Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   mystart.incredibar infiziert mit Google Chrome (https://www.trojaner-board.de/123936-mystart-incredibar-infiziert-google-chrome.html)

Astirala 11.09.2012 22:46

mystart.incredibar infiziert mit Google Chrome
 
Gute Abend zusammen,

ich habe mir heute im Internet Schriftarten angesehen und habe mir eine gezogen. Nur wie es scheint leider nicht nur diese, sondern dieses nervige mystart.incredibar leider gratis dazu.

Nun kriege ich das leider nicht mehr weg. Auf der Suche nach Hilfe bin ich hier bei euch gelandet und hoffe, dass ihr meine Rettung seid.

Ich habe schon einige Beiträge dazu hier gelesen und ein wenig tätig geworden.

Die empfohlenen Programme habe ich mir gezogen und so wie sie dort beschrieben wurden laufen lassen, um die Berichte zu kriegen. Ich poste sie direkt mal, damit ihr vielleicht direkt helfen könnt.

Solltet ihr sonst noch Infos brauchen, dann will ich euch die natürlich auch zukommen lassen :)

Adw Cleaner
Code:

# AdwCleaner v2.001 - Datei am 09/11/2012 um 23:23:42 erstellt
# Aktualisiert am 09/09/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium  (64 bits)
# Benutzer : Astirala - ASTIRALA-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Astirala\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421


-\\ Mozilla Firefox v13.0.1 (de)

Profilname : default
Datei : C:\Users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\prefs.js

[OK] Die Datei ist sauber.

-\\ Google Chrome v21.0.1180.89

Datei : C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [4476 octets] - [11/09/2012 22:53:09]
AdwCleaner[S1].txt - [4832 octets] - [11/09/2012 22:55:12]
AdwCleaner[S2].txt - [1100 octets] - [11/09/2012 23:17:52]
AdwCleaner[S3].txt - [1032 octets] - [11/09/2012 23:23:42]

########## EOF - C:\AdwCleaner[S3].txt - [1092 octets] ##########

OTL Datei
Code:

OTL logfile created on: 11.09.2012 23:26:33 - Run 2
OTL by OldTimer - Version 3.2.61.3    Folder = C:\Users\Astirala\Desktop
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,99 Gb Total Physical Memory | 2,72 Gb Available Physical Memory | 68,24% Memory free
7,98 Gb Paging File | 6,67 Gb Available in Paging File | 83,57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 906,61 Gb Total Space | 716,06 Gb Free Space | 78,98% Space Free | Partition Type: NTFS
Drive E: | 931,28 Gb Total Space | 680,36 Gb Free Space | 73,06% Space Free | Partition Type: FAT32
 
Computer Name: ASTIRALA-PC | User Name: Astirala | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Astirala\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\EXPERTool\TBPANEL.exe (Gainward Co.)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Windows\SysWOW64\XSrvSetup.exe ()
PRC - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
PRC - C:\Users\Astirala\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtGui4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtSql4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtScript4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtCore4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtDeclarative4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\EXPERTool\TBManage.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (AppleChargerSrv) -- C:\Windows\SysNative\AppleChargerSrv.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (AVP) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)
SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (JMB36X) -- C:\Windows\SysWOW64\XSrvSetup.exe ()
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (KLIF) -- C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (ssudmdm) -- C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (dg_ssudbus) -- C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (KLIM6) -- C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kl2) -- C:\Windows\SysNative\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KL1) -- C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (sscdbus) -- C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation)
DRV:64bit: - (AppleCharger) -- C:\Windows\SysNative\drivers\AppleCharger.sys ()
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (JRAID) -- C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (klmouflt) -- C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation)
DRV:64bit: - (LVUVC64) -- C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (UltraMonUtility) -- C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys (Realtime Soft Ltd)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.stegcomputer.ch [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.stegcomputer.ch [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 1D 89 A6 64 C9 4C CD 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.50524.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Astirala\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Astirala\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Astirala\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Astirala\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.06.16 15:27:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru [2012.09.03 14:19:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru [2012.09.03 14:19:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\KavAntiBanner@Kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru [2012.09.03 14:19:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.17 20:18:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2012.06.17 20:18:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Astirala\AppData\Roaming\mozilla\Extensions
[2012.09.11 22:55:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Astirala\AppData\Roaming\mozilla\Firefox\Profiles\amukf51a.default\extensions
[2012.06.17 20:18:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.06.15 00:19:07 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.15 00:46:57 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.15 00:46:56 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.15 00:46:57 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.15 00:46:57 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.15 00:46:57 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.15 00:46:56 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - homepage: hxxp://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Astirala\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Astirala\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Astirala\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Windows Live\\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Astirala\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50524.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Modul zur Link-Untersuchung = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\12.0.0.477_1\
CHR - Extension: Rummikub = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\inkiliggodjonlfmnpchdgikolcbopif\1.0.0.5_0\
CHR - Extension: Virtuelle Tastatur = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\12.0.0.477_1\
CHR - Extension: New tab for Chrome\u2122 = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\
CHR - Extension: Mehr Leistung und Videoformate f\\u00FCr dein HTML5 \\u003Cvideo\\u003E = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Google Mail = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Anti-Banner = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\12.0.0.374_0\
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKCU..\Run: [GAINWARD] C:\Program Files (x86)\EXPERTool\TBPanel.exe (Gainward Co.)
O4 - HKCU..\Run: [googletalk] C:\Users\Astirala\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKCU..\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm ()
O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm ()
O9:64bit: - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87D59B29-8F0F-4EFA-A9BC-49F877C81F5E}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.11 23:13:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.09.11 23:13:08 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.09.11 23:12:01 | 003,927,560 | ---- | C] (Piriform Ltd) -- C:\Users\Astirala\Desktop\ccsetup322.exe
[2012.09.11 22:54:31 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\Astirala\Desktop\OTL.exe
[2012.09.11 15:06:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Perion
[2012.09.11 14:46:14 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Local\Windows Live
[2012.09.11 12:12:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012.09.11 12:11:16 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2012.09.11 12:10:57 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2012.09.11 12:10:57 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2012.09.11 12:10:57 | 000,095,208 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2012.09.11 12:10:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2012.09.10 11:30:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metin2
[2012.09.10 11:29:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Metin2
[2012.09.10 00:11:50 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment
[2012.09.10 00:11:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment
[2012.09.10 00:04:47 | 000,000,000 | ---D | C] -- C:\Perfect World Entertainment
[2012.09.10 00:04:24 | 000,258,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unicows.dll
[2012.09.09 20:12:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PWI_DE_v165_Installer
[2012.09.09 20:11:53 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Local\PMB Files
[2012.09.09 20:11:49 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2012.09.09 20:11:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks
[2012.08.14 21:55:37 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012.08.14 21:55:37 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012.08.14 21:55:36 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012.08.14 21:55:36 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012.08.14 21:55:36 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012.08.14 21:55:35 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012.08.14 21:55:33 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012.08.14 21:55:33 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012.08.14 21:55:31 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012.08.14 21:55:31 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012.08.14 21:55:31 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012.08.14 21:55:30 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012.08.14 21:55:30 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012.08.14 19:08:41 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2012.08.14 19:08:38 | 000,751,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll
[2012.08.14 19:08:38 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll
[2012.08.14 19:08:38 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\splwow64.exe
[2012.08.14 19:08:35 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\browcli.dll
[2012.08.14 19:08:34 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netapi32.dll
[2012.08.14 19:08:34 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browcli.dll
[2012.08.14 19:08:29 | 000,956,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.11 23:29:04 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-382671035-3137015300-3879576489-1000UA.job
[2012.09.11 23:24:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.11 23:24:40 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\lvuvc.hs
[2012.09.11 23:24:35 | 3214,483,456 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.11 23:23:55 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.11 23:23:55 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.11 23:13:09 | 000,000,829 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.09.11 22:54:33 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Astirala\Desktop\OTL.exe
[2012.09.11 22:52:09 | 000,512,399 | ---- | M] () -- C:\Users\Astirala\Desktop\adwcleaner.exe
[2012.09.11 22:40:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.11 12:10:52 | 000,095,208 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2012.09.11 12:10:51 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2012.09.11 12:10:51 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2012.09.11 12:10:51 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2012.09.11 12:10:51 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2012.09.11 12:10:51 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2012.09.11 02:29:00 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-382671035-3137015300-3879576489-1000Core.job
[2012.09.10 11:30:48 | 000,000,986 | ---- | M] () -- C:\Users\Public\Desktop\Metin2.lnk
[2012.09.10 00:11:57 | 000,001,202 | ---- | M] () -- C:\Users\Astirala\Desktop\Perfect World International.lnk
[2012.09.09 21:16:20 | 000,258,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\unicows.dll
[2012.08.21 01:03:03 | 000,062,696 | ---- | M] () -- C:\Users\Astirala\Desktop\267700_142654595812927_4715403_n.jpg
[2012.08.15 02:40:27 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012.08.15 02:40:27 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012.08.14 23:40:11 | 000,090,401 | ---- | M] () -- C:\Users\Astirala\Desktop\189418_4382056914733_76348426_n.jpg
[2012.08.14 22:03:16 | 000,293,448 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
 
========== Files Created - No Company Name ==========
 
[2012.09.11 23:13:09 | 000,000,829 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.09.11 22:52:08 | 000,512,399 | ---- | C] () -- C:\Users\Astirala\Desktop\adwcleaner.exe
[2012.09.11 15:06:37 | 000,081,953 | ---- | C] () -- C:\Users\Astirala\Desktop\mutlu.zip
[2012.09.11 14:48:16 | 000,149,994 | ---- | C] () -- C:\Users\Astirala\Desktop\556863_321610694583982_204200287_n.jpg
[2012.09.10 11:30:48 | 000,000,986 | ---- | C] () -- C:\Users\Public\Desktop\Metin2.lnk
[2012.09.10 00:11:57 | 000,001,202 | ---- | C] () -- C:\Users\Astirala\Desktop\Perfect World International.lnk
[2012.08.21 01:03:13 | 000,062,696 | ---- | C] () -- C:\Users\Astirala\Desktop\267700_142654595812927_4715403_n.jpg
[2012.08.14 23:40:17 | 000,090,401 | ---- | C] () -- C:\Users\Astirala\Desktop\189418_4382056914733_76348426_n.jpg
[2012.06.16 15:30:14 | 000,017,408 | ---- | C] () -- C:\Users\Astirala\AppData\Local\WebpageIcons.db
[2012.05.15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011.08.11 04:06:32 | 000,007,764 | ---- | C] () -- C:\Windows\cadx2.ini
[2010.10.21 09:59:18 | 000,072,304 | R--- | C] () -- C:\Windows\SysWow64\XSrvSetup.exe
[2010.10.21 09:58:32 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini

< End of report >

OTL Extras
Code:

OTL Extras logfile created on: 11.09.2012 23:26:33 - Run 2
OTL by OldTimer - Version 3.2.61.3    Folder = C:\Users\Astirala\Desktop
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,99 Gb Total Physical Memory | 2,72 Gb Available Physical Memory | 68,24% Memory free
7,98 Gb Paging File | 6,67 Gb Available in Paging File | 83,57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 906,61 Gb Total Space | 716,06 Gb Free Space | 78,98% Space Free | Partition Type: NTFS
Drive E: | 931,28 Gb Total Space | 680,36 Gb Free Space | 73,06% Space Free | Partition Type: FAT32
 
Computer Name: ASTIRALA-PC | User Name: Astirala | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0873D1C7-523F-4CF3-97AC-494537E32C07}" = rport=139 | protocol=6 | dir=out | app=system |
"{0A8897A1-08A3-4248-96F7-63290FF7B455}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{1006790A-23CD-4A0A-A9E7-36F15FF9BDCD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{23A66608-6777-4CF2-A14B-572D5D535044}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2506A035-5E66-4264-A2D0-651D1A43C6BD}" = lport=139 | protocol=6 | dir=in | app=system |
"{2F62ABF4-37F7-4906-BFB8-7AEB8CC69291}" = lport=137 | protocol=17 | dir=in | app=system |
"{30825A28-0D26-4378-871F-48A4A55ED0ED}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{3407594E-46D6-430B-B9D0-F0DD3C556BE0}" = rport=138 | protocol=17 | dir=out | app=system |
"{3D9D515F-5994-4832-837B-33B22C0CFD32}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{446FE5CB-5C1E-4E8C-9E7A-A78530D0D500}" = lport=138 | protocol=17 | dir=in | app=system |
"{5CE700AB-623F-44B1-B31F-FB305E7F8656}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5E54996B-BBEA-418F-B5B4-19CCA1F3962C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6E7C2E0D-FCF0-4497-90CB-23F349A0F151}" = rport=445 | protocol=6 | dir=out | app=system |
"{719CE635-8BC6-4254-B6CD-53F2B1CCA93A}" = lport=10243 | protocol=6 | dir=in | app=system |
"{7BA0DF5D-09D0-4B3D-8F4B-244CAF56B6F2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8179C67E-E5C1-46A1-9EC7-332D6B6F0D0B}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8BC60F5B-0F69-4A6D-B4E4-6AB87BB1FCF6}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{978F2D26-36CD-4BC7-B97E-C2639E725DA1}" = rport=137 | protocol=17 | dir=out | app=system |
"{98ECBC17-2AAB-49A1-816B-B0946AC280DD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AB4BED3C-2147-498C-A465-2E1D28F9F3EE}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{ABD0A079-A97D-4228-916D-6F6DE40CA6D5}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{BCB20EB8-9CC3-4C96-B9D8-9DB2BB9B7705}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{CFC5C5AC-4155-4E69-9D58-9C426DC1A37E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E7D70838-E59F-4CFC-BFF5-D0BA4BD1FDA8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F40163C8-988A-4FD1-82CB-3D2ED0FC6291}" = lport=445 | protocol=6 | dir=in | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B41EA67-57CB-4B39-99C4-4FD69C83154C}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{12C38ADB-1D78-4685-9F99-CDFBCC207BB4}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{17141F62-A1EA-4779-B956-CD48C96B3FDA}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{1B223651-A0C8-4EF8-8F82-6CCDCD2048C5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1E96AFA7-4A57-4F06-B1F0-68CD1AD59B23}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{278BB56F-9510-417C-8BDD-1FD7D251D2BA}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{395D4F20-F9F8-4DA7-A531-6C639448E508}" = protocol=6 | dir=out | app=system |
"{5032AF76-E4B6-41C7-841F-4B3FF6F0702B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{52DE0798-B8CB-4A1A-972A-19A235617007}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{653F55A1-CAA4-4146-A66F-AAEC248D1A10}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{6B190101-9AB9-434C-A5D2-7291B5645637}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6FD3B70B-968F-4FAF-AA25-CCB789579EBD}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{85128A17-4D84-413C-A112-CD8C509F03E1}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{8624DA2D-71D5-4F5E-AFE8-9045BCEEA67B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{8CA0685F-F2C8-4998-A7C9-6EEE0DDC96A4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9018209A-3E81-48D8-9DEC-43C406FBF72D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{952C828D-9F06-484B-8ADB-E4416F6BCEAA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{97C1964F-600C-42DA-8996-8021B5561AEA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9C172793-D4A6-4A26-9ED1-1D4796F9D80E}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{A07D0C90-C531-46A4-9E38-AE3FC126FF5D}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{CA685E43-E01E-423E-AF5C-FFB5037C7B4D}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D1E6F52D-6A12-4165-9149-097064B370C8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DADC3DDD-3DF8-41CF-8ABE-5FBAA5F28C08}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{DCC2966D-67CB-4FA3-983C-95F3A6B99929}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DE413E04-12C3-47EA-A0E8-F21CE38E3A99}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{EDD18447-19C2-485F-9542-8A380D9FA028}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F9477D32-4122-41F4-B1B3-5C00BF24116E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{537056B7-32A4-4408-9B54-0341963C7C9C}" = UltraMon
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 301.42
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.0213
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.8.15
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.16.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"TeamSpeak 3 Client" = TeamSpeak 3 Client
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = Gigabyte Raid Configurer
"{3DECD372-76A1-4483-BF10-B547790A3261}" = ON_OFF Charge B10.0427.1
"{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C552FD3-2CCD-4E00-AC64-0681DBB3F8B5}" = OpenOffice.org 3.4
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{873E4648-6F6E-47F6-A7B2-A6F8DFABDCE6}" = Windows Live Messenger
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{8915E13E-E304-4CD6-BF23-B35DF327ECBC}" = Gmail Notifier Pro
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96334581-5554-3E5F-8BC9-924C3C3AC5BE}" = Google Talk Plugin
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E48FF52-082C-4CC2-BB67-6E10D09C0431}" = Windows Live UX Platform Language Pack
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.2 MUI
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Digital Editions" = Adobe Digital Editions
"DivX Setup" = DivX-Setup
"InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"InstallWIX_{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012
"Metin2_is1" = Metin2
"Mozilla Firefox 13.0.1 (x86 de)" = Mozilla Firefox 13.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MySSID_is1" = EXPERTool 7.21
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"VLC media player" = VLC media player 2.0.1
"WinLiveSuite" = Windows Live Essentials
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"Google Chrome" = Google Chrome
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 09.08.2012 21:52:35 | Computer Name = Astirala-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 10.08.2012 19:38:23 | Computer Name = Astirala-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 12.08.2012 01:52:14 | Computer Name = Astirala-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 16.08.2012 01:35:44 | Computer Name = Astirala-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 16.08.2012 15:54:06 | Computer Name = Astirala-PC | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Astirala\Downloads\SoftonicDownloader_fuer_googlemail-notifier-pro.exe".
 Fehler in  Manifest- oder Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche
 Komponentenversion steht in Konflikt mit  einer anderen, bereits aktiven Komponentenversion.
In
 Konflikt stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.
 
Error - 18.08.2012 08:08:45 | Computer Name = Astirala-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 19.08.2012 14:38:25 | Computer Name = Astirala-PC | Source = Application Hang | ID = 1002
Description = Programm Client.exe, Version 5.0.1.2553 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 478    Startzeit:
01cd7e1e701f2d34    Endzeit: 272    Anwendungspfad: C:\Program Files (x86)\Runes of Magic\Client.exe

Berichts-ID:
 
 
Error - 20.08.2012 06:00:12 | Computer Name = Astirala-PC | Source = Application Hang | ID = 1002
Description = Programm Client.exe, Version 5.0.1.2553 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 10f4    Startzeit:
 01cd7e39eafa30d9    Endzeit: 227    Anwendungspfad: C:\Program Files (x86)\Runes of Magic\Client.exe

Berichts-ID:
 d05558f6-eaad-11e1-bc36-1c6f6534c5da 
 
Error - 20.08.2012 07:57:44 | Computer Name = Astirala-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 20.08.2012 22:30:52 | Computer Name = Astirala-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
[ System Events ]
Error - 31.08.2012 11:43:46 | Computer Name = Astirala-PC | Source = bowser | ID = 8003
Description =
 
Error - 01.09.2012 03:27:04 | Computer Name = Astirala-PC | Source = bowser | ID = 8003
Description =
 
Error - 01.09.2012 06:19:08 | Computer Name = Astirala-PC | Source = bowser | ID = 8003
Description =
 
Error - 01.09.2012 11:40:07 | Computer Name = Astirala-PC | Source = Service Control Manager | ID = 7038
Description = Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser"
 mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:  %%1330    Vergewissern
 Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
 Management Console (MMC).
 
