.sys
20:20:47.0972 5972        SiSGbeLH - ok
20:20:47.0987 5972        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
20:20:48.0003 5972        SiSRaid2 - ok
20:20:48.0019 5972        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
20:20:48.0034 5972        SiSRaid4 - ok
20:20:48.0128 5972        SkypeUpdate    (ea396139541706b4b433641d62ea53ce) C:\Program Files (x86)\Skype\Updater\Updater.exe
20:20:48.0128 5972        SkypeUpdate - ok
20:20:48.0159 5972        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
20:20:48.0190 5972        Smb - ok
20:20:48.0221 5972        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
20:20:48.0237 5972        SNMPTRAP - ok
20:20:48.0362 5972        SNP2UVC        (c98375d19f9e9966f6201bae65fb3728) C:\Windows\system32\DRIVERS\snp2uvc.sys
20:20:48.0424 5972        SNP2UVC - ok
20:20:48.0549 5972        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
20:20:48.0549 5972        spldr - ok
20:20:48.0596 5972        Spooler        (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
20:20:48.0627 5972        Spooler - ok
20:20:48.0814 5972        sppsvc          (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
20:20:48.0939 5972        sppsvc - ok
20:20:49.0048 5972        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
20:20:49.0079 5972        sppuinotify - ok
20:20:49.0142 5972        srv            (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
20:20:49.0189 5972        srv - ok
20:20:49.0220 5972        srv2            (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
20:20:49.0267 5972        srv2 - ok
20:20:49.0298 5972        srvnet          (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
20:20:49.0298 5972        srvnet - ok
20:20:49.0345 5972        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
20:20:49.0391 5972        SSDPSRV - ok
20:20:49.0407 5972        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
20:20:49.0454 5972        SstpSvc - ok
20:20:49.0485 5972        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
20:20:49.0501 5972        stexstor - ok
20:20:49.0547 5972        stisvc          (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
20:20:49.0594 5972        stisvc - ok
20:20:49.0610 5972        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
20:20:49.0610 5972        swenum - ok
20:20:49.0657 5972        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
20:20:49.0703 5972        swprv - ok
20:20:49.0797 5972        SysMain        (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
20:20:49.0859 5972        SysMain - ok
20:20:49.0969 5972        TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
20:20:50.0000 5972        TabletInputService - ok
20:20:50.0047 5972        TapiSrv        (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
20:20:50.0078 5972        TapiSrv - ok
20:20:50.0109 5972        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
20:20:50.0125 5972        TBS - ok
20:20:50.0265 5972        Tcpip          (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
20:20:50.0343 5972        Tcpip - ok
20:20:50.0515 5972        TCPIP6          (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
20:20:50.0546 5972        TCPIP6 - ok
20:20:50.0671 5972        tcpipreg        (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
20:20:50.0702 5972        tcpipreg - ok
20:20:50.0717 5972        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
20:20:50.0749 5972        TDPIPE - ok
20:20:50.0780 5972        TDTCP          (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
20:20:50.0780 5972        TDTCP - ok
20:20:50.0827 5972        tdx            (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
20:20:50.0858 5972        tdx - ok
20:20:50.0889 5972        TermDD          (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
20:20:50.0905 5972        TermDD - ok
20:20:50.0951 5972        TermService    (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
20:20:51.0014 5972        TermService - ok
20:20:51.0061 5972        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
20:20:51.0076 5972        Themes - ok
20:20:51.0107 5972        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
20:20:51.0123 5972        THREADORDER - ok
20:20:51.0154 5972        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
20:20:51.0185 5972        TrkWks - ok
20:20:51.0248 5972        TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
20:20:51.0295 5972        TrustedInstaller - ok
20:20:51.0341 5972        tssecsrv        (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
20:20:51.0373 5972        tssecsrv - ok
20:20:51.0404 5972        TsUsbFlt        (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
20:20:51.0435 5972        TsUsbFlt - ok
20:20:51.0482 5972        tunnel          (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
20:20:51.0513 5972        tunnel - ok
20:20:51.0560 5972        TurboB          (fd24f98d2898be093fe926604be7db99) C:\Windows\system32\DRIVERS\TurboB.sys
20:20:51.0575 5972        TurboB - ok
20:20:51.0638 5972        TurboBoost      (600b406a04d90f577fea8a88d7379f08) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
20:20:51.0638 5972        TurboBoost - ok
20:20:51.0669 5972        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
20:20:51.0685 5972        uagp35 - ok
20:20:51.0731 5972        udfs            (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
20:20:51.0794 5972        udfs - ok
20:20:51.0872 5972        UI Assistant Service (13bff97e926bf8d9c1230cecc371a0c0) C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe
20:20:51.0887 5972        UI Assistant Service - ok
20:20:51.0919 5972        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
20:20:51.0934 5972        UI0Detect - ok
20:20:51.0981 5972        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
20:20:51.0997 5972        uliagpkx - ok
20:20:52.0012 5972        umbus          (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
20:20:52.0028 5972        umbus - ok
20:20:52.0059 5972        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
20:20:52.0075 5972        UmPass - ok
20:20:52.0121 5972        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
20:20:52.0184 5972        upnphost - ok
20:20:52.0215 5972        upperdev        (34afb83c7bba370e404e52cc2290350c) C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
20:20:52.0231 5972        upperdev - ok
20:20:52.0277 5972        usbccgp        (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
20:20:52.0293 5972        usbccgp - ok
20:20:52.0340 5972        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
20:20:52.0371 5972        usbcir - ok
20:20:52.0387 5972        usbehci        (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
20:20:52.0418 5972        usbehci - ok
20:20:52.0465 5972        usbhub          (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
20:20:52.0496 5972        usbhub - ok
20:20:52.0543 5972        usbohci        (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
20:20:52.0558 5972        usbohci - ok
20:20:52.0605 5972        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
20:20:52.0636 5972        usbprint - ok
20:20:52.0667 5972        usbscan        (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
20:20:52.0683 5972        usbscan - ok
20:20:52.0730 5972        usbser          (4acee387fa8fd39f83564fcd2fc234f2) C:\Windows\system32\drivers\usbser.sys
20:20:52.0761 5972        usbser - ok
20:20:52.0808 5972        UsbserFilt      (aa75e1efbee7186b4cbaaacf1f15e6ca) C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
20:20:52.0839 5972        UsbserFilt - ok
20:20:52.0855 5972        USBSTOR        (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:20:52.0886 5972        USBSTOR - ok
20:20:52.0901 5972        usbuhci        (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
20:20:52.0917 5972        usbuhci - ok
20:20:52.0948 5972        usbvideo        (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
20:20:52.0964 5972        usbvideo - ok
20:20:53.0042 5972        usb_rndisx      (70d05ee263568a742d14e1876df80532) C:\Windows\system32\DRIVERS\usb8023x.sys
20:20:53.0057 5972        usb_rndisx - ok
20:20:53.0089 5972        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
20:20:53.0135 5972        UxSms - ok
20:20:53.0151 5972        VaultSvc        (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:20:53.0167 5972        VaultSvc - ok
20:20:53.0198 5972        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
20:20:53.0198 5972        vdrvroot - ok
20:20:53.0245 5972        vds            (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
20:20:53.0307 5972        vds - ok
20:20:53.0338 5972        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
20:20:53.0354 5972        vga - ok
20:20:53.0369 5972        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
20:20:53.0401 5972        VgaSave - ok
20:20:53.0447 5972        vhdmp          (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
20:20:53.0463 5972        vhdmp - ok
20:20:53.0494 5972        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
20:20:53.0510 5972        viaide - ok
20:20:53.0572 5972        VideAceWindowsService (c37ce43fb54066ffb540729c6e6e194e) C:\ExpressGateUtil\VAWinService.exe
20:20:53.0572 5972        VideAceWindowsService - ok
20:20:53.0603 5972        volmgr          (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
20:20:53.0603 5972        volmgr - ok
20:20:53.0650 5972        volmgrx        (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
20:20:53.0666 5972        volmgrx - ok
20:20:53.0697 5972        volsnap        (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
20:20:53.0713 5972        volsnap - ok
20:20:53.0759 5972        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
20:20:53.0775 5972        vsmraid - ok
20:20:53.0869 5972        VSS            (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
20:20:53.0947 5972        VSS - ok
20:20:54.0071 5972        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
20:20:54.0103 5972        vwifibus - ok
20:20:54.0118 5972        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
20:20:54.0134 5972        vwififlt - ok
20:20:54.0165 5972        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
20:20:54.0165 5972        vwifimp - ok
20:20:54.0212 5972        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
20:20:54.0259 5972        W32Time - ok
20:20:54.0290 5972        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
20:20:54.0321 5972        WacomPen - ok
20:20:54.0352 5972        WANARP          (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
20:20:54.0383 5972        WANARP - ok
20:20:54.0383 5972        Wanarpv6        (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
20:20:54.0415 5972        Wanarpv6 - ok
20:20:54.0508 5972        WatAdminSvc    (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
20:20:54.0555 5972        WatAdminSvc - ok
20:20:54.0633 5972        wbengine        (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
20:20:54.0711 5972        wbengine - ok
20:20:54.0867 5972        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
20:20:54.0883 5972        WbioSrvc - ok
20:20:54.0945 5972        wcncsvc        (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
20:20:54.0976 5972        wcncsvc - ok
20:20:55.0007 5972        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
20:20:55.0039 5972        WcsPlugInService - ok
20:20:55.0085 5972        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
20:20:55.0101 5972        Wd - ok
20:20:55.0148 5972        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
20:20:55.0179 5972        Wdf01000 - ok
20:20:55.0210 5972        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
20:20:55.0304 5972        WdiServiceHost - ok
20:20:55.0304 5972        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
20:20:55.0319 5972        WdiSystemHost - ok
20:20:55.0366 5972        wdkmd          (fe31110e39a0b11abae1ba43a2dc94f9) C:\Windows\system32\DRIVERS\WDKMD.sys
20:20:55.0382 5972        wdkmd - ok
20:20:55.0429 5972        WebClient      (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
20:20:55.0460 5972        WebClient - ok
20:20:55.0507 5972        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
20:20:55.0553 5972        Wecsvc - ok
20:20:55.0585 5972        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
20:20:55.0616 5972        wercplsupport - ok
20:20:55.0631 5972        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
20:20:55.0678 5972        WerSvc - ok
20:20:55.0709 5972        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
20:20:55.0725 5972        WfpLwf - ok
20:20:55.0803 5972        WimFltr        (52ded146e4797e6ccf94799e8e22bb2a) C:\Windows\system32\DRIVERS\wimfltr.sys
20:20:55.0803 5972        WimFltr - ok
20:20:55.0834 5972        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
20:20:55.0834 5972        WIMMount - ok
20:20:55.0865 5972        WinDefend - ok
20:20:55.0881 5972        WinHttpAutoProxySvc - ok
20:20:55.0943 5972        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
20:20:55.0990 5972        Winmgmt - ok
20:20:56.0099 5972        WinRM          (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
20:20:56.0193 5972        WinRM - ok
20:20:56.0349 5972        WinUsb          (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
20:20:56.0365 5972        WinUsb - ok
20:20:56.0427 5972        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
20:20:56.0474 5972        Wlansvc - ok
20:20:56.0536 5972        wlcrasvc        (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
20:20:56.0552 5972        wlcrasvc - ok
20:20:56.0692 5972        wlidsvc        (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
20:20:56.0723 5972        wlidsvc - ok
20:20:56.0848 5972        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
20:20:56.0864 5972        WmiAcpi - ok
20:20:56.0926 5972        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
20:20:56.0942 5972        wmiApSrv - ok
20:20:56.0989 5972        WMPNetworkSvc - ok
20:20:57.0020 5972        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
20:20:57.0035 5972        WPCSvc - ok
20:20:57.0082 5972        WPDBusEnum      (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
20:20:57.0082 5972        WPDBusEnum - ok
20:20:57.0129 5972        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
20:20:57.0145 5972        ws2ifsl - ok
20:20:57.0176 5972        wscsvc          (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\System32\wscsvc.dll
20:20:57.0191 5972        wscsvc - ok
20:20:57.0191 5972        WSearch - ok
20:20:57.0316 5972        wuauserv        (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
20:20:57.0394 5972        wuauserv - ok
20:20:57.0519 5972        WudfPf          (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
20:20:57.0550 5972        WudfPf - ok
20:20:57.0597 5972        WUDFRd          (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
20:20:57.0628 5972        WUDFRd - ok
20:20:57.0644 5972        wudfsvc        (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
20:20:57.0675 5972        wudfsvc - ok
20:20:57.0737 5972        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
20:20:57.0769 5972        WwanSvc - ok
20:20:57.0831 5972        ZTEusbmdm6k    (ff5a03a65b68db7e02a12880399d40d4) C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys
20:20:57.0862 5972        ZTEusbmdm6k - ok
20:20:57.0878 5972        ZTEusbnmea      (ff5a03a65b68db7e02a12880399d40d4) C:\Windows\system32\DRIVERS\ZTEusbnmea.sys
20:20:57.0893 5972        ZTEusbnmea - ok
20:20:57.0925 5972        ZTEusbser6k    (ff5a03a65b68db7e02a12880399d40d4) C:\Windows\system32\DRIVERS\ZTEusbser6k.sys
20:20:57.0940 5972        ZTEusbser6k - ok
20:20:57.0971 5972        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
20:20:58.0361 5972        \Device\Harddisk0\DR0 - ok
20:20:58.0720 5972        MBR (0x1B8)    (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR1
20:20:58.0907 5972        \Device\Harddisk1\DR1 - ok
20:20:58.0907 5972        Boot (0x1200)  (5695c82d7e0431652ea16f8eb48b01da) \Device\Harddisk0\DR0\Partition0
20:20:58.0907 5972        \Device\Harddisk0\DR0\Partition0 - ok
20:20:58.0970 5972        Boot (0x1200)  (95d652eb7997ac6494c4e7ef7c26e849) \Device\Harddisk0\DR0\Partition1
20:20:58.0985 5972        \Device\Harddisk0\DR0\Partition1 - ok
20:20:58.0985 5972        Boot (0x1200)  (3f9678c86d5bf609e63b0b92d06f0b3b) \Device\Harddisk1\DR1\Partition0
20:20:58.0985 5972        \Device\Harddisk1\DR1\Partition0 - ok
20:20:58.0985 5972        Boot (0x1200)  (4f8cd3a84a039820e000897ff574ac79) \Device\Harddisk1\DR1\Partition1
20:20:58.0985 5972        \Device\Harddisk1\DR1\Partition1 - ok
20:20:58.0985 5972        ============================================================
20:20:58.0985 5972        Scan finished
20:20:58.0985 5972        ============================================================
20:20:59.0001 4844        Detected object count: 1
20:20:59.0001 4844        Actual detected object count: 1
20:21:24.0944 4844        C:\Program Files (x86)\Browny02\BrYNSvc.exe - copied to quarantine
20:21:24.0944 4844        BrYNSvc ( UnsignedFile.Multi.Generic ) - User select action: Quarantine


cosinus 19.07.2012 11:08

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

sebbi86 19.07.2012 18:56

So Combofix ist durchgelaufen.

