Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 (https://www.trojaner-board.de/123876-fehler-c-windows-syswow64-rundll32-exe-folgender-eintrag-fehlt-fq10.html)

gabi.flabi 11.09.2012 08:19

Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10
 
Hallo, ich hoffe diesmal klappt es.
Wenn ich Windows starte kommt ein Fenster mit dem Inhalt: "Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10"

Habe OTL durchlaufen lassen und bekomme nur OTL.txt...aber keine Extra.txt


OTL logfile created on: 11.09.2012 08:31:44 - Run 1
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Users\gabriele\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

3,90 Gb Total Physical Memory | 2,10 Gb Available Physical Memory | 53,91% Memory free
7,79 Gb Paging File | 5,62 Gb Available in Paging File | 72,14% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 446,13 Gb Total Space | 390,22 Gb Free Space | 87,47% Space Free | Partition Type: NTFS

Computer Name: DELLICIOUS | User Name: gabriele | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012.09.10 10:39:04 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\gabriele\Desktop\OTL(1).exe
PRC - [2012.09.10 10:36:09 | 000,050,477 | ---- | M] () -- C:\Users\gabriele\Desktop\Defogger.exe
PRC - [2012.08.13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012.08.08 23:09:47 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.07.27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.07.03 03:21:38 | 026,868,192 | ---- | M] (Dropbox, Inc.) -- C:\Users\gabriele\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2012.05.15 14:42:08 | 001,044,816 | ---- | M] (Flexera Software, Inc.) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
PRC - [2012.05.14 20:20:05 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.14 20:20:04 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.02.29 16:57:26 | 002,306,048 | ---- | M] (Nemetschek SCIA) -- C:\Program Files (x86)\Common Files\SCIA\Protection\SCIA.exe
PRC - [2012.02.06 18:23:20 | 003,110,184 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\SyncUP\SyncUP.exe
PRC - [2011.11.25 16:32:36 | 000,687,400 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011.09.06 19:29:20 | 004,259,648 | ---- | M] (SoftThinks - Dell) -- C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
PRC - [2011.08.18 17:05:54 | 002,751,808 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
PRC - [2011.08.18 17:05:46 | 001,692,480 | ---- | M] (SoftThinks SAS) -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
PRC - [2011.08.01 19:56:48 | 000,460,096 | ---- | M] (SoftThinks - Dell) -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
PRC - [2011.07.08 01:14:02 | 000,150,312 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\SyncUP\Nero.AndroidServer.exe
PRC - [2011.06.29 16:52:54 | 000,474,176 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe
PRC - [2011.06.28 03:26:30 | 002,022,976 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe
PRC - [2011.05.26 14:05:44 | 001,408,848 | ---- | M] (Flexera Software, Inc.) -- C:\Program Files (x86)\Common Files\SCIA\Protection\lmgrd.exe
PRC - [2011.05.19 09:16:48 | 000,995,392 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
PRC - [2011.05.19 09:16:46 | 001,335,360 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
PRC - [2011.05.19 09:16:36 | 000,921,664 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
PRC - [2011.05.19 09:16:34 | 000,839,744 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
PRC - [2011.04.30 02:18:16 | 000,885,760 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
PRC - [2011.04.13 18:39:14 | 000,503,942 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
PRC - [2010.12.21 02:24:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.12.21 02:24:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.11.17 18:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe


========== Modules (No Company Name) ==========

MOD - [2012.09.10 10:36:09 | 000,050,477 | ---- | M] () -- C:\Users\gabriele\Desktop\Defogger.exe
MOD - [2012.06.19 16:11:46 | 000,240,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\f2f8201dd3453250dfd9ed1afce630a0\WindowsFormsIntegration.ni.dll
MOD - [2012.06.19 15:03:23 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll
MOD - [2012.06.19 15:03:16 | 001,044,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Printing\991dbe40be5b114ed705bb5b48e6b330\System.Printing.ni.dll
MOD - [2012.06.19 15:03:15 | 002,157,056 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\87f73de6e080d37be93adfc7d5c31d7a\ReachFramework.ni.dll
MOD - [2012.06.19 15:03:13 | 001,658,368 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\163517c8a195fb48f7ef6ee17c585bdb\PresentationUI.ni.dll
MOD - [2012.06.19 15:03:12 | 014,340,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll
MOD - [2012.06.19 15:02:54 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012.06.19 15:02:47 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012.06.19 15:02:46 | 001,806,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\3421b96c2885b8e4137a376ff3d95fa5\System.Deployment.ni.dll
MOD - [2012.06.19 15:02:42 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
MOD - [2012.05.15 08:57:42 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\64de6810023adccdc56ddae13bdd6b03\System.Xml.Linq.ni.dll
MOD - [2012.05.15 08:57:37 | 009,921,536 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\51a2589d5ee1c9c40fb6c56391570f9e\System.Data.Entity.ni.dll
MOD - [2012.05.15 08:56:48 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll
MOD - [2012.05.15 08:41:12 | 002,347,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\72a24b45e11d64eb2bc840aae9419ba5\System.Runtime.Serialization.ni.dll
MOD - [2012.05.15 08:40:52 | 002,297,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
MOD - [2012.05.15 08:25:02 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll
MOD - [2012.05.15 08:24:46 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012.05.15 08:24:45 | 000,628,224 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\168755d010e5a96ac940b0ddd27616a4\System.EnterpriseServices.ni.dll
MOD - [2012.05.15 08:24:44 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll
MOD - [2012.05.15 08:24:44 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\80fae9f16f80075535e72458ef293f7a\System.Transactions.ni.dll
MOD - [2012.05.15 08:24:40 | 001,117,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ef0d8a4790c24a3a091170958bc7b976\System.DirectoryServices.ni.dll
MOD - [2012.05.15 08:24:24 | 000,039,424 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5a9d0ff936810991cedd098fe006a9be\PresentationCFFRasterizer.ni.dll
MOD - [2012.05.15 08:24:16 | 000,185,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\d8af9a65cf0ed85d47360796e2645a06\UIAutomationTypes.ni.dll
MOD - [2012.05.15 08:24:16 | 000,060,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ca2eff60beb3ba00a529a2d42dceca22\UIAutomationProvider.ni.dll
MOD - [2012.05.15 08:24:16 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessibility.ni.dll
MOD - [2012.05.15 08:24:08 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
MOD - [2012.05.15 08:24:05 | 000,680,448 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\054fcff18035c210487b0888e6461192\System.Security.ni.dll
MOD - [2012.05.15 08:24:03 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012.05.15 08:24:00 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012.05.15 08:23:59 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012.05.15 08:23:56 | 000,015,872 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\55c57057dc81a5e8c5bde3a230f0bcb9\Microsoft.VisualC.ni.dll
MOD - [2012.05.15 08:23:55 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2011.11.09 04:10:25 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2011.08.18 17:05:54 | 002,751,808 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
MOD - [2011.07.08 01:14:06 | 000,891,688 | ---- | M] () -- C:\Program Files (x86)\Nero\SyncUP\System.Data.SQLite.dll
MOD - [2011.07.08 01:13:10 | 000,251,688 | ---- | M] () -- C:\Program Files (x86)\Nero\SyncUP\System.ComponentModel.Composition.dll
MOD - [2011.06.29 16:52:54 | 000,474,176 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe
MOD - [2011.06.28 03:26:30 | 002,022,976 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe
MOD - [2011.06.28 03:25:30 | 000,058,944 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\DataService.dll
MOD - [2011.06.25 07:32:36 | 000,323,136 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\de-DE\UI\ManagerUI.dll
MOD - [2011.06.25 07:20:26 | 000,565,968 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\sqlite3.dll
MOD - [2011.04.30 02:18:16 | 000,885,760 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
MOD - [2011.04.30 02:13:50 | 002,225,664 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtCore4.dll
MOD - [2011.04.30 02:13:48 | 007,938,048 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtGui4.dll
MOD - [2011.03.17 00:11:16 | 004,297,568 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
MOD - [2010.11.25 06:44:02 | 000,375,280 | ---- | M] () -- c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
MOD - [2010.11.21 08:49:35 | 000,397,312 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Data.Entity.resources\3.5.0.0_de_b77a5c561934e089\System.Data.Entity.resources.dll
MOD - [2010.11.21 08:49:35 | 000,249,856 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_de_31bf3856ad364e35\PresentationFramework.resources.dll
MOD - [2010.11.21 08:49:35 | 000,110,592 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationCore.resources\3.0.0.0_de_31bf3856ad364e35\PresentationCore.resources.dll
MOD - [2010.11.21 08:49:27 | 000,167,936 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml.resources\2.0.0.0_de_b77a5c561934e089\System.Xml.resources.dll
MOD - [2010.11.21 08:49:25 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll
MOD - [2010.11.21 05:24:08 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2010.11.17 18:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
MOD - [2010.03.22 23:52:42 | 006,776,832 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\QtGui4.dll
MOD - [2010.03.17 04:28:28 | 000,326,144 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\QtXml4.dll
MOD - [2010.03.17 04:28:16 | 000,635,904 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\QtNetwork4.dll
MOD - [2010.03.17 04:28:04 | 001,926,144 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\QtCore4.dll
MOD - [2010.03.12 03:52:34 | 000,225,280 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qmng4.dll
MOD - [2010.03.12 03:52:34 | 000,028,160 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qgif4.dll
MOD - [2010.03.05 23:07:58 | 000,125,952 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qjpeg4.dll
MOD - [2010.03.05 23:07:58 | 000,031,744 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qico4.dll
MOD - [2009.06.10 23:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll


