Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   MyStart Incredibar bei neuen Tabs lässt sich nicht beseitigen (https://www.trojaner-board.de/122468-mystart-incredibar-neuen-tabs-laesst-beseitigen.html)

T!tr0 20.08.2012 14:46

MyStart Incredibar bei neuen Tabs lässt sich nicht beseitigen
 
Hallo Leute,

ich habe mir wie viele andere anscheinend auch den MyStart Incredibar Trojaner eingefangen. Ich habe die Toolbar und die Suchmaschine schon wegbekommen. Den Webassistent und die Toolbar habe ich auch bei den Programmen deinstalliert.

Wie muss ich jetzt vorgehen das ich die Startseite bei neuen Tabs nichtmehr sehen muss?

Ich hoffe ihr könnt mir helfen und wäre euch echt dankbar :)

Gruß T!tr0

t'john 20.08.2012 14:54

:hallo:

Wie laeuft der Rechner?

1. Schritt
Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Malwarebytes Anti-Malware
- Anwendbar auf Windows 2000, XP, Vista und 7.
- Installiere das Programm in den vorgegebenen Pfad.
- Aktualisiere die Datenbank!
- Aktiviere "Komplett Scan durchführen" => Scan.
- Wähle alle verfügbaren Laufwerke (ausser CD/DVD) aus und starte den Scan.
- Funde bitte löschen lassen oder in Quarantäne.
- Wenn der Scan beendet ist, klicke auf "Zeige Resultate".
danach:

2. Schritt

Downloade Dir bitte AdwCleaner auf deinen Desktop.

  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

T!tr0 20.08.2012 15:16

So, hier mal der Log von Malewarebytes:

Malwarebytes Anti-Malware (Test) 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.08.20.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Maas :: MAAS-PC [Administrator]

Schutz: Aktiviert

20.08.2012 16:05:48
mbam-log-2012-08-20 (16-05-48).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|F:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 356912
Laufzeit: 9 Minute(n), 24 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Adwcleaner kommt gleich ;)

# AdwCleaner v1.801 - Logfile created 08/20/2012 at 16:16:58
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
# User : Maas - MAAS-PC
# Boot Mode : Normal
# Running from : C:\Users\Maas\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Users\Maas\AppData\Local\Ilivid Player
Folder Found : C:\Users\Maas\AppData\LocalLow\AskToolbar
File Found : C:\user.js

***** [Registry] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Key Found : HKLM\SOFTWARE\Web Assistant
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
[x64] Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
[x64] Key Found : HKLM\SOFTWARE\Web Assistant
[x64] Value Found : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]

***** [Registre - GUID] *****

[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v9.0.1 (de)

Profile name : default
File : C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js

Found : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb178?a=6R8BQWs4Vd&loc=FF_NT");
Found : user_pref("extensions.incredibar_i.aflt", "orgnl");
Found : user_pref("extensions.incredibar_i.dfltLng", "");
Found : user_pref("extensions.incredibar_i.did", "10643");
Found : user_pref("extensions.incredibar_i.excTlbr", false);
Found : user_pref("extensions.incredibar_i.id", "fcb3b847000000000000002354484502");
Found : user_pref("extensions.incredibar_i.installerproductid", "26");
Found : user_pref("extensions.incredibar_i.instlDay", "15564");
Found : user_pref("extensions.incredibar_i.instlRef", "");
Found : user_pref("extensions.incredibar_i.ms_url_id", "");
Found : user_pref("extensions.incredibar_i.newTab", false);
Found : user_pref("extensions.incredibar_i.ppd", "453");
Found : user_pref("extensions.incredibar_i.prdct", "incredibar");
Found : user_pref("extensions.incredibar_i.productid", "26");
Found : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
Found : user_pref("extensions.incredibar_i.smplGrp", "none");
Found : user_pref("extensions.incredibar_i.tlbrId", "base");
Found : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8BQWs4Vd&loc=IB[...]
Found : user_pref("extensions.incredibar_i.upn2", "6R8BQWs4Vd");
Found : user_pref("extensions.incredibar_i.upn2n", "92824867901773931");
Found : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");
Found : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1414:07:42");
Found : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");

*************************

AdwCleaner[R1].txt - [3245 octets] - [20/08/2012 16:16:58]

########## EOF - C:\AdwCleaner[R1].txt - [3373 octets] ##########

t'john 20.08.2012 17:38

Sehr gut! :daumenhoc


  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.




danach:


Malware-Scan mit Emsisoft Anti-Malware

Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm.
Lade über Jetzt Updaten die aktuellen Signaturen herunter.
Wähle den Freeware-Modus aus.

Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers.
Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten.

Anleitung: http://www.trojaner-board.de/103809-...i-malware.html

T!tr0 20.08.2012 18:39

# AdwCleaner v1.801 - Logfile created 08/20/2012 at 19:36:22
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
# User : Maas - MAAS-PC
# Boot Mode : Normal
# Running from : C:\Users\Maas\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\Maas\AppData\Local\Ilivid Player
Folder Deleted : C:\Users\Maas\AppData\LocalLow\AskToolbar
File Deleted : C:\user.js

***** [Registry] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Web Assistant
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]
[x64] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
[x64] Key Deleted : HKLM\SOFTWARE\Web Assistant

***** [Registre - GUID] *****

[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v9.0.1 (de)

Profile name : default
File : C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js

C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\user.js ... Deleted !

Deleted : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb178?a=6R8BQWs4Vd&loc=FF_NT");
Deleted : user_pref("extensions.incredibar_i.aflt", "orgnl");
Deleted : user_pref("extensions.incredibar_i.dfltLng", "");
Deleted : user_pref("extensions.incredibar_i.did", "10643");
Deleted : user_pref("extensions.incredibar_i.excTlbr", false);
Deleted : user_pref("extensions.incredibar_i.id", "fcb3b847000000000000002354484502");
Deleted : user_pref("extensions.incredibar_i.installerproductid", "26");
Deleted : user_pref("extensions.incredibar_i.instlDay", "15564");
Deleted : user_pref("extensions.incredibar_i.instlRef", "");
Deleted : user_pref("extensions.incredibar_i.ms_url_id", "");
Deleted : user_pref("extensions.incredibar_i.newTab", false);
Deleted : user_pref("extensions.incredibar_i.ppd", "453");
Deleted : user_pref("extensions.incredibar_i.prdct", "incredibar");
Deleted : user_pref("extensions.incredibar_i.productid", "26");
Deleted : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
Deleted : user_pref("extensions.incredibar_i.smplGrp", "none");
Deleted : user_pref("extensions.incredibar_i.tlbrId", "base");
Deleted : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8BQWs4Vd&loc=IB[...]
Deleted : user_pref("extensions.incredibar_i.upn2", "6R8BQWs4Vd");
Deleted : user_pref("extensions.incredibar_i.upn2n", "92824867901773931");
Deleted : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");
Deleted : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1414:07:42");
Deleted : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");

*************************

AdwCleaner[R1].txt - [3364 octets] - [20/08/2012 16:16:58]
AdwCleaner[R2].txt - [3424 octets] - [20/08/2012 16:18:12]
AdwCleaner[S1].txt - [283 octets] - [20/08/2012 16:18:18]
AdwCleaner[S2].txt - [3428 octets] - [20/08/2012 19:36:22]

########## EOF - C:\AdwCleaner[S2].txt - [3556 octets] ##########

Und hier Emsisoft ;)

Emsisoft Anti-Malware - Version 6.6
Letztes Update: 20.08.2012 19:54:42

Scan Einstellungen:

Scan Methode: Detail Scan
Objekte: Rootkits, Speicher, Traces, C:\, D:\, E:\, F:\, G:\
Archiv Scan: An
ADS Scan: An

Scan Beginn: 20.08.2012 19:54:49

C:\w7ldr gefunden: HackTool.Win32.Gendows!E2
C:\Windows\Setup\SCRIPTS\w7ldr1 gefunden: HackTool.Win32.Gendows!E2
C:\Windows\AutoKMS\AutoKMS.exe gefunden: Riskware.Activator.MSOffice!E2
G:\ICQ Downloads neu\237506453 Dani\Geld verdienen\Multiclicker.1.5.1.zip -> Multiclicker\Multiclicker-win.exe gefunden: Virus.Win32.Injector!E2

Gescannt 672787
Gefunden 4

Scan Ende: 20.08.2012 20:32:58
Scan Zeit: 0:38:09

C:\Windows\AutoKMS\AutoKMS.exe Quarantäne Riskware.Activator.MSOffice!E2
C:\w7ldr Quarantäne HackTool.Win32.Gendows!E2
C:\Windows\Setup\SCRIPTS\w7ldr1 Quarantäne HackTool.Win32.Gendows!E2

Quarantäne 3

Lass dich nicht täuschen warum nur 3 in Quarantäne gewandert sind, den Ordner mit dem Multiclicker habe ich schon während des Scans gelöscht ;)

t'john 20.08.2012 22:27

Sehr gut! :daumenhoc



Deinstalliere:
Emsisoft Anti-Malware


ESET Online Scanner

Vorbereitung

  • Schließe evtl. vorhandene externe Festplatten und/oder sonstigen Wechselmedien (z. B. evtl. vorhandene USB-Sticks) an den Rechner an.
  • Bitte während des Online-Scans Anti-Virus-Programm und Firewall deaktivieren.
  • Vista/Win7-User: Bitte den Browser unbedingt als Administrator starten.
Los geht's

  • Lade und starte Eset Smartinstaller
  • Haken setzen bei YES, I accept the Terms of Use.
  • Klick auf Start.
  • Haken setzen bei Remove found threads und Scan archives.
  • Klick auf Start.
  • Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Finish drücken.
  • Browser schließen.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (manchmal auch C:\Programme\Eset\log.txt) suchen und mit Deinem Editor öffnen.
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

T!tr0 21.08.2012 12:04

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=74545a457cfcbc4aac4c2afb117dfefb
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-08-21 10:55:09
# local_time=2012-08-21 12:55:09 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=3588 16777214 85 67 343947 14247551 0 0
# compatibility_mode=5893 16776574 100 94 25230461 97170485 0 0
# compatibility_mode=8192 67108863 100 0 117 117 0 0
# scanned=188985
# found=1
# cleaned=1
# scan_time=5874
C:\ProgramData\Spybot - Search & Destroy\Recovery\IncrediBar6.zip Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

t'john 21.08.2012 15:11

Java aktualisieren

Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
  • Downloade dir bitte die neueste Java-Version von hier
  • Speichere die jxpiinstall.exe
  • Schließe alle laufenden Programme. Speziell deinen Browser.
  • Starte die jxpiinstall.exe. Diese wird den Installer für die neueste Java Version ( Java 7 Update 6 ) herunter laden.
  • Wenn die Installation beendet wurde
    Start --> Systemsteuerung --> Programme und deinstalliere alle älteren Java Versionen.
  • Starte deinen Rechner neu sobald alle älteren Versionen deinstalliert wurden.
Nach dem Neustart
  • Öffne erneut die Systemsteuerung --> Programme und klicke auf das Java Symbol.
  • Im Reiter Allgemein, klicke unter Temporäre Internetdateien auf Einstellungen.
  • Klicke auf Dateien löschen....
  • Gehe sicher das überall ein Hacken gesetzt ist und klicke OK.
  • Klicke erneut OK.


Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html

Danach poste (kopieren und einfuegen) mir, was du hier angezeigt bekommst: PluginCheck

T!tr0 21.08.2012 17:06

PluginCheck

Der PluginCheck hilft die größten Sicherheitslücken beim Surfen im Internet zu schliessen.
Überprüft wird: Browser, Flash, Java und Adobe Reader Version.

Firefox 14.0.1 ist aktuell

Flash (11,3,300,270) ist aktuell.

Java (1,7,0,6) ist aktuell.

Adobe Reader 10,1,4,38 ist aktuell.

t'john 21.08.2012 17:38

Malware mit Combofix beseitigen

Lade Combofix von einem der folgenden Download-Spiegel herunter:

BleepingComputer.com - ForoSpyware.com

und speichere das Programm auf den Desktop, nicht woanders hin, das ist wichtig!
Beachte die ausführliche Original-Anleitung.

Zurzeit ist Combofix auf folgenden Windows-Versionen lauffähig:
  • Windows XP (nur 32-bit)
  • Windows Vista (32-bit/64-bit)
  • Windows 7 (32-bit/64-bit)


Vorbereitung und wichtige Hinweise

  • Bitte während des Scans mit Combofix Antiviren- sowie Antispy-Programme, die Firewall und evtl. vorhandenes Skript-Blocking (Norton) deaktivieren.
  • Liste der zu deaktivierenden Programme.
    Bei Unklarheiten bitte fragen.


  • ComboFix wird Deine Einstellungen in Bezug auf den Bildschirmschoner zurücksetzen.
  • Diese Einstellungen kannst Du nach Beendigung unserer Bereinigung wieder ändern.
  • Mache nichts anderes, wenn es Dir nicht gelungen ist, Combofix laufen zu lassen.
  • Teile uns das mit und warte auf unsere Anweisungen.


  • Starte die Combofix.exe mit Rechtsklick => Als Administrator ausführen und folge den Anweisungen.
  • Während des Laufs von Combofix nichts anderes am Computer machen!
  • Akzeptiere die Bedingungen (Disclaimer) mit "Ja".


