Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Incredibar Toolbar gefangen und blutiger Anfänger ... ! (https://www.trojaner-board.de/124493-incredibar-toolbar-gefangen-blutiger-anfaenger.html)

rwt69 22.09.2012 07:41

Incredibar Toolbar gefangen und blutiger Anfänger ... !
 
Hallo beisammen,

ich finde es ja super dass es so was wie hier gibt. Ich habe mir (dumm, dumm) eine Software heruntergeladen und gleich wieder deinstalliert aber jetzt hab ich in Firefox und IE jeweils die Toolbar von Incredibar und krieg sie nicht wieder weg ! Startseite ist jetzt immer "MyStart".

Ich hab hier schon ein wenig mitgelesen und gleich Angst gekriegt, weil das hier alles für mich "böhmische Dörfer" sind.
Deswegen hoffe ich, dass sich einer erbarmt und mir (so dass auch ich es schaffe) so helfen kann das Dings wieder loszuwerden.

Hilfe !!! :heulen:

Ein paar Infos noch:
1. Ich möchte meine vielen Tabs in firefox und im IE nicht verlieren, wenn das geht.
2. Ich habe den Avira Free Antivirus (und auch schon laufen lassen).
3. Ich habe eine mobile Festplatte, nur zum Datenspeichern. Kann ich die (USB) einfach abstöpseln oder muss die auch überprüft werden ?
4. Ich habe die Programme - wie gefordert - heruntergeladen:
* defogger
* OTL (Ergebnisse nächstes Posting)
* ich habe als Systemtyp einen X86-basierten PC

Aber das Programm gmer starten, übersteigt meine Möglichkeiten. Ich habe hier im Haus noch einen Laptop, WLAN, wenn ich das abkopple / ausschalte, krieg ich das ohne fremde Hilfe vor Ort NIEMALS wieder hin. Das will ich eigentlich nicht machen, wenns irgendwie geht.

Avira Free Antivirus - soll ich das deinstallieren ?

Also, so weit bin ich im Moment und nervlich am Ende.
:dankeschoen: schon mal für jede Hilfe.

OTL Logfile:
Code:

OTL logfile created on: 22.09.2012 08:09:37 - Run 1
OTL by OldTimer - Version 3.2.65.1    Folder = C:\Users\User\Downloads
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 2,10 Gb Available Physical Memory | 64,62% Memory free
6,50 Gb Paging File | 5,28 Gb Available in Paging File | 81,32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 195,21 Gb Total Space | 75,07 Gb Free Space | 38,46% Space Free | Partition Type: NTFS
Drive D: | 270,45 Gb Total Space | 270,09 Gb Free Space | 99,87% Space Free | Partition Type: NTFS
Drive F: | 931,51 Gb Total Space | 399,37 Gb Free Space | 42,87% Space Free | Partition Type: NTFS
 
Computer Name: ROBERT | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.09.21 18:41:52 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Users\User\Downloads\OTL.exe
PRC - [2012.08.08 09:21:43 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.05.08 20:06:11 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.08 20:06:10 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.08 20:06:10 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.11.01 16:40:04 | 001,053,056 | ---- | M] (Nokia) -- C:\Programme\Nokia\Nokia Suite\NokiaSuite.exe
PRC - [2011.10.27 11:34:30 | 000,718,384 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe
PRC - [2011.10.27 11:33:58 | 000,173,104 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2011.10.27 11:33:32 | 000,148,016 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
PRC - [2011.06.24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.11.20 14:16:54 | 000,100,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
PRC - [2010.10.28 10:06:42 | 000,328,024 | ---- | M] (TeVii Technology Ltd.) -- C:\Windows\TeViiRC.exe
PRC - [2010.07.21 18:07:04 | 001,778,064 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft IntelliType Pro\itype.exe
PRC - [2010.07.21 17:51:42 | 001,797,008 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft IntelliPoint\ipoint.exe
PRC - [2010.05.20 23:59:30 | 011,312,128 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.bin
PRC - [2010.05.20 23:59:28 | 011,318,784 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.exe
PRC - [2009.10.13 09:39:04 | 000,935,208 | ---- | M] (Nero AG) -- C:\Programme\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2009.08.28 11:43:14 | 001,486,848 | R--- | M] (VIA) -- C:\Programme\VIA\VIAudioi\VDeck\VDeck.exe
PRC - [2009.08.19 14:41:26 | 003,618,104 | ---- | M] (brother) -- C:\Programme\Brownie\BrStsWnd.exe
PRC - [2009.07.14 13:28:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009.07.14 03:14:41 | 000,354,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\StikyNot.exe
PRC - [2008.10.17 16:52:16 | 000,099,632 | ---- | M] (brother) -- C:\Programme\Brownie\brpjp04a.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.11.01 16:42:14 | 000,392,064 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\ssoengine.dll
MOD - [2011.11.01 16:42:12 | 000,058,240 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\securestorage.dll
MOD - [2011.11.01 16:42:08 | 000,095,104 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\qjson.dll
MOD - [2011.11.01 16:42:06 | 000,272,768 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\phonon4.dll
MOD - [2011.11.01 16:41:38 | 000,165,248 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QxtWeb.dll
MOD - [2011.11.01 16:41:36 | 000,384,896 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QxtCore.dll
MOD - [2011.11.01 16:41:34 | 002,557,312 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtXmlPatterns4.dll
MOD - [2011.11.01 16:41:32 | 000,346,496 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtXml4.dll
MOD - [2011.11.01 16:41:30 | 010,843,520 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtWebKit4.dll
MOD - [2011.11.01 16:41:24 | 000,196,480 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtSql4.dll
MOD - [2011.11.01 16:41:22 | 001,294,208 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtScript4.dll
MOD - [2011.11.01 16:41:20 | 000,682,880 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtOpenGL4.dll
MOD - [2011.11.01 16:41:18 | 000,919,936 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtNetwork4.dll
MOD - [2011.11.01 16:41:16 | 000,517,504 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtMultimediaKit1.dll
MOD - [2011.11.01 16:41:14 | 008,172,928 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtGui4.dll
MOD - [2011.11.01 16:41:12 | 002,252,672 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtDeclarative4.dll
MOD - [2011.11.01 16:41:10 | 002,288,512 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtCore4.dll
MOD - [2011.11.01 16:41:06 | 000,422,272 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll
MOD - [2011.11.01 16:40:56 | 000,202,624 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\Imageformats\qjpeg4.dll
MOD - [2011.11.01 16:40:54 | 000,034,688 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\Imageformats\qico4.dll
MOD - [2011.11.01 16:40:52 | 000,032,640 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\Imageformats\qgif4.dll
MOD - [2011.11.01 16:40:08 | 000,388,480 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\OviShareLib.dll
MOD - [2011.11.01 16:40:00 | 000,438,144 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\NService.dll
MOD - [2011.11.01 16:39:36 | 001,041,792 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\Maps Service API.dll
MOD - [2011.11.01 16:39:06 | 000,740,736 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\CommonUpdateChecker.dll
MOD - [2011.11.01 15:57:42 | 000,112,640 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\mediaservice\dsengine.dll
MOD - [2010.05.04 15:36:28 | 000,970,752 | ---- | M] () -- C:\Programme\OpenOffice.org 3\program\libxml2.dll
MOD - [2009.08.28 05:31:08 | 047,628,288 | R--- | M] () -- C:\Programme\VIA\VIAudioi\VDeck\skin.dll
MOD - [2009.05.07 10:53:18 | 000,106,496 | R--- | M] () -- C:\Programme\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
MOD - [2009.05.07 10:50:46 | 000,073,728 | R--- | M] () -- C:\Programme\VIA\VIAudioi\VDeck\QsApoApi.dll
MOD - [2008.02.14 07:57:00 | 000,094,208 | R--- | M] () -- C:\Programme\VIA\VIAudioi\VDeck\VMicApi.dll
 
