Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Malwarebytes findet Trojan.Lameshield. Welche Schritte sind nun notwendig? (https://www.trojaner-board.de/119971-malwarebytes-findet-trojan-lameshield-welche-schritte-notwendig.html)

sucnas 20.07.2012 18:18

Malwarebytes findet Trojan.Lameshield. Welche Schritte sind nun notwendig?
 
Liste der Anhänge anzeigen (Anzahl: 1)
Guten Abend zusammen,

leider musste ich heute feststellen, dass es mich nun auch erwischt hat.
Auf einmal öffnete sich ein kleines Fenster und teilte mir mit, was bei mir nicht alles für Dateien infiziert wären.
Ich konnte unten in der Taskleiste erkennen, dass das Fenster von einem Programm Security Shield geöffnet wurde.
Ich klickte weder in der Taskleiste noch in dem kleinen Fenster. Ich googelte nach Security Shield und kam auf euer Board. Umgehend stoppte ich im Taskmanager den Prozess, dann schloss sich auch das kleine Pop up Fenster. Danach führte ich rkill.com 3x aus, lud Malwarebytes und führte einen vollständigen Scan durch. Dieser fand zwei infizierte Objekte. Wobei die zweite Meldung vermutlich nur darauf hinweist, dass ich die Datei vom IE9 noch auf dem Desktop habe.
Vermutlich habe ich mir den Trojaner auch über den IE geholt. Ich war so selten dämlich und habe eine völlig alte Version des IE kurz offen gehabt. Ich konnte mit dem Firefox eine Seite nicht öffnen und wollte schauen ob es über den IE geht .... dumm und ich ärgere mich maßlos, aber es ist nun passiert.

Ich würde mich riesig freuen wenn ihr mir helfen könnt.

Bislang wie gesagt nur Malwarebytes ausgeführt und die Logdatei gespeichert. Malwarebytes ist noch mit dem Fenster nach dem Scan geöffnet. Keine weiteren Schritte unternommen. Das würde ich gerne nun mit euch zusammen machen.

Danke im Voraus.

Viele Grüße
Katja

Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
 
Datenbank Version: v2012.07.20.06
 
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Katja :: MEINGEWINN [Administrator]
 
20.07.2012 15:59:47
mbam-log-2012-07-20 (18-53-24).txt
 
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 391852
Laufzeit: 2 Stunde(n), 47 Minute(n), 29 Sekunde(n)
 
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
 
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
 
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
 
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
 
Infizierte Dateien: 2
C:\Users\Katja\AppData\Local\fzzcyvn.exe (Trojan.Lameshield) -> Keine Aktion durchgeführt.
C:\Users\Katja\Desktop\eXplorer.exe (Heuristics.Reserved.Word.Exploit) -> Keine Aktion durchgeführt.
 
(Ende)

Ich habe nun noch 2 aktuelle Logs. So sieht es ja nun sauber aus. Ob ich doch noch einmal Glück hatte?

Ich hoffe von euch kommen noch Tipps wie ich das System weiter prüfen kann.


Malewarebytes
Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
 
Datenbank Version: v2012.07.22.10
 
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Katja :: MEINGEWINN [limitiert]
 
23.07.2012 00:08:07
mbam-log-2012-07-23 (00-08-07).txt
 
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 158706
Laufzeit: 4 Minute(n), 28 Sekunde(n)
 
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
 
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
 
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
 
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
 
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
 
(Ende)



ESET gestern

Code:

ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=a50b512a6bac0540a32376e07e503e78
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-21 07:58:34
# local_time=2012-07-21 09:58:34 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 24142621 24142621 0 0
# compatibility_mode=5893 16776573 100 94 75904 94520349 0 0
# compatibility_mode=8192 67108863 100 0 461 461 0 0
# scanned=218303
# found=0
# cleaned=0
# scan_time=10215


Allerdings habe ich eine komische Entdeckung im Infobereich gemacht. Diesen wollte ich anpassen und bin dann auf folgendes Bild gestoßen

http://www.trojaner-board.de/attachm...1&d=1342995721

Schlummert da doch noch was?

Vorsichtshalber habe ich über einen anderen Rechner alle relevanten Passwörter geändert.
Und ich habe mit Secunia PSI alles auf den neusten Stand gebracht. Man vergisst doch immer ein paar Programme.

Liebe Grüße
Katja

cosinus 23.07.2012 10:59

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

sucnas 23.07.2012 11:33

Nein, ich habe das Programm erst Freitag geladen. Ich kannte es vorher nicht und habe alle Schritte die ich oben beschrieben habe nur mit Hilfe des Trojaner Boards gemacht.
Vorher hatte ich nur Avira.

Gruß Katja

EDIT: Der Teil im obigen Beitrag der mit
Zitat:

Ich habe nun noch 2 aktuelle Logs. So sieht es ja nun sauber aus. Ob ich doch noch einmal Glück hatte?
beginnt, stammt von gestern. Das hatte ich noch hier gepostet und wurde vermutlich vom Team mit meinem ersten Beitrag zusammengeführt.

cosinus 23.07.2012 15:23

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

sucnas 23.07.2012 15:58

Liste der Anhänge anzeigen (Anzahl: 1)
Hallo Arne,

leider kann ich das Programm nicht ausführen.
Bekomme folgende Fehlermeldung

http://www.trojaner-board.de/attachm...1&d=1343055466

Habe es extra noch einmal runtergeladen.

Gruß Katja

sucnas 23.07.2012 20:00

Hat nun geklappt, ich bin auf die Seite des Anbieters und habe die Datei per Rechtsklick runtergeladen. Vorher hatte sie nie die komplette Größe. Liegt vielleicht daran, dass ich im Moment nur mit Webstick unterwegs bin. Könnte die Seiten vermutlich schneller malen wie sie laden.


Code:

# AdwCleaner v1.703 - Logfile created 07/23/2012 at 20:57:31
# Updated 20/07/2012 by Xplode
# Operating system : Windows 7 Professional Service Pack 1 (64 bits)
# User : Katja_alles - MEINGEWINN
# Running from : C:\Users\Katja\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Users\Katja\AppData\Local\AskToolbar
Folder Found : C:\Users\Katja\AppData\Local\Conduit
Folder Found : C:\Users\Katja\AppData\Local\Ilivid Player
Folder Found : C:\Users\Katja_alles\AppData\Local\AskToolbar
Folder Found : C:\Users\Katja\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Katja\AppData\LocalLow\Conduit
Folder Found : C:\Users\Katja_alles\AppData\LocalLow\AskToolbar
Folder Found : C:\Program Files (x86)\Ask.com
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\Program Files (x86)\Ilivid
Folder Found : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
File Found : C:\Users\Katja\AppData\Roaming\Mozilla\Firefox\Profiles\nxz5u7io.default\searchplugins\Conduit.xml

***** [Registry] *****
[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT1060933
Key Found : HKCU\Software\APN
Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
Key Found : HKCU\Software\AskToolbar
Key Found : HKLM\SOFTWARE\APN
Key Found : HKLM\SOFTWARE\AskToolbar
Key Found : HKLM\SOFTWARE\bandoo
Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore
Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1
Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr
Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1
Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr
Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1
Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr
Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
[x64] Key Found : HKCU\Software\APN
[x64] Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
[x64] Key Found : HKCU\Software\AskToolbar
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
[x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore
[x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1
[x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr
[x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1
[x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr
[x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1
[x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr
[x64] Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1
[x64] Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
[x64] Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
[x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644}
Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2D5E2D34-BED5-4B9F-9793-A31E26E6806E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2D5E2D34-BED5-4B9F-9793-A31E26E6806E}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971}
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC}
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12}
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
[x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v14.0.1 (de)

Profile name : default
File : C:\Users\Katja\AppData\Roaming\Mozilla\Firefox\Profiles\nxz5u7io.default\prefs.js

Found : user_pref("CT1060933..clientLogIsEnabled", true);
Found : user_pref("CT1060933..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT1060933..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT1060933.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Found : user_pref("CT1060933.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT1060933.BrowserCompStateIsOpen_129681785283868963", true);
Found : user_pref("CT1060933.BrowserCompStateIsOpen_129686665230467549", true);
Found : user_pref("CT1060933.CTID", "CT1060933");
Found : user_pref("CT1060933.CurrentServerDate", "29-1-2012");
Found : user_pref("CT1060933.DSInstall", false);
Found : user_pref("CT1060933.DialogsAlignMode", "LTR");
Found : user_pref("CT1060933.DialogsGetterLastCheckTime", "Sun Jan 29 2012 19:26:26 GMT+0100");
Found : user_pref("CT1060933.DownloadReferralCookieData", "");
Found : user_pref("CT1060933.FirstServerDate", "29-1-2012");
Found : user_pref("CT1060933.FirstTime", true);
Found : user_pref("CT1060933.FirstTimeFF3", true);
Found : user_pref("CT1060933.FixPageNotFoundErrors", true);
Found : user_pref("CT1060933.GroupingServerCheckInterval", 1440);
Found : user_pref("CT1060933.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT1060933.HPInstall", false);
Found : user_pref("CT1060933.HasUserGlobalKeys", true);
Found : user_pref("CT1060933.Initialize", true);
Found : user_pref("CT1060933.InitializeCommonPrefs", true);
Found : user_pref("CT1060933.InstallationAndCookieDataSentCount", 1);
Found : user_pref("CT1060933.InstallationId", "ConduitNSISIntegration");
Found : user_pref("CT1060933.InstallationType", "ConduitXPEIntegration");
Found : user_pref("CT1060933.InstalledDate", "Sun Jan 29 2012 19:26:26 GMT+0100");
Found : user_pref("CT1060933.InvalidateCache", false);
Found : user_pref("CT1060933.IsAlertDBUpdated", true);
Found : user_pref("CT1060933.IsGrouping", false);
Found : user_pref("CT1060933.IsInitSetupIni", true);
Found : user_pref("CT1060933.IsMulticommunity", false);
Found : user_pref("CT1060933.IsOpenThankYouPage", false);
Found : user_pref("CT1060933.IsOpenUninstallPage", true);
Found : user_pref("CT1060933.LanguagePackLastCheckTime", "Sun Jan 29 2012 19:26:27 GMT+0100");
Found : user_pref("CT1060933.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT1060933.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT1060933.LastLogin_3.9.0.3", "Sun Jan 29 2012 19:26:27 GMT+0100");
Found : user_pref("CT1060933.LatestVersion", "3.9.0.3");
Found : user_pref("CT1060933.Locale", "en-us");
Found : user_pref("CT1060933.MCDetectTooltipHeight", "83");
Found : user_pref("CT1060933.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT1060933.MCDetectTooltipWidth", "295");
Found : user_pref("CT1060933.MyStuffEnabledAtInstallation", true);
Found : user_pref("CT1060933.OriginalFirstVersion", "3.9.0.3");
Found : user_pref("CT1060933.RadioIsPodcast", false);
Found : user_pref("CT1060933.RadioLastCheckTime", "Sun Jan 29 2012 19:26:28 GMT+0100");
Found : user_pref("CT1060933.RadioLastUpdateIPServer", "0");
Found : user_pref("CT1060933.RadioLastUpdateServer", "129326918102570000");
Found : user_pref("CT1060933.RadioMediaID", "21504191");
Found : user_pref("CT1060933.RadioMediaType", "Media Player");
Found : user_pref("CT1060933.RadioMenuSelectedID", "EBRadioMenu_CT106093321504191");
Found : user_pref("CT1060933.RadioShrinkedFromSetup", false);
Found : user_pref("CT1060933.RadioStationName", "KFOG");
Found : user_pref("CT1060933.RadioStationURL", "hxxp://live.cumulusstreaming.com/KFOG-FM");
Found : user_pref("CT1060933.SearchCaption", "Freecorder Customized Web Search");
Found : user_pref("CT1060933.SearchFromAddressBarIsInit", true);
Found : user_pref("CT1060933.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT106[...]
Found : user_pref("CT1060933.SearchInNewTabEnabled", true);
Found : user_pref("CT1060933.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT1060933.SearchInNewTabLastCheckTime", "Sun Jan 29 2012 19:26:28 GMT+0100");
Found : user_pref("CT1060933.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT1060933.SendProtectorDataViaLogin", true);
Found : user_pref("CT1060933.ServiceMapLastCheckTime", "Sun Jan 29 2012 19:26:25 GMT+0100");
Found : user_pref("CT1060933.SettingsLastCheckTime", "Sun Jan 29 2012 19:26:25 GMT+0100");
Found : user_pref("CT1060933.SettingsLastUpdate", "1327080122");
Found : user_pref("CT1060933.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT1060933&SearchSource=13");
Found : user_pref("CT1060933.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT1060933.ThirdPartyComponentsLastCheck", "Sun Jan 29 2012 19:26:25 GMT+0100");
Found : user_pref("CT1060933.ThirdPartyComponentsLastUpdate", "1312887586");
Found : user_pref("CT1060933.ToolbarShrinkedFromSetup", false);
Found : user_pref("CT1060933.TrusteLinkUrl", "hxxp://trust.conduit.com/CT1060933");
Found : user_pref("CT1060933.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Found : user_pref("CT1060933.UserID", "UN61153422592245393");
Found : user_pref("CT1060933.ValidationData_Toolbar", 0);
Found : user_pref("CT1060933.alertChannelId", "15651");
Found : user_pref("CT1060933.appApproved.129272674122038321", true);
Found : user_pref("CT1060933.autoDisableScopes", -1);
Found : user_pref("CT1060933.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Found : user_pref("CT1060933.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Found : user_pref("CT1060933.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Found : user_pref("CT1060933.backendstorage./9b+7e.:2z527", "2423");
Found : user_pref("CT1060933.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Found : user_pref("CT1060933.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Found : user_pref("CT1060933.backendstorage./9b+7e06cg5el8:", "6E6D6F6B6B6E7472746F");
Found : user_pref("CT1060933.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A7473757171747A787A75242F4B4947[...]
Found : user_pref("CT1060933.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Found : user_pref("CT1060933.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Found : user_pref("CT1060933.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Found : user_pref("CT1060933.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Found : user_pref("CT1060933.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Found : user_pref("CT1060933.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Found : user_pref("CT1060933.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Found : user_pref("CT1060933.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Found : user_pref("CT1060933.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Found : user_pref("CT1060933.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Found : user_pref("CT1060933.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Found : user_pref("CT1060933.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Found : user_pref("CT1060933.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Found : user_pref("CT1060933.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Found : user_pref("CT1060933.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Found : user_pref("CT1060933.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Found : user_pref("CT1060933.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Found : user_pref("CT1060933.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Found : user_pref("CT1060933.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Found : user_pref("CT1060933.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Found : user_pref("CT1060933.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Found : user_pref("CT1060933.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Found : user_pref("CT1060933.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Found : user_pref("CT1060933.backendstorage./9b-0?3g>d", "39693C6B703E736D7A42744872204A7D7D7C25202324512A20[...]
Found : user_pref("CT1060933.backendstorage./9b-0?3g@6:5;", "");
Found : user_pref("CT1060933.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E424[...]
Found : user_pref("CT1060933.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Found : user_pref("CT1060933.backendstorage./9b3=>@44i48?", "372C2D32697576334236334148477A213F3E484F4E4D464[...]
Found : user_pref("CT1060933.backendstorage./9b5ba==9cjag", "396F68703F6E75437A70467479734A4C7A7A507C7B");
Found : user_pref("CT1060933.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6F6B6B6E74716E7873777A");
Found : user_pref("CT1060933.backendstorage./9b9643g3/9e", "6A");
Found : user_pref("CT1060933.backendstorage./9b<:222h64<", "393F352F3E");
Found : user_pref("CT1060933.backendstorage./9b=+03eh8h8j?:", "4443");
Found : user_pref("CT1060933.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Found : user_pref("CT1060933.backendstorage./9b?b0d:8aj62<h", "6D");
Found : user_pref("CT1060933.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Found : user_pref("CT1060933.backendstorage.autocompletepro_enable_auto", "31");
Found : user_pref("CT1060933.backendstorage.shoppingapp.gk.exipres", "4672692046656220303320323031322031393A[...]
Found : user_pref("CT1060933.backendstorage.shoppingapp.gk.geolocation", "6765726D616E79");
Found : user_pref("CT1060933.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT1060933.globalFirstTimeInfoLastCheckTime", "Sun Jan 29 2012 19:26:27 GMT+0100");
Found : user_pref("CT1060933.homepageProtectorEnableByLogin", true);
Found : user_pref("CT1060933.initDone", true);
Found : user_pref("CT1060933.isAppTrackingManagerOn", true);
Found : user_pref("CT1060933.isFirstRadioInstallation", false);
Found : user_pref("CT1060933.myStuffEnabled", true);
Found : user_pref("CT1060933.myStuffPublihserMinWidth", 400);
Found : user_pref("CT1060933.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT1060933.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT1060933.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT1060933.revertSettingsEnabled", true);
Found : user_pref("CT1060933.searchProtectorDialogDelayInSec", 10);
Found : user_pref("CT1060933.searchProtectorEnableByLogin", true);
Found : user_pref("CT1060933.testingCtid", "");
Found : user_pref("CT1060933.toolbarAppMetaDataLastCheckTime", "Sun Jan 29 2012 19:26:26 GMT+0100");
Found : user_pref("CT1060933.toolbarContextMenuLastCheckTime", "Sun Jan 29 2012 19:26:27 GMT+0100");
Found : user_pref("CT1060933.usagesFlag", 1);
Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT1060933/CT1060933[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT1060933", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT1060933",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/equaliz[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/minimiz[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play.gi[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/stop.gi[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/vol.gif[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...]
Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Katja\\AppData\\Roaming\\Mozilla\\F[...]
Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.9.0.3");
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
Found : user_pref("CommunityToolbar.ToolbarsList", "CT1060933");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT1060933");
Found : user_pref("CommunityToolbar.ToolbarsList4", "CT1060933");
Found : user_pref("CommunityToolbar.globalUserId", "f61bcc6e-0a5b-45e9-b752-cba96cbf1bd3");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT1060933");
Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sun Jan 29 2012 19:26:2[...]
Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.notifications.locale", "en");
Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Jan 29 2012 19:26:27 GMT+0100");
Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.notifications.userId", "1c1b943b-6135-46c6-96ff-ba72bf316b41");
Found : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.google.de/");
Found : user_pref("CommunityToolbar.originalSearchEngine", "Winload Customized Web Search");
Found : user_pref("browser.search.defaultthis.engineName", "Winload Customized Web Search");
Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&Sea[...]
Found : user_pref("browser.search.selectedEngine", "Winload Customized Web Search");
Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=2&q=[...]