========== Services (SafeList) ==========

SRV:64bit: - [2011.08.08 15:39:18 | 001,166,848 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3)
SRV:64bit: - [2011.07.28 05:04:48 | 001,517,328 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:64bit: - [2011.07.28 04:48:34 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2011.07.28 04:44:18 | 000,844,560 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:64bit: - [2011.06.03 20:51:38 | 000,134,928 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr)
SRV:64bit: - [2010.11.29 23:00:56 | 000,149,504 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:64bit: - [2010.10.08 07:18:46 | 000,697,616 | ---- | M] () [Auto | Running] -- C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe -- (ipsecd)
SRV:64bit: - [2010.10.08 07:18:46 | 000,056,592 | ---- | M] () [Auto | Running] -- C:\Program Files\ShrewSoft\VPN Client\dtpd.exe -- (dtpd)
SRV:64bit: - [2010.10.08 07:18:44 | 000,957,712 | ---- | M] () [Auto | Running] -- C:\Program Files\ShrewSoft\VPN Client\iked.exe -- (iked)
SRV:64bit: - [2009.11.18 04:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012.08.15 01:31:52 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.08.13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012.08.09 20:18:59 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.07.27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.06.07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.05.15 14:42:08 | 001,044,816 | ---- | M] (Flexera Software, Inc.) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012.05.14 20:20:05 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.14 20:20:04 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.11.25 16:32:36 | 000,687,400 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011.10.17 23:11:03 | 001,673,520 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\DIAL GmbH\DIAL Communication Framework\DialComService.exe -- (DialComService)
SRV - [2011.08.18 17:05:46 | 001,692,480 | ---- | M] (SoftThinks SAS) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE -- (SftService)
SRV - [2011.05.26 14:05:44 | 001,408,848 | ---- | M] (Flexera Software, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\SCIA\Protection\lmgrd.exe -- (Scia Licence Server)
SRV - [2011.05.19 09:16:48 | 000,995,392 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2011.05.19 09:16:46 | 001,335,360 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2011.05.19 09:16:36 | 000,921,664 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2010.12.21 02:24:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010.12.21 02:24:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010.11.25 13:34:18 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12)
SRV - [2010.11.25 13:33:18 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012.05.14 20:20:05 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.05.14 20:20:05 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.11.09 04:10:36 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.11.09 04:10:36 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.09.16 16:08:07 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011.08.08 15:32:08 | 000,299,008 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPALP)
DRV:64bit: - [2011.08.08 15:32:08 | 000,299,008 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPAL)
DRV:64bit: - [2011.08.04 03:28:32 | 008,604,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64)
DRV:64bit: - [2011.07.20 15:39:58 | 012,287,456 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011.07.20 02:54:06 | 000,059,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (iBtFltCoex)
DRV:64bit: - [2011.07.19 23:13:42 | 000,282,624 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf)
DRV:64bit: - [2011.05.19 09:17:04 | 000,053,248 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux)
DRV:64bit: - [2011.05.19 09:17:02 | 000,051,712 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btmaud.sys -- (btmaudio)
DRV:64bit: - [2011.05.17 17:27:52 | 000,025,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus)
DRV:64bit: - [2011.05.17 17:27:50 | 000,034,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:64bit: - [2011.05.13 10:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2011.02.11 00:52:34 | 000,181,760 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2011.02.11 00:52:34 | 000,082,432 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2011.01.20 19:20:46 | 000,176,096 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV:64bit: - [2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.12.01 18:12:06 | 000,250,984 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010.12.01 00:02:54 | 000,412,264 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010.11.29 23:00:04 | 000,016,120 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.10.20 02:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010.10.16 02:28:18 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010.09.02 09:18:46 | 000,021,504 | ---- | M] (Shrew Soft Inc) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vfilter.sys -- (vflt)
DRV:64bit: - [2010.09.02 09:18:46 | 000,017,408 | ---- | M] (Shrew Soft Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\virtualnet.sys -- (vnet)
DRV:64bit: - [2010.03.19 11:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2010.02.27 17:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008.06.27 07:51:10 | 000,088,632 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:64bit: - [2006.11.01 20:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {A01FE0C9-8B06-4230-AB15-E564468E38A8}
IE:64bit: - HKLM\..\SearchScopes\{A01FE0C9-8B06-4230-AB15-E564468E38A8}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {A01FE0C9-8B06-4230-AB15-E564468E38A8}
IE - HKLM\..\SearchScopes\{A01FE0C9-8B06-4230-AB15-E564468E38A8}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USCON/8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/USCON/8
IE - HKCU\..\SearchScopes,DefaultScope = {A01FE0C9-8B06-4230-AB15-E564468E38A8}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.9
FF - prefs.js..network.proxy.type: 4
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_271.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@graphisoft.com/GDL Web Plug-in: C:\Program Files (x86)\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll (Graphisoft SE)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\gabriele\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.08.10 07:32:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012.08.10 07:32:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.08.10 07:32:26 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012.03.30 17:47:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\gabriele\AppData\Roaming\Mozilla\Extensions
[2012.05.03 11:37:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\gabriele\AppData\Roaming\Mozilla\Firefox\Profiles\bdxvsrnh.default\extensions
[2012.03.30 19:12:45 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\gabriele\AppData\Roaming\Mozilla\Firefox\Profiles\bdxvsrnh.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.09.03 01:30:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.08.26 23:10:53 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.08.10 07:23:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}
[2012.09.03 01:30:26 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.08.09 20:18:59 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.07.01 12:34:54 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.07.01 12:34:54 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.07.01 12:34:54 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.07.01 12:34:54 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.01 12:34:54 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.01 12:34:54 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml

O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (DIALux 3.1 ULDBrowserHelper Class) - {69AB812A-8CE4-4BF3-B49B-3B60A9F31FB2} - C:\Program Files (x86)\DIALux\DLXShellExtension.dll (DIAL GmbH, Germany)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] c:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Stage Remote] C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe ()
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe (Dell, Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [NeroLauncher] C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe ()
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKCU..\Run: [Facebook Update] C:\Users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - Startup: C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\gabriele\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2541EF2C-0496-4F0B-9962-BD4206C8C433}: Domain = fh-bochum.de
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2541EF2C-0496-4F0B-9962-BD4206C8C433}: NameServer = 193.175.112.3,195.37.168.3
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A564C12D-7DE1-4F1E-B840-C5DA06EF52D4}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\dialux - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\dialux {8352FA4C-39C6-11D3-ADBA-00A0244FB1A2} - C:\Program Files (x86)\DIALux\DLXToolBox.dll (DIAL GmbH, Germany)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012.09.10 10:39:02 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\gabriele\Desktop\OTL(1).exe
[2012.09.03 23:57:45 | 000,000,000 | R--D | C] -- C:\Users\gabriele\Desktop\MySyncUPFiles
[2012.09.03 01:25:12 | 000,000,000 | ---D | C] -- C:\Users\gabriele\Desktop\joschui
[2012.08.23 22:54:37 | 000,000,000 | ---D | C] -- C:\Users\gabriele\Documents\BIMx
[2012.08.23 22:43:10 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Support Center
[2012.08.23 22:43:10 | 000,000,000 | ---D | C] -- C:\ProgramData\PC-Doctor for Windows

========== Files - Modified Within 30 Days ==========

[2012.09.11 08:31:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.11 08:30:58 | 000,001,150 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000UA.job
[2012.09.11 08:30:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.11 08:01:48 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.11 08:01:48 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.11 07:56:01 | 000,001,114 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.09.11 07:56:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.09.11 07:54:03 | 3137,994,752 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.10 10:52:23 | 000,302,592 | ---- | M] () -- C:\Users\gabriele\Desktop\y29pw4u5.exe
[2012.09.10 10:39:04 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\gabriele\Desktop\OTL(1).exe
[2012.09.10 10:37:25 | 000,000,000 | ---- | M] () -- C:\Users\gabriele\defogger_reenable
[2012.09.10 10:36:09 | 000,050,477 | ---- | M] () -- C:\Users\gabriele\Desktop\Defogger.exe
[2012.09.10 10:34:42 | 000,001,128 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000Core.job
[2012.09.04 00:01:17 | 001,612,484 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.09.04 00:01:17 | 000,696,870 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.09.04 00:01:17 | 000,652,148 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.09.04 00:01:17 | 000,148,134 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.09.04 00:01:17 | 000,121,080 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.08.26 23:08:51 | 003,089,016 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.08.13 23:05:47 | 004,503,728 | ---- | M] () -- C:\ProgramData\23lldnur.pad
[2012.08.13 23:05:47 | 000,001,859 | ---- | M] () -- C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk

========== Files Created - No Company Name ==========

[2012.09.10 10:52:23 | 000,302,592 | ---- | C] () -- C:\Users\gabriele\Desktop\y29pw4u5.exe
[2012.09.10 10:37:25 | 000,000,000 | ---- | C] () -- C:\Users\gabriele\defogger_reenable
[2012.09.10 10:36:04 | 000,050,477 | ---- | C] () -- C:\Users\gabriele\Desktop\Defogger.exe
[2012.08.13 23:05:47 | 004,503,728 | ---- | C] () -- C:\ProgramData\23lldnur.pad
[2012.08.13 23:05:47 | 000,001,859 | ---- | C] () -- C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk
[2012.04.09 16:25:57 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2012.04.06 18:52:09 | 000,000,102 | ---- | C] () -- C:\Windows\Dialux.ini
[2012.04.02 18:59:53 | 000,008,192 | ---- | C] () -- C:\Users\gabriele\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.11.09 03:51:17 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.11.09 03:51:15 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.11.09 03:51:14 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2011.11.09 03:51:13 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.11.09 03:51:11 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011.11.09 02:45:48 | 000,017,776 | ---- | C] () -- C:\Windows\EvtMessage.dll
[2011.02.11 12:22:50 | 001,590,378 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI

========== LOP Check ==========

[2012.09.11 07:55:21 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Dropbox
[2012.05.01 17:51:21 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\DVDVideoSoft
[2012.03.30 16:53:34 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Fingertapps
[2012.08.23 22:53:51 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Graphisoft
[2012.03.30 18:24:32 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Install.GS
[2012.03.30 16:53:04 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Leadertech
[2012.09.02 23:13:17 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Nokia
[2012.09.02 23:13:17 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Nokia Suite
[2012.03.30 21:35:03 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\OpenOffice.org
[2012.03.30 19:51:05 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\PC Suite
[2012.04.02 12:03:45 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\PCDr
[2012.06.15 22:31:09 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\PDF Writer
[2012.03.30 19:35:04 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\SoftGrid Client
[2012.03.30 17:55:56 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Thunderbird
[2012.03.30 17:42:10 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\TP
[2012.03.30 17:56:22 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\ZinioReader4
[2012.09.10 10:34:42 | 000,001,128 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000Core.job
[2012.09.11 08:30:58 | 000,001,150 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000UA.job
[2012.07.27 00:50:00 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2009.07.14 07:08:49 | 000,026,082 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >


Danke im Voraus ! Ich hab nämlich keine Ahnung was ich machen soll..:wtf:

Grüße

cosinus 11.09.2012 12:49

Bitte erstmal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

gabi.flabi 12.09.2012 22:43

hi cosinus,

danke für deine hilfe !

log von malewarebytes
Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.12.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
gabriele :: DELLICIOUS [Administrator]

Schutz: Aktiviert

12.09.2012 16:46:55
mbam-log-2012-09-12 (16-46-55).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 363966
Laufzeit: 1 Stunde(n), 43 Minute(n), 9 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk (Trojan.Ransom.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

und
Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.12.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
gabriele :: DELLICIOUS [Administrator]

Schutz: Aktiviert

12.09.2012 16:46:55
mbam-log-2012-09-12 (18-30-41).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 363966
Laufzeit: 1 Stunde(n), 43 Minute(n), 9 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk (Trojan.Ransom.Gen) -> Keine Aktion durchgeführt.