  • Sollte Combofix eine aktuellere Version anbieten, Downlaod erlauben.
  • Klicke "Ja", um mit dem Suchlauf nach Malware fortzufahren.
  • Es erscheint eine blaue Eingabeaufforderung, Combofix wird für den Suchlauf vorbereitet.
  • Bitte nicht in dieses Combofix-Fenster klicken.
  • Das könnte Dein System einfrieren oder hängen bleiben lassen.
  • Es wird ein Backup Deiner Registry erstellt.
  • Nun werden die einzelnen Stufen des Programms abgearbeitet, das kann eine Weile dauern.


  • Wenn ComboFix fertig ist, wird es ein Log erstellen (bitte warten, das dauert einen Moment).
  • Unbedingt warten, bis sich das Combofix-Fenster geschlossen hat und das Logfile im Editor erscheint.
  • Bitte poste die Log-Dateien C:\ComboFix.txt und C:\Qoobox\Add-Remove Programs.txt in Code-Tags hier in den Thread.


  • Hinweis: Combofix macht aus verschiedenen Gründen den Internet Explorer zum Standard-Browser und erstellt ein IE-Icon auf dem Desktop.
  • Das IE-Desktop-Icon kannst Du nach der Bereinigung wieder löschen und Deinen bevorzugten Browser wieder als Standard-Browser einstellen.



Combofix nicht auf eigene Faust einsetzen. Wenn keine entsprechende Infektion vorliegt, kann das den Rechner lahmlegen und/oder nachhaltig schädigen!

T!tr0 21.08.2012 17:54

Danke, das werde ich morgen gleich mal machen, nur heute fehlt mir leider die Zeit dazu ;)

Aber ich möchte mich jetzt schonmal für deine Hilfe bedanken, ich denke wir sind auf einem guten weg :)

t'john 21.08.2012 17:55

Alles klar.

T!tr0 22.08.2012 13:01

Code:

ComboFix 12-08-22.01 - Maas 22.08.2012  13:44:51.1.8 - x64
Microsoft Windows 7 Ultimate  6.1.7601.1.1252.49.1031.18.6135.4523 [GMT 2:00]
ausgeführt von:: c:\users\Maas\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\gema
c:\windows\SysWow64\muzapp.exe
c:\windows\SysWow64\tmp5BF4.tmp
c:\windows\SysWow64\tmp5C05.tmp
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-07-22 bis 2012-08-22  ))))))))))))))))))))))))))))))
.
.
2012-08-22 11:47 . 2012-08-22 11:47        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-08-21 16:05 . 2012-08-21 16:05        --------        d-----w-        c:\program files (x86)\Common Files\Java
2012-08-21 16:04 . 2012-08-21 16:04        95208        ----a-w-        c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-08-21 15:59 . 2012-08-21 15:59        --------        d-----w-        c:\program files (x86)\Java
2012-08-20 17:42 . 2012-08-21 09:12        --------        d-----w-        c:\program files (x86)\Emsisoft Anti-Malware
2012-08-20 12:42 . 2012-08-20 12:42        --------        d-----w-        c:\users\Maas\AppData\Roaming\Malwarebytes
2012-08-20 12:42 . 2012-08-20 12:42        --------        d-----w-        c:\programdata\Malwarebytes
2012-08-20 12:42 . 2012-07-03 11:46        24904        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-08-19 10:23 . 2012-08-19 10:38        --------        d-----w-        c:\programdata\Spybot - Search & Destroy
2012-08-16 12:22 . 2012-05-04 11:00        366592        ----a-w-        c:\windows\system32\qdvd.dll
2012-08-16 12:22 . 2012-05-04 09:59        514560        ----a-w-        c:\windows\SysWow64\qdvd.dll
2012-08-16 10:52 . 2012-08-17 09:44        --------        d-----w-        c:\windows\system32\drivers\NISx64\1308000.00E
2012-08-13 14:47 . 2012-08-13 14:47        --------        d-----w-        c:\users\UpdatusUser
2012-08-13 14:46 . 2012-08-13 14:46        --------        d-----w-        C:\NVIDIA
2012-08-12 17:35 . 2012-08-12 17:35        --------        d-----w-        c:\users\Maas\AppData\Roaming\NVIDIA
2012-08-12 17:34 . 2012-08-12 17:34        --------        d-----w-        c:\program files (x86)\AMD
2012-08-12 17:34 . 2010-06-02 02:55        77656        ----a-w-        c:\windows\system32\XAPOFX1_5.dll
2012-08-12 17:34 . 2010-06-02 02:55        518488        ----a-w-        c:\windows\system32\XAudio2_7.dll
2012-08-12 17:34 . 2010-06-02 02:55        176984        ----a-w-        c:\windows\system32\xactengine3_7.dll
2012-08-12 17:34 . 2010-05-26 09:41        511328        ----a-w-        c:\windows\system32\d3dx10_43.dll
2012-08-12 17:34 . 2010-05-26 09:41        276832        ----a-w-        c:\windows\system32\d3dx11_43.dll
2012-08-12 17:34 . 2010-05-26 09:41        2526056        ----a-w-        c:\windows\system32\D3DCompiler_43.dll
2012-08-12 17:34 . 2010-05-26 09:41        1907552        ----a-w-        c:\windows\system32\d3dcsx_43.dll
2012-07-27 20:51 . 2012-07-27 20:51        184248        ----a-w-        c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-22 10:43 . 2012-04-03 15:13        696520        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-22 10:43 . 2011-09-23 16:32        73416        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-21 16:04 . 2012-06-14 21:00        821736        ----a-w-        c:\windows\SysWow64\npDeployJava1.dll
2012-08-21 16:04 . 2011-10-04 08:29        746984        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2012-08-16 12:22 . 2011-09-24 12:34        62134624        ----a-w-        c:\windows\system32\MRT.exe
2012-06-15 16:00 . 2012-06-15 16:00        283200        ----a-w-        c:\windows\system32\drivers\dtsoftbus01.sys
2012-06-09 05:43 . 2012-07-11 17:12        14172672        ----a-w-        c:\windows\system32\shell32.dll
2012-06-06 06:06 . 2012-07-11 17:12        2004480        ----a-w-        c:\windows\system32\msxml6.dll
2012-06-06 06:06 . 2012-07-11 17:12        1881600        ----a-w-        c:\windows\system32\msxml3.dll
2012-06-06 06:02 . 2012-07-11 17:11        1133568        ----a-w-        c:\windows\system32\cdosys.dll
2012-06-06 05:05 . 2012-07-11 17:12        1390080        ----a-w-        c:\windows\SysWow64\msxml6.dll
2012-06-06 05:05 . 2012-07-11 17:12        1236992        ----a-w-        c:\windows\SysWow64\msxml3.dll
2012-06-06 05:03 . 2012-07-11 17:11        805376        ----a-w-        c:\windows\SysWow64\cdosys.dll
2012-06-04 16:14 . 2012-06-04 16:14        91648        ----a-w-        c:\windows\system32\SetIEInstalledDate.exe
2012-06-04 16:14 . 2012-06-04 16:14        89088        ----a-w-        c:\windows\system32\RegisterIEPKEYs.exe
2012-06-04 16:14 . 2012-06-04 16:14        89088        ----a-w-        c:\windows\system32\ie4uinit.exe
2012-06-04 16:14 . 2012-06-04 16:14        86528        ----a-w-        c:\windows\SysWow64\iesysprep.dll
2012-06-04 16:14 . 2012-06-04 16:14        85504        ----a-w-        c:\windows\system32\iesetup.dll
2012-06-04 16:14 . 2012-06-04 16:14        82432        ----a-w-        c:\windows\system32\icardie.dll
2012-06-04 16:14 . 2012-06-04 16:14        76800        ----a-w-        c:\windows\SysWow64\SetIEInstalledDate.exe
2012-06-04 16:14 . 2012-06-04 16:14        76800        ----a-w-        c:\windows\system32\tdc.ocx
2012-06-04 16:14 . 2012-06-04 16:14        74752        ----a-w-        c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-06-04 16:14 . 2012-06-04 16:14        74752        ----a-w-        c:\windows\SysWow64\iesetup.dll
2012-06-04 16:14 . 2012-06-04 16:14        697344        ----a-w-        c:\windows\system32\msfeeds.dll
2012-06-04 16:14 . 2012-06-04 16:14        65024        ----a-w-        c:\windows\system32\pngfilt.dll
2012-06-04 16:14 . 2012-06-04 16:14        63488        ----a-w-        c:\windows\SysWow64\tdc.ocx
2012-06-04 16:14 . 2012-06-04 16:14        603648        ----a-w-        c:\windows\system32\vbscript.dll
2012-06-04 16:14 . 2012-06-04 16:14        55296        ----a-w-        c:\windows\system32\msfeedsbs.dll
2012-06-04 16:14 . 2012-06-04 16:14        534528        ----a-w-        c:\windows\system32\ieapfltr.dll
2012-06-04 16:14 . 2012-06-04 16:14        49664        ----a-w-        c:\windows\system32\imgutil.dll
2012-06-04 16:14 . 2012-06-04 16:14        48640        ----a-w-        c:\windows\SysWow64\mshtmler.dll
2012-06-04 16:14 . 2012-06-04 16:14        48640        ----a-w-        c:\windows\system32\mshtmler.dll
2012-06-04 16:14 . 2012-06-04 16:14        452608        ----a-w-        c:\windows\system32\dxtmsft.dll
2012-06-04 16:14 . 2012-06-04 16:14        448512        ----a-w-        c:\windows\system32\html.iec
2012-06-04 16:14 . 2012-06-04 16:14        420864        ----a-w-        c:\windows\SysWow64\vbscript.dll
2012-06-04 16:14 . 2012-06-04 16:14        403248        ----a-w-        c:\windows\system32\iedkcs32.dll
2012-06-04 16:14 . 2012-06-04 16:14        39936        ----a-w-        c:\windows\system32\iernonce.dll
2012-06-04 16:14 . 2012-06-04 16:14        3695416        ----a-w-        c:\windows\system32\ieapfltr.dat
2012-06-04 16:14 . 2012-06-04 16:14        367104        ----a-w-        c:\windows\SysWow64\html.iec
2012-06-04 16:14 . 2012-06-04 16:14        35840        ----a-w-        c:\windows\SysWow64\imgutil.dll
2012-06-04 16:14 . 2012-06-04 16:14        30720        ----a-w-        c:\windows\system32\licmgr10.dll
2012-06-04 16:14 . 2012-06-04 16:14        282112        ----a-w-        c:\windows\system32\dxtrans.dll
2012-06-04 16:14 . 2012-06-04 16:14        267776        ----a-w-        c:\windows\system32\ieaksie.dll
2012-06-04 16:14 . 2012-06-04 16:14        249344        ----a-w-        c:\windows\system32\webcheck.dll
2012-06-04 16:14 . 2012-06-04 16:14        23552        ----a-w-        c:\windows\SysWow64\licmgr10.dll
2012-06-04 16:14 . 2012-06-04 16:14        222208        ----a-w-        c:\windows\system32\msls31.dll
2012-06-04 16:14 . 2012-06-04 16:14        197120        ----a-w-        c:\windows\system32\msrating.dll
2012-06-04 16:14 . 2012-06-04 16:14        165888        ----a-w-        c:\windows\system32\iexpress.exe
2012-06-04 16:14 . 2012-06-04 16:14        163840        ----a-w-        c:\windows\system32\ieakui.dll
2012-06-04 16:14 . 2012-06-04 16:14        161792        ----a-w-        c:\windows\SysWow64\msls31.dll
2012-06-04 16:14 . 2012-06-04 16:14        160256        ----a-w-        c:\windows\system32\wextract.exe
2012-06-04 16:14 . 2012-06-04 16:14        160256        ----a-w-        c:\windows\system32\ieakeng.dll
2012-06-04 16:14 . 2012-06-04 16:14        152064        ----a-w-        c:\windows\SysWow64\wextract.exe
2012-06-04 16:14 . 2012-06-04 16:14        150528        ----a-w-        c:\windows\SysWow64\iexpress.exe
2012-06-04 16:14 . 2012-06-04 16:14        149504        ----a-w-        c:\windows\system32\occache.dll
2012-06-04 16:14 . 2012-06-04 16:14        145920        ----a-w-        c:\windows\system32\iepeers.dll
2012-06-04 16:14 . 2012-06-04 16:14        135168        ----a-w-        c:\windows\system32\IEAdvpack.dll
2012-06-04 16:14 . 2012-06-04 16:14        12288        ----a-w-        c:\windows\system32\mshta.exe
2012-06-04 16:14 . 2012-06-04 16:14        11776        ----a-w-        c:\windows\SysWow64\mshta.exe
2012-06-04 16:14 . 2012-06-04 16:14        114176        ----a-w-        c:\windows\system32\admparse.dll
2012-06-04 16:14 . 2012-06-04 16:14        111616        ----a-w-        c:\windows\system32\iesysprep.dll
2012-06-04 16:14 . 2012-06-04 16:14        110592        ----a-w-        c:\windows\SysWow64\IEAdvpack.dll
2012-06-04 16:14 . 2012-06-04 16:14        10752        ----a-w-        c:\windows\system32\msfeedssync.exe
2012-06-04 16:14 . 2012-06-04 16:14        103936        ----a-w-        c:\windows\system32\inseng.dll
2012-06-04 16:14 . 2012-06-04 16:14        101888        ----a-w-        c:\windows\SysWow64\admparse.dll
2012-06-02 22:19 . 2012-06-19 14:48        38424        ----a-w-        c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 14:48        2428952        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-19 14:48        57880        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 14:48        44056        ----a-w-        c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 14:48        701976        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-19 14:48        2622464        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-19 14:48        99840        ----a-w-        c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-19 14:48        186752        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-19 14:48        36864        ----a-w-        c:\windows\system32\wuapp.exe
2012-06-02 05:50 . 2012-07-11 17:11        458704        ----a-w-        c:\windows\system32\drivers\cng.sys
2012-06-02 05:48 . 2012-07-11 17:11        95600        ----a-w-        c:\windows\system32\drivers\ksecdd.sys
2012-06-02 05:48 . 2012-07-11 17:11        151920        ----a-w-        c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 05:45 . 2012-07-11 17:11        340992        ----a-w-        c:\windows\system32\schannel.dll
2012-06-02 05:44 . 2012-07-11 17:11        307200        ----a-w-        c:\windows\system32\ncrypt.dll
2012-06-02 04:40 . 2012-07-11 17:11        22016        ----a-w-        c:\windows\SysWow64\secur32.dll
2012-06-02 04:40 . 2012-07-11 17:11        225280        ----a-w-        c:\windows\SysWow64\schannel.dll
2012-06-02 04:39 . 2012-07-11 17:11        219136        ----a-w-        c:\windows\SysWow64\ncrypt.dll
2012-06-02 04:34 . 2012-07-11 17:11        96768        ----a-w-        c:\windows\SysWow64\sspicli.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ICQ"="e:\program files (x86)\ICQ7.6\ICQ.exe" [2011-10-10 127040]
"Steam"="e:\program files (x86)\Steam\steam.exe" [2012-08-04 1353080]
"MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240]
"DAEMON Tools Lite"="e:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]
"SpybotSD TeaTimer"="e:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Ai Nap"="c:\program files (x86)\ASUS\AI Suite\AiNap\AiNap.exe" [2009-08-21 1427968]
"QFan Help"="c:\program files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe" [2009-08-19 603136]
"Cpu Level Up help"="c:\program files (x86)\ASUS\AI Suite\CpuLevelUpHelp.exe" [2009-08-21 887936]
"SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2011-09-23 1310720]
"WinampAgent"="e:\program files (x86)\Winamp\winampa.exe" [2011-07-11 74752]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"SSBkgdUpdate"="c:\program files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files (x86)\ScanSoft\PaperPort\pptd40nt.exe" [2008-07-09 29984]
"IndexSearch"="c:\program files (x86)\ScanSoft\PaperPort\IndexSearch.exe" [2008-07-09 46368]
"PPort11reminder"="c:\program files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe" [2009-08-03 1167360]
"ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
"iTunesHelper"="e:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-07 421776]
"amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"Malwarebytes' Anti-Malware"="e:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-04 136176]
R2 MBAMService;MBAMService;e:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-02-24 99384]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-04 136176]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;e:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 PorscheWheelFilterUsb;PorscheWheelFilterUsb;c:\windows\system32\DRIVERS\PWFilterUsb.sys [2010-12-15 58448]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-02-24 203320]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WSDPrintDevice;WSD-Druckunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
S0 mv61xx;mv61xx;c:\windows\system32\DRIVERS\mv61xx.sys [2009-05-11 178728]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1308000.00E\SYMDS64.SYS [2011-07-25 451192]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1308000.00E\SYMEFA64.SYS [2012-05-22 1129120]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120811.003\BHDrvx64.sys [2012-08-11 1385120]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1308000.00E\ccSetx64.sys [2012-06-07 167072]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-06-15 283200]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120821.001\IDSvia64.sys [2012-06-14 509088]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1308000.00E\Ironx64.SYS [2012-04-18 190072]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1308000.00E\SYMNETS.SYS [2012-04-18 405624]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 DevoloNetworkService;devolo Network Service;e:\program files (x86)\devolo\dlan\devolonetsvc.exe [2010-07-19 2231616]
S2 NIS;Norton Internet Security;e:\program files (x86)\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe [2012-06-16 138272]
S2 NPF_devolo;NetGroup Packet Filter Driver (devolo);c:\windows\sysWOW64\drivers\npf_devolo.sys [2010-06-10 34048]
S2 SBSDWSCService;SBSD Security Center Service;e:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 BrSerIb;Brother Serial Interface Driver(WDM);c:\windows\system32\DRIVERS\BrSerIb.sys [2009-11-03 87552]
S3 BrUsbSIb;Brother Serial USB Driver(WDM);c:\windows\system32\DRIVERS\BrUsbSIb.sys [2009-11-03 14592]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-10 138912]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2012-04-18 188736]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-09-28 395264]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2012-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-04 17:14]
.
2012-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-04 17:14]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAX"="c:\program files (x86)\Analog Devices\SoundMAX\soundmax.exe" [2009-05-18 3866624]
"BCSSync"="e:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube to MP3 Converter - c:\users\Maas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xcel exportieren - e:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - e:\program files (x86)\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.de
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"e:\program files (x86)\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe\" /s \"NIS\" /m \"e:\program files (x86)\Norton Internet Security\Engine\19.8.0.14\diMaster.dll\" /prefetch:1"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-08-22  13:50:29 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-08-22 11:50
.
Vor Suchlauf: 3.516.809.216 Bytes frei
Nach Suchlauf: 3.372.150.784 Bytes frei
.
- - End Of File - - E7F25D6EC6846AA45FD537CE5A55A298