Profile name : default
File : C:\Users\Katja_alles\AppData\Roaming\Mozilla\Firefox\Profiles\wr83doto.default\prefs.js

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [25796 octets] - [23/07/2012 20:57:31]

########## EOF - \AdwCleaner[R1].txt - [25925 octets] ##########


cosinus 24.07.2012 15:17

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

sucnas 24.07.2012 15:29

Anbei die Datei.
Die Avira Toolbar für den Browserschutz wurde auch entfernt. Ist das richtig so?

Code:

# AdwCleaner v1.703 - Logfile created 07/24/2012 at 16:22:01
# Updated 20/07/2012 by Xplode
# Operating system : Windows 7 Professional Service Pack 1 (64 bits)
# User : Katja_alles - MEINGEWINN
# Running from : C:\Users\Katja\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\Katja\AppData\Local\AskToolbar
Folder Deleted : C:\Users\Katja\AppData\Local\Conduit
Folder Deleted : C:\Users\Katja\AppData\Local\Ilivid Player
Folder Deleted : C:\Users\Katja_alles\AppData\Local\AskToolbar
Folder Deleted : C:\Users\Katja\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Katja\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Katja_alles\AppData\LocalLow\AskToolbar
Deleted on reboot : C:\Program Files (x86)\Ask.com
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\Ilivid
Folder Deleted : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
File Deleted : C:\Users\Katja\AppData\Roaming\Mozilla\Firefox\Profiles\nxz5u7io.default\searchplugins\Conduit.xml

***** [Registry] *****
[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1060933
Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\AskToolbar
Key Deleted : HKLM\SOFTWARE\APN
Key Deleted : HKLM\SOFTWARE\AskToolbar
Key Deleted : HKLM\SOFTWARE\bandoo
Key Deleted : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.BandooCore
Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1
Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr
Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1
Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr
Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1
Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr
Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
[x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2D5E2D34-BED5-4B9F-9793-A31E26E6806E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}
[x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC}
[x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12}
[x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}
[x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v14.0.1 (de)

Profile name : default
File : C:\Users\Katja\AppData\Roaming\Mozilla\Firefox\Profiles\nxz5u7io.default\prefs.js

Deleted : user_pref("CT1060933..clientLogIsEnabled", true);
Deleted : user_pref("CT1060933..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT1060933..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT1060933.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Deleted : user_pref("CT1060933.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT1060933.BrowserCompStateIsOpen_129681785283868963", true);
Deleted : user_pref("CT1060933.BrowserCompStateIsOpen_129686665230467549", true);
Deleted : user_pref("CT1060933.CTID", "CT1060933");
Deleted : user_pref("CT1060933.CurrentServerDate", "29-1-2012");
Deleted : user_pref("CT1060933.DSInstall", false);
Deleted : user_pref("CT1060933.DialogsAlignMode", "LTR");
Deleted : user_pref("CT1060933.DialogsGetterLastCheckTime", "Sun Jan 29 2012 19:26:26 GMT+0100");
Deleted : user_pref("CT1060933.DownloadReferralCookieData", "");
Deleted : user_pref("CT1060933.FirstServerDate", "29-1-2012");
Deleted : user_pref("CT1060933.FirstTime", true);
Deleted : user_pref("CT1060933.FirstTimeFF3", true);
Deleted : user_pref("CT1060933.FixPageNotFoundErrors", true);
Deleted : user_pref("CT1060933.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT1060933.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT1060933.HPInstall", false);
Deleted : user_pref("CT1060933.HasUserGlobalKeys", true);
Deleted : user_pref("CT1060933.Initialize", true);
Deleted : user_pref("CT1060933.InitializeCommonPrefs", true);
Deleted : user_pref("CT1060933.InstallationAndCookieDataSentCount", 1);
Deleted : user_pref("CT1060933.InstallationId", "ConduitNSISIntegration");
Deleted : user_pref("CT1060933.InstallationType", "ConduitXPEIntegration");
Deleted : user_pref("CT1060933.InstalledDate", "Sun Jan 29 2012 19:26:26 GMT+0100");
Deleted : user_pref("CT1060933.InvalidateCache", false);
Deleted : user_pref("CT1060933.IsAlertDBUpdated", true);
Deleted : user_pref("CT1060933.IsGrouping", false);
Deleted : user_pref("CT1060933.IsInitSetupIni", true);
Deleted : user_pref("CT1060933.IsMulticommunity", false);
Deleted : user_pref("CT1060933.IsOpenThankYouPage", false);
Deleted : user_pref("CT1060933.IsOpenUninstallPage", true);
Deleted : user_pref("CT1060933.LanguagePackLastCheckTime", "Sun Jan 29 2012 19:26:27 GMT+0100");
Deleted : user_pref("CT1060933.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT1060933.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT1060933.LastLogin_3.9.0.3", "Sun Jan 29 2012 19:26:27 GMT+0100");
Deleted : user_pref("CT1060933.LatestVersion", "3.9.0.3");
Deleted : user_pref("CT1060933.Locale", "en-us");
Deleted : user_pref("CT1060933.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT1060933.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT1060933.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT1060933.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT1060933.OriginalFirstVersion", "3.9.0.3");
Deleted : user_pref("CT1060933.RadioIsPodcast", false);
Deleted : user_pref("CT1060933.RadioLastCheckTime", "Sun Jan 29 2012 19:26:28 GMT+0100");
Deleted : user_pref("CT1060933.RadioLastUpdateIPServer", "0");
Deleted : user_pref("CT1060933.RadioLastUpdateServer", "129326918102570000");
Deleted : user_pref("CT1060933.RadioMediaID", "21504191");
Deleted : user_pref("CT1060933.RadioMediaType", "Media Player");
Deleted : user_pref("CT1060933.RadioMenuSelectedID", "EBRadioMenu_CT106093321504191");
Deleted : user_pref("CT1060933.RadioShrinkedFromSetup", false);
Deleted : user_pref("CT1060933.RadioStationName", "KFOG");
Deleted : user_pref("CT1060933.RadioStationURL", "hxxp://live.cumulusstreaming.com/KFOG-FM");
Deleted : user_pref("CT1060933.SearchCaption", "Freecorder Customized Web Search");
Deleted : user_pref("CT1060933.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT1060933.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT106[...]
Deleted : user_pref("CT1060933.SearchInNewTabEnabled", true);
Deleted : user_pref("CT1060933.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT1060933.SearchInNewTabLastCheckTime", "Sun Jan 29 2012 19:26:28 GMT+0100");
Deleted : user_pref("CT1060933.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT1060933.SendProtectorDataViaLogin", true);
Deleted : user_pref("CT1060933.ServiceMapLastCheckTime", "Sun Jan 29 2012 19:26:25 GMT+0100");
Deleted : user_pref("CT1060933.SettingsLastCheckTime", "Sun Jan 29 2012 19:26:25 GMT+0100");
Deleted : user_pref("CT1060933.SettingsLastUpdate", "1327080122");
Deleted : user_pref("CT1060933.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT1060933&SearchSource=13");
Deleted : user_pref("CT1060933.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT1060933.ThirdPartyComponentsLastCheck", "Sun Jan 29 2012 19:26:25 GMT+0100");
Deleted : user_pref("CT1060933.ThirdPartyComponentsLastUpdate", "1312887586");
Deleted : user_pref("CT1060933.ToolbarShrinkedFromSetup", false);
Deleted : user_pref("CT1060933.TrusteLinkUrl", "hxxp://trust.conduit.com/CT1060933");
Deleted : user_pref("CT1060933.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Deleted : user_pref("CT1060933.UserID", "UN61153422592245393");
Deleted : user_pref("CT1060933.ValidationData_Toolbar", 0);
Deleted : user_pref("CT1060933.alertChannelId", "15651");
Deleted : user_pref("CT1060933.appApproved.129272674122038321", true);
Deleted : user_pref("CT1060933.autoDisableScopes", -1);
Deleted : user_pref("CT1060933.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e.:2z527", "2423");
Deleted : user_pref("CT1060933.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e06cg5el8:", "6E6D6F6B6B6E7472746F");
Deleted : user_pref("CT1060933.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A7473757171747A787A75242F4B4947[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Deleted : user_pref("CT1060933.backendstorage./9b-0?3g>d", "39693C6B703E736D7A42744872204A7D7D7C25202324512A20[...]
Deleted : user_pref("CT1060933.backendstorage./9b-0?3g@6:5;", "");
Deleted : user_pref("CT1060933.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E424[...]
Deleted : user_pref("CT1060933.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Deleted : user_pref("CT1060933.backendstorage./9b3=>@44i48?", "372C2D32697576334236334148477A213F3E484F4E4D464[...]
Deleted : user_pref("CT1060933.backendstorage./9b5ba==9cjag", "396F68703F6E75437A70467479734A4C7A7A507C7B");
Deleted : user_pref("CT1060933.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6F6B6B6E74716E7873777A");
Deleted : user_pref("CT1060933.backendstorage./9b9643g3/9e", "6A");
Deleted : user_pref("CT1060933.backendstorage./9b<:222h64<", "393F352F3E");
Deleted : user_pref("CT1060933.backendstorage./9b=+03eh8h8j?:", "4443");
Deleted : user_pref("CT1060933.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Deleted : user_pref("CT1060933.backendstorage./9b?b0d:8aj62<h", "6D");
Deleted : user_pref("CT1060933.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Deleted : user_pref("CT1060933.backendstorage.autocompletepro_enable_auto", "31");
Deleted : user_pref("CT1060933.backendstorage.shoppingapp.gk.exipres", "4672692046656220303320323031322031393A[...]
Deleted : user_pref("CT1060933.backendstorage.shoppingapp.gk.geolocation", "6765726D616E79");
Deleted : user_pref("CT1060933.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Deleted : user_pref("CT1060933.globalFirstTimeInfoLastCheckTime", "Sun Jan 29 2012 19:26:27 GMT+0100");
Deleted : user_pref("CT1060933.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT1060933.initDone", true);
Deleted : user_pref("CT1060933.isAppTrackingManagerOn", true);
Deleted : user_pref("CT1060933.isFirstRadioInstallation", false);
Deleted : user_pref("CT1060933.myStuffEnabled", true);
Deleted : user_pref("CT1060933.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT1060933.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT1060933.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT1060933.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT1060933.revertSettingsEnabled", true);
Deleted : user_pref("CT1060933.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT1060933.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT1060933.testingCtid", "");
Deleted : user_pref("CT1060933.toolbarAppMetaDataLastCheckTime", "Sun Jan 29 2012 19:26:26 GMT+0100");
Deleted : user_pref("CT1060933.toolbarContextMenuLastCheckTime", "Sun Jan 29 2012 19:26:27 GMT+0100");
Deleted : user_pref("CT1060933.usagesFlag", 1);
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT1060933/CT1060933[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT1060933", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT1060933",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/equaliz[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/minimiz[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play.gi[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/stop.gi[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/vol.gif[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...]
Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Katja\\AppData\\Roaming\\Mozilla\\F[...]
Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.9.0.3");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT1060933");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT1060933");
Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT1060933");
Deleted : user_pref("CommunityToolbar.globalUserId", "f61bcc6e-0a5b-45e9-b752-cba96cbf1bd3");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT1060933");
Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sun Jan 29 2012 19:26:2[...]
Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Jan 29 2012 19:26:27 GMT+0100");
Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.notifications.userId", "1c1b943b-6135-46c6-96ff-ba72bf316b41");
Deleted : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.google.de/");
Deleted : user_pref("CommunityToolbar.originalSearchEngine", "Winload Customized Web Search");
Deleted : user_pref("browser.search.defaultthis.engineName", "Winload Customized Web Search");
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&Sea[...]
Deleted : user_pref("browser.search.selectedEngine", "Winload Customized Web Search");
Deleted : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=2&q=[...]

Profile name : default
File : C:\Users\Katja_alles\AppData\Roaming\Mozilla\Firefox\Profiles\wr83doto.default\prefs.js

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [24234 octets] - [24/07/2012 16:22:01]
AdwCleaner[R1].txt - [25849 octets] - [23/07/2012 20:57:31]

########## EOF - \AdwCleaner[S1].txt - [24424 octets] ##########


cosinus 24.07.2012 20:41

Ja, diesen Browserschutz braucht man nicht und der ist an diese nervige Müll-Toolbar von Ask gekoppelt! :pfui:

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

sucnas 24.07.2012 20:56

zu 1. Windows lief die ganze Zeit ohne Probleme.
Mir stellt sich immer noch die Frage was die Sachen im Infobereich machen und wie sie verschwinden. Sie sind nämlich noch da. Auch wenn die Meldung kommt, dass sie deaktiviert sind.

zu 2. Ich bin nun alle Ordner durch und alle sind mit den entsprechenden Anwendungen gefüllt. Im Moment fällt mir nichts ein was weg sein könnte.

cosinus 24.07.2012 22:03

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


sucnas 24.07.2012 22:49

Hier die Datei.
Die Extras.txt benötigst du nicht?