Musste zwischendurch mal kurz die Maus bewegen, weil mein Bildschirmschoner angesprungen ist:

Hier das Log dazu

Code:

ComboFix 12-07-19.02 - Asus 19.07.2012  19:44:14.1.8 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.8103.6136 [GMT 2:00]
ausgeführt von:: c:\users\Asus\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\FullRemove.exe
c:\windows\msvcr71.dll
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-06-19 bis 2012-07-19  ))))))))))))))))))))))))))))))
.
.
2012-07-19 17:51 . 2012-07-19 17:51        --------        d-----w-        c:\users\UpdatusUser\AppData\Local\temp
2012-07-19 17:51 . 2012-07-19 17:51        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-07-18 18:21 . 2012-07-18 18:21        --------        d-----w-        C:\TDSSKiller_Quarantine
2012-07-17 19:25 . 2012-07-17 19:25        --------        d-----w-        C:\_OTL
2012-07-12 01:06 . 2012-06-12 03:08        3148800        ----a-w-        c:\windows\system32\win32k.sys
2012-07-11 20:21 . 2012-07-11 20:21        --------        d-----w-        c:\program files (x86)\ESET
2012-07-08 15:52 . 2012-07-08 15:52        --------        d-----w-        c:\users\Versuch
2012-07-07 20:19 . 2012-07-07 20:19        --------        d-----w-        c:\users\Asus\AppData\Roaming\Malwarebytes
2012-07-07 20:19 . 2012-07-07 20:19        --------        d-----w-        c:\programdata\Malwarebytes
2012-07-07 20:19 . 2012-07-14 05:23        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-07-07 20:19 . 2012-07-03 11:46        24904        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-07-05 19:25 . 2012-07-12 15:13        405144        ----a-w-        c:\windows\SysWow64\Newtonsoft.Json.Net20.dll
2012-06-25 14:04 . 2012-06-25 14:04        1394248        ----a-w-        c:\windows\SysWow64\msxml4.dll
2012-06-21 16:16 . 2012-06-02 22:19        2428952        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-21 16:16 . 2012-06-02 22:19        57880        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-21 16:16 . 2012-06-02 22:19        44056        ----a-w-        c:\windows\system32\wups2.dll
2012-06-21 16:16 . 2012-06-02 22:15        2622464        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-21 16:16 . 2012-06-02 22:19        38424        ----a-w-        c:\windows\system32\wups.dll
2012-06-21 16:16 . 2012-06-02 22:19        701976        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-21 16:16 . 2012-06-02 22:15        99840        ----a-w-        c:\windows\system32\wudriver.dll
2012-06-21 16:16 . 2012-06-02 13:19        186752        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-21 16:16 . 2012-06-02 13:15        36864        ----a-w-        c:\windows\system32\wuapp.exe
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-18 05:35 . 2011-04-03 18:13        45056        ----a-w-        c:\windows\system32\acovcnt.exe
2012-07-12 01:01 . 2011-04-30 17:49        59701280        ----a-w-        c:\windows\system32\MRT.exe
2012-05-04 11:06 . 2012-06-13 06:05        5559664        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-05-04 10:03 . 2012-06-13 06:05        3968368        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-13 06:05        3913072        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2012-05-02 13:24 . 2012-05-25 05:27        27760        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2012-05-01 05:40 . 2012-06-13 06:05        209920        ----a-w-        c:\windows\system32\profsvc.dll
2012-04-28 03:55 . 2012-06-13 06:05        210944        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-04-27 08:20 . 2012-05-25 05:27        132832        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-04-26 05:41 . 2012-06-13 06:05        77312        ----a-w-        c:\windows\system32\rdpwsx.dll
2012-04-26 05:41 . 2012-06-13 06:05        149504        ----a-w-        c:\windows\system32\rdpcorekmts.dll
2012-04-26 05:34 . 2012-06-13 06:05        9216        ----a-w-        c:\windows\system32\rdrmemptylst.exe
2012-04-24 22:32 . 2012-05-25 05:27        98848        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2012-04-24 05:37 . 2012-06-13 06:04        184320        ----a-w-        c:\windows\system32\cryptsvc.dll
2012-04-24 05:37 . 2012-06-13 06:04        140288        ----a-w-        c:\windows\system32\cryptnet.dll
2012-04-24 05:37 . 2012-06-13 06:04        1462272        ----a-w-        c:\windows\system32\crypt32.dll
2012-04-24 04:36 . 2012-06-13 06:04        1158656        ----a-w-        c:\windows\SysWow64\crypt32.dll
2012-04-24 04:36 . 2012-06-13 06:04        140288        ----a-w-        c:\windows\SysWow64\cryptsvc.dll
2012-04-24 04:36 . 2012-06-13 06:04        103936        ----a-w-        c:\windows\SysWow64\cryptnet.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ICQ"="c:\program files (x86)\ICQ7.5\ICQ.exe" [2011-08-01 124480]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-01-12 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" [2008-11-03 328992]
"SonicMasterTray"="c:\program files (x86)\ASUS\SonicMaster\SonicMasterTray.exe" [2010-07-10 984400]
"FLxHCIm"="c:\program files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe" [2011-01-21 40448]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536]
"VAWinAgent"="c:\expressgateutil\VAWinAgent.exe" [2011-01-17 191304]
"RemoteControl10"="c:\program files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 87336]
"BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2010-11-12 75048]
"UpdatePSTShortCut"="c:\program files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2010-11-24 222504]
"UIExec"="c:\program files (x86)\1&1 Surf-Stick\UIExec.exe" [2010-09-30 139088]
"BrStsMon00"="c:\program files (x86)\Browny02\Brother\BrStMonW.exe" [2010-02-09 2621440]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-05-01 348624]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2012-02-16 322176]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2011-10-24 174720]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe [2011-1-12 548528]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-8-3 1080608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 CLKMSVC10_38F51D56;CyberLink Product - 2011/04/03 11:10;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2010-11-12 241648]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-07 135664]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-03 160944]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2010-05-03 44032]
R3 cpuz135;cpuz135;c:\windows\TEMP\cpuz135\cpuz135_x64.sys [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-12-09 135584]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-07 135664]
R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2009-10-29 11776]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-06 129976]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-07-20 340240]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2012-03-11 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2011-03-10 25576]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-05-02 27760]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [2011-01-25 379520]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-01 86224]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-03-10 1997416]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120]
S2 UI Assistant Service;UI Assistant Service;c:\program files (x86)\1&1 Surf-Stick\AssistantServices.exe [2010-09-30 253264]
S2 VideAceWindowsService;VideAceWindowsService;c:\expressgateutil\VAWinService.exe [2011-01-17 91464]
S3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe [2010-01-25 245760]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-07-01 52264]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-09-08 129024]
S3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\DRIVERS\FLxHCIc.sys [2011-01-21 161280]
S3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver;c:\windows\system32\DRIVERS\FLxHCIh.sys [2011-01-21 50176]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-08-24 76912]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2010-07-14 7821312]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [2010-06-18 39832]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - CLKMDRV10_38F51D56
.
Inhalt des "geplante Tasks" Ordners
.
2012-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-07 09:13]
.
2012-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-07 09:13]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49        70656        ----a-w-        c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49        70656        ----a-w-        c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-10-13 2168424]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-07-20 1931024]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-05-03 324096]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2010-01-21 909824]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-10-21 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-10-21 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-10-21 416024]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://asus.msn.com
mStart Page = hxxp://asus.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Free YouTube Download - c:\users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\iskpx8ki.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-ETDWare - c:\program files (x86)\Elantech\ETDCtrl.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1516755417-3234397197-3308580895-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:f0,05,9a,ba,88,30,d1,be,ff,ea,d5,02,66,4a,89,ac,29,3d,50,35,de,7c,0f,
  8b,7a,3e,5c,51,b7,bb,4a,7a,ee,c6,ac,9a,27,18,ec,47,2c,df,f7,c4,e7,70,bf,29,\
"??"=hex:03,19,76,33,70,8c,2e,19,d1,71,a8,71,bc,15,cf,05
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-07-19  19:54:06
ComboFix-quarantined-files.txt  2012-07-19 17:54
.
Vor Suchlauf: 12 Verzeichnis(se), 13.204.955.136 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 15.202.340.864 Bytes frei
.
- - End Of File - - 6E08974703EDD894B4B8E4F9A34A9335

Grüße Sebastian

cosinus 19.07.2012 20:12

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

sebbi86 20.07.2012 19:25

So alles erfolgreich geschafft. Probleme gabs keine.

Hier die Logs von

Gmer:

Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-07-20 08:41:07
Windows 6.1.7601 Service Pack 1
Running: 8y9np4vh.exe


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0015007a2bc2                     
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74f06dd1dd25                     
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74f06dd1dd25@d4cbaf233ebb        0xF6 0x89 0x07 0xEB ...
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74f06dd1dd25@000704ce0b97        0xC9 0xBC 0x6F 0x0F ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0015007a2bc2 (not active ControlSet) 
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74f06dd1dd25 (not active ControlSet) 
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74f06dd1dd25@d4cbaf233ebb            0xF6 0x89 0x07 0xEB ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74f06dd1dd25@000704ce0b97            0xC9 0xBC 0x6F 0x0F ...

---- EOF - GMER 1.0.15 ----

OSAM:

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 19:50:14 on 20.07.2012

OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 64-bit
Default Browser: Mozilla Corporation Firefox 12.0

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"ASMMAP64" (ASMMAP64) - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys
"ATKWMIACPI Driver" (ATKWMIACPIIO) - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"cpuz135" (cpuz135) - ? - C:\Windows\TEMP\cpuz135\cpuz135_x64.sys  (File not found)
"FssFltr" (fssfltr) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\fssfltr.sys
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"WimFltr" (WimFltr) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\wimfltr.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} "Album Download IE Asynchronous Pluggable Protocol Interface" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files (x86)\WinRAR\rarext.dll
{B41DB860-64E4-11D2-9906-E49FADC173CA} "WinRAR shell extension" - ? -  (File not found | COM-object registry key not found)
{0563DB41-F538-4B37-A92D-4659049B7766} "WLMD Message Handler" - ? -  (File not found | COM-object registry key not found)
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} "@C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "@C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
"ICQ7.5" - "ICQ, LLC." - C:\Program Files (x86)\ICQ7.5\ICQ.exe
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Plug-In" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" - "Google Inc." - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Plug-In" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID Sign-in Helper" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{9FDDE16B-836F-4806-AB1F-1455CBEFF289} "Windows Live Messenger Companion Helper" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

[LSA Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )-----
"Security Packages" - "Microsoft Corp." - C:\Windows\system32\livessp.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"AsusVibeLauncher.lnk" - ? - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe  (Shortcut exists | File exists)
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Bluetooth.lnk" - ? - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File not found)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"ICQ" - "ICQ, LLC." - "C:\Program Files (x86)\ICQ7.5\ICQ.exe" silent loginmode=4
"swg" - "Google Inc." - "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"ATKMEDIA" - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
"ATKOSD2" - "ASUSTek Computer Inc." - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"BDRegion" - "cyberlink" - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
"BrStsMon00" - "Brother Industries, Ltd." - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
"FLxHCIm" - "Windows (R) Win 7 DDK provider" - "C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe"
"HControlUser" - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"Nuance PDF Reader-reminder" - "Nuance Communications, Inc." - "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
"RemoteControl10" - "CyberLink Corp." - "C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe"
"SonicMasterTray" - "Virage Logic Corporation / Sonic Focus" - C:\Program Files (x86)\ASUS\SonicMaster\SonicMasterTray.exe
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"UIExec" - ? - "C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe"  (File found, but it contains no detailed information)
"UpdateLBPShortCut" - "CyberLink Corp." - "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
"UpdateP2GoShortCut" - "CyberLink Corp." - "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
"UpdatePSTShortCut" - "CyberLink Corp." - "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
"VAWinAgent" - ? - C:\ExpressGateUtil\VAWinAgent.exe  (File found, but it contains no detailed information)
"Wireless Console 3" - ? - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"EPSON BX320FW Series 64MonitorBE" - "SEIKO EPSON CORPORATION" - C:\Windows\system32\E_ILMGIE.DLL
"EpsonNet Print Port" - "SEIKO EPSON CORPORATION" - C:\Windows\system32\enppmon.dll
"PDFCreator" - ? - C:\Windows\system32\pdfcmnnt.dll  (File found, but it contains no detailed information)

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll  (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe"  (File not found)
"AFBAgent" (AFBAgent) - "ASUSTeK Computer Inc." - C:\Windows\system32\FBAgent.exe
"ASLDR Service" (ASLDRService) - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
"ATKGFNEX Service" (ATKGFNEXSrv) - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
"Bluetooth Service" (btwdins) - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
"BrYNSvc" (BrYNSvc) - "Brother Industries, Ltd." - C:\Program Files (x86)\Browny02\BrYNSvc.exe
"CyberLink Product - 2011/04/03 11:10:19" (CLKMSVC10_38F51D56) - "CyberLink" - C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
"Futuremark SystemInfo Service" (Futuremark SystemInfo Service) - "Futuremark Corporation" - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Intel(R) PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
"Intel(R) PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
"Intel(R) Turbo Boost Technology Monitor 2.0" (TurboBoost) - "Intel(R) Corporation" - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
"NVIDIA Driver Helper Service" (NVSvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe
"NVIDIA Update Service Daemon" (nvUpdatusService) - "NVIDIA Corporation" - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
"PnkBstrA" (PnkBstrA) - ? - C:\Windows\system32\PnkBstrA.exe  (File not found)
"ServiceLayer" (ServiceLayer) - "Nokia" - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files (x86)\Skype\Updater\Updater.exe
"UI Assistant Service" (UI Assistant Service) - ? - C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe  (File found, but it contains no detailed information)
"VideAceWindowsService" (VideAceWindowsService) - ? - C:\ExpressGateUtil\VAWinService.exe  (File found, but it contains no detailed information)
"Windows Live Family Safety Service" (fsssvc) - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
"Wireless PAN DHCP Server" (MyWiFiDHCPDNS) - ? - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe

[Winlogon]
-----( HKCU\Control Panel\Desktop )-----
"SCRNSAVE.EXE" - "Microsoft Corporation" - C:\Windows\WLXPGSS.SCR

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"WindowsLive Local NSP" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
"WindowsLive NSP" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

und aswMBR

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-20 19:51:14
-----------------------------
19:51:14.132    OS Version: Windows x64 6.1.7601 Service Pack 1
19:51:14.132    Number of processors: 8 586 0x2A07
19:51:14.132    ComputerName: ASUS-PC  UserName: Asus
19:51:15.162    Initialize success
19:52:12.462    AVAST engine defs: 12072000
19:52:26.939    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:52:26.939    Disk 0 Vendor: ST950032 0003 Size: 476940MB BusType: 3
19:52:26.939    Disk 1  \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2
19:52:26.939    Disk 1 Vendor: ST950032 0003 Size: 476940MB BusType: 3
19:52:26.954    Disk 0 MBR read successfully
19:52:26.954    Disk 0 MBR scan
19:52:26.954    Disk 0 Windows 7 default MBR code
19:52:26.970    Disk 0 Partition 1 00    1C Hidd FAT32 LBA MSDOS5.0    25600 MB offset 2048
19:52:26.986    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS      202291 MB offset 52430848
19:52:26.986    Disk 0 Partition - 00    0F Extended LBA            249048 MB offset 466722816
19:52:27.017    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      249047 MB offset 466724864
19:52:27.032    Disk 0 scanning C:\Windows\system32\drivers
19:52:40.027    Service scanning
19:53:06.157    Modules scanning
19:53:06.157    Disk 0 trace - called modules:
19:53:06.189    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
19:53:06.189    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80080e0790]
19:53:06.189    3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa8007e1dbf0]
19:53:06.189    5 ACPI.sys[fffff88000f917a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007e1c050]
19:53:07.203    AVAST engine scan C:\Windows
19:53:10.541    AVAST engine scan C:\Windows\system32
19:55:59.988    AVAST engine scan C:\Windows\system32\drivers
19:56:13.186    AVAST engine scan C:\Users\Asus
19:56:56.383    Disk 0 MBR has been saved successfully to "C:\Users\Asus\Desktop\MBR.dat"
19:56:56.398    The log file has been saved successfully to "C:\Users\Asus\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-20 19:58:10
-----------------------------
19:58:10.139    OS Version: Windows x64 6.1.7601 Service Pack 1
19:58:10.139    Number of processors: 8 586 0x2A07
19:58:10.139    ComputerName: ASUS-PC  UserName: Asus
19:58:11.481    Initialize success
19:58:15.053    AVAST engine defs: 12072000
19:58:20.685    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:58:20.685    Disk 0 Vendor: ST950032 0003 Size: 476940MB BusType: 3
19:58:20.685    Disk 1  \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2
19:58:20.685    Disk 1 Vendor: ST950032 0003 Size: 476940MB BusType: 3
19:58:20.731    Disk 0 MBR read successfully
19:58:20.747    Disk 0 MBR scan
19:58:20.747    Disk 0 Windows 7 default MBR code
19:58:20.763    Disk 0 Partition 1 00    1C Hidd FAT32 LBA MSDOS5.0    25600 MB offset 2048
19:58:20.778    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS      202291 MB offset 52430848
19:58:20.778    Disk 0 Partition - 00    0F Extended LBA            249048 MB offset 466722816
19:58:20.809    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      249047 MB offset 466724864
19:58:20.841    Disk 0 scanning C:\Windows\system32\drivers
19:58:34.834    Service scanning
19:59:01.167    Modules scanning
19:59:01.167    Disk 0 trace - called modules:
19:59:01.229    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
19:59:01.229    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80080e0790]
19:59:01.229    3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa8007e1dbf0]
19:59:01.229    5 ACPI.sys[fffff88000f917a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007e1c050]
19:59:02.352    AVAST engine scan C:\Windows
19:59:06.471    AVAST engine scan C:\Windows\system32
20:02:50.035    AVAST engine scan C:\Windows\system32\drivers
20:03:04.668    AVAST engine scan C:\Users\Asus
20:16:04.486    AVAST engine scan C:\ProgramData
20:18:11.485    Scan finished successfully
20:19:00.891    Disk 0 MBR has been saved successfully to "C:\Users\Asus\Desktop\MBR.dat"
20:19:00.891    The log file has been saved successfully to "C:\Users\Asus\Desktop\aswMBR.txt"

3 kurze Fragen am Rande: Wieviel kommt denn noch? So ca.? Hab mittlerweile 7 Antivirenprogramme, was fast soviel ist, wie ich normale Programme aufm PC hab ^^

Und noch ne Frage für neugierige: Wenn ich Text als Code Einfüge steht dann über der Codebox was von Larusso Mode. Was ist das?

Und als letztes: Kann ich meinen Rechner wieder normal nutzen? Oder solte ich noch vorsichtig sein, wegen eventuellen Resten von dem Trojaner???

Grüße und ein Dickes Danke für die Hilfe

Sebastian

So jetzt wird es richtig unlustig. Ich hatte mir ja einen 2. Benutzer erstellt. Der funktionierte die ganze Zeit fehlerlos.

Heute mache ich meinen PC an melde mich am 2. Benutzer an und zack PC ist durch den GVU Trojaner gesperrt. Ich dreh gleich durch.

Hoffe es war kein Fehler aber den Benutzer habe ich gelöscht.

Sebastian

cosinus 21.07.2012 15:35

Zitat:

Hab mittlerweile 7 Antivirenprogramme, was fast soviel ist, wie ich normale Programme aufm PC hab ^^

Das sind nicht alles AV-Programme! Außerdme stören die deinen installierten Virenscanner nicht!

Zitat:

Wenn ich Text als Code Einfüge steht dann über der Codebox was von Larusso Mode. Was ist das?
Klick doch einfach mal drauf!

Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

sebbi86 22.07.2012 05:32

Guten Morgen

Also der Reihe nach. Hab auf das Feld mit Larusso Modus gedrückt ... nix passiert ^^

Danach n Vollscan mit Malwarebytes

Code:

Malwarebytes Anti-Malware (Test) 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.07.21.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Asus :: ASUS-PC [Administrator]

Schutz: Aktiviert

21.07.2012 20:03:33
mbam-log-2012-07-21 (20-03-33).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 420921
Laufzeit: 1 Stunde(n), 23 Minute(n), 30 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

und dann einen mit SUPERAntiSpyware

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 07/22/2012 at 00:26 AM

Application Version : 5.5.1006

Core Rules Database Version : 8939
Trace Rules Database Version: 6751

Scan type      : Complete Scan
Total Scan Time : 02:51:31

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Administrator

Memory items scanned      : 716
Memory threats detected  : 0
Registry items scanned    : 70486
Registry threats detected : 0
File items scanned        : 209721
File threats detected    : 555

Adware.Tracking Cookie
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\asus@ad2.adfarm1.adition[1].txt [ /ad2.adfarm1.adition ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\asus@ad2.adfarm1.adition[3].txt [ /ad2.adfarm1.adition ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\asus@ad4.adfarm1.adition[2].txt [ /ad4.adfarm1.adition ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\asus@adx.chip[1].txt [ /adx.chip ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\asus@atdmt[2].txt [ /atdmt ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\asus@atwola[1].txt [ /atwola ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\asus@msnportal.112.2o7[1].txt [ /msnportal.112.2o7 ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\asus@sevenoneintermedia.112.2o7[1].txt [ /sevenoneintermedia.112.2o7 ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\asus@zbox.zanox[1].txt [ /zbox.zanox ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\BE92Y1RP.txt [ /www.zanox-affiliate.de ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\MC1NNCHT.txt [ /imrworldwide.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\TMOPRNUF.txt [ /ad.adserver01.de ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\L9P15RJQ.txt [ /eas.apm.emediate.eu ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\1XB4P3EE.txt [ /track.adform.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\E8I8TADG.txt [ /fastclick.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\EA127O43.txt [ /ad.ad-srv.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\XLH7WR2T.txt [ /tracking.quisma.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\TPIER6XF.txt [ /adtech.de ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\C1465JJL.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\V176WDU2.txt [ /adviva.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\SYTX7D0A.txt [ /doubleclick.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\3DBMIX9B.txt [ /unister-adservices.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\XAPTBOZI.txt [ /revsci.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\GU3FJGFK.txt [ /ad4.adfarm1.adition.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\JGUW525W.txt [ /adform.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\E259M06X.txt [ /webmasterplan.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\4UI41HYC.txt [ /questionmarket.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\QOSTSNFA.txt [ /ad3.adfarm1.adition.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\0QAFPFPW.txt [ /ad.adc-serv.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\LBNVO19W.txt [ /zanox-affiliate.de ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\MEF7484Q.txt [ /ads.creative-serving.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\XOKWSEQN.txt [ /server.adform.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\X2PEFSGM.txt [ /smartadserver.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\A1RNXLT2.txt [ /unitymedia.de ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\9MMITPC8.txt [ /ad.yieldmanager.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\VTC0G77V.txt [ /apmebf.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\JS2UKJR6.txt [ /tradedoubler.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\HUPY65IN.txt [ /serving-sys.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\DBQYTSUN.txt [ /server.adformdsp.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\2CNUNEKV.txt [ /atdmt.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\4MTKBDP4.txt [ /c.atdmt.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\ANDO99R9.txt [ /ad.dyntracker.de ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\OZZR07XH.txt [ /ad.360yield.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\5F4ZX7CH.txt [ /ad4.adfarm1.adition.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\6DD13KM2.txt [ /adformdsp.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\9NA8JRUB.txt [ /specificclick.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\V7GWG8TQ.txt [ /tracking.mindshare.de ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\04BMX4OY.txt [ /adfarm1.adition.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\R1BS9KD2.txt [ /bs.serving-sys.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\9I28DHPC.txt [ /ad1.adfarm1.adition.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\N52ODA0D.txt [ /content.yieldmanager.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\8ASAM7ZW.txt [ /adfarm1.adition.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\ZUBSO0LL.txt [ /zanox.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\66Y4VUGH.txt [ /ad.zanox.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\A0MLUA4C.txt [ /content.yieldmanager.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\ODQMG1AK.txt [ /eyewonder.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\BD9AKGGW.txt [ /www.traffective-tracking.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\OAUOGELF.txt [ /adserv.kwick.de ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\OMRIONY9.txt [ /mediaplex.com ]
        C:\USERS\ASUS\AppData\Roaming\Microsoft\Windows\Cookies\Low\asus@statcounter[3].txt [ Cookie:asus@statcounter.com/ ]
        C:\USERS\ASUS\AppData\Roaming\Microsoft\Windows\Cookies\Low\asus@ad.yieldmanager[1].txt [ Cookie:asus@ad.yieldmanager.com/ ]
        C:\USERS\ASUS\AppData\Roaming\Microsoft\Windows\Cookies\Low\4X3PNCG6.txt [ Cookie:asus@atdmt.com/ ]
        C:\USERS\ASUS\AppData\Roaming\Microsoft\Windows\Cookies\Low\asus@content.yieldmanager[2].txt [ Cookie:asus@content.yieldmanager.com/ ]
        C:\USERS\ASUS\Cookies\BE92Y1RP.txt [ Cookie:asus@www.zanox-affiliate.de/ ]
        C:\USERS\ASUS\Cookies\asus@atwola[1].txt [ Cookie:asus@atwola.com/ ]
        C:\USERS\ASUS\Cookies\L9P15RJQ.txt [ Cookie:asus@eas.apm.emediate.eu/ ]
        C:\USERS\ASUS\Cookies\1XB4P3EE.txt [ Cookie:asus@track.adform.net/ ]
        C:\USERS\ASUS\Cookies\XLH7WR2T.txt [ Cookie:asus@tracking.quisma.com/ ]
        C:\USERS\ASUS\Cookies\TPIER6XF.txt [ Cookie:asus@adtech.de/ ]
        C:\USERS\ASUS\Cookies\C1465JJL.txt [ Cookie:asus@ad2.adfarm1.adition.com/ ]
        C:\USERS\ASUS\Cookies\asus@sevenoneintermedia.112.2o7[1].txt [ Cookie:asus@sevenoneintermedia.112.2o7.net/ ]
        C:\USERS\ASUS\Cookies\SYTX7D0A.txt [ Cookie:asus@doubleclick.net/ ]
        C:\USERS\ASUS\Cookies\3DBMIX9B.txt [ Cookie:asus@unister-adservices.com/ ]
        C:\USERS\ASUS\Cookies\GU3FJGFK.txt [ Cookie:asus@ad4.adfarm1.adition.com/ ]
        C:\USERS\ASUS\Cookies\JGUW525W.txt [ Cookie:asus@adform.net/ ]
        C:\USERS\ASUS\Cookies\E259M06X.txt [ Cookie:asus@webmasterplan.com/ ]
        C:\USERS\ASUS\Cookies\4UI41HYC.txt [ Cookie:asus@questionmarket.com/ ]
        C:\USERS\ASUS\Cookies\QOSTSNFA.txt [ Cookie:asus@ad3.adfarm1.adition.com/ ]
        C:\USERS\ASUS\Cookies\asus@adx.chip[1].txt [ Cookie:asus@adx.chip.de/ ]
        C:\USERS\ASUS\Cookies\LBNVO19W.txt [ Cookie:asus@zanox-affiliate.de/ ]
        C:\USERS\ASUS\Cookies\XOKWSEQN.txt [ Cookie:asus@server.adform.net/ ]
        C:\USERS\ASUS\Cookies\A1RNXLT2.txt [ Cookie:asus@unitymedia.de/ ]
        C:\USERS\ASUS\Cookies\9MMITPC8.txt [ Cookie:asus@ad.yieldmanager.com/ ]
        C:\USERS\ASUS\Cookies\DBQYTSUN.txt [ Cookie:asus@server.adformdsp.net/ ]
        C:\USERS\ASUS\Cookies\2CNUNEKV.txt [ Cookie:asus@atdmt.com/ ]
        C:\USERS\ASUS\Cookies\4MTKBDP4.txt [ Cookie:asus@c.atdmt.com/ ]
        C:\USERS\ASUS\Cookies\ANDO99R9.txt [ Cookie:asus@ad.dyntracker.de/ ]
        C:\USERS\ASUS\Cookies\6DD13KM2.txt [ Cookie:asus@adformdsp.net/ ]
        C:\USERS\ASUS\Cookies\V7GWG8TQ.txt [ Cookie:asus@tracking.mindshare.de/ ]
        C:\USERS\ASUS\Cookies\04BMX4OY.txt [ Cookie:asus@adfarm1.adition.com/ ]
        C:\USERS\ASUS\Cookies\R1BS9KD2.txt [ Cookie:asus@bs.serving-sys.com/ ]
        C:\USERS\ASUS\Cookies\9I28DHPC.txt [ Cookie:asus@ad1.adfarm1.adition.com/ ]
        C:\USERS\ASUS\Cookies\N52ODA0D.txt [ Cookie:asus@content.yieldmanager.com/ ]
        C:\USERS\ASUS\Cookies\8ASAM7ZW.txt [ Cookie:asus@adfarm1.adition.com/ ]
        C:\USERS\ASUS\Cookies\ZUBSO0LL.txt [ Cookie:asus@zanox.com/ ]
        C:\USERS\ASUS\Cookies\OAUOGELF.txt [ Cookie:asus@adserv.kwick.de/ ]
        C:\USERS\ASUS\Cookies\OMRIONY9.txt [ Cookie:asus@mediaplex.com/ ]
        statse.webtrendslive.com [ C:\USERS\ALTERNATIVE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2GOCDVLE.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ALTERNATIVE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2GOCDVLE.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ALTERNATIVE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2GOCDVLE.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ALTERNATIVE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2GOCDVLE.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ALTERNATIVE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2GOCDVLE.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ALTERNATIVE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2GOCDVLE.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ALTERNATIVE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2GOCDVLE.DEFAULT\COOKIES.SQLITE ]
        cdn2.themis-media.com [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        de.partypoker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        delivery.ibanner.de [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        ia.media-imdb.com [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        imagesrv.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        macromedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        media.adxpansion.com [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        media.mtvnservices.com [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        media.noob.us [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        media.trafficfactory.biz [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        objects.tremormedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        s0.2mdn.net [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        secure-us.imrworldwide.com [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        stat.easydate.biz [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        stat.ed.cupidplc.com [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        stat.upforitnetworks.com [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        www.ardmediathek.de [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        www.partypoker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        C:\USERS\ASUS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ASUS@CONTENT.YIELDMANAGER[3].TXT [ /CONTENT.YIELDMANAGER ]
        C:\USERS\ASUS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ASUS@AD.YIELDMANAGER[2].TXT [ /AD.YIELDMANAGER ]
        C:\USERS\ASUS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ASUS@CONTENT.YIELDMANAGER[4].TXT [ /CONTENT.YIELDMANAGER ]
        C:\USERS\ASUS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ASUS@ATDMT[2].TXT [ /ATDMT ]
        C:\USERS\ASUS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ASUS@MICROSOFTWLSEARCHCRM.112.2O7[1].TXT [ /MICROSOFTWLSEARCHCRM.112.2O7 ]
        C:\USERS\ASUS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ASUS@MSNPORTAL.112.2O7[1].TXT [ /MSNPORTAL.112.2O7 ]
        C:\USERS\ASUS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ASUS@STATCOUNTER[1].TXT [ /STATCOUNTER ]
        .im.banner.t-online.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .server.cpmstar.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ibanner.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .googleads.g.doubleclick.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revenuemax.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .gostats.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tto2.traffictrack.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        7.rotator.wigetmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad3.adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ww251.smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .lego.112.2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .bwincom.122.2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .realmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .sexkontakt.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .sexkontakt.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .uk.at.atwola.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .xm.xtendmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .imagesrv.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .schnurstracks-kletterparks.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .schnurstracks-kletterparks.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        tracker.bmtsystem.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ads2.fettspielen.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        tracking.affiliates.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        tracking.affiliates.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .realmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .aka-cdn-ns.adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .animetoplist.org [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .www.animetoplist.org [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .game-advertising-online.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adserver.adtechus.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        tracking.dc-storm.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tto2.traffictrack.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .msnbc.112.2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ar.atwola.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        adserver1.mokono.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        fidelity.rotator.hadj7.adjuggler.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        fidelity.rotator.hadj7.adjuggler.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track2.httptrack.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track71.solocpm.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track71.solocpm.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track2.httptrack.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track71.solocpm.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track2.httptrack.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track1.httptrack.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .freshnewtracks.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .burstnet.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .burstnet.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .freshnewtracks.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .freshnewtracks.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        server.adformdsp.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adformdsp.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad.velmedia.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad.velmedia.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .velmedia.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        stat.easydate.biz [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        stat.ed.cupidplc.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.youporn.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        dm3adserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adnetwork.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .harrenmedianetwork.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        stats.bmw.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ads.trafficjunky.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .sexad.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .de.partypoker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .pornofilmpjes.nl [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .pornofilmpjes.nl [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .advertisingenhanced.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .advertisingenhanced.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .maximumfindings.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .maximumfindings.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .cpvadverts.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .cpvadverts.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ads1.zenoviaexchange.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        7.rotator.wigetmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        delivery.atkmedia.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .burstnet.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .kontera.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.usenext.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracker.vinsight.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        tomtailor.dyntracker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        yourxxxdate.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-Frauder
        C:\PROGRAM FILES (X86)\1&1 SURF-STICK\COMPONENT\BIUSBSOUND.DLL