Code:

Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.4) - Deutsch
AI Suite
Apple Application Support
Apple Software Update
Ashampoo WinOptimizer 8 v.8.14
Batman: Arkham City™
Brother MFL-Pro Suite MFC-5895CW
CDBurnerXP
Counter-Strike: Source
DAEMON Tools Lite
devolo dLAN-Konfigurationsassistent
devolo dLAN Cockpit
devolo Informer
dLAN Cockpit
Dual-Core Optimizer
eReg
EVEREST Home Edition v2.20
F1 2011
Foxit Reader
Free Audio CD to MP3 Converter version 1.3.12.908
Free YouTube to MP3 Converter version 3.10.11.923
Freemake Audio Converter Version 1.1.0
Google Earth Plug-in
Google Update Helper
GrabIt 1.7.2 Beta 6 (build 1008)
Host OpenAL (ADI)
Hotfix for Microsoft .NET Framework 4 Client Profile (KB2461678)
ICQ7.6
Java 7 Update 6
Java Auto Updater
Malwarebytes Anti-Malware Version 1.62.0.1300
marvell 61xx
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319
Mozilla Firefox 14.0.1 (x86 de)
Mozilla Firefox 9.0.1 (x86 de)
Mozilla Thunderbird (6.0.2)
Mozilla Thunderbird (8.0)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Norton Internet Security
NVIDIA PhysX
OpenAL
OpenOffice.org 3.3
QuickPar 0.9
QuickTime
Rapture3D 2.4.9 Game
ScanSoft PaperPort 11
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
SoundMAX
Spybot - Search & Destroy
Steam
System Requirements Lab
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
VLC media player 2.0.1
Winamp
Winamp Erkennungs-Plug-in


t'john 22.08.2012 18:13

Kontrollscan:

1. Schritt

Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Malwarebytes Anti-Malware
- Anwendbar auf Windows 2000, XP, Vista und 7.
- Installiere das Programm in den vorgegebenen Pfad.
- Aktualisiere die Datenbank!
- Aktiviere "Komplett Scan durchführen" => Scan.
- Wähle alle verfügbaren Laufwerke (ausser CD/DVD) aus und starte den Scan.
- Funde bitte löschen lassen oder in Quarantäne.
- Wenn der Scan beendet ist, klicke auf "Zeige Resultate".

T!tr0 22.08.2012 19:29

Code:

Malwarebytes Anti-Malware (Test) 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.08.22.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Maas :: MAAS-PC [Administrator]

Schutz: Aktiviert

22.08.2012 20:14:11
mbam-log-2012-08-22 (20-14-11).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 395881
Laufzeit: 14 Minute(n), 38 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


t'john 22.08.2012 22:18

Incredi noch da?

T!tr0 23.08.2012 10:01

Ja leider :killpc:

t'john 23.08.2012 19:06

Ababeiten: http://www.trojaner-board.de/122287-...entfernen.html

T!tr0 27.08.2012 09:56

Tut mir leid, ich war über das Wochenende nicht zu Hause.

Die Liste habe ich abgearbeitet aber ich habe nach wie vor noch das Problem wenn ich einen neuen Tab aufmache das die MyStart Suche kommt :(

Unter about:config finde ich unter "mystart" nur noch diesen Eintrag, der ändert sich aber bei jedem Neustart wieder.

browser.newtab.url;hxxp://mystart.incredibar.com/mb178?a=6R8BQWs4Vd&loc=FF_NT

t'john 27.08.2012 18:09

Lasse SuperAntiSpyware laufen: http://www.trojaner-board.de/51871-a...tispyware.html

T!tr0 28.08.2012 13:03

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 08/28/2012 at 02:01 PM

Application Version : 5.5.1012

Core Rules Database Version : 9134
Trace Rules Database Version: 6946

Scan type      : Complete Scan
Total Scan Time : 01:02:57

Operating System Information
Windows 7 Ultimate 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Administrator

Memory items scanned      : 732
Memory threats detected  : 0
Registry items scanned    : 70467
Registry threats detected : 0
File items scanned        : 196518
File threats detected    : 378

Adware.Tracking Cookie
        C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Cookies\ZS05IQQD.txt [ /ads.creative-serving.com ]
        C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Cookies\46GP8UFL.txt [ /2o7.net ]
        C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Cookies\OIBURPNI.txt [ /bs.serving-sys.com ]
        C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Cookies\XGNOBNUZ.txt [ /server.adformdsp.net ]
        C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Cookies\85WO3KLD.txt [ /serving-sys.com ]
        C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Cookies\VTJ1JC1K.txt [ /atdmt.com ]
        C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Cookies\35WF9CHE.txt [ /adformdsp.net ]
        C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Cookies\ZGW0KYY0.txt [ /doubleclick.net ]
        C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Cookies\MDDSAX08.txt [ /invitemedia.com ]
        C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Cookies\DLH3JC0R.txt [ /adform.net ]
        C:\USERS\MAAS\Cookies\46GP8UFL.txt [ Cookie:maas@2o7.net/ ]
        C:\USERS\MAAS\Cookies\OIBURPNI.txt [ Cookie:maas@bs.serving-sys.com/ ]
        C:\USERS\MAAS\Cookies\XGNOBNUZ.txt [ Cookie:maas@server.adformdsp.net/ ]
        C:\USERS\MAAS\Cookies\VTJ1JC1K.txt [ Cookie:maas@atdmt.com/ ]
        C:\USERS\MAAS\Cookies\35WF9CHE.txt [ Cookie:maas@adformdsp.net/ ]
        C:\USERS\MAAS\Cookies\ZGW0KYY0.txt [ Cookie:maas@doubleclick.net/ ]
        C:\USERS\MAAS\Cookies\MDDSAX08.txt [ Cookie:maas@invitemedia.com/ ]
        C:\USERS\MAAS\Cookies\DLH3JC0R.txt [ Cookie:maas@adform.net/ ]
        delivery.ibanner.de [ C:\USERS\MAAS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\JWH6HF6T ]
        media.mtvnservices.com [ C:\USERS\MAAS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\JWH6HF6T ]
        secure-uk.imrworldwide.com [ C:\USERS\MAAS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\JWH6HF6T ]
        tracking.mlsat02.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        server.adformdsp.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adformdsp.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .secmedia.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .secmedia.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .banner.congstar.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .banner.congstar.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .banner.congstar.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .warez-load.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .warez-load.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .warez-load.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        a.lon.lpsnmedia.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        a.lon.lpsnmedia.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        a.lon.lpsnmedia.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjl4khc5ohp.stats.esomniture.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.singletracksafari.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .essexhertsmtb.co.uk [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .essexhertsmtb.co.uk [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .essexhertsmtb.co.uk [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .essexhertsmtb.co.uk [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .essexhertsmtb.co.uk [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .essexhertsmtb.co.uk [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .ad1.adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .ad1.adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .ad1.adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .pixel.invitemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .pixel.invitemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .pixel.invitemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .track.shop2market.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .track.shop2market.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .track.shop2market.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        dk-adserver.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adserver.freenet.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adserver.freenet.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adserver.freenet.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .ad.yieldmanager.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .ad.yieldmanager.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .ad.yieldmanager.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wgmiggdzgeq.stats.esomniture.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .imagesrv.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .imagesrv.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .imagesrv.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wfkiwjd5ebo.stats.esomniture.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .blogads.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .blogads.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .c.amazon-adsystem.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .c.amazon-adsystem.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .c.amazon-adsystem.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .aax-eu.amazon-adsystem.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .aax-eu.amazon-adsystem.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .aax-eu.amazon-adsystem.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .skydeutschland.122.2o7.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        adserver1.mokono.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        stat.dealtime.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        track.zalando.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .bizrate.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .kontera.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .americanexpress.122.2o7.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .autoscout24.112.2o7.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        adserver.gb4.motorpresse.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        uk.sitestat.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        uk.sitestat.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.bike-discount.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        targeting.revenuemax.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .sonyeurope.112.2o7.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        server.lon.liveperson.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tracker.vinsight.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        tracking.fahrrad.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .bike-discount.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .bike-discount.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .bike-discount.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        www.bike-discount.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .paypal.112.2o7.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        tomtailor.dyntracker.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .comstats.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .comstats.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .comstats.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .comstats.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .comstats.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ads.gamersmedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ads.gamersmedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ads.gamersmedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\MAAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UAMSLMVL.DEFAULT\COOKIES.SQLITE ]


t'john 28.08.2012 19:52

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.




danach:


CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.


Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\*.*
%APPDATA%\*AcroIEH*.*
%APPDATA%\*.exe
%APPDATA%\*.tmp
CREATERESTOREPOINT


T!tr0 30.08.2012 11:48

Code:

# AdwCleaner v1.801 - Logfile created 08/30/2012 at 12:48:16
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
# User : Maas - MAAS-PC
# Boot Mode : Normal
# Running from : C:\Users\Maas\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****

[x64] Value Found : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]

***** [Registre - GUID] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v9.0.1 (de)

Profile name : default
File : C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js

Found : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb178?a=6R8BQWs4Vd&loc=FF_NT");

*************************

AdwCleaner[R1].txt - [3364 octets] - [20/08/2012 16:16:58]
AdwCleaner[R2].txt - [3424 octets] - [20/08/2012 16:18:12]
AdwCleaner[S1].txt - [283 octets] - [20/08/2012 16:18:18]
AdwCleaner[S2].txt - [3551 octets] - [20/08/2012 19:36:22]
AdwCleaner[R3].txt - [1144 octets] - [30/08/2012 12:48:16]

########## EOF - C:\AdwCleaner[R3].txt - [1272 octets] ##########

Code:

OTL logfile created on: 30.08.2012 12:51:25 - Run 1
OTL by OldTimer - Version 3.2.59.1    Folder = C:\Users\Maas\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5,99 Gb Total Physical Memory | 4,05 Gb Available Physical Memory | 67,62% Memory free
11,98 Gb Paging File | 9,83 Gb Available in Paging File | 82,06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 43,95 Gb Total Space | 3,27 Gb Free Space | 7,44% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 181,94 Gb Free Space | 39,06% Space Free | Partition Type: NTFS
Drive E: | 75,29 Gb Total Space | 33,91 Gb Free Space | 45,04% Space Free | Partition Type: NTFS
Drive F: | 39,06 Gb Total Space | 38,97 Gb Free Space | 99,77% Space Free | Partition Type: NTFS
Drive G: | 284,71 Gb Total Space | 52,53 Gb Free Space | 18,45% Space Free | Partition Type: NTFS
 
Computer Name: MAAS-PC | User Name: Maas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.08.30 12:49:49 | 000,598,528 | ---- | M] (OldTimer Tools) -- C:\Users\Maas\Desktop\otl.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.07.03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.06.16 04:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\ccsvchst.exe
PRC - [2012.05.15 12:48:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012.04.17 17:19:40 | 003,671,872 | ---- | M] (DT Soft Ltd) -- E:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2012.02.23 12:30:40 | 000,059,240 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
PRC - [2011.07.11 23:47:06 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- E:\Program Files (x86)\Winamp\winampa.exe
PRC - [2010.07.19 19:57:32 | 002,231,616 | ---- | M] () -- E:\Program Files (x86)\devolo\dlan\devolonetsvc.exe
PRC - [2009.08.21 11:22:50 | 001,427,968 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite\AiNap\AiNap.exe
PRC - [2009.08.19 16:44:56 | 000,603,136 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe
PRC - [2009.03.30 16:00:54 | 000,221,184 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe
PRC - [2009.01.26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) -- E:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- E:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.09.27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.09.27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009.09.30 11:33:06 | 000,024,576 | ---- | M] () -- C:\Windows\SysWOW64\AsIO.dll
MOD - [2009.02.27 17:38:20 | 000,139,264 | R--- | M] () -- C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
MOD - [2008.02.25 15:08:54 | 000,208,896 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite\AiNap\AiNap.dll
MOD - [2007.01.03 22:25:56 | 000,008,704 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite\AiNap\vvc.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2011.09.23 18:06:49 | 000,111,616 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\AEADISRV.EXE -- (AEADIFilters)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012.08.12 13:57:03 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.06.16 04:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe -- (NIS)
SRV - [2012.05.15 12:48:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2011.09.27 21:04:08 | 000,359,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2011.08.12 01:38:04 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Programme\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
SRV - [2011.06.12 12:43:28 | 051,740,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2010.07.19 19:57:32 | 002,231,616 | ---- | M] () [Auto | Running] -- E:\Program Files (x86)\devolo\dlan\devolonetsvc.exe -- (DevoloNetworkService)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.01.09 22:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010.01.09 22:20:56 | 000,174,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose64)
SRV - [2009.08.18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.07.06 04:17:58 | 000,037,536 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\srtspx64.sys -- (SRTSPX)
DRV:64bit: - [2012.07.06 04:17:57 | 000,737,952 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2012.07.03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.06.15 18:00:28 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2012.06.07 06:43:38 | 000,167,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\ccsetx64.sys -- (ccSet_NIS)
DRV:64bit: - [2012.05.22 03:37:12 | 001,129,120 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\symefa64.sys -- (SymEFA)
DRV:64bit: - [2012.04.18 19:08:03 | 000,188,736 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2012.04.18 04:13:32 | 000,405,624 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\symnets.sys -- (SymNetS)
DRV:64bit: - [2012.04.18 03:42:14 | 000,190,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\ironx64.sys -- (SymIRON)
DRV:64bit: - [2012.03.28 18:23:22 | 000,175,736 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.02.24 11:14:42 | 000,203,320 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2012.02.24 11:14:42 | 000,099,384 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2012.02.15 11:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011.09.23 18:06:49 | 000,475,136 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV:64bit: - [2011.09.02 08:30:46 | 000,042,776 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2011.09.02 08:30:36 | 000,060,696 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2011.09.02 08:30:24 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2011.07.25 20:18:36 | 000,451,192 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\symds64.sys -- (SymDS)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.12.15 11:24:18 | 000,058,448 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PWFilterUsb.sys -- (PorscheWheelFilterUsb)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 13:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2009.11.03 13:06:36 | 000,087,552 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BrSerIb.sys -- (BrSerIb)
DRV:64bit: - [2009.11.03 13:06:36 | 000,014,592 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BrUsbSib.sys -- (BrUsbSIb)
DRV:64bit: - [2009.09.28 09:22:00 | 000,395,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009.07.16 11:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 02:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009.07.14 02:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009.05.12 00:49:10 | 000,178,728 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mv61xx.sys -- (mv61xx)
DRV - [2012.08.29 19:12:11 | 002,084,000 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120829.003\ex64.sys -- (NAVEX15)
DRV - [2012.08.29 19:12:11 | 000,125,600 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120829.003\eng64.sys -- (NAVENG)
DRV - [2012.08.22 04:05:05 | 000,512,672 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120828.001\IDSviA64.sys -- (IDSVia64)
DRV - [2012.08.11 02:25:13 | 001,385,120 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120823.005\BHDrvx64.sys -- (BHDrvx64)
DRV - [2012.08.10 18:36:48 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012.08.10 15:56:19 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2011.07.22 18:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV - [2011.07.12 23:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV - [2010.06.10 13:32:14 | 000,034,048 | ---- | M] (CACE Technologies) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\drivers\npf_devolo.sys -- (NPF_devolo)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B4 34 3C 2E 07 77 CD 01  [binary data]
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: E:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: E:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.6.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.6.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: E:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPlgn\ [2012.02.03 14:18:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\ [2012.08.30 12:46:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components [2012.07.18 20:19:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins [2012.08.17 11:48:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Components: E:\Program Files (x86)\Mozilla Thunderbird\components [2011.09.28 18:06:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Plugins: E:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components [2012.07.18 20:19:56 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins [2012.08.17 11:48:14 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: E:\Program Files (x86)\Mozilla Thunderbird\components [2011.09.28 18:06:41 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: E:\Program Files (x86)\Mozilla Thunderbird\plugins
 
[2011.09.23 18:35:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maas\AppData\Roaming\mozilla\Extensions
[2012.08.12 15:50:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maas\AppData\Roaming\mozilla\Firefox\Profiles\uamslmvl.default\extensions
[2011.09.24 14:23:04 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Maas\AppData\Roaming\mozilla\Firefox\Profiles\uamslmvl.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.15 13:28:33 | 000,000,000 | ---D | M] ("FRITZ!Box AddOn") -- C:\Users\Maas\AppData\Roaming\mozilla\Firefox\Profiles\uamslmvl.default\extensions\fb_add_on@avm.de
[2012.05.18 19:15:35 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Maas\AppData\Roaming\mozilla\Firefox\Profiles\uamslmvl.default\extensions\ich@maltegoetz.de
[2012.08.10 16:41:14 | 000,000,853 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\searchplugins\11-suche.xml
[2012.08.10 16:41:14 | 000,002,209 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\searchplugins\englische-ergebnisse.xml
[2012.08.10 16:41:14 | 000,010,506 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\searchplugins\gmx-suche.xml
[2012.08.10 16:41:14 | 000,002,368 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\searchplugins\lastminute.xml
[2011.11.06 14:36:48 | 000,002,449 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\searchplugins\safesearch.xml
[2012.08.10 16:41:14 | 000,005,489 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\searchplugins\webde-suche.xml
[2012.08.30 12:46:31 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN
[2012.02.03 14:18:41 | 000,000,000 | ---D | M] (Norton Vulnerability Protection) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPLGN
 
O1 HOSTS File: ([2012.08.22 13:49:17 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [BCSSync] E:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [Ai Nap] C:\Program Files (x86)\ASUS\AI Suite\AiNap\AiNap.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files (x86)\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [QFan Help] C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [WinampAgent] E:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001..\Run: [DAEMON Tools Lite] E:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001..\Run: [ICQ] E:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001..\Run: [SpybotSD TeaTimer] E:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001..\Run: [Steam] E:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1003..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2467352279-2334928693-883034293-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Maas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - E:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Maas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - E:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - E:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - E:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6B573A56-CF3F-491B-B67F-F3CD6EDB108A}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKU\.DEFAULT Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-18 Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-19 Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-20 Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Programme\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - E:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
 
 
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: !SASCORE - C:\Programme\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: !SASCORE - C:\Programme\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.08.30 12:49:49 | 000,598,528 | ---- | C] (OldTimer Tools) -- C:\Users\Maas\Desktop\otl.exe
[2012.08.28 12:55:18 | 000,000,000 | ---D | C] -- C:\Users\Maas\AppData\Roaming\SUPERAntiSpyware.com
[2012.08.28 12:54:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012.08.28 12:54:51 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2012.08.28 12:54:51 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012.08.22 13:50:30 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.08.22 13:49:18 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012.08.22 13:44:03 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.08.22 13:44:03 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.08.22 13:44:03 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.08.22 13:41:24 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.08.22 13:41:18 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012.08.21 18:50:43 | 004,735,900 | R--- | C] (Swearware) -- C:\Users\Maas\Desktop\ComboFix.exe
[2012.08.21 18:05:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012.08.21 17:59:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2012.08.20 19:42:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Emsisoft Anti-Malware
[2012.08.20 19:42:37 | 000,000,000 | ---D | C] -- C:\Users\Maas\Documents\Anti-Malware
[2012.08.20 14:42:59 | 000,000,000 | ---D | C] -- C:\Users\Maas\AppData\Roaming\Malwarebytes
[2012.08.20 14:42:54 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.08.20 14:42:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.08.20 14:42:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.08.19 12:23:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012.08.19 12:23:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012.08.13 16:46:31 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2012.08.12 19:35:20 | 000,000,000 | ---D | C] -- C:\Users\Maas\AppData\Roaming\NVIDIA
[2012.08.12 19:35:16 | 000,000,000 | ---D | C] -- C:\Users\Maas\Documents\WB Games
[2012.08.12 19:34:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD
[2012.08.12 14:08:06 | 000,000,000 | ---D | C] -- C:\Users\Maas\Documents\My Cheat Tables
 
========== Files - Modified Within 30 Days ==========
 
[2012.08.30 12:53:25 | 001,612,484 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.08.30 12:53:25 | 000,696,620 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.08.30 12:53:25 | 000,651,938 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.08.30 12:53:25 | 000,147,916 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.08.30 12:53:25 | 000,120,870 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.08.30 12:49:49 | 000,598,528 | ---- | M] (OldTimer Tools) -- C:\Users\Maas\Desktop\otl.exe
[2012.08.30 12:46:41 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.08.30 12:46:30 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.08.30 12:46:25 | 529,874,943 | -HS- | M] () -- C:\hiberfil.sys
[2012.08.29 20:04:56 | 000,020,992 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.08.29 20:04:56 | 000,020,992 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.08.29 19:37:00 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.08.28 12:54:54 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.08.22 13:49:17 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.08.22 13:41:11 | 004,735,900 | R--- | M] (Swearware) -- C:\Users\Maas\Desktop\ComboFix.exe
[2012.08.20 16:06:13 | 000,618,227 | ---- | M] () -- C:\Users\Maas\Desktop\adwcleaner.exe
[2012.08.20 14:43:43 | 000,000,786 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.08.19 12:45:28 | 000,000,524 | ---- | M] () -- C:\Windows\wininit.ini
[2012.08.17 11:44:46 | 000,001,424 | ---- | M] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk
[2012.08.17 11:44:44 | 000,365,464 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.08.17 11:44:37 | 001,795,833 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\Cat.DB
[2012.08.16 12:52:24 | 000,008,942 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\VT20120731.038
[2012.08.12 14:43:17 | 000,491,972 | ---- | M] () -- C:\Users\Maas\Desktop\Download.jpg
[2012.08.10 07:28:35 | 000,000,172 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\isolate.ini
 