Code:

OTL logfile created on: 24.07.2012 23:14:34 - Run 1
OTL by OldTimer - Version 3.2.54.1    Folder = C:\Users\Katja\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,86 Gb Total Physical Memory | 2,53 Gb Available Physical Memory | 65,52% Memory free
7,71 Gb Paging File | 6,10 Gb Available in Paging File | 79,16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 116,44 Gb Total Space | 39,23 Gb Free Space | 33,70% Space Free | Partition Type: NTFS
Drive D: | 329,79 Gb Total Space | 324,80 Gb Free Space | 98,49% Space Free | Partition Type: NTFS
 
Computer Name: MEINGEWINN | User Name: Katja_alles | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.07.24 23:12:24 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Katja\Desktop\OTL.exe
PRC - [2012.07.19 06:58:18 | 000,400,352 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
PRC - [2012.06.27 09:25:04 | 000,681,056 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\sua.exe
PRC - [2012.05.23 16:20:18 | 000,364,544 | ---- | M] (Secure Banking) -- C:\Program Files (x86)\Secure Banking\SecureBanking.exe
PRC - [2012.05.09 17:33:59 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.09 17:33:57 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
PRC - [2012.05.09 17:33:57 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.05.09 17:33:57 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.04.04 07:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.01.30 16:17:44 | 000,001,536 | ---- | M] () -- C:\Program Files (x86)\Secure Banking\sbservice.exe
PRC - [2010.12.21 12:53:40 | 001,483,264 | ---- | M] (Nokia) -- C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe
PRC - [2010.12.20 14:05:55 | 003,054,136 | ---- | M] (ASUS) -- C:\Windows\AsScrPro.exe
PRC - [2010.12.08 15:31:06 | 000,628,736 | ---- | M] (Nokia) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
PRC - [2010.05.11 11:16:34 | 000,140,288 | ---- | M] (Nokia) -- C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
PRC - [2009.12.03 11:12:12 | 000,976,320 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
PRC - [2009.11.09 20:20:36 | 000,096,896 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
PRC - [2009.10.27 10:15:02 | 000,120,832 | ---- | M] (Nokia) -- C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2009.10.26 21:29:32 | 006,998,656 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
PRC - [2009.10.26 11:10:42 | 000,174,720 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
PRC - [2009.09.30 20:34:22 | 002,314,240 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009.09.30 20:33:08 | 000,262,144 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009.08.19 21:31:48 | 000,170,624 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
PRC - [2009.06.24 13:30:18 | 000,272,952 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
PRC - [2009.06.19 11:29:42 | 000,105,016 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
PRC - [2009.06.19 11:29:26 | 002,488,888 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
PRC - [2009.06.15 18:30:42 | 000,084,536 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
PRC - [2009.05.14 18:07:14 | 000,759,048 | ---- | M] (ABBYY) -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
PRC - [2008.12.22 18:15:34 | 000,174,648 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
PRC - [2008.03.31 03:55:48 | 000,225,280 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
PRC - [2007.08.03 13:24:54 | 000,125,496 | ---- | M] () -- C:\Programme\ASUS\NB Probe\SPM\spmgr.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.07.19 06:58:21 | 001,936,352 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
MOD - [2012.07.19 06:58:20 | 000,162,784 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\nsldap32v60.dll
MOD - [2012.07.19 06:58:20 | 000,021,984 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\nsldappr32v60.dll
MOD - [2012.05.22 15:10:52 | 000,007,680 | ---- | M] () -- C:\Program Files (x86)\Secure Banking\funcs.dll
MOD - [2012.05.22 15:09:44 | 000,012,800 | ---- | M] () -- C:\Program Files (x86)\Secure Banking\SecureBanking.dll
MOD - [2012.01.30 16:17:44 | 000,001,536 | ---- | M] () -- C:\Program Files (x86)\Secure Banking\sbservice.exe
MOD - [2008.08.12 11:16:16 | 002,023,424 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia PC Suite 7\QtCore4.dll
MOD - [2008.07.29 14:47:56 | 000,016,384 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia PC Suite 7\imageformats\qsvg4.dll
MOD - [2008.07.29 14:47:38 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia PC Suite 7\imageformats\qjpeg4.dll
MOD - [2008.07.29 14:11:18 | 000,253,952 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia PC Suite 7\QtSvg4.dll
MOD - [2008.07.29 14:01:12 | 007,331,840 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia PC Suite 7\QtGUI4.dll
MOD - [2008.07.29 13:50:26 | 000,364,544 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia PC Suite 7\QtXml4.dll
MOD - [2007.06.15 11:28:36 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll
MOD - [2007.06.01 18:08:18 | 000,143,360 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2009.11.27 05:39:46 | 000,243,712 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_38986e29a8b510a2\stacsv64.exe -- (STacSV)
SRV:64bit: - [2009.11.11 10:29:14 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009.09.17 12:36:34 | 000,359,552 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Windows\SysNative\FBAgent.exe -- (AFBAgent)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012.07.20 17:16:13 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.07.17 23:21:08 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.06.27 09:25:06 | 001,326,176 | ---- | M] (Secunia) [On_Demand | Stopped] -- C:\Program Files (x86)\Secunia\PSI\psia.exe -- (Secunia PSI Agent)
SRV - [2012.06.27 09:25:04 | 000,681,056 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2012.05.09 17:33:59 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.09 17:33:57 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService)
SRV - [2012.05.09 17:33:57 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.04.04 07:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010.12.08 15:31:06 | 000,628,736 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.11.27 05:39:46 | 000,243,712 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_38986e29a8b510a2\STacSV64.exe -- (STacSV)
SRV - [2009.11.09 20:20:36 | 000,096,896 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)
SRV - [2009.09.30 20:34:22 | 002,314,240 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009.09.30 20:33:08 | 000,262,144 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009.09.14 05:00:00 | 000,166,400 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Programme\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE -- (EPSON_EB_RPCV4_04)
SRV - [2009.09.14 05:00:00 | 000,128,512 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Programme\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE -- (EPSON_PM_RPCV4_04)
SRV - [2009.06.15 18:30:42 | 000,084,536 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe -- (ASLDRService)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.05.14 18:07:14 | 000,759,048 | ---- | M] (ABBYY) [Auto | Running] -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0)
SRV - [2008.03.31 03:55:48 | 000,225,280 | ---- | M] (ASUSTek Computer Inc.) [On_Demand | Running] -- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe -- (ADSMService)
SRV - [2007.08.03 13:24:54 | 000,125,496 | ---- | M] () [On_Demand | Running] -- C:\Programme\ASUS\NB Probe\SPM\spmgr.exe -- (spmgr)
SRV - [2007.05.31 17:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007.05.31 17:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.05.09 17:33:59 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.05.09 17:33:59 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.12.16 16:20:10 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
DRV:64bit: - [2011.10.27 03:25:42 | 000,177,640 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdm.sys -- (ssadmdm)
DRV:64bit: - [2011.10.27 03:25:42 | 000,157,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus)
DRV:64bit: - [2011.10.27 03:25:42 | 000,016,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV:64bit: - [2011.10.11 15:00:01 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011.08.17 11:04:34 | 000,171,008 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nmwcdnsux64.sys -- (nmwcdnsux64)
DRV:64bit: - [2011.08.17 10:58:26 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys -- (UsbserFilt)
DRV:64bit: - [2011.08.17 10:58:22 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev)
DRV:64bit: - [2011.08.17 10:58:20 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc)
DRV:64bit: - [2011.08.17 10:58:16 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.12.20 14:08:55 | 000,035,384 | ---- | M] (ASUSTek Computer Inc) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\AsDsm.sys -- (AsDsm)
DRV:64bit: - [2010.12.14 19:51:20 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 12:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2010.06.14 10:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TFsExDisk.sys -- (TFsExDisk)
DRV:64bit: - [2009.11.27 05:39:46 | 000,505,344 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2009.11.13 11:47:36 | 000,067,072 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2009.11.11 11:02:12 | 006,104,576 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009.10.15 11:23:20 | 000,117,760 | ---- | M] (ELAN Microelectronic Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2009.10.05 17:34:00 | 001,542,656 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009.09.30 03:34:32 | 000,121,872 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009.09.17 13:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009.08.21 08:48:18 | 000,044,032 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:64bit: - [2009.08.13 09:38:24 | 000,029,184 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcp.sys -- (BthAvrcp)
DRV:64bit: - [2009.08.06 23:24:14 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.07.20 11:29:40 | 000,015,416 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbfiltr.sys -- (kbfiltr)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.22 21:01:16 | 000,132,608 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbnet.sys -- (ewusbnet)
DRV:64bit: - [2009.06.22 20:38:34 | 000,116,992 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:64bit: - [2009.06.22 20:26:40 | 000,113,792 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ewusbdev.sys -- (hwusbdev)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.13 10:07:20 | 000,015,928 | ---- | M] (ASUS) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ATK64AMD.sys -- (MTsensor)
DRV:64bit: - [2008.08.28 12:44:42 | 000,025,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
DRV:64bit: - [2008.05.23 18:27:28 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2010.06.14 10:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009.07.02 18:36:14 | 000,015,416 | ---- | M] (ASUS) [Kernel | Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)
DRV - [2007.08.03 06:26:48 | 000,017,464 | ---- | M] () [Kernel | Auto | Running] -- C:\Programme\ASUS\NB Probe\SPM\ghaio.sys -- (ghaio)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-4249268044-3350026307-1324416323-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-4249268044-3350026307-1324416323-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-4249268044-3350026307-1324416323-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4D 15 D1 64 5C 66 CD 01  [binary data]
IE - HKU\S-1-5-21-4249268044-3350026307-1324416323-1001\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No CLSID value found
IE - HKU\S-1-5-21-4249268044-3350026307-1324416323-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-4249268044-3350026307-1324416323-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-4249268044-3350026307-1324416323-1001\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933
IE - HKU\S-1-5-21-4249268044-3350026307-1324416323-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-4249268044-3350026307-1324416323-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-4249268044-3350026307-1324416323-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files (x86)\Nokia\Nokia PC Suite 7\bkmrksync\ [2011.02.10 22:44:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.07.20 21:42:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.07.20 21:42:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012.07.20 21:42:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
 
[2012.07.21 19:01:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Katja_alles\AppData\Roaming\mozilla\Extensions
[2012.05.04 13:12:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.04.10 16:30:56 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.07.17 23:21:08 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010.08.24 11:31:30 | 000,773,120 | ---- | M] (BitComet) -- C:\Program Files (x86)\mozilla firefox\plugins\npBitCometAgent.dll
[2010.12.20 17:31:56 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010.03.08 12:24:04 | 000,103,168 | ---- | M] (Midasplayer Ltd) -- C:\Program Files (x86)\mozilla firefox\plugins\npmidas.dll
[2011.12.09 19:23:32 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2012.06.18 14:18:31 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.18 14:18:31 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.18 14:18:31 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.18 14:18:31 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.18 14:18:31 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.18 14:18:31 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKU\S-1-5-21-4249268044-3350026307-1324416323-1001\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (AlcorMicro Co., Ltd.)
O4:64bit: - HKLM..\Run: [ETDWare] C:\Programme\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [NPSStartup]  File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-4249268044-3350026307-1324416323-1001..\Run: [EPSON SX525WD Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGAE.EXE /FU "C:\Windows\TEMP\E_S5028.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-4249268044-3350026307-1324416323-1001..\Run: [PC Suite Tray] C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKU\S-1-5-21-4249268044-3350026307-1324416323-1005..\Run: [SecureBanking] C:\Program Files (x86)\Secure Banking\SecureBanking.exe (Secure Banking)
O4 - HKU\S-1-5-21-4249268044-3350026307-1324416323-1005..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [DeleteOnReboot] C:\Windows\DeleteOnReboot.bat ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-4249268044-3350026307-1324416323-1005..\RunOnce: [Report] \AdwCleaner[S1].txt ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000016 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1049382D-DACC-4614-977C-5A719D827664}: DhcpNameServer = 139.7.30.125 139.7.30.126
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{175A031B-1AD6-4DD8-B476-BAB95728D5BB}: DhcpNameServer = 139.7.30.125 139.7.30.126
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AA74FD59-37D6-4691-B427-CBA22E41E5B2}: DhcpNameServer = 139.7.30.125 139.7.30.126
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
 
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Update Agent.lnk - C:\Program Files (x86)\Connect it\Connect it\AutoUpdateSrv.exe - (Birdstep Technology)
MsConfig:64bit - StartUpFolder: C:^Users^Katja^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe - ()
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: ADSMTray - hkey= - key= - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.)
MsConfig:64bit - StartUpReg: APSDaemon - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: ASUS Screen Saver Protector - hkey= - key= - C:\Windows\AsScrPro.exe (ASUS)
MsConfig:64bit - StartUpReg: AutoStartNPSAgent - hkey= - key= - C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
MsConfig:64bit - StartUpReg: Freecorder FLV Service - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: iTunesHelper - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: KiesHelper - hkey= - key= - C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe (Samsung)
MsConfig:64bit - StartUpReg: KiesPDLR - hkey= - key= - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
MsConfig:64bit - StartUpReg: KiesTrayAgent - hkey= - key= - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
MsConfig:64bit - StartUpReg: Logitech Download Assistant - hkey= - key= - C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: WinampAgent - hkey= - key= - C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
MsConfig:64bit - State: "startup" - Reg Error: Key error.
 
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.23 10:09:11 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\sun
[2012.07.21 19:01:43 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Roaming\Mozilla
[2012.07.21 19:01:43 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Local\Mozilla
[2012.07.21 19:00:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.07.20 21:51:03 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4
[2012.07.20 21:50:03 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Roaming\Macromedia
[2012.07.20 21:50:00 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Roaming\Adobe
[2012.07.20 21:41:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012.07.20 21:41:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2012.07.20 21:37:45 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Roaming\Apple Computer
[2012.07.20 21:37:45 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Local\Apple Computer
[2012.07.20 21:28:02 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Local\Secunia PSI
[2012.07.20 21:27:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secunia
[2012.07.20 21:15:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure Banking
[2012.07.20 21:15:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secure Banking
[2012.07.20 21:15:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012.07.20 21:15:12 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2012.07.20 20:16:42 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Roaming\Malwarebytes
[2012.07.20 20:05:34 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Roaming\ATI
[2012.07.20 20:05:34 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Local\ATI
[2012.07.20 20:05:33 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Roaming\Epson
[2012.07.20 20:03:58 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.07.20 20:03:58 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\Searches
[2012.07.20 20:03:58 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.07.20 20:03:48 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Roaming\Identities
[2012.07.20 20:03:44 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\Contacts
[2012.07.20 20:03:11 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Local\VirtualStore
[2012.07.20 20:03:11 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Roaming\PC Suite
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\Vorlagen
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\AppData\Local\Verlauf
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\AppData\Local\Temporary Internet Files
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\Startmenü
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\SendTo
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\Recent
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\Netzwerkumgebung
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\Lokale Einstellungen
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\Documents\Eigene Videos
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\Documents\Eigene Musik
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\Eigene Dateien
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\Documents\Eigene Bilder
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\Druckumgebung
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\Cookies
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\AppData\Local\Anwendungsdaten
[2012.07.20 20:03:06 | 000,000,000 | -HSD | C] -- C:\Users\Katja_alles\Anwendungsdaten
[2012.07.20 20:03:05 | 000,000,000 | --SD | C] -- C:\Users\Katja_alles\AppData\Roaming\Microsoft
[2012.07.20 20:03:05 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\Videos
[2012.07.20 20:03:05 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\Saved Games
[2012.07.20 20:03:05 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\Pictures
[2012.07.20 20:03:05 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\Music
[2012.07.20 20:03:05 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.07.20 20:03:05 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\Links
[2012.07.20 20:03:05 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\Favorites
[2012.07.20 20:03:05 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\Downloads
[2012.07.20 20:03:05 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\Documents
[2012.07.20 20:03:05 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\Desktop
[2012.07.20 20:03:05 | 000,000,000 | R--D | C] -- C:\Users\Katja_alles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.07.20 20:03:05 | 000,000,000 | -H-D | C] -- C:\Users\Katja_alles\AppData
[2012.07.20 20:03:05 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Local\Temp
[2012.07.20 20:03:05 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Local\Microsoft
[2012.07.20 20:03:05 | 000,000,000 | ---D | C] -- C:\Users\Katja_alles\AppData\Roaming\Media Center Programs
[2012.07.20 16:13:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012.07.20 16:13:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Oracle
[2012.07.20 16:05:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2012.07.20 15:58:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.20 15:58:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.20 15:58:07 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.20 15:58:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.24 23:08:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.24 16:31:17 | 000,014,848 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.24 16:31:17 | 000,014,848 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.24 16:30:51 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.07.24 16:30:51 | 000,654,400 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.07.24 16:30:51 | 000,616,242 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.07.24 16:30:51 | 000,130,240 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.07.24 16:30:51 | 000,106,622 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.07.24 16:23:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.24 16:23:17 | 3105,259,520 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.24 16:22:27 | 000,000,098 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2012.07.24 08:35:22 | 000,001,902 | ---- | M] () -- C:\Windows\SysNative\AutoRunFilter.ini
[2012.07.20 22:05:11 | 000,001,849 | ---- | M] () -- C:\Windows\SysNative\ServiceFilter.ini
[2012.07.20 22:04:20 | 000,293,472 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.07.20 19:59:07 | 000,045,056 | ---- | M] () -- C:\Windows\SysNative\acovcnt.exe
[2012.07.20 17:24:22 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.07.20 17:24:18 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2012.07.20 15:58:11 | 000,001,075 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
 
========== Files Created - No Company Name ==========
 
[2012.07.24 16:22:12 | 000,000,098 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2012.07.20 21:27:03 | 000,001,035 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012.07.20 20:04:47 | 000,001,411 | ---- | C] () -- C:\Users\Katja_alles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012.07.20 20:04:01 | 000,001,405 | ---- | C] () -- C:\Users\Katja_alles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.07.20 17:24:22 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.07.20 17:24:18 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2012.07.20 17:16:15 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.20 15:58:11 | 000,001,075 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.02.03 23:40:06 | 000,000,010 | ---- | C] () -- C:\Windows\popcinfo.dat
[2011.04.12 21:48:59 | 000,032,608 | ---- | C] () -- C:\Windows\king-uninstall.exe
[2011.03.03 00:57:44 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2011.03.03 00:57:40 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2011.03.03 00:57:40 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2011.03.03 00:57:40 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2011.03.03 00:57:40 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2010.12.20 14:07:04 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\LogonStart.dll
[2010.12.20 13:53:58 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
 