(Ende)

bei eset gab es keine funde..lasse es aber nochmal durchlaufen

und auch nach dem 3.Scan kommt "No threats found"

cosinus 13.09.2012 15:37

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.

Falls der adwCleaner schon mal in der runtergeladen wurde, bitte die alte adwcleaner.exe löschen und neu runterladen!!
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Rx].txt. (x=fortlaufende Nummer)

gabi.flabi 14.09.2012 18:36

Code:

# AdwCleaner v2.001 - Datei am 09/14/2012 um 19:35:16 erstellt
# Aktualisiert am 09/09/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : gabriele - DELLICIOUS
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\gabriele\Desktop\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v15.0.1 (de)

Profilname : default
Datei : C:\Users\gabriele\AppData\Roaming\Mozilla\Firefox\Profiles\bdxvsrnh.default\prefs.js

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [852 octets] - [14/09/2012 19:35:16]

########## EOF - C:\AdwCleaner[R1].txt - [911 octets] ##########


cosinus 14.09.2012 22:58

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Sx].txt. (x=fortlaufende Nummer)

gabi.flabi 15.09.2012 08:30

Code:

# AdwCleaner v2.001 - Datei am 09/15/2012 um 09:26:27 erstellt
# Aktualisiert am 09/09/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : gabriele - DELLICIOUS
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\gabriele\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

Wiederhergestellt : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

-\\ Mozilla Firefox v15.0.1 (de)

Profilname : default
Datei : C:\Users\gabriele\AppData\Roaming\Mozilla\Firefox\Profiles\bdxvsrnh.default\prefs.js

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [977 octets] - [14/09/2012 19:35:16]
AdwCleaner[S1].txt - [1570 octets] - [15/09/2012 09:26:27]

########## EOF - C:\AdwCleaner[S1].txt - [1630 octets] ##########


cosinus 15.09.2012 14:04

Hätte da mal zwei Fragen bevor es weiter geht (wir sind noch nicht fertig!)

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

gabi.flabi 15.09.2012 18:15

Windows funktioniert wieder..keine Fehlermeldung mehr beim Start.
Im Startmenü ist alles wie zuvor vorhanden.

cosinus 16.09.2012 16:03

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


gabi.flabi 16.09.2012 22:23

OTL Logfile:
Code:

OTL logfile created on: 16.09.2012 23:04:57 - Run 1
OTL by OldTimer - Version 3.2.61.5    Folder = C:\Users\gabriele\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,90 Gb Total Physical Memory | 2,27 Gb Available Physical Memory | 58,17% Memory free
7,79 Gb Paging File | 5,64 Gb Available in Paging File | 72,41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 446,13 Gb Total Space | 387,10 Gb Free Space | 86,77% Space Free | Partition Type: NTFS
Drive Y: | 19,53 Gb Total Space | 10,99 Gb Free Space | 56,28% Space Free | Partition Type: NTFS
 