Error - 01.09.2012 11:40:07 | Computer Name = Astirala-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%1069
 
Error - 01.09.2012 12:26:40 | Computer Name = Astirala-PC | Source = bowser | ID = 8003
Description =
 
Error - 02.09.2012 10:24:58 | Computer Name = Astirala-PC | Source = bowser | ID = 8003
Description =
 
Error - 04.09.2012 06:13:23 | Computer Name = Astirala-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?04.?09.?2012 um 12:12:14 unerwartet heruntergefahren.
 
Error - 04.09.2012 06:15:46 | Computer Name = Astirala-PC | Source = Service Control Manager | ID = 7038
Description = Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser"
 mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:  %%1330    Vergewissern
 Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
 Management Console (MMC).
 
Error - 04.09.2012 06:15:46 | Computer Name = Astirala-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%1069
 
 
< End of report >

und ccleaner
Code:

7-Zip 9.20 (x64 edition)        Igor Pavlov        16.06.2012        4,53MB        9.20.00.0
Acrobat.com        Adobe Systems Incorporated        21.10.2010        1,60MB        1.6.65
Adobe AIR        Adobe Systems Inc.        21.10.2010                1.5.0.7220
Adobe Digital Editions                04.07.2012               
Adobe Flash Player 11 ActiveX        Adobe Systems Incorporated        15.08.2012        6,00MB        11.3.300.271
Adobe Reader 9.2 MUI        Adobe Systems Incorporated        07.07.2012        652MB        9.2.0
CCleaner        Piriform        22.08.2012                3.22
DivX-Setup        DivX, LLC        16.06.2012                2.6.1.9
EXPERTool 7.21        Gainward Co., Ltd        18.06.2012        11,2MB       
Gigabyte Raid Configurer        GIGABYTE Technologies, Inc.        21.10.2010                1.00.0001
Gmail Notifier Pro        GmailNotifierPro        17.06.2012        11,0MB        3.6.1.0
Google Chrome        Google Inc.        16.06.2012                21.0.1180.89
Google Talk (remove only)                16.06.2012               
Google Talk Plugin        Google        21.08.2012        18,9MB        3.5.1.8982
Java 7 Update 7        Oracle        11.09.2012        128MB        7.0.70
JavaFX 2.1.1        Oracle Corporation        07.07.2012        20,8MB        2.1.1
Kaspersky Internet Security 2012        Kaspersky Lab        16.06.2012                12.0.0.374
Metin2        Gameforge 4D GmbH        10.09.2012        874MB       
Microsoft .NET Framework 4 Client Profile        Microsoft Corporation        21.10.2010        38,8MB        4.0.30319
Microsoft Office 2010        Microsoft Corporation        21.10.2010        6,31MB        14.0.4763.1000
Microsoft Silverlight        Microsoft Corporation        21.10.2010        20,4MB        4.0.50524.0
Microsoft SQL Server 2005 Compact Edition [ENU]        Microsoft Corporation        16.06.2012        1,69MB        3.1.0000
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17        Microsoft Corporation        16.06.2012        788KB        9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411        Microsoft Corporation        19.06.2012        2,10MB        9.0.30411
Mozilla Firefox 13.0.1 (x86 de)        Mozilla        17.06.2012        35,7MB        13.0.1
Mozilla Maintenance Service        Mozilla        17.06.2012        199KB        13.0.1
NEC Electronics USB 3.0 Host Controller Driver        NEC Electronics Corporation        21.10.2010        993KB        1.0.17.0
NVIDIA 3D Vision Controller-Treiber 301.42        NVIDIA Corporation        18.06.2012                301.42
NVIDIA 3D Vision Treiber 301.42        NVIDIA Corporation        18.06.2012                301.42
NVIDIA Grafiktreiber 301.42        NVIDIA Corporation        18.06.2012                301.42
NVIDIA HD-Audiotreiber 1.3.16.0        NVIDIA Corporation        18.06.2012                1.3.16.0
NVIDIA PhysX-Systemsoftware 9.12.0213        NVIDIA Corporation        18.06.2012                9.12.0213
NVIDIA Update 1.8.15        NVIDIA Corporation        18.06.2012                1.8.15
ON_OFF Charge B10.0427.1        GIGABYTE        21.10.2010                1.00.0001
OpenOffice.org 3.4        OpenOffice.org        19.06.2012        327MB        3.4.9590
Pando Media Booster        Pando Networks Inc.        09.09.2012        5,46MB        2.6.0.8
Realtek Ethernet Controller Driver For Windows 7        Realtek        21.10.2010                7.17.304.2010
Realtek High Definition Audio Driver        Realtek Semiconductor Corp.        21.10.2010                6.0.1.6077
TeamSpeak 3 Client        TeamSpeak Systems GmbH        13.08.2012                3.0.8.1
UltraMon        Realtime Soft Ltd        16.06.2012        6,18MB        3.1.0
VLC media player 2.0.1        VideoLAN        16.06.2012                2.0.1
Windows Live Essentials        Microsoft Corporation        16.06.2012                15.4.3502.0922
Windows Live Mesh ActiveX control for remote connections        Microsoft Corporation        16.06.2012        5,57MB        15.4.5722.2

Danke schonmal für etwaige Hilfe
Astirala

cosinus 12.09.2012 12:27

Bitte alle Logs vom adwCleaner posten

Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

Astirala 12.09.2012 12:34

Hallo. Ich wusste nicht, ob ich das nach benutzen des browsers nochmal machen muss, daher habe ich insgesamt 4 Protokolle. Das letzte hatte ich ja schon gepostet .. hier nun die anderen 3 :pfeiff:

Code:

# AdwCleaner v2.001 - Datei am 09/11/2012 um 22:53:09 erstellt
# Aktualisiert am 09/09/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium  (64 bits)
# Benutzer : Astirala - ASTIRALA-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Astirala\Desktop\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****

Gefunden : Web Assistant Updater

***** [Dateien / Ordner] *****

Datei Gefunden : C:\user.js
Datei Gefunden : C:\Users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\searchplugins\MyStart Search.xml
Ordner Gefunden : C:\Program Files\Web Assistant
Ordner Gefunden : C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Ordner Gefunden : C:\Users\Astirala\AppData\LocalLow\boost_interprocess
Ordner Gefunden : C:\Users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\extensions\ffxtlbr@incredibar.com

***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKCU\Software\IM
Schlüssel Gefunden : HKCU\Software\ImInstaller
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Schlüssel Gefunden : HKLM\Software\Web Assistant
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Schlüssel Gefunden : HKLM\SOFTWARE\Web Assistant
Schlüssel Gefunden : HKU\S-1-5-21-382671035-3137015300-3879576489-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://mystart.incredibar.com/mb178?a=6OyNNxoTPJ&i=26

-\\ Mozilla Firefox v13.0.1 (de)

Profilname : default
Datei : C:\Users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\prefs.js

Gefunden : user_pref("browser.startup.homepage", "hxxp://mystart.incredibar.com/mb178?a=6OyNNxoTPJ&i=26");
Gefunden : user_pref("browser.search.defaultenginename", "MyStart Search");
Gefunden : user_pref("browser.search.selectedEngine", "MyStart Search");
Gefunden : user_pref("keyword.URL", "hxxp://mystart.incredibar.com/mb178/?loc=IB_DS&a=6OyNNxoTPJ&&i=26&search="[...]
Gefunden : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb178?a=6OyNNxoTPJ&loc=FF_NT");

-\\ Google Chrome v21.0.1180.89

Datei : C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [4363 octets] - [11/09/2012 22:53:09]

########## EOF - C:\AdwCleaner[R1].txt - [4423 octets] ##########


Code:

# AdwCleaner v2.001 - Datei am 09/11/2012 um 22:55:12 erstellt
# Aktualisiert am 09/09/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium  (64 bits)
# Benutzer : Astirala - ASTIRALA-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Astirala\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****

Gestoppt & Gelöscht : Web Assistant Updater

***** [Dateien / Ordner] *****

Datei Gelöscht : C:\user.js
Datei Gelöscht : C:\Users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\searchplugins\MyStart Search.xml
Ordner Gelöscht : C:\Program Files\Web Assistant
Ordner Gelöscht : C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Ordner Gelöscht : C:\Users\Astirala\AppData\LocalLow\boost_interprocess
Ordner Gelöscht : C:\Users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\extensions\ffxtlbr@incredibar.com

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\ImInstaller
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Schlüssel Gelöscht : HKLM\Software\Web Assistant
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Web Assistant
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

Wiederhergestellt : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://mystart.incredibar.com/mb178?a=6OyNNxoTPJ&i=26 --> hxxp://www.google.com

-\\ Mozilla Firefox v13.0.1 (de)

Profilname : default
Datei : C:\Users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\prefs.js

C:\Users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\user.js ... Gelöscht !

Gelöscht : user_pref("browser.startup.homepage", "hxxp://mystart.incredibar.com/mb178?a=6OyNNxoTPJ&i=26");
Gelöscht : user_pref("browser.search.defaultenginename", "MyStart Search");
Gelöscht : user_pref("browser.search.selectedEngine", "MyStart Search");
Gelöscht : user_pref("keyword.URL", "hxxp://mystart.incredibar.com/mb178/?loc=IB_DS&a=6OyNNxoTPJ&&i=26&search="[...]
Gelöscht : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb178?a=6OyNNxoTPJ&loc=FF_NT");

-\\ Google Chrome v21.0.1180.89

Datei : C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [4476 octets] - [11/09/2012 22:53:09]
AdwCleaner[S1].txt - [4719 octets] - [11/09/2012 22:55:12]

########## EOF - C:\AdwCleaner[S1].txt - [4779 octets] ##########


Code:

# AdwCleaner v2.001 - Datei am 09/11/2012 um 23:17:52 erstellt
# Aktualisiert am 09/09/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium  (64 bits)
# Benutzer : Astirala - ASTIRALA-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Astirala\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421


-\\ Mozilla Firefox v13.0.1 (de)

Profilname : default
Datei : C:\Users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\prefs.js

[OK] Die Datei ist sauber.

-\\ Google Chrome v21.0.1180.89

Datei : C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [4476 octets] - [11/09/2012 22:53:09]
AdwCleaner[S1].txt - [4832 octets] - [11/09/2012 22:55:12]
AdwCleaner[S2].txt - [972 octets] - [11/09/2012 23:17:52]

########## EOF - C:\AdwCleaner[S2].txt - [1031 octets] ##########

Sorry und Danke
Astirala

cosinus 12.09.2012 14:35

Bitte nun routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

Astirala 12.09.2012 23:19

Soooo, hat zwar bissl gedauert, aber nun hab ich beide Logs.

Malwarebytes
Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.12.05

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Astirala :: ASTIRALA-PC [Administrator]

Schutz: Aktiviert

12.09.2012 16:58:23
mbam-log-2012-09-12 (19-06-10).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 595062
Laufzeit: 2 Stunde(n), 6 Minute(n), 49 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\Astirala\Downloads\video_downloader.exe (PUP.BundleInstaller.VG) -> Keine Aktion durchgeführt.

(Ende)

Eset
Code:

C:\Users\Astirala\Downloads\MutluvonSchriftartenFontsde_downloader_by_SchriftartenFontsde (1).exe        a variant of Win32/Somoto.A application
C:\Users\Astirala\Downloads\MutluvonSchriftartenFontsde_downloader_by_SchriftartenFontsde.exe        a variant of Win32/Somoto.A application
C:\Users\Astirala\Downloads\SoftonicDownloader_fuer_googlemail-notifier-pro.exe        a variant of Win32/SoftonicDownloader.D application

Hoffe die Daten sind hilfreich :)
Astirala

cosinus 13.09.2012 15:45

Hätte da mal zwei Fragen bevor es weiter geht (wir sind noch nicht fertig!)

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

Astirala 13.09.2012 17:08

Huhu

Also Windows ging immer komplett normal (uneingeschränkt) und Ordner sind alle so wie sie sein sollten. Keinerlei Auffälligkeiten.

cosinus 13.09.2012 23:36

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Astirala 14.09.2012 08:16

Guten Morgen

Also entweder habe ich nun was falsch gemacht oder .. ich weiss auch nicht.
Ich habe OTL gestartet. Habe das Häkchen gesetzt, den Text eingefügt etc. Alles wie beschrieben. Nun hat er sich zwischendrin ca. 3 mal "aufgehängt" mit keine Rückmeldung, sich dann aber von alleine ohne das ich was gemacht habe wieder eingekriegt und weitergemacht. Soweit ok. Nun steht er seit einiger Zeit unten auf "Manual File Scan - Getting folder structure ..." und macht nichts mehr. Und nun vor ein paar Sekunden ging ein "warnfenster" auf mit "out of memory".

Keine Logdatei nichts vorhanden :(

LG

cosinus 14.09.2012 15:08

Du hast OTL auch neu runtergeladen?
Per Rechtsklick als Admin ausgeführt?
Sonst alles richtig umgesetzt?

Astirala 14.09.2012 15:57

Hallo mal wieder :)

Also habe alles gemacht wie du geschrieben hattest. Dennoch kam der "Error".

Habe Version 3.2.61.4 von OTL, weiss halt nicht, ob es wo anders noch eine neuere Version gibt...

Habe gerade, um Fehler meinerseits auszuschliessen alles nochmal gemacht. Also OTL gezogen, auf Desktop verschoben, als Admin ausgeführt, Haken bei Alle Benutzer gesetzt, Text eingeführt und Quick Scan laufen lassen. Gleiches Resultat. Bei Manual File Scan - Getting folder structure ... ist Feierabend und dann kommt die Meldung.

Greetz

Edit: Habe alles geschlossen gehabt. Lief nur das OTL, kein Browser oder Programm lief sonst noch (ausser Kaspersky) ... oben vergessen reinzuschreiben.

cosinus 14.09.2012 20:12

Probier es bitte nochmal im abgesicherten Modus ausd

Astirala 14.09.2012 22:47

Einen wunderschönen ... oder leider auch nicht.

Habe das nun gemacht. Dein Script in einem Editor-File gespeichert, abgesicherter Modus gestartet, OTL gestartet, Haken gesetzt, Script eingefügt Quick Scan und wieder das gleich wie auch im normalem Modus. Out of Memory ...

Langsam mache ich mir ein wenig Sorgen um meinen Rechner, weil normal scheint das ja nicht wirklich zu sein ...:(

Grüsse

cosinus 15.09.2012 12:56

Das kommt hin und wieder vor, dass manche Rechner den CustomScan nicht wollen/mögen - mach es dann einfach so

Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.

Astirala 15.09.2012 13:09

OTL
Code:

OTL logfile created on: 15.09.2012 14:00:54 - Run 3
OTL by OldTimer - Version 3.2.61.4    Folder = C:\Users\Astirala\Desktop
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,99 Gb Total Physical Memory | 2,71 Gb Available Physical Memory | 68,00% Memory free
7,98 Gb Paging File | 6,37 Gb Available in Paging File | 79,87% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 906,61 Gb Total Space | 713,81 Gb Free Space | 78,73% Space Free | Partition Type: NTFS
Drive E: | 931,28 Gb Total Space | 686,47 Gb Free Space | 73,71% Space Free | Partition Type: FAT32
 
Computer Name: ASTIRALA-PC | User Name: Astirala | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Astirala\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\EXPERTool\TBPANEL.exe (Gainward Co.)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Windows\SysWOW64\XSrvSetup.exe ()
PRC - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
PRC - C:\Users\Astirala\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtGui4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtSql4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtScript4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtCore4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtDeclarative4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\EXPERTool\TBManage.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (AppleChargerSrv) -- C:\Windows\SysNative\AppleChargerSrv.exe ()
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (AVP) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)
SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (JMB36X) -- C:\Windows\SysWOW64\XSrvSetup.exe ()
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (KLIF) -- C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (ssudmdm) -- C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (dg_ssudbus) -- C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (KLIM6) -- C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kl2) -- C:\Windows\SysNative\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KL1) -- C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (sscdbus) -- C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation)
DRV:64bit: - (AppleCharger) -- C:\Windows\SysNative\drivers\AppleCharger.sys ()
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (JRAID) -- C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (klmouflt) -- C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation)
DRV:64bit: - (LVUVC64) -- C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (UltraMonUtility) -- C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys (Realtime Soft Ltd)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.stegcomputer.ch [binary data]
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.stegcomputer.ch [binary data]
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2319825
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 1D 89 A6 64 C9 4C CD 01  [binary data]
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - No CLSID value found
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Astirala\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Astirala\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Astirala\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Astirala\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.06.16 15:27:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru [2012.09.03 14:19:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru [2012.09.03 14:19:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\KavAntiBanner@Kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru [2012.09.03 14:19:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.17 20:18:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2012.06.17 20:18:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Astirala\AppData\Roaming\mozilla\Extensions
[2012.09.13 12:55:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Astirala\AppData\Roaming\mozilla\Firefox\Profiles\amukf51a.default\extensions
[2012.09.13 12:55:56 | 000,000,000 | ---D | M] (Winload) -- C:\Users\Astirala\AppData\Roaming\mozilla\Firefox\Profiles\amukf51a.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f}
[2012.06.17 20:18:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.06.15 00:19:07 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.15 00:46:57 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.15 00:46:56 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.15 00:46:57 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.15 00:46:57 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.15 00:46:57 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.15 00:46:56 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - homepage: hxxp://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Astirala\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Astirala\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Astirala\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Windows Live\\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Astirala\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50524.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Modul zur Link-Untersuchung = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\12.0.0.477_1\
CHR - Extension: Rummikub = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\inkiliggodjonlfmnpchdgikolcbopif\1.0.0.5_0\
CHR - Extension: Virtuelle Tastatur = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\12.0.0.477_1\
CHR - Extension: New tab for Chrome\u2122 = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\
CHR - Extension: Mehr Leistung und Videoformate f\\u00FCr dein HTML5 \\u003Cvideo\\u003E = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Google Mail = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Anti-Banner = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\12.0.0.374_0\
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-382671035-3137015300-3879576489-1000..\Run: [GAINWARD] C:\Program Files (x86)\EXPERTool\TBPanel.exe (Gainward Co.)
O4 - HKU\S-1-5-21-382671035-3137015300-3879576489-1000..\Run: [googletalk] C:\Users\Astirala\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKU\S-1-5-21-382671035-3137015300-3879576489-1000..\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm ()
O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm ()
O9:64bit: - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87D59B29-8F0F-4EFA-A9BC-49F877C81F5E}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.13 12:56:12 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Local\CRE
[2012.09.13 12:55:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2012.09.13 12:55:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2012.09.13 12:55:18 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Local\Conduit
[2012.09.12 19:09:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.09.12 18:45:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\20-20 Technologies
[2012.09.12 16:54:45 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Roaming\Malwarebytes
[2012.09.12 16:54:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.09.12 16:54:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.09.12 16:54:40 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.09.12 16:54:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.09.12 13:54:57 | 000,574,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll
[2012.09.11 23:13:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.09.11 23:13:08 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.09.11 22:54:31 | 000,599,552 | ---- | C] (OldTimer Tools) -- C:\Users\Astirala\Desktop\OTL.exe
[2012.09.11 15:06:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Perion
[2012.09.11 14:46:14 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Local\Windows Live
[2012.09.11 12:12:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012.09.11 12:11:16 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2012.09.11 12:10:57 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2012.09.11 12:10:57 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2012.09.11 12:10:57 | 000,095,208 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2012.09.11 12:10:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2012.09.10 11:30:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metin2
[2012.09.10 11:29:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Metin2
[2012.09.10 00:11:50 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment
[2012.09.10 00:11:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment
[2012.09.10 00:04:47 | 000,000,000 | ---D | C] -- C:\Perfect World Entertainment
[2012.09.10 00:04:24 | 000,258,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unicows.dll
[2012.09.09 20:12:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PWI_DE_v165_Installer
[2012.09.09 20:11:53 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Local\PMB Files
[2012.09.09 20:11:49 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2012.09.09 20:11:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.15 13:59:49 | 000,599,552 | ---- | M] (OldTimer Tools) -- C:\Users\Astirala\Desktop\OTL.exe
[2012.09.15 13:40:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.15 13:29:01 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-382671035-3137015300-3879576489-1000UA.job
[2012.09.15 04:45:54 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.15 04:45:54 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.15 02:29:00 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-382671035-3137015300-3879576489-1000Core.job
[2012.09.14 23:43:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.14 23:43:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\lvuvc.hs
[2012.09.14 23:43:30 | 3214,483,456 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.13 12:56:17 | 000,000,009 | ---- | M] () -- C:\END
[2012.09.12 16:54:41 | 000,001,116 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.11 23:13:09 | 000,000,829 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.09.11 22:52:09 | 000,512,399 | ---- | M] () -- C:\Users\Astirala\Desktop\adwcleaner.exe
[2012.09.11 12:10:52 | 000,095,208 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2012.09.11 12:10:51 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2012.09.11 12:10:51 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2012.09.11 12:10:51 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2012.09.11 12:10:51 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2012.09.11 12:10:51 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2012.09.10 11:30:48 | 000,000,986 | ---- | M] () -- C:\Users\Public\Desktop\Metin2.lnk
[2012.09.10 00:11:57 | 000,001,202 | ---- | M] () -- C:\Users\Astirala\Desktop\Perfect World International.lnk
[2012.09.09 21:16:20 | 000,258,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\unicows.dll
[2012.09.07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
 