 
========== Services (SafeList) ==========
 
SRV - [2012.09.21 15:09:08 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.09.10 18:59:46 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.05.08 20:06:11 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.08 20:06:10 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.10.27 11:34:30 | 000,718,384 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2009.10.13 09:39:04 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Programme\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2009.07.14 13:28:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2012.05.08 20:06:11 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.05.08 20:06:11 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.12.15 16:00:00 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011.05.10 10:04:12 | 000,293,464 | ---- | M] (TechniSat Digital, S.A.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SkyNetU2CBDA.sys -- (SkyNetU2CBDA)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.10.28 10:06:40 | 000,128,344 | ---- | M] (TeVii Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\TeViiS2.sys -- (SAllBDA)
DRV - [2010.07.07 19:18:56 | 000,044,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.05.10 09:09:34 | 000,248,920 | ---- | M] (TechniSat Digital, S.A.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SkyNetU2C.sys -- (SKYNETU2C)
DRV - [2009.12.15 15:19:26 | 000,034,112 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\emOEM.sys -- (USB28xxOEM)
DRV - [2009.12.15 15:19:16 | 000,385,088 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\emBDA.sys -- (USB28xxBGA)
DRV - [2009.08.17 13:17:44 | 001,077,760 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009.07.30 11:12:54 | 000,287,392 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmf6232.sys -- (NVNET)
DRV - [2009.07.16 05:36:30 | 000,013,216 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2009.07.14 05:54:00 | 009,557,216 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009.07.14 00:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2009.06.28 18:36:36 | 000,017,920 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2004.10.14 06:29:54 | 000,021,888 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\eps2kt1.sys -- (token)
DRV - [2004.09.28 17:01:28 | 000,012,800 | ---- | M] (OEM) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smccard.sys -- (R5BaseSmc)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://mystart.incredibar.com/mb174?a=6R8FQJiBhA&i=26
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 F8 0C 37 F4 CB CA 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=109958&tt=3012_6&babsrc=SP_ss&mntrId=ec0f7e7900000000000090e6bae17256
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = hxxp://mystart.incredibar.com/mb174/?search={searchTerms}&loc=IB_DS&a=6R8FQJiBhA&i=26
IE - HKCU\..\SearchScopes\{FF1CABE9-894B-4960-8563-0C6C910D353B}: "URL" = hxxp://www.google.de/search?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://mystart.incredibar.com/mb174?a=6R8FQJiBhA&i=26"
FF - prefs.js..extensions.enabledAddons: {dd3d7613-0246-469d-bc65-2a3cc1668adc}:0.7.1.1
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}:6.0.33
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}:6.0.35
FF - prefs.js..extensions.enabledAddons: ffxtlbr@incredibar.com:1.5.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {dd3d7613-0246-469d-bc65-2a3cc1668adc}:0.7.1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://mystart.incredibar.com/mb174/?loc=IB_DS&a=6R8FQJiBhA&&i=26&search="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.10 18:59:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.08.17 10:54:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_7.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_7.0 [2011.12.26 16:08:28 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.10 18:59:47 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.08.17 10:54:55 | 000,000,000 | ---D | M]
 