Computer Name: DELLICIOUS | User Name: gabriele | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.09.16 23:02:07 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\gabriele\Desktop\OTL(1).exe
PRC - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.07 17:04:44 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.08.13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012.08.08 23:09:47 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.07.27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.07.13 20:18:35 | 000,138,096 | ---- | M] (Facebook Inc.) -- C:\Users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe
PRC - [2012.07.03 03:21:38 | 026,868,192 | ---- | M] (Dropbox, Inc.) -- C:\Users\gabriele\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2012.05.15 14:42:08 | 001,044,816 | ---- | M] (Flexera Software, Inc.) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
PRC - [2012.05.14 20:20:05 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.14 20:20:04 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.02.29 16:57:26 | 002,306,048 | ---- | M] (Nemetschek SCIA) -- C:\Program Files (x86)\Common Files\SCIA\Protection\SCIA.exe
PRC - [2012.02.06 18:23:20 | 003,110,184 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\SyncUP\SyncUP.exe
PRC - [2011.11.25 16:32:36 | 000,687,400 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011.09.06 19:29:20 | 004,259,648 | ---- | M] (SoftThinks - Dell) -- C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
PRC - [2011.08.18 17:05:54 | 002,751,808 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
PRC - [2011.08.18 17:05:46 | 001,692,480 | ---- | M] (SoftThinks SAS) -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
PRC - [2011.08.01 19:56:48 | 000,460,096 | ---- | M] (SoftThinks - Dell) -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
PRC - [2011.07.08 01:14:02 | 000,150,312 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\SyncUP\Nero.AndroidServer.exe
PRC - [2011.06.29 16:52:54 | 000,474,176 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe
PRC - [2011.06.28 03:26:30 | 002,022,976 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe
PRC - [2011.05.26 14:05:44 | 001,408,848 | ---- | M] (Flexera Software, Inc.) -- C:\Program Files (x86)\Common Files\SCIA\Protection\lmgrd.exe
PRC - [2011.05.19 09:16:48 | 000,995,392 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
PRC - [2011.05.19 09:16:46 | 001,335,360 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
PRC - [2011.05.19 09:16:36 | 000,921,664 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
PRC - [2011.05.19 09:16:34 | 000,839,744 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
PRC - [2011.04.13 18:39:14 | 000,503,942 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
PRC - [2010.12.21 02:24:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.12.21 02:24:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.11.17 18:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.19 16:11:46 | 000,240,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\f2f8201dd3453250dfd9ed1afce630a0\WindowsFormsIntegration.ni.dll
MOD - [2012.06.19 15:03:23 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll
MOD - [2012.06.19 15:03:16 | 001,044,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Printing\991dbe40be5b114ed705bb5b48e6b330\System.Printing.ni.dll
MOD - [2012.06.19 15:03:15 | 002,157,056 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\87f73de6e080d37be93adfc7d5c31d7a\ReachFramework.ni.dll
MOD - [2012.06.19 15:03:13 | 001,658,368 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\163517c8a195fb48f7ef6ee17c585bdb\PresentationUI.ni.dll
MOD - [2012.06.19 15:03:12 | 014,340,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll
MOD - [2012.06.19 15:02:54 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012.06.19 15:02:47 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012.06.19 15:02:46 | 001,806,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\3421b96c2885b8e4137a376ff3d95fa5\System.Deployment.ni.dll
MOD - [2012.06.19 15:02:42 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
MOD - [2012.05.15 08:57:42 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\64de6810023adccdc56ddae13bdd6b03\System.Xml.Linq.ni.dll
MOD - [2012.05.15 08:57:37 | 009,921,536 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\51a2589d5ee1c9c40fb6c56391570f9e\System.Data.Entity.ni.dll
MOD - [2012.05.15 08:56:48 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll
MOD - [2012.05.15 08:41:12 | 002,347,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\72a24b45e11d64eb2bc840aae9419ba5\System.Runtime.Serialization.ni.dll
MOD - [2012.05.15 08:40:52 | 002,297,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
MOD - [2012.05.15 08:25:02 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll
MOD - [2012.05.15 08:24:46 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012.05.15 08:24:45 | 000,628,224 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\168755d010e5a96ac940b0ddd27616a4\System.EnterpriseServices.ni.dll
MOD - [2012.05.15 08:24:44 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll
MOD - [2012.05.15 08:24:44 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\80fae9f16f80075535e72458ef293f7a\System.Transactions.ni.dll
MOD - [2012.05.15 08:24:40 | 001,117,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ef0d8a4790c24a3a091170958bc7b976\System.DirectoryServices.ni.dll
MOD - [2012.05.15 08:24:24 | 000,039,424 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5a9d0ff936810991cedd098fe006a9be\PresentationCFFRasterizer.ni.dll
MOD - [2012.05.15 08:24:16 | 000,185,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\d8af9a65cf0ed85d47360796e2645a06\UIAutomationTypes.ni.dll
MOD - [2012.05.15 08:24:16 | 000,060,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ca2eff60beb3ba00a529a2d42dceca22\UIAutomationProvider.ni.dll
MOD - [2012.05.15 08:24:16 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessibility.ni.dll
MOD - [2012.05.15 08:24:08 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
MOD - [2012.05.15 08:24:05 | 000,680,448 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\054fcff18035c210487b0888e6461192\System.Security.ni.dll
MOD - [2012.05.15 08:24:03 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012.05.15 08:24:00 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012.05.15 08:23:59 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012.05.15 08:23:56 | 000,015,872 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\55c57057dc81a5e8c5bde3a230f0bcb9\Microsoft.VisualC.ni.dll
MOD - [2012.05.15 08:23:55 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2011.11.09 04:10:25 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2011.08.18 17:05:54 | 002,751,808 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
MOD - [2011.07.08 01:14:06 | 000,891,688 | ---- | M] () -- C:\Program Files (x86)\Nero\SyncUP\System.Data.SQLite.dll
MOD - [2011.07.08 01:13:24 | 000,026,408 | ---- | M] () -- C:\Program Files (x86)\Nero\SyncUP\AdbDetect.dll
MOD - [2011.07.08 01:13:10 | 000,251,688 | ---- | M] () -- C:\Program Files (x86)\Nero\SyncUP\System.ComponentModel.Composition.dll
MOD - [2011.06.29 16:52:54 | 000,474,176 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe
MOD - [2011.06.28 03:26:30 | 002,022,976 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe
MOD - [2011.06.28 03:25:30 | 000,058,944 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\DataService.dll
MOD - [2011.06.25 07:32:36 | 000,323,136 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\de-DE\UI\ManagerUI.dll
MOD - [2011.06.25 07:20:26 | 000,565,968 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\sqlite3.dll
MOD - [2010.11.25 06:44:02 | 000,375,280 | ---- | M] () -- c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
MOD - [2010.11.21 08:49:35 | 000,397,312 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Data.Entity.resources\3.5.0.0_de_b77a5c561934e089\System.Data.Entity.resources.dll
MOD - [2010.11.21 08:49:35 | 000,249,856 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_de_31bf3856ad364e35\PresentationFramework.resources.dll
MOD - [2010.11.21 08:49:35 | 000,110,592 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationCore.resources\3.0.0.0_de_31bf3856ad364e35\PresentationCore.resources.dll
MOD - [2010.11.21 08:49:27 | 000,167,936 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml.resources\2.0.0.0_de_b77a5c561934e089\System.Xml.resources.dll
MOD - [2010.11.21 05:24:08 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2010.11.17 18:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
MOD - [2010.03.22 23:52:42 | 006,776,832 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\QtGui4.dll
MOD - [2010.03.17 04:28:28 | 000,326,144 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\QtXml4.dll
MOD - [2010.03.17 04:28:16 | 000,635,904 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\QtNetwork4.dll
MOD - [2010.03.17 04:28:04 | 001,926,144 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\QtCore4.dll
MOD - [2010.03.12 03:52:34 | 000,225,280 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qmng4.dll
MOD - [2010.03.12 03:52:34 | 000,028,160 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qgif4.dll
MOD - [2010.03.05 23:07:58 | 000,125,952 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qjpeg4.dll
MOD - [2010.03.05 23:07:58 | 000,031,744 | ---- | M] () -- C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qico4.dll
MOD - [2009.06.10 23:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2011.08.08 15:39:18 | 001,166,848 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3)
SRV:64bit: - [2011.07.28 05:04:48 | 001,517,328 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:64bit: - [2011.07.28 04:48:34 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2011.07.28 04:44:18 | 000,844,560 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:64bit: - [2011.06.03 20:51:38 | 000,134,928 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr)
SRV:64bit: - [2010.11.29 23:00:56 | 000,149,504 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:64bit: - [2010.10.08 07:18:46 | 000,697,616 | ---- | M] () [Auto | Running] -- C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe -- (ipsecd)
SRV:64bit: - [2010.10.08 07:18:46 | 000,056,592 | ---- | M] () [Auto | Running] -- C:\Program Files\ShrewSoft\VPN Client\dtpd.exe -- (dtpd)
SRV:64bit: - [2010.10.08 07:18:44 | 000,957,712 | ---- | M] () [Auto | Running] -- C:\Program Files\ShrewSoft\VPN Client\iked.exe -- (iked)
SRV:64bit: - [2009.11.18 04:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012.09.12 23:50:01 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.08.15 01:31:52 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.08.13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012.07.27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.06.07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.05.15 14:42:08 | 001,044,816 | ---- | M] (Flexera Software, Inc.) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012.05.14 20:20:05 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.14 20:20:04 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.11.25 16:32:36 | 000,687,400 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011.10.17 23:11:03 | 001,673,520 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\DIAL GmbH\DIAL Communication Framework\DialComService.exe -- (DialComService)
SRV - [2011.08.18 17:05:46 | 001,692,480 | ---- | M] (SoftThinks SAS) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE -- (SftService)
SRV - [2011.05.26 14:05:44 | 001,408,848 | ---- | M] (Flexera Software, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\SCIA\Protection\lmgrd.exe -- (Scia Licence Server)
SRV - [2011.05.19 09:16:48 | 000,995,392 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2011.05.19 09:16:46 | 001,335,360 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2011.05.19 09:16:36 | 000,921,664 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2010.12.21 02:24:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010.12.21 02:24:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010.11.25 13:34:18 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12)
SRV - [2010.11.25 13:33:18 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.09.07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.05.14 20:20:05 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.05.14 20:20:05 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.11.09 04:10:36 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.11.09 04:10:36 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.09.16 16:08:07 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011.08.08 15:32:08 | 000,299,008 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPALP)
DRV:64bit: - [2011.08.08 15:32:08 | 000,299,008 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPAL)
DRV:64bit: - [2011.08.04 03:28:32 | 008,604,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64)
DRV:64bit: - [2011.07.20 15:39:58 | 012,287,456 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011.07.20 02:54:06 | 000,059,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (iBtFltCoex)
DRV:64bit: - [2011.07.19 23:13:42 | 000,282,624 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf)
DRV:64bit: - [2011.05.19 09:17:04 | 000,053,248 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux)
DRV:64bit: - [2011.05.19 09:17:02 | 000,051,712 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaud.sys -- (btmaudio)
DRV:64bit: - [2011.05.17 17:27:52 | 000,025,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus)
DRV:64bit: - [2011.05.17 17:27:50 | 000,034,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:64bit: - [2011.05.13 10:28:46 | 000,363,856 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2011.02.11 00:52:34 | 000,181,760 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2011.02.11 00:52:34 | 000,082,432 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2011.01.20 19:20:46 | 000,176,096 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV:64bit: - [2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.12.01 18:12:06 | 000,250,984 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010.12.01 00:02:54 | 000,412,264 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010.11.29 23:00:04 | 000,016,120 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.10.20 02:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010.10.16 02:28:18 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010.09.02 09:18:46 | 000,021,504 | ---- | M] (Shrew Soft Inc) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vfilter.sys -- (vflt)
DRV:64bit: - [2010.09.02 09:18:46 | 000,017,408 | ---- | M] (Shrew Soft Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\virtualnet.sys -- (vnet)
DRV:64bit: - [2010.03.19 11:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2010.02.27 17:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008.06.27 07:51:10 | 000,088,632 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:64bit: - [2006.11.01 20:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{A01FE0C9-8B06-4230-AB15-E564468E38A8}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{A01FE0C9-8B06-4230-AB15-E564468E38A8}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-1531662492-2859076138-1287364489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USCON/8
IE - HKU\S-1-5-21-1531662492-2859076138-1287364489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/USCON/8
IE - HKU\S-1-5-21-1531662492-2859076138-1287364489-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1531662492-2859076138-1287364489-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledAddons: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.9
FF - prefs.js..network.proxy.type: 4
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_271.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@graphisoft.com/GDL Web Plug-in: C:\Program Files (x86)\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll (Graphisoft SE)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\gabriele\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.12 23:50:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012.08.10 07:32:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.12 23:50:01 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2012.03.30 17:47:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\gabriele\AppData\Roaming\Mozilla\Extensions
[2012.09.16 23:03:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\gabriele\AppData\Roaming\Mozilla\Firefox\Profiles\bdxvsrnh.default\extensions
[2012.03.30 19:12:45 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\gabriele\AppData\Roaming\Mozilla\Firefox\Profiles\bdxvsrnh.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.09.16 23:03:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\gabriele\AppData\Roaming\Mozilla\Firefox\Profiles\bdxvsrnh.default\extensions\staged
[2012.09.12 23:50:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.08.26 23:10:53 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.09.03 01:30:26 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.09.12 23:50:01 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.07.01 12:34:54 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.09.12 23:50:00 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.07.01 12:34:54 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.07.01 12:34:54 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.01 12:34:54 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.01 12:34:54 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (DIALux 3.1 ULDBrowserHelper Class) - {69AB812A-8CE4-4BF3-B49B-3B60A9F31FB2} - C:\Program Files (x86)\DIALux\DLXShellExtension.dll (DIAL GmbH, Germany)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] c:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Stage Remote] C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe ()
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe (Dell, Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [NeroLauncher] C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe ()
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1531662492-2859076138-1287364489-1000..\Run: [Facebook Update] C:\Users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\gabriele\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2541EF2C-0496-4F0B-9962-BD4206C8C433}: Domain = fh-bochum.de
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2541EF2C-0496-4F0B-9962-BD4206C8C433}: NameServer = 193.175.112.3,195.37.168.3
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A564C12D-7DE1-4F1E-B840-C5DA06EF52D4}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\dialux - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\dialux {8352FA4C-39C6-11D3-ADBA-00A0244FB1A2} - C:\Program Files (x86)\DIALux\DLXToolBox.dll (DIAL GmbH, Germany)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - Unable to obtain root file information for disk Y:\
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: MCODS - Reg Error: Value error.
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MCODS - Reg Error: Value error.
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: MCODS - Reg Error: Value error.
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: MCODS - Reg Error: Value error.
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {A88AD365-C2DD-41ED-3DC2-238587A9EDE7} - Browser Customizations
ActiveX: {BAC058C0-A203-9824-D8AF-5CD493B61F27} - Microsoft Windows Media Player
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EE36EBE3-DF5C-D2EF-D051-8CE83DAC09FA} - Themes Setup
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.16 23:02:00 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\gabriele\Desktop\OTL(1).exe
[2012.09.15 19:27:05 | 000,000,000 | ---D | C] -- C:\Users\gabriele\Desktop\Gebäudetechnik
[2012.09.12 18:34:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.09.12 18:32:55 | 002,322,184 | ---- | C] (ESET) -- C:\Users\gabriele\Desktop\esetsmartinstaller_enu.exe
[2012.09.12 16:45:04 | 000,000,000 | ---D | C] -- C:\Users\gabriele\AppData\Roaming\Malwarebytes
[2012.09.12 16:44:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.09.12 16:44:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.09.12 16:44:54 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.09.12 16:44:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.09.03 23:57:45 | 000,000,000 | R--D | C] -- C:\Users\gabriele\Desktop\MySyncUPFiles
[2012.09.03 01:25:12 | 000,000,000 | ---D | C] -- C:\Users\gabriele\Desktop\joschui
[2012.08.23 22:54:37 | 000,000,000 | ---D | C] -- C:\Users\gabriele\Documents\BIMx
[2012.08.23 22:43:10 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Support Center
[2012.08.23 22:43:10 | 000,000,000 | ---D | C] -- C:\ProgramData\PC-Doctor for Windows
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.16 23:05:07 | 000,001,128 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000Core.job
[2012.09.16 23:02:07 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\gabriele\Desktop\OTL(1).exe
[2012.09.16 23:00:20 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.16 23:00:20 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.16 23:00:15 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.09.16 22:58:07 | 001,612,484 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.09.16 22:58:07 | 000,696,870 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.09.16 22:58:07 | 000,652,148 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.09.16 22:58:07 | 000,148,134 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.09.16 22:58:07 | 000,121,080 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.09.16 22:56:00 | 000,001,114 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.09.16 22:55:11 | 000,001,150 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000UA.job
[2012.09.16 22:54:48 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.16 22:54:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.15 19:43:05 | 000,193,079 | ---- | M] () -- C:\Users\gabriele\Desktop\Effiziente Beleuchtung.pdf
[2012.09.15 19:38:16 | 005,472,273 | ---- | M] () -- C:\Users\gabriele\Desktop\Behaglichkeit.pdf
[2012.09.15 19:06:51 | 3137,994,752 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.14 19:34:39 | 000,512,399 | ---- | M] () -- C:\Users\gabriele\Desktop\adwcleaner.exe
[2012.09.12 18:33:11 | 002,322,184 | ---- | M] (ESET) -- C:\Users\gabriele\Desktop\esetsmartinstaller_enu.exe
[2012.09.12 16:44:55 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.10 10:37:25 | 000,000,000 | ---- | M] () -- C:\Users\gabriele\defogger_reenable
[2012.09.07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.08.26 23:08:51 | 003,089,016 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
 