Ich muss sagen, ich finde es doch recht ittitierend, dass Malwarebytes keinen Fund meldet SASW dafür 555!!! Bin ja fast aus den Latschen gekippt:-( Und nun?

Schönen Sonntag

Sebastian

cosinus 23.07.2012 14:23

Zitat:

Hab auf das Feld mit Larusso Modus gedrückt ... nix passiert ^^
Dann bist du ein schlechter Beobachter! :pfeiff:
Probier es mal mit der CODE-Box in der das Log von SASW ist aus


Zitat:

Bin ja fast aus den Latschen gekippt:-( Und nun?
Das kommt weil du leicht hysterisch bist - man sollte schon mal lesen WAS GENAU von SASW gefunden wurde, das waren nämlich nur Cookies und ein Fehlalarm war dabei!

Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

sebbi86 23.07.2012 20:25

Nabend.

Bin kein schlechter Beobachter. Dachte ich zumindest immer... Naja egal ich habs mal ausprobiert. Da passiert in der Tat bei mir gar nichts. Null Nada. Das sieht nachm Button drücken genauso aus wie vorm Button drücken.

Und leicht hysterisch bin ich auch nicht. Das mit den aus den Latschen gekippt war etwas übertrieben formuliert ... Der Witz kam wohl nicht so ganz an ... Das das Cookies waren hab ich gesehn. Der Fehlalarm entging mir aber in der Tat.

Ob mein System wieder in Ordnung ist ... Ehrlich ich hab keine Ahnung. Andere Funde gabs nicht. Habe alle Logs was so war gepostet.
Was mir halt Sorgen macht, ist die Tatsache, dass der GVU Trojaner auf meinem Alternativen Benutzer aufgetaucht ist.
Aber ansonsten ist an sich alles in Ordnung glaub ich.

Sebastian

cosinus 24.07.2012 15:23

Wenn du auf Larusso Modus klcikst wird die CODE-Box komplett ausgerollt bzw. komplett angezeigt, man muss dann nicht mehr innerhalb der CODE-Box scrollen
Warum das bei dir nicht geht weiß ich nicht. Verwendest du den IE? Mit dem geht das nicht


Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

sebbi86 24.07.2012 20:38

Ok

Na dann bedank ich mich mal ganz artig und fleißig für die Hilfe.

Ich hoffe ich muss mich nicht so bald wieder bei euch melden ^^

In diesem Sinne wünsche ich noch ein frohes schaffen

Vielen Dank nochmal

Sebastian

sebbi86 03.08.2012 20:11

Heyho.

Ich bins mal wieder.

Er ist wieder da :-( Der tolle tolle GVU Trojaner. Und ich habe keine Ahnung wieso. Ich habe mcih auf keinen komsichen, verdächtigen oder halblegalen Seiten rumgetrieben. Zumindest solang GMX und Youtube als legal gelten.

Und nu? Wieder alles von vorn? Oder bringt es was einfach alle für mich wichtigen Daten auf ne Externe Festplatte zu ziehen und dann den Rechner platt zu machen und windows neu zu installieren? Oder zieh ich den Trojaner dann nur mit zur auf die Externe?

Liebe grüße von einem grad sehr genervten :headbang:

Sebastian

cosinus 03.08.2012 21:04

Das kommt davon, wenn man meine letzten Hinweise bzgl. der Updates nicht umsetzt :pfeiff:

sebbi86 03.08.2012 21:19

Updates hatte ich alle gemacht. Also vor kp 2 Wochen oder so, wo ich noch dachte ich wäre das problem los....

Aber der Hinweis auf die Updates hilft mir grad nicht wirklich weiter :(

Hab grad versucht Windows über den Windowsunlocker freizuschalten. Windowsunlocker ausgeführt ... Windows immernoch gesperrt :(

Sorry das sollt jetzt nicht böse klingen, ich bin nur grad etwas durch den Wid, weil mich dieses Problem das letzte mal schon 2 Wochen gekostet hat und ich mich nicht schon wieder damit rumschlagen wollt.

Hoffe auf erneute Hilfe ...

cosinus 03.08.2012 21:57

Funktioniert noch der abgesicherte Modus mit Netzwerktreibern? Mit Internetverbindung?



Abgesicherter Modus zur Bereinigung
  • Windows mit F8-Taste beim Start in den abgesicherten Modus bringen.
  • Starte den Rechner in den abgesicherten Modus mit Netzwerktreibern:

    Windows im abgesicherten Modusstarten

sebbi86 03.08.2012 22:16

Japs geht und Internetverbindung ist auch da.

sebbi86 04.08.2012 11:27

Heyho und einen schönen Samstag.

Also gestern hab ich meinen PC im abgesicherten Modus gestartet und dann Malewarebytes durchlaufen lassen.

Hier das Log:

Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.08.03.09

Windows 7 Service Pack 1 x64 NTFS (Abgesichertenmodus/Netzwerkfähig)
Internet Explorer 9.0.8112.16421
Asus :: ASUS-PC [Administrator]

03.08.2012 23:20:33
mbam-log-2012-08-03 (23-20-33).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 447522
Laufzeit: 1 Stunde(n), 10 Minute(n), 13 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\Asus\AppData\Local\Temp\deo0_sar.exe (Trojan.Inject) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk (Trojan.Ransom.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Die beiden Funde hab ich in Quarantäne geschoben. Danach lies sich mein PC wieder normal starten.

Hab schonmal nen Scan mit OTL und SASW gemacht. Hier die Logs

Code:

OTL Extras logfile created on: 04.08.2012 09:16:16 - Run 4
OTL by OldTimer - Version 3.2.43.0    Folder = C:\Users\Asus\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7,91 Gb Total Physical Memory | 6,10 Gb Available Physical Memory | 77,14% Memory free
15,82 Gb Paging File | 13,77 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 197,55 Gb Total Space | 11,72 Gb Free Space | 5,93% Space Free | Partition Type: NTFS
Drive D: | 243,21 Gb Total Space | 178,00 Gb Free Space | 73,19% Space Free | Partition Type: NTFS
Drive E: | 232,88 Gb Total Space | 106,35 Gb Free Space | 45,67% Space Free | Partition Type: NTFS
Drive F: | 232,87 Gb Total Space | 9,86 Gb Free Space | 4,24% Space Free | Partition Type: NTFS
Drive G: | 264,60 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
 