[2010.04.19 21:53:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Extensions
[2012.09.21 16:18:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions
[2010.11.08 17:08:35 | 000,000,000 | ---D | M] (BlockSite) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
[2012.09.21 16:18:25 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions\ffxtlbr@incredibar.com
[2012.09.21 16:18:18 | 000,002,203 | ---- | M] () -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\kdie60r2.default\searchplugins\MyStart Search.xml
[2012.09.01 14:02:40 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.07.01 20:46:42 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.09.01 14:02:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.07.01 20:46:42 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.09.01 14:02:40 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.09.10 18:59:47 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.06.25 19:48:13 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.07.27 16:55:17 | 000,002,349 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012.09.10 18:59:45 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.06.25 19:48:13 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.25 19:48:13 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.25 19:48:13 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.25 19:48:13 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (GretechBHO Class) - {F0181C6E-9218-4792-9F3C-E8DF52B2F1AC} - C:\Programme\GRETECH\GomPicker\GomPickerBHO.dll (Gretech Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe (brother)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [TeViiRC] C:\Windows\TeViiRC.exe (TeVii Technology Ltd.)
O4 - HKCU..\Run: []  File not found
O4 - HKCU..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3CFF6DC9-BF64-4944-A914-75D25565DFAC}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{89D51DB1-15A5-4A74-BA0F-272D3A60C09C}: DhcpNameServer = 0.0.0.0
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - Unable to obtain root file information for disk F:\
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.21 16:18:42 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.22 08:09:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.22 07:34:00 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.09.21 18:29:11 | 000,000,000 | ---- | M] () -- C:\Users\User\defogger_reenable
[2012.09.21 18:03:27 | 000,001,150 | ---- | M] () -- C:\Users\User\Desktop\Continue Video Converter Installation.lnk
[2012.09.21 17:58:17 | 000,017,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.21 17:58:17 | 000,017,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.21 17:51:28 | 000,000,338 | ---- | M] () -- C:\Windows\Brownie.ini
[2012.09.21 17:51:21 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.09.21 17:51:21 | 000,000,306 | ---- | M] () -- C:\Windows\tasks\WinMaximizer-User-Startup.job
[2012.09.21 17:51:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.21 17:50:40 | 2616,643,584 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.21 16:18:26 | 000,000,758 | ---- | M] () -- C:\user.js
[2012.09.15 11:08:27 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.09.15 11:08:27 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.09.15 11:08:27 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.09.15 11:08:27 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.09.05 12:23:28 | 000,029,679 | R--- | M] () -- C:\Users\User\Desktop\Vereinsspielplan_20120905122313.csv
[2012.08.23 20:43:09 | 003,386,646 | ---- | M] () -- C:\Users\User\Desktop\Betriebsanleitung Kopierer.pdf
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.09.21 18:29:11 | 000,000,000 | ---- | C] () -- C:\Users\User\defogger_reenable
[2012.09.21 18:03:27 | 000,001,150 | ---- | C] () -- C:\Users\User\Desktop\Continue Video Converter Installation.lnk
[2012.09.05 12:23:32 | 000,029,679 | R--- | C] () -- C:\Users\User\Desktop\Vereinsspielplan_20120905122313.csv
[2012.08.23 20:43:09 | 003,386,646 | ---- | C] () -- C:\Users\User\Desktop\Betriebsanleitung Kopierer.pdf
[2012.07.01 16:05:32 | 000,338,432 | ---- | C] () -- C:\Windows\System32\sqlite36_engine.dll
[2011.07.07 12:24:52 | 000,000,367 | ---- | C] () -- C:\Users\User\Heimnetzgruppe - Verknüpfung.lnk
[2010.06.24 15:38:47 | 000,017,408 | ---- | C] () -- C:\Users\User\AppData\Local\WebpageIcons.db
 
========== ZeroAccess Check ==========
 
[2011.09.01 13:30:06 | 000,000,114 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\Net\FTP\L.pm
[2010.07.29 16:45:36 | 000,001,686 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\AHex\N.pl
[2010.07.29 16:45:40 | 000,008,696 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Alpha\N.pl
[2010.07.29 16:45:40 | 000,007,010 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Bc\L.pl
[2010.07.29 16:45:38 | 000,001,668 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\BidiC\N.pl
[2010.07.29 16:45:34 | 000,003,445 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\BidiM\N.pl
[2010.07.29 16:45:40 | 000,003,148 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Cased\N.pl
[2010.07.29 16:45:40 | 000,001,522 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Ccc\L.pl
[2010.07.29 16:45:36 | 000,002,190 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\CE\N.pl
[2010.07.29 16:45:40 | 000,006,290 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\CI\N.pl
[2010.07.29 16:45:34 | 000,002,852 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\CompEx\N.pl
[2010.07.29 16:45:40 | 000,006,973 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\CWCF\N.pl
[2010.07.29 16:45:38 | 000,003,136 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\CWCM\N.pl
[2010.07.29 16:45:34 | 000,009,716 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\CWKCF\N.pl
[2010.07.29 16:45:40 | 000,006,825 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\CWL\N.pl
[2010.07.29 16:45:40 | 000,007,240 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\CWT\N.pl
[2010.07.29 16:45:40 | 000,007,222 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\CWU\N.pl
[2010.07.29 16:45:40 | 000,001,921 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Dash\N.pl
[2010.07.29 16:45:38 | 000,001,761 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Dep\N.pl
[2010.07.29 16:45:42 | 000,001,984 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\DI\N.pl
[2010.07.29 16:45:40 | 000,003,702 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Dia\N.pl
[2010.07.29 16:45:36 | 000,005,102 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Ea\N.pl
[2010.07.29 16:45:36 | 000,002,004 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Ext\N.pl
[2010.07.29 16:45:42 | 000,008,777 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Gc\L.pl
[2010.07.29 16:45:42 | 000,003,122 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Gc\N.pl
[2010.07.29 16:45:34 | 000,002,294 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\GCB\L.pl
[2010.07.29 16:45:40 | 000,010,280 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\GrBase\N.pl
[2010.07.29 16:45:40 | 000,005,184 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\GrExt\N.pl
[2010.07.29 16:45:40 | 000,001,764 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Hex\N.pl
[2010.07.29 16:45:36 | 000,001,841 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Hyphen\N.pl
[2010.07.29 16:45:38 | 000,009,235 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\IDC\N.pl
[2010.07.29 16:45:38 | 000,001,842 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Ideo\N.pl
[2010.07.29 16:45:40 | 000,008,105 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\IDS\N.pl
[2010.07.29 16:45:42 | 000,001,687 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\IDSB\N.pl
[2010.07.29 16:45:36 | 000,001,673 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\IDST\N.pl
[2010.07.29 16:45:40 | 000,001,649 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\JoinC\N.pl
[2010.07.29 16:45:40 | 000,005,118 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Jt\U.pl
[2010.07.29 16:45:34 | 000,001,747 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\LOE\N.pl
[2010.07.29 16:45:34 | 000,007,635 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Lower\N.pl
[2010.07.29 16:45:38 | 000,003,241 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Math\N.pl
[2010.07.29 16:45:40 | 000,002,084 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\NChar\N.pl
[2010.07.29 16:45:34 | 000,005,316 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\NFDQC\N.pl
[2010.07.29 16:45:34 | 000,004,801 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\NFKCQC\N.pl
[2010.07.29 16:45:38 | 000,006,708 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\NFKDQC\N.pl
[2010.07.29 16:45:38 | 000,004,140 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\OAlpha\N.pl
[2010.07.29 16:45:40 | 000,001,981 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\ODI\N.pl
[2010.07.29 16:45:38 | 000,002,070 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\OGrExt\N.pl
[2010.07.29 16:45:40 | 000,001,778 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\OIDC\N.pl
[2010.07.29 16:45:40 | 000,001,766 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\OIDS\N.pl
[2010.07.29 16:45:34 | 000,001,977 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\OLower\N.pl
[2010.07.29 16:45:36 | 000,003,178 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\OMath\N.pl
[2010.07.29 16:45:38 | 000,001,760 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\OUpper\N.pl
[2010.07.29 16:45:40 | 000,002,112 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\PatSyn\N.pl
[2010.07.29 16:45:40 | 000,001,753 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\PatWS\N.pl
[2010.07.29 16:45:40 | 000,001,867 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\QMark\N.pl
[2010.07.29 16:45:40 | 000,001,614 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Radical\N.pl
[2010.07.29 16:45:40 | 000,002,248 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\SD\N.pl
[2010.07.29 16:45:36 | 000,002,001 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Space\N.pl
[2010.07.29 16:45:36 | 000,002,387 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\STerm\N.pl
[2010.07.29 16:45:42 | 000,002,882 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Term\N.pl
[2010.07.29 16:45:40 | 000,001,821 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\UIdeo\N.pl
[2010.07.29 16:45:34 | 000,007,498 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\Upper\N.pl
[2010.07.29 16:45:34 | 000,001,700 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\VS\N.pl
[2010.07.29 16:45:36 | 000,009,330 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\XIDC\N.pl
[2010.07.29 16:45:36 | 000,008,201 | ---- | M] () -- C:\Users\User\AppData\Local\Temp\par-User\cache-cf599bc34281b6a54ff6471f11f6253b9071563f\inc\lib\unicore\lib\XIDS\N.pl
[2012.02.07 20:54:11 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\LocalLow\Microsoft\Silverlight\is\4ehebbel.10j\ounsuszw.lb1\1\l
[2004.12.14 16:37:16 | 000,004,208 | ---- | M] () -- C:\Users\User\Documents\Sport\TT\Unzipped\map24portal_de_eur_ld2[1]\u.class
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
========== LOP Check ==========
 