========== Files Created - No Company Name ==========
 
[2012.09.15 19:42:37 | 000,193,079 | ---- | C] () -- C:\Users\gabriele\Desktop\Effiziente Beleuchtung.pdf
[2012.09.15 19:38:17 | 005,472,273 | ---- | C] () -- C:\Users\gabriele\Desktop\Behaglichkeit.pdf
[2012.09.14 19:26:54 | 000,512,399 | ---- | C] () -- C:\Users\gabriele\Desktop\adwcleaner.exe
[2012.09.12 16:44:55 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.10 10:37:25 | 000,000,000 | ---- | C] () -- C:\Users\gabriele\defogger_reenable
[2012.08.13 23:05:47 | 004,503,728 | ---- | C] () -- C:\ProgramData\23lldnur.pad
[2012.04.09 16:25:57 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2012.04.06 18:52:09 | 000,000,102 | ---- | C] () -- C:\Windows\Dialux.ini
[2012.04.02 18:59:53 | 000,008,192 | ---- | C] () -- C:\Users\gabriele\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.11.09 03:51:17 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.11.09 03:51:15 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.11.09 03:51:14 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2011.11.09 03:51:13 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.11.09 03:51:11 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011.11.09 02:45:48 | 000,017,776 | ---- | C] () -- C:\Windows\EvtMessage.dll
[2011.02.11 12:22:50 | 001,590,378 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
 
========== LOP Check ==========
 
[2012.09.15 19:08:23 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Dropbox
[2012.05.01 17:51:21 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\DVDVideoSoft
[2012.03.30 16:53:34 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Fingertapps
[2012.08.23 22:53:51 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Graphisoft
[2012.03.30 18:24:32 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Install.GS
[2012.03.30 16:53:04 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Leadertech
[2012.09.02 23:13:17 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Nokia
[2012.09.02 23:13:17 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Nokia Suite
[2012.03.30 21:35:03 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\OpenOffice.org
[2012.03.30 19:51:05 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\PC Suite
[2012.04.02 12:03:45 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\PCDr
[2012.06.15 22:31:09 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\PDF Writer
[2012.03.30 19:35:04 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\SoftGrid Client
[2012.03.30 17:55:56 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Thunderbird
[2012.03.30 17:42:10 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\TP
[2012.03.30 17:56:22 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\ZinioReader4
[2012.09.16 23:05:07 | 000,001,128 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000Core.job
[2012.09.16 22:55:11 | 000,001,150 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000UA.job
[2012.07.27 00:50:00 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2009.07.14 07:08:49 | 000,027,342 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.05.30 08:51:24 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Adobe
[2012.08.10 07:37:39 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Apple Computer
[2012.03.30 19:10:39 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Avira
[2012.03.30 16:53:07 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Creative
[2012.04.01 18:40:44 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Dell
[2012.03.30 16:53:14 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Dell Touch Zone
[2012.09.15 19:08:23 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Dropbox
[2012.05.20 00:30:38 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\dvdcss
[2012.05.01 17:51:21 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\DVDVideoSoft
[2012.03.30 16:53:34 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Fingertapps
[2012.08.23 22:53:51 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Graphisoft
[2012.03.30 16:52:28 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Identities
[2012.03.30 18:24:32 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Install.GS
[2012.03.30 16:47:49 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Intel
[2012.03.30 16:53:04 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Leadertech
[2011.11.09 03:24:10 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Macromedia
[2012.04.01 18:17:31 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Macrovision
[2012.09.12 16:45:04 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Malwarebytes
[2010.11.21 09:00:23 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Media Center Programs
[2012.09.11 10:45:46 | 000,000,000 | --SD | M] -- C:\Users\gabriele\AppData\Roaming\Microsoft
[2012.03.30 17:47:51 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Mozilla
[2012.03.30 17:24:47 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Nero
[2012.09.02 23:13:17 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Nokia
[2012.09.02 23:13:17 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Nokia Suite
[2012.03.30 21:35:03 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\OpenOffice.org
[2012.03.30 19:51:05 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\PC Suite
[2012.04.02 12:03:45 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\PCDr
[2012.06.15 22:31:09 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\PDF Writer
[2012.03.30 21:26:54 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Reallusion
[2012.03.30 16:53:06 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Roxio
[2012.04.01 18:16:22 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Roxio Burn
[2012.07.08 16:13:18 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Skype
[2012.04.09 16:25:56 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\skypePM
[2012.03.30 19:35:04 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\SoftGrid Client
[2012.03.30 17:55:56 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\Thunderbird
[2012.03.30 17:42:10 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\TP
[2012.09.03 01:35:09 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\vlc
[2012.04.02 13:19:09 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\WinRAR
[2012.03.30 17:56:22 | 000,000,000 | ---D | M] -- C:\Users\gabriele\AppData\Roaming\ZinioReader4
 
< %APPDATA%\*.exe /s >
[2012.07.03 03:21:38 | 026,868,192 | ---- | M] (Dropbox, Inc.) -- C:\Users\gabriele\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2012.07.03 03:21:40 | 000,874,424 | ---- | M] (Dropbox, Inc.) -- C:\Users\gabriele\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe
[2012.07.03 03:21:46 | 000,181,784 | ---- | M] (Dropbox, Inc.) -- C:\Users\gabriele\AppData\Roaming\Dropbox\bin\Uninstall.exe
[2012.08.23 22:41:45 | 040,757,736 | ---- | M] (Dell Inc) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Binaries\full_dsc_6032_47_64_01.exe
[2012.09.12 17:06:03 | 010,374,600 | ---- | M] (Dell Inc) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Binaries\patch_dsc_603247to603255_64_02.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\04330686-d410-4f35-957b-e7ce10aae678\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\127b4a19-cfa9-44df-817a-ba9d2e118e9a\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\1af61f1d-6e2d-455a-8104-0e299f679267\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\1c785c37-39b2-4ddd-a607-dd329c03f3c7\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\1cdf35be-935c-40ee-87c9-e2e5eb4ed7aa\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\204fb7d7-aa37-43c4-a6b7-fcc6ada660db\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\20dbedb9-79a9-46eb-a173-72d6b673fa5f\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\223d17b7-a2c1-448f-a8df-4b2bbcfcf125\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\22a4170f-eee9-4893-8589-5e138b3eaf64\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\2467cf84-68f7-4490-9b31-7595e4f4611c\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\2a3d5e90-d8fe-48c2-8d20-350fc9da155e\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\4042f4a2-3c12-4209-97fa-c0eb5201142d\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\4c6e7196-a645-47ad-bbfe-0b6f13fe583f\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\4ce2fee8-9b52-4e31-af54-30091733feea\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\4d466a7c-1a4b-4301-ab8d-b07ff3be7040\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\6fa0b805-cd4e-4a33-bf06-d80bc7d5b866\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\77c8cf92-4aac-4572-938b-83f398b7bea7\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\99370b31-d565-447a-941a-414292e68f64\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\a557254e-b3cd-45d3-919a-710dc44af47c\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\c9f73c80-3486-418f-80ac-66b2a94038b9\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\d2ff75f2-0876-48df-a6f4-4657c8b33226\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\d5e5f122-ef21-49e8-ba88-c395dd33056b\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\d6b0c813-0176-443e-8a30-27c8fb735f55\appupdaterrules_dell\AddCertificate.exe
[2012.07.05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\gabriele\AppData\Roaming\PCDr\Update\Rules\d8938645-1e02-4646-bac7-8f5cb1c8e5f6\appupdaterrules_dell\AddCertificate.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\Drivers\Chipset_IRST\f6flpy-x64\iaStor.sys
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\Windows\SysNative\drivers\iaStor.sys
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_a36325196df56f7d\iaStor.sys
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\Windows\SysNative\DriverStore\FileRepository\iastor.inf_amd64_neutral_e3082ac13af8d3bf\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.11.09 04:10:36 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.11.09 04:10:36 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.11.09 04:10:36 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.11.09 04:10:36 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.11.09 04:10:36 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.11.09 04:10:36 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.11.09 04:10:36 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.11.09 04:10:36 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

--- --- ---


..hab auch noch ne Extra.txt Datei. Brauchst du auch diesen Inhalt ?

cosinus 17.09.2012 11:44

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
FF - user.js - File not found
FF - prefs.js..network.proxy.type: 4
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O32 - HKLM CDRom: AutoRun - 1
:Files
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

gabi.flabi 17.09.2012 13:27

Code:

All processes killed
========== OTL ==========
Prefs.js: 4 removed from network.proxy.type
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
========== FILES ==========
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\gabriele\Desktop\cmd.bat deleted successfully.
C:\Users\gabriele\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: gabriele
->Temp folder emptied: 923955043 bytes
->Temporary Internet Files folder emptied: 37817021 bytes
->Java cache emptied: 937 bytes
->FireFox cache emptied: 1109110934 bytes
->Flash cache emptied: 13649 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 550254803 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes
RecycleBin emptied: 193079 bytes
 