========== Files Created - No Company Name ==========
 
[2012.09.13 12:56:17 | 000,000,009 | ---- | C] () -- C:\END
[2012.09.12 18:39:17 | 000,002,720 | ---- | C] () -- C:\Users\Astirala\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VPUIPlayerInstallFF.lnk
[2012.09.12 16:54:41 | 000,001,116 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.11 23:13:09 | 000,000,829 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.09.11 22:52:08 | 000,512,399 | ---- | C] () -- C:\Users\Astirala\Desktop\adwcleaner.exe
[2012.09.10 11:30:48 | 000,000,986 | ---- | C] () -- C:\Users\Public\Desktop\Metin2.lnk
[2012.09.10 00:11:57 | 000,001,202 | ---- | C] () -- C:\Users\Astirala\Desktop\Perfect World International.lnk
[2012.06.16 15:30:14 | 000,017,408 | ---- | C] () -- C:\Users\Astirala\AppData\Local\WebpageIcons.db
[2012.05.15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011.08.11 04:06:32 | 000,007,764 | ---- | C] () -- C:\Windows\cadx2.ini
[2010.10.21 09:59:18 | 000,072,304 | R--- | C] () -- C:\Windows\SysWow64\XSrvSetup.exe
[2010.10.21 09:58:32 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini

< End of report >

Extras
Code:

OTL logfile created on: 15.09.2012 14:00:54 - Run 3
OTL by OldTimer - Version 3.2.61.4    Folder = C:\Users\Astirala\Desktop
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,99 Gb Total Physical Memory | 2,71 Gb Available Physical Memory | 68,00% Memory free
7,98 Gb Paging File | 6,37 Gb Available in Paging File | 79,87% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 906,61 Gb Total Space | 713,81 Gb Free Space | 78,73% Space Free | Partition Type: NTFS
Drive E: | 931,28 Gb Total Space | 686,47 Gb Free Space | 73,71% Space Free | Partition Type: FAT32
 
Computer Name: ASTIRALA-PC | User Name: Astirala | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Astirala\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\EXPERTool\TBPANEL.exe (Gainward Co.)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Windows\SysWOW64\XSrvSetup.exe ()
PRC - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
PRC - C:\Users\Astirala\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtGui4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtSql4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtScript4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtCore4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtDeclarative4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\EXPERTool\TBManage.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (AppleChargerSrv) -- C:\Windows\SysNative\AppleChargerSrv.exe ()
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (AVP) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)
SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (JMB36X) -- C:\Windows\SysWOW64\XSrvSetup.exe ()
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (KLIF) -- C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (ssudmdm) -- C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (dg_ssudbus) -- C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (KLIM6) -- C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kl2) -- C:\Windows\SysNative\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KL1) -- C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (sscdbus) -- C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation)
DRV:64bit: - (AppleCharger) -- C:\Windows\SysNative\drivers\AppleCharger.sys ()
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (JRAID) -- C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (klmouflt) -- C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation)
DRV:64bit: - (LVUVC64) -- C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (UltraMonUtility) -- C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys (Realtime Soft Ltd)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.stegcomputer.ch [binary data]
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.stegcomputer.ch [binary data]
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2319825
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 1D 89 A6 64 C9 4C CD 01  [binary data]
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - No CLSID value found
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Astirala\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Astirala\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Astirala\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Astirala\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.06.16 15:27:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru [2012.09.03 14:19:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru [2012.09.03 14:19:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\KavAntiBanner@Kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru [2012.09.03 14:19:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.17 20:18:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2012.06.17 20:18:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Astirala\AppData\Roaming\mozilla\Extensions
[2012.09.13 12:55:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Astirala\AppData\Roaming\mozilla\Firefox\Profiles\amukf51a.default\extensions
[2012.09.13 12:55:56 | 000,000,000 | ---D | M] (Winload) -- C:\Users\Astirala\AppData\Roaming\mozilla\Firefox\Profiles\amukf51a.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f}
[2012.06.17 20:18:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.06.15 00:19:07 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.15 00:46:57 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.15 00:46:56 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.15 00:46:57 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.15 00:46:57 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.15 00:46:57 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.15 00:46:56 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - homepage: hxxp://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Astirala\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Astirala\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Astirala\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Windows Live\\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Astirala\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50524.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Modul zur Link-Untersuchung = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\12.0.0.477_1\
CHR - Extension: Rummikub = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\inkiliggodjonlfmnpchdgikolcbopif\1.0.0.5_0\
CHR - Extension: Virtuelle Tastatur = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\12.0.0.477_1\
CHR - Extension: New tab for Chrome\u2122 = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\
CHR - Extension: Mehr Leistung und Videoformate f\\u00FCr dein HTML5 \\u003Cvideo\\u003E = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Google Mail = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Anti-Banner = C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\12.0.0.374_0\
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-382671035-3137015300-3879576489-1000..\Run: [GAINWARD] C:\Program Files (x86)\EXPERTool\TBPanel.exe (Gainward Co.)
O4 - HKU\S-1-5-21-382671035-3137015300-3879576489-1000..\Run: [googletalk] C:\Users\Astirala\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKU\S-1-5-21-382671035-3137015300-3879576489-1000..\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm ()
O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm ()
O9:64bit: - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87D59B29-8F0F-4EFA-A9BC-49F877C81F5E}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.13 12:56:12 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Local\CRE
[2012.09.13 12:55:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2012.09.13 12:55:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2012.09.13 12:55:18 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Local\Conduit
[2012.09.12 19:09:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.09.12 18:45:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\20-20 Technologies
[2012.09.12 16:54:45 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Roaming\Malwarebytes
[2012.09.12 16:54:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.09.12 16:54:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.09.12 16:54:40 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.09.12 16:54:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.09.12 13:54:57 | 000,574,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll
[2012.09.11 23:13:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.09.11 23:13:08 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.09.11 22:54:31 | 000,599,552 | ---- | C] (OldTimer Tools) -- C:\Users\Astirala\Desktop\OTL.exe
[2012.09.11 15:06:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Perion
[2012.09.11 14:46:14 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Local\Windows Live
[2012.09.11 12:12:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012.09.11 12:11:16 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2012.09.11 12:10:57 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2012.09.11 12:10:57 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2012.09.11 12:10:57 | 000,095,208 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2012.09.11 12:10:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2012.09.10 11:30:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metin2
[2012.09.10 11:29:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Metin2
[2012.09.10 00:11:50 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment
[2012.09.10 00:11:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment
[2012.09.10 00:04:47 | 000,000,000 | ---D | C] -- C:\Perfect World Entertainment
[2012.09.10 00:04:24 | 000,258,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unicows.dll
[2012.09.09 20:12:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PWI_DE_v165_Installer
[2012.09.09 20:11:53 | 000,000,000 | ---D | C] -- C:\Users\Astirala\AppData\Local\PMB Files
[2012.09.09 20:11:49 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2012.09.09 20:11:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.15 13:59:49 | 000,599,552 | ---- | M] (OldTimer Tools) -- C:\Users\Astirala\Desktop\OTL.exe
[2012.09.15 13:40:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.15 13:29:01 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-382671035-3137015300-3879576489-1000UA.job
[2012.09.15 04:45:54 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.15 04:45:54 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.15 02:29:00 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-382671035-3137015300-3879576489-1000Core.job
[2012.09.14 23:43:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.14 23:43:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\lvuvc.hs
[2012.09.14 23:43:30 | 3214,483,456 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.13 12:56:17 | 000,000,009 | ---- | M] () -- C:\END
[2012.09.12 16:54:41 | 000,001,116 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.11 23:13:09 | 000,000,829 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.09.11 22:52:09 | 000,512,399 | ---- | M] () -- C:\Users\Astirala\Desktop\adwcleaner.exe
[2012.09.11 12:10:52 | 000,095,208 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2012.09.11 12:10:51 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2012.09.11 12:10:51 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2012.09.11 12:10:51 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2012.09.11 12:10:51 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2012.09.11 12:10:51 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2012.09.10 11:30:48 | 000,000,986 | ---- | M] () -- C:\Users\Public\Desktop\Metin2.lnk
[2012.09.10 00:11:57 | 000,001,202 | ---- | M] () -- C:\Users\Astirala\Desktop\Perfect World International.lnk
[2012.09.09 21:16:20 | 000,258,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\unicows.dll
[2012.09.07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
 
========== Files Created - No Company Name ==========
 
[2012.09.13 12:56:17 | 000,000,009 | ---- | C] () -- C:\END
[2012.09.12 18:39:17 | 000,002,720 | ---- | C] () -- C:\Users\Astirala\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VPUIPlayerInstallFF.lnk
[2012.09.12 16:54:41 | 000,001,116 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.11 23:13:09 | 000,000,829 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.09.11 22:52:08 | 000,512,399 | ---- | C] () -- C:\Users\Astirala\Desktop\adwcleaner.exe
[2012.09.10 11:30:48 | 000,000,986 | ---- | C] () -- C:\Users\Public\Desktop\Metin2.lnk
[2012.09.10 00:11:57 | 000,001,202 | ---- | C] () -- C:\Users\Astirala\Desktop\Perfect World International.lnk
[2012.06.16 15:30:14 | 000,017,408 | ---- | C] () -- C:\Users\Astirala\AppData\Local\WebpageIcons.db
[2012.05.15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011.08.11 04:06:32 | 000,007,764 | ---- | C] () -- C:\Windows\cadx2.ini
[2010.10.21 09:59:18 | 000,072,304 | R--- | C] () -- C:\Windows\SysWow64\XSrvSetup.exe
[2010.10.21 09:58:32 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini

< End of report >


cosinus 16.09.2012 14:20

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
FF - user.js - File not found
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.stegcomputer.ch [binary data]
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.stegcomputer.ch [binary data]
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2319825
IE - HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-21-382671035-3137015300-3879576489-1000..\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
:Files
C:\Program Files (x86)\Conduit
C:\Users\Astirala\AppData\Local\Conduit
C:\Users\Astirala\Downloads\MutluvonSchriftartenFontsde_downloader_by_SchriftartenFontsde (1).exe
C:\Users\Astirala\Downloads\MutluvonSchriftartenFontsde_downloader_by_SchriftartenFontsde.exe
C:\Users\Astirala\Downloads\SoftonicDownloader_fuer_googlemail-notifier-pro.exe
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Astirala 16.09.2012 16:50

Moin. Hier das Log nach einem Neustart.

OTL
Code:

All processes killed
========== OTL ==========
HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Secondary_Page_URL| /E : value set successfully!
HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Secondary Start Pages| /E : value set successfully!
HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-21-382671035-3137015300-3879576489-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully!
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-21-382671035-3137015300-3879576489-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Overwolf deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
========== FILES ==========
C:\Program Files (x86)\Conduit\Community Alerts folder moved successfully.
C:\Program Files (x86)\Conduit folder moved successfully.
C:\Users\Astirala\AppData\Local\Conduit folder moved successfully.
File\Folder C:\Users\Astirala\Downloads\MutluvonSchriftartenFontsde_downloader_by_SchriftartenFontsde (1).exe not found.
File\Folder C:\Users\Astirala\Downloads\MutluvonSchriftartenFontsde_downloader_by_SchriftartenFontsde.exe not found.
File\Folder C:\Users\Astirala\Downloads\SoftonicDownloader_fuer_googlemail-notifier-pro.exe not found.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Astirala\Desktop\cmd.bat deleted successfully.
C:\Users\Astirala\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Astirala
->Temp folder emptied: 192864463 bytes
->Temporary Internet Files folder emptied: 13753013 bytes
->Java cache emptied: 41695 bytes
->FireFox cache emptied: 16770067 bytes
->Google Chrome cache emptied: 422059217 bytes
->Flash cache emptied: 167846 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 106733508 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 46421933 bytes
RecycleBin emptied: 1813105 bytes
 
Total Files Cleaned = 764,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.61.4 log created on 09162012_174519

Files\Folders moved on Reboot...
C:\Users\Astirala\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


cosinus 17.09.2012 09:10

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

Astirala 17.09.2012 11:56

Code:

12:49:33.0312 1028  TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
12:49:39.0030 1028  ============================================================
12:49:39.0030 1028  Current date / time: 2012/09/17 12:49:39.0030
12:49:39.0030 1028  SystemInfo:
12:49:39.0030 1028 
12:49:39.0031 1028  OS Version: 6.1.7600 ServicePack: 0.0
12:49:39.0031 1028  Product type: Workstation
12:49:39.0031 1028  ComputerName: ASTIRALA-PC
12:49:39.0031 1028  UserName: Astirala
12:49:39.0031 1028  Windows directory: C:\Windows
12:49:39.0031 1028  System windows directory: C:\Windows
12:49:39.0031 1028  Running under WOW64
12:49:39.0031 1028  Processor architecture: Intel x64
12:49:39.0031 1028  Number of processors: 4
12:49:39.0031 1028  Page size: 0x1000
12:49:39.0031 1028  Boot type: Normal boot
12:49:39.0031 1028  ============================================================
12:49:40.0053 1028  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0CADE00 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
12:49:40.0065 1028  Drive \Device\Harddisk5\DR5 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
12:49:40.0066 1028  ============================================================
12:49:40.0066 1028  \Device\Harddisk0\DR0:
12:49:40.0066 1028  MBR partitions:
12:49:40.0066 1028  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xFA000
12:49:40.0066 1028  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x31CE800, BlocksNum 0x71537000
12:49:40.0066 1028  \Device\Harddisk5\DR5:
12:49:40.0067 1028  MBR partitions:
12:49:40.0067 1028  \Device\Harddisk5\DR5\Partition1: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x74705982
12:49:40.0067 1028  ============================================================
12:49:40.0100 1028  C: <-> \Device\Harddisk0\DR0\Partition2
12:49:40.0101 1028  E: <-> \Device\Harddisk5\DR5\Partition1
12:49:40.0101 1028  ============================================================
12:49:40.0101 1028  Initialize success
12:49:40.0101 1028  ============================================================
12:50:38.0763 4188  ============================================================
12:50:38.0768 4188  Scan started
12:50:38.0768 4188  Mode: Manual; SigCheck; TDLFS;
12:50:38.0768 4188  ============================================================
12:50:38.0900 4188  ================ Scan system memory ========================
12:50:38.0900 4188  System memory - ok
12:50:38.0901 4188  ================ Scan services =============================
12:50:39.0179 4188  [ 1B00662092F9F9568B995902F0CC40D5 ] 1394ohci        C:\Windows\system32\DRIVERS\1394ohci.sys
12:50:39.0304 4188  1394ohci - ok
12:50:39.0323 4188  [ 6F11E88748CDEFD2F76AA215F97DDFE5 ] ACPI            C:\Windows\system32\DRIVERS\ACPI.sys
12:50:39.0338 4188  ACPI - ok
12:50:39.0364 4188  [ 63B05A0420CE4BF0E4AF6DCC7CADA254 ] AcpiPmi        C:\Windows\system32\DRIVERS\acpipmi.sys
12:50:39.0421 4188  AcpiPmi - ok
12:50:39.0523 4188  [ A9D3B95E8466BD58EEB8A1154654E162 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
12:50:39.0547 4188  AdobeFlashPlayerUpdateSvc - ok
12:50:39.0570 4188  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx        C:\Windows\system32\DRIVERS\adp94xx.sys
12:50:39.0594 4188  adp94xx - ok
12:50:39.0602 4188  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci        C:\Windows\system32\DRIVERS\adpahci.sys
12:50:39.0617 4188  adpahci - ok
12:50:39.0621 4188  [ E109549C90F62FB570B9540C4B148E54 ] adpu320        C:\Windows\system32\DRIVERS\adpu320.sys
12:50:39.0633 4188  adpu320 - ok
12:50:39.0658 4188  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
12:50:39.0840 4188  AeLookupSvc - ok
12:50:39.0901 4188  [ DB9D6C6B2CD95A9CA414D045B627422E ] AFD            C:\Windows\system32\drivers\afd.sys
12:50:39.0979 4188  AFD - ok
12:50:39.0998 4188  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows\system32\DRIVERS\agp440.sys
12:50:40.0010 4188  agp440 - ok
12:50:40.0038 4188  [ 3290D6946B5E30E70414990574883DDB ] ALG            C:\Windows\System32\alg.exe
12:50:40.0100 4188  ALG - ok
12:50:40.0119 4188  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows\system32\DRIVERS\aliide.sys
12:50:40.0132 4188  aliide - ok
12:50:40.0147 4188  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows\system32\DRIVERS\amdide.sys
12:50:40.0160 4188  amdide - ok
12:50:40.0173 4188  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8          C:\Windows\system32\DRIVERS\amdk8.sys
12:50:40.0225 4188  AmdK8 - ok
12:50:40.0246 4188  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
12:50:40.0282 4188  AmdPPM - ok
12:50:40.0313 4188  [ EC7EBAB00A4D8448BAB68D1E49B4BEB9 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
12:50:40.0332 4188  amdsata - ok
12:50:40.0345 4188  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
12:50:40.0362 4188  amdsbs - ok
12:50:40.0378 4188  [ DB27766102C7BF7E95140A2AA81D042E ] amdxata        C:\Windows\system32\drivers\amdxata.sys
12:50:40.0389 4188  amdxata - ok
12:50:40.0416 4188  [ 42FD751B27FA0E9C69BB39F39E409594 ] AppID          C:\Windows\system32\drivers\appid.sys
12:50:40.0518 4188  AppID - ok
12:50:40.0524 4188  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
12:50:40.0588 4188  AppIDSvc - ok
12:50:40.0608 4188  [ D065BE66822847B7F127D1F90158376E ] Appinfo        C:\Windows\System32\appinfo.dll
12:50:40.0663 4188  Appinfo - ok
12:50:40.0697 4188  [ 301AA64F9643BC453D90A66C4C0E7204 ] AppleCharger    C:\Windows\system32\DRIVERS\AppleCharger.sys
12:50:40.0731 4188  AppleCharger - ok
12:50:40.0753 4188  [ 95EF7247C50C7241FDAE39A9B3AFF4AE ] AppleChargerSrv C:\Windows\system32\AppleChargerSrv.exe
12:50:40.0760 4188  AppleChargerSrv - ok
12:50:40.0775 4188  [ C484F8CEB1717C540242531DB7845C4E ] arc            C:\Windows\system32\DRIVERS\arc.sys
12:50:40.0825 4188  arc - ok
12:50:40.0887 4188  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
12:50:40.0956 4188  arcsas - ok
12:50:41.0043 4188  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
12:50:41.0119 4188  AsyncMac - ok
12:50:41.0138 4188  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi          C:\Windows\system32\DRIVERS\atapi.sys
12:50:41.0147 4188  atapi - ok
12:50:41.0166 4188  [ 07721A77180EDD4D39CCB865BF63C7FD ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
12:50:41.0231 4188  AudioEndpointBuilder - ok
12:50:41.0240 4188  [ 07721A77180EDD4D39CCB865BF63C7FD ] AudioSrv        C:\Windows\System32\Audiosrv.dll
12:50:41.0276 4188  AudioSrv - ok
12:50:41.0363 4188  [ 2718DC27571BD1E37813F5759D2DC118 ] AVP            C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
12:50:41.0389 4188  AVP - ok
12:50:41.0425 4188  [ B20B5FA5CA050E9926E4D1DB81501B32 ] AxInstSV        C:\Windows\System32\AxInstSV.dll
12:50:41.0500 4188  AxInstSV - ok
12:50:41.0538 4188  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv        C:\Windows\system32\DRIVERS\bxvbda.sys
12:50:41.0607 4188  b06bdrv - ok
12:50:41.0694 4188  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
12:50:41.0764 4188  b57nd60a - ok
12:50:41.0802 4188  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows\System32\bdesvc.dll
12:50:41.0842 4188  BDESVC - ok
12:50:41.0855 4188  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
12:50:41.0928 4188  Beep - ok
12:50:41.0981 4188  [ 4992C609A6315671463E30F6512BC022 ] BFE            C:\Windows\System32\bfe.dll
12:50:42.0072 4188  BFE - ok
12:50:42.0121 4188  [ 7F0C323FE3DA28AA4AA1BDA3F575707F ] BITS            C:\Windows\System32\qmgr.dll
12:50:42.0173 4188  BITS - ok
12:50:42.0183 4188  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
12:50:42.0208 4188  blbdrive - ok
12:50:42.0236 4188  [ 19D20159708E152267E53B66677A4995 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
12:50:42.0273 4188  bowser - ok
12:50:42.0289 4188  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
12:50:42.0322 4188  BrFiltLo - ok
12:50:42.0341 4188  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
12:50:42.0393 4188  BrFiltUp - ok
12:50:42.0432 4188  [ 6B054C67AAA87843504E8E3C09102009 ] Browser        C:\Windows\System32\browser.dll
12:50:42.0488 4188  Browser - ok
12:50:42.0498 4188  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
12:50:42.0535 4188  Brserid - ok
12:50:42.0554 4188  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
12:50:42.0569 4188  BrSerWdm - ok
12:50:42.0584 4188  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
12:50:42.0600 4188  BrUsbMdm - ok
12:50:42.0617 4188  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
12:50:42.0638 4188  BrUsbSer - ok
12:50:42.0658 4188  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
12:50:42.0693 4188  BTHMODEM - ok
12:50:42.0711 4188  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv        C:\Windows\system32\bthserv.dll
12:50:42.0768 4188  bthserv - ok
12:50:42.0796 4188  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
12:50:42.0844 4188  cdfs - ok
12:50:42.0881 4188  [ 83D2D75E1EFB81B3450C18131443F7DB ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
12:50:42.0908 4188  cdrom - ok
12:50:42.0929 4188  [ 312E2F82AF11E79906898AC3E3D58A1F ] CertPropSvc    C:\Windows\System32\certprop.dll
12:50:42.0993 4188  CertPropSvc - ok
12:50:43.0003 4188  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
12:50:43.0023 4188  circlass - ok
12:50:43.0053 4188  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows\system32\CLFS.sys
12:50:43.0069 4188  CLFS - ok
12:50:43.0183 4188  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:50:43.0206 4188  clr_optimization_v2.0.50727_32 - ok
12:50:43.0264 4188  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
12:50:43.0286 4188  clr_optimization_v2.0.50727_64 - ok
12:50:43.0345 4188  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:50:43.0382 4188  clr_optimization_v4.0.30319_32 - ok
12:50:43.0430 4188  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
12:50:43.0445 4188  clr_optimization_v4.0.30319_64 - ok
12:50:43.0472 4188  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
12:50:43.0525 4188  CmBatt - ok
12:50:43.0537 4188  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows\system32\DRIVERS\cmdide.sys
12:50:43.0551 4188  cmdide - ok
12:50:43.0601 4188  [ CA7720B73446FDDEC5C69519C1174C98 ] CNG            C:\Windows\system32\Drivers\cng.sys
12:50:43.0637 4188  CNG - ok
12:50:43.0656 4188  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
12:50:43.0668 4188  Compbatt - ok
12:50:43.0692 4188  [ F26B3A86F6FA87CA360B879581AB4123 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
12:50:43.0756 4188  CompositeBus - ok
12:50:43.0761 4188  COMSysApp - ok
12:50:43.0780 4188  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk        C:\Windows\system32\DRIVERS\crcdisk.sys
12:50:43.0803 4188  crcdisk - ok
12:50:43.0839 4188  [ F02786B66375292E58C8777082D4396D ] CryptSvc        C:\Windows\system32\cryptsvc.dll
12:50:43.0893 4188  CryptSvc - ok
12:50:43.0920 4188  [ 7266972E86890E2B30C0C322E906B027 ] DcomLaunch      C:\Windows\system32\rpcss.dll
12:50:43.0984 4188  DcomLaunch - ok
12:50:44.0007 4188  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc      C:\Windows\System32\defragsvc.dll
12:50:44.0053 4188  defragsvc - ok
12:50:44.0084 4188  [ 9C253CE7311CA60FC11C774692A13208 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
12:50:44.0120 4188  DfsC - ok
12:50:44.0159 4188  [ 113212D25D0C9BB8901A9833774DA97F ] dg_ssudbus      C:\Windows\system32\DRIVERS\ssudbus.sys
12:50:44.0173 4188  dg_ssudbus - ok
12:50:44.0198 4188  [ CE3B9562D997F69B330D181A8875960F ] Dhcp            C:\Windows\system32\dhcpcore.dll
12:50:44.0282 4188  Dhcp - ok
12:50:44.0298 4188  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows\system32\drivers\discache.sys
12:50:44.0355 4188  discache - ok
12:50:44.0368 4188  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows\system32\DRIVERS\disk.sys
12:50:44.0378 4188  Disk - ok
12:50:44.0411 4188  [ 85CF424C74A1D5EC33533E1DBFF9920A ] Dnscache        C:\Windows\System32\dnsrslvr.dll
12:50:44.0466 4188  Dnscache - ok
12:50:44.0497 4188  [ 14452ACDB09B70964C8C21BF80A13ACB ] dot3svc        C:\Windows\System32\dot3svc.dll
12:50:44.0564 4188  dot3svc - ok
12:50:44.0587 4188  [ 8C2BA6BEA949EE6E68385F5692BAFB94 ] DPS            C:\Windows\system32\dps.dll
12:50:44.0635 4188  DPS - ok
12:50:44.0657 4188  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
12:50:44.0687 4188  drmkaud - ok
12:50:44.0737 4188  [ 1633B9ABF52784A1331476397A48CBEF ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
12:50:44.0778 4188  DXGKrnl - ok
12:50:44.0806 4188  EagleX64 - ok
12:50:44.0817 4188  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost        C:\Windows\System32\eapsvc.dll
12:50:44.0870 4188  EapHost - ok
12:50:44.0967 4188  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv          C:\Windows\system32\DRIVERS\evbda.sys
12:50:45.0113 4188  ebdrv - ok
12:50:45.0149 4188  [ 156F6159457D0AA7E59B62681B56EB90 ] EFS            C:\Windows\System32\lsass.exe
12:50:45.0194 4188  EFS - ok
12:50:45.0260 4188  [ 47C071994C3F649F23D9CD075AC9304A ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
12:50:45.0331 4188  ehRecvr - ok
12:50:45.0354 4188  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched        C:\Windows\ehome\ehsched.exe
12:50:45.0386 4188  ehSched - ok
12:50:45.0418 4188  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor        C:\Windows\system32\DRIVERS\elxstor.sys
12:50:45.0444 4188  elxstor - ok
12:50:45.0462 4188  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows\system32\DRIVERS\errdev.sys
12:50:45.0506 4188  ErrDev - ok
12:50:45.0549 4188  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem    C:\Windows\system32\es.dll
12:50:45.0608 4188  EventSystem - ok
12:50:45.0621 4188  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat          C:\Windows\system32\drivers\exfat.sys
12:50:45.0663 4188  exfat - ok
12:50:45.0683 4188  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat        C:\Windows\system32\drivers\fastfat.sys
12:50:45.0717 4188  fastfat - ok
12:50:45.0737 4188  [ D607B2F1BEE3992AA6C2C92C0A2F0855 ] Fax            C:\Windows\system32\fxssvc.exe
12:50:45.0787 4188  Fax - ok
12:50:45.0803 4188  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
12:50:45.0843 4188  fdc - ok
12:50:45.0864 4188  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost        C:\Windows\system32\fdPHost.dll
12:50:45.0912 4188  fdPHost - ok
12:50:45.0930 4188  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
12:50:45.0960 4188  FDResPub - ok
12:50:45.0971 4188  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
12:50:45.0981 4188  FileInfo - ok
12:50:45.0995 4188  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
12:50:46.0049 4188  Filetrace - ok
12:50:46.0082 4188  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
12:50:46.0112 4188  flpydisk - ok
12:50:46.0137 4188  [ F7866AF72ABBAF84B1FA5AA195378C59 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
12:50:46.0157 4188  FltMgr - ok
12:50:46.0192 4188  [ CB5E4B9C319E3C6BB363EB7E58A4A051 ] FontCache      C:\Windows\system32\FntCache.dll
12:50:46.0242 4188  FontCache - ok
12:50:46.0290 4188  [ 8D89E3131C27FDD6932189CB785E1B7A ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:50:46.0308 4188  FontCache3.0.0.0 - ok
12:50:46.0331 4188  [ D43703496149971890703B4B1B723EAC ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
12:50:46.0346 4188  FsDepends - ok
12:50:46.0361 4188  [ D3E3F93D67821A2DB2B3D9FAC2DC2064 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
12:50:46.0371 4188  Fs_Rec - ok
12:50:46.0391 4188  [ AE87BA80D0EC3B57126ED2CDC15B24ED ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
12:50:46.0405 4188  fvevol - ok
12:50:46.0417 4188  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
12:50:46.0427 4188  gagp30kx - ok
12:50:46.0452 4188  gdrv - ok
12:50:46.0481 4188  [ FE5AB4525BC2EC68B9119A6E5D40128B ] gpsvc          C:\Windows\System32\gpsvc.dll
12:50:46.0527 4188  gpsvc - ok
12:50:46.0541 4188  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
12:50:46.0580 4188  hcw85cir - ok
12:50:46.0593 4188  [ 6410F6F415B2A5A9037224C41DA8BF12 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
12:50:46.0632 4188  HdAudAddService - ok
12:50:46.0650 4188  [ 0A49913402747A0B67DE940FB42CBDBB ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
12:50:46.0681 4188  HDAudBus - ok
12:50:46.0695 4188  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt        C:\Windows\system32\DRIVERS\HidBatt.sys
12:50:46.0713 4188  HidBatt - ok
12:50:46.0728 4188  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
12:50:46.0753 4188  HidBth - ok
12:50:46.0770 4188  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr          C:\Windows\system32\DRIVERS\hidir.sys
12:50:46.0803 4188  HidIr - ok
12:50:46.0815 4188  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv        C:\Windows\system32\hidserv.dll
12:50:46.0849 4188  hidserv - ok
12:50:46.0892 4188  [ B3BF6B5B50006DEF50B66306D99FCF6F ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
12:50:46.0914 4188  HidUsb - ok
12:50:46.0934 4188  [ EFA58EDE58DD74388FFD04CB32681518 ] hkmsvc          C:\Windows\system32\kmsvc.dll
12:50:46.0991 4188  hkmsvc - ok
12:50:47.0016 4188  [ 046B2673767CA626E2CFB7FDF735E9E8 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
12:50:47.0065 4188  HomeGroupListener - ok
12:50:47.0094 4188  [ 06A7422224D9865A5613710A089987DF ] HomeGroupProvider C:\Windows\system32\provsvc.dll
12:50:47.0122 4188  HomeGroupProvider - ok
12:50:47.0135 4188  [ 0886D440058F203EBA0E1825E4355914 ] HpSAMD          C:\Windows\system32\DRIVERS\HpSAMD.sys
12:50:47.0148 4188  HpSAMD - ok
12:50:47.0175 4188  [ CEE049CAC4EFA7F4E1E4AD014414A5D4 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
12:50:47.0224 4188  HTTP - ok
12:50:47.0238 4188  [ F17766A19145F111856378DF337A5D79 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
12:50:47.0247 4188  hwpolicy - ok
12:50:47.0270 4188  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
12:50:47.0283 4188  i8042prt - ok
12:50:47.0308 4188  [ B75E45C564E944A2657167D197AB29DA ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
12:50:47.0325 4188  iaStorV - ok
12:50:47.0374 4188  [ 2F2BE70D3E02B6FA877921AB9516D43C ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
12:50:47.0400 4188  idsvc - ok
12:50:47.0411 4188  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp          C:\Windows\system32\DRIVERS\iirsp.sys
12:50:47.0421 4188  iirsp - ok
12:50:47.0459 4188  [ C5B4683680DF085B57BC53E5EF34861F ] IKEEXT          C:\Windows\System32\ikeext.dll
12:50:47.0504 4188  IKEEXT - ok
12:50:47.0563 4188  [ 163F94EBF8F8A98616A6B804AF08D736 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
12:50:47.0645 4188  IntcAzAudAddService - ok
12:50:47.0667 4188  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows\system32\DRIVERS\intelide.sys
12:50:47.0677 4188  intelide - ok
12:50:47.0699 4188  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