[2010.06.05 12:59:54 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Amazon
[2010.04.24 23:03:04 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Canon
[2012.07.01 21:48:58 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DesktopIconForAmazon
[2012.08.02 12:23:03 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\elsterformular
[2010.09.01 22:57:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\OpenOffice.org
[2011.12.26 16:08:48 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\PC Suite
[2012.07.01 21:48:11 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Systweak
[2010.04.22 20:37:58 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TerraTec
[2010.10.07 22:52:15 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\UDC Profiles
 
========== Purity Check ==========
 
 

< End of report >

--- --- ---
OTL Logfile:
Code:

OTL Extras logfile created on: 22.09.2012 08:09:37 - Run 1
OTL by OldTimer - Version 3.2.65.1    Folder = C:\Users\User\Downloads
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 2,10 Gb Available Physical Memory | 64,62% Memory free
6,50 Gb Paging File | 5,28 Gb Available in Paging File | 81,32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 195,21 Gb Total Space | 75,07 Gb Free Space | 38,46% Space Free | Partition Type: NTFS
Drive D: | 270,45 Gb Total Space | 270,09 Gb Free Space | 99,87% Space Free | Partition Type: NTFS
Drive F: | 931,51 Gb Total Space | 399,37 Gb Free Space | 42,87% Space Free | Partition Type: NTFS
 