Total Files Cleaned = 2.500,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.61.5 log created on 09172012_140105

Files\Folders moved on Reboot...
C:\Users\gabriele\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


cosinus 17.09.2012 14:51

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

gabi.flabi 17.09.2012 19:18

Hab den Log gezipped und in den Anhang getan.

cosinus 18.09.2012 14:29

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

gabi.flabi 18.09.2012 19:31

Combofix Logfile:
Code:

ComboFix 12-09-18.06 - gabriele 18.09.2012  20:21:39.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3990.2083 [GMT 2:00]
ausgeführt von:: c:\users\gabriele\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\23lldnur.pad
c:\programdata\PCDr\6032\AddOnDownloaded\06004c97-c212-44da-81de-706b46554efe.dll
c:\programdata\PCDr\6032\AddOnDownloaded\07439fd5-7039-4014-b635-5bf088a1465b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\0d461521-7dbf-4cec-a29e-936c88cdf8c9.dll
c:\programdata\PCDr\6032\AddOnDownloaded\0d85b53c-d766-4bf0-8940-17b534910268.dll
c:\programdata\PCDr\6032\AddOnDownloaded\100c3865-0c76-461b-b2fd-042d6d5fa7f6.dll
c:\programdata\PCDr\6032\AddOnDownloaded\140239b3-d59a-46fa-b856-17682a46cb44.dll
c:\programdata\PCDr\6032\AddOnDownloaded\16837627-a839-41c5-a88f-3a0335128383.dll
c:\programdata\PCDr\6032\AddOnDownloaded\16ab6978-b6b5-41fa-81a1-8bffc55a69b9.dll
c:\programdata\PCDr\6032\AddOnDownloaded\173c4dd2-e93c-4725-b006-db1d8f465192.dll
c:\programdata\PCDr\6032\AddOnDownloaded\1e0aaf9a-9947-4a7b-b1ae-8a89919438ed.dll
c:\programdata\PCDr\6032\AddOnDownloaded\263d6ac9-4f87-466c-947c-bd9af71d7035.dll
c:\programdata\PCDr\6032\AddOnDownloaded\2ee79d71-badc-46b4-b731-42b15f3cd1c3.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3410f47b-5e8c-47c6-bf2c-234af4121d4c.dll
c:\programdata\PCDr\6032\AddOnDownloaded\378deb7f-049e-4a5e-83b2-5381dcd9e928.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3972fea3-214c-4935-a7d1-96bf66115683.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3a79f062-8f3e-464f-9815-2c45840494ee.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3b1c7acd-5e3e-4459-ab98-5109117e2341.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3e4c86d5-a5c1-4c3f-8fc7-6258992b16c5.dll
c:\programdata\PCDr\6032\AddOnDownloaded\44ddba62-3b58-480f-a775-ae7e9dd9d5df.dll
c:\programdata\PCDr\6032\AddOnDownloaded\4546f2bc-b9d9-4667-abe7-b0bacc90279e.dll
c:\programdata\PCDr\6032\AddOnDownloaded\4804ced5-915b-48a3-a465-b8a5e02714bf.dll
c:\programdata\PCDr\6032\AddOnDownloaded\4818e109-9489-4cd8-9044-44defd8ec187.dll
c:\programdata\PCDr\6032\AddOnDownloaded\493f295d-1a46-46f6-926c-63b474cedab4.dll
c:\programdata\PCDr\6032\AddOnDownloaded\5e1c102f-bfde-420c-87c0-64fe851888e5.dll
c:\programdata\PCDr\6032\AddOnDownloaded\62d1f0b0-bc9a-4f6c-bad7-93b19a91276a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\67c3d4fe-b638-467a-9fe2-c5813ade3330.dll
c:\programdata\PCDr\6032\AddOnDownloaded\6820b110-e483-4f1e-9b48-438f7916f078.dll
c:\programdata\PCDr\6032\AddOnDownloaded\684a43a7-04d5-4797-bc20-4db8a316286c.dll
c:\programdata\PCDr\6032\AddOnDownloaded\6928cebe-dc61-4564-a488-e19724a8de68.dll
c:\programdata\PCDr\6032\AddOnDownloaded\6b5978fa-48d7-4309-a523-7e157768c0d8.dll
c:\programdata\PCDr\6032\AddOnDownloaded\6f4fb483-ce30-493a-8cb4-3e530ab1be5b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\7014e871-cc3b-4dec-b82b-bc70222b40ed.dll
c:\programdata\PCDr\6032\AddOnDownloaded\739db3eb-d3cd-4c86-a6ea-01a49984fa3b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\7bd83798-7a02-4f50-83a2-b91cabcbd1f9.dll
c:\programdata\PCDr\6032\AddOnDownloaded\7dbfef1a-6148-4748-a1b3-71627763a45a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\813755dc-2229-47a2-b85b-19d0aaa641c9.dll
c:\programdata\PCDr\6032\AddOnDownloaded\872965c7-08b7-47fc-a74c-ff167590b71a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\8a6735b1-c078-4648-9416-b6bb29ec3dc1.dll
c:\programdata\PCDr\6032\AddOnDownloaded\8d357f17-07ad-4392-ba06-fb67564c98cd.dll
c:\programdata\PCDr\6032\AddOnDownloaded\934f6059-2d35-4bd9-a130-a17cb5563507.dll
c:\programdata\PCDr\6032\AddOnDownloaded\9ad10df8-6662-488d-9a0f-1fab1ee3403d.dll
c:\programdata\PCDr\6032\AddOnDownloaded\9f8591c3-5048-42f7-9553-387b30449f54.dll
c:\programdata\PCDr\6032\AddOnDownloaded\a4930af9-016c-4915-a740-a3364e7618aa.dll
c:\programdata\PCDr\6032\AddOnDownloaded\a61f44a8-21a3-4c4a-a04b-993dfb73bf96.dll
c:\programdata\PCDr\6032\AddOnDownloaded\a9de0c84-9a7c-4638-9653-13aa8cf56e80.dll
c:\programdata\PCDr\6032\AddOnDownloaded\ac96894a-064b-4c44-a457-9d5aaee7032a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\adb45b82-004f-4eed-bd54-d60d7eda1ff5.dll
c:\programdata\PCDr\6032\AddOnDownloaded\ae67b364-b69e-471e-b177-2459120b84d4.dll
c:\programdata\PCDr\6032\AddOnDownloaded\b2152f30-7380-4987-8fcf-e4c06952615d.dll
c:\programdata\PCDr\6032\AddOnDownloaded\b2ed8d53-41ce-48e6-b4ac-8b8e5e1a4fdf.dll
c:\programdata\PCDr\6032\AddOnDownloaded\b4cc2a4a-87f5-49cd-935c-18f1a80e65b7.dll
c:\programdata\PCDr\6032\AddOnDownloaded\b9ce760f-6209-48f2-a4a3-695324591c45.dll
c:\programdata\PCDr\6032\AddOnDownloaded\bbfa36b0-30b0-4e36-8d8c-69df1d87626b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\bc6fc708-5b6b-4a72-b336-09b3089baa7a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\bf647bd7-dfb5-4746-a6b4-b7c2fdbbf3b1.dll
c:\programdata\PCDr\6032\AddOnDownloaded\c2690c4c-81f4-4565-a861-643c7af1fa90.dll
c:\programdata\PCDr\6032\AddOnDownloaded\c4211805-b43b-471d-81af-4e0589f8607b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\cdda52ec-6ccd-425a-8c72-b7bbdc8b3acd.dll
c:\programdata\PCDr\6032\AddOnDownloaded\d1f4dc82-bc4c-4916-b37c-3ab9c30ae468.dll
c:\programdata\PCDr\6032\AddOnDownloaded\d34c0cf7-889f-43dd-9283-b2b6f442aae3.dll
c:\programdata\PCDr\6032\AddOnDownloaded\daf30858-49d8-434b-b4b1-068b5dc9267c.dll
c:\programdata\PCDr\6032\AddOnDownloaded\ddb9fe5d-525c-4d5d-ac37-0bd10f2864f8.dll
c:\programdata\PCDr\6032\AddOnDownloaded\e45cd45a-4d7c-4802-881f-74582b847e5c.dll
c:\programdata\PCDr\6032\AddOnDownloaded\e86f11dd-8b83-43cc-899e-f935ce0a1ea0.dll
c:\programdata\PCDr\6032\AddOnDownloaded\e9bb45d9-5a2b-47e8-9c48-168276d422cc.dll
c:\programdata\PCDr\6032\AddOnDownloaded\ef78c3e8-1d94-4219-8070-7617e119bba4.dll
c:\programdata\PCDr\6032\AddOnDownloaded\f06c5597-1a85-4d1f-ac16-a6fdd2a6bedc.dll
c:\programdata\PCDr\6032\AddOnDownloaded\f80d4ad1-1fad-43b5-b6f3-347848b5ddd5.dll
c:\programdata\PCDr\6032\AddOnDownloaded\f9dc840b-c6f7-42a5-acec-50cc7a2827fd.dll
c:\programdata\Roaming
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-08-18 bis 2012-09-18  ))))))))))))))))))))))))))))))
.
.
2012-09-18 18:26 . 2012-09-18 18:26        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-09-18 17:20 . 2012-09-18 17:20        69000        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{FEF2AC9E-79AC-4156-96C3-C595C8BBA1A0}\offreg.dll
2012-09-17 17:31 . 2012-09-17 17:31        --------        d-----w-        c:\program files (x86)\7-Zip
2012-09-17 12:01 . 2012-09-17 12:01        --------        d-----w-        C:\_OTL
2012-09-15 17:06 . 2012-08-23 08:26        9310152        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{FEF2AC9E-79AC-4156-96C3-C595C8BBA1A0}\mpengine.dll
2012-09-12 21:50 . 2012-09-12 21:50        73696        ----a-w-        c:\program files (x86)\Mozilla Firefox\breakpadinjector.dll
2012-09-12 16:34 . 2012-09-12 16:34        --------        d-----w-        c:\program files (x86)\ESET
2012-09-12 14:45 . 2012-09-12 14:45        --------        d-----w-        c:\users\gabriele\AppData\Roaming\Malwarebytes
2012-09-12 14:44 . 2012-09-12 14:44        --------        d-----w-        c:\programdata\Malwarebytes
2012-09-12 14:44 . 2012-09-12 14:44        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-09-12 14:44 . 2012-09-07 15:04        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-09-12 14:32 . 2012-08-22 18:12        950128        ----a-w-        c:\windows\system32\drivers\ndis.sys
2012-09-12 14:32 . 2012-07-04 20:26        41472        ----a-w-        c:\windows\system32\drivers\RNDISMP.sys
2012-09-12 14:32 . 2012-08-22 18:12        1913200        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-09-12 14:32 . 2012-08-22 18:12        376688        ----a-w-        c:\windows\system32\drivers\netio.sys
2012-09-12 14:32 . 2012-08-22 18:12        288624        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 14:32 . 2012-08-02 17:58        574464        ----a-w-        c:\windows\system32\d3d10level9.dll
2012-09-12 14:32 . 2012-08-02 16:57        490496        ----a-w-        c:\windows\SysWow64\d3d10level9.dll
2012-08-23 22:31 . 2012-07-06 20:07        552960        ----a-w-        c:\windows\system32\drivers\bthport.sys
2012-08-23 20:43 . 2012-08-23 20:43        --------        d-----w-        c:\programdata\PC-Doctor for Windows
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-13 10:01 . 2012-04-01 16:30        64462936        ----a-w-        c:\windows\system32\MRT.exe
2012-08-28 18:24 . 2012-08-10 05:23        477168        ----a-w-        c:\windows\SysWow64\npdeployJava1.dll
2012-08-28 18:24 . 2011-11-09 00:42        473072        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2012-08-14 23:31 . 2012-03-30 23:11        426184        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-14 23:31 . 2011-11-09 00:26        70344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        94208        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        94208        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        94208        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-13 138096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2012-07-27 35768]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942]
"Dell Registration"="c:\program files (x86)\System Registration\prodreg.exe" [2011-08-04 4165440]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"NeroLauncher"="c:\program files (x86)\Nero\SyncUP\NeroLauncher.exe" [2012-02-06 66872]
"AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-04-30 885760]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
.
c:\users\gabriele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\gabriele\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-7-3 26868192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-05-19 995392]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 116648]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-07 676936]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-14 250056]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protokoll;c:\windows\system32\DRIVERS\amppal.sys [2011-08-08 299008]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-05-19 1335360]
R3 DialComService;DIAL Communication Service;c:\program files (x86)\DIAL GmbH\DIAL Communication Framework\DialComService.exe [2011-10-17 1673520]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 116648]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-02-27 158976]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-05-17 34200]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-07 25928]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-12 114144]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-28 340240]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-12-01 250984]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 vnet;Shrew Soft Virtual Adapter;c:\windows\system32\DRIVERS\virtualnet.sys [2010-09-02 17408]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-09-16 27760]
S1 vflt;Shrew Soft Lightweight Filter;c:\windows\system32\DRIVERS\vfilter.sys [2010-09-02 21504]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-08-08 1166848]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-14 86224]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-05-19 921664]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928]
S2 dtpd;ShrewSoft DNS Proxy Daemon;c:\program files\ShrewSoft\VPN Client\dtpd.exe [2010-10-08 56592]
S2 iked;ShrewSoft IKE Daemon;c:\program files\ShrewSoft\VPN Client\iked.exe [2010-10-08 957712]
S2 ipsecd;ShrewSoft IPSEC Daemon;c:\program files\ShrewSoft\VPN Client\ipsecd.exe [2010-10-08 697616]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-07 399432]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400]
S2 Scia Licence Server;Scia Licence Server;c:\program files (x86)\Common Files\SCIA\Protection\lmgrd.exe [2011-05-26 1408848]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-08-18 1692480]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed - Virtueller Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-08-08 299008]
S3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys [2011-05-19 51712]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2011-05-19 53248]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-07-19 282624]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-01-20 176096]
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-07-20 59904]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-16 317440]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-05-17 25496]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-08-04 8604672]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-02-10 82432]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-02-10 181760]
S3 PCDSRVC{1E208CE0-FB7451FF-06020200}_0;PCDSRVC{1E208CE0-FB7451FF-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2012-08-17 25584]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-11-30 412264]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - PCDSRVC{1E208CE0-FB7451FF-06020200}_0
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 23:31]
.
2012-09-18 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000Core.job
- c:\users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-30 18:18]
.
2012-09-18 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000UA.job
- c:\users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-30 18:18]
.
2012-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 18:24]
.
2012-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 18:24]
.
2012-07-26 c:\windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job
- c:\program files\Dell Support Center\uaclauncher.exe [2012-08-23 05:36]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        97792        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        97792        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        97792        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        97792        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-04-14 6629480]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-05 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-05 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-05 416024]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-04-12 609144]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-07-28 1935120]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-05-19 10365952]
"QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2011-03-11 4500640]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"Stage Remote"="c:\program files (x86)\Dell\Stage Remote\StageRemote.exe" [2011-06-28 2022976]
"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-04-30 2055016]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{2541EF2C-0496-4F0B-9962-BD4206C8C433}: NameServer = 193.175.112.3,195.37.168.3
FF - ProfilePath - c:\users\gabriele\AppData\Roaming\Mozilla\Firefox\Profiles\bdxvsrnh.default\
.
.
------- Dateityp-Verknüpfung -------
.
.txt=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-ESET Online Scanner - c:\program files (x86)\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020200}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-09-18  20:29:05
ComboFix-quarantined-files.txt  2012-09-18 18:29
.
Vor Suchlauf: 12 Verzeichnis(se), 422.012.559.360 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 421.861.691.392 Bytes frei
.
- - End Of File - - 5C0ECB1A75CD81B26D8FD3313E243E09