========== LOP Check ==========
 
[2011.01.28 21:40:22 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\Amazon
[2011.02.02 20:43:48 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\becker
[2011.08.28 14:36:45 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\Birdstep Technology
[2011.12.31 22:32:11 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\BitComet
[2011.07.30 20:28:56 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\calibre
[2011.04.26 17:05:44 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\Canneverbe Limited
[2011.04.17 15:09:45 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\Epson
[2012.07.20 17:00:48 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\FileZilla
[2012.07.16 22:29:31 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\gtk-2.0
[2012.04.26 18:16:17 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\Mouse Recorder Pro
[2011.08.29 13:13:52 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\Nokia
[2011.01.19 17:36:30 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\Notepad++
[2010.12.20 17:43:04 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\OpenOffice.org
[2011.08.29 13:09:24 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\PC Suite
[2011.12.25 02:20:27 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\Samsung
[2011.12.25 02:39:04 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\Temp
[2010.12.20 16:40:00 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\Thunderbird
[2011.10.25 20:47:01 | 000,000,000 | ---D | M] -- C:\Users\Katja\AppData\Roaming\XMedia Recode
[2012.07.20 20:05:33 | 000,000,000 | ---D | M] -- C:\Users\Katja_alles\AppData\Roaming\Epson
[2012.07.20 20:03:11 | 000,000,000 | ---D | M] -- C:\Users\Katja_alles\AppData\Roaming\PC Suite
[2012.06.16 09:15:43 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.07.20 21:50:00 | 000,000,000 | ---D | M] -- C:\Users\Katja_alles\AppData\Roaming\Adobe
[2012.07.20 21:37:45 | 000,000,000 | ---D | M] -- C:\Users\Katja_alles\AppData\Roaming\Apple Computer
[2012.07.20 20:05:34 | 000,000,000 | ---D | M] -- C:\Users\Katja_alles\AppData\Roaming\ATI
[2012.07.20 20:05:33 | 000,000,000 | ---D | M] -- C:\Users\Katja_alles\AppData\Roaming\Epson
[2012.07.20 20:03:48 | 000,000,000 | ---D | M] -- C:\Users\Katja_alles\AppData\Roaming\Identities
[2012.07.20 21:50:03 | 000,000,000 | ---D | M] -- C:\Users\Katja_alles\AppData\Roaming\Macromedia
[2012.07.20 20:16:42 | 000,000,000 | ---D | M] -- C:\Users\Katja_alles\AppData\Roaming\Malwarebytes
[2009.07.14 20:18:34 | 000,000,000 | ---D | M] -- C:\Users\Katja_alles\AppData\Roaming\Media Center Programs
[2012.07.20 20:07:09 | 000,000,000 | --SD | M] -- C:\Users\Katja_alles\AppData\Roaming\Microsoft
[2012.07.21 19:01:48 | 000,000,000 | ---D | M] -- C:\Users\Katja_alles\AppData\Roaming\Mozilla
[2012.07.20 20:03:11 | 000,000,000 | ---D | M] -- C:\Users\Katja_alles\AppData\Roaming\PC Suite
 
< %APPDATA%\*.exe /s >
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2009.08.06 23:24:14 | 000,408,600 | ---- | M] (Intel Corporation) MD5=BBB3B6DF1ABB0FE35802EDE85CC1C011 -- C:\Windows\SysNative\drivers\iaStor.sys
[2009.08.06 23:24:14 | 000,408,600 | ---- | M] (Intel Corporation) MD5=BBB3B6DF1ABB0FE35802EDE85CC1C011 -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_4fa22a1c88c09097\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2009.05.26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\Katja\AppData\Local\Temp\RarSFX0\userinit.exe
[2009.05.26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\Katja\AppData\Local\Temp\RarSFX1\userinit.exe
[2009.05.26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\Katja\AppData\Local\Temp\RarSFX2\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.07.03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.05.26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\Katja\AppData\Local\Temp\RarSFX0\winlogon.exe
[2009.05.26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\Katja\AppData\Local\Temp\RarSFX1\winlogon.exe
[2009.05.26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\Katja\AppData\Local\Temp\RarSFX2\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 217 bytes -> C:\ProgramData\TEMP:A1D3FEF0

< End of report >


cosinus 25.07.2012 09:35

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE - HKU\S-1-5-21-4249268044-3350026307-1324416323-1001\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933
FF - user.js - File not found
O3 - HKU\S-1-5-21-4249268044-3350026307-1324416323-1001\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\RunOnce: [DeleteOnReboot] C:\Windows\DeleteOnReboot.bat ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-4249268044-3350026307-1324416323-1005..\RunOnce: [Report] \AdwCleaner[S1].txt ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
@Alternate Data Stream - 217 bytes -> C:\ProgramData\TEMP:A1D3FEF0
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

sucnas 25.07.2012 10:35

Code:

All processes killed
========== OTL ==========
Registry key HKEY_USERS\S-1-5-21-4249268044-3350026307-1324416323-1001\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry value HKEY_USERS\S-1-5-21-4249268044-3350026307-1324416323-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\DeleteOnReboot deleted successfully.
C:\Windows\DeleteOnReboot.bat moved successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-21-4249268044-3350026307-1324416323-1005\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Report deleted successfully.
File move failed. \AdwCleaner[S1].txt scheduled to be moved on reboot.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
ADS C:\ProgramData\TEMP:A1D3FEF0 deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 80055 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Katja
->Temp folder emptied: 590421076 bytes
->Temporary Internet Files folder emptied: 121868435 bytes
->Java cache emptied: 578035 bytes
->FireFox cache emptied: 834387652 bytes
->Flash cache emptied: 121336 bytes
 
User: Katja_alles
->Temp folder emptied: 434948922 bytes
->Temporary Internet Files folder emptied: 8431453 bytes
->FireFox cache emptied: 54956072 bytes
->Flash cache emptied: 321 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 363354886 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67832 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 558 bytes
RecycleBin emptied: 4720 bytes
 
Total Files Cleaned = 2.298,00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
 
User: Default User
 
User: Katja
->Flash cache emptied: 0 bytes
 
User: Katja_alles
->Flash cache emptied: 0 bytes
 
User: Public
 
Total Flash Files Cleaned = 0,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.54.1 log created on 07252012_111634

Files\Folders moved on Reboot...
File move failed. \AdwCleaner[S1].txt scheduled to be moved on reboot.
File move failed. C:\Users\Katja\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.

PendingFileRenameOperations files...
[2012.07.24 16:22:27 | 000,024,400 | ---- | M] () \AdwCleaner[S1].txt : MD5=A6D08C47BFB577531DA61CCEC58260DA
[2010.12.20 13:31:04 | 000,000,000 | ---- | M] () C:\Users\Katja\AppData\Local\Temp\FXSAPIDebugLogFile.txt : Unable to obtain MD5

Registry entries deleted on Reboot...


cosinus 25.07.2012 11:34

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

sucnas 25.07.2012 12:06

Code:

13:01:37.0688 3960        TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
13:01:39.0703 3960        ============================================================
13:01:39.0703 3960        Current date / time: 2012/07/25 13:01:39.0703
13:01:39.0703 3960        SystemInfo:
13:01:39.0703 3960       
13:01:39.0703 3960        OS Version: 6.1.7601 ServicePack: 1.0
13:01:39.0703 3960        Product type: Workstation
13:01:39.0703 3960        ComputerName: MEINGEWINN
13:01:39.0703 3960        UserName: Katja_alles
13:01:39.0703 3960        Windows directory: C:\Windows
13:01:39.0703 3960        System windows directory: C:\Windows
13:01:39.0703 3960        Running under WOW64
13:01:39.0703 3960        Processor architecture: Intel x64
13:01:39.0703 3960        Number of processors: 4
13:01:39.0703 3960        Page size: 0x1000
13:01:39.0703 3960        Boot type: Normal boot
13:01:39.0703 3960        ============================================================
13:01:40.0840 3960        Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:01:40.0858 3960        ============================================================
13:01:40.0859 3960        \Device\Harddisk0\DR0:
13:01:40.0859 3960        MBR partitions:
13:01:40.0859 3960        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x2711676, BlocksNum 0xE8E0168
13:01:40.0889 3960        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x10FF2000, BlocksNum 0x29393800
13:01:40.0890 3960        ============================================================
13:01:40.0920 3960        C: <-> \Device\Harddisk0\DR0\Partition0
13:01:41.0029 3960        D: <-> \Device\Harddisk0\DR0\Partition1
13:01:41.0029 3960        ============================================================
13:01:41.0029 3960        Initialize success
13:01:41.0029 3960        ============================================================
13:02:12.0842 5592        ============================================================
13:02:12.0843 5592        Scan started
13:02:12.0843 5592        Mode: Manual; SigCheck; TDLFS;
13:02:12.0843 5592        ============================================================
13:02:13.0332 5592        1394ohci        (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
13:02:13.0601 5592        1394ohci - ok
13:02:13.0765 5592        ABBYY.Licensing.FineReader.Sprint.9.0 (b33cf4de909a5b30f526d82053a63c8e) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
13:02:13.0849 5592        ABBYY.Licensing.FineReader.Sprint.9.0 - ok
13:02:13.0923 5592        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
13:02:13.0972 5592        ACPI - ok
13:02:14.0005 5592        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
13:02:14.0124 5592        AcpiPmi - ok
13:02:14.0209 5592        AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
13:02:14.0229 5592        AdobeARMservice - ok
13:02:14.0345 5592        AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
13:02:14.0374 5592        AdobeFlashPlayerUpdateSvc - ok
13:02:14.0445 5592        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
13:02:14.0510 5592        adp94xx - ok
13:02:14.0563 5592        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
13:02:14.0613 5592        adpahci - ok
13:02:14.0660 5592        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
13:02:14.0690 5592        adpu320 - ok
13:02:14.0808 5592        ADSMService    (c0bf554d2277f7a4c735d475ade2e3b2) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
13:02:14.0857 5592        ADSMService ( UnsignedFile.Multi.Generic ) - warning
13:02:14.0857 5592        ADSMService - detected UnsignedFile.Multi.Generic (1)
13:02:14.0890 5592        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
13:02:15.0096 5592        AeLookupSvc - ok
13:02:15.0174 5592        AFBAgent        (fb2be0bae9b3f248080cdbf91ef16c7f) C:\Windows\system32\FBAgent.exe
13:02:15.0382 5592        AFBAgent - ok
13:02:15.0445 5592        AFD            (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
13:02:15.0550 5592        AFD - ok
13:02:15.0586 5592        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
13:02:15.0615 5592        agp440 - ok
13:02:15.0677 5592        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
13:02:15.0754 5592        ALG - ok
13:02:15.0786 5592        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
13:02:15.0809 5592        aliide - ok
13:02:15.0860 5592        AMD External Events Utility (46693222fcdb3175aaaed017eaa6fcc7) C:\Windows\system32\atiesrxx.exe
13:02:15.0945 5592        AMD External Events Utility - ok
13:02:15.0989 5592        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
13:02:16.0015 5592        amdide - ok
13:02:16.0040 5592        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
13:02:16.0079 5592        AmdK8 - ok
13:02:16.0101 5592        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
13:02:16.0148 5592        AmdPPM - ok
13:02:16.0187 5592        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
13:02:16.0217 5592        amdsata - ok
13:02:16.0257 5592        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
13:02:16.0297 5592        amdsbs - ok
13:02:16.0335 5592        amdxata        (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
13:02:16.0360 5592        amdxata - ok
13:02:16.0413 5592        AmUStor        (9c7f164b49cadc658d1b3c575782f346) C:\Windows\system32\drivers\AmUStor.SYS
13:02:16.0485 5592        AmUStor - ok
13:02:16.0592 5592        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
13:02:16.0627 5592        AntiVirSchedulerService - ok
13:02:16.0678 5592        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
13:02:16.0702 5592        AntiVirService - ok
13:02:16.0774 5592        AntiVirWebService (676894fa57b671fec5c3f05f8929e03b) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
13:02:16.0825 5592        AntiVirWebService - ok
13:02:16.0891 5592        AppID          (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
13:02:17.0107 5592        AppID - ok
13:02:17.0141 5592        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
13:02:17.0250 5592        AppIDSvc - ok
13:02:17.0299 5592        Appinfo        (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
13:02:17.0409 5592        Appinfo - ok
13:02:17.0504 5592        Apple Mobile Device (f401929ee0cc92bfe7f15161ca535383) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
13:02:17.0583 5592        Apple Mobile Device - ok
13:02:17.0626 5592        AppMgmt        (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll
13:02:17.0696 5592        AppMgmt - ok
13:02:17.0740 5592        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
13:02:17.0769 5592        arc - ok
13:02:17.0801 5592        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
13:02:17.0831 5592        arcsas - ok
13:02:17.0855 5592        AsDsm          (88fbc8bebfd38566235eaa5e4dbc4e05) C:\Windows\system32\drivers\AsDsm.sys
13:02:17.0878 5592        AsDsm - ok
13:02:17.0935 5592        ASLDRService    (18e5c2f937f9deb8c282df66a3761925) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
13:02:17.0958 5592        ASLDRService - ok
13:02:17.0975 5592        ASMMAP64        (4c016fd76ed5c05e84ca8cab77993961) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys
13:02:18.0003 5592        ASMMAP64 - ok
13:02:18.0026 5592        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
13:02:18.0144 5592        AsyncMac - ok
13:02:18.0198 5592        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
13:02:18.0224 5592        atapi - ok
13:02:18.0344 5592        athr            (0acc06fcf46f64ed4f11e57ee461c1f4) C:\Windows\system32\DRIVERS\athrx.sys
13:02:18.0489 5592        athr - ok
13:02:18.0671 5592        AtiHdmiService  (fb7602c5c508be281368aae0b61b51c6) C:\Windows\system32\drivers\AtiHdmi.sys
13:02:18.0698 5592        AtiHdmiService - ok
13:02:19.0150 5592        atikmdag        (99c262242a279976206ece1d3c74df27) C:\Windows\system32\DRIVERS\atikmdag.sys
13:02:19.0481 5592        atikmdag - ok
13:02:19.0576 5592        ATKGFNEXSrv    (63f1212ffe13e62ca1e8d8ee19abd9a7) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
13:02:19.0600 5592        ATKGFNEXSrv - ok
13:02:19.0768 5592        AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
13:02:19.0915 5592        AudioEndpointBuilder - ok
13:02:19.0926 5592        AudioSrv        (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
13:02:20.0019 5592        AudioSrv - ok
13:02:20.0102 5592        avgntflt        (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys
13:02:20.0124 5592        avgntflt - ok
13:02:20.0187 5592        avipbb          (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys
13:02:20.0213 5592        avipbb - ok
13:02:20.0239 5592        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
13:02:20.0259 5592        avkmgr - ok
13:02:20.0316 5592        AxInstSV        (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
13:02:20.0424 5592        AxInstSV - ok
13:02:20.0484 5592        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
13:02:20.0563 5592        b06bdrv - ok
13:02:20.0612 5592        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
13:02:20.0687 5592        b57nd60a - ok
13:02:20.0748 5592        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
13:02:20.0815 5592        BDESVC - ok
13:02:20.0860 5592        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
13:02:20.0972 5592        Beep - ok
13:02:21.0060 5592        BFE            (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
13:02:21.0188 5592        BFE - ok
13:02:21.0275 5592        BITS            (1ea7969e3271cbc59e1730697dc74682) C:\Windows\System32\qmgr.dll
13:02:21.0551 5592        BITS - ok
13:02:21.0604 5592        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
13:02:21.0641 5592        blbdrive - ok
13:02:21.0758 5592        Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
13:02:21.0812 5592        Bonjour Service - ok
13:02:21.0860 5592        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
13:02:21.0912 5592        bowser - ok
13:02:21.0951 5592        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:02:22.0029 5592        BrFiltLo - ok
13:02:22.0041 5592        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:02:22.0075 5592        BrFiltUp - ok
13:02:22.0127 5592        Browser        (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
13:02:22.0240 5592        Browser - ok
13:02:22.0272 5592        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
13:02:22.0339 5592        Brserid - ok
13:02:22.0361 5592        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
13:02:22.0405 5592        BrSerWdm - ok
13:02:22.0439 5592        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
13:02:22.0478 5592        BrUsbMdm - ok
13:02:22.0496 5592        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
13:02:22.0547 5592        BrUsbSer - ok
13:02:22.0584 5592        BthAvrcp        (832b121e4532919cc49f2438f1dcaa21) C:\Windows\system32\DRIVERS\BthAvrcp.sys
13:02:22.0641 5592        BthAvrcp - ok
13:02:22.0699 5592        BthEnum        (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\DRIVERS\BthEnum.sys
13:02:22.0761 5592        BthEnum - ok
13:02:22.0780 5592        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
13:02:22.0828 5592        BTHMODEM - ok
13:02:22.0867 5592        BthPan          (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
13:02:22.0921 5592        BthPan - ok
13:02:23.0019 5592        BTHPORT        (64c198198501f7560ee41d8d1efa7952) C:\Windows\system32\Drivers\BTHport.sys
13:02:23.0122 5592        BTHPORT - ok
13:02:23.0163 5592        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
13:02:23.0273 5592        bthserv - ok
13:02:23.0312 5592        BTHUSB          (f188b7394d81010767b6df3178519a37) C:\Windows\system32\Drivers\BTHUSB.sys
13:02:23.0358 5592        BTHUSB - ok
13:02:23.0394 5592        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
13:02:23.0503 5592        cdfs - ok
13:02:23.0560 5592        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
13:02:23.0604 5592        cdrom - ok
13:02:23.0665 5592        CertPropSvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
13:02:23.0780 5592        CertPropSvc - ok
13:02:23.0822 5592        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
13:02:23.0877 5592        circlass - ok
13:02:23.0933 5592        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
13:02:23.0983 5592        CLFS - ok
13:02:24.0043 5592        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:02:24.0066 5592        clr_optimization_v2.0.50727_32 - ok
13:02:24.0126 5592        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
13:02:24.0148 5592        clr_optimization_v2.0.50727_64 - ok
13:02:24.0227 5592        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:02:24.0252 5592        clr_optimization_v4.0.30319_32 - ok
13:02:24.0298 5592        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
13:02:24.0322 5592        clr_optimization_v4.0.30319_64 - ok
13:02:24.0353 5592        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
13:02:24.0396 5592        CmBatt - ok
13:02:24.0424 5592        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
13:02:24.0451 5592        cmdide - ok
13:02:24.0518 5592        CNG            (9ac4f97c2d3e93367e2148ea940cd2cd) C:\Windows\system32\Drivers\cng.sys
13:02:24.0614 5592        CNG - ok
13:02:24.0647 5592        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
13:02:24.0673 5592        Compbatt - ok
13:02:24.0704 5592        CompositeBus    (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
13:02:24.0758 5592        CompositeBus - ok
13:02:24.0773 5592        COMSysApp - ok
13:02:24.0796 5592        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
13:02:24.0822 5592        crcdisk - ok
13:02:24.0867 5592        CryptSvc        (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll
13:02:24.0920 5592        CryptSvc - ok
13:02:24.0981 5592        CSC            (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
13:02:25.0071 5592        CSC - ok
13:02:25.0193 5592        CscService      (3ab183ab4d2c79dcf459cd2c1266b043) C:\Windows\System32\cscsvc.dll
13:02:25.0250 5592        CscService - ok
13:02:25.0308 5592        DcomLaunch      (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
13:02:25.0455 5592        DcomLaunch - ok
13:02:25.0507 5592        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
13:02:25.0632 5592        defragsvc - ok
13:02:25.0698 5592        DfsC            (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
13:02:25.0808 5592        DfsC - ok
13:02:25.0870 5592        Dhcp            (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
13:02:25.0993 5592        Dhcp - ok
13:02:26.0019 5592        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
13:02:26.0117 5592        discache - ok
13:02:26.0159 5592        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
13:02:26.0185 5592        Disk - ok
13:02:26.0226 5592        Dnscache        (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
13:02:26.0295 5592        Dnscache - ok
13:02:26.0339 5592        dot3svc        (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
13:02:26.0469 5592        dot3svc - ok
13:02:26.0503 5592        DPS            (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
13:02:26.0620 5592        DPS - ok
13:02:26.0660 5592        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
13:02:26.0696 5592        drmkaud - ok
13:02:26.0789 5592        DXGKrnl        (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
13:02:26.0876 5592        DXGKrnl - ok
13:02:26.0918 5592        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
13:02:27.0031 5592        EapHost - ok
13:02:27.0233 5592        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
13:02:27.0398 5592        ebdrv - ok
13:02:27.0526 5592        EFS            (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
13:02:27.0586 5592        EFS - ok
13:02:27.0691 5592        ehRecvr        (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
13:02:27.0785 5592        ehRecvr - ok
13:02:27.0821 5592        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
13:02:27.0864 5592        ehSched - ok
13:02:27.0996 5592        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
13:02:28.0055 5592        elxstor - ok
13:02:28.0154 5592        EPSON_EB_RPCV4_04 (7db097f4f6786307168c0dddec43a565) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
13:02:28.0207 5592        EPSON_EB_RPCV4_04 - ok
13:02:28.0248 5592        EPSON_PM_RPCV4_04 (258aa65a0862e19b7de6981fda3758ad) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
13:02:28.0285 5592        EPSON_PM_RPCV4_04 - ok
13:02:28.0316 5592        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
13:02:28.0353 5592        ErrDev - ok
13:02:28.0417 5592        ETD            (3c38648375b7f3988691f53a7aae10a9) C:\Windows\system32\DRIVERS\ETD.sys
13:02:28.0460 5592        ETD - ok
13:02:28.0511 5592        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
13:02:28.0648 5592        EventSystem - ok
13:02:28.0693 5592        ewusbnet        (53913561a7089c9a4649ce4e42f6101b) C:\Windows\system32\DRIVERS\ewusbnet.sys
13:02:28.0734 5592        ewusbnet - ok
13:02:28.0770 5592        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
13:02:28.0867 5592        exfat - ok
13:02:28.0894 5592        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
13:02:29.0003 5592        fastfat - ok
13:02:29.0086 5592        Fax            (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
13:02:29.0154 5592        Fax - ok
13:02:29.0177 5592        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
13:02:29.0216 5592        fdc - ok
13:02:29.0259 5592        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
13:02:29.0359 5592        fdPHost - ok
13:02:29.0380 5592        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
13:02:29.0474 5592        FDResPub - ok
13:02:29.0513 5592        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
13:02:29.0537 5592        FileInfo - ok
13:02:29.0551 5592        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
13:02:29.0633 5592        Filetrace - ok
13:02:29.0661 5592        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
13:02:29.0700 5592        flpydisk - ok
13:02:29.0745 5592        FltMgr          (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
13:02:29.0789 5592        FltMgr - ok
13:02:29.0884 5592        FontCache      (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
13:02:29.0997 5592        FontCache - ok
13:02:30.0080 5592        FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
13:02:30.0100 5592        FontCache3.0.0.0 - ok
13:02:30.0147 5592        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
13:02:30.0176 5592        FsDepends - ok
13:02:30.0201 5592        Fs_Rec          (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
13:02:30.0227 5592        Fs_Rec - ok
13:02:30.0282 5592        fvevol          (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
13:02:30.0329 5592        fvevol - ok
13:02:30.0350 5592        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
13:02:30.0379 5592        gagp30kx - ok
13:02:30.0474 5592        ghaio          (7d66ebde8b7f9b4e00beefeee82670d4) C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys
13:02:30.0497 5592        ghaio - ok
13:02:30.0579 5592        gpsvc          (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
13:02:30.0720 5592        gpsvc - ok
13:02:30.0752 5592        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
13:02:30.0809 5592        hcw85cir - ok
13:02:30.0878 5592        HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
13:02:30.0946 5592        HdAudAddService - ok
13:02:30.0996 5592        HDAudBus        (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
13:02:31.0053 5592        HDAudBus - ok
13:02:31.0101 5592        HECIx64        (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
13:02:31.0125 5592        HECIx64 - ok
13:02:31.0147 5592        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
13:02:31.0193 5592        HidBatt - ok
13:02:31.0219 5592        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
13:02:31.0273 5592        HidBth - ok
13:02:31.0300 5592        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
13:02:31.0337 5592        HidIr - ok
13:02:31.0362 5592        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
13:02:31.0474 5592        hidserv - ok
13:02:31.0525 5592        HidUsb          (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
13:02:31.0551 5592        HidUsb - ok
13:02:31.0592 5592        hkmsvc          (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
13:02:31.0703 5592        hkmsvc - ok
13:02:31.0767 5592        HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
13:02:31.0840 5592        HomeGroupListener - ok
13:02:31.0887 5592        HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
13:02:31.0953 5592        HomeGroupProvider - ok
13:02:31.0998 5592        HpSAMD          (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
13:02:32.0027 5592        HpSAMD - ok
13:02:32.0111 5592        HTTP            (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
13:02:32.0250 5592        HTTP - ok
13:02:32.0317 5592        hwdatacard      (d96a290f699081ae737390c0fe329d7c) C:\Windows\system32\DRIVERS\ewusbmdm.sys
13:02:32.0373 5592        hwdatacard - ok
13:02:32.0401 5592        hwpolicy        (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
13:02:32.0426 5592        hwpolicy - ok
13:02:32.0456 5592        hwusbdev        (e0c7255498640fc64b19aae17fd6f965) C:\Windows\system32\DRIVERS\ewusbdev.sys
13:02:32.0513 5592        hwusbdev - ok
13:02:32.0592 5592        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
13:02:32.0624 5592        i8042prt - ok
13:02:32.0671 5592        iaStor          (bbb3b6df1abb0fe35802ede85cc1c011) C:\Windows\system32\DRIVERS\iaStor.sys
13:02:32.0706 5592        iaStor - ok
13:02:32.0757 5592        iaStorV        (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
13:02:32.0812 5592        iaStorV - ok
13:02:32.0953 5592        idsvc          (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
13:02:33.0046 5592        idsvc - ok
13:02:33.0076 5592        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
13:02:33.0104 5592        iirsp - ok
13:02:33.0190 5592        IKEEXT          (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
13:02:33.0329 5592        IKEEXT - ok
13:02:33.0357 5592        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
13:02:33.0383 5592        intelide - ok
13:02:33.0413 5592        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
13:02:33.0457 5592        intelppm - ok
13:02:33.0504 5592        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
13:02:33.0617 5592        IPBusEnum - ok
13:02:33.0669 5592        IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:02:33.0764 5592        IpFilterDriver - ok
13:02:33.0862 5592        iphlpsvc        (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll
13:02:33.0977 5592        iphlpsvc - ok
13:02:34.0013 5592        IPMIDRV        (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
13:02:34.0062 5592        IPMIDRV - ok
13:02:34.0094 5592        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
13:02:34.0206 5592        IPNAT - ok
13:02:34.0227 5592        ipswuio - ok
13:02:34.0251 5592        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
13:02:34.0351 5592        IRENUM - ok
13:02:34.0403 5592        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
13:02:34.0429 5592        isapnp - ok
13:02:34.0476 5592        iScsiPrt        (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
13:02:34.0528 5592        iScsiPrt - ok
13:02:34.0547 5592        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
13:02:34.0575 5592        kbdclass - ok
13:02:34.0594 5592        kbdhid          (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
13:02:34.0625 5592        kbdhid - ok
13:02:34.0658 5592        kbfiltr        (e63ef8c3271d014f14e2469ce75fecb4) C:\Windows\system32\DRIVERS\kbfiltr.sys
13:02:34.0679 5592        kbfiltr - ok
13:02:34.0701 5592        KeyIso          (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:02:34.0727 5592        KeyIso - ok
13:02:34.0759 5592        KSecDD          (97a7070aea4c058b6418519e869a63b4) C:\Windows\system32\Drivers\ksecdd.sys
13:02:34.0786 5592        KSecDD - ok
13:02:34.0820 5592        KSecPkg        (26c43a7c2862447ec59deda188d1da07) C:\Windows\system32\Drivers\ksecpkg.sys
13:02:34.0849 5592        KSecPkg - ok
13:02:34.0875 5592        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
13:02:34.0982 5592        ksthunk - ok
13:02:35.0029 5592        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
13:02:35.0146 5592        KtmRm - ok
13:02:35.0187 5592        L1C            (9c46a5421de9d116c47155317cabb522) C:\Windows\system32\DRIVERS\L1C62x64.sys
13:02:35.0238 5592        L1C - ok
13:02:35.0307 5592        LanmanServer    (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll
13:02:35.0458 5592        LanmanServer - ok
13:02:35.0497 5592        LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
13:02:35.0635 5592        LanmanWorkstation - ok
13:02:35.0691 5592        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
13:02:35.0802 5592        lltdio - ok
13:02:35.0853 5592        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
13:02:35.0971 5592        lltdsvc - ok
13:02:36.0005 5592        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
13:02:36.0090 5592        lmhosts - ok
13:02:36.0177 5592        LMS            (a1c148801b4af64847aeb9f3ad9594ef) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
13:02:36.0209 5592        LMS ( UnsignedFile.Multi.Generic ) - warning
13:02:36.0209 5592        LMS - detected UnsignedFile.Multi.Generic (1)
13:02:36.0241 5592        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
13:02:36.0268 5592        LSI_FC - ok
13:02:36.0293 5592        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
13:02:36.0319 5592        LSI_SAS - ok
13:02:36.0334 5592        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:02:36.0359 5592        LSI_SAS2 - ok
13:02:36.0385 5592        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:02:36.0413 5592        LSI_SCSI - ok
13:02:36.0451 5592        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
13:02:36.0547 5592        luafv - ok
13:02:36.0585 5592        Mcx2Svc        (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
13:02:36.0627 5592        Mcx2Svc - ok
13:02:36.0655 5592        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
13:02:36.0679 5592        megasas - ok
13:02:36.0715 5592        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
13:02:36.0767 5592        MegaSR - ok
13:02:36.0797 5592        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
13:02:36.0910 5592        MMCSS - ok
13:02:36.0929 5592        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
13:02:37.0038 5592        Modem - ok
13:02:37.0081 5592        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
13:02:37.0137 5592        monitor - ok
13:02:37.0186 5592        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
13:02:37.0213 5592        mouclass - ok
13:02:37.0241 5592        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
13:02:37.0281 5592        mouhid - ok
13:02:37.0315 5592        mountmgr        (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
13:02:37.0344 5592        mountmgr - ok
13:02:37.0432 5592        MozillaMaintenance (46297fa8e30a6007f14118fc2b942fbc) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
13:02:37.0458 5592        MozillaMaintenance - ok
13:02:37.0489 5592        mpio            (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
13:02:37.0520 5592        mpio - ok
13:02:37.0552 5592        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
13:02:37.0636 5592        mpsdrv - ok
13:02:37.0721 5592        MpsSvc          (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll
13:02:37.0850 5592        MpsSvc - ok
13:02:37.0894 5592        MRxDAV          (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
13:02:37.0950 5592        MRxDAV - ok
13:02:37.0986 5592        mrxsmb          (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:02:38.0054 5592        mrxsmb - ok
13:02:38.0089 5592        mrxsmb10        (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:02:38.0153 5592        mrxsmb10 - ok
13:02:38.0178 5592        mrxsmb20        (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:02:38.0208 5592        mrxsmb20 - ok
13:02:38.0237 5592        msahci          (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
13:02:38.0264 5592        msahci - ok
13:02:38.0300 5592        msdsm          (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
13:02:38.0331 5592        msdsm - ok
13:02:38.0367 5592        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
13:02:38.0423 5592        MSDTC - ok
13:02:38.0470 5592        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
13:02:38.0561 5592        Msfs - ok
13:02:38.0595 5592        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
13:02:38.0701 5592        mshidkmdf - ok
13:02:38.0730 5592        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
13:02:38.0753 5592        msisadrv - ok
13:02:38.0787 5592        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
13:02:38.0902 5592        MSiSCSI - ok
13:02:38.0906 5592        msiserver - ok
13:02:38.0948 5592        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
13:02:39.0055 5592        MSKSSRV - ok
13:02:39.0088 5592        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
13:02:39.0192 5592        MSPCLOCK - ok
13:02:39.0214 5592        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
13:02:39.0322 5592        MSPQM - ok
13:02:39.0376 5592        MsRPC          (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
13:02:39.0429 5592        MsRPC - ok
13:02:39.0459 5592        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
13:02:39.0486 5592        mssmbios - ok
13:02:39.0509 5592        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
13:02:39.0600 5592        MSTEE - ok
13:02:39.0613 5592        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
13:02:39.0651 5592        MTConfig - ok
13:02:39.0696 5592        MTsensor        (032d35c996f21d19a205a7c8f0b76f3c) C:\Windows\system32\DRIVERS\ATK64AMD.sys
13:02:39.0714 5592        MTsensor - ok
13:02:39.0729 5592        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
13:02:39.0754 5592        Mup - ok
13:02:39.0814 5592        napagent        (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
13:02:39.0933 5592        napagent - ok
13:02:39.0987 5592        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
13:02:40.0052 5592        NativeWifiP - ok
13:02:40.0135 5592        NDIS            (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
13:02:40.0216 5592        NDIS - ok
13:02:40.0240 5592        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
13:02:40.0332 5592        NdisCap - ok