========== Files Created - No Company Name ==========
 
[2012.08.28 12:54:54 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.08.22 13:44:03 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.08.22 13:44:03 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.08.22 13:44:03 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.08.22 13:44:03 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.08.22 13:44:03 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.08.20 16:06:13 | 000,618,227 | ---- | C] () -- C:\Users\Maas\Desktop\adwcleaner.exe
[2012.08.20 14:42:54 | 000,000,786 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.08.19 12:45:27 | 000,000,524 | ---- | C] () -- C:\Windows\wininit.ini
[2012.08.13 16:47:47 | 002,621,723 | ---- | C] () -- C:\Windows\SysNative\nvcoproc.bin
[2012.08.12 14:43:16 | 000,491,972 | ---- | C] () -- C:\Users\Maas\Desktop\Download.jpg
[2012.08.10 15:44:58 | 006,992,864 | ---- | C] () -- C:\Users\Maas\Desktop\01_Let_It_Roll.m4a
[2012.03.28 22:11:06 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2012.03.28 22:11:06 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2012.03.28 22:11:06 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2012.03.28 22:11:06 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2012.03.10 15:51:55 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012.03.10 15:51:55 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2012.03.10 15:34:21 | 000,106,496 | ---- | C] () -- C:\Windows\SysWow64\BrMuSNMP.dll
[2012.03.10 15:32:23 | 000,031,864 | ---- | C] () -- C:\Windows\maxlink.ini
[2012.02.22 19:34:00 | 000,004,096 | -H-- | C] () -- C:\Users\Maas\AppData\Local\keyfile3.drm
[2011.11.03 11:34:57 | 001,589,442 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.09.28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.09.23 18:15:40 | 000,000,017 | ---- | C] () -- C:\Users\Maas\AppData\Local\resmon.resmoncfg
[2011.09.23 18:06:24 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2011.09.23 18:06:24 | 000,013,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2011.09.23 18:06:22 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2011.09.23 18:06:22 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2011.09.23 18:05:33 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
 
========== LOP Check ==========
 
[2012.02.20 15:03:00 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Canneverbe Limited
[2012.04.14 14:48:23 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\DAEMON Tools Lite
[2012.02.20 16:27:30 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\DVDVideoSoft
[2011.09.24 14:23:03 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.09.24 14:40:34 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Foxit Software
[2012.08.30 12:51:20 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\ICQ
[2011.09.23 18:09:08 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Leadertech
[2011.12.27 15:02:39 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\libimobiledevice
[2011.12.27 15:02:34 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\mediAvatar
[2011.10.04 10:30:37 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\OpenOffice.org
[2011.12.28 13:55:15 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\redsn0w
[2012.04.21 14:26:07 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Samsung
[2012.03.10 15:58:33 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\ScanSoft
[2011.09.23 19:17:26 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Thunderbird
[2012.04.09 20:54:10 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\WindSolutions
[2012.03.10 15:58:36 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Zeon
[2012.08.28 14:06:52 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.11.19 14:13:57 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Adobe
[2012.04.10 16:44:01 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Apple Computer
[2012.03.10 16:01:29 | 000,000,000 | R--D | M] -- C:\Users\Maas\AppData\Roaming\Brother
[2012.02.20 15:03:00 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Canneverbe Limited
[2012.04.14 14:48:23 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\DAEMON Tools Lite
[2012.02.20 16:27:30 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\DVDVideoSoft
[2011.09.24 14:23:03 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.09.24 14:40:34 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Foxit Software
[2012.08.30 12:51:20 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\ICQ
[2011.09.23 17:51:19 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Identities
[2011.09.23 18:06:59 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\InstallShield
[2011.09.23 18:09:08 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Leadertech
[2011.12.27 15:02:39 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\libimobiledevice
[2011.09.23 18:08:35 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Logishrd
[2011.09.23 18:09:11 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Logitech
[2011.09.23 18:33:07 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Macromedia
[2012.08.20 14:42:59 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Malwarebytes
[2009.07.14 20:18:19 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Media Center Programs
[2011.12.27 15:02:34 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\mediAvatar
[2012.05.14 09:04:29 | 000,000,000 | --SD | M] -- C:\Users\Maas\AppData\Roaming\Microsoft
[2011.09.23 18:35:27 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Mozilla
[2012.08.12 19:35:20 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\NVIDIA
[2011.10.04 10:30:37 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\OpenOffice.org
[2011.12.28 13:55:15 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\redsn0w
[2012.04.21 14:26:07 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Samsung
[2012.03.10 15:58:33 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\ScanSoft
[2012.08.28 12:55:18 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\SUPERAntiSpyware.com
[2011.09.23 19:17:26 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Thunderbird
[2012.08.21 13:02:09 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\vlc
[2012.08.29 19:42:25 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Winamp
[2012.04.09 20:54:10 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\WindSolutions
[2011.09.23 18:27:17 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\WinRAR
[2012.03.10 15:58:36 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Zeon
 
< %APPDATA%\*.exe /s >
[2012.05.14 09:04:29 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Maas\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2012.08.12 19:34:04 | 000,010,134 | R--- | M] () -- C:\Users\Maas\AppData\Roaming\Microsoft\Installer\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}\ARPPRODUCTICON.exe
[2012.05.11 18:00:30 | 003,154,792 | ---- | M] (Microsoft Corporation) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\NDP40-KB2461678-x64.exe
[2012.03.31 04:38:12 | 000,954,256 | ---- | M] (Samsung) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Kies.exe
[2012.03.31 04:38:16 | 000,278,928 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesDriverInstaller.exe
[2012.03.28 22:13:22 | 000,309,760 | ---- | M] (Samsung) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesLogger.exe
[2012.03.31 04:38:14 | 003,521,424 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesTrayAgent.exe
[2012.03.28 22:12:02 | 000,694,784 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceManager.exe
[2012.03.31 04:38:20 | 000,067,472 | ---- | M] (Samsung) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\Kies_Tutorial.exe
[2012.03.28 22:11:38 | 000,106,920 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\AgentInstaller.exe
[2012.03.28 22:11:38 | 000,101,288 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\AgentUpdate.exe
[2012.03.31 04:38:24 | 000,183,696 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\BinaryLoaderMgr.exe
[2012.03.31 04:38:26 | 000,021,392 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\KiesPDLR.exe
[2012.03.31 04:38:28 | 003,570,312 | ---- | M] (Freeware) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\MediaModules\MyFreeCodecPack.exe
[2012.03.31 04:38:30 | 000,371,088 | ---- | M] (ml) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\Temp\Kies.Update.exe
[2012.05.04 07:37:12 | 000,371,088 | ---- | M] (ml) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\erdnt\cache64\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\erdnt\cache86\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\erdnt\cache64\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\erdnt\cache64\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\erdnt\cache86\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\erdnt\cache86\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\erdnt\cache64\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\erdnt\cache86\user32.dll
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\erdnt\cache64\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\erdnt\cache86\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\erdnt\cache64\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\erdnt\cache64\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\erdnt\cache86\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\erdnt\cache64\winlogon.exe
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
< %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\*.* >
[2012.07.12 17:01:09 | 000,000,174 | -HS- | M] () -- C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
 
< %APPDATA%\*AcroIEH*.* >
 
< %APPDATA%\*.exe >
 
< %APPDATA%\*.tmp >
 
<          >

< End of report >


t'john 30.08.2012 19:47

  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

T!tr0 31.08.2012 16:12

Code:

# AdwCleaner v1.801 - Logfile created 08/31/2012 at 17:09:08
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
# User : Maas - MAAS-PC
# Boot Mode : Normal
# Running from : C:\Users\Maas\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****


***** [Registre - GUID] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v9.0.1 (de)

Profile name : default
File : C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js

Deleted : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb178?a=6R8BQWs4Vd&loc=FF_NT");

*************************

AdwCleaner[R1].txt - [3364 octets] - [20/08/2012 16:16:58]
AdwCleaner[R2].txt - [3424 octets] - [20/08/2012 16:18:12]
AdwCleaner[S1].txt - [283 octets] - [20/08/2012 16:18:18]
AdwCleaner[S2].txt - [3551 octets] - [20/08/2012 19:36:22]
AdwCleaner[R3].txt - [1271 octets] - [30/08/2012 12:48:16]
AdwCleaner[S3].txt - [1101 octets] - [31/08/2012 17:09:08]

########## EOF - C:\AdwCleaner[S3].txt - [1229 octets] ##########


t'john 31.08.2012 23:34

Fixen mit OTL

Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).

  • Deaktiviere etwaige Virenscanner wie Avira, Kaspersky etc.
  • Starte die OTL.exe.
    Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen".
  • Kopiere folgendes Skript in das Textfeld unterhalb von Benuterdefinierte Scans/Fixes:
  • Der Fix fängt mit :OTL an. Vergewissere dich, dass du ihn richtig kopiert hast.


Code:

:OTL
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\ [2012.08.30 12:46:31 | 000,000,000 | ---D | M]
[2012.08.30 12:46:31 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\coieplg.dll (Symantec Corporation)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
:Files
C:\Users\Maas\AppData\Local\{*}
C:\ProgramData\*.exe
C:\ProgramData\TEMP
C:\Users\Maas\AppData\Local\Temp\*.exe
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk
%SystemRoot%\System32\*.tmp
%SystemRoot%\SysWOW64\*.tmp
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]

  • Schließe alle Programme.
  • Klicke auf den Fix Button.
  • Wenn OTL einen Neustart verlangt, bitte zulassen.
  • Kopiere den Inhalt des Logfiles hier in Code-Tags in Deinen Thread.
    Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\<datum_nummer.log>

Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

T!tr0 01.09.2012 11:31

Code:

All processes killed
========== OTL ==========
Prefs.js: "Google" removed from browser.search.selectedEngine
Prefs.js: true removed from browser.search.useDBForOrder
Prefs.js: "www.google.com" removed from browser.startup.homepage
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}\ not found.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\content scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\components scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn scheduled to be moved on reboot.
Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN\content scheduled to be moved on reboot.
Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN\components scheduled to be moved on reboot.
Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN\chrome scheduled to be moved on reboot.
Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN scheduled to be moved on reboot.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.
Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ .
File move failed. E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\coieplg.dll scheduled to be moved on reboot.
Registry value HKEY_USERS\S-1-5-21-2467352279-2334928693-883034293-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2467352279-2334928693-883034293-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
========== FILES ==========
File\Folder C:\Users\Maas\AppData\Local\{*} not found.
File\Folder C:\ProgramData\*.exe not found.
File\Folder C:\ProgramData\TEMP not found.
File\Folder C:\Users\Maas\AppData\Local\Temp\*.exe not found.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
File/Folder C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk not found.
File/Folder C:\Windows\System32\*.tmp not found.
File/Folder C:\Windows\SysWOW64\*.tmp not found.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Maas\Desktop\cmd.bat deleted successfully.
C:\Users\Maas\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56468 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Maas
->Temp folder emptied: 1818994 bytes
->Temporary Internet Files folder emptied: 5354819 bytes
->FireFox cache emptied: 463911266 bytes
->Flash cache emptied: 20237 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56468 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3040 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 449,00 mb
 
 
OTL by OldTimer - Version 3.2.59.1 log created on 09012012_122710

Files\Folders moved on Reboot...
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\content scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\components scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\content scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\components scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn scheduled to be moved on reboot.
File move failed. E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\coieplg.dll scheduled to be moved on reboot.
C:\Users\Maas\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


t'john 01.09.2012 16:56

NEU RUNTERLADEN

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

T!tr0 01.09.2012 18:09

Code:

# AdwCleaner v2.000 - Datei am 09/01/2012 um 19:08:45 erstellt
# Aktualisiert am 30/08/2012 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzer : Maas - MAAS-PC
# Normaler Modus : Normal
# Ausgeführt unter : C:\Users\Maas\Desktop\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v9.0.1 (de)

Profilname : default
Datei : C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js

Gefunden : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb178?a=6R8BQWs4Vd&loc=FF_NT");

*************************

AdwCleaner[R1].txt - [3364 octets] - [20/08/2012 16:16:58]
AdwCleaner[R2].txt - [3424 octets] - [20/08/2012 16:18:12]
AdwCleaner[S1].txt - [283 octets] - [20/08/2012 16:18:18]
AdwCleaner[S2].txt - [3551 octets] - [20/08/2012 19:36:22]
AdwCleaner[R3].txt - [1271 octets] - [30/08/2012 12:48:16]
AdwCleaner[S3].txt - [1230 octets] - [31/08/2012 17:09:08]
AdwCleaner[R4].txt - [1180 octets] - [01/09/2012 19:08:45]

########## EOF - C:\AdwCleaner[R4].txt - [1240 octets] ##########


t'john 02.09.2012 09:39

  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

T!tr0 03.09.2012 10:11

Code:

# AdwCleaner v2.000 - Datei am 09/03/2012 um 11:08:56 erstellt
# Aktualisiert am 30/08/2012 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzer : Maas - MAAS-PC
# Normaler Modus : Normal
# Ausgeführt unter : C:\Users\Maas\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

Wiederhergestellt : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-21-2467352279-2334928693-883034293-1003\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

-\\ Mozilla Firefox v9.0.1 (de)

Profilname : default
Datei : C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js

Gelöscht : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb178?a=6R8BQWs4Vd&loc=FF_NT");

*************************

AdwCleaner[R1].txt - [3364 octets] - [20/08/2012 16:16:58]
AdwCleaner[R2].txt - [3424 octets] - [20/08/2012 16:18:12]
AdwCleaner[S1].txt - [283 octets] - [20/08/2012 16:18:18]
AdwCleaner[S2].txt - [3551 octets] - [20/08/2012 19:36:22]
AdwCleaner[R3].txt - [1271 octets] - [30/08/2012 12:48:16]
AdwCleaner[S3].txt - [1230 octets] - [31/08/2012 17:09:08]
AdwCleaner[R4].txt - [1309 octets] - [01/09/2012 19:08:45]
AdwCleaner[S4].txt - [1742 octets] - [03/09/2012 11:08:56]

########## EOF - C:\AdwCleaner[S4].txt - [1802 octets] ##########


t'john 03.09.2012 20:24

Incredi noch da?