Computer Name: ASUS-PC | User Name: Asus | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-1516755417-3234397197-3308580895-1001\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{17B8F551-47E0-443D-BE2B-E29486BC146A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1DEF9043-1413-470B-B7AC-463B9A6D6772}" = lport=8182 | protocol=6 | dir=in | name=java(tm) platform se binary |
"{2CF6BD61-749F-4B6A-BDA8-6AD746903ABC}" = rport=10243 | protocol=6 | dir=out | app=system |
"{3126D077-E228-4019-A0B5-0844089AD590}" = rport=445 | protocol=6 | dir=out | app=system |
"{3B2D6E27-6F8A-47D0-8F73-7AA9B9DB2770}" = lport=5353 | protocol=17 | dir=in | name=java(tm) platform se binary |
"{3BEB78F3-8A24-41CF-87AA-D76E13FF0F51}" = lport=137 | protocol=17 | dir=in | app=system |
"{3E5B0FCA-BD4E-4711-8D51-FB3C8D19481D}" = rport=139 | protocol=6 | dir=out | app=system |
"{488CDB0B-A8B6-4B86-B8AA-EF7C5A308FAF}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{53158159-126F-443C-8507-1D4526A6A587}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{53180F5C-0C4B-4E0E-BA73-95775C99EB75}" = lport=10243 | protocol=6 | dir=in | app=system |
"{5B579CF9-667A-421B-B53C-D57EADA7FB62}" = rport=137 | protocol=17 | dir=out | app=system |
"{6AA40B18-67E7-4887-A191-52F8BBA81A2D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{74219546-678A-4219-980D-C33F7FF697D0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7BBF9904-4DC5-4DD0-834D-3F71D7EF2622}" = lport=445 | protocol=6 | dir=in | app=system |
"{89CBDDD0-E5B3-4AD4-A7B0-3BFB0063617F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9447EBDE-7FAD-4170-9682-497FEA4B408B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AED689EE-641F-4972-9C6C-DE63AAC0712F}" = lport=138 | protocol=17 | dir=in | app=system |
"{B0152C9A-1334-4CAE-A565-F2F83B2ED375}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BD8C43CE-F7ED-429A-AD04-A12AB55F7115}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{CBD581CD-B72A-4E61-8C31-B704298B3338}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D1D07AF9-6712-40F8-B80D-97AA20AE62B1}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DA78110C-2370-4EB5-9B93-16E4CC27C9EF}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{E9DC8B33-D38B-4A37-80A8-9ED33EE7C43F}" = rport=138 | protocol=17 | dir=out | app=system |
"{F278788E-048A-4BC6-AA22-CBFC9D864B5C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FE903E68-B57A-4381-BB1D-A4B950EE6CEF}" = lport=139 | protocol=6 | dir=in | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0379AD61-8E1C-4FFF-9CD5-0C563D11402A}" = protocol=17 | dir=in | app=d:\assassin's creed brotherhood\assassinscreedbrotherhood.exe |
"{04E5672F-B534-4EC6-AA71-EA3C46D3EF2B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{054A606D-D33A-4EF6-8D58-ECAC6D8EAD45}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{06A79AA5-6836-44AA-B664-DCE38331919F}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.5\icq.exe |
"{07DC65B2-52D7-4D31-8213-5D5FA14E2DBB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0C8FA460-9466-4B17-BDB7-5CCC97C4FFC1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0F32252D-4502-4417-8A54-130BA488181B}" = protocol=17 | dir=in | app=d:\assassin's creed revelations\acrmp.exe |
"{198E6E9B-51AD-46E0-8DCA-13DD254FCCAD}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.5\icq.exe |
"{1A48A96B-0BD1-46AD-B449-578538F5993A}" = protocol=6 | dir=in | app=d:\assassin's creed ii\uplaybrowser.exe |
"{1A4FB1E8-9522-480F-9DAD-1AC07B3306E1}" = protocol=6 | dir=in | app=d:\assassin's creed ii\assassinscreediigame.exe |
"{1FCF67DA-CBFB-465D-8F86-9B7F46BC0240}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{233F600F-9754-4928-906A-5CEC918E3FDF}" = protocol=17 | dir=in | app=d:\assassin's creed brotherhood\acbsp.exe |
"{252ADC24-4DBF-4104-B2D0-26A93C025B66}" = dir=in | app=c:\program files (x86)\intel corporation\intel wireless display\widiapp.exe |
"{253BA3A2-92F6-41C0-8408-390D6F794341}" = protocol=17 | dir=in | app=d:\assassin's creed ii\assassinscreediigame.exe |
"{26396AA0-7D9D-4F1A-893B-E8B7C48A9902}" = protocol=6 | dir=out | app=system |
"{272A0DE5-9288-42A7-88CF-50F5C39AB4C0}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.5\icq.exe |
"{28FD06AB-C6D9-410E-B2EC-0A295470D980}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{31974063-77B9-4C54-8B89-2B9BC003FDAF}" = protocol=6 | dir=in | app=d:\assassin's creed revelations\acrsp.exe |
"{3279E1D4-C002-48E0-AC00-F2A5EA6690ED}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{341B9122-813C-40FA-8446-364B86FB4E24}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{3731FD58-7E91-4F75-8284-C4FD62B4D303}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{395D98A9-B6BE-440B-8D3E-3F992AB4E2A8}" = dir=in | app=c:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe |
"{3E188D29-2EA2-47E3-B69E-92ADA85BB5F8}" = protocol=17 | dir=in | app=d:\diablo iii\diablo iii.exe |
"{40C2AF6C-7AC2-4145-B381-B2342BA88C08}" = protocol=17 | dir=in | app=d:\assassin's creed brotherhood\acbmp.exe |
"{465423EC-0915-46CA-BA76-A9FC64226E5C}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{46E3AA93-7D0E-49AD-8F08-A8E2046B85C8}" = protocol=17 | dir=in | app=d:\assassin's creed brotherhood\uplaybrowser.exe |
"{4A9FE5E1-83E4-4864-A60D-15F8E758E9F2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4BF7E80A-7CBD-42BC-9772-94EAEA2D0D21}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{4E4A3146-BA94-4330-AD37-7D72A61B9F29}" = protocol=6 | dir=in | app=d:\diablo iii\diablo iii.exe |
"{50386D42-3D7B-426E-8D96-32B5B7357D59}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{50399C0B-C5DE-4797-A215-72168E30B878}" = protocol=17 | dir=in | app=d:\fable iii\fable3.exe |
"{522EA85C-6A30-4AA6-A2BC-09E2B36AF9FE}" = protocol=17 | dir=in | app=d:\assassin's creed revelations\acrsp.exe |
"{5345F2F6-1E95-470E-883C-D25315BE7F08}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{54AFFC1B-98D1-412E-BF8F-90CF5CEB04B3}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe |
"{56ED5951-F73B-45CD-8CBB-9738365B528D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{56F35561-C31B-4E7D-AE92-BA106AA365E6}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{61F10157-F916-4C7C-8E5C-FAF2792F5D6D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{69474C04-4B7A-45DC-9A66-4B188FAF2665}" = protocol=6 | dir=in | app=d:\assassin's creed revelations\assassinscreedrevelations.exe |
"{6A314C11-4A5F-410A-95E1-A1D0969B8B6C}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.5\icq.exe |
"{6CC7E53E-24A4-439A-B8E0-BEEAC7290091}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{7C2488E2-23F3-4C36-80BC-D23DA3831257}" = protocol=6 | dir=in | app=d:\assassin's creed brotherhood\acbsp.exe |
"{80ED44D7-346B-44E9-AC84-084CD6E35F04}" = dir=in | app=c:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe |
"{81EC2676-9772-45DE-97D5-1CB1121D7DD9}" = protocol=6 | dir=in | app=d:\assassin's creed brotherhood\assassinscreedbrotherhood.exe |
"{8554D5F3-9027-4BD3-9F05-BAB093F00B15}" = protocol=6 | dir=in | app=d:\fable iii\fable3.exe |
"{8F21EB87-E1A2-40D4-892E-37AF71E0BE08}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{9122EC28-5B98-404B-8EF8-C7342E2BAED1}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{96A4465B-F9DB-477D-B863-9AE3E3EBE31E}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{977E681B-11E6-45C9-994F-7A4DA16CFE2A}" = protocol=6 | dir=in | app=d:\starcraft ii demo\starcraft ii.exe |
"{A3BDDEA1-243C-42A4-A1FA-5C43F70B1A7B}" = dir=in | app=c:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe |
"{A3F0A925-EBE9-47F8-B1D5-1E6CF048397D}" = protocol=17 | dir=in | app=d:\starcraft ii demo\starcraft ii.exe |
"{A7D79D5C-33BD-4E20-A9F7-8F25FC3DF72D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A8135997-DCC3-48F4-B4DE-C56F9224DC6F}" = dir=in | app=c:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe |
"{B0B97529-8D13-4F0F-8D32-BFC489951D68}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B6CE2B8A-3326-4CC7-A7B0-A840B904C03F}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{B7C4D6EC-7F95-42A8-910A-7C9967E62016}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BDB49A91-3AAC-4209-ACDC-33D008B19B85}" = protocol=6 | dir=in | app=d:\assassin's creed revelations\acrmp.exe |
"{BE3AAA80-F927-41DE-93A3-C4A40828B207}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr8.exe |
"{C1D62477-5511-4C71-8185-337F9AE00FAF}" = dir=in | app=c:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe |
"{C23F05DF-03B5-4F6F-A743-1BDE8FC7DAE8}" = protocol=6 | dir=in | app=d:\assassin's creed ii\assassinscreedii.exe |
"{C53DA91D-993C-4EC1-9432-52EB53F311CB}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{C6FFABCF-BA4A-4CE8-8EE3-BE8ED8961337}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{CD217599-5A7B-4A26-9209-B8EDB8E38774}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{CDA39641-F8FC-45F1-9BD0-CFD90E471BA6}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{D69957CA-9E73-44E3-95ED-EC137451A8A3}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe |
"{D81FBDAA-5621-4D87-9573-4B61F3382CA0}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{DA1BDA07-9BD4-4756-B96E-1643C2C9DD9F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{DA75C297-3D86-4729-9C3F-84C0B1672577}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{E0F1C9D9-5FE9-4B29-8C4E-C9D37D56F9CF}" = protocol=17 | dir=in | app=d:\assassin's creed ii\uplaybrowser.exe |
"{E46C0430-8C28-4964-8579-F0159AF9467B}" = protocol=6 | dir=in | app=d:\assassin's creed brotherhood\acbmp.exe |
"{E85E15D8-B847-421F-8904-6ABEC085DE37}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{E976661D-2092-4ECD-B348-6C3FA540178F}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{EBD8B9BE-6D84-4BAB-A0A0-DA11A4A0AE10}" = protocol=6 | dir=in | app=d:\assassin's creed brotherhood\uplaybrowser.exe |
"{EC0D8580-514B-4B05-B71C-941FA9DBC193}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EC2374AD-8C5C-4658-A475-CD1B69271FFB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F1567D35-DD4F-474D-A667-A57F699AE196}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F520D087-5F7A-47D8-BE1C-6B2565F57DA2}" = protocol=17 | dir=in | app=d:\assassin's creed ii\assassinscreedii.exe |
"{F9A2083E-C00A-48AA-B7A5-DD714EC889E6}" = protocol=17 | dir=in | app=d:\assassin's creed revelations\assassinscreedrevelations.exe |
"{FDE82DAA-AA0A-41AC-86B2-D3873A0B87EA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{0AE1C895-7BA6-4CA0-9CEF-3D24D6D25F9C}C:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=6 | dir=in | app=c:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe |
"TCP Query User{69186C7C-5A3C-4CEC-9F55-6FFF12CE6072}D:\diablo iii\diablo iii.exe" = protocol=6 | dir=in | app=d:\diablo iii\diablo iii.exe |
"TCP Query User{81895A06-D88B-48A0-A240-C6A783B322E6}D:\assassin's creed revelations\acrsp.exe" = protocol=6 | dir=in | app=d:\assassin's creed revelations\acrsp.exe |
"TCP Query User{A32E2EC3-D8A4-4609-8C94-D818F637852C}C:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe" = protocol=6 | dir=in | app=c:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe |
"TCP Query User{AA098231-DA2C-4E37-B6DC-60054AE8435C}C:\program files (x86)\icq7.5\icq.exe" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.5\icq.exe |
"TCP Query User{C0DFE0A6-121B-4489-88CC-4F2AF394CCCF}C:\programdata\battle.net\agent\agent.976\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"TCP Query User{C4FB9AF4-026D-49BD-9F85-8DB12CC85C18}D:\assassin's creed brotherhood\acbsp.exe" = protocol=6 | dir=in | app=d:\assassin's creed brotherhood\acbsp.exe |
"TCP Query User{CC48BEAB-63B2-404C-AE59-5EEC1674FEA1}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"TCP Query User{D214F69B-F15E-4B71-89F3-95F95B9761DF}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"UDP Query User{0940D473-3645-4D06-868C-69C4BDA799F9}D:\assassin's creed brotherhood\acbsp.exe" = protocol=17 | dir=in | app=d:\assassin's creed brotherhood\acbsp.exe |
"UDP Query User{32EE7F1D-2DFE-4F55-9C56-AB3A463641CE}C:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=17 | dir=in | app=c:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe |
"UDP Query User{4DF10DB3-E334-4107-8D94-03EB7F8FE862}C:\program files (x86)\icq7.5\icq.exe" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.5\icq.exe |
"UDP Query User{95FC289C-9E2F-4E92-8868-CCA34892A972}D:\diablo iii\diablo iii.exe" = protocol=17 | dir=in | app=d:\diablo iii\diablo iii.exe |
"UDP Query User{9B3DB6F1-B342-4884-BF52-4DA951D5F168}C:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe" = protocol=17 | dir=in | app=c:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe |
"UDP Query User{A42D90BD-B60F-4C95-9AE6-DFE5BA0F833E}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"UDP Query User{B0A8E2F6-7A06-495B-8AC4-44AEDD1C25A2}D:\assassin's creed revelations\acrsp.exe" = protocol=17 | dir=in | app=d:\assassin's creed revelations\acrsp.exe |
"UDP Query User{DB242BBF-06BE-42EF-997B-9F7312E31A32}C:\programdata\battle.net\agent\agent.976\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"UDP Query User{F6F943EF-4501-4782-8320-5B06EB2032D4}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0919C44F-F18A-4E3B-A737-03685272CE72}" = Windows Live Remote Service Resources
"{13F4A7F3-EABC-4261-AF6B-1317777F0755}" = Fast Boot
"{169C77B7-69C9-4648-9DD0-72B152AF269F}" = Windows Live Family Safety
"{19F09425-3C20-4730-9E2A-FC2E17C9F362}" = Windows Live Remote Service Resources
"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1C55470A-7C9E-4C63-B466-6AFFC69E94E9}" = Windows Live Family Safety
"{1EB2CFC3-E1C5-4FC4-B1F8-549DD6242C67}" = Windows Live Remote Service Resources
"{26211D4B-CD06-44C8-BA6E-F937E1692629}" = Fresco Logic USB3.0 Host Controller
"{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java(TM) 7 Update 5 (64-bit)
"{289809B1-078A-49F3-83D0-7E51715B3915}" = Windows Live Family Safety
"{3946328A-5B3A-434C-A22B-64CF6652FBAD}" = Windows Live Family Safety
"{401C50F6-B443-43EE-8F27-A80DB19B03FD}" = Windows Live Family Safety
"{4327107B-E95E-415C-9194-458FCED6BF12}" = Intel(R) PROSet/Wireless WiFi Software
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{5FEAD3E5-A158-4B66-B92B-0C959D7CF838}" = Windows Live Remote Service Resources
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{680EDA59-9266-44B4-949E-0C24F65DFF82}" = Microsoft_VC100_CRT_SP1_x64
"{692CCE55-9EAE-4F57-A834-092882E7FE0B}" = Windows Live Remote Client Resources
"{6CBFDC3C-CF21-4C02-A6DC-A5A2707FAF55}" = Windows Live Remote Service Resources
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{825C7D3F-D0B3-49D5-A42B-CBB0FBE85E99}" = Windows Live Remote Client Resources
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8970AE69-40BE-4058-9916-0ACB1B974A3D}" = Windows Live Remote Client Resources