12:50:47.0730 4188  intelppm - ok
12:50:47.0755 4188  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
12:50:47.0805 4188  IPBusEnum - ok
12:50:47.0815 4188  [ 722DD294DF62483CECAAE6E094B4D695 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:50:47.0853 4188  IpFilterDriver - ok
12:50:47.0875 4188  [ F8E058D17363EC580E4B7232778B6CB5 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
12:50:47.0931 4188  iphlpsvc - ok
12:50:47.0945 4188  [ E2B4A4494DB7CB9B89B55CA268C337C5 ] IPMIDRV        C:\Windows\system32\DRIVERS\IPMIDrv.sys
12:50:47.0956 4188  IPMIDRV - ok
12:50:47.0967 4188  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
12:50:48.0011 4188  IPNAT - ok
12:50:48.0027 4188  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
12:50:48.0053 4188  IRENUM - ok
12:50:48.0061 4188  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows\system32\DRIVERS\isapnp.sys
12:50:48.0071 4188  isapnp - ok
12:50:48.0092 4188  [ FA4D2557DE56D45B0A346F93564BE6E1 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
12:50:48.0105 4188  iScsiPrt - ok
12:50:48.0185 4188  [ F3A41EC4C6506E76E07A219B3A1DF8D2 ] JMB36X          C:\Windows\SysWOW64\XSrvSetup.exe
12:50:48.0200 4188  JMB36X - ok
12:50:48.0213 4188  [ 1C368C1A2733DCC5B8E15420AA2B0F6D ] JRAID          C:\Windows\system32\DRIVERS\jraid.sys
12:50:48.0228 4188  JRAID - ok
12:50:48.0249 4188  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
12:50:48.0266 4188  kbdclass - ok
12:50:48.0288 4188  [ 6DEF98F8541E1B5DCEB2C822A11F7323 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
12:50:48.0341 4188  kbdhid - ok
12:50:48.0365 4188  [ 156F6159457D0AA7E59B62681B56EB90 ] KeyIso          C:\Windows\system32\lsass.exe
12:50:48.0391 4188  KeyIso - ok
12:50:48.0429 4188  [ E656FE10D6D27794AFA08136685A69E8 ] KL1            C:\Windows\system32\DRIVERS\kl1.sys
12:50:48.0450 4188  KL1 - ok
12:50:48.0459 4188  [ D865DD8B0448E3F963D68C04C532858F ] kl2            C:\Windows\system32\DRIVERS\kl2.sys
12:50:48.0467 4188  kl2 - ok
12:50:48.0505 4188  [ C7D4F357C482DD37E2B05F34093B7B0C ] KLIF            C:\Windows\system32\DRIVERS\klif.sys
12:50:48.0525 4188  KLIF - ok
12:50:48.0564 4188  [ 89FB5A33D7171B6D84F5EB721D5055E1 ] KLIM6          C:\Windows\system32\DRIVERS\klim6.sys
12:50:48.0573 4188  KLIM6 - ok
12:50:48.0589 4188  [ 9468D07E91BA136D82415F5DFC1FE168 ] klmouflt        C:\Windows\system32\DRIVERS\klmouflt.sys
12:50:48.0599 4188  klmouflt - ok
12:50:48.0621 4188  [ 4F4B5FDE429416877DE7143044582EB5 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
12:50:48.0634 4188  KSecDD - ok
12:50:48.0653 4188  [ 6F40465A44ECDC1731BEFAFEC5BDD03C ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
12:50:48.0667 4188  KSecPkg - ok
12:50:48.0686 4188  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
12:50:48.0793 4188  ksthunk - ok
12:50:48.0824 4188  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm          C:\Windows\system32\msdtckrm.dll
12:50:48.0872 4188  KtmRm - ok
12:50:48.0901 4188  [ 81F1D04D4D0E433099365127375FD501 ] LanmanServer    C:\Windows\system32\srvsvc.dll
12:50:48.0927 4188  LanmanServer - ok
12:50:48.0956 4188  [ 27026EAC8818E8A6C00A1CAD2F11D29A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
12:50:48.0998 4188  LanmanWorkstation - ok
12:50:49.0010 4188  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
12:50:49.0051 4188  lltdio - ok
12:50:49.0085 4188  [ C1185803384AB3FEED115F79F109427F ] lltdsvc        C:\Windows\System32\lltdsvc.dll
12:50:49.0153 4188  lltdsvc - ok
12:50:49.0176 4188  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts        C:\Windows\System32\lmhsvc.dll
12:50:49.0207 4188  lmhosts - ok
12:50:49.0231 4188  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
12:50:49.0242 4188  LSI_FC - ok
12:50:49.0266 4188  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS        C:\Windows\system32\DRIVERS\lsi_sas.sys
12:50:49.0277 4188  LSI_SAS - ok
12:50:49.0296 4188  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
12:50:49.0306 4188  LSI_SAS2 - ok
12:50:49.0318 4188  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
12:50:49.0331 4188  LSI_SCSI - ok
12:50:49.0346 4188  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv          C:\Windows\system32\drivers\luafv.sys
12:50:49.0401 4188  luafv - ok
12:50:49.0553 4188  [ 5747BC465ABEA2858C5D037252AED84E ] LVUVC64        C:\Windows\system32\DRIVERS\lvuvc64.sys
12:50:49.0727 4188  LVUVC64 - ok
12:50:49.0760 4188  [ B9FC4CCE5758B816F27DD4D1EED11841 ] MBAMProtector  C:\Windows\system32\drivers\mbam.sys
12:50:49.0769 4188  MBAMProtector - ok
12:50:49.0822 4188  [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
12:50:49.0849 4188  MBAMScheduler - ok
12:50:49.0871 4188  [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
12:50:49.0888 4188  MBAMService - ok
12:50:49.0905 4188  [ F84C8F1000BC11E3B7B23CBD3BAFF111 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
12:50:49.0928 4188  Mcx2Svc - ok
12:50:49.0939 4188  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas        C:\Windows\system32\DRIVERS\megasas.sys
12:50:49.0951 4188  megasas - ok
12:50:49.0969 4188  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
12:50:49.0983 4188  MegaSR - ok
12:50:50.0002 4188  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS          C:\Windows\system32\mmcss.dll
12:50:50.0055 4188  MMCSS - ok
12:50:50.0067 4188  [ 800BA92F7010378B09F9ED9270F07137 ] Modem          C:\Windows\system32\drivers\modem.sys
12:50:50.0113 4188  Modem - ok
12:50:50.0134 4188  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
12:50:50.0149 4188  monitor - ok
12:50:50.0164 4188  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
12:50:50.0175 4188  mouclass - ok
12:50:50.0197 4188  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
12:50:50.0210 4188  mouhid - ok
12:50:50.0242 4188  [ 791AF66C4D0E7C90A3646066386FB571 ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
12:50:50.0255 4188  mountmgr - ok
12:50:50.0296 4188  [ 15D5398EED42C2504BB3D4FC875C15D1 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
12:50:50.0310 4188  MozillaMaintenance - ok
12:50:50.0330 4188  [ 609D1D87649ECC19796F4D76D4C15CEA ] mpio            C:\Windows\system32\DRIVERS\mpio.sys
12:50:50.0346 4188  mpio - ok
12:50:50.0363 4188  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
12:50:50.0405 4188  mpsdrv - ok
12:50:50.0425 4188  [ AECAB449567D1846DAD63ECE49E893E3 ] MpsSvc          C:\Windows\system32\mpssvc.dll
12:50:50.0467 4188  MpsSvc - ok
12:50:50.0471 4188  [ 30524261BB51D96D6FCBAC20C810183C ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
12:50:50.0500 4188  MRxDAV - ok
12:50:50.0527 4188  [ 040D62A9D8AD28922632137ACDD984F2 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
12:50:50.0580 4188  mrxsmb - ok
12:50:50.0606 4188  [ F0067552F8F9B33D7C59403AB808A3CB ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:50:50.0627 4188  mrxsmb10 - ok
12:50:50.0643 4188  [ 3C142D31DE9F2F193218A53FE2632051 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:50:50.0672 4188  mrxsmb20 - ok
12:50:50.0685 4188  [ 5C37497276E3B3A5488B23A326A754B7 ] msahci          C:\Windows\system32\DRIVERS\msahci.sys
12:50:50.0701 4188  msahci - ok
12:50:50.0705 4188  [ 8D27B597229AED79430FB9DB3BCBFBD0 ] msdsm          C:\Windows\system32\DRIVERS\msdsm.sys
12:50:50.0717 4188  msdsm - ok
12:50:50.0739 4188  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC          C:\Windows\System32\msdtc.exe
12:50:50.0770 4188  MSDTC - ok
12:50:50.0794 4188  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
12:50:50.0842 4188  Msfs - ok
12:50:50.0857 4188  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
12:50:50.0896 4188  mshidkmdf - ok
12:50:50.0908 4188  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows\system32\DRIVERS\msisadrv.sys
12:50:50.0918 4188  msisadrv - ok
12:50:50.0941 4188  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
12:50:50.0975 4188  MSiSCSI - ok
12:50:50.0978 4188  msiserver - ok
12:50:51.0003 4188  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
12:50:51.0052 4188  MSKSSRV - ok
12:50:51.0066 4188  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
12:50:51.0110 4188  MSPCLOCK - ok
12:50:51.0142 4188  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
12:50:51.0175 4188  MSPQM - ok
12:50:51.0201 4188  [ 89CB141AA8616D8C6A4610FA26C60964 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
12:50:51.0216 4188  MsRPC - ok
12:50:51.0235 4188  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
12:50:51.0244 4188  mssmbios - ok
12:50:51.0247 4188  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
12:50:51.0278 4188  MSTEE - ok
12:50:51.0288 4188  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
12:50:51.0298 4188  MTConfig - ok
12:50:51.0317 4188  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup            C:\Windows\system32\Drivers\mup.sys
12:50:51.0326 4188  Mup - ok
12:50:51.0357 4188  [ 4987E079A4530FA737A128BE54B63B12 ] napagent        C:\Windows\system32\qagentRT.dll
12:50:51.0419 4188  napagent - ok
12:50:51.0438 4188  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
12:50:51.0455 4188  NativeWifiP - ok
12:50:51.0478 4188  [ CAD515DBD07D082BB317D9928CE8962C ] NDIS            C:\Windows\system32\drivers\ndis.sys
12:50:51.0503 4188  NDIS - ok
12:50:51.0536 4188  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
12:50:51.0567 4188  NdisCap - ok
12:50:51.0589 4188  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
12:50:51.0636 4188  NdisTapi - ok
12:50:51.0657 4188  [ F105BA1E22BF1F2EE8F005D4305E4BEC ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
12:50:51.0688 4188  Ndisuio - ok
12:50:51.0709 4188  [ 557DFAB9CA1FCB036AC77564C010DAD3 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
12:50:51.0740 4188  NdisWan - ok
12:50:51.0746 4188  [ 659B74FB74B86228D6338D643CD3E3CF ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
12:50:51.0776 4188  NDProxy - ok
12:50:51.0783 4188  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
12:50:51.0826 4188  NetBIOS - ok
12:50:51.0850 4188  [ 9162B273A44AB9DCE5B44362731D062A ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
12:50:51.0918 4188  NetBT - ok
12:50:51.0929 4188  [ 156F6159457D0AA7E59B62681B56EB90 ] Netlogon        C:\Windows\system32\lsass.exe
12:50:51.0939 4188  Netlogon - ok
12:50:51.0972 4188  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows\System32\netman.dll
12:50:52.0024 4188  Netman - ok
12:50:52.0040 4188  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows\System32\netprofm.dll
12:50:52.0077 4188  netprofm - ok
12:50:52.0100 4188  [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:50:52.0109 4188  NetTcpPortSharing - ok
12:50:52.0124 4188  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960        C:\Windows\system32\DRIVERS\nfrd960.sys
12:50:52.0134 4188  nfrd960 - ok
12:50:52.0139 4188  [ D9A0CE66046D6EFA0C61BAA885CBA0A8 ] NlaSvc          C:\Windows\System32\nlasvc.dll
12:50:52.0175 4188  NlaSvc - ok
12:50:52.0194 4188  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
12:50:52.0242 4188  Npfs - ok
12:50:52.0263 4188  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi            C:\Windows\system32\nsisvc.dll
12:50:52.0308 4188  nsi - ok
12:50:52.0325 4188  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
12:50:52.0367 4188  nsiproxy - ok
12:50:52.0430 4188  [ 378E0E0DFEA67D98AE6EA53ADBBD76BC ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
12:50:52.0484 4188  Ntfs - ok
12:50:52.0499 4188  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows\system32\drivers\Null.sys
12:50:52.0537 4188  Null - ok
12:50:52.0583 4188  [ F5BC2345E8C89D4E90FAFD23A2239935 ] nusb3hub        C:\Windows\system32\DRIVERS\nusb3hub.sys
12:50:52.0621 4188  nusb3hub - ok
12:50:52.0643 4188  [ 5D42578241BC2A9B4A64837077436D5F ] nusb3xhc        C:\Windows\system32\DRIVERS\nusb3xhc.sys
12:50:52.0665 4188  nusb3xhc - ok
12:50:52.0721 4188  [ 102806B360D0E6BC6E55BF47EF655D43 ] NVHDA          C:\Windows\system32\drivers\nvhda64v.sys
12:50:52.0745 4188  NVHDA - ok
12:50:53.0015 4188  [ BA0B4889C40380A01ECDF84C227A89C9 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
12:50:53.0376 4188  nvlddmkm - ok
12:50:53.0422 4188  [ A4D9C9A608A97F59307C2F2600EDC6A4 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
12:50:53.0434 4188  nvraid - ok
12:50:53.0456 4188  [ 6C1D5F70E7A6A3FD1C90D840EDC048B9 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
12:50:53.0470 4188  nvstor - ok
12:50:53.0538 4188  [ 06633CF95BEA62164C3BFCA24BCE6B11 ] NVSvc          C:\Windows\system32\nvvsvc.exe
12:50:53.0561 4188  NVSvc - ok
12:50:53.0624 4188  [ 53B629CE436B110C5689C2F6439E567B ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
12:50:53.0671 4188  nvUpdatusService - ok
12:50:53.0697 4188  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows\system32\DRIVERS\nv_agp.sys
12:50:53.0709 4188  nv_agp - ok
12:50:53.0728 4188  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
12:50:53.0742 4188  ohci1394 - ok
12:50:53.0776 4188  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
12:50:53.0819 4188  p2pimsvc - ok
12:50:53.0845 4188  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows\system32\p2psvc.dll
12:50:53.0884 4188  p2psvc - ok
12:50:53.0909 4188  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport        C:\Windows\system32\DRIVERS\parport.sys
12:50:53.0944 4188  Parport - ok
12:50:53.0973 4188  [ 90061B1ACFE8CCAA5345750FFE08D8B8 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
12:50:53.0990 4188  partmgr - ok
12:50:54.0012 4188  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
12:50:54.0043 4188  PcaSvc - ok
12:50:54.0061 4188  [ F36F6504009F2FB0DFD1B17A116AD74B ] pci            C:\Windows\system32\DRIVERS\pci.sys
12:50:54.0075 4188  pci - ok
12:50:54.0084 4188  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows\system32\DRIVERS\pciide.sys
12:50:54.0095 4188  pciide - ok
12:50:54.0099 4188  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
12:50:54.0112 4188  pcmcia - ok
12:50:54.0126 4188  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw            C:\Windows\system32\drivers\pcw.sys
12:50:54.0136 4188  pcw - ok
12:50:54.0153 4188  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
12:50:54.0192 4188  PEAUTH - ok
12:50:54.0211 4188  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
12:50:54.0239 4188  PerfHost - ok
12:50:54.0286 4188  [ 557E9A86F65F0DE18C9B6751DFE9D3F1 ] pla            C:\Windows\system32\pla.dll
12:50:54.0349 4188  pla - ok
12:50:54.0406 4188  [ 98B1721B8718164293B9701B98C52D77 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
12:50:54.0443 4188  PlugPlay - ok
12:50:54.0447 4188  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
12:50:54.0461 4188  PNRPAutoReg - ok
12:50:54.0468 4188  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
12:50:54.0484 4188  PNRPsvc - ok
12:50:54.0525 4188  [ 166EB40D1F5B47E615DE3D0FFFE5F243 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
12:50:54.0588 4188  PolicyAgent - ok
12:50:54.0603 4188  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power          C:\Windows\system32\umpo.dll
12:50:54.0656 4188  Power - ok
12:50:54.0683 4188  [ 27CC19E81BA5E3403C48302127BDA717 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
12:50:54.0727 4188  PptpMiniport - ok
12:50:54.0743 4188  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor      C:\Windows\system32\DRIVERS\processr.sys
12:50:54.0760 4188  Processor - ok
12:50:54.0793 4188  [ 97293447431311C06703368AD0F6C4BE ] ProfSvc        C:\Windows\system32\profsvc.dll
12:50:54.0826 4188  ProfSvc - ok
12:50:54.0830 4188  [ 156F6159457D0AA7E59B62681B56EB90 ] ProtectedStorage C:\Windows\system32\lsass.exe
12:50:54.0843 4188  ProtectedStorage - ok
12:50:54.0868 4188  [ EE992183BD8EAEFD9973F352E587A299 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
12:50:54.0921 4188  Psched - ok
12:50:54.0974 4188  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
12:50:55.0036 4188  ql2300 - ok
12:50:55.0041 4188  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
12:50:55.0053 4188  ql40xx - ok
12:50:55.0069 4188  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE          C:\Windows\system32\qwave.dll
12:50:55.0087 4188  QWAVE - ok
12:50:55.0090 4188  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
12:50:55.0117 4188  QWAVEdrv - ok
12:50:55.0128 4188  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
12:50:55.0160 4188  RasAcd - ok
12:50:55.0193 4188  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
12:50:55.0245 4188  RasAgileVpn - ok
12:50:55.0255 4188  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto        C:\Windows\System32\rasauto.dll
12:50:55.0305 4188  RasAuto - ok
12:50:55.0317 4188  [ 87A6E852A22991580D6D39ADC4790463 ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
12:50:55.0375 4188  Rasl2tp - ok
12:50:55.0411 4188  [ 47394ED3D16D053F5906EFE5AB51CC83 ] RasMan          C:\Windows\System32\rasmans.dll
12:50:55.0471 4188  RasMan - ok
12:50:55.0487 4188  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
12:50:55.0534 4188  RasPppoe - ok
12:50:55.0583 4188  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
12:50:55.0633 4188  RasSstp - ok
12:50:55.0655 4188  [ 3BAC8142102C15D59A87757C1D41DCE5 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
12:50:55.0716 4188  rdbss - ok
12:50:55.0757 4188  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
12:50:55.0791 4188  rdpbus - ok
12:50:55.0829 4188  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
12:50:55.0883 4188  RDPCDD - ok
12:50:55.0906 4188  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
12:50:55.0937 4188  RDPENCDD - ok
12:50:55.0953 4188  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
12:50:55.0985 4188  RDPREFMP - ok
12:50:56.0031 4188  [ 447DE7E3DEA39D422C1504F245B668B1 ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
12:50:56.0074 4188  RDPWD - ok
12:50:56.0099 4188  [ 634B9A2181D98F15941236886164EC8B ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
12:50:56.0121 4188  rdyboost - ok
12:50:56.0150 4188  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
12:50:56.0194 4188  RemoteAccess - ok
12:50:56.0214 4188  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
12:50:56.0253 4188  RemoteRegistry - ok
12:50:56.0273 4188  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
12:50:56.0334 4188  RpcEptMapper - ok
12:50:56.0355 4188  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows\system32\locator.exe
12:50:56.0384 4188  RpcLocator - ok
12:50:56.0400 4188  [ 7266972E86890E2B30C0C322E906B027 ] RpcSs          C:\Windows\system32\rpcss.dll
12:50:56.0439 4188  RpcSs - ok
12:50:56.0443 4188  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
12:50:56.0483 4188  rspndr - ok
12:50:56.0513 4188  [ 7EA8D2EB9BBFD2AB8A3117A1E96D3B3A ] RTL8167        C:\Windows\system32\DRIVERS\Rt64win7.sys
12:50:56.0526 4188  RTL8167 - ok