--- --- ---

cosinus 19.09.2012 15:00

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

gabi.flabi 20.09.2012 16:54

GMER
GMER Logfile:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-09-20 17:06:04
Windows 6.1.7601 Service Pack 1
Running: 4qx7ui69.exe


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4c80930c6ce5                     
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4c80930c6ce5@9c4a7bf9e3ad        0x9E 0x67 0x88 0xDF ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4c80930c6ce5 (not active ControlSet) 
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4c80930c6ce5@9c4a7bf9e3ad            0x9E 0x67 0x88 0xDF ...

---- EOF - GMER 1.0.15 ----

--- --- ---


OSAM
OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 18:07:41 on 20.09.2012

OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 64-bit
Default Browser: Mozilla Corporation Firefox 15.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000Core.job" - "Facebook Inc." - C:\Users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe
"FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000UA.job" - "Facebook Inc." - C:\Users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"adfs" (adfs) - "Adobe Systems, Inc." - C:\Windows\system32\drivers\adfs.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"PCDSRVC{1E208CE0-FB7451FF-06020200}_0 - PCDR Kernel Mode Service Helper Driver" (PCDSRVC{1E208CE0-FB7451FF-06020200}_0) - "PC-Doctor, Inc." - c:\program files\dell support center\pcdsrvc_x64.pkms
"WimFltr" (WimFltr) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\wimfltr.sys

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{8352FA4C-39C6-11D3-ADBA-00A0244FB1A2} "DIALux 2.0 ArchivProtocol Class" - "DIAL GmbH, Germany" - C:\Program Files (x86)\DIALux\DLXToolBox.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
{314111c7-a502-11d2-bbca-00c04f8ec294} "ms-help" - ? -  (File not found | COM-object registry key not found)
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files (x86)\7-Zip\7-zip.dll
{3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D} "Arbeitsbereiche" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{7CCA70DB-DE7A-4FB7-9B2B-52E2335A3B5A} "Enterprise-Projekte" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\NAMEEXT.DLL
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{0006F045-0000-0000-C000-000000000046} "Microsoft Outlook Custom Icon Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\OLKFSTUB.DLL
DIALux Doc ShellExtension "{7889C2D5-D128-43e2-A8D8-A7590A12C8B3}" - ? -  (File not found | COM-object registry key not found)
DIALux LumFile ShellExtension "{7EFFF3DD-71B3-11D4-A25E-005056DCFB89}" - ? -  (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_35" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} "Java Plug-in 1.6.0_35" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_35" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\npjpi160_35.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{69AB812A-8CE4-4BF3-B49B-3B60A9F31FB2} "DIALux 3.1 ULDBrowserHelper Class" - "DIAL GmbH, Germany" - C:\Program Files (x86)\DIALux\DLXShellExtension.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
{B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Dropbox.lnk" - "Dropbox, Inc." - C:\Users\gabriele\AppData\Roaming\Dropbox\bin\Dropbox.exe  (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Facebook Update" - "Facebook Inc." - "C:\Users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"AccuWeatherWidget" - ? - "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"Dell Registration" - "Dell, Inc." - C:\Program Files (x86)\System Registration\prodreg.exe /boot
"Dell Webcam Central" - "Creative Technology Ltd" - "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
"Desktop Disc Tool" - ? - "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
"NeroLauncher" - ? - C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe 900  (File found, but it contains no detailed information)
"QuickTime Task" - "Apple Inc." - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
"RoxWatchTray" - "Sonic Solutions" - "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Bullzip PDF Print Monitor" - "Bullzip" - C:\Windows\system32\bzpdf.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll  (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe"  (File not found)
"@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200" (NAUpdate) - "Nero AG" - C:\Program Files (x86)\Nero\Update\NASvc.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
"ASP.NET State Service" (aspnet_state) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
"Bluetooth Device Monitor" (Bluetooth Device Monitor) - "Intel Corporation" - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
"Bluetooth Media Service" (Bluetooth Media Service) - "Intel Corporation" - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
"Bluetooth OBEX Service" (Bluetooth OBEX Service) - "Intel Corporation" - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
"DIAL Communication Service" (DialComService) - ? - C:\Program Files (x86)\DIAL GmbH\DIAL Communication Framework\DialComService.exe
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Flexera Software, Inc." - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
"Google Update-Dienst (gupdate)" (gupdate) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service" (BTHSSecurityMgr) - "Intel(R) Corporation" - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
"Intel(R) Management and Security Application Local Management Service" (LMS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
"Intel(R) Management and Security Application User Notification Service" (UNS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
"Intel(R) PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
"Intel(R) PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
"Intel(R) Turbo Boost Technology Monitor 2.0" (TurboBoost) - "Intel(R) Corporation" - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
"Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service" (AMPPALR3) - "Intel Corporation" - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
"MBAMScheduler" (MBAMScheduler) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft SharePoint Workspace Audit Service" (Microsoft SharePoint Workspace Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
"Office 64 Source Engine" (ose64) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"Roxio Hard Drive Watcher 12" (RoxWatch12) - "Sonic Solutions" - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
"RoxMediaDB12OEM" (RoxMediaDB12OEM) - "Sonic Solutions" - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
"Scia Licence Server" (Scia Licence Server) - "Flexera Software, Inc." - C:\Program Files (x86)\Common Files\SCIA\Protection\lmgrd.exe
"ShrewSoft DNS Proxy Daemon" (dtpd) - ? - C:\Program Files\ShrewSoft\VPN Client\dtpd.exe  (File found, but it contains no detailed information)
"ShrewSoft IKE Daemon" (iked) - ? - C:\Program Files\ShrewSoft\VPN Client\iked.exe  (File found, but it contains no detailed information)
"ShrewSoft IPSEC Daemon" (ipsecd) - ? - C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe  (File found, but it contains no detailed information)
"Skype C2C Service" (Skype C2C Service) - "Skype Technologies S.A." - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files (x86)\Skype\Updater\Updater.exe
"SoftThinks Agent Service" (SftService) - "SoftThinks SAS" - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
"stllssvr" (stllssvr) - "MicroVision Development, Inc." - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
"Wireless PAN DHCP Server" (MyWiFiDHCPDNS) - ? - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
[/code]