"{8EB588BD-D398-40D0-ADF7-BE1CEEF7C116}" = Windows Live Remote Client Resources
"{9210D7A2-DC28-43F6-92F9-E6CD4C729F7B}" = Windows Live Family Safety
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}" = ASUS Power4Gear Hybrid
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1" = PDF-Viewer
"{A679FBE4-BA2D-4514-8834-030982C8B31A}" = Windows Live Remote Service Resources
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B0BF8602-EA52-4B0A-A2BD-EDABB0977030}" = Windows Live Remote Client Resources
"{B22C8566-D522-4B40-A7AF-525F5A70D832}" = Windows Live Family Safety
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 265.96
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 265.96
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.0.9
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources
"{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}" = Überwachungstool für die Intel® Turbo-Boost-Technik 2.0
"{C298FF86-AB23-4B58-AC53-A23383C07B3A}" = Intel(R) Wireless Display
"{C9F05151-95A9-4B9B-B534-1760E2D014A5}" = Windows Live Remote Client Resources
"{CB7935EF-43EE-4C0F-AC02-B0E4DD5DAC17}" = Windows Live Family Safety
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DBEDAF67-C5A3-4C91-951D-31F3FE63AF3F}" = Windows Live Remote Client Resources
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FAA3933C-6F0D-4350-B66B-9D7F7031343E}" = Windows Live Remote Service Resources
"{FE4BE0BD-1EDB-4D24-9614-847B3C472887}" = Windows Live Family Safety
"0E74EB10C05C955C24243E6D3120CDC972FC5B1D" = Windows Driver Package - Broadcom HIDClass  (06/11/2009 6.2.0.9500)
"2AA10AB519DC7432D599A0E860206A7DDCC27764" = Windows Driver Package - Broadcom Bluetooth  (07/29/2009 6.1.7100.0)
"Elantech" = ETDWare PS/2-x64 7.0.5.15_WHQL
"F9FD5BBF579A4BFD40D38BE291F731666B27DC28" = Windows Driver Package - Broadcom Bluetooth  (07/17/2009 6.2.0.9403)
"FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D" = Windows-Treiberpaket - Nokia pccsmcfd  (08/22/2008 7.0.0.0)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"ProInst" = Intel PROSet Wireless
"USB2.0 UVC 2M WebCam" = USB2.0 UVC 2M WebCam
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{04668DF2-D32F-4555-9C7E-35523DCD6544}" = Control ActiveX de Windows Live Mesh para conexiones remotas
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
"{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}" = SonicMaster
"{09F56A49-A7B1-4AAB-95B9-D13094254AD1}" = Windows Live UX Platform Language Pack
"{0A9256E0-C924-46DE-921B-F6C4548A1C64}" = Windows Live Messenger
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0BE5C4DB-8EA2-483D-BD71-D7EB09040CDE}" = Windows Live UX Platform Language Pack
"{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail
"{0EC0B576-90F9-43C3-8FAD-A4902DF4B8F4}" = Galeria de Fotografias do Windows Live
"{13FAE3E3-283E-4BF4-8FE5-17D256EDDD77}" = Windows Live UX Platform Language Pack
"{14B441B7-774D-4170-98EA-A13667AE6218}" = Windows Live Writer Resources
"{17F99FCE-8F03-4439-860A-25C5A5434E18}" = Windows Live Essentials
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{198EA334-8A3F-4CB2-9D61-6C10B8168A6F}" = Windows Live Writer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1F7424F8-F992-48BC-90EF-7C4DB0405E3F}" = Alcor Micro USB Card Reader
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = ASUS Video Magic
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}" = Wireless Console 3
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2511AAD7-82DF-4B97-B0B3-E1B933317010}" = Windows Live Writer Resources
"{25A381E1-0AB9-4E7A-ACCE-BA49D519CF4E}" = Windows Live Mail
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{29373E24-AC72-424E-8F2A-FB0F9436F21F}" = Windows Live Photo Common
"{2A07C35B-8384-4DA4-9A95-442B6C89A073}" = Windows Live Essentials
"{2AD2DD70-27F7-4343-BB4E-DE50A32D854B}" = Windows Live Messenger
"{2B81872B-A054-48DA-BE3B-FA5C164C303A}" = ASUS FancyStart
"{2C865FB0-051E-4D22-AC62-428E035AEAF0}" = Windows Live Mesh
"{32C01DD0-3260-4D2B-BDB2-36CEC3E5B27A}" = Windows Live UX Platform Language Pack
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33A22B2D-55BA-4508-B767-BF2E9C21A73F}" = Assassin's Creed Revelations 1.03
"{341697D8-9923-445E-B42A-529E5A99CB7A}" = syncables desktop SE
"{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{36B0DC39-3282-40EB-8587-B875CE46C3A7}" = ExpressGateCloud
"{370F888E-42A7-4911-9E34-7D74632E17EB}" = Windows Live Photo Common
"{38253529-D97D-4901-AE53-5CC9736D3A2E}" = ASUS AI Recovery
"{3A09ED0F-8DDF-47BB-B53D-841AB9D1D3A7}" = Complemento Messenger
"{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer
"{3D0C22FA-96D7-4789-BC5B-991A5A99BFFA}" = Windows Live Messenger
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{3F4143A1-9C21-4011-8679-3BC1014C6886}" = Windows Live Mesh
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{4412F224-3849-4461-A3E9-DEEF8D252790}" = Visual Studio C++ 10.0 Runtime
"{46872828-6453-4138-BE1C-CE35FBF67978}" = Windows Live Mesh
"{46EDCFA5-7EDB-46A9-B093-1C6237470CEC}" = 3DMark 11
"{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live
"{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer
"{4A275FD1-2F24-4274-8C01-813F5AD1A92D}" = Windows Live Messenger
"{4AA68A73-DB9C-439D-9481-981C82BD008B}" = Nokia Connectivity Cable Driver
"{4B28D47A-5FF0-45F8-8745-11DC2A1C9D0F}" = Windows Live Writer
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4D53090A-9B45-437B-A66A-831000008300}" = Fable III
"{4D53090A-CE35-42BD-B377-831000028301}" = Fable III
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{55D003F4-9599-44BF-BA9E-95D060730DD3}" = Contrôle ActiveX Windows Live Mesh pour connexions à distance
"{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker
"{5F6E678A-7E61-448A-86CB-BC2AD1E04138}" = Windows Live Messenger
"{6057E21C-ABE9-4059-AE3E-3BEB9925E660}" = Windows Live Messenger
"{622DE1BE-9EDE-49D3-B349-29D64760342A}" = 適用遠端連線的 Windows Live Mesh ActiveX 控制項
"{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources
"{63AE67AA-1AB1-4565-B4EF-ABBC5C841E8D}" = Windows Live Messenger
"{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon
"{66D6F3BD-CA23-41A4-9FA3-96B26B32528D}" = Command & Conquer Die ersten 10 Jahre
"{677AAD91-1790-4FC5-B285-0E6A9D65F7DC}" = Windows Live Mail
"{6807427D-8D68-4D30-AF5B-0B38F8F948C8}" = Windows Live Writer Resources
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6A563426-3474-41C6-B847-42B39F1485B2}" = Windows Live Messenger
"{6CB36609-E3A6-446C-A3C1-C71E311D2B9C}" = Windows Live Movie Maker
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker
"{6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}" = Complément Messenger
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73FC3510-6421-40F7-9503-EDAE4D0CF70D}" = Windows Live Photo Common
"{7496FD31-E5CB-4AE4-82D3-31099558BF6A}" = Windows Live Mesh
"{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5
"{76046298-768C-492C-8C93-2983C9E3719E}" = Windows Live UX Platform Language Pack
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh
"{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials
"{7E017923-16F8-4E32-94EF-0A150BD196FE}" = Windows Live Writer
"{804DE397-F82C-4867-9085-E0AA539A3294}" = Windows Live Writer
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{8142D25E-028A-4563-86ED-5755783C8029}" = Messenger Companion
"{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh
"{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}" = Assassin's Creed II
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{873E4648-6F6E-47F6-A7B2-A6F8DFABDCE6}" = Windows Live Messenger
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash
"{92D1CEBC-7C72-4ECF-BFC6-C131EF3FE6A7}" = Nokia Suite
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{939C80FA-96C9-44A6-B318-8E7D8BD8481B}" = Messenger Companion
"{93E464B3-D075-4989-87FD-A828B5C308B1}" = Windows Live Writer Resources
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96403552-88D1-429F-9C92-388B814B885E}" = Messenger Companion
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD262D0-B788-4546-A0A5-F4F56EC3834B}" = Windows Live Photo Common
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}" = פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DB90178-B5B0-45BD-B0A7-D40A6A1DF1CA}" = Windows Live Movie Maker
"{9E48FF52-082C-4CC2-BB67-6E10D09C0431}" = Windows Live UX Platform Language Pack
"{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail
"{A0B91308-6666-4249-8FF6-1E11AFD75FE1}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A2AA4204-C05A-4013-888A-AD153139297F}" = PC Connectivity Solution
"{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common
"{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}" = Windows Live Photo Gallery
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}" = 1&1 Surf-Stick
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB5977C5-11AE-4003-BA7D-261C48F2BC35}" = מסייע Messenger
"{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
"{ABD534B7-E951-470E-92C2-CD5AF1735726}" = Windows Live Essentials
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{ADE85655-8D1E-4E4B-BF88-5E312FB2C74F}" = Windows Live Mail
"{ADFE4AED-7F8E-4658-8D6E-742B15B9F120}" = Windows Live Photo Common
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B0C30E93-D3D9-4F04-A2AC-54749B573275}" = Command & Conquer 3
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B2BCA478-EC0F-45EE-A9E9-5EABE87EA72D}" = Windows Live Photo Common
"{B480904D-F73F-4673-B034-8A5F492C9184}" = Nuance PDF Reader
"{B618C3BF-5142-4630-81DD-F96864F97C7E}" = Windows Live Essentials
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{BBC019AB-8349-42A2-AF5A-A8B759722E2F}" = Windows Live UX Platform Language Pack
"{BE4BA698-8533-4F77-9559-C7F3F78C0B05}" = Assassin's Creed Brotherhood
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{BF022D76-9F72-4203-B8FA-6522DC66DFDA}" = Windows Live Movie Maker
"{C00C2A91-6CB3-483F-80B3-2958E29468F1}" = Συλλογή φωτογραφιών του Windows Live
"{C29FC15D-E84B-4EEC-8505-4DED94414C59}" = Windows Live Writer Resources
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C32CE55C-12BA-4951-8797-0967FDEF556F}" = Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}" = Windows Live Mesh ActiveX Control for Remote Connections
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C7DAD22D-29D4-438F-B986-03B9ED582EA4}" = Messenger Companion
"{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common
"{C9D8A041-2963-4B31-8FFC-1500F3DB9293}" = EpsonNet Setup 3.2
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}" = Windows Live Movie Maker
"{CE929F09-3853-4180-BD90-30764BFF7136}" = גלריית התמונות של Windows Live
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF088261-BC81-4FB9-9BA0-7B5B9602D01A}" = Messenger 分享元件
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D2131BFA-A0D6-4FDE-8614-75B07A9B15EE}" = Windows Live UX Platform Language Pack
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D588365A-AE39-4F27-BDAE-B4E72C8E900C}" = Windows Live Mail
"{DAEF48AD-89C8-4A93-B1DD-45B7E4FB6071}" = Windows Live Movie Maker
"{DBAA2B17-D596-4195-A169-BA2166B0D69B}" = Windows Live Mail
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE7C13A6-E4EA-4296-B0D5-5D7E8AD69501}" = Windows Live Writer
"{DE8F99FD-2FC7-4C98-AA67-2729FDE1F040}" = Windows Live Writer Resources
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DEF91E0F-D266-453D-B6F2-1BA002B40CB6}" = Windows Live Essentials
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}" = Controlo ActiveX do Windows Live Mesh para Ligações Remotas
"{E62E0550-C098-43A2-B54B-03FB1E634483}" = Windows Live Writer
"{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
"{E71E60C1-533E-45A5-8D80-E475E88D2B17}_is1" = Game Park Console
"{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources
"{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{ED16B700-D91F-44B0-867C-7EB5253CA38D}" = Raccolta foto di Windows Live
"{ED86C4AB-D1E5-42CF-BFA3-56BAAE617D4E}" = Windows Live UX Platform Language Pack
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EEF99142-3357-402C-B298-DEC303E12D92}" = Windows Live 影像中心
"{EF7EAB13-46FC-49DD-8E3C-AAF8A286C5BB}" = Windows Live 程式集
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}" = Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις
"{F7E80BA7-A09D-4DD1-828B-C4A0274D4720}" = Windows Live Mesh
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FB83EAC4-E3F6-4666-B45B-44522F2344B6}" = Brother MFL-Pro Suite MFC-J220
"{FCDE76CB-989D-4E32-9739-6A272D2B0ED7}" = Windows Live Mesh
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF3DFA01-1E98-46B4-A065-DA8AD47C9598}" = Windows Live Movie Maker
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Asus Vibe2.0" = AsusVibe2.0
"ASUS WebStorage" = ASUS WebStorage
"ASUS_N3_Series" = ASUS_N3_Series
"Avira AntiVir Desktop" = Avira Free Antivirus
"Cooking Dash" = Cooking Dash
"Diablo II" = Diablo II
"Diablo III" = Diablo III
"EPSON BX320FW Series Manual" = EPSON BX320FW Series Handbuch
"EPSON BX320FW Series Network Guide" = EPSON BX320FW Series Netzwerk-Handbuch
"EPSON Scanner" = EPSON Scan
"ESET Online Scanner" = ESET Online Scanner v3
"Free Studio_is1" = Free Studio version 5.6.3.706
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.8.815
"FreeCommander_is1" = FreeCommander 2009.02b
"GFWL_{4D53090A-9B45-437B-A66A-831000008300}" = Fable III
"Governor of Poker" = Governor of Poker
"Hotel Dash Suite Success" = Hotel Dash Suite Success
"InstallShield_{1F7424F8-F992-48BC-90EF-7C4DB0405E3F}" = Alcor Micro USB Card Reader
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = ASUS Video Magic
"InstallShield_{36B0DC39-3282-40EB-8587-B875CE46C3A7}" = ExpressGateCloud
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso
"Jewel Quest 3" = Jewel Quest 3
"Luxor 3" = Luxor 3
"Mahjongg dimensions" = Mahjongg dimensions
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.62.0.1300
"Mozilla Firefox 12.0 (x86 de)" = Mozilla Firefox 12.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MyTomTom" = MyTomTom 3.1.0.432
"Nokia Suite" = Nokia Suite
"Plants vs Zombies" = Plants vs Zombies
"PlugY, The Survival Kit" = PlugY, The Survival Kit
"PunkBusterSvc" = PunkBuster Services
"SpeedCommander 13" = SpeedCommander 13
"Tomb Raider: Anniversary" = Tomb Raider: Anniversary 1.0
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.1.9
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.20 (32-Bit)
"World of Goo" = World of Goo
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 24.03.2012 06:36:09 | Computer Name = Asus-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\freecommander\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "c:\program
 files (x86)\freecommander\DelZip179.dll" in Zeile 8.  Der Wert "*" des "language"-Attributs
 im assemblyIdentity-Element ist ungültig.
 