T!tr0 04.09.2012 14:33

nach wie vor :(

t'john 04.09.2012 18:39

interessant.

CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.


Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\*.*
%APPDATA%\*AcroIEH*.*
%APPDATA%\*.exe
%APPDATA%\*.tmp
CREATERESTOREPOINT


T!tr0 05.09.2012 10:25

Code:

OTL logfile created on: 05.09.2012 11:18:27 - Run 2
OTL by OldTimer - Version 3.2.61.0    Folder = C:\Users\Maas\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5,99 Gb Total Physical Memory | 4,45 Gb Available Physical Memory | 74,22% Memory free
11,98 Gb Paging File | 10,48 Gb Available in Paging File | 87,51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 43,95 Gb Total Space | 3,32 Gb Free Space | 7,55% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 181,94 Gb Free Space | 39,06% Space Free | Partition Type: NTFS
Drive E: | 75,29 Gb Total Space | 33,91 Gb Free Space | 45,04% Space Free | Partition Type: NTFS
Drive F: | 39,06 Gb Total Space | 38,97 Gb Free Space | 99,77% Space Free | Partition Type: NTFS
Drive G: | 284,71 Gb Total Space | 52,53 Gb Free Space | 18,45% Space Free | Partition Type: NTFS
 
Computer Name: MAAS-PC | User Name: Maas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.09.05 11:16:56 | 000,599,040 | ---- | M] (OldTimer Tools) -- C:\Users\Maas\Desktop\OTL.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.06.16 04:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\ccsvchst.exe
PRC - [2012.05.15 12:48:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012.04.17 17:19:40 | 003,671,872 | ---- | M] (DT Soft Ltd) -- E:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2012.02.23 12:30:40 | 000,059,240 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
PRC - [2011.07.11 23:47:06 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- E:\Program Files (x86)\Winamp\winampa.exe
PRC - [2010.07.19 19:57:32 | 002,231,616 | ---- | M] () -- E:\Program Files (x86)\devolo\dlan\devolonetsvc.exe
PRC - [2009.08.21 11:22:50 | 001,427,968 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite\AiNap\AiNap.exe
PRC - [2009.08.19 16:44:56 | 000,603,136 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe
PRC - [2009.03.30 16:00:54 | 000,221,184 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe
PRC - [2009.01.26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) -- E:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- E:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.09.27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.09.27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009.09.30 11:33:06 | 000,024,576 | ---- | M] () -- C:\Windows\SysWOW64\AsIO.dll
MOD - [2009.02.27 17:38:20 | 000,139,264 | R--- | M] () -- C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
MOD - [2008.02.25 15:08:54 | 000,208,896 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite\AiNap\AiNap.dll
MOD - [2007.01.03 22:25:56 | 000,008,704 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite\AiNap\vvc.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - File not found [Auto | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
SRV:64bit: - [2011.09.23 18:06:49 | 000,111,616 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\AEADISRV.EXE -- (AEADIFilters)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012.08.12 13:57:03 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.06.16 04:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe -- (NIS)
SRV - [2012.05.15 12:48:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2011.09.27 21:04:08 | 000,359,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2011.06.12 12:43:28 | 051,740,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2010.07.19 19:57:32 | 002,231,616 | ---- | M] () [Auto | Running] -- E:\Program Files (x86)\devolo\dlan\devolonetsvc.exe -- (DevoloNetworkService)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.01.09 22:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010.01.09 22:20:56 | 000,174,440 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose64)
SRV - [2009.08.18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.07.06 04:17:58 | 000,037,536 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\srtspx64.sys -- (SRTSPX)
DRV:64bit: - [2012.07.06 04:17:57 | 000,737,952 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2012.06.15 18:00:28 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2012.06.07 06:43:38 | 000,167,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\ccsetx64.sys -- (ccSet_NIS)
DRV:64bit: - [2012.05.22 03:37:12 | 001,129,120 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\symefa64.sys -- (SymEFA)
DRV:64bit: - [2012.04.18 19:08:03 | 000,188,736 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2012.04.18 04:13:32 | 000,405,624 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\symnets.sys -- (SymNetS)
DRV:64bit: - [2012.04.18 03:42:14 | 000,190,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\ironx64.sys -- (SymIRON)
DRV:64bit: - [2012.03.28 18:23:22 | 000,175,736 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.02.24 11:14:42 | 000,203,320 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2012.02.24 11:14:42 | 000,099,384 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2012.02.15 11:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011.09.23 18:06:49 | 000,475,136 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV:64bit: - [2011.09.02 08:30:46 | 000,042,776 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2011.09.02 08:30:36 | 000,060,696 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2011.09.02 08:30:24 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2011.07.25 20:18:36 | 000,451,192 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\symds64.sys -- (SymDS)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.12.15 11:24:18 | 000,058,448 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PWFilterUsb.sys -- (PorscheWheelFilterUsb)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 13:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2009.11.03 13:06:36 | 000,087,552 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BrSerIb.sys -- (BrSerIb)
DRV:64bit: - [2009.11.03 13:06:36 | 000,014,592 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BrUsbSib.sys -- (BrUsbSIb)
DRV:64bit: - [2009.09.28 09:22:00 | 000,395,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009.07.16 11:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 02:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009.07.14 02:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009.05.12 00:49:10 | 000,178,728 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mv61xx.sys -- (mv61xx)
DRV - [2012.09.05 11:10:36 | 002,084,000 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120904.032\ex64.sys -- (NAVEX15)
DRV - [2012.09.05 11:10:36 | 000,125,600 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120904.032\eng64.sys -- (NAVENG)
DRV - [2012.09.01 02:27:23 | 000,513,184 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120901.001\IDSviA64.sys -- (IDSVia64)
DRV - [2012.08.10 18:36:48 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012.08.10 15:56:19 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2012.06.19 02:01:14 | 001,161,376 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120823.007\BHDrvx64.sys -- (BHDrvx64)
DRV - [2010.06.10 13:32:14 | 000,034,048 | ---- | M] (CACE Technologies) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\drivers\npf_devolo.sys -- (NPF_devolo)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B4 34 3C 2E 07 77 CD 01  [binary data]
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: ""
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/"
FF - prefs.js..extensions.enabledAddons: fb_add_on@avm.de:1.6.3
FF - prefs.js..extensions.enabledAddons: ich@maltegoetz.de:1.4.2
FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.5
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.0.73 - 1
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2012.7.5.2
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: E:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: E:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: E:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPlgn\ [2012.02.03 14:18:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\ [2012.09.05 10:50:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components [2012.09.01 12:30:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins [2012.08.17 11:48:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Components: E:\Program Files (x86)\Mozilla Thunderbird\components [2011.09.28 18:06:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Plugins: E:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components [2012.09.01 12:30:44 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins [2012.08.17 11:48:14 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: E:\Program Files (x86)\Mozilla Thunderbird\components [2011.09.28 18:06:41 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: E:\Program Files (x86)\Mozilla Thunderbird\plugins
 
[2011.09.23 18:35:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maas\AppData\Roaming\mozilla\Extensions
[2012.08.12 15:50:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maas\AppData\Roaming\mozilla\Firefox\Profiles\uamslmvl.default\extensions
[2011.09.24 14:23:04 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Maas\AppData\Roaming\mozilla\Firefox\Profiles\uamslmvl.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.15 13:28:33 | 000,000,000 | ---D | M] ("FRITZ!Box AddOn") -- C:\Users\Maas\AppData\Roaming\mozilla\Firefox\Profiles\uamslmvl.default\extensions\fb_add_on@avm.de
[2012.05.18 19:15:35 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Maas\AppData\Roaming\mozilla\Firefox\Profiles\uamslmvl.default\extensions\ich@maltegoetz.de
[2012.08.10 16:41:14 | 000,000,853 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\mozilla\firefox\profiles\uamslmvl.default\searchplugins\11-suche.xml
[2012.08.10 16:41:14 | 000,002,209 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\mozilla\firefox\profiles\uamslmvl.default\searchplugins\englische-ergebnisse.xml
[2012.08.10 16:41:14 | 000,010,506 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\mozilla\firefox\profiles\uamslmvl.default\searchplugins\gmx-suche.xml
[2012.08.10 16:41:14 | 000,002,368 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\mozilla\firefox\profiles\uamslmvl.default\searchplugins\lastminute.xml
[2011.11.06 14:36:48 | 000,002,449 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\mozilla\firefox\profiles\uamslmvl.default\searchplugins\safesearch.xml
[2012.08.10 16:41:14 | 000,005,489 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\mozilla\firefox\profiles\uamslmvl.default\searchplugins\webde-suche.xml
[2012.09.05 10:50:07 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN
[2012.02.03 14:18:41 | 000,000,000 | ---D | M] (Norton Vulnerability Protection) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPLGN
 
O1 HOSTS File: ([2012.08.22 13:49:17 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [BCSSync] E:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [Ai Nap] C:\Program Files (x86)\ASUS\AI Suite\AiNap\AiNap.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files (x86)\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [QFan Help] C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [WinampAgent] E:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001..\Run: [DAEMON Tools Lite] E:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001..\Run: [ICQ] E:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001..\Run: [SpybotSD TeaTimer] E:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001..\Run: [Steam] E:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-2467352279-2334928693-883034293-1003..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2467352279-2334928693-883034293-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Maas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - E:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Maas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - E:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - E:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - E:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6B573A56-CF3F-491B-B67F-F3CD6EDB108A}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKU\.DEFAULT Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-18 Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-19 Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-20 Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Programme\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - E:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
 
 
SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.05 11:16:55 | 000,599,040 | ---- | C] (OldTimer Tools) -- C:\Users\Maas\Desktop\OTL.exe
[2012.09.03 09:52:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2012.09.01 12:27:10 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.08.22 13:50:30 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.08.22 13:49:18 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012.08.22 13:44:03 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.08.22 13:44:03 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.08.22 13:44:03 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.08.22 13:41:24 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.08.22 13:41:18 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012.08.21 18:50:43 | 004,735,900 | R--- | C] (Swearware) -- C:\Users\Maas\Desktop\ComboFix.exe
[2012.08.21 18:05:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012.08.20 19:42:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Emsisoft Anti-Malware
[2012.08.20 19:42:37 | 000,000,000 | ---D | C] -- C:\Users\Maas\Documents\Anti-Malware
[2012.08.20 14:42:59 | 000,000,000 | ---D | C] -- C:\Users\Maas\AppData\Roaming\Malwarebytes
[2012.08.20 14:42:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.08.19 12:23:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012.08.19 12:23:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012.08.13 16:46:31 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2012.08.12 19:35:20 | 000,000,000 | ---D | C] -- C:\Users\Maas\AppData\Roaming\NVIDIA
[2012.08.12 19:35:16 | 000,000,000 | ---D | C] -- C:\Users\Maas\Documents\WB Games
[2012.08.12 19:34:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD
[2012.08.12 14:08:06 | 000,000,000 | ---D | C] -- C:\Users\Maas\Documents\My Cheat Tables
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.05 11:16:56 | 000,599,040 | ---- | M] (OldTimer Tools) -- C:\Users\Maas\Desktop\OTL.exe
[2012.09.05 10:56:00 | 001,612,484 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.09.05 10:56:00 | 000,696,620 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.09.05 10:56:00 | 000,651,938 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.09.05 10:56:00 | 000,147,916 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.09.05 10:56:00 | 000,120,870 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.09.05 10:50:14 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.09.05 10:50:05 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.05 10:50:01 | 529,874,943 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.04 19:04:13 | 000,020,992 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.04 19:04:13 | 000,020,992 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.04 18:37:00 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.09.01 19:08:10 | 000,511,265 | ---- | M] () -- C:\Users\Maas\Desktop\adwcleaner.exe
[2012.08.22 13:49:17 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.08.22 13:41:11 | 004,735,900 | R--- | M] (Swearware) -- C:\Users\Maas\Desktop\ComboFix.exe
[2012.08.19 12:45:28 | 000,000,524 | ---- | M] () -- C:\Windows\wininit.ini
[2012.08.17 11:44:46 | 000,001,424 | ---- | M] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk
[2012.08.17 11:44:44 | 000,365,464 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.08.17 11:44:37 | 001,795,833 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\Cat.DB
[2012.08.16 12:52:24 | 000,008,942 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\VT20120731.038
[2012.08.12 14:43:17 | 000,491,972 | ---- | M] () -- C:\Users\Maas\Desktop\Download.jpg
[2012.08.10 07:28:35 | 000,000,172 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1308000.00E\isolate.ini
 