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-20 18:56:12
-----------------------------
18:56:12.722    OS Version: Windows x64 6.1.7601 Service Pack 1
18:56:12.722    Number of processors: 4 586 0x2A07
18:56:12.722    ComputerName: DELLICIOUS  UserName: gabriele
18:56:15.352    Initialize success
18:56:23.182    AVAST engine defs: 12092000
18:56:29.662    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:56:29.672    Disk 0 Vendor: ST950032 D005 Size: 476940MB BusType: 3
18:56:29.702    Disk 0 MBR read successfully
18:56:29.702    Disk 0 MBR scan
18:56:29.712    Disk 0 Windows VISTA default MBR code
18:56:29.722    Disk 0 Partition 1 00    DE Dell Utility Dell 8.0      101 MB offset 63
18:56:29.742    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        20000 MB offset 212992
18:56:29.772    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      456835 MB offset 41172992
18:56:29.812    Disk 0 scanning C:\Windows\system32\drivers
18:56:48.472    Service scanning
18:57:28.812    Modules scanning
18:57:28.822    Disk 0 trace - called modules:
18:57:28.852    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
18:57:28.862    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80065b1060]
18:57:28.872    3 CLASSPNP.SYS[fffff88000cc143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8005356050]
18:57:28.892    Scan finished successfully
18:57:41.141    Disk 0 MBR has been saved successfully to "C:\Users\gabriele\Desktop\Neuer Ordner\MBR.dat"
18:57:41.141    The log file has been saved successfully to "C:\Users\gabriele\Desktop\Neuer Ordner\aswMBR.txt"

hab mal eine frage..muss ich noch viele scans machen ? :)

cosinus 20.09.2012 20:20

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

gabi.flabi 23.09.2012 22:46

Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.23.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
gabriele :: DELLICIOUS [Administrator]

Schutz: Deaktiviert

23.09.2012 22:16:54
mbam-log-2012-09-23 (22-16-54).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 335424
Laufzeit: 1 Stunde(n), 16 Minute(n),

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/24/2012 at 09:55 AM

Application Version : 5.5.1016

Core Rules Database Version : 9197
Trace Rules Database Version: 7009

Scan type      : Complete Scan
Total Scan Time : 01:55:47

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 653
Memory threats detected  : 0
Registry items scanned    : 68685
Registry threats detected : 0
File items scanned        : 142546
File threats detected    : 383

Adware.Tracking Cookie
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\PHB1CE34.txt [ /media6degrees.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\8KUDFLTB.txt [ /serving-sys.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\Q6SIGC1Q.txt [ /ad1.adfarm1.adition.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\E0Q6ELOW.txt [ /invitemedia.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\RWUUKCKX.txt [ /ad.zanox.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\L7T2W09S.txt [ /imrworldwide.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\E2KH3VCA.txt [ /tracking.quisma.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\N2Q4M2DR.txt [ /apmebf.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\G505DBC0.txt [ /fastclick.net ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\WECVINYQ.txt [ /lucidmedia.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\MJABQUIB.txt [ /c.atdmt.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\F7HEJTIQ.txt [ /mediaplex.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\UKTZCDXV.txt [ /zanox.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\A52YNKJ0.txt [ /track.adform.net ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\9GT86HKS.txt [ /2o7.net ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\141QOIB4.txt [ /adfarm1.adition.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\CCWITI3L.txt [ /adform.net ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\73VWJVQ3.txt [ /doubleclick.net ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\B53N0SIG.txt [ /smartadserver.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\E5BPPIJN.txt [ /atdmt.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\ZZ13WNI5.txt [ /dyntracker.com ]
        C:\USERS\GABRIELE\AppData\Roaming\Microsoft\Windows\Cookies\Low\T2UY4KAD.txt [ Cookie:gabriele@serving-sys.com/ ]
        C:\USERS\GABRIELE\AppData\Roaming\Microsoft\Windows\Cookies\Low\G6MXUMQX.txt [ Cookie:gabriele@statse.webtrendslive.com/ ]
        C:\USERS\GABRIELE\AppData\Roaming\Microsoft\Windows\Cookies\Low\JCR4YC1Q.txt [ Cookie:gabriele@bs.serving-sys.com/ ]
        C:\USERS\GABRIELE\Cookies\PHB1CE34.txt [ Cookie:gabriele@media6degrees.com/ ]
        C:\USERS\GABRIELE\Cookies\8KUDFLTB.txt [ Cookie:gabriele@serving-sys.com/ ]
        C:\USERS\GABRIELE\Cookies\Q6SIGC1Q.txt [ Cookie:gabriele@ad1.adfarm1.adition.com/ ]
        C:\USERS\GABRIELE\Cookies\RWUUKCKX.txt [ Cookie:gabriele@ad.zanox.com/ ]
        C:\USERS\GABRIELE\Cookies\L7T2W09S.txt [ Cookie:gabriele@imrworldwide.com/cgi-bin ]
        C:\USERS\GABRIELE\Cookies\E2KH3VCA.txt [ Cookie:gabriele@tracking.quisma.com/ ]
        C:\USERS\GABRIELE\Cookies\N2Q4M2DR.txt [ Cookie:gabriele@apmebf.com/ ]
        C:\USERS\GABRIELE\Cookies\G505DBC0.txt [ Cookie:gabriele@fastclick.net/ ]
        C:\USERS\GABRIELE\Cookies\WECVINYQ.txt [ Cookie:gabriele@lucidmedia.com/ ]
        C:\USERS\GABRIELE\Cookies\F7HEJTIQ.txt [ Cookie:gabriele@mediaplex.com/ ]
        C:\USERS\GABRIELE\Cookies\UKTZCDXV.txt [ Cookie:gabriele@zanox.com/ ]
        C:\USERS\GABRIELE\Cookies\A52YNKJ0.txt [ Cookie:gabriele@track.adform.net/ ]
        C:\USERS\GABRIELE\Cookies\CCWITI3L.txt [ Cookie:gabriele@adform.net/ ]
        C:\USERS\GABRIELE\Cookies\B53N0SIG.txt [ Cookie:gabriele@smartadserver.com/ ]
        C:\USERS\GABRIELE\Cookies\E5BPPIJN.txt [ Cookie:gabriele@atdmt.com/ ]
        C:\USERS\GABRIELE\Cookies\ZZ13WNI5.txt [ Cookie:gabriele@dyntracker.com/ ]
        .adbrite.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adserver.adreactor.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adinterax.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adinterax.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ikea.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .realmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .harrenmedianetwork.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .euros4click.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        tracking.dc-storm.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.unitymedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        edu-stats.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .secmedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .dealtime.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .mm.chitika.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        affiliate.mediatemple.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        optimize.indieclick.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        optimize.indieclick.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adserver.adtechus.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        track.zalando.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .loyaltypartner.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adx.kat.ph [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        securetrafficserver5.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        stats.vertriebsassistent.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        7.rotator.wigetmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .bwincom.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .gostats.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .traveladvertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .traveladvertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .hawaiianairlines.112.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ar.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .hotwire.db.advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .networldmedia.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .trafficmp.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        clicks.stylefruits.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.3gnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .burstnet.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .www.burstnet.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        7.rotator.wigetmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        rotator.hadj7.adjuggler.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.usenext.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        stat.dealtime.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .realmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        network.realmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .opodo.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www2.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www2.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revenuemax.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adt.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adt.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adt.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adt.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tto2.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .kontera.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .rambler.ru [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .rambler.ru [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adnetwork.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .content.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .content.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .xm.xtendmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-Falprod[i]
        C:\PROGRAM FILES (X86)\SCIA\ENGINEER2011.0\NESSIE.DLL


cosinus 24.09.2012 14:27

Code:

UAC On - Limited User
Wie hast du sasw gestartet? Einfach per Doppelklick?

gabi.flabi 25.09.2012 08:59

rechtsklick..als administrator ausführen

soll ichs wiederholen ?

cosinus 25.09.2012 12:55

Nein dann ist das ok, das Programm hat da einen Bug und zeigt das nicht immer richtig an

Code:

C:\PROGRAM FILES (X86)\SCIA\ENGINEER2011.0\NESSIE.DLL
Was machst du mit dieser Software, wie kommt die darauf?! :wtf:

gabi.flabi 26.09.2012 12:20

ich arbeite ab und an mal mit der software...für die uni...

cosinus 26.09.2012 15:40

Gut, Uni also...dann ist das geklärt! :daumenhoc

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?


Alle Zeitangaben in WEZ +1. Es ist jetzt 08:12 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131