12:50:56.0537 4188  [ 156F6159457D0AA7E59B62681B56EB90 ] SamSs          C:\Windows\system32\lsass.exe
12:50:56.0548 4188  SamSs - ok
12:50:56.0567 4188  [ E3BBB89983DAF5622C1D50CF49F28227 ] sbp2port        C:\Windows\system32\DRIVERS\sbp2port.sys
12:50:56.0578 4188  sbp2port - ok
12:50:56.0604 4188  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows\System32\SCardSvr.dll
12:50:56.0661 4188  SCardSvr - ok
12:50:56.0673 4188  [ C94DA20C7E3BA1DCA269BC8460D98387 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
12:50:56.0734 4188  scfilter - ok
12:50:56.0781 4188  [ 624D0F5FF99428BB90A5B8A4123E918E ] Schedule        C:\Windows\system32\schedsvc.dll
12:50:56.0822 4188  Schedule - ok
12:50:56.0834 4188  [ 312E2F82AF11E79906898AC3E3D58A1F ] SCPolicySvc    C:\Windows\System32\certprop.dll
12:50:56.0866 4188  SCPolicySvc - ok
12:50:56.0882 4188  [ 765A27C3279CE11D14CB9E4F5869FCA5 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
12:50:56.0905 4188  SDRSVC - ok
12:50:56.0915 4188  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
12:50:56.0945 4188  secdrv - ok
12:50:56.0963 4188  [ 463B386EBC70F98DA5DFF85F7E654346 ] seclogon        C:\Windows\system32\seclogon.dll
12:50:57.0001 4188  seclogon - ok
12:50:57.0030 4188  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows\System32\sens.dll
12:50:57.0081 4188  SENS - ok
12:50:57.0084 4188  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
12:50:57.0105 4188  SensrSvc - ok
12:50:57.0140 4188  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum        C:\Windows\system32\DRIVERS\serenum.sys
12:50:57.0151 4188  Serenum - ok
12:50:57.0169 4188  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
12:50:57.0183 4188  Serial - ok
12:50:57.0211 4188  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
12:50:57.0237 4188  sermouse - ok
12:50:57.0264 4188  [ C3BC61CE47FF6F4E88AB8A3B429A36AF ] SessionEnv      C:\Windows\system32\sessenv.dll
12:50:57.0305 4188  SessionEnv - ok
12:50:57.0315 4188  [ A554811BCD09279536440C964AE35BBF ] sffdisk        C:\Windows\system32\DRIVERS\sffdisk.sys
12:50:57.0343 4188  sffdisk - ok
12:50:57.0358 4188  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows\system32\DRIVERS\sffp_mmc.sys
12:50:57.0381 4188  sffp_mmc - ok
12:50:57.0392 4188  [ 178298F767FE638C9FEDCBDEF58BB5E4 ] sffp_sd        C:\Windows\system32\DRIVERS\sffp_sd.sys
12:50:57.0415 4188  sffp_sd - ok
12:50:57.0433 4188  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy        C:\Windows\system32\DRIVERS\sfloppy.sys
12:50:57.0452 4188  sfloppy - ok
12:50:57.0477 4188  [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess    C:\Windows\System32\ipnathlp.dll
12:50:57.0535 4188  SharedAccess - ok
12:50:57.0560 4188  [ 0298AC45D0EFFFB2DB4BAA7DD186E7BF ] ShellHWDetection C:\Windows\System32\shsvcs.dll
12:50:57.0591 4188  ShellHWDetection - ok
12:50:57.0603 4188  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
12:50:57.0613 4188  SiSRaid2 - ok
12:50:57.0628 4188  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
12:50:57.0638 4188  SiSRaid4 - ok
12:50:57.0668 4188  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
12:50:57.0711 4188  Smb - ok
12:50:57.0734 4188  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
12:50:57.0774 4188  SNMPTRAP - ok
12:50:57.0792 4188  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr          C:\Windows\system32\drivers\spldr.sys
12:50:57.0805 4188  spldr - ok
12:50:57.0837 4188  [ 567977DC43CC13C4C35ED7084C0B84D5 ] Spooler        C:\Windows\System32\spoolsv.exe
12:50:57.0872 4188  Spooler - ok
12:50:57.0959 4188  [ 913D843498553A1BC8F8DBAD6358E49F ] sppsvc          C:\Windows\system32\sppsvc.exe
12:50:58.0123 4188  sppsvc - ok
12:50:58.0202 4188  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify    C:\Windows\system32\sppuinotify.dll
12:50:58.0340 4188  sppuinotify - ok
12:50:58.0377 4188  [ 2408C0366D96BCDF63E8F1C78E4A29C5 ] srv            C:\Windows\system32\DRIVERS\srv.sys
12:50:58.0406 4188  srv - ok
12:50:58.0440 4188  [ 76548F7B818881B47D8D1AE1BE9C11F8 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
12:50:58.0461 4188  srv2 - ok
12:50:58.0498 4188  [ 0AF6E19D39C70844C5CAA8FB0183C36E ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
12:50:58.0521 4188  srvnet - ok
12:50:58.0561 4188  [ ED161B91FDF7EAA39469D72D463D5F4E ] sscdbus        C:\Windows\system32\DRIVERS\sscdbus.sys
12:50:58.0573 4188  sscdbus - ok
12:50:58.0603 4188  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
12:50:58.0662 4188  SSDPSRV - ok
12:50:58.0678 4188  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc        C:\Windows\system32\sstpsvc.dll
12:50:58.0732 4188  SstpSvc - ok
12:50:58.0777 4188  [ 855335BF5792E56164F98C012E3D92DD ] ssudmdm        C:\Windows\system32\DRIVERS\ssudmdm.sys
12:50:58.0790 4188  ssudmdm - ok
12:50:58.0872 4188  [ C354621B6B94E10AE7F5CDBE745FEB86 ] Stereo Service  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
12:50:58.0891 4188  Stereo Service - ok
12:50:58.0909 4188  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
12:50:58.0919 4188  stexstor - ok
12:50:58.0946 4188  [ 52D0E33B681BD0F33FDC08812FEE4F7D ] stisvc          C:\Windows\System32\wiaservc.dll
12:50:58.0986 4188  stisvc - ok
12:50:59.0003 4188  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
12:50:59.0013 4188  swenum - ok
12:50:59.0035 4188  [ E08E46FDD841B7184194011CA1955A0B ] swprv          C:\Windows\System32\swprv.dll
12:50:59.0106 4188  swprv - ok
12:50:59.0154 4188  [ 3C1284516A62078FB68F768DE4F1A7BE ] SysMain        C:\Windows\system32\sysmain.dll
12:50:59.0216 4188  SysMain - ok
12:50:59.0230 4188  [ 238935C3CF2854886DC7CBB2A0E2CC66 ] TabletInputService C:\Windows\System32\TabSvc.dll
12:50:59.0258 4188  TabletInputService - ok
12:50:59.0282 4188  [ 884264AC597B690C5707C89723BB8E7B ] TapiSrv        C:\Windows\System32\tapisrv.dll
12:50:59.0335 4188  TapiSrv - ok
12:50:59.0368 4188  TBPanel - ok
12:50:59.0385 4188  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS            C:\Windows\System32\tbssvc.dll
12:50:59.0423 4188  TBS - ok
12:50:59.0494 4188  [ 624C5B3AA4C99B3184BB922D9ECE3FF0 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
12:50:59.0575 4188  Tcpip - ok
12:50:59.0600 4188  [ 624C5B3AA4C99B3184BB922D9ECE3FF0 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
12:50:59.0632 4188  TCPIP6 - ok
12:50:59.0646 4188  [ 76D078AF6F587B162D50210F761EB9ED ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
12:50:59.0688 4188  tcpipreg - ok
12:50:59.0709 4188  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
12:50:59.0759 4188  TDPIPE - ok
12:50:59.0777 4188  [ 7518F7BCFD4B308ABC9192BACAF6C970 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
12:50:59.0813 4188  TDTCP - ok
12:50:59.0832 4188  [ 079125C4B17B01FCAEEBCE0BCB290C0F ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
12:50:59.0870 4188  tdx - ok
12:50:59.0877 4188  [ C448651339196C0E869A355171875522 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
12:50:59.0888 4188  TermDD - ok
12:50:59.0914 4188  [ 0F05EC2887BFE197AD82A13287D2F404 ] TermService    C:\Windows\System32\termsrv.dll
12:50:59.0967 4188  TermService - ok
12:50:59.0985 4188  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows\system32\themeservice.dll
12:51:00.0013 4188  Themes - ok
12:51:00.0034 4188  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER    C:\Windows\system32\mmcss.dll
12:51:00.0067 4188  THREADORDER - ok
12:51:00.0078 4188  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows\System32\trkwks.dll
12:51:00.0112 4188  TrkWks - ok
12:51:00.0162 4188  [ 840F7FB849F5887A49BA18C13B2DA920 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
12:51:00.0212 4188  TrustedInstaller - ok
12:51:00.0225 4188  [ 61B96C26131E37B24E93327A0BD1FB95 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
12:51:00.0260 4188  tssecsrv - ok
12:51:00.0292 4188  [ 3836171A2CDF3AF8EF10856DB9835A70 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
12:51:00.0341 4188  tunnel - ok
12:51:00.0354 4188  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
12:51:00.0365 4188  uagp35 - ok
12:51:00.0388 4188  [ D47BAEAD86C65D4F4069D7CE0A4EDCEB ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
12:51:00.0431 4188  udfs - ok
12:51:00.0453 4188  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
12:51:00.0465 4188  UI0Detect - ok
12:51:00.0485 4188  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows\system32\DRIVERS\uliagpkx.sys
12:51:00.0496 4188  uliagpkx - ok
12:51:00.0554 4188  [ 694BCF23662F97D987CF4C6739C35F8B ] UltraMonUtility C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys
12:51:00.0567 4188  UltraMonUtility - ok
12:51:00.0596 4188  [ EAB6C35E62B1B0DB0D1B48B671D3A117 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
12:51:00.0617 4188  umbus - ok
12:51:00.0654 4188  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
12:51:00.0698 4188  UmPass - ok
12:51:00.0719 4188  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows\System32\upnphost.dll
12:51:00.0778 4188  upnphost - ok
12:51:00.0825 4188  [ 77B01BC848298223A95D4EC23E1785A1 ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
12:51:00.0846 4188  usbaudio - ok
12:51:00.0869 4188  [ 7B6A127C93EE590E4D79A5F2A76FE46F ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
12:51:00.0904 4188  usbccgp - ok
12:51:00.0925 4188  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows\system32\DRIVERS\usbcir.sys
12:51:00.0955 4188  usbcir - ok
12:51:00.0968 4188  [ 92969BA5AC44E229C55A332864F79677 ] usbehci        C:\Windows\system32\drivers\usbehci.sys
12:51:00.0983 4188  usbehci - ok
12:51:00.0997 4188  [ E7DF1CFD28CA86B35EF5ADD0735CEEF3 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
12:51:01.0018 4188  usbhub - ok
12:51:01.0055 4188  [ F1BB1E55F1E7A65C5839CCC7B36D773E ] usbohci        C:\Windows\system32\drivers\usbohci.sys
12:51:01.0080 4188  usbohci - ok
12:51:01.0090 4188  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
12:51:01.0119 4188  usbprint - ok
12:51:01.0149 4188  [ F39983647BC1F3E6100778DDFE9DCE29 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:51:01.0183 4188  USBSTOR - ok
12:51:01.0190 4188  [ BC3070350A491D84B518D7CCA9ABD36F ] usbuhci        C:\Windows\system32\drivers\usbuhci.sys
12:51:01.0220 4188  usbuhci - ok
12:51:01.0245 4188  [ 7CB8C573C6E4A2714402CC0A36EAB4FE ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
12:51:01.0297 4188  usbvideo - ok
12:51:01.0313 4188  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms          C:\Windows\System32\uxsms.dll
12:51:01.0361 4188  UxSms - ok
12:51:01.0385 4188  [ 156F6159457D0AA7E59B62681B56EB90 ] VaultSvc        C:\Windows\system32\lsass.exe
12:51:01.0397 4188  VaultSvc - ok
12:51:01.0408 4188  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows\system32\DRIVERS\vdrvroot.sys
12:51:01.0418 4188  vdrvroot - ok
12:51:01.0432 4188  [ 44D73E0BBC1D3C8981304BA15135C2F2 ] vds            C:\Windows\System32\vds.exe
12:51:01.0468 4188  vds - ok
12:51:01.0479 4188  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
12:51:01.0493 4188  vga - ok
12:51:01.0502 4188  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave        C:\Windows\System32\drivers\vga.sys
12:51:01.0547 4188  VgaSave - ok
12:51:01.0567 4188  [ C82E748660F62A242B2DFAC1442F22A4 ] vhdmp          C:\Windows\system32\DRIVERS\vhdmp.sys
12:51:01.0581 4188  vhdmp - ok
12:51:01.0592 4188  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows\system32\DRIVERS\viaide.sys
12:51:01.0602 4188  viaide - ok
12:51:01.0617 4188  [ 2B1A3DAE2B4E70DBBA822B7A03FBD4A3 ] volmgr          C:\Windows\system32\DRIVERS\volmgr.sys
12:51:01.0627 4188  volmgr - ok
12:51:01.0648 4188  [ 99B0CBB569CA79ACAED8C91461D765FB ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
12:51:01.0663 4188  volmgrx - ok
12:51:01.0676 4188  [ 58F82EED8CA24B461441F9C3E4F0BF5C ] volsnap        C:\Windows\system32\DRIVERS\volsnap.sys
12:51:01.0691 4188  volsnap - ok
12:51:01.0695 4188  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid        C:\Windows\system32\DRIVERS\vsmraid.sys
12:51:01.0707 4188  vsmraid - ok
12:51:01.0734 4188  [ 787898BF9FB6D7BD87A36E2D95C899BA ] VSS            C:\Windows\system32\vssvc.exe
12:51:01.0784 4188  VSS - ok
12:51:01.0797 4188  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
12:51:01.0833 4188  vwifibus - ok
12:51:01.0865 4188  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time        C:\Windows\system32\w32time.dll
12:51:01.0910 4188  W32Time - ok
12:51:01.0922 4188  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
12:51:01.0945 4188  WacomPen - ok
12:51:01.0965 4188  [ 47CA49400643EFFD3F1C9A27E1D69324 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
12:51:02.0011 4188  WANARP - ok
12:51:02.0014 4188  [ 47CA49400643EFFD3F1C9A27E1D69324 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
12:51:02.0045 4188  Wanarpv6 - ok
12:51:02.0117 4188  [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc    C:\Windows\system32\Wat\WatAdminSvc.exe
12:51:02.0166 4188  WatAdminSvc - ok
12:51:02.0205 4188  [ 5AB1BB85BD8B5089CC5D64200DEDAE68 ] wbengine        C:\Windows\system32\wbengine.exe
12:51:02.0255 4188  wbengine - ok
12:51:02.0291 4188  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
12:51:02.0324 4188  WbioSrvc - ok
12:51:02.0360 4188  [ DD1BAE8EBFC653824D29CCF8C9054D68 ] wcncsvc        C:\Windows\System32\wcncsvc.dll
12:51:02.0403 4188  wcncsvc - ok
12:51:02.0415 4188  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
12:51:02.0449 4188  WcsPlugInService - ok
12:51:02.0462 4188  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows\system32\DRIVERS\wd.sys
12:51:02.0477 4188  Wd - ok
12:51:02.0501 4188  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
12:51:02.0522 4188  Wdf01000 - ok
12:51:02.0534 4188  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
12:51:02.0551 4188  WdiServiceHost - ok
12:51:02.0555 4188  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost  C:\Windows\system32\wdi.dll
12:51:02.0571 4188  WdiSystemHost - ok
12:51:02.0606 4188  [ 733006127F235BE7C35354EBEE7B9A7B ] WebClient      C:\Windows\System32\webclnt.dll
12:51:02.0658 4188  WebClient - ok
12:51:02.0681 4188  [ C749025A679C5103E575E3B48E092C43 ] Wecsvc          C:\Windows\system32\wecsvc.dll
12:51:02.0738 4188  Wecsvc - ok
12:51:02.0757 4188  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
12:51:02.0806 4188  wercplsupport - ok
12:51:02.0836 4188  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows\System32\WerSvc.dll
12:51:02.0870 4188  WerSvc - ok
12:51:02.0885 4188  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
12:51:02.0914 4188  WfpLwf - ok
12:51:02.0934 4188  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
12:51:02.0943 4188  WIMMount - ok
12:51:02.0965 4188  WinDefend - ok
12:51:02.0968 4188  WinHttpAutoProxySvc - ok
12:51:02.0998 4188  [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
12:51:03.0032 4188  Winmgmt - ok
12:51:03.0091 4188  [ 41FBB751936B387F9179E7F03A74FE29 ] WinRM          C:\Windows\system32\WsmSvc.dll
12:51:03.0181 4188  WinRM - ok
12:51:03.0244 4188  [ 817EAFF5D38674EDD7713B9DFB8E9791 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
12:51:03.0273 4188  WinUsb - ok
12:51:03.0301 4188  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc        C:\Windows\System32\wlansvc.dll
12:51:03.0373 4188  Wlansvc - ok
12:51:03.0451 4188  [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc        C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
12:51:03.0470 4188  wlcrasvc - ok
12:51:03.0588 4188  [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
12:51:03.0669 4188  wlidsvc - ok
12:51:03.0699 4188  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi        C:\Windows\system32\DRIVERS\wmiacpi.sys
12:51:03.0717 4188  WmiAcpi - ok
12:51:03.0736 4188  [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
12:51:03.0761 4188  wmiApSrv - ok
12:51:03.0789 4188  WMPNetworkSvc - ok
12:51:03.0799 4188  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
12:51:03.0826 4188  WPCSvc - ok
12:51:03.0837 4188  [ 2E57DDF2880A7E52E76F41C7E96D327B ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
12:51:03.0864 4188  WPDBusEnum - ok
12:51:03.0880 4188  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
12:51:03.0937 4188  ws2ifsl - ok
12:51:03.0962 4188  [ 8F9F3969933C02DA96EB0F84576DB43E ] wscsvc          C:\Windows\System32\wscsvc.dll
12:51:03.0989 4188  wscsvc - ok
12:51:04.0014 4188  [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice  C:\Windows\system32\DRIVERS\WSDPrint.sys
12:51:04.0029 4188  WSDPrintDevice - ok
12:51:04.0032 4188  WSearch - ok
12:51:04.0116 4188  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
12:51:04.0223 4188  wuauserv - ok
12:51:04.0234 4188  [ 7CADC74271DD6461C452C271B30BD378 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
12:51:04.0311 4188  WudfPf - ok
12:51:04.0329 4188  [ 3B197AF0FFF08AA66B6B2241CA538D64 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
12:51:04.0379 4188  WUDFRd - ok
12:51:04.0392 4188  [ B551D6637AA0E132C18AC6E504F7B79B ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
12:51:04.0426 4188  wudfsvc - ok
12:51:04.0436 4188  [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc        C:\Windows\System32\wwansvc.dll
12:51:04.0467 4188  WwanSvc - ok
12:51:04.0470 4188  ================ Scan global ===============================
12:51:04.0493 4188  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
12:51:04.0521 4188  [ 0CB6EBF4B461A6043353C570BD72A1E1 ] C:\Windows\system32\winsrv.dll
12:51:04.0530 4188  [ 0CB6EBF4B461A6043353C570BD72A1E1 ] C:\Windows\system32\winsrv.dll
12:51:04.0541 4188  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
12:51:04.0553 4188  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
12:51:04.0558 4188  [Global] - ok
12:51:04.0559 4188  ================ Scan MBR ==================================
12:51:04.0568 4188  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
12:51:04.0956 4188  \Device\Harddisk0\DR0 - ok
12:51:04.0961 4188  [ 180DBDE3AF7EA48B3DB3AC27B1DDF401 ] \Device\Harddisk5\DR5
12:51:05.0068 4188  \Device\Harddisk5\DR5 - ok
12:51:05.0069 4188  ================ Scan VBR ==================================
12:51:05.0072 4188  [ F01E121EEC5767DD775DD92DC7C9BCED ] \Device\Harddisk0\DR0\Partition1
12:51:05.0074 4188  \Device\Harddisk0\DR0\Partition1 - ok
12:51:05.0085 4188  [ 7F56485D252E93B46656E0B3A227C50F ] \Device\Harddisk0\DR0\Partition2
12:51:05.0087 4188  \Device\Harddisk0\DR0\Partition2 - ok
12:51:05.0090 4188  [ 5DDD9B2D3994C29CC7A2EA523F495F87 ] \Device\Harddisk5\DR5\Partition1
12:51:05.0092 4188  \Device\Harddisk5\DR5\Partition1 - ok
12:51:05.0092 4188  ============================================================
12:51:05.0092 4188  Scan finished
12:51:05.0092 4188  ============================================================
12:51:05.0101 3912  Detected object count: 0
12:51:05.0101 3912  Actual detected object count: 0