Computer Name: ROBERT | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Digital Photo Professional] -- C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Fotoschau] -- "C:\Users\User\Pixum EasyBook\Fotoschau.exe" -d "%1" ()
Directory [Pixum EasyBook] -- "C:\Users\User\Pixum EasyBook\Pixum EasyBook.exe" "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{07998F95-C02A-47C1-8520-083CE27419A1}" = lport=137 | protocol=17 | dir=in | app=system |
"{12E183D5-50C9-4A10-8B36-2DA0910C4B11}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1C7BBD0D-7158-406B-AA4F-E20CA258E7E7}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{25EC54FF-30BE-4C68-BDEA-3828403CF58A}" = rport=139 | protocol=6 | dir=out | app=system |
"{34455ED6-F6A9-483C-9C9E-BD4F2A72EE6E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{36ACF07E-C4EA-4604-820D-1E51B097DB3E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{44EF6D88-596D-4912-9B42-C7AF76B15307}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4C93910E-6905-40D9-BF9D-A90175414FD6}" = rport=445 | protocol=6 | dir=out | app=system |
"{5FEF8673-EAF9-4EB7-9D99-2E01DDCCE1C1}" = lport=10243 | protocol=6 | dir=in | app=system |
"{67E80439-B035-4F3E-87CA-58C167BC5FD2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{7F31742C-545F-4389-8A6E-2F8E10B97312}" = lport=445 | protocol=6 | dir=in | app=system |
"{830E7BCE-60AF-48BA-B508-44187B349250}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{837DA039-E2C6-46AA-BD5A-7F94F147E110}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8501BE2B-B9C2-412F-9FE3-526A60A4DB16}" = lport=138 | protocol=17 | dir=in | app=system |
"{9288926D-E7B9-40FB-BB9A-C34E475A66B8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9342889D-DCF8-4EE7-A212-26425D8A78C1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9FE8B6A4-97DF-421E-8373-DDB3D9F09B6E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AD1A1281-A370-4158-9252-7A35C5B80B5B}" = lport=139 | protocol=6 | dir=in | app=system |
"{ADC6C959-A373-4667-AD94-992B095EF4BD}" = rport=137 | protocol=17 | dir=out | app=system |
"{B905ABD2-ADE6-4099-8916-F2B05053310A}" = rport=10243 | protocol=6 | dir=out | app=system |
"{D522765A-D72F-4691-A375-C0FDFED35ECC}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{DFF1537B-1D9E-4244-9D4E-93D5BB597E0F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FC1EF07C-BC29-41D2-BD1F-A0C2016CD578}" = rport=138 | protocol=17 | dir=out | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04724065-58EE-48D7-B2A3-0EA78EA1F147}" = dir=in | app=c:\program files\nokia\nokia suite\nokiasuite.exe |
"{0E0C2024-6920-4E3E-A210-90F777073CCB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{432B0135-DF0B-4231-9725-8D88814DB360}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{48942EC1-DDA3-4C88-985D-017AE7B40A61}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{5891C70C-5748-40B3-BA40-81959E2587ED}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{72A07261-28D8-4D4D-BD3B-C91DBA5B8470}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{78BB5E11-8FC2-4ADF-9062-34ABE8D36232}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{81188C38-E66B-4AE8-87FE-974F1C05751E}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{831C6C8F-6467-4E96-B38E-9D7ABBAB3B8F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{99CB1438-1616-4B2D-926B-CBA234A6761A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9B04A22E-A83A-44DD-85E0-2CC8B7582473}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AE491B62-FC5D-4794-8A8F-6E9D0B050030}" = dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"{BD4720A2-81BA-4C7C-A4B1-525A14507637}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{BF05514C-E69A-493F-8A23-A7A168FB45BE}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C8F2F429-1762-4B0E-9818-A598CA5F1FDB}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{E0B1A659-8F37-4348-8612-B47A9416FA9B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E3C2774D-A8CB-4F17-8518-FBDE931BDE4F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E758D59F-7E63-442A-8EAD-2CB6B45CC04B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FEB300C9-B707-41DA-BB64-0E79B18F0CAF}" = protocol=6 | dir=out | app=system |
"TCP Query User{6180AA38-0E93-455F-BA2F-4315956E1EE1}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"TCP Query User{B4F2E3C3-2CD6-4F4E-9141-52E123C790E9}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{F2C0EB29-8B03-46FB-A472-339FDAD3FF79}C:\program files\dvbviewer te2\ts_winlirc.exe" = protocol=6 | dir=in | app=c:\program files\dvbviewer te2\ts_winlirc.exe |
"UDP Query User{0BBB3B35-4D64-415C-A3E6-0C67781B92A0}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"UDP Query User{2142F8F7-B9F4-4762-A2EF-F51CA4448B1B}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{F64C2EE8-5C93-4C79-A289-74A9E2DBCBFD}C:\program files\dvbviewer te2\ts_winlirc.exe" = protocol=17 | dir=in | app=c:\program files\dvbviewer te2\ts_winlirc.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000407-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Premium
"{00F93853-D9D3-4795-A89E-84CCBA0205C9}" = Microsoft IntelliPoint 8.0
"{02627EE5-EACA-4742-A9CC-E687631773E4}" = Nero ShowTime
"{04d40d0d-6ecf-4138-972a-0f368c3e4953}" = Nero 9 Essentials
"{09298F26-A95C-31E2-9D95-2C60F586F075}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{16480125-0428-4097-9A2A-74464004D169}" = EOS Capture 1.3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20400DBD-E6DB-45B8-9B6B-1DD7033818EC}" = Nero InfoTool Help
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{218BBBE3-FE63-4BB2-81A8-7435575A84FA}" = PhotoStitch
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 35
"{28291BD5-92D2-4685-82DC-CCA925C53CCA}" = RemoteCapture Task 1.1
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{33CF7CDF-9805-4500-9CC7-D19D52AD63C4}" = Canon Camera WIA Driver
"{368BA326-73AD-4351-84ED-3C0A7A52CC53}" = Nero Rescue Agent
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{43E39830-1826-415D-8BAE-86845787B54B}" = Nero Vision
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{55EB7967-5BB1-4EA2-8AFF-B2F9E487E553}" = PC Connectivity Solution
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5D9BE3C1-8BA4-4E7E-82FD-9F74FA6815D1}" = Nero Vision Help
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{5E08ECD1-C98E-4711-BF65-8FD736B3F969}" = Nero RescueAgent Help
"{60C731FB-C951-41CE-AD41-8E54C8594609}" = Nero Disc Copy Gadget Help
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}" = Nero CoverDesigner
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7B847C9D-6758-45E6-B598-3BD8F43EAE9E}" = Camera Window DS
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help
"{862983D7-FA08-493E-A9ED-6B7859E069D3}" = Canon PhotoRecord
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D1E61D1-1395-4E97-997F-D002DB3A5074}" = OpenOffice.org 3.2
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9973B206-7D7C-4519-A27F-23B1FD281957}" = Brother HL-2150N
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A0F34E4E-25F0-4B68-AE8F-EF0C15CB1FED}" = RAW Image Task 2.0
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
"{AD88355B-A4E0-4DA1-BAC3-EA4FEA930691}" = Ipswitch WS_FTP Professional 2007
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{AF88496B-4BBA-4922-97E9-2582D3A28358}" = Nokia Connectivity Cable Driver
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{CC019E3F-59D2-4486-8D4B-878105B62A71}" = Nero DiscSpeed Help
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE96F5A5-584D-4F8F-AA3E-9BAED413DB72}" = Nero CoverDesigner Help
"{D4CFC5F3-481C-40AA-9944-E7E4E732136C}" = Microsoft IntelliType Pro 8.0
"{D9DCF92E-72EB-412D-AC71-3B01276E5F8B}" = Nero ShowTime
"{DB24A9E5-A068-43DD-88D0-B51BED3C0B99}" = Nokia Suite
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3723A04-A894-4036-A78E-282E18F43C0A}_is1" = Tinypic 3.18
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{E498385E-1C51-459A-B45F-1721E37AA1A0}" = Movie Templates - Starter Kit
"{E5C7D048-F9B4-4219-B323-8BDB01A2563D}" = Nero DriveSpeed Help
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1861F30-3419-44DB-B2A1-C274825698B3}" = Nero Disc Copy Gadget
"{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter
"{F6BDD7C5-89ED-4569-9318-469AA9732572}" = Nero BurnRights Help
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F7E1CA14-B39D-452A-960B-39423DDDD933}" = DriveImage XML (Private Edition)
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.15
"Avira AntiVir Desktop" = Avira Free Antivirus
"CameraWindowDC8" = Canon Utilities CameraWindow DC 8
"CameraWindowLauncher" = Canon Utilities CameraWindow
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"Canon RAW Codec" = Canon RAW Codec
"Childsplay_is1" = Childsplay 1.6
"CoreAAC" = CoreAAC
"DPP" = Canon Utilities Digital Photo Professional 3.8
"ElsterFormular 11.5.0.4546" = ElsterFormular-Upgrade
"GOM Picker" = GOM PICKER
"GOM Player" = GOM Player
"GOM Video Converter" = GOM Video Converter
"InstallShield_{16480125-0428-4097-9A2A-74464004D169}" = Canon Utilities EOS Capture 1.3
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Plattform-Geräte-Manager
"InstallShield_{218BBBE3-FE63-4BB2-81A8-7435575A84FA}" = Canon Utilities PhotoStitch 3.1
"InstallShield_{28291BD5-92D2-4685-82DC-CCA925C53CCA}" = Canon RemoteCapture Task for ZoomBrowser EX
"InstallShield_{33CF7CDF-9805-4500-9CC7-D19D52AD63C4}" = Canon EOS Kiss_N REBEL_XT 350D WIA-Treiber
"InstallShield_{7B847C9D-6758-45E6-B598-3BD8F43EAE9E}" = Canon Camera Window DS for ZoomBrowser EX
"InstallShield_{A0F34E4E-25F0-4B68-AE8F-EF0C15CB1FED}" = Canon RAW Image Task for ZoomBrowser EX
"Mediaport" = Mediaport
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox 15.0.1 (x86 de)" = Mozilla Firefox 15.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MPEG2 Codec(libmpeg2/mad)" = MPEG2 Codec(libmpeg2/mad)
"MyCamera" = Canon Utilities MyCamera
"MyTeVii" = myTeVii
"Nokia Suite" = Nokia Suite
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Picture Style Editor" = Canon Utilities Picture Style Editor
"Pixum EasyBook" = Pixum EasyBook
"WinLiveSuite_Wave3" = Windows Live Essentials
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 11.01.2012 07:24:49 | Computer Name = robert | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 11.01.2012 07:24:53 | Computer Name = robert | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 11.01.2012 07:25:18 | Computer Name = robert | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 12.01.2012 01:41:09 | Computer Name = robert | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 12.01.2012 01:41:09 | Computer Name = robert | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 12.01.2012 08:27:50 | Computer Name = robert | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 12.01.2012 08:27:50 | Computer Name = robert | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 12.01.2012 12:44:04 | Computer Name = robert | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\runtime
 software\driveimage xml\vss64.exe".  Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8""
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
 "sxstrace.exe".
 