Error - 26.03.2012 04:42:34 | Computer Name = Asus-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\freecommander\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "c:\program
 files (x86)\freecommander\DelZip179.dll" in Zeile 8.  Der Wert "*" des "language"-Attributs
 im assemblyIdentity-Element ist ungültig.
 
Error - 29.03.2012 22:55:16 | Computer Name = Asus-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\freecommander\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "c:\program
 files (x86)\freecommander\DelZip179.dll" in Zeile 8.  Der Wert "*" des "language"-Attributs
 im assemblyIdentity-Element ist ungültig.
 
Error - 30.03.2012 07:10:28 | Computer Name = Asus-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: ICQ.exe, Version: 7.5.0.5259, Zeitstempel:
 0x4e354e55  Name des fehlerhaften Moduls: mshtml.dll, Version: 9.0.8112.16441, Zeitstempel:
 0x4ee81830  Ausnahmecode: 0xc0000005  Fehleroffset: 0x003c47c1  ID des fehlerhaften Prozesses:
 0x134c  Startzeit der fehlerhaften Anwendung: 0x01cd0e125d4a933d  Pfad der fehlerhaften
 Anwendung: C:\Program Files (x86)\ICQ7.5\ICQ.exe  Pfad des fehlerhaften Moduls: C:\Windows\system32\mshtml.dll
Berichtskennung:
 f43f3725-7a58-11e1-b828-74f06dd1dd25
 
Error - 31.03.2012 07:27:07 | Computer Name = Asus-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\freecommander\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "c:\program
 files (x86)\freecommander\DelZip179.dll" in Zeile 8.  Der Wert "*" des "language"-Attributs
 im assemblyIdentity-Element ist ungültig.
 
Error - 31.03.2012 20:18:19 | Computer Name = Asus-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\freecommander\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "c:\program
 files (x86)\freecommander\DelZip179.dll" in Zeile 8.  Der Wert "*" des "language"-Attributs
 im assemblyIdentity-Element ist ungültig.
 
Error - 02.04.2012 09:08:44 | Computer Name = Asus-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\freecommander\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "c:\program
 files (x86)\freecommander\DelZip179.dll" in Zeile 8.  Der Wert "*" des "language"-Attributs
 im assemblyIdentity-Element ist ungültig.
 
Error - 03.04.2012 05:31:43 | Computer Name = Asus-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\freecommander\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "c:\program
 files (x86)\freecommander\DelZip179.dll" in Zeile 8.  Der Wert "*" des "language"-Attributs
 im assemblyIdentity-Element ist ungültig.
 
Error - 04.04.2012 03:08:08 | Computer Name = Asus-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\freecommander\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "c:\program
 files (x86)\freecommander\DelZip179.dll" in Zeile 8.  Der Wert "*" des "language"-Attributs
 im assemblyIdentity-Element ist ungültig.
 
Error - 06.04.2012 06:11:46 | Computer Name = Asus-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\freecommander\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "c:\program
 files (x86)\freecommander\DelZip179.dll" in Zeile 8.  Der Wert "*" des "language"-Attributs
 im assemblyIdentity-Element ist ungültig.
 
[ System Events ]
Error - 03.08.2012 17:04:42 | Computer Name = Asus-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" wurde aufgrund
 folgenden Fehlers nicht gestartet:  %%1069
 
Error - 03.08.2012 17:10:17 | Computer Name = Asus-PC | Source = Service Control Manager | ID = 7038
Description = Der Dienst "WinHttpAutoProxySvc" konnte sich nicht als "NT AUTHORITY\LocalService"
 mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:  %%1352    Vergewissern
 Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
 Management Console (MMC).
 
Error - 03.08.2012 17:10:17 | Computer Name = Asus-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" wurde aufgrund
 folgenden Fehlers nicht gestartet:  %%1069
 
Error - 03.08.2012 17:14:41 | Computer Name = Asus-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  ATKWMIACPIIO  avipbb  avkmgr  discache  SASDIFSV  SASKUTIL  spldr  Wanarpv6
 
Error - 03.08.2012 17:14:44 | Computer Name = Asus-PC | Source = DCOM | ID = 10005
Description =
 
Error - 03.08.2012 17:14:53 | Computer Name = Asus-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.    Modulpfad:
 C:\Windows\System32\IWMSSvc.dll  Fehlercode: 21 
 
Error - 03.08.2012 17:14:55 | Computer Name = Asus-PC | Source = DCOM | ID = 10005
Description =
 
Error - 03.08.2012 17:15:04 | Computer Name = Asus-PC | Source = DCOM | ID = 10005
Description =
 
Error - 03.08.2012 17:15:04 | Computer Name = Asus-PC | Source = DCOM | ID = 10005
Description =
 
Error - 03.08.2012 17:53:22 | Computer Name = Asus-PC | Source = DCOM | ID = 10005
Description =
 
 
< End of report >

Code:

OTL logfile created on: 04.08.2012 09:16:16 - Run 4
OTL by OldTimer - Version 3.2.43.0    Folder = C:\Users\Asus\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7,91 Gb Total Physical Memory | 6,10 Gb Available Physical Memory | 77,14% Memory free
15,82 Gb Paging File | 13,77 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 197,55 Gb Total Space | 11,72 Gb Free Space | 5,93% Space Free | Partition Type: NTFS
Drive D: | 243,21 Gb Total Space | 178,00 Gb Free Space | 73,19% Space Free | Partition Type: NTFS
Drive E: | 232,88 Gb Total Space | 106,35 Gb Free Space | 45,67% Space Free | Partition Type: NTFS
Drive F: | 232,87 Gb Total Space | 9,86 Gb Free Space | 4,24% Space Free | Partition Type: NTFS
Drive G: | 264,60 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
 
Computer Name: ASUS-PC | User Name: Asus | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Asus\Desktop\OTL(1).exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Windows\AsScrPro.exe (ASUS)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\ExpressGateUtil\VAWinAgent.exe ()
PRC - C:\ExpressGateUtil\VAWinService.exe ()
PRC - C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe ()
PRC - C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe ()
PRC - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()
PRC - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
PRC - C:\Windows\vsnp2uvc.exe (Sonix Technology Co., Ltd.)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\ExpressGateUtil\VAWinAgent.exe ()
MOD - C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe ()
MOD - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (AFBAgent) -- C:\Windows\SysNative\FBAgent.exe (ASUSTeK Computer Inc.)
SRV:64bit: - (TurboBoost) Intel(R) -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel(R) Corporation)
SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (EvtEng) Intel(R) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) Intel(R) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
SRV:64bit: - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (Futuremark SystemInfo Service) -- C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS)
SRV - (ATKGFNEXSrv) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (VideAceWindowsService) -- C:\ExpressGateUtil\VAWinService.exe ()
SRV - (CLKMSVC10_38F51D56) -- C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe (CyberLink)
SRV - (UI Assistant Service) -- C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (BrYNSvc) -- C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys (Nokia)
DRV:64bit: - (upperdev) -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia)
DRV:64bit: - (nmwcdc) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:64bit: - (nmwcd) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (nvpciflt) -- C:\Windows\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV:64bit: - (FLxHCIc) Fresco Logic xHCI (USB3) -- C:\Windows\SysNative\drivers\FLxHCIc.sys (Fresco Logic)
DRV:64bit: - (FLxHCIh) Fresco Logic xHCI (USB3) -- C:\Windows\SysNative\drivers\FLxHCIh.sys (Fresco Logic)
DRV:64bit: - (TurboB) -- C:\Windows\SysNative\drivers\TurboB.sys (Intel(R) Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) Intel(R) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel(R) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronic Corp.)
DRV:64bit: - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) -- C:\Windows\SysNative\drivers\snp2uvc.sys (Sonix Technology Co., Ltd.)
DRV:64bit: - (L1C) -- C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (NETwNs64) ___ Intel(R) -- C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (wdkmd) -- C:\Windows\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (AmUStor) -- C:\Windows\SysNative\drivers\AmUStor.sys (Alcor Micro, Corp.)
DRV:64bit: - (ZTEusbser6k) -- C:\Windows\SysNative\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV:64bit: - (ZTEusbnmea) -- C:\Windows\SysNative\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV:64bit: - (ZTEusbmdm6k) -- C:\Windows\SysNative\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV:64bit: - (massfilter) -- C:\Windows\SysNative\drivers\massfilter.sys (ZTE Incorporated)
DRV:64bit: - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( )
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (btusbflt) -- C:\Windows\SysNative\drivers\btusbflt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) -- C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (SiSGbeLH) -- C:\Windows\SysNative\drivers\SiSG664.sys (Silicon Integrated Systems Corp.)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (btwl2cap) -- C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (ATKWMIACPIIO) -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ASUS)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (ASMMAP64) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ASUT_deDE491
IE - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.useDBForOrder: true
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_270.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_270.dll ()
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.05.06 21:04:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.08.03 22:36:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files (x86)\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012.03.05 20:22:36 | 000,000,000 | ---D | M]
 
[2011.04.28 20:31:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\Extensions
[2012.06.28 16:43:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\Firefox\Profiles\iskpx8ki.default\extensions
[2011.05.11 10:15:38 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Asus\AppData\Roaming\mozilla\Firefox\Profiles\iskpx8ki.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.06.28 16:43:58 | 000,000,853 | ---- | M] () -- C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\iskpx8ki.default\searchplugins\11-suche.xml
[2012.06.28 16:43:58 | 000,002,209 | ---- | M] () -- C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\iskpx8ki.default\searchplugins\englische-ergebnisse.xml
[2012.06.28 16:43:58 | 000,010,506 | ---- | M] () -- C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\iskpx8ki.default\searchplugins\gmx-suche.xml
[2012.06.28 16:43:58 | 000,002,368 | ---- | M] () -- C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\iskpx8ki.default\searchplugins\lastminute.xml
[2012.06.28 16:43:58 | 000,005,489 | ---- | M] () -- C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\iskpx8ki.default\searchplugins\webde-suche.xml
[2012.03.26 19:40:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.05.05 20:23:47 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.06.28 16:43:57 | 000,575,217 | ---- | M] () (No name found) -- C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\EXTENSIONS\TOOLBAR@GMX.NET.XPI
[2012.05.06 21:04:24 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.07.17 20:00:14 | 000,170,624 | ---- | M] (Tracker Software Products (Canada) Ltd.) -- C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2012.02.13 08:20:42 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.02.13 08:20:42 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.02.13 08:20:42 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.13 08:20:42 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.13 08:20:42 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.13 08:20:42 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012.07.19 19:52:36 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll File not found
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe (Sonix Technology Co., Ltd.)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [FLxHCIm] C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe (Windows (R) Win 7 DDK provider)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [Nuance PDF Reader-reminder] C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\SonicMaster\SonicMasterTray.exe (Virage Logic Corporation / Sonic Focus)
O4 - HKLM..\Run: [UIExec] C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe ()
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VAWinAgent] C:\ExpressGateUtil\VAWinAgent.exe ()
O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000..\Run: [ICQ] C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001..\Run: [ICQ] C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1516755417-3234397197-3308580895-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2EA5B419-5589-46C0-8493-6F92D4C0ED6B}: DhcpNameServer = 192.168.2.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A658CF3C-152A-4012-9255-8A1934FA0622}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.08.04 09:08:00 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Users\Asus\Desktop\OTL(1).exe
[2012.08.03 23:18:29 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Local\Macromedia
[2012.08.03 22:36:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer
[2012.08.03 22:36:42 | 000,000,000 | ---D | C] -- C:\Program Files\Tracker Software
[2012.08.03 22:33:59 | 000,955,888 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll
[2012.08.03 22:33:59 | 000,839,152 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\deployJava1.dll
[2012.08.03 22:33:59 | 000,268,784 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe
[2012.08.03 22:33:51 | 000,189,424 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
[2012.08.03 22:33:51 | 000,188,912 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
[2012.08.03 22:33:45 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012.08.03 22:28:39 | 000,426,184 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012.08.03 22:27:41 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2012.08.03 22:27:41 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2012.07.21 21:32:33 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Roaming\SUPERAntiSpyware.com
[2012.07.21 21:31:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012.07.21 21:31:41 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2012.07.21 21:31:41 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012.07.21 21:30:19 | 018,101,376 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\Asus\Desktop\SUPERAntiSpyware.exe
[2012.07.20 08:17:03 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Asus\Desktop\aswMBR.exe
[2012.07.20 08:16:34 | 000,000,000 | ---D | C] -- C:\Users\Asus\Desktop\Osam
[2012.07.20 08:15:24 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Roaming\WinRAR
[2012.07.20 08:15:24 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012.07.20 08:15:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012.07.20 08:15:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR
[2012.07.20 07:37:16 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.07.19 19:54:08 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.07.19 19:41:47 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.07.19 19:41:47 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.07.19 19:41:47 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.07.19 19:41:41 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.07.19 19:41:26 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012.07.19 19:38:53 | 004,582,475 | R--- | C] (Swearware) -- C:\Users\Asus\Desktop\ComboFix.exe
[2012.07.18 20:21:24 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012.07.18 20:16:19 | 002,136,664 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Asus\Desktop\tdsskiller.exe
[2012.07.17 21:25:03 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.07.16 20:51:08 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Asus\Desktop\OTL.exe
[2012.07.14 14:46:05 | 000,000,000 | ---D | C] -- C:\Users\Asus\Desktop\Steinberg
[2012.07.12 03:01:06 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012.07.12 03:01:06 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012.07.12 03:01:05 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012.07.12 03:01:05 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012.07.12 03:01:04 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012.07.12 03:01:04 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012.07.12 03:01:04 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012.07.12 03:01:04 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012.07.12 03:01:03 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012.07.12 03:01:03 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012.07.12 03:01:03 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012.07.12 03:01:02 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012.07.12 03:01:02 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012.07.11 22:21:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.07.11 19:20:23 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll
[2012.07.11 19:20:23 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll
[2012.07.11 19:20:15 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2012.07.11 19:20:13 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdosys.dll
[2012.07.11 19:20:12 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdosys.dll
[2012.07.07 22:19:35 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Roaming\Malwarebytes
[2012.07.07 22:19:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.07 22:19:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.07 22:19:08 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.07 22:19:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.07.07 11:25:34 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
[2012.07.07 11:11:38 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Roaming\Google
[2012.07.05 21:25:09 | 000,405,144 | ---- | C] (Newtonsoft) -- C:\Windows\SysWow64\Newtonsoft.Json.Net20.dll
 