========== Files Created - No Company Name ==========
 
[2012.09.01 19:08:10 | 000,511,265 | ---- | C] () -- C:\Users\Maas\Desktop\adwcleaner.exe
[2012.08.22 13:44:03 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.08.22 13:44:03 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.08.22 13:44:03 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.08.22 13:44:03 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.08.22 13:44:03 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.08.19 12:45:27 | 000,000,524 | ---- | C] () -- C:\Windows\wininit.ini
[2012.08.13 16:47:47 | 002,621,723 | ---- | C] () -- C:\Windows\SysNative\nvcoproc.bin
[2012.08.12 14:43:16 | 000,491,972 | ---- | C] () -- C:\Users\Maas\Desktop\Download.jpg
[2012.08.10 15:44:58 | 006,992,864 | ---- | C] () -- C:\Users\Maas\Desktop\01_Let_It_Roll.m4a
[2012.03.28 22:11:06 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2012.03.28 22:11:06 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2012.03.28 22:11:06 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2012.03.28 22:11:06 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2012.03.10 15:51:55 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012.03.10 15:51:55 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2012.03.10 15:34:21 | 000,106,496 | ---- | C] () -- C:\Windows\SysWow64\BrMuSNMP.dll
[2012.03.10 15:32:23 | 000,031,864 | ---- | C] () -- C:\Windows\maxlink.ini
[2012.02.22 19:34:00 | 000,004,096 | -H-- | C] () -- C:\Users\Maas\AppData\Local\keyfile3.drm
[2011.11.03 11:34:57 | 001,589,442 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.09.28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.09.23 18:15:40 | 000,000,017 | ---- | C] () -- C:\Users\Maas\AppData\Local\resmon.resmoncfg
[2011.09.23 18:06:24 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2011.09.23 18:06:24 | 000,013,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2011.09.23 18:06:22 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2011.09.23 18:06:22 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2011.09.23 18:05:33 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
 
========== LOP Check ==========
 
[2012.02.20 15:03:00 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Canneverbe Limited
[2012.04.14 14:48:23 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\DAEMON Tools Lite
[2012.02.20 16:27:30 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\DVDVideoSoft
[2011.09.24 14:23:03 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.09.24 14:40:34 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Foxit Software
[2012.09.05 11:18:25 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\ICQ
[2011.09.23 18:09:08 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Leadertech
[2011.12.27 15:02:39 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\libimobiledevice
[2011.12.27 15:02:34 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\mediAvatar
[2011.10.04 10:30:37 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\OpenOffice.org
[2011.12.28 13:55:15 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\redsn0w
[2012.04.21 14:26:07 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Samsung
[2012.03.10 15:58:33 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\ScanSoft
[2011.09.23 19:17:26 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Thunderbird
[2012.04.09 20:54:10 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\WindSolutions
[2012.03.10 15:58:36 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Zeon
[2012.08.28 14:06:52 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.11.19 14:13:57 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Adobe
[2012.04.10 16:44:01 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Apple Computer
[2012.03.10 16:01:29 | 000,000,000 | R--D | M] -- C:\Users\Maas\AppData\Roaming\Brother
[2012.02.20 15:03:00 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Canneverbe Limited
[2012.04.14 14:48:23 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\DAEMON Tools Lite
[2012.02.20 16:27:30 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\DVDVideoSoft
[2011.09.24 14:23:03 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.09.24 14:40:34 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Foxit Software
[2012.09.05 11:18:25 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\ICQ
[2011.09.23 17:51:19 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Identities
[2011.09.23 18:06:59 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\InstallShield
[2011.09.23 18:09:08 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Leadertech
[2011.12.27 15:02:39 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\libimobiledevice
[2011.09.23 18:08:35 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Logishrd
[2011.09.23 18:09:11 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Logitech
[2011.09.23 18:33:07 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Macromedia
[2012.08.20 14:42:59 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Malwarebytes
[2009.07.14 20:18:19 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Media Center Programs
[2011.12.27 15:02:34 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\mediAvatar
[2012.05.14 09:04:29 | 000,000,000 | --SD | M] -- C:\Users\Maas\AppData\Roaming\Microsoft
[2011.09.23 18:35:27 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Mozilla
[2012.08.12 19:35:20 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\NVIDIA
[2011.10.04 10:30:37 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\OpenOffice.org
[2011.12.28 13:55:15 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\redsn0w
[2012.04.21 14:26:07 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Samsung
[2012.03.10 15:58:33 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\ScanSoft
[2011.09.23 19:17:26 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Thunderbird
[2012.08.21 13:02:09 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\vlc
[2012.09.05 10:55:55 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Winamp
[2012.04.09 20:54:10 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\WindSolutions
[2011.09.23 18:27:17 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\WinRAR
[2012.03.10 15:58:36 | 000,000,000 | ---D | M] -- C:\Users\Maas\AppData\Roaming\Zeon
 
< %APPDATA%\*.exe /s >
[2012.05.14 09:04:29 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Maas\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2012.08.12 19:34:04 | 000,010,134 | R--- | M] () -- C:\Users\Maas\AppData\Roaming\Microsoft\Installer\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}\ARPPRODUCTICON.exe
[2012.05.11 18:00:30 | 003,154,792 | ---- | M] (Microsoft Corporation) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\NDP40-KB2461678-x64.exe
[2012.03.31 04:38:12 | 000,954,256 | ---- | M] (Samsung) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Kies.exe
[2012.03.31 04:38:16 | 000,278,928 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesDriverInstaller.exe
[2012.03.28 22:13:22 | 000,309,760 | ---- | M] (Samsung) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesLogger.exe
[2012.03.31 04:38:14 | 003,521,424 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesTrayAgent.exe
[2012.03.28 22:12:02 | 000,694,784 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceManager.exe
[2012.03.31 04:38:20 | 000,067,472 | ---- | M] (Samsung) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\Kies_Tutorial.exe
[2012.03.28 22:11:38 | 000,106,920 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\AgentInstaller.exe
[2012.03.28 22:11:38 | 000,101,288 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\AgentUpdate.exe
[2012.03.31 04:38:24 | 000,183,696 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\BinaryLoaderMgr.exe
[2012.03.31 04:38:26 | 000,021,392 | ---- | M] () -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\KiesPDLR.exe
[2012.03.31 04:38:28 | 003,570,312 | ---- | M] (Freeware) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\MediaModules\MyFreeCodecPack.exe
[2012.03.31 04:38:30 | 000,371,088 | ---- | M] (ml) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\Temp\Kies.Update.exe
[2012.05.04 07:37:12 | 000,371,088 | ---- | M] (ml) -- C:\Users\Maas\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\erdnt\cache64\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\erdnt\cache86\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\erdnt\cache64\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\erdnt\cache64\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\erdnt\cache86\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\erdnt\cache86\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\erdnt\cache64\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\erdnt\cache86\user32.dll
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\erdnt\cache64\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\erdnt\cache86\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\erdnt\cache64\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\erdnt\cache64\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\erdnt\cache86\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\erdnt\cache64\winlogon.exe
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
< %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\*.* >
[2012.07.12 17:01:09 | 000,000,174 | -HS- | M] () -- C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
 
< %APPDATA%\*AcroIEH*.* >
 
< %APPDATA%\*.exe >
 
< %APPDATA%\*.tmp >
 
<          >

< End of report >


t'john 06.09.2012 00:45

Fixen mit OTL

Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).

  • Deaktiviere etwaige Virenscanner wie Avira, Kaspersky etc.
  • Starte die OTL.exe.
    Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen".
  • Kopiere folgendes Skript in das Textfeld unterhalb von Benuterdefinierte Scans/Fixes:
  • Der Fix fängt mit :OTL an. Vergewissere dich, dass du ihn richtig kopiert hast.


Code:

:OTL
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-2467352279-2334928693-883034293-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: ""
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledAddons: fb_add_on@avm.de:1.6.3
FF - prefs.js..extensions.enabledAddons: ich@maltegoetz.de:1.4.2
FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.5
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.0.73 - 1
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2012.7.5.2
FF - user.js - File not found
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\ [2012.09.05 10:50:07 | 000,000,000 | ---D | M]
[2012.09.05 10:50:07 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\coieplg.dll (Symantec Corporation)
O32 - HKLM CDRom: AutoRun - 1

[2012.08.21 18:50:43 | 004,735,900 | R--- | C] (Swearware) -- C:\Users\Maas\Desktop\ComboFix.exe

:Files
C:\ProgramData\*.exe
C:\ProgramData\TEMP
C:\Users\Maas\AppData\Local\{*}
C:\Users\Maas\AppData\Local\Temp\*.exe
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]

  • Schließe alle Programme.
  • Klicke auf den Fix Button.
  • Wenn OTL einen Neustart verlangt, bitte zulassen.
  • Kopiere den Inhalt des Logfiles hier in Code-Tags in Deinen Thread.
    Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\<datum_nummer.log>

Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

T!tr0 06.09.2012 17:08

Code:

All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_USERS\S-1-5-21-2467352279-2334928693-883034293-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-2467352279-2334928693-883034293-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKU\S-1-5-21-2467352279-2334928693-883034293-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKU\S-1-5-21-2467352279-2334928693-883034293-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKEY_USERS\S-1-5-21-2467352279-2334928693-883034293-1003\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Prefs.js: "" removed from browser.search.selectedEngine
Prefs.js: "" removed from browser.search.useDBForOrder
Prefs.js: "hxxp://www.google.com/" removed from browser.startup.homepage
Prefs.js: fb_add_on@avm.de:1.6.3 removed from extensions.enabledAddons
Prefs.js: ich@maltegoetz.de:1.4.2 removed from extensions.enabledAddons
Prefs.js: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.5 removed from extensions.enabledAddons
Prefs.js: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.0.73 - 1 removed from extensions.enabledAddons
Prefs.js: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2012.7.5.2 removed from extensions.enabledAddons
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}\ not found.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\content scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\components scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn scheduled to be moved on reboot.
Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN\content scheduled to be moved on reboot.
Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN\components scheduled to be moved on reboot.
Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN\chrome scheduled to be moved on reboot.
Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\COFFPLGN scheduled to be moved on reboot.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.
Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ .
File move failed. E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\coieplg.dll scheduled to be moved on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\Users\Maas\Desktop\ComboFix.exe moved successfully.
========== FILES ==========
File\Folder C:\ProgramData\*.exe not found.
File\Folder C:\ProgramData\TEMP not found.
File\Folder C:\Users\Maas\AppData\Local\{*} not found.
C:\Users\Maas\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Users\Maas\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
File/Folder C:\Users\Maas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk not found.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Maas\Desktop\cmd.bat deleted successfully.
C:\Users\Maas\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Maas
->Temp folder emptied: 183580 bytes
->Temporary Internet Files folder emptied: 1846153 bytes
->FireFox cache emptied: 422909446 bytes
->Flash cache emptied: 6537 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1216 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 405,00 mb
 
 
OTL by OldTimer - Version 3.2.61.0 log created on 09062012_180409

Files\Folders moved on Reboot...
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\content scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\components scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\content scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\components scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\chrome scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn scheduled to be moved on reboot.
File move failed. E:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\coieplg.dll scheduled to be moved on reboot.
C:\Users\Maas\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


t'john 06.09.2012 19:23

Sehr gut! :daumenhoc


1. Schritt
Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Malwarebytes Anti-Malware
- Anwendbar auf Windows 2000, XP, Vista und 7.
- Installiere das Programm in den vorgegebenen Pfad.
- Aktualisiere die Datenbank!
- Aktiviere "Komplett Scan durchführen" => Scan.
- Wähle alle verfügbaren Laufwerke (ausser CD/DVD) aus und starte den Scan.
- Funde bitte löschen lassen oder in Quarantäne.
- Wenn der Scan beendet ist, klicke auf "Zeige Resultate".
danach:

2. Schritt

Downloade Dir bitte AdwCleaner auf deinen Desktop.

  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

T!tr0 08.09.2012 16:16

Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.09.08.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Maas :: MAAS-PC [Administrator]

08.09.2012 17:01:08
mbam-log-2012-09-08 (17-01-08).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 400944
Laufzeit: 14 Minute(n), 47 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

# AdwCleaner v2.000 - Datei am 09/08/2012 um 17:17:38 erstellt
# Aktualisiert am 30/08/2012 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzer : Maas - MAAS-PC
# Normaler Modus : Normal
# Ausgeführt unter : C:\Users\Maas\Desktop\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v9.0.1 (de)

Profilname : default
Datei : C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js

Gefunden : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb178?a=6R8BQWs4Vd&loc=FF_NT");

*************************

AdwCleaner[R1].txt - [3364 octets] - [20/08/2012 16:16:58]
AdwCleaner[R2].txt - [3424 octets] - [20/08/2012 16:18:12]
AdwCleaner[S1].txt - [283 octets] - [20/08/2012 16:18:18]
AdwCleaner[S2].txt - [3551 octets] - [20/08/2012 19:36:22]
AdwCleaner[R3].txt - [1271 octets] - [30/08/2012 12:48:16]
AdwCleaner[S3].txt - [1230 octets] - [31/08/2012 17:09:08]
AdwCleaner[R4].txt - [1309 octets] - [01/09/2012 19:08:45]
AdwCleaner[S4].txt - [1871 octets] - [03/09/2012 11:08:56]
AdwCleaner[R5].txt - [1300 octets] - [08/09/2012 17:17:38]

########## EOF - C:\AdwCleaner[R5].txt - [1360 octets] ##########


t'john 08.09.2012 20:42

Sehr gut! :daumenhoc


  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.




danach:


Malware-Scan mit Emsisoft Anti-Malware

Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm.
Lade über Jetzt Updaten die aktuellen Signaturen herunter.
Wähle den Freeware-Modus aus.

Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers.
Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten.

Anleitung: http://www.trojaner-board.de/103809-...i-malware.html

T!tr0 10.09.2012 15:58

Code:

# AdwCleaner v2.000 - Datei am 09/10/2012 um 16:56:08 erstellt
# Aktualisiert am 30/08/2012 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzer : Maas - MAAS-PC
# Normaler Modus : Normal
# Ausgeführt unter : C:\Users\Maas\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-21-2467352279-2334928693-883034293-1003\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

-\\ Mozilla Firefox v9.0.1 (de)

Profilname : default
Datei : C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js

Gelöscht : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb178?a=6R8BQWs4Vd&loc=FF_NT");

*************************

AdwCleaner[R1].txt - [3364 octets] - [20/08/2012 16:16:58]
AdwCleaner[R2].txt - [3424 octets] - [20/08/2012 16:18:12]
AdwCleaner[S1].txt - [283 octets] - [20/08/2012 16:18:18]
AdwCleaner[S2].txt - [3551 octets] - [20/08/2012 19:36:22]
AdwCleaner[R3].txt - [1271 octets] - [30/08/2012 12:48:16]
AdwCleaner[S3].txt - [1230 octets] - [31/08/2012 17:09:08]
AdwCleaner[R4].txt - [1309 octets] - [01/09/2012 19:08:45]
AdwCleaner[S4].txt - [1871 octets] - [03/09/2012 11:08:56]
AdwCleaner[R5].txt - [1429 octets] - [08/09/2012 17:17:38]
AdwCleaner[S5].txt - [2052 octets] - [10/09/2012 16:56:08]

########## EOF - C:\AdwCleaner[S5].txt - [2112 octets] ##########

Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.09.10.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Maas :: MAAS-PC [Administrator]

Schutz: Aktiviert

10.09.2012 17:00:16
mbam-log-2012-09-10 (17-00-16).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 404492
Laufzeit: 14 Minute(n), 52 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


t'john 11.09.2012 00:17

Fixen mit OTL

Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).

  • Deaktiviere etwaige Virenscanner wie Avira, Kaspersky etc.
  • Starte die OTL.exe.
    Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen".
  • Kopiere folgendes Skript in das Textfeld unterhalb von Benuterdefinierte Scans/Fixes:
  • Der Fix fängt mit :OTL an. Vergewissere dich, dass du ihn richtig kopiert hast.


Code:

:OTL
:reg
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions]
"{336D0C35-8A85-403a-B9D2-65C292C39087}"=-

[-HKEY_USERS\S-1-5-21-3912799286-88314524-4274648788-1000\Software\Microsoft\Internet Explorer\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087}]

:Files
C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js

  • Schließe alle Programme.
  • Klicke auf den Fix Button.
  • Wenn OTL einen Neustart verlangt, bitte zulassen.
  • Kopiere den Inhalt des Logfiles hier in Code-Tags in Deinen Thread.
    Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\<datum_nummer.log>

Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

T!tr0 13.09.2012 14:36

Code:

========== OTL ==========
========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ not found.
Registry key HKEY_USERS\S-1-5-21-3912799286-88314524-4274648788-1000\Software\Microsoft\Internet Explorer\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ not found.
========== FILES ==========
C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js moved successfully.
 
OTL by OldTimer - Version 3.2.61.0 log created on 09132012_153559


t'john 14.09.2012 15:30

  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

T!tr0 15.09.2012 12:13

Code:

# AdwCleaner v2.000 - Datei am 09/15/2012 um 13:10:33 erstellt
# Aktualisiert am 30/08/2012 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzer : Maas - MAAS-PC
# Normaler Modus : Normal
# Ausgeführt unter : C:\Users\Maas\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\extensions\staged

***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v9.0.1 (de)

Profilname : default
Datei : C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js

Gelöscht : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb178?a=6R8BQWs4Vd&loc=FF_NT");

*************************

AdwCleaner[R1].txt - [3364 octets] - [20/08/2012 16:16:58]
AdwCleaner[R2].txt - [3424 octets] - [20/08/2012 16:18:12]
AdwCleaner[S1].txt - [283 octets] - [20/08/2012 16:18:18]
AdwCleaner[S2].txt - [3551 octets] - [20/08/2012 19:36:22]
AdwCleaner[R3].txt - [1271 octets] - [30/08/2012 12:48:16]
AdwCleaner[S3].txt - [1230 octets] - [31/08/2012 17:09:08]
AdwCleaner[R4].txt - [1309 octets] - [01/09/2012 19:08:45]
AdwCleaner[S4].txt - [1871 octets] - [03/09/2012 11:08:56]
AdwCleaner[R5].txt - [1429 octets] - [08/09/2012 17:17:38]
AdwCleaner[S5].txt - [2177 octets] - [10/09/2012 16:56:08]
AdwCleaner[S6].txt - [1531 octets] - [15/09/2012 13:10:33]

########## EOF - C:\AdwCleaner[S6].txt - [1591 octets] ##########


t'john 16.09.2012 17:54

Deinstalliere Firefox 9 und installiere Firefox 15.

T!tr0 17.09.2012 18:06

Hab ich gemacht :)

t'john 18.09.2012 02:34

incredi noch da oder weg?

T!tr0 18.09.2012 14:45

leider immernoch da :killpc:

t'john 19.09.2012 17:40

Scan mit SystemLook

Hiermit prüfe ich, ob für diese Infektion übliche Einträge noch vorhanden sind. Das Tool ändert nichts, wirft mir nur die nötigen Infos aus.

Lade SystemLook von jpshortstuff von einem der folgenden Spiegel herunter und speichere das Tool auf dem Desktop (falls noch nicht vorhanden).

Download Mirror #1

User mit 64Bit-Windows-Versionen benutzen diese Version => http://jpshortstuff.247fixes.com/SystemLook_x64.exe
  • Doppelklick auf die SystemLook.exe, um das Tool zu starten.
    Vista- und Windows 7-User unbedingt mit Rechtsklick und als Administrator starten.
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:

    Code:

    :regfind
    incredi
    perion

    :folderfind
    assist
    perion

    :filefind
    prefs.js
    perion

  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Wenn der Suchlauf beendet ist, wird sich Dein Editor mit den Ergebnissen öffnen, diese hier in den Thread posten.
  • Die Ergebnisse werden auf dem Desktop als SystemLook.txt gespeichert.

T!tr0 20.09.2012 16:51

Code:

SystemLook 30.07.11 by jpshortstuff
Log created at 17:50 on 20/09/2012 by Maas
Administrator - Elevation successful

========== regfind ==========

Searching for "incredi"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\incredibar_installer_RASAPI32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\incredibar_installer_RASMANCS]

Searching for "perion"
No data found.

========== folderfind ==========

Searching for "assist"
No folders found.

Searching for "perion"
No folders found.

========== filefind ==========

Searching for "prefs.js"
C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js        --a---- 4647 bytes        [14:03 20/09/2012]        [14:03 20/09/2012] C5258D76FEFACF19D7BAF9806944FD86
C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\extensions\ich@maltegoetz.de\defaults\preferences\prefs.js        --a---- 420 bytes        [14:27 16/09/2012]        [17:34 26/08/2012] 6A255A300814A5E98F59C3657C2081E8
C:\Users\Maas\AppData\Roaming\Thunderbird\Profiles\poqgwthf.default\prefs.js        --a---- 13953 bytes        [17:42 22/02/2012]        [17:42 22/02/2012] EA90529F81E588EB8C66DAD89FAB5401
C:\_OTL\MovedFiles\09132012_153559\C_Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js        --a---- 7812 bytes        [13:35 13/09/2012]        [13:35 13/09/2012] E7F614A2E560E058EEAAADFE62854828

Searching for "perion"
No files found.

Searching for "        "
No files found.

-= EOF =-


t'john 21.09.2012 19:55

Fixen mit OTL

Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).

  • Deaktiviere etwaige Virenscanner wie Avira, Kaspersky etc.
  • Starte die OTL.exe.
    Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen".
  • Kopiere folgendes Skript in das Textfeld unterhalb von Benuterdefinierte Scans/Fixes:
  • Der Fix fängt mit :OTL an. Vergewissere dich, dass du ihn richtig kopiert hast.


Code:

:OTL
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\incredibar_installer_RASAPI32]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\incredibar_installer_RASMANCS]

:files
C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js
C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\extensions\ich@maltegoetz.de\defaults\preferences\prefs.js
C:\Users\Maas\AppData\Roaming\Thunderbird\Profiles\poqgwthf.default\prefs.js
:Commands
[emptytemp]

  • Schließe alle Programme.
  • Klicke auf den Fix Button.
  • Wenn OTL einen Neustart verlangt, bitte zulassen.
  • Kopiere den Inhalt des Logfiles hier in Code-Tags in Deinen Thread.
    Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\<datum_nummer.log>

Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

T!tr0 25.09.2012 12:58

Code:

All processes killed
========== OTL ==========
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\incredibar_installer_RASAPI32\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\incredibar_installer_RASMANCS\ deleted successfully.
========== FILES ==========
C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js moved successfully.
C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\extensions\ich@maltegoetz.de\defaults\preferences\prefs.js moved successfully.
C:\Users\Maas\AppData\Roaming\Thunderbird\Profiles\poqgwthf.default\prefs.js moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Maas
->Temp folder emptied: 6298058 bytes
->Temporary Internet Files folder emptied: 95382899 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 621374258 bytes
->Flash cache emptied: 9095 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5472 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 690,00 mb
 
 
OTL by OldTimer - Version 3.2.61.0 log created on 09252012_135507

Files\Folders moved on Reboot...
C:\Users\Maas\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Users\Maas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{A1AB7097-A03D-4746-8E24-E701CF3C2727}.tmp not found!
File\Folder C:\Users\Maas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{A439BDFD-28A1-444E-8D0B-B4A35BD457FB}.tmp not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


t'john 26.09.2012 12:20

Downloade Dir bitte AdwCleaner auf deinen Desktop.
NEU RUNTERLADEN
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

T!tr0 27.09.2012 15:06

Code:

# AdwCleaner v2.003 - Datei am 09/27/2012 um 16:03:52 erstellt
# Aktualisiert am 23/09/2012 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzer : Maas - MAAS-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Maas\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v15.0.1 (de)

Profilname : default
Datei : C:\Users\Maas\AppData\Roaming\Mozilla\Firefox\Profiles\uamslmvl.default\prefs.js

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [3364 octets] - [20/08/2012 16:16:58]
AdwCleaner[R2].txt - [3424 octets] - [20/08/2012 16:18:12]
AdwCleaner[S1].txt - [283 octets] - [20/08/2012 16:18:18]
AdwCleaner[S2].txt - [3551 octets] - [20/08/2012 19:36:22]
AdwCleaner[R3].txt - [1271 octets] - [30/08/2012 12:48:16]
AdwCleaner[S3].txt - [1230 octets] - [31/08/2012 17:09:08]
AdwCleaner[R4].txt - [1309 octets] - [01/09/2012 19:08:45]
AdwCleaner[S4].txt - [1871 octets] - [03/09/2012 11:08:56]
AdwCleaner[R5].txt - [1429 octets] - [08/09/2012 17:17:38]
AdwCleaner[S5].txt - [2177 octets] - [10/09/2012 16:56:08]
AdwCleaner[S6].txt - [1660 octets] - [15/09/2012 13:10:33]
AdwCleaner[S7].txt - [1399 octets] - [27/09/2012 16:03:52]

########## EOF - C:\AdwCleaner[S7].txt - [1459 octets] ##########

Incredi scheint auch nichtmehr da zu sein, zumindest nicht wenn ich einen neuen Tab öffne.

t'john 27.09.2012 19:24

Sehr gut! :daumenhoc


Deinstalliere:
Emsisoft Anti-Malware


ESET Online Scanner

Vorbereitung

  • Schließe evtl. vorhandene externe Festplatten und/oder sonstigen Wechselmedien (z. B. evtl. vorhandene USB-Sticks) an den Rechner an.
  • Bitte während des Online-Scans Anti-Virus-Programm und Firewall deaktivieren.
  • Vista/Win7-User: Bitte den Browser unbedingt als Administrator starten.
Los geht's

  • Lade und starte Eset Smartinstaller
  • Haken setzen bei YES, I accept the Terms of Use.
  • Klick auf Start.
  • Haken setzen bei Remove found threads und Scan archives.
  • Klick auf Start.
  • Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Finish drücken.
  • Browser schließen.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (manchmal auch C:\Programme\Eset\log.txt) suchen und mit Deinem Editor öffnen.
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Alle Zeitangaben in WEZ +1. Es ist jetzt 21:27 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132