13:02:40.0357 5592        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
13:02:40.0462 5592        NdisTapi - ok
13:02:40.0498 5592        Ndisuio        (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
13:02:40.0605 5592        Ndisuio - ok
13:02:40.0636 5592        NdisWan        (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
13:02:40.0745 5592        NdisWan - ok
13:02:40.0795 5592        NDProxy        (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
13:02:40.0888 5592        NDProxy - ok
13:02:40.0932 5592        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
13:02:41.0029 5592        NetBIOS - ok
13:02:41.0074 5592        NetBT          (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
13:02:41.0187 5592        NetBT - ok
13:02:41.0217 5592        Netlogon        (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:02:41.0242 5592        Netlogon - ok
13:02:41.0295 5592        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
13:02:41.0426 5592        Netman - ok
13:02:41.0476 5592        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
13:02:41.0609 5592        netprofm - ok
13:02:41.0690 5592        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
13:02:41.0713 5592        NetTcpPortSharing - ok
13:02:41.0747 5592        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
13:02:41.0774 5592        nfrd960 - ok
13:02:41.0840 5592        NlaSvc          (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
13:02:41.0971 5592        NlaSvc - ok
13:02:42.0049 5592        nmwcd          (907b5e1e4a592e5edc5e4ccbde4863c2) C:\Windows\system32\drivers\ccdcmbx64.sys
13:02:42.0123 5592        nmwcd - ok
13:02:42.0151 5592        nmwcdc          (41c1ac1f3613435eb32d67bcb80a5fa5) C:\Windows\system32\drivers\ccdcmbox64.sys
13:02:42.0221 5592        nmwcdc - ok
13:02:42.0274 5592        nmwcdnsux64    (9573223e205907247ae6d948e3453770) C:\Windows\system32\drivers\nmwcdnsux64.sys
13:02:42.0338 5592        nmwcdnsux64 - ok
13:02:42.0372 5592        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
13:02:42.0464 5592        Npfs - ok
13:02:42.0490 5592        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
13:02:42.0593 5592        nsi - ok
13:02:42.0619 5592        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
13:02:42.0712 5592        nsiproxy - ok
13:02:42.0855 5592        Ntfs            (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
13:02:42.0978 5592        Ntfs - ok
13:02:43.0113 5592        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
13:02:43.0221 5592        Null - ok
13:02:43.0270 5592        nvraid          (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
13:02:43.0301 5592        nvraid - ok
13:02:43.0374 5592        nvstor          (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
13:02:43.0410 5592        nvstor - ok
13:02:43.0465 5592        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
13:02:43.0497 5592        nv_agp - ok
13:02:43.0531 5592        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
13:02:43.0574 5592        ohci1394 - ok
13:02:43.0637 5592        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
13:02:43.0712 5592        p2pimsvc - ok
13:02:43.0765 5592        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
13:02:43.0820 5592        p2psvc - ok
13:02:43.0842 5592        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
13:02:43.0873 5592        Parport - ok
13:02:43.0921 5592        partmgr        (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
13:02:43.0949 5592        partmgr - ok
13:02:43.0978 5592        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
13:02:44.0055 5592        PcaSvc - ok
13:02:44.0099 5592        pccsmcfd        (bc0018c2d29f655188a0ed3fa94fdb24) C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
13:02:44.0155 5592        pccsmcfd - ok
13:02:44.0192 5592        pci            (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
13:02:44.0224 5592        pci - ok
13:02:44.0247 5592        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
13:02:44.0272 5592        pciide - ok
13:02:44.0310 5592        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
13:02:44.0361 5592        pcmcia - ok
13:02:44.0383 5592        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
13:02:44.0411 5592        pcw - ok
13:02:44.0467 5592        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
13:02:44.0589 5592        PEAUTH - ok
13:02:44.0694 5592        PeerDistSvc    (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll
13:02:44.0811 5592        PeerDistSvc - ok
13:02:44.0916 5592        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
13:02:44.0973 5592        PerfHost - ok
13:02:45.0206 5592        pla            (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
13:02:45.0406 5592        pla - ok
13:02:45.0474 5592        PlugPlay        (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
13:02:45.0536 5592        PlugPlay - ok
13:02:45.0567 5592        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
13:02:45.0612 5592        PNRPAutoReg - ok
13:02:45.0651 5592        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
13:02:45.0684 5592        PNRPsvc - ok
13:02:45.0750 5592        PolicyAgent    (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
13:02:45.0871 5592        PolicyAgent - ok
13:02:45.0919 5592        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
13:02:46.0039 5592        Power - ok
13:02:46.0117 5592        PptpMiniport    (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
13:02:46.0226 5592        PptpMiniport - ok
13:02:46.0253 5592        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
13:02:46.0296 5592        Processor - ok
13:02:46.0330 5592        ProfSvc        (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll
13:02:46.0406 5592        ProfSvc - ok
13:02:46.0444 5592        ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:02:46.0473 5592        ProtectedStorage - ok
13:02:46.0527 5592        Psched          (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
13:02:46.0643 5592        Psched - ok
13:02:46.0702 5592        PSI            (fb46e9a827a8799ebd7bfa9128c91f37) C:\Windows\system32\DRIVERS\psi_mf.sys
13:02:46.0723 5592        PSI - ok
13:02:46.0841 5592        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
13:02:46.0957 5592        ql2300 - ok
13:02:47.0068 5592        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
13:02:47.0099 5592        ql40xx - ok
13:02:47.0141 5592        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
13:02:47.0222 5592        QWAVE - ok
13:02:47.0242 5592        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
13:02:47.0301 5592        QWAVEdrv - ok
13:02:47.0379 5592        RapiMgr        (a55e7d0d873b2c97585b3b5926ac6ade) C:\Windows\WindowsMobile\rapimgr.dll
13:02:47.0658 5592        RapiMgr - ok
13:02:47.0686 5592        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
13:02:47.0795 5592        RasAcd - ok
13:02:47.0848 5592        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
13:02:47.0946 5592        RasAgileVpn - ok
13:02:47.0981 5592        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
13:02:48.0107 5592        RasAuto - ok
13:02:48.0149 5592        Rasl2tp        (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
13:02:48.0242 5592        Rasl2tp - ok
13:02:48.0306 5592        RasMan          (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
13:02:48.0434 5592        RasMan - ok
13:02:48.0472 5592        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
13:02:48.0578 5592        RasPppoe - ok
13:02:48.0613 5592        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
13:02:48.0728 5592        RasSstp - ok
13:02:48.0783 5592        rdbss          (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
13:02:48.0913 5592        rdbss - ok
13:02:48.0942 5592        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
13:02:48.0995 5592        rdpbus - ok
13:02:49.0019 5592        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
13:02:49.0119 5592        RDPCDD - ok
13:02:49.0164 5592        RDPDR          (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
13:02:49.0209 5592        RDPDR - ok
13:02:49.0225 5592        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
13:02:49.0325 5592        RDPENCDD - ok
13:02:49.0350 5592        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
13:02:49.0442 5592        RDPREFMP - ok
13:02:49.0472 5592        RDPWD          (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys
13:02:49.0520 5592        RDPWD - ok
13:02:49.0573 5592        rdyboost        (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
13:02:49.0612 5592        rdyboost - ok
13:02:49.0638 5592        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
13:02:49.0751 5592        RemoteAccess - ok
13:02:49.0797 5592        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
13:02:49.0916 5592        RemoteRegistry - ok
13:02:49.0970 5592        RFCOMM          (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
13:02:50.0029 5592        RFCOMM - ok
13:02:50.0058 5592        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
13:02:50.0180 5592        RpcEptMapper - ok
13:02:50.0212 5592        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
13:02:50.0254 5592        RpcLocator - ok
13:02:50.0312 5592        RpcSs          (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
13:02:50.0419 5592        RpcSs - ok
13:02:50.0449 5592        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
13:02:50.0552 5592        rspndr - ok
13:02:50.0577 5592        s3cap          (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
13:02:50.0620 5592        s3cap - ok
13:02:50.0647 5592        SamSs          (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:02:50.0672 5592        SamSs - ok
13:02:50.0703 5592        sbp2port        (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
13:02:50.0732 5592        sbp2port - ok
13:02:50.0771 5592        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
13:02:50.0888 5592        SCardSvr - ok
13:02:50.0921 5592        scfilter        (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
13:02:51.0028 5592        scfilter - ok
13:02:51.0120 5592        Schedule        (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
13:02:51.0288 5592        Schedule - ok
13:02:51.0330 5592        SCPolicySvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
13:02:51.0422 5592        SCPolicySvc - ok
13:02:51.0450 5592        SDRSVC          (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
13:02:51.0520 5592        SDRSVC - ok
13:02:51.0565 5592        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
13:02:51.0670 5592        secdrv - ok
13:02:51.0707 5592        seclogon        (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
13:02:51.0801 5592        seclogon - ok
13:02:51.0932 5592        Secunia PSI Agent (f70a51eb03ee7046784ef62efce9528e) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
13:02:52.0031 5592        Secunia PSI Agent - ok
13:02:52.0092 5592        Secunia Update Agent (ad56ceb08eeb517332355fde9e5939c8) C:\Program Files (x86)\Secunia\PSI\sua.exe
13:02:52.0153 5592        Secunia Update Agent - ok
13:02:52.0288 5592        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
13:02:52.0401 5592        SENS - ok
13:02:52.0426 5592        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
13:02:52.0461 5592        SensrSvc - ok
13:02:52.0498 5592        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
13:02:52.0525 5592        Serenum - ok
13:02:52.0545 5592        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
13:02:52.0591 5592        Serial - ok
13:02:52.0632 5592        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
13:02:52.0678 5592        sermouse - ok
13:02:52.0782 5592        ServiceLayer    (7d3903af48e6c1dc2704eafcb608d031) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
13:02:52.0842 5592        ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
13:02:52.0842 5592        ServiceLayer - detected UnsignedFile.Multi.Generic (1)
13:02:52.0893 5592        SessionEnv      (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
13:02:53.0014 5592        SessionEnv - ok
13:02:53.0041 5592        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
13:02:53.0094 5592        sffdisk - ok
13:02:53.0115 5592        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
13:02:53.0150 5592        sffp_mmc - ok
13:02:53.0175 5592        sffp_sd        (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
13:02:53.0229 5592        sffp_sd - ok
13:02:53.0257 5592        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
13:02:53.0296 5592        sfloppy - ok
13:02:53.0365 5592        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
13:02:53.0489 5592        SharedAccess - ok
13:02:53.0552 5592        ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
13:02:53.0673 5592        ShellHWDetection - ok
13:02:53.0705 5592        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
13:02:53.0730 5592        SiSRaid2 - ok
13:02:53.0766 5592        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
13:02:53.0792 5592        SiSRaid4 - ok
13:02:53.0862 5592        SkypeUpdate    (f07af60b152221472fbdb2fecec4896d) C:\Program Files (x86)\Skype\Updater\Updater.exe
13:02:53.0885 5592        SkypeUpdate - ok
13:02:53.0915 5592        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
13:02:54.0009 5592        Smb - ok
13:02:54.0059 5592        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
13:02:54.0093 5592        SNMPTRAP - ok
13:02:54.0119 5592        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
13:02:54.0145 5592        spldr - ok
13:02:54.0234 5592        spmgr          (739db668dbd812285ecc553e64a5e212) C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
13:02:54.0256 5592        spmgr - ok
13:02:54.0319 5592        Spooler        (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
13:02:54.0447 5592        Spooler - ok
13:02:54.0708 5592        sppsvc          (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
13:02:54.0965 5592        sppsvc - ok
13:02:55.0086 5592        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
13:02:55.0195 5592        sppuinotify - ok
13:02:55.0261 5592        srv            (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
13:02:55.0351 5592        srv - ok
13:02:55.0391 5592        srv2            (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
13:02:55.0451 5592        srv2 - ok
13:02:55.0484 5592        srvnet          (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
13:02:55.0541 5592        srvnet - ok
13:02:55.0584 5592        ssadbus        (8f8324ed1de63ffc7b1a02cd2d963c72) C:\Windows\system32\DRIVERS\ssadbus.sys
13:02:55.0656 5592        ssadbus - ok
13:02:55.0691 5592        ssadmdfl        (58221efcb74167b73667f0024c661ce0) C:\Windows\system32\DRIVERS\ssadmdfl.sys
13:02:55.0733 5592        ssadmdfl - ok
13:02:55.0773 5592        ssadmdm        (4da7c71bfac5ad71255b7e4cab980163) C:\Windows\system32\DRIVERS\ssadmdm.sys
13:02:55.0821 5592        ssadmdm - ok
13:02:55.0872 5592        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
13:02:56.0004 5592        SSDPSRV - ok
13:02:56.0027 5592        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
13:02:56.0127 5592        SstpSvc - ok
13:02:56.0216 5592        STacSV          (94a6522ac9f3e05fd039ad105ade96d0) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_38986e29a8b510a2\STacSV64.exe
13:02:56.0289 5592        STacSV - ok
13:02:56.0314 5592        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
13:02:56.0340 5592        stexstor - ok
13:02:56.0423 5592        STHDA          (ddb811b13d827081e7c1ddff302ab334) C:\Windows\system32\DRIVERS\stwrt64.sys
13:02:56.0487 5592        STHDA - ok
13:02:56.0576 5592        stisvc          (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
13:02:56.0673 5592        stisvc - ok
13:02:56.0714 5592        storflt        (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
13:02:56.0741 5592        storflt - ok
13:02:56.0766 5592        StorSvc        (c40841817ef57d491f22eb103da587cc) C:\Windows\system32\storsvc.dll
13:02:56.0823 5592        StorSvc - ok
13:02:56.0842 5592        storvsc        (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
13:02:56.0869 5592        storvsc - ok
13:02:56.0891 5592        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
13:02:56.0919 5592        swenum - ok
13:02:56.0983 5592        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
13:02:57.0136 5592        swprv - ok
13:02:57.0275 5592        SysMain        (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
13:02:57.0408 5592        SysMain - ok
13:02:57.0528 5592        TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
13:02:57.0599 5592        TabletInputService - ok
13:02:57.0640 5592        TapiSrv        (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
13:02:57.0766 5592        TapiSrv - ok
13:02:57.0799 5592        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
13:02:57.0900 5592        TBS - ok
13:02:58.0084 5592        Tcpip          (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
13:02:58.0221 5592        Tcpip - ok
13:02:58.0456 5592        TCPIP6          (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
13:02:58.0553 5592        TCPIP6 - ok
13:02:58.0635 5592        tcpipreg        (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
13:02:58.0740 5592        tcpipreg - ok
13:02:58.0773 5592        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
13:02:58.0813 5592        TDPIPE - ok
13:02:58.0833 5592        TDTCP          (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
13:02:58.0873 5592        TDTCP - ok
13:02:58.0908 5592        tdx            (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
13:02:59.0015 5592        tdx - ok
13:02:59.0055 5592        TermDD          (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
13:02:59.0083 5592        TermDD - ok
13:02:59.0146 5592        TermService    (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
13:02:59.0288 5592        TermService - ok
13:02:59.0341 5592        TFsExDisk      (48d9d00c2e0e72c3d4f52772c80355f6) C:\Windows\System32\Drivers\TFsExDisk.sys
13:02:59.0363 5592        TFsExDisk - ok
13:02:59.0386 5592        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
13:02:59.0446 5592        Themes - ok
13:02:59.0472 5592        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
13:02:59.0556 5592        THREADORDER - ok
13:02:59.0583 5592        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
13:02:59.0697 5592        TrkWks - ok
13:02:59.0768 5592        TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
13:02:59.0889 5592        TrustedInstaller - ok
13:02:59.0924 5592        tssecsrv        (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
13:03:00.0013 5592        tssecsrv - ok
13:03:00.0071 5592        TsUsbFlt        (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
13:03:00.0122 5592        TsUsbFlt - ok
13:03:00.0183 5592        tunnel          (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
13:03:00.0287 5592        tunnel - ok
13:03:00.0317 5592        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
13:03:00.0345 5592        uagp35 - ok
13:03:00.0402 5592        udfs            (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
13:03:00.0533 5592        udfs - ok
13:03:00.0571 5592        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
13:03:00.0615 5592        UI0Detect - ok
13:03:00.0656 5592        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
13:03:00.0681 5592        uliagpkx - ok
13:03:00.0703 5592        umbus          (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
13:03:00.0745 5592        umbus - ok
13:03:00.0780 5592        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
13:03:00.0805 5592        UmPass - ok
13:03:00.0855 5592        UmRdpService    (a293dcd756d04d8492a750d03b9a297c) C:\Windows\System32\umrdp.dll
13:03:00.0920 5592        UmRdpService - ok
13:03:01.0159 5592        UNS            (41118d920b2b268c0adc36421248cdcf) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
13:03:01.0280 5592        UNS ( UnsignedFile.Multi.Generic ) - warning
13:03:01.0280 5592        UNS - detected UnsignedFile.Multi.Generic (1)
13:03:01.0438 5592        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
13:03:01.0551 5592        upnphost - ok
13:03:01.0597 5592        upperdev        (4e93c8496359e97830c75ac36393654d) C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
13:03:01.0663 5592        upperdev - ok
13:03:01.0706 5592        USBAAPL64      (f724b03c3dfaacf08d17d38bf3333583) C:\Windows\system32\Drivers\usbaapl64.sys
13:03:01.0732 5592        USBAAPL64 ( UnsignedFile.Multi.Generic ) - warning
13:03:01.0732 5592        USBAAPL64 - detected UnsignedFile.Multi.Generic (1)
13:03:01.0767 5592        usbccgp        (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
13:03:01.0815 5592        usbccgp - ok
13:03:01.0850 5592        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
13:03:01.0884 5592        usbcir - ok
13:03:01.0909 5592        usbehci        (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
13:03:01.0949 5592        usbehci - ok
13:03:01.0998 5592        usbhub          (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
13:03:02.0055 5592        usbhub - ok
13:03:02.0083 5592        usbohci        (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
13:03:02.0123 5592        usbohci - ok
13:03:02.0164 5592        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
13:03:02.0212 5592        usbprint - ok
13:03:02.0241 5592        usbscan        (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
13:03:02.0277 5592        usbscan - ok
13:03:02.0315 5592        usbser          (4acee387fa8fd39f83564fcd2fc234f2) C:\Windows\system32\drivers\usbser.sys
13:03:02.0369 5592        usbser - ok
13:03:02.0390 5592        UsbserFilt      (8844cb19a37b65e27049d4a7786726a9) C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
13:03:02.0452 5592        UsbserFilt - ok
13:03:02.0497 5592        USBSTOR        (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:03:02.0554 5592        USBSTOR - ok
13:03:02.0582 5592        usbuhci        (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
13:03:02.0621 5592        usbuhci - ok
13:03:02.0682 5592        usbvideo        (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
13:03:02.0743 5592        usbvideo - ok
13:03:02.0782 5592        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
13:03:02.0914 5592        UxSms - ok
13:03:02.0940 5592        VaultSvc        (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:03:02.0964 5592        VaultSvc - ok
13:03:03.0001 5592        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
13:03:03.0026 5592        vdrvroot - ok
13:03:03.0099 5592        vds            (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
13:03:03.0227 5592        vds - ok
13:03:03.0255 5592        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
13:03:03.0290 5592        vga - ok
13:03:03.0304 5592        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
13:03:03.0409 5592        VgaSave - ok
13:03:03.0459 5592        vhdmp          (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
13:03:03.0500 5592        vhdmp - ok
13:03:03.0539 5592        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
13:03:03.0566 5592        viaide - ok
13:03:03.0599 5592        vmbus          (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
13:03:03.0640 5592        vmbus - ok
13:03:03.0664 5592        VMBusHID        (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
13:03:03.0706 5592        VMBusHID - ok
13:03:03.0733 5592        volmgr          (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
13:03:03.0761 5592        volmgr - ok
13:03:03.0820 5592        volmgrx        (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
13:03:03.0869 5592        volmgrx - ok
13:03:03.0914 5592        volsnap        (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
13:03:03.0963 5592        volsnap - ok
13:03:04.0012 5592        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
13:03:04.0044 5592        vsmraid - ok
13:03:04.0177 5592        VSS            (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
13:03:04.0346 5592        VSS - ok
13:03:04.0463 5592        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
13:03:04.0512 5592        vwifibus - ok
13:03:04.0550 5592        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
13:03:04.0590 5592        vwififlt - ok
13:03:04.0628 5592        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
13:03:04.0687 5592        vwifimp - ok
13:03:04.0739 5592        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
13:03:04.0860 5592        W32Time - ok
13:03:04.0882 5592        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
13:03:04.0921 5592        WacomPen - ok
13:03:04.0973 5592        WANARP          (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
13:03:05.0081 5592        WANARP - ok
13:03:05.0085 5592        Wanarpv6        (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
13:03:05.0167 5592        Wanarpv6 - ok
13:03:05.0293 5592        WatAdminSvc    (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
13:03:05.0386 5592        WatAdminSvc - ok
13:03:05.0531 5592        wbengine        (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
13:03:05.0642 5592        wbengine - ok
13:03:05.0774 5592        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
13:03:05.0837 5592        WbioSrvc - ok
13:03:05.0939 5592        WcesComm        (8bda6db43aa54e8bb5e0794541ddc209) C:\Windows\WindowsMobile\wcescomm.dll
13:03:05.0991 5592        WcesComm - ok
13:03:06.0042 5592        wcncsvc        (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
13:03:06.0113 5592        wcncsvc - ok
13:03:06.0147 5592        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
13:03:06.0196 5592        WcsPlugInService - ok
13:03:06.0243 5592        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
13:03:06.0279 5592        Wd - ok
13:03:06.0331 5592        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
13:03:06.0394 5592        Wdf01000 - ok
13:03:06.0411 5592        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
13:03:06.0539 5592        WdiServiceHost - ok
13:03:06.0545 5592        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
13:03:06.0595 5592        WdiSystemHost - ok
13:03:06.0648 5592        WebClient      (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
13:03:06.0728 5592        WebClient - ok
13:03:06.0774 5592        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
13:03:06.0902 5592        Wecsvc - ok
13:03:06.0933 5592        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
13:03:07.0040 5592        wercplsupport - ok
13:03:07.0076 5592        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
13:03:07.0179 5592        WerSvc - ok
13:03:07.0232 5592        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
13:03:07.0313 5592        WfpLwf - ok
13:03:07.0352 5592        WimFltr        (52ded146e4797e6ccf94799e8e22bb2a) C:\Windows\system32\DRIVERS\wimfltr.sys
13:03:07.0390 5592        WimFltr - ok
13:03:07.0416 5592        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
13:03:07.0439 5592        WIMMount - ok
13:03:07.0460 5592        WinDefend - ok
13:03:07.0470 5592        WinHttpAutoProxySvc - ok
13:03:07.0554 5592        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
13:03:07.0674 5592        Winmgmt - ok
13:03:07.0839 5592        WinRM          (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
13:03:08.0034 5592        WinRM - ok
13:03:08.0175 5592        WinUsb          (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
13:03:08.0221 5592        WinUsb - ok
13:03:08.0309 5592        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
13:03:08.0408 5592        Wlansvc - ok
13:03:08.0430 5592        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
13:03:08.0458 5592        WmiAcpi - ok
13:03:08.0532 5592        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
13:03:08.0592 5592        wmiApSrv - ok
13:03:08.0642 5592        WMPNetworkSvc - ok
13:03:08.0680 5592        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
13:03:08.0719 5592        WPCSvc - ok
13:03:08.0755 5592        WPDBusEnum      (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
13:03:08.0817 5592        WPDBusEnum - ok
13:03:08.0849 5592        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
13:03:08.0943 5592        ws2ifsl - ok
13:03:08.0978 5592        wscsvc          (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\System32\wscsvc.dll
13:03:09.0041 5592        wscsvc - ok
13:03:09.0047 5592        WSearch - ok
13:03:09.0246 5592        wuauserv        (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
13:03:09.0413 5592        wuauserv - ok
13:03:09.0543 5592        WudfPf          (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
13:03:09.0652 5592        WudfPf - ok
13:03:09.0686 5592        WUDFRd          (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
13:03:09.0789 5592        WUDFRd - ok
13:03:09.0830 5592        wudfsvc        (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
13:03:09.0926 5592        wudfsvc - ok
13:03:09.0975 5592        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
13:03:10.0033 5592        WwanSvc - ok
13:03:10.0110 5592        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
13:03:10.0588 5592        \Device\Harddisk0\DR0 - ok
13:03:10.0593 5592        Boot (0x1200)  (294e016372193910841e720e6cee7794) \Device\Harddisk0\DR0\Partition0
13:03:10.0596 5592        \Device\Harddisk0\DR0\Partition0 - ok
13:03:10.0624 5592        Boot (0x1200)  (3d53a687a77f5da8af13314386a97019) \Device\Harddisk0\DR0\Partition1
13:03:10.0628 5592        \Device\Harddisk0\DR0\Partition1 - ok
13:03:10.0628 5592        ============================================================
13:03:10.0628 5592        Scan finished
13:03:10.0628 5592        ============================================================
13:03:10.0644 3356        Detected object count: 5
13:03:10.0644 3356        Actual detected object count: 5
13:04:49.0061 3356        ADSMService ( UnsignedFile.Multi.Generic ) - skipped by user
13:04:49.0061 3356        ADSMService ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:04:49.0063 3356        LMS ( UnsignedFile.Multi.Generic ) - skipped by user
13:04:49.0063 3356        LMS ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:04:49.0066 3356        ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
13:04:49.0066 3356        ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:04:49.0069 3356        UNS ( UnsignedFile.Multi.Generic ) - skipped by user
13:04:49.0069 3356        UNS ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:04:49.0071 3356        USBAAPL64 ( UnsignedFile.Multi.Generic ) - skipped by user
13:04:49.0071 3356        USBAAPL64 ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 25.07.2012 13:04