cosinus 17.09.2012 12:23

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

Astirala 17.09.2012 12:58

Code:

ComboFix 12-09-16.01 - Astirala 17.09.2012  13:42:13.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.49.1031.18.4087.2859 [GMT 2:00]
ausgeführt von:: c:\users\Astirala\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-08-17 bis 2012-09-17  ))))))))))))))))))))))))))))))
.
.
2012-09-16 15:45 . 2012-09-16 15:45        --------        d-----w-        C:\_OTL
2012-09-14 08:14 . 2012-08-23 08:26        9310152        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{55753A58-83BD-4C29-8308-AFB4CAE2F448}\mpengine.dll
2012-09-13 10:56 . 2012-09-13 10:56        --------        d-----w-        c:\users\Astirala\AppData\Local\CRE
2012-09-13 10:55 . 2012-09-13 10:55        --------        d-----w-        c:\program files (x86)\Common Files\Wise Installation Wizard
2012-09-12 17:09 . 2012-09-12 17:09        --------        d-----w-        c:\program files (x86)\ESET
2012-09-12 16:45 . 2012-09-12 16:45        --------        d-----w-        c:\windows\system32\20-20 Technologies
2012-09-12 14:54 . 2012-09-12 14:54        --------        d-----w-        c:\users\Astirala\AppData\Roaming\Malwarebytes
2012-09-12 14:54 . 2012-09-12 14:54        --------        d-----w-        c:\programdata\Malwarebytes
2012-09-12 14:54 . 2012-09-12 14:54        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-09-12 14:54 . 2012-09-07 15:04        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-09-12 11:54 . 2012-08-02 17:55        574464        ----a-w-        c:\windows\system32\d3d10level9.dll
2012-09-12 11:54 . 2012-08-02 17:05        490496        ----a-w-        c:\windows\SysWow64\d3d10level9.dll
2012-09-11 21:13 . 2012-09-11 21:13        --------        d-----w-        c:\program files\CCleaner
2012-09-11 13:06 . 2012-09-11 13:06        --------        d-----w-        c:\program files (x86)\Perion
2012-09-11 12:46 . 2012-09-11 12:48        --------        d-----w-        c:\users\Astirala\AppData\Local\Windows Live
2012-09-11 10:12 . 2012-09-11 10:12        --------        d-----w-        c:\program files (x86)\Common Files\Java
2012-09-11 10:10 . 2012-09-11 10:10        95208        ----a-w-        c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-09-11 10:10 . 2012-09-11 10:10        --------        d-----w-        c:\program files (x86)\Java
2012-09-10 09:29 . 2012-09-10 14:18        --------        d-----w-        c:\program files (x86)\Metin2
2012-09-09 22:04 . 2012-09-09 22:04        --------        d-----w-        C:\Perfect World Entertainment
2012-09-09 22:04 . 2012-09-09 19:16        258352        ----a-w-        c:\windows\SysWow64\unicows.dll
2012-09-09 18:12 . 2012-09-09 22:04        --------        d-----w-        c:\program files (x86)\PWI_DE_v165_Installer
2012-09-09 18:11 . 2012-09-10 17:37        --------        d-----w-        c:\users\Astirala\AppData\Local\PMB Files
2012-09-09 18:11 . 2012-09-09 18:12        --------        d-----w-        c:\programdata\PMB Files
2012-09-09 18:11 . 2012-09-09 18:11        --------        d-----w-        c:\program files (x86)\Pando Networks
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-11 10:10 . 2012-07-07 10:12        821736        ----a-w-        c:\windows\SysWow64\npDeployJava1.dll
2012-09-11 10:10 . 2012-07-07 10:12        746984        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2012-08-15 00:40 . 2012-06-17 20:41        70344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-15 00:40 . 2012-06-17 20:41        426184        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-18 17:31 . 2012-08-14 17:08        3146752        ----a-w-        c:\windows\system32\win32k.sys
2012-07-04 22:04 . 2012-08-14 17:08        73216        ----a-w-        c:\windows\system32\netapi32.dll
2012-07-04 22:01 . 2012-08-14 17:08        58880        ----a-w-        c:\windows\system32\browcli.dll
2012-07-04 22:01 . 2012-08-14 17:08        136704        ----a-w-        c:\windows\system32\browser.dll
2012-07-04 21:23 . 2012-08-14 17:08        41472        ----a-w-        c:\windows\SysWow64\browcli.dll
2012-06-29 04:55 . 2012-08-14 19:55        17809920        ----a-w-        c:\windows\system32\mshtml.dll
2012-06-29 04:09 . 2012-08-14 19:55        10925568        ----a-w-        c:\windows\system32\ieframe.dll
2012-06-29 03:56 . 2012-08-14 19:55        2312704        ----a-w-        c:\windows\system32\jscript9.dll
2012-06-29 03:49 . 2012-08-14 19:55        1346048        ----a-w-        c:\windows\system32\urlmon.dll
2012-06-29 03:49 . 2012-08-14 19:55        1392128        ----a-w-        c:\windows\system32\wininet.dll
2012-06-29 03:48 . 2012-08-14 19:55        1494528        ----a-w-        c:\windows\system32\inetcpl.cpl
2012-06-29 03:47 . 2012-08-14 19:55        237056        ----a-w-        c:\windows\system32\url.dll
2012-06-29 03:45 . 2012-08-14 19:55        85504        ----a-w-        c:\windows\system32\jsproxy.dll
2012-06-29 03:44 . 2012-08-14 19:55        816640        ----a-w-        c:\windows\system32\jscript.dll
2012-06-29 03:43 . 2012-08-14 19:55        173056        ----a-w-        c:\windows\system32\ieUnatt.exe
2012-06-29 03:42 . 2012-08-14 19:55        2144768        ----a-w-        c:\windows\system32\iertutil.dll
2012-06-29 03:40 . 2012-08-14 19:55        96768        ----a-w-        c:\windows\system32\mshtmled.dll
2012-06-29 03:39 . 2012-08-14 19:55        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2012-06-29 03:35 . 2012-08-14 19:55        248320        ----a-w-        c:\windows\system32\ieui.dll
2012-06-29 00:16 . 2012-08-14 19:55        1800704        ----a-w-        c:\windows\SysWow64\jscript9.dll
2012-06-29 00:09 . 2012-08-14 19:55        1129472        ----a-w-        c:\windows\SysWow64\wininet.dll
2012-06-29 00:08 . 2012-08-14 19:55        1427968        ----a-w-        c:\windows\SysWow64\inetcpl.cpl
2012-06-29 00:04 . 2012-08-14 19:55        142848        ----a-w-        c:\windows\SysWow64\ieUnatt.exe
2012-06-29 00:00 . 2012-08-14 19:55        2382848        ----a-w-        c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"googletalk"="c:\users\Astirala\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"GAINWARD"="c:\program files (x86)\EXPERTool\TBPanel.exe" [2011-08-02 2273608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-10-21 106496]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2011-04-24 202296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
UltraMon.lnk - c:\windows\Installer\{537056B7-32A4-4408-9B54-0341963C7C9C}\IcoUltraMon.ico [2012-6-16 29310]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 250056]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-02-15 99384]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-14 113120]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-05-11 203320]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-21 1255736]
R3 WSDPrintDevice;WSD-Druckunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [2010-04-27 21544]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2011-03-04 11864]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2011-03-10 29488]
S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe [2010-01-19 72304]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-07 399432]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-07 676936]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-05-15 382272]
S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2008-11-14 20512]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 22544]
S3 LVUVC64;QuickCam Communicate Deluxe(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [2009-10-07 6379288]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-07 25928]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2009-10-26 75264]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2009-10-26 176640]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2012-04-18 188736]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-17 00:40]
.
2012-09-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-382671035-3137015300-3879576489-1000Core.job
- c:\users\Astirala\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-16 13:17]
.
2012-09-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-382671035-3137015300-3879576489-1000UA.job
- c:\users\Astirala\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-16 13:17]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-26 10135584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Hinzufügen zu Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{40c3cc16-7269-4b32-9531-17f2950fb06f} - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,48,8d,09,94,83,ba,45,47,b3,c4,4b,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,48,8d,09,94,83,ba,45,47,b3,c4,4b,\
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-09-17  13:55:51 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-09-17 11:55
.
Vor Suchlauf: 17 Verzeichnis(se), 771.955.204.096 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 771.655.483.392 Bytes frei
.
- - End Of File - - B2BCC4F58E60FC880C8D69813A44C33E


cosinus 17.09.2012 14:40

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

Astirala 17.09.2012 16:08

hm habe ich nun was falsch gemacht? Habe GMER laufen lassen und am Ende nur ein Pop up gekriegt "hasn't found any system modifications" aber keinerlei Logfile. Auch im Hauptfenster war nichts zu lesen.

Versuche nun das andere. Falls ich GMER nochmal laufen lassen soll mit einer anderen Einschränkung oder so (vll habe ich wirklich was vergessen?) dann mache ich das natürlich danach gerne.

Osam
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 17:14:45 on 17.09.2012

OS: Windows 7 Home Premium Edition (Build 7600), 64-bit
Default Browser: Google Inc. Google Chrome 21.0.1180.89

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskUserS-1-5-21-382671035-3137015300-3879576489-1000Core.job" - "Google Inc." - C:\Users\Astirala\AppData\Local\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-382671035-3137015300-3879576489-1000UA.job" - "Google Inc." - C:\Users\Astirala\AppData\Local\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Pando" - "Pando Networks" - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"AppleCharger" (AppleCharger) - ? - C:\Windows\System32\DRIVERS\AppleCharger.sys  (File found, but it contains no detailed information)
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"EagleX64" (EagleX64) - ? - C:\Windows\system32\drivers\EagleX64.sys  (File not found)
"gdrv" (gdrv) - ? - C:\Windows\gdrv.sys  (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"TBPanel" (TBPanel) - ? - C:\Windows\system32\drivers\TBPanel.sys  (File not found)
"UltraMon Utility Driver" (UltraMonUtility) - "Realtime Soft Ltd" - C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} "Album Download IE Asynchronous Pluggable Protocol Interface" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{D8D1CE8C-B1EB-4E95-B63B-1531BA60E992} "DivX Property Handler" - "DivX, Inc." - C:\Program Files (x86)\DivX\DivX Plus Media Foundation Components\DivXPropertyHandler.dll
{83238FAE-D346-4E12-8734-D42F7554B3E6} "DivX Thumbnail Provider" - "DivX, Inc." - C:\Program Files (x86)\DivX\DivX Plus Media Foundation Components\DivXThumbnailProvider.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{0563DB41-F538-4B37-A92D-4659049B7766} "WLMD Message Handler" - ? -  (File not found | COM-object registry key not found)
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height64 "ITBar7Height64" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout64" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\SysWOW64\Macromed\Flash\Flash32_11_3_300_271.ocx / hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{4248FE82-7FCB-46AC-B270-339F08212110} "&Virtuelle Tastatur" - "Kaspersky Lab ZAO" - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
{B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} "@C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "@C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
{CCF151D8-D089-449F-A5A4-D9909053F20F} "Li&nks untersuchen" - "Kaspersky Lab ZAO" - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{326E768D-4182-46FD-9C16-1449A49795F4} "DivX Plus Web Player HTML5 <video>" - "DivX, LLC" - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
{E33CF602-D945-461A-83F0-819F76A199F8} "FilterBHO Class" - "Kaspersky Lab ZAO" - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} "IEVkbdBHO Class" - "Kaspersky Lab ZAO" - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Oracle Corporation" - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Oracle Corporation" - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID-Anmelde-Hilfsprogramm" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{9FDDE16B-836F-4806-AB1F-1455CBEFF289} "Windows Live Messenger Companion Helper" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

[LSA Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )-----
"Security Packages" - "Microsoft Corp." - C:\Windows\system32\livessp.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Astirala\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"UltraMon.lnk" - "Realtime Soft Ltd" - C:\Program Files\UltraMon\UltraMon.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"GAINWARD" - "Gainward Co." - C:\Program Files (x86)\EXPERTool\TBPanel.exe /A
"googletalk" - "Google" - C:\Users\Astirala\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"AVP" - "Kaspersky Lab ZAO" - "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe"
"DivXUpdate" - ? - "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"JMB36X IDE Setup" - ? - C:\Windows\RaidTool\xInsIDE.exe  (File found, but it contains no detailed information)
"NUSB3MON" - "NEC Electronics Corporation" - "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"PCL hpf3l02t" - "Hewlett-Packard Company" - C:\Windows\system32\hpf3l02t.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll  (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe"  (File not found)
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
"AppleChargerSrv" (AppleChargerSrv) - ? - C:\Windows\System32\AppleChargerSrv.exe  (File found, but it contains no detailed information)
"JMB36X" (JMB36X) - ? - C:\Windows\SysWOW64\XSrvSetup.exe  (File found, but it contains no detailed information)
"Kaspersky Anti-Virus Service" (AVP) - "Kaspersky Lab ZAO" - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
"MBAMScheduler" (MBAMScheduler) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
"NVIDIA Display Driver Service" (NVSvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe
"NVIDIA Stereoscopic 3D Driver Service" (Stereo Service) - "NVIDIA Corporation" - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
"NVIDIA Update Service Daemon" (nvUpdatusService) - "NVIDIA Corporation" - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"WindowsLive Local NSP" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
"WindowsLive NSP" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

aswMBR
Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-17 17:16:42
-----------------------------
17:16:42.960    OS Version: Windows x64 6.1.7600
17:16:42.961    Number of processors: 4 586 0x2505
17:16:42.961    ComputerName: ASTIRALA-PC  UserName: Astirala
17:16:44.205    Initialize success
17:18:30.717    AVAST engine defs: 12091400
17:19:07.149    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
17:19:07.155    Disk 0 Vendor: WDC_WD10EARS-00MVWB0 50.0AB50 Size: 953868MB BusType: 3
17:19:07.168    Disk 0 MBR read successfully
17:19:07.174    Disk 0 MBR scan
17:19:07.183    Disk 0 Windows 7 default MBR code
17:19:07.189    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          500 MB offset 2048
17:19:07.203    Disk 0 Partition 2 00    27 Hidden NTFS WinRE NTFS        25000 MB offset 1026048
17:19:07.209    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      928366 MB offset 52226048
17:19:07.241    Disk 0 scanning C:\Windows\system32\drivers
17:19:14.692    Service scanning
17:19:30.010    Modules scanning
17:19:30.026    Disk 0 trace - called modules:
17:19:30.040    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
17:19:30.046    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800478c060]
17:19:30.276    3 CLASSPNP.SYS[fffff8800180143f] -> nt!IofCallDriver -> [0xfffffa8004516e40]
17:19:30.290    5 ACPI.sys[fffff88000f38781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80044fe060]
17:19:32.828    AVAST engine scan C:\Windows
17:19:35.492    AVAST engine scan C:\Windows\system32
17:21:31.795    AVAST engine scan C:\Windows\system32\drivers
17:21:40.915    AVAST engine scan C:\Users\Astirala
17:22:37.999    AVAST engine scan C:\ProgramData
17:23:58.925    Scan finished successfully
17:24:19.255    Disk 0 MBR has been saved successfully to "C:\Users\Astirala\Desktop\MBR.dat"
17:24:19.261    The log file has been saved successfully to "C:\Users\Astirala\Desktop\aswMBR.txt"


cosinus 17.09.2012 20:26

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

Astirala 18.09.2012 01:26

Malwarebytes
Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.17.08

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Astirala :: ASTIRALA-PC [Administrator]

Schutz: Deaktiviert

17.09.2012 21:49:31
mbam-log-2012-09-17 (21-49-31).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 216360
Laufzeit: 2 Minute(n), 4 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

SuperAntiSpyware
Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/18/2012 at 02:23 AM

Application Version : 5.5.1016

Core Rules Database Version : 9240
Trace Rules Database Version: 7052

Scan type      : Complete Scan
Total Scan Time : 04:27:09

Operating System Information
Windows 7 Home Premium 64-bit (Build 6.01.7600)
UAC On - Limited User

Memory items scanned      : 595
Memory threats detected  : 0
Registry items scanned    : 64572
Registry threats detected : 0
File items scanned        : 368262
File threats detected    : 803

Adware.Tracking Cookie
        C:\Users\Astirala\AppData\Roaming\Microsoft\Windows\Cookies\F2674JH1.txt [ /doubleclick.net ]
        C:\Users\Astirala\AppData\Roaming\Microsoft\Windows\Cookies\C0ODMRUS.txt [ /tradedoubler.com ]
        C:\USERS\ASTIRALA\AppData\Roaming\Microsoft\Windows\Cookies\HFRTV3O2.txt [ Cookie:astirala@clkads.com/adServe ]
        C:\USERS\ASTIRALA\AppData\Roaming\Microsoft\Windows\Cookies\Low\LVTXIIWP.txt [ Cookie:astirala@bs.serving-sys.com/ ]
        C:\USERS\ASTIRALA\AppData\Roaming\Microsoft\Windows\Cookies\Low\P3JH6ILV.txt [ Cookie:astirala@serving-sys.com/ ]
        C:\USERS\ASTIRALA\AppData\Roaming\Microsoft\Windows\Cookies\Low\GLVGUSDE.txt [ Cookie:astirala@c.atdmt.com/ ]
        C:\USERS\ASTIRALA\AppData\Roaming\Microsoft\Windows\Cookies\Low\H3T7GGN3.txt [ Cookie:astirala@atdmt.com/ ]
        C:\USERS\ASTIRALA\Cookies\HFRTV3O2.txt [ Cookie:astirala@clkads.com/adServe ]
        C:\USERS\ASTIRALA\Cookies\C0ODMRUS.txt [ Cookie:astirala@tradedoubler.com/ ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .aim4media.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .cssversicherung.122.2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .questionmarket.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .moviepilot.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .moviepilot.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .aim4media.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        s07.flagcounter.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .a.revenuemax.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ru4.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .amazon-adsystem.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .amazon-adsystem.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .specificclick.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .xiti.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bwincom.122.2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.247activemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .histats.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .histats.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .histats.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .elitepartner.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        statse.webtrendslive.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .account.frogster-online.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tribalfusion.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mm.chitika.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        7.rotator.wigetmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.findix.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adxpose.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .dealtime.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        stat.dealtime.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mmstat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.tchibo.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .rakuten.112.2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lfstmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lfstmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.interdiscount.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .interdiscount.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .interdiscount.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .collective-media.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexpartnerclub.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexpartnerclub.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        clicks.pangora.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        clicks.pangora.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.pornme.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .businessenhanced.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .businessenhanced.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        rexsex.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adserver1.mokono.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yieldmanager.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .interclick.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .interclick.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .allthemedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .allthemedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adserver.psinternet.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .liveperson.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickbank.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertisingenhanced.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertisingenhanced.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .horyzon-media.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .horyzon-media.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .horyzon-media.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .e-2dj6aekywpczalp.stats.esomniture.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        server.adform.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bubblestat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        server.adform.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .e-2dj6wdkywiajkho.stats.esomniture.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        counters.gigya.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .estat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adserver.local.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ch-stailamedia.videoplaza.tv [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .googleads.g.doubleclick.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fr.sitestat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fr.sitestat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .e-2dj6wfkyskczaho.stats.esomniture.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad-emea.doubleclick.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        in.getclicky.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lfstmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adserver.adtechus.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .gostats.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.zanox.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ru4.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .jamster.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .jamster.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .jamster.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .kontera.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .unister-adservices.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .unister-adservices.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pro-market.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pro-market.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pro-market.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pro-market.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        media3.tchibo-content.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        webstat.delti.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.zanox-affiliate.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tns-counter.ru [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        targeting.revenuemax.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ads20.wwe-media.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yadro.ru [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        aa.adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        stat.aldi.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        media4.tchibo-content.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        media2.tchibo-content.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        media.gan-online.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bs.serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        7.rotator.wigetmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clicksor.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clicksor.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clicksor.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clicksor.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .statcounter.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .myroitracking.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .secmedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .conrad.122.2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        api.zanox.ws [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adnet.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mmotraffic.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mmotraffic.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revenuemax.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradetracker.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .server.cpmstar.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .server.cpmstar.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lucidmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .overture.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        partners.webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.youtube.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .accounts.google.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .accounts.google.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        wstat.wibiya.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adviva.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imagesrv.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imagesrv.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .gs-media.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.zanox-affiliate.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.zanox-affiliate.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .unrulymedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.google.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .e-2dj6wgkoqpcpicp.stats.esomniture.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        zbox.zanox.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .quartermedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracker.vinsight.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        bs.serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickfuse.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox-affiliate.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.zanox.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .traffictrack.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        server.adformdsp.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adformdsp.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adform.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad4.adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad2.adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ww251.smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickfuse.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickfuse.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad1.adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.tchibo.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.mediamarkt.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        shop.mediamarkt.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .shop.mediamarkt.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .shop.mediamarkt.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .fastclick.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradetracker.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradetracker.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mmotraffic.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        viewad.exchangecash.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pornme.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.mktrack.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pornme.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pornme.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pornme.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.metricsmedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.metricsmedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.metricsmedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .content.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adform.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        7.rotator.trafficbee.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        7.rotator.trafficbee.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        7.rotator.trafficbee.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .rotator.wigetmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .partypoker.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .partypoker.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .partypoker.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        banners.webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad3.adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adform.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        revsci.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        doubleclick.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        atdmt.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        atdmt.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        revsci.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        revsci.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        revsci.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        revsci.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        content.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        adtech.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        apmebf.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        mediaplex.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        mediaplex.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        imrworldwide.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        imrworldwide.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        adform.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        doubleclick.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        fastclick.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        aim4media.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        aim4media.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        clickfuse.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        fastclick.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .media.funpic.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        vbstats.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        vbstats.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        vbstats.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .specificclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adviva.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        s10.flagcounter.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ru4.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .technoratimedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .technoratimedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lucidmedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yadro.ru [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yieldmanager.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ru4.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads2.iweb.cortica.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.247activemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adxpose.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .statcounter.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.dyntracker.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        stat.aldi.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .quartermedia.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .quartermedia.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .elitepartner.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .elitepartner.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .elitepartner.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bs.serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .gostats.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .gostats.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .histats.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .gostats.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .histats.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .exoclick.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adserver.adtechus.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .game-advertising-online.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .questionmarket.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .cunda.122.2o7.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .a.revenuemax.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .burstnet.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .www.burstnet.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lfstmedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.adserver01.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.adserver01.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        media.gan-online.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .amazon-adsystem.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .amazon-adsystem.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.mlsat02.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .jamster.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.soundmedia.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .e-2dj6wjl4and5obp.stats.esomniture.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .2o7.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .estat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        stat.dealtime.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fr.sitestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fr.sitestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .xiti.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        statse.webtrendslive.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        in.getclicky.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .statcounter.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad4.adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .conrad.122.2o7.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.counter-gratis.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox-affiliate.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.dyntracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.zanox-affiliate.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .jamster.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .jamster.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adform.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        stats.computecmedia.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad1.adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        nl.sitestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .guj.122.2o7.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .traffictrack.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad3.adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .overture.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad2.adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .secmedia.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .secmedia.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        partners.webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.mediamarkt.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        shop.mediamarkt.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .shop.mediamarkt.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .shop.mediamarkt.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .shop.mediamarkt.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickfuse.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bubblestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bubblestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertstream.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickfuse.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www4.smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickfuse.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ww251.smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.google.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.google.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .fastclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.zanox.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaserver.digitec.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        delivery.ibanner.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\KXJ2WX7G ]
        www.sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\KXJ2WX7G ]
        C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ASTIRALA@CONTENT.YIELDMANAGER[2].TXT [ /CONTENT.YIELDMANAGER ]
        C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ASTIRALA@CONTENT.YIELDMANAGER[1].TXT [ /CONTENT.YIELDMANAGER ]
        C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ASTIRALA@ADFARM1.ADITION[2].TXT [ /ADFARM1.ADITION ]
        C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ASTIRALA@AD.YIELDMANAGER[1].TXT [ /AD.YIELDMANAGER ]
        .doubleclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        server.iad.liveperson.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .content.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tracking.3gnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .content.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .fuckshow.org [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .fuckshow.org [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .fuckshow.org [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.netdebit-counter.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.cyonix.to [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.cyonix.to [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .cyonix.to [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .cyonix.to [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .cyonix.to [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-MSFake
        C:\KASPERSKY\KASPERSKY INTERNET SECURITY 2011.EXE
        C:\WINDOWS\CONFIGSETROOT\$OEM$\$1\KASPERSKY\KASPERSKY INTERNET SECURITY 2011.EXE
        C:\WINDOWS.OLD\KASPERSKY\KASPERSKY INTERNET SECURITY 2011.EXE
        C:\WINDOWS.OLD\WINDOWS\CONFIGSETROOT\$OEM$\$1\KASPERSKY\KASPERSKY INTERNET SECURITY 2011.EXE