Error - 13.01.2012 01:50:07 | Computer Name = robert | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 13.01.2012 01:50:07 | Computer Name = robert | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
[ System Events ]
Error - 11.09.2012 01:37:05 | Computer Name = robert | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
 
Error - 11.09.2012 15:45:02 | Computer Name = robert | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
 
Error - 11.09.2012 17:01:55 | Computer Name = robert | Source = Service Control Manager | ID = 7016
Description = Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen
 Status gemeldet: 32
 
Error - 13.09.2012 02:39:50 | Computer Name = robert | Source = Service Control Manager | ID = 7016
Description = Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen
 Status gemeldet: 32
 
Error - 15.09.2012 05:00:50 | Computer Name = robert | Source = Service Control Manager | ID = 7016
Description = Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen
 Status gemeldet: 32
 
Error - 16.09.2012 04:56:23 | Computer Name = robert | Source = Service Control Manager | ID = 7016
Description = Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen
 Status gemeldet: 32
 
Error - 19.09.2012 17:14:45 | Computer Name = robert | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 20.09.2012 07:26:08 | Computer Name = robert | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 21.09.2012 07:31:37 | Computer Name = robert | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 21.09.2012 10:23:53 | Computer Name = robert | Source = Service Control Manager | ID = 7016
Description = Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen
 Status gemeldet: 32
 
 
< End of report >

--- --- ---

Avira Free Antivirus
Erstellungsdatum der Reportdatei: Freitag, 21. September 2012 18:14

Es wird nach 4250358 Virenstämmen gesucht.

Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer : Avira AntiVir Personal - Free Antivirus
Seriennummer : 0000149996-ADJIE-0000001
Plattform : Windows 7 Home Premium
Windowsversion : (Service Pack 1) [6.1.7601]
Boot Modus : Normal gebootet
Benutzername : SYSTEM
Computername : ROBERT