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

sucnas 25.07.2012 14:23

Code:

ComboFix 12-07-26.02 - Katja_alles 25.07.2012  15:09:36.1.4 - x64
Microsoft Windows 7 Professional  6.1.7601.1.1252.49.1031.18.3949.2709 [GMT 2:00]
ausgeführt von:: c:\users\Katja\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
D:\install.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-06-25 bis 2012-07-25  ))))))))))))))))))))))))))))))
.
.
2012-07-25 13:16 . 2012-07-25 13:16        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-07-25 13:10 . 2012-07-25 13:10        69000        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{57446165-43E6-4C4F-A360-1E098E589282}\offreg.dll
2012-07-25 09:16 . 2012-07-25 09:16        --------        d-----w-        C:\_OTL
2012-07-24 15:45 . 2010-10-11 21:00        274944        ----a-w-        c:\users\Katja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MWconn\MWconn_downdate.exe
2012-07-24 15:42 . 2010-10-11 21:00        274944        ----a-w-        c:\users\Katja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MWconn\UMTSGPRS.exe
2012-07-24 15:42 . 2010-10-11 21:00        274944        ----a-w-        c:\users\Katja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MWconn\UMTS.exe
2012-07-24 15:42 . 2010-10-11 21:00        274944        ----a-w-        c:\users\Katja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MWconn\GPRS.exe
2012-07-24 15:42 . 2010-10-11 21:00        274944        ----a-w-        c:\users\Katja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MWconn\CONFIG.exe
2012-07-24 15:42 . 2010-10-11 21:00        274944        ----a-w-        c:\users\Katja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MWconn\MWconn.exe
2012-07-24 07:39 . 2012-06-29 10:04        9133488        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{57446165-43E6-4C4F-A360-1E098E589282}\mpengine.dll
2012-07-21 17:00 . 2012-07-21 17:00        --------        d-----w-        c:\program files (x86)\ESET
2012-07-20 20:06 . 2012-07-20 20:06        --------        d-----w-        c:\users\Katja\AppData\Local\fontconfig
2012-07-20 20:06 . 2012-07-20 20:07        --------        d-----w-        c:\users\Katja\.gimp-2.8
2012-07-20 20:06 . 2012-07-20 20:06        --------        d-----w-        c:\users\Katja\AppData\Local\gegl-0.2
2012-07-20 19:27 . 2012-07-20 19:27        --------        d-----w-        c:\program files (x86)\Secunia
2012-07-20 19:15 . 2012-07-20 19:17        --------        d-----w-        c:\program files (x86)\Secure Banking
2012-07-20 19:15 . 2012-07-20 19:15        --------        d-----w-        c:\program files\7-Zip
2012-07-20 18:03 . 2012-07-22 21:43        --------        d-----w-        c:\users\Katja_alles
2012-07-20 17:55 . 2012-07-20 17:55        --------        d-----w-        c:\windows\SysWow64\wbem\en-US
2012-07-20 17:55 . 2012-07-20 17:55        --------        d-----w-        c:\windows\system32\wbem\en-US
2012-07-20 15:16 . 2012-07-20 15:16        70344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-20 15:16 . 2012-07-20 15:16        426184        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-20 14:13 . 2012-07-20 14:13        --------        d-----w-        c:\program files (x86)\Common Files\Java
2012-07-20 14:13 . 2012-07-20 14:13        --------        d-----w-        c:\program files (x86)\Oracle
2012-07-20 14:12 . 2012-07-05 20:06        772544        ----a-w-        c:\windows\SysWow64\npDeployJava1.dll
2012-07-20 14:05 . 2012-07-20 14:07        --------        d-----w-        c:\windows\system32\appmgmt
2012-07-20 13:59 . 2012-07-20 13:59        --------        d-----w-        c:\users\Katja\AppData\Roaming\Malwarebytes
2012-07-20 13:58 . 2012-07-20 13:58        --------        d-----w-        c:\programdata\Malwarebytes
2012-07-20 13:58 . 2012-07-20 13:58        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-07-20 13:58 . 2012-07-03 11:46        24904        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-07-12 13:36 . 2012-06-12 03:08        3148800        ----a-w-        c:\windows\system32\win32k.sys
2012-07-11 13:03 . 2012-06-06 06:06        2004480        ----a-w-        c:\windows\system32\msxml6.dll
2012-07-11 13:03 . 2012-06-06 06:06        1881600        ----a-w-        c:\windows\system32\msxml3.dll
2012-07-11 13:03 . 2012-06-06 05:05        1390080        ----a-w-        c:\windows\SysWow64\msxml6.dll
2012-07-11 13:03 . 2012-06-06 05:05        1236992        ----a-w-        c:\windows\SysWow64\msxml3.dll
2012-07-11 13:03 . 2010-06-26 03:55        2048        ----a-w-        c:\windows\system32\msxml3r.dll
2012-07-11 13:03 . 2010-06-26 03:24        2048        ----a-w-        c:\windows\SysWow64\msxml3r.dll
2012-07-11 13:03 . 2012-06-09 05:43        14172672        ----a-w-        c:\windows\system32\shell32.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-20 17:59 . 2010-12-28 07:52        45056        ----a-w-        c:\windows\system32\acovcnt.exe
2012-07-12 13:24 . 2010-12-20 14:27        59701280        ----a-w-        c:\windows\system32\MRT.exe
2012-07-05 20:06 . 2010-12-20 14:46        687544        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2012-06-02 22:19 . 2012-06-21 13:06        38424        ----a-w-        c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-21 13:06        2428952        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-21 13:06        57880        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-21 13:06        44056        ----a-w-        c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-21 13:06        701976        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-21 13:06        2622464        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-21 13:06        99840        ----a-w-        c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-21 13:05        186752        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-21 13:05        36864        ----a-w-        c:\windows\system32\wuapp.exe
2012-05-31 10:25 . 2010-12-20 14:22        279656        ------w-        c:\windows\system32\MpSigStub.exe
2012-05-09 15:33 . 2011-10-16 06:51        98848        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2012-05-09 15:33 . 2011-10-16 06:51        132832        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-05-04 11:06 . 2012-06-14 14:36        5559664        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-05-04 10:03 . 2012-06-14 14:36        3968368        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-14 14:36        3913072        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40 . 2012-06-14 14:36        209920        ----a-w-        c:\windows\system32\profsvc.dll
2012-04-28 03:55 . 2012-06-14 14:35        210944        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 16:08        143360        ----a-w-        c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files (x86)\Windows Sidebar\Sidebar.exe" [2010-11-20 1174016]
"SecureBanking"="c:\program files (x86)\Secure Banking\SecureBanking.exe" [2012-05-23 364544]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-11-11 98304]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2009-10-26 6998656]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2009-08-19 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-05-09 348624]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-18 421888]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2010-12-20 12862]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-20 250056]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2009-08-21 44032]
R3 BthAvrcp;Bluetooth-AVRCP-Profil;c:\windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 29184]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-17 113120]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2011-12-16 17976]
R3 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2012-06-27 1326176]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-10-27 157672]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-10-27 16872]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-10-27 177640]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2010-06-14 16448]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2010-12-14 51712]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2011-08-21 1255736]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-10-11 27760]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [2009-09-17 359552]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-11-11 202752]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-09 86224]
S2 AntiVirWebService;Avira Browser Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [2012-05-09 465360]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [2009-09-14 166400]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2009-09-14 128512]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2012-06-27 681056]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2314240]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-06-22 132608]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-06-22 113792]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2009-11-13 67072]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 78085778
*Deregistered* - 78085778
.
Inhalt des "geplante Tasks" Ordners
.
2012-07-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-20 15:16]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:52        159744        ----a-w-        c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-11-27 487424]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-01 323584]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 660360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 139.7.30.125 139.7.30.126
FF - ProfilePath - c:\users\Katja_alles\AppData\Roaming\Mozilla\Firefox\Profiles\wr83doto.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-NPSStartup - (no file)
AddRemove-K_Series_ScreenSaver_EN - c:\windows\system32\K_Series_ScreenSaver_EN.scr
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-07-25  15:19:43
ComboFix-quarantined-files.txt  2012-07-25 13:19
.
Vor Suchlauf: 13 Verzeichnis(se), 42.776.784.896 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 42.381.545.472 Bytes frei
.
- - End Of File - - AD5E833EE5AA703931F50F315A39EA73


cosinus 25.07.2012 14:46

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

sucnas 25.07.2012 16:04

Ich schaffe es nicht OSAM zu laden. Der Download endet immer zwischen 689KB und 1,5MB. Schreibt mir aber nicht, dass er unvollständig ist. Die anderen konnte ich herunterladen. Habe es auch mit der autorun Datei von OSAM probiert - auch unvollständig. Und nun?

Log GMER

Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-07-25 17:31:41
Windows 6.1.7601 Service Pack 1
Running: ro2t5vqq.exe


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0009dd5091f1                     
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0009dd5091f1@001de91c335b        0xF0 0x15 0xE3 0x7A ...
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0009dd5091f1@9c1874e9f98b        0x6C 0x7A 0xE6 0xE5 ...
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0009dd5091f1@d8543a467bd2        0x9C 0x97 0x19 0xCB ...
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0009dd5091f1@1886ac6da8d1        0xC5 0x1A 0x0D 0x80 ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0009dd5091f1 (not active ControlSet) 
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0009dd5091f1@001de91c335b            0xF0 0x15 0xE3 0x7A ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0009dd5091f1@9c1874e9f98b            0x6C 0x7A 0xE6 0xE5 ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0009dd5091f1@d8543a467bd2            0x9C 0x97 0x19 0xCB ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0009dd5091f1@1886ac6da8d1            0xC5 0x1A 0x0D 0x80 ...