Riskware.HideWindows
        C:\PACKAGES\CMDOW.EXE
        C:\WINDOWS\CONFIGSETROOT\$OEM$\$$\SYSTEM32\CMDOW.EXE
        C:\WINDOWS\CONFIGSETROOT\$OEM$\$1\PACKAGES\CMDOW.EXE
        C:\WINDOWS.OLD\PACKAGES\CMDOW.EXE
        C:\WINDOWS.OLD\WINDOWS\CONFIGSETROOT\$OEM$\$$\SYSTEM32\CMDOW.EXE
        C:\WINDOWS.OLD\WINDOWS\CONFIGSETROOT\$OEM$\$1\PACKAGES\CMDOW.EXE

Trojan.Dropper/Win-NV
        C:\WINDOWS.OLD\PROGRAM FILES (X86)\PRIVATE TAX 2010\UPDATE.EXE


cosinus 19.09.2012 11:06

Das war leider kein Vollscan mit Malwarebytes

Code:

UAC On - Limited User
Wie hast du sasw gestartet? Einfach per Doppelklick?

Astirala 19.09.2012 15:16

Huhu, ich mache beide Scans heute Abend nochmal. Ich weiss nimmer wie ich Sasw gestartet habe ... Ist wohl besser auf Nummer Sicher zu gehen.

So, habe nun beides nochmal geupdated und nochmals durchlaufen lassen. Bei Malwarebytes habe ich wohl den Fehler gemacht und auf Quick statt Vollscan zu klicken. Sollte nun nach wie vor was nicht in Ordnung sein, einfach nochmal bitte schnell schreiben, was ich evtl anhaken muss, resp wo ich was entfernen muss.

Ausgeführt habe ich beide Programme mit Rechtsklick als Admin ausführen, da Win 7.

Malwarebytes
Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.19.12

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Astirala :: ASTIRALA-PC [Administrator]

Schutz: Deaktiviert

19.09.2012 23:34:24
mbam-log-2012-09-19 (23-34-24).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 562422
Laufzeit: 1 Stunde(n), 44 Minute(n), 6 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

SuperAntiSpyware
Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/20/2012 at 04:11 AM

Application Version : 5.5.1016

Core Rules Database Version : 9257
Trace Rules Database Version: 7069

Scan type      : Complete Scan
Total Scan Time : 02:31:49

Operating System Information
Windows 7 Home Premium 64-bit (Build 6.01.7600)
UAC On - Administrator

Memory items scanned      : 670
Memory threats detected  : 0
Registry items scanned    : 64706
Registry threats detected : 0
File items scanned        : 339249
File threats detected    : 784

Adware.Tracking Cookie
        C:\Users\Astirala\AppData\Roaming\Microsoft\Windows\Cookies\F2674JH1.txt [ /doubleclick.net ]
        C:\Users\Astirala\AppData\Roaming\Microsoft\Windows\Cookies\C0ODMRUS.txt [ /tradedoubler.com ]
        C:\USERS\ASTIRALA\AppData\Roaming\Microsoft\Windows\Cookies\HFRTV3O2.txt [ Cookie:astirala@clkads.com/adServe ]
        C:\USERS\ASTIRALA\AppData\Roaming\Microsoft\Windows\Cookies\Low\LVTXIIWP.txt [ Cookie:astirala@bs.serving-sys.com/ ]
        C:\USERS\ASTIRALA\AppData\Roaming\Microsoft\Windows\Cookies\Low\P3JH6ILV.txt [ Cookie:astirala@serving-sys.com/ ]
        C:\USERS\ASTIRALA\AppData\Roaming\Microsoft\Windows\Cookies\Low\GLVGUSDE.txt [ Cookie:astirala@c.atdmt.com/ ]
        C:\USERS\ASTIRALA\AppData\Roaming\Microsoft\Windows\Cookies\Low\H3T7GGN3.txt [ Cookie:astirala@atdmt.com/ ]
        C:\USERS\ASTIRALA\Cookies\HFRTV3O2.txt [ Cookie:astirala@clkads.com/adServe ]
        C:\USERS\ASTIRALA\Cookies\C0ODMRUS.txt [ Cookie:astirala@tradedoubler.com/ ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .aim4media.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .cssversicherung.122.2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .questionmarket.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .moviepilot.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .moviepilot.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .aim4media.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        s07.flagcounter.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .a.revenuemax.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ru4.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .amazon-adsystem.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .amazon-adsystem.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .specificclick.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .xiti.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bwincom.122.2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.247activemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .histats.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .histats.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .histats.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .elitepartner.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        statse.webtrendslive.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .account.frogster-online.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tribalfusion.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mm.chitika.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        7.rotator.wigetmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.findix.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adxpose.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .dealtime.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        stat.dealtime.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mmstat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.tchibo.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .rakuten.112.2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lfstmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lfstmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.interdiscount.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .interdiscount.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .interdiscount.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .collective-media.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexpartnerclub.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexpartnerclub.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        clicks.pangora.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        clicks.pangora.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.pornme.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .businessenhanced.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .businessenhanced.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        rexsex.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adserver1.mokono.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yieldmanager.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .interclick.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .interclick.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .allthemedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .allthemedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adserver.psinternet.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .liveperson.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickbank.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertisingenhanced.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertisingenhanced.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .horyzon-media.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .horyzon-media.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .horyzon-media.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .e-2dj6aekywpczalp.stats.esomniture.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        server.adform.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bubblestat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        server.adform.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .e-2dj6wdkywiajkho.stats.esomniture.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        counters.gigya.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .estat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adserver.local.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ch-stailamedia.videoplaza.tv [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .googleads.g.doubleclick.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fr.sitestat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fr.sitestat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .e-2dj6wfkyskczaho.stats.esomniture.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad-emea.doubleclick.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        in.getclicky.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lfstmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adserver.adtechus.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ero-advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .gostats.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.zanox.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ru4.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .jamster.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .jamster.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .jamster.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .kontera.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .unister-adservices.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .unister-adservices.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pro-market.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pro-market.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pro-market.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pro-market.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        media3.tchibo-content.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        webstat.delti.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.zanox-affiliate.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tns-counter.ru [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        targeting.revenuemax.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ads20.wwe-media.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yadro.ru [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        aa.adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        stat.aldi.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        media4.tchibo-content.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        media2.tchibo-content.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        media.gan-online.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bs.serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clicksor.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clicksor.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clicksor.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clicksor.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .statcounter.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .myroitracking.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .secmedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .conrad.122.2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        api.zanox.ws [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adnet.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mmotraffic.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mmotraffic.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revenuemax.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradetracker.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .server.cpmstar.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .server.cpmstar.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lucidmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .overture.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        partners.webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.youtube.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .accounts.google.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .accounts.google.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        wstat.wibiya.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adviva.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imagesrv.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imagesrv.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .gs-media.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.zanox-affiliate.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.zanox-affiliate.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .unrulymedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.google.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .e-2dj6wgkoqpcpicp.stats.esomniture.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        zbox.zanox.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .quartermedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracker.vinsight.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        bs.serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickfuse.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox-affiliate.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .traffictrack.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .2o7.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        server.adformdsp.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adformdsp.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adform.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad4.adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad2.adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ww251.smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickfuse.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickfuse.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.tchibo.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.mediamarkt.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .fastclick.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradetracker.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradetracker.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mmotraffic.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pornme.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.mktrack.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pornme.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pornme.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.metricsmedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.metricsmedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.metricsmedia.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .content.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        7.rotator.trafficbee.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        7.rotator.trafficbee.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .partypoker.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .partypoker.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .partypoker.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad3.adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        7.rotator.wigetmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad1.adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adform.net [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        shop.mediamarkt.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .shop.mediamarkt.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .shop.mediamarkt.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .shop.mediamarkt.ch [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.zanox.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .e-2dj6wfligpdzkdp.stats.esomniture.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .rotator.wigetmedia.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        revsci.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        doubleclick.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        atdmt.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        atdmt.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        revsci.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        tradedoubler.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        revsci.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        revsci.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        revsci.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        content.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        adtech.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        apmebf.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        mediaplex.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        mediaplex.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        imrworldwide.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        imrworldwide.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        adform.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        doubleclick.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        fastclick.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        aim4media.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        aim4media.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        im.banner.t-online.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        clickfuse.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        fastclick.net [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        invitemedia.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMUKF51A.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .media.funpic.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        vbstats.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        vbstats.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        vbstats.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .specificclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adviva.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        s10.flagcounter.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ru4.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .technoratimedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .technoratimedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lucidmedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yadro.ru [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yieldmanager.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ru4.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads2.iweb.cortica.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.247activemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adxpose.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .statcounter.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.solocpm.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track1.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track2.httptrack.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.dyntracker.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        stat.aldi.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .quartermedia.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .quartermedia.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .elitepartner.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .elitepartner.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .elitepartner.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bs.serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .gostats.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .gostats.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .histats.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .gostats.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .histats.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .exoclick.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adserver.adtechus.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .game-advertising-online.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .questionmarket.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .cunda.122.2o7.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .a.revenuemax.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .burstnet.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .www.burstnet.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lfstmedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.adserver01.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.adserver01.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        media.gan-online.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .amazon-adsystem.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .amazon-adsystem.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .findix.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.mlsat02.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .jamster.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.soundmedia.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .e-2dj6wjl4and5obp.stats.esomniture.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .2o7.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .estat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        stat.dealtime.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fr.sitestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fr.sitestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .xiti.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        statse.webtrendslive.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        in.getclicky.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .statcounter.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad4.adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .conrad.122.2o7.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.counter-gratis.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox-affiliate.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.dyntracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.zanox-affiliate.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .jamster.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .jamster.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adform.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        stats.computecmedia.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad1.adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        nl.sitestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .guj.122.2o7.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .traffictrack.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad3.adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .overture.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad2.adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .secmedia.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .secmedia.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        partners.webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.mediamarkt.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        shop.mediamarkt.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .shop.mediamarkt.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .shop.mediamarkt.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .shop.mediamarkt.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickfuse.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bubblestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bubblestat.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertstream.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickfuse.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www4.smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clickfuse.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ww251.smartadserver.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.google.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.google.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .fastclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.zanox.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaserver.digitec.ch [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        delivery.ibanner.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\KXJ2WX7G ]
        www.sexkiste.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\KXJ2WX7G ]
        C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ASTIRALA@CONTENT.YIELDMANAGER[2].TXT [ /CONTENT.YIELDMANAGER ]
        C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ASTIRALA@CONTENT.YIELDMANAGER[1].TXT [ /CONTENT.YIELDMANAGER ]
        C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ASTIRALA@ADFARM1.ADITION[2].TXT [ /ADFARM1.ADITION ]
        C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ASTIRALA@AD.YIELDMANAGER[1].TXT [ /AD.YIELDMANAGER ]
        .doubleclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        server.iad.liveperson.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .content.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tracking.3gnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .content.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .fuckshow.org [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .fuckshow.org [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .fuckshow.org [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.netdebit-counter.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.cyonix.to [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        www.cyonix.to [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .cyonix.to [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .cyonix.to [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .cyonix.to [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ASTIRALA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\68D0URV3.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-MSFake
        C:\KASPERSKY\KASPERSKY INTERNET SECURITY 2011.EXE
        C:\WINDOWS\CONFIGSETROOT\$OEM$\$1\KASPERSKY\KASPERSKY INTERNET SECURITY 2011.EXE
        C:\WINDOWS.OLD\KASPERSKY\KASPERSKY INTERNET SECURITY 2011.EXE
        C:\WINDOWS.OLD\WINDOWS\CONFIGSETROOT\$OEM$\$1\KASPERSKY\KASPERSKY INTERNET SECURITY 2011.EXE

Riskware.HideWindows
        C:\PACKAGES\CMDOW.EXE
        C:\WINDOWS\CONFIGSETROOT\$OEM$\$$\SYSTEM32\CMDOW.EXE
        C:\WINDOWS\CONFIGSETROOT\$OEM$\$1\PACKAGES\CMDOW.EXE
        C:\WINDOWS.OLD\PACKAGES\CMDOW.EXE
        C:\WINDOWS.OLD\WINDOWS\CONFIGSETROOT\$OEM$\$$\SYSTEM32\CMDOW.EXE
        C:\WINDOWS.OLD\WINDOWS\CONFIGSETROOT\$OEM$\$1\PACKAGES\CMDOW.EXE

Trojan.Dropper/Win-NV
        C:\WINDOWS.OLD\PROGRAM FILES (X86)\PRIVATE TAX 2010\UPDATE.EXE


Astirala 29.09.2012 00:17

Guten Abend mal wieder.

Es ist mir fast etwas unangenehm, aber ich wollte mal nachfragen, ob da nun noch was kommt, weil ich schon lange nichts mehr gehört habe und das Problem ja noch nicht behoben ist.

Ich möchte nicht stressen oder so, bitte nicht falsch verstehen, aber es wundert mich gar nichts mehr zu hören.

Lieben Gruss
Asti

cosinus 29.09.2012 00:24

Sieht ok aus, da wurden nur Cookies gefunden. Die anderen sollten nur Fehlalarme sein.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

Astirala 29.09.2012 12:11

Huhu.

Ähm ja es gibt noch ein Problem. Nämlich das, warum ich dieses hier überhaupt gestartet habe. Also das bescheuerte mystart gedöns ist nach wie vor da.

Nun weiss ich zwar das mein Rechner soweit gut in Schuss ist was Viren, Trojaner und sonstiges angeht, aber das eigentlich Problem haben wir bisher nicht gelöst :(

cosinus 01.10.2012 11:40

Dann ist immer noch Toolbar-Müll drin
Bitte mal den aktuellen adwCleaner runterladen, also die alte adwcleaner löschen und neu runterladen

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.

Falls der adwCleaner schon mal in der runtergeladen wurde, bitte die alte adwcleaner.exe löschen und neu runterladen!!
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Rx].txt. (x=fortlaufende Nummer)

Astirala 01.10.2012 12:40

Hi, hier das Log
Code:

# AdwCleaner v2.003 - Datei am 10/01/2012 um 13:38:57 erstellt
# Aktualisiert am 23/09/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Astirala - ASTIRALA-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Astirala\Desktop\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gefunden : C:\Users\Astirala\AppData\LocalLow\Conduit
Ordner Gefunden : C:\Users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f}

***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gefunden : HKCU\Software\Conduit
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2319825
Schlüssel Gefunden : HKLM\Software\Conduit

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v13.0.1 (de)

Profilname : default
Datei : C:\Users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\prefs.js

Gefunden : user_pref("CT2319825.autoDisableScopes",  0);

-\\ Google Chrome v22.0.1229.79

Datei : C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R2].txt - [1426 octets] - [01/10/2012 13:38:57]

########## EOF - C:\AdwCleaner[R2].txt - [1486 octets] ##########


cosinus 01.10.2012 13:40

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Sx].txt. (x=fortlaufende Nummer)

Astirala 01.10.2012 15:06

Code:

# AdwCleaner v2.003 - Datei am 10/01/2012 um 16:02:51 erstellt
# Aktualisiert am 23/09/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Astirala - ASTIRALA-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Astirala\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\Users\Astirala\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f}

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2319825
Schlüssel Gelöscht : HKLM\Software\Conduit

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

-\\ Mozilla Firefox v13.0.1 (de)

Profilname : default
Datei : C:\Users\Astirala\AppData\Roaming\Mozilla\Firefox\Profiles\amukf51a.default\prefs.js

Gelöscht : user_pref("CT2319825.autoDisableScopes",  0);

-\\ Google Chrome v22.0.1229.79

Datei : C:\Users\Astirala\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R2].txt - [1555 octets] - [01/10/2012 13:38:57]
AdwCleaner[S4].txt - [1543 octets] - [01/10/2012 16:02:51]

########## EOF - C:\AdwCleaner[S4].txt - [1603 octets] ##########


cosinus 01.10.2012 15:18

Ist jetzt besser?

Astirala 01.10.2012 16:00

Was ich halt nicht verstehe ... ich habe das gemacht, also die Dateien oder was das auch ist gelöscht und dennoch ist das Zeug immernoch da. Das kann doch nicht mehr normal sein. In den Einstellungen habe ich es ja direkt nach bemerken entfernt, genau wie auch den Kram wieder deinstalliert ....

Also wenn ich den Browser ganz geschlossen habe und dann öffne, kommt meine normale Startseite. Mache ich dann jedoch ein zweites Browserfenster oder einen zweiten Reiter auf kommt der mystart krempel.

Huhu habs anscheinend gefunden, warum er dennoch nicht normal den Browser geöffnet hatte. Das Ding schreibt sich selbst unter Chrome ein Tool, resp installiert das. Das muss separat gelöscht werden. Das habe ich gerade getan und nun funktioniert alles wieder so wie es soll.

Ganz lieben Dank für die ganze Hilfe!

cosinus 02.10.2012 11:15

Hattest du auch mit dem Firefox bzw. ist das immer noch? Da muss u.U. ein neues Profil her oder man muss einige Einstellen in der about:config durchgehen

Oder ist nun alles okay jetzt?

Astirala 02.10.2012 12:55

Da ich den Firefox nur hin und wieder nutze hat sich das Ding nur in den Chrome gespeichert gehabt, wie es aussieht. Somit ist das Problem für mich behoben :) Danke nochmal für deine Hilfe!! :)

cosinus 02.10.2012 18:59

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 18:43 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131