========== Files - Modified Within 30 Days ==========
 
[2012.08.04 09:11:17 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.08.04 09:11:17 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.08.04 09:08:00 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Users\Asus\Desktop\OTL(1).exe
[2012.08.04 09:07:23 | 001,529,502 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.08.04 09:07:23 | 000,665,812 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.08.04 09:07:23 | 000,627,654 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.08.04 09:07:23 | 000,133,992 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.08.04 09:07:23 | 000,110,374 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.08.04 09:04:42 | 000,045,056 | ---- | M] () -- C:\Windows\SysNative\acovcnt.exe
[2012.08.04 09:04:42 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.08.04 09:02:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.08.04 09:02:18 | 2077,265,919 | -HS- | M] () -- C:\hiberfil.sys
[2012.08.04 04:28:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.08.04 03:49:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.08.03 23:11:29 | 000,001,472 | ---- | M] () -- C:\Windows\SysNative\ServiceFilter.ini
[2012.08.03 22:33:46 | 000,955,888 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll
[2012.08.03 22:33:46 | 000,839,152 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\deployJava1.dll
[2012.08.03 22:33:46 | 000,268,784 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe
[2012.08.03 22:33:46 | 000,189,424 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
[2012.08.03 22:33:46 | 000,188,912 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
[2012.08.03 22:28:39 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012.08.03 22:28:39 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012.08.03 22:03:42 | 004,503,728 | ---- | M] () -- C:\ProgramData\ras_0oed.pad
[2012.07.29 12:50:13 | 000,002,520 | ---- | M] () -- C:\Windows\SysNative\AutoRunFilter.ini
[2012.07.21 21:31:45 | 000,001,810 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.07.21 21:30:28 | 018,101,376 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\Asus\Desktop\SUPERAntiSpyware.exe
[2012.07.21 11:27:24 | 004,503,728 | ---- | M] () -- C:\ProgramData\kp_0loor.pad
[2012.07.20 20:19:00 | 000,000,512 | ---- | M] () -- C:\Users\Asus\Desktop\MBR.dat
[2012.07.20 08:17:18 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Asus\Desktop\aswMBR.exe
[2012.07.20 08:12:51 | 000,302,592 | ---- | M] () -- C:\Users\Asus\Desktop\8y9np4vh.exe
[2012.07.19 19:52:36 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.07.19 19:39:14 | 004,582,475 | R--- | M] (Swearware) -- C:\Users\Asus\Desktop\ComboFix.exe
[2012.07.18 20:16:20 | 002,136,664 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Asus\Desktop\tdsskiller.exe
[2012.07.16 20:51:09 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Asus\Desktop\OTL.exe
[2012.07.14 14:36:41 | 000,001,245 | ---- | M] () -- C:\Users\Asus\Desktop\DVDVideoSoft Free Studio.lnk
[2012.07.14 14:21:22 | 000,624,883 | ---- | M] () -- C:\Users\Asus\Desktop\adwcleaner0.exe
[2012.07.12 17:13:40 | 000,405,144 | ---- | M] (Newtonsoft) -- C:\Windows\SysWow64\Newtonsoft.Json.Net20.dll
[2012.07.12 03:24:04 | 000,305,184 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
 
========== Files Created - No Company Name ==========
 
[2012.08.03 22:28:40 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.08.03 21:02:34 | 004,503,728 | ---- | C] () -- C:\ProgramData\ras_0oed.pad
[2012.07.21 21:31:45 | 000,001,810 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.07.21 02:51:05 | 004,503,728 | ---- | C] () -- C:\ProgramData\kp_0loor.pad
[2012.07.20 19:56:56 | 000,000,512 | ---- | C] () -- C:\Users\Asus\Desktop\MBR.dat
[2012.07.20 08:12:51 | 000,302,592 | ---- | C] () -- C:\Users\Asus\Desktop\8y9np4vh.exe
[2012.07.19 19:41:47 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.07.19 19:41:47 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.07.19 19:41:47 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.07.19 19:41:47 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.07.19 19:41:47 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.07.14 18:05:41 | 000,624,883 | ---- | C] () -- C:\Users\Asus\Desktop\adwcleaner0.exe
[2012.07.14 14:36:41 | 000,001,245 | ---- | C] () -- C:\Users\Asus\Desktop\DVDVideoSoft Free Studio.lnk
[2012.07.07 11:13:14 | 000,001,110 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.07 11:13:12 | 000,001,106 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.02.18 17:15:52 | 000,000,241 | ---- | C] () -- C:\Windows\Brpfx04a.ini
[2012.02.18 17:15:52 | 000,000,093 | ---- | C] () -- C:\Windows\brpcfx.ini
[2012.02.18 17:13:14 | 000,000,000 | ---- | C] () -- C:\Windows\brdfxspd.dat
[2012.02.04 14:04:18 | 000,026,779 | ---- | C] () -- C:\Windows\DIIUnin.dat
[2011.10.21 18:27:54 | 000,217,536 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.10.21 18:22:54 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2011.10.21 18:03:04 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011.09.10 13:39:14 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2011.09.10 13:39:14 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2011.05.05 20:24:43 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.05.05 19:53:52 | 000,280,976 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011.05.05 19:53:50 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011.04.30 11:27:22 | 000,011,264 | ---- | C] () -- C:\Users\Asus\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.03.26 01:16:10 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.02.12 04:19:28 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.01.26 12:22:43 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini
 
========== LOP Check ==========
 
[2012.08.03 22:35:47 | 000,000,000 | ---D | M] -- C:\Users\Alternative\AppData\Roaming\Nuance
[2012.08.03 22:35:45 | 000,000,000 | ---D | M] -- C:\Users\Alternative\AppData\Roaming\Zeon
[2011.04.16 17:16:07 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Asus WebStorage
[2012.01.04 21:44:43 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2012.07.14 14:39:02 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\DVDVideoSoft
[2012.07.05 21:26:15 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.06.17 11:02:27 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Epson
[2011.09.24 23:14:12 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\FreeCommander
[2012.08.04 09:15:27 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\ICQ
[2011.10.04 00:32:01 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Lionhead Studios
[2011.04.28 18:15:20 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\MAXON
[2012.03.05 20:23:33 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Nokia
[2011.04.30 11:21:56 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Nokia Ovi Suite
[2012.03.05 20:24:28 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Nokia Suite
[2011.05.04 19:54:18 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Nuance
[2011.05.04 11:27:40 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\OpenOffice.org
[2011.04.30 11:21:31 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\PC Suite
[2011.05.05 19:53:49 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\PunkBuster
[2011.06.04 15:36:19 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\SpeedProject
[2011.12.21 16:06:09 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Ubisoft
[2011.04.30 09:22:10 | 000,000,000 | ---D | M] -- C:\Users\Asus\AppData\Roaming\Zeon
[2012.06.17 05:15:22 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 08/04/2012 at 12:19 PM

Application Version : 5.5.1012

Core Rules Database Version : 9010
Trace Rules Database Version: 6822

Scan type      : Complete Scan
Total Scan Time : 02:56:06

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 673
Memory threats detected  : 0
Registry items scanned    : 71232
Registry threats detected : 0
File items scanned        : 214785
File threats detected    : 354

Adware.Tracking Cookie
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\V54EZR3N.txt [ /imrworldwide.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\9ZLQ65PD.txt [ /track.adform.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\I5ELX9A7.txt [ /fastclick.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\QRWZ0IPZ.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\OS3CT8MJ.txt [ /doubleclick.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\TMFZMA7G.txt [ /ad4.adfarm1.adition.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\GY0ZCJ2Q.txt [ /adform.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\GJSUZWOL.txt [ /ads.creative-serving.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\D4TMT9ES.txt [ /apmebf.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\SPM3M5DU.txt [ /serving-sys.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\F5B39AYH.txt [ /server.adformdsp.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\WIGSCZYB.txt [ /atdmt.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\3MGFEW71.txt [ /c.atdmt.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\39FX1LE6.txt [ /ad.360yield.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\93YJLWPI.txt [ /adfarm1.adition.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\74HOKOZM.txt [ /bs.serving-sys.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\QXKP4BQS.txt [ /zanox.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\WLMFOO9R.txt [ /ad.zanox.com ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\OB81SWJS.txt [ /adformdsp.net ]
        C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Cookies\VDXXPOK3.txt [ /mediaplex.com ]
        C:\USERS\ASUS\Cookies\9ZLQ65PD.txt [ Cookie:asus@track.adform.net/ ]
        C:\USERS\ASUS\Cookies\QRWZ0IPZ.txt [ Cookie:asus@ad2.adfarm1.adition.com/ ]
        C:\USERS\ASUS\Cookies\OS3CT8MJ.txt [ Cookie:asus@doubleclick.net/ ]
        C:\USERS\ASUS\Cookies\TMFZMA7G.txt [ Cookie:asus@ad4.adfarm1.adition.com/ ]
        C:\USERS\ASUS\Cookies\GY0ZCJ2Q.txt [ Cookie:asus@adform.net/ ]
        C:\USERS\ASUS\Cookies\F5B39AYH.txt [ Cookie:asus@server.adformdsp.net/ ]
        C:\USERS\ASUS\Cookies\WIGSCZYB.txt [ Cookie:asus@atdmt.com/ ]
        C:\USERS\ASUS\Cookies\3MGFEW71.txt [ Cookie:asus@c.atdmt.com/ ]
        C:\USERS\ASUS\Cookies\93YJLWPI.txt [ Cookie:asus@adfarm1.adition.com/ ]
        C:\USERS\ASUS\Cookies\74HOKOZM.txt [ Cookie:asus@bs.serving-sys.com/ ]
        C:\USERS\ASUS\Cookies\QXKP4BQS.txt [ Cookie:asus@zanox.com/ ]
        C:\USERS\ASUS\Cookies\OB81SWJS.txt [ Cookie:asus@adformdsp.net/ ]
        C:\USERS\ASUS\Cookies\VDXXPOK3.txt [ Cookie:asus@mediaplex.com/ ]
        ia.media-imdb.com [ C:\USERS\ALTERNATIVE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TUGDLKWG ]
        core.saymedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        delivery.ibanner.de [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        media.trafficfactory.biz [ C:\USERS\ASUS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DGFQD8BS ]
        .doubleclick.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        adserver.doccheck.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .rewetouristik.112.2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adnetwork.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        aimfar.solution.weborama.fr [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .weboramapublishertrackinguk2.solution.weborama.fr [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .weboramapublishertrackinguk2.solution.weborama.fr [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.usenext.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        7.rotator.wigetmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        7.rotator.wigetmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        tracking.mobile.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .audiag.112.2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        7.rotator.trafficbee.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        7.rotator.trafficbee.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        7.rotator.trafficbee.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        wmedia.rotator.hadj7.adjuggler.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        wmedia.rotator.hadj7.adjuggler.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        wmedia.rotator.hadj7.adjuggler.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        7.rotator.wigetmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .burstnet.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adserver.adtechus.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .saymedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .saymedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        wstat.wibiya.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        tomtailor.dyntracker.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .saymedia.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.mediamarkt.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        data.mediamarkt.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.mediamarkt.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\ASUS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ISKPX8KI.DEFAULT\COOKIES.SQLITE ]

Grüße

Sebastian

cosinus 04.08.2012 17:32

Ok, ist das Problem nun behoben?!
Wenn ja unbedingt die Updates machen! Prüf mit Secunia nach ob auch wirklich alles auf dem aktuellen Stand ist!
Für die Zukunft solltest du im Firefox mindestens mit NoScript und Flashblock drin sein, am besten auch WOT und Adblock+ verwenden
Evtl. wäre das hier auch was für dich => http://www.trojaner-board.de/71542-a...tml#post424906

sebbi86 04.08.2012 20:04

Nabend.

Ja also das prinzipielle Problem, dass mein Rechner gesperrt wird sobald ich ihn anmache ist erstmal behoben., Wie hoch die wahrscheinlichkeit ist, dass der Trojaner noch auf meinem Rechenr "schlummert" dachte ich kannst du mir sagen.

Updates sind neu gemacht, wie du es letztens beschrieben hast.

Jetzt muss ich aber mal wieder meine Unwissenheit kundtun: Flashblock? NoScript? WOT??? und Adblock+? Sorry davon versteh ich grad net soviel ....

Mit dem Sandboxie beschäftige ich mich mal morgen. klang ganz interessant.

Danke ... mal wieder ^^

Sebastian


Alle Zeitangaben in WEZ +1. Es ist jetzt 10:52 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132