---- Files - GMER 1.0.15 ----

File  C:\ADSM_PData_0150                                                                              0 bytes
File  C:\ADSM_PData_0150\DB                                                                            0 bytes
File  C:\ADSM_PData_0150\DB\SI.db                                                                      624 bytes
File  C:\ADSM_PData_0150\DB\UL.db                                                                      16 bytes
File  C:\ADSM_PData_0150\DB\VL.db                                                                      16 bytes
File  C:\ADSM_PData_0150\DB\WAL.db                                                                    2048 bytes
File  C:\ADSM_PData_0150\DragWait.exe                                                                  315392 bytes executable
File  C:\ADSM_PData_0150\_avt                                                                          512 bytes

---- EOF - GMER 1.0.15 ----

aswMBR

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-25 19:02:08
-----------------------------
19:02:08.062    OS Version: Windows x64 6.1.7601 Service Pack 1
19:02:08.062    Number of processors: 4 586 0x2502
19:02:08.062    ComputerName: MEINGEWINN  UserName:
19:02:09.326    Initialize success
19:02:13.080    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:02:13.080    Disk 0 Vendor: ST950032 0003 Size: 476940MB BusType: 3
19:02:13.096    Disk 0 MBR read successfully
19:02:13.111    Disk 0 MBR scan
19:02:13.111    Disk 0 Windows 7 default MBR code
19:02:13.111    Disk 0 Partition 1 00    1C Hidd FAT32 LBA MSDOS5.0    20002 MB offset 63
19:02:13.142    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS      119232 MB offset 40965750
19:02:13.142    Disk 0 Partition - 00    0F Extended LBA            337704 MB offset 285153280
19:02:13.174    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      337703 MB offset 285155328
19:02:13.220    Disk 0 scanning C:\Windows\system32\drivers
19:02:23.938    Service scanning
19:02:43.172    Modules scanning
19:02:43.188    Disk 0 trace - called modules:
19:02:43.344    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
19:02:43.859    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c69060]
19:02:43.859    3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa80049d0e40]
19:02:43.874    5 ACPI.sys[fffff88000f7f7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80049d3050]
19:02:43.890    Scan finished successfully
19:03:02.329    Disk 0 MBR has been saved successfully to "C:\Users\Katja_alles\Desktop\MBR.dat"
19:03:02.329    The log file has been saved successfully to "C:\Users\Katja_alles\Desktop\aswMBR.txt"
19:03:44.826    Disk 0 MBR has been saved successfully to "C:\Users\Katja\Desktop\MBR.dat"
19:03:44.841    The log file has been saved successfully to "C:\Users\Katja\Desktop\aswMBR.txt"

Hier nun OSAM. Habe es nun per Email bekommen.

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 22:35:02 on 25.07.2012

OS: Windows 7  Service Pack 1 (Build 7601), 64-bit
Default Browser: Microsoft Corporation Internet Explorer 9.00.8112.16421

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"NokiaConnectionManager" - "Nokia" - C:\PROGRA~2\Nokia\NOKIAP~1\CONNEC~1.CPL
"QuickTime" - "Apple Inc." - C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Apple Mobile USB Driver" (USBAAPL64) - "Apple, Inc." - C:\Windows\System32\Drivers\usbaapl64.sys
"ASMMAP64" (ASMMAP64) - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys
"aswMBR" (aswMBR) - ? - C:\Users\KATJA_~1\AppData\Local\Temp\aswMBR.sys  (Hidden registry entry, rootkit activity | File not found)
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"Data Security Manager Driver" (AsDsm) - "ASUSTek Computer Inc" - C:\Windows\system32\drivers\AsDsm.sys
"ghaio" (ghaio) - ? - C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys  (File found, but it contains no detailed information)
"ipswuio" (ipswuio) - ? - C:\Windows\System32\DRIVERS\ipswuio.sys  (File not found)
"PSI" (PSI) - "Secunia" - C:\Windows\System32\DRIVERS\psi_mf.sys
"TFsExDisk" (TFsExDisk) - "Teruten Inc" - C:\Windows\System32\Drivers\TFsExDisk.sys
"WimFltr" (WimFltr) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\wimfltr.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{16148659-720A-457d-850B-2DBD87BB129D} "AudibleShlExt Class" - "Audible, Inc." - C:\Program Files (x86)\Audible\Bin\AudibleExt.dll
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{16148659-720A-457d-850B-2DBD87BB129D} "AudibleShlExt Class" - "Audible, Inc." - C:\Program Files (x86)\Audible\Bin\AudibleExt.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "Catalyst Context Menu extension" - ? -  (File not found | COM-object registry key not found)
{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} "Nokia Phone Browser" - "Nokia" - C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Oracle Corporation" - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Oracle Corporation" - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Katja_alles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"FancyStart daemon.lnk" - "ASUSTeK Computer Inc." - C:\Program Files (x86)\ASUS\FancyStart\FancyStart.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"SecureBanking" - ? - C:\Program Files (x86)\Secure Banking\SecureBanking.exe
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"ATKMEDIA" - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
"ATKOSD2" - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"EEventManager" - "SEIKO EPSON CORPORATION" - "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
"HControlUser" - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
"QuickTime Task" - "Apple Inc." - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"PDFCreator" - ? - C:\Windows\system32\pdfcmnnt.dll  (File found, but it contains no detailed information)

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll  (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe"  (File not found)
"ABBYY FineReader 9.0 Sprint Licensing Service" (ABBYY.Licensing.FineReader.Sprint.9.0) - "ABBYY" - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
"ADSM Service" (ADSMService) - "ASUSTek Computer Inc." - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
"AFBAgent" (AFBAgent) - "ASUSTeK Computer Inc." - C:\Windows\system32\FBAgent.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"ASLDR Service" (ASLDRService) - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
"ATKGFNEX Service" (ATKGFNEXSrv) - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
"Avira Browser Schutz" (AntiVirWebService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"Intel(R) Management & Security Application User Notification Service" (UNS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
"Intel(R) Management and Security Application Local Management Service" (LMS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
"Secunia PSI Agent" (Secunia PSI Agent) - "Secunia" - C:\Program Files (x86)\Secunia\PSI\PSIA.exe
"Secunia Update Agent" (Secunia Update Agent) - "Secunia" - C:\Program Files (x86)\Secunia\PSI\sua.exe
"ServiceLayer" (ServiceLayer) - "Nokia" - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files (x86)\Skype\Updater\Updater.exe
"spmgr" (spmgr) - ? - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files (x86)\Bonjour\mdnsNSP.dll
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries )-----
"AVSDA" - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


cosinus 26.07.2012 09:44

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

sucnas 26.07.2012 14:27

Malewarebytes

Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.07.26.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Katja :: MEINGEWINN [limitiert]

26.07.2012 11:06:51
mbam-log-2012-07-26 (11-06-51).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 329797
Laufzeit: 1 Stunde(n), 2 Minute(n), 42 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


SUPERAntiSpyware

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 07/26/2012 at 03:22 PM

Application Version : 5.5.1012

Core Rules Database Version : 8963
Trace Rules Database Version: 6775

Scan type      : Complete Scan
Total Scan Time : 02:04:30

Operating System Information
Windows 7 Professional 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Administrator

Memory items scanned      : 795
Memory threats detected  : 0
Registry items scanned    : 69913
Registry threats detected : 0
File items scanned        : 163058
File threats detected    : 522

Adware.Tracking Cookie
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\S03P8219.txt [ Cookie:katja@zanox.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\KGHUCI2H.txt [ Cookie:katja@ar.atwola.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\NVPLTLKK.txt [ Cookie:katja@www.etracker.de/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\W6DXM8HW.txt [ Cookie:katja@atwola.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\AHQFBG0B.txt [ Cookie:katja@smartadserver.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\YL4IH2O4.txt [ Cookie:katja@mediaplex.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\AZE6NLL9.txt [ Cookie:katja@interclick.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\katja@adx.chip[2].txt [ Cookie:katja@adx.chip.de/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\KZY3S2VW.txt [ Cookie:katja@zanox-affiliate.de/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\WR0MKY1A.txt [ Cookie:katja@advertising.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\0LZ2NX1C.txt [ Cookie:katja@doubleclick.net/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\JRHY2IHL.txt [ Cookie:katja@tacoda.at.atwola.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\NQH7EOWC.txt [ Cookie:katja@adform.net/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\8S6CO97B.txt [ Cookie:katja@counter.hitslink.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\M94PNHTH.txt [ Cookie:katja@atdmt.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\Y2RIZC1D.txt [ Cookie:katja@apmebf.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\I53B53EL.txt [ Cookie:katja@c.atdmt.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\DK3DAR86.txt [ Cookie:katja@ad1.adfarm1.adition.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\VNHMY39B.txt [ Cookie:katja@ad.zanox.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\185O2HJ3.txt [ Cookie:katja@ad.yieldmanager.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\WDZ7A7CS.txt [ Cookie:katja@adfarm1.adition.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\katja@yieldmanager[1].txt [ Cookie:katja@yieldmanager.net/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\katja@anrtx.tacoda[1].txt [ Cookie:katja@anrtx.tacoda.net/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\L2JW78Q3.txt [ Cookie:katja@at.atwola.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\Low\katja@bs.serving-sys[2].txt [ Cookie:katja@bs.serving-sys.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\Low\CK0XUJNO.txt [ Cookie:katja@atdmt.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\Low\VN2VWP2F.txt [ Cookie:katja@c.atdmt.com/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\Low\katja@msnportal.112.2o7[1].txt [ Cookie:katja@msnportal.112.2o7.net/ ]
        C:\USERS\KATJA\AppData\Roaming\Microsoft\Windows\Cookies\Low\REV1AEWK.txt [ Cookie:katja@serving-sys.com/ ]
        C:\USERS\KATJA\Cookies\S03P8219.txt [ Cookie:katja@zanox.com/ ]
        C:\USERS\KATJA\Cookies\KGHUCI2H.txt [ Cookie:katja@ar.atwola.com/ ]
        C:\USERS\KATJA\Cookies\NVPLTLKK.txt [ Cookie:katja@www.etracker.de/ ]
        C:\USERS\KATJA\Cookies\W6DXM8HW.txt [ Cookie:katja@atwola.com/ ]
        C:\USERS\KATJA\Cookies\AHQFBG0B.txt [ Cookie:katja@smartadserver.com/ ]
        C:\USERS\KATJA\Cookies\YL4IH2O4.txt [ Cookie:katja@mediaplex.com/ ]
        C:\USERS\KATJA\Cookies\AZE6NLL9.txt [ Cookie:katja@interclick.com/ ]
        C:\USERS\KATJA\Cookies\katja@adx.chip[2].txt [ Cookie:katja@adx.chip.de/ ]
        C:\USERS\KATJA\Cookies\KZY3S2VW.txt [ Cookie:katja@zanox-affiliate.de/ ]
        C:\USERS\KATJA\Cookies\WR0MKY1A.txt [ Cookie:katja@advertising.com/ ]
        C:\USERS\KATJA\Cookies\0LZ2NX1C.txt [ Cookie:katja@doubleclick.net/ ]
        C:\USERS\KATJA\Cookies\JRHY2IHL.txt [ Cookie:katja@tacoda.at.atwola.com/ ]
        C:\USERS\KATJA\Cookies\NQH7EOWC.txt [ Cookie:katja@adform.net/ ]
        C:\USERS\KATJA\Cookies\8S6CO97B.txt [ Cookie:katja@counter.hitslink.com/ ]
        C:\USERS\KATJA\Cookies\M94PNHTH.txt [ Cookie:katja@atdmt.com/ ]
        C:\USERS\KATJA\Cookies\Y2RIZC1D.txt [ Cookie:katja@apmebf.com/ ]
        C:\USERS\KATJA\Cookies\I53B53EL.txt [ Cookie:katja@c.atdmt.com/ ]
        C:\USERS\KATJA\Cookies\DK3DAR86.txt [ Cookie:katja@ad1.adfarm1.adition.com/ ]
        C:\USERS\KATJA\Cookies\VNHMY39B.txt [ Cookie:katja@ad.zanox.com/ ]
        C:\USERS\KATJA\Cookies\185O2HJ3.txt [ Cookie:katja@ad.yieldmanager.com/ ]
        C:\USERS\KATJA\Cookies\WDZ7A7CS.txt [ Cookie:katja@adfarm1.adition.com/ ]
        C:\USERS\KATJA\Cookies\katja@yieldmanager[1].txt [ Cookie:katja@yieldmanager.net/ ]
        C:\USERS\KATJA\Cookies\katja@anrtx.tacoda[1].txt [ Cookie:katja@anrtx.tacoda.net/ ]
        C:\USERS\KATJA\Cookies\L2JW78Q3.txt [ Cookie:katja@at.atwola.com/ ]
        C:\USERS\KATJA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\KATJA@R1-ADS.ACE.ADVERTISING[2].TXT [ /R1-ADS.ACE.ADVERTISING ]
        .smartadserver.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .deutschepostag.112.2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.unitymedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        data.coremetrics.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.unitymedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        in.getclicky.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .cunda.122.2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .rezeptefinden.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .rezeptefinden.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        server.adformdsp.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.tchibo.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymediaforum.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymediaforum.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymediaforum.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .heizungsfinder.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .heizungsfinder.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .heizungsfinder.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .heizungsfinder.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        track.zalando.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        media4.tchibo-content.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .finderia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .finderia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        s09.flagcounter.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        cast.trustclick.ne.jp [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .discounty.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .discounty.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        stat.novasol.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracker.d-sire.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        zbox.zanox.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .mediaforge.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .mediaforge.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .mediaforge.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        adserver1.mokono.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        nl.sitestat.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        nl.sitestat.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .philips.112.2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wfkokhcjkbp.stats.esomniture.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        adserver.yopi.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        vb.mol.vs.bluedotmedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        vb.mol.vs.bluedotmedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ads.ventivmedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        panzertraffic.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.mediamarkt.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .mediamarkt.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        banner.reifensuchmaschine.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        adserver.tiervermittlung.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        delivery.atkmedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        adserver.autotreffen.at [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unrulymedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .toplist.cz [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .toplist.eu [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .ads20.wwe-media.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        aimfar.solution.weborama.fr [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .aimfar.solution.weborama.fr [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .weboramapublishertrackinguk2.solution.weborama.fr [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .weboramapublishertrackinguk2.solution.weborama.fr [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .4stats.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .4stats.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.mobile.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .myroitracking.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .bwincom.122.2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        stats.crsend.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        stats.crsend.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        stats.crsend.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.youporn.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .enoratraffic.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .syndication.traffichaus.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .syndication.traffichaus.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        openx.sexsearch.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .de.partypoker.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ads.crakmedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ads.trafficjunky.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.youporn.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .sexad.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .autoscout24.112.2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wnkiojdjwdp.stats.esomniture.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .petcarerx.112.2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .conrad.122.2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.count24.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.count24.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.count24.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.count24.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.count24.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.122.2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .microsoftinternetexplorer.112.2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        server.adformdsp.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adformdsp.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tracker.vinsight.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tto2.traffictrack.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        radservice.radroutenplaner.nrw.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        radservice.radroutenplaner.nrw.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .www.unitymedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.unitymedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.unitymedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymedia-kabelbw-helpdesk.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymedia-kabelbw-helpdesk.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymedia-kabelbw-helpdesk.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .advertstream.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .advertstream.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .kontera.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .rambler.ru [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .rambler.ru [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .openstat.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .spylog.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .shop.erfinderladen-berlin.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .shop.erfinderladen-berlin.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .shop.erfinderladen-berlin.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .blogads.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .blogads.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        buntebilder.trendymedia.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymediakabelbwforum.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymediakabelbwforum.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymediakabelbwforum.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymediakabelbwforum.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymediakabelbwforum.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymediakabelbwforum.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .unitymediakabelbwforum.de [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KATJA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXZ5U7IO.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\KATJA_ALLES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\WR83DOTO.DEFAULT\COOKIES.SQLITE ]


SUPERAntiSpyware ist noch offen. Soll ich die Cookies entfernen lassen?

cosinus 26.07.2012 21:54

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

sucnas 26.07.2012 23:04

Danke Arne.

Das System war ja die ganze Zeit stabil.
Ich denke durch die schnelle Handlung und des nicht klicken der angeblichen AVS konnte ich ein wenig mildern.

Die Cookies kann ich also getrost löschen?

Und könntest du mir noch die Frage beantworten was das im Infobereich sein könnte? Es ist immer noch vorhanden.

cosinus 27.07.2012 08:20

Die Cookies können weg. Was du im Infobereich gesehen hast sind Überreste, weil die dazugehörigen Dateien entfernt wurde - wie man diese verwaisten Einträge raus kriegt müsste man mal recherchieren, das weiß ich jetzt so nicht aus dem Stehgreif

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 12:02 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129