Versionsinformationen:
BUILD.DAT : 12.0.0.1199 40869 Bytes 07.09.2012 22:14:00
AVSCAN.EXE : 12.3.0.33 468472 Bytes 08.08.2012 07:21:43
AVSCAN.DLL : 12.3.0.15 66256 Bytes 08.05.2012 18:06:10
LUKE.DLL : 12.3.0.15 68304 Bytes 08.05.2012 18:06:11
AVSCPLR.DLL : 12.3.0.14 97032 Bytes 08.05.2012 18:06:11
AVREG.DLL : 12.3.0.17 232200 Bytes 10.05.2012 18:06:02
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06.11.2009 18:18:34
VBASE001.VDF : 7.11.0.0 13342208 Bytes 14.12.2010 23:31:49
VBASE002.VDF : 7.11.19.170 14374912 Bytes 20.12.2011 06:46:54
VBASE003.VDF : 7.11.21.238 4472832 Bytes 01.02.2012 06:46:57
VBASE004.VDF : 7.11.26.44 4329472 Bytes 28.03.2012 20:38:21
VBASE005.VDF : 7.11.34.116 4034048 Bytes 29.06.2012 16:52:24
VBASE006.VDF : 7.11.41.250 4902400 Bytes 06.09.2012 13:52:59
VBASE007.VDF : 7.11.41.251 2048 Bytes 06.09.2012 13:52:59
VBASE008.VDF : 7.11.41.252 2048 Bytes 06.09.2012 13:52:59
VBASE009.VDF : 7.11.41.253 2048 Bytes 06.09.2012 13:52:59
VBASE010.VDF : 7.11.41.254 2048 Bytes 06.09.2012 13:52:59
VBASE011.VDF : 7.11.41.255 2048 Bytes 06.09.2012 13:52:59
VBASE012.VDF : 7.11.42.0 2048 Bytes 06.09.2012 13:53:00
VBASE013.VDF : 7.11.42.1 2048 Bytes 06.09.2012 13:53:00
VBASE014.VDF : 7.11.42.65 203264 Bytes 09.09.2012 16:16:04
VBASE015.VDF : 7.11.42.125 156672 Bytes 11.09.2012 06:33:20
VBASE016.VDF : 7.11.42.171 187904 Bytes 12.09.2012 06:33:20
VBASE017.VDF : 7.11.42.235 141312 Bytes 13.09.2012 09:09:40
VBASE018.VDF : 7.11.43.35 133632 Bytes 15.09.2012 06:59:54
VBASE019.VDF : 7.11.43.89 129024 Bytes 18.09.2012 06:59:55
VBASE020.VDF : 7.11.43.141 130560 Bytes 19.09.2012 11:26:20
VBASE021.VDF : 7.11.43.187 121856 Bytes 21.09.2012 11:31:45
VBASE022.VDF : 7.11.43.188 2048 Bytes 21.09.2012 11:31:45
VBASE023.VDF : 7.11.43.189 2048 Bytes 21.09.2012 11:31:45
VBASE024.VDF : 7.11.43.190 2048 Bytes 21.09.2012 11:31:45
VBASE025.VDF : 7.11.43.191 2048 Bytes 21.09.2012 11:31:45
VBASE026.VDF : 7.11.43.192 2048 Bytes 21.09.2012 11:31:45
VBASE027.VDF : 7.11.43.193 2048 Bytes 21.09.2012 11:31:45
VBASE028.VDF : 7.11.43.194 2048 Bytes 21.09.2012 11:31:45
VBASE029.VDF : 7.11.43.195 2048 Bytes 21.09.2012 11:31:45
VBASE030.VDF : 7.11.43.196 2048 Bytes 21.09.2012 11:31:45
VBASE031.VDF : 7.11.43.212 73728 Bytes 21.09.2012 16:14:10
Engineversion : 8.2.10.164
AEVDF.DLL : 8.1.2.10 102772 Bytes 12.07.2012 19:47:31
AESCRIPT.DLL : 8.1.4.54 459131 Bytes 19.09.2012 06:59:58
AESCN.DLL : 8.1.8.2 131444 Bytes 12.02.2012 06:47:03
AESBX.DLL : 8.2.5.12 606578 Bytes 14.06.2012 15:38:47
AERDL.DLL : 8.1.9.15 639348 Bytes 14.12.2011 23:31:02
AEPACK.DLL : 8.3.0.36 811382 Bytes 15.09.2012 09:10:50
AEOFFICE.DLL : 8.1.2.42 201083 Bytes 20.07.2012 12:53:18
AEHEUR.DLL : 8.1.4.100 5280120 Bytes 15.09.2012 09:10:44
AEHELP.DLL : 8.1.23.2 258422 Bytes 28.06.2012 16:52:29
AEGEN.DLL : 8.1.5.36 434549 Bytes 24.08.2012 15:44:12
AEEXP.DLL : 8.1.0.86 90484 Bytes 07.09.2012 16:19:51
AEEMU.DLL : 8.1.3.2 393587 Bytes 12.07.2012 19:47:31
AECORE.DLL : 8.1.27.4 201078 Bytes 08.08.2012 07:21:42
AEBB.DLL : 8.1.1.0 53618 Bytes 14.12.2011 23:30:58
AVWINLL.DLL : 12.3.0.15 27344 Bytes 08.05.2012 18:06:10
AVPREF.DLL : 12.3.0.15 51920 Bytes 08.05.2012 18:06:10
AVREP.DLL : 12.3.0.15 179208 Bytes 08.05.2012 18:06:11
AVARKT.DLL : 12.3.0.15 211408 Bytes 08.05.2012 18:06:10
AVEVTLOG.DLL : 12.3.0.15 169168 Bytes 08.05.2012 18:06:10
SQLITE3.DLL : 3.7.0.1 398288 Bytes 08.05.2012 18:06:11
AVSMTP.DLL : 12.3.0.32 63480 Bytes 08.08.2012 07:21:43
NETNT.DLL : 12.3.0.15 17104 Bytes 08.05.2012 18:06:11
RCIMAGE.DLL : 12.3.0.31 4444408 Bytes 08.08.2012 07:21:41
RCTEXT.DLL : 12.3.0.31 100088 Bytes 08.08.2012 07:21:41

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: Vollständige Systemprüfung
Konfigurationsdatei...................: C:\program files\avira\antivir desktop\sysscan.avp
Protokollierung.......................: standard
Primäre Aktion........................: interaktiv
Sekundäre Aktion......................: ignorieren
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: ein
Bootsektoren..........................: C:, D:, F:,
Durchsuche aktive Programme...........: ein
Laufende Programme erweitert..........: ein
Durchsuche Registrierung..............: ein
Suche nach Rootkits...................: ein
Integritätsprüfung von Systemdateien..: aus
Datei Suchmodus.......................: Alle Dateien
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: erweitert

Beginn des Suchlaufs: Freitag, 21. September 2012 18:14

Der Suchlauf über die Masterbootsektoren wird begonnen:
Masterbootsektor HD0
[INFO] Es wurde kein Virus gefunden!
Masterbootsektor HD1
[INFO] Es wurde kein Virus gefunden!

Der Suchlauf über die Bootsektoren wird begonnen:
Bootsektor 'C:\'
[INFO] Es wurde kein Virus gefunden!
Bootsektor 'D:\'
[INFO] Es wurde kein Virus gefunden!
Bootsektor 'F:\'
[INFO] Es wurde kein Virus gefunden!

Der Suchlauf nach versteckten Objekten wird begonnen.

Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'SearchFilterHost.exe' - '27' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchProtocolHost.exe' - '29' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'vssvc.exe' - '47' Modul(e) wurden durchsucht
Durchsuche Prozess 'avscan.exe' - '89' Modul(e) wurden durchsucht
Durchsuche Prozess 'avcenter.exe' - '111' Modul(e) wurden durchsucht
Durchsuche Prozess 'AUDIODG.EXE' - '38' Modul(e) wurden durchsucht
Durchsuche Prozess 'WINWORD.EXE' - '62' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'FlashPlayerPlugin_11_4_402_278.exe' - '62' Modul(e) wurden durchsucht
Durchsuche Prozess 'FlashPlayerPlugin_11_4_402_278.exe' - '40' Modul(e) wurden durchsucht
Durchsuche Prozess 'plugin-container.exe' - '69' Modul(e) wurden durchsucht
Durchsuche Prozess 'firefox.exe' - '126' Modul(e) wurden durchsucht
Durchsuche Prozess 'NclMSBTSrvEx.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '59' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '63' Modul(e) wurden durchsucht
Durchsuche Prozess 'wmpnetwk.exe' - '113' Modul(e) wurden durchsucht
Durchsuche Prozess 'NclUSBSrv.exe' - '26' Modul(e) wurden durchsucht
Durchsuche Prozess 'ServiceLayer.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchIndexer.exe' - '63' Modul(e) wurden durchsucht
Durchsuche Prozess 'soffice.bin' - '102' Modul(e) wurden durchsucht
Durchsuche Prozess 'soffice.exe' - '18' Modul(e) wurden durchsucht
Durchsuche Prozess 'NokiaSuite.exe' - '198' Modul(e) wurden durchsucht
Durchsuche Prozess 'StikyNot.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'jusched.exe' - '23' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '82' Modul(e) wurden durchsucht
Durchsuche Prozess 'brpjp04a.exe' - '27' Modul(e) wurden durchsucht
Durchsuche Prozess 'TeViiRC.exe' - '48' Modul(e) wurden durchsucht
Durchsuche Prozess 'ipoint.exe' - '61' Modul(e) wurden durchsucht
Durchsuche Prozess 'itype.exe' - '59' Modul(e) wurden durchsucht
Durchsuche Prozess 'BrStsWnd.exe' - '26' Modul(e) wurden durchsucht
Durchsuche Prozess 'VDeck.exe' - '49' Modul(e) wurden durchsucht
Durchsuche Prozess 'Explorer.EXE' - '162' Modul(e) wurden durchsucht
Durchsuche Prozess 'Dwm.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'taskhost.exe' - '52' Modul(e) wurden durchsucht
Durchsuche Prozess 'conhost.exe' - '14' Modul(e) wurden durchsucht
Durchsuche Prozess 'avshadow.exe' - '31' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '32' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvSCPAPISvr.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '21' Modul(e) wurden durchsucht
Durchsuche Prozess 'NBService.exe' - '51' Modul(e) wurden durchsucht
Durchsuche Prozess 'avguard.exe' - '65' Modul(e) wurden durchsucht
Durchsuche Prozess 'armsvc.exe' - '23' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvvsvc.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '63' Modul(e) wurden durchsucht
Durchsuche Prozess 'sched.exe' - '41' Modul(e) wurden durchsucht
Durchsuche Prozess 'spoolsv.exe' - '82' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '73' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '77' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '156' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '107' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '95' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvvsvc.exe' - '19' Modul(e) wurden durchsucht
Durchsuche Prozess 'winlogon.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '41' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '52' Modul(e) wurden durchsucht
Durchsuche Prozess 'lsm.exe' - '16' Modul(e) wurden durchsucht
Durchsuche Prozess 'lsass.exe' - '63' Modul(e) wurden durchsucht
Durchsuche Prozess 'services.exe' - '33' Modul(e) wurden durchsucht
Durchsuche Prozess 'csrss.exe' - '16' Modul(e) wurden durchsucht
Durchsuche Prozess 'wininit.exe' - '26' Modul(e) wurden durchsucht
Durchsuche Prozess 'csrss.exe' - '18' Modul(e) wurden durchsucht
Durchsuche Prozess 'smss.exe' - '2' Modul(e) wurden durchsucht

Der Suchlauf auf Verweise zu ausführbaren Dateien (Registry) wird begonnen:
Die Registry wurde durchsucht ( '1881' Dateien ).


Der Suchlauf über die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\'
C:\myTeVii\Uninstall.exe
[WARNUNG] Unerwartetes Dateiende erreicht
C:\Program Files\CoreAAC\Uninstall.exe
[WARNUNG] Unerwartetes Dateiende erreicht
C:\Program Files\GNU\MPEG2\Uninstall.exe
[WARNUNG] Unerwartetes Dateiende erreicht
C:\Program Files\GRETECH\GomPicker\Uninstall.exe
[WARNUNG] Unerwartetes Dateiende erreicht
C:\Users\User\AppData\Local\Microsoft\Windows Live Mail\Online (rob 7cc\Deleted Items\3D88358A-00003527.eml
[0] Archivtyp: MIME
--> FedEx_Label_ID_Order_83-27-4534US.zip
[1] Archivtyp: ZIP
--> FedEx_Label_ID_Order_83-27-4534US.exe
[FUND] Ist das Trojanische Pferd TR/Dropper.Gen
C:\Users\User\AppData\Local\Temp\jar_cache6090344143095132872.tmp
[WARNUNG] Unerwartetes Dateiende erreicht
C:\Users\User\AppData\Local\Temp\IM_96D0.tmp\terms.7z
[WARNUNG] Der Archivheader ist defekt
C:\Users\User\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\77b39d24-59a13b5b
[0] Archivtyp: ZIP
--> t6a/t6c.class
[FUND] Enthält Erkennungsmuster des Java-Virus JAVA/Dldr.Lamar.DY
--> t6a/t6a.class
[FUND] Enthält Erkennungsmuster des Exploits EXP/CVE-2012-1723.X
--> t6a/t6d.class
[FUND] Enthält Erkennungsmuster des Exploits EXP/CVE-2012-0507.CJ
C:\Users\User\Documents\Mixed\Rest\t-online\EMAIL2\ANLAGEN\winamp3_0-full.exe
[WARNUNG] Die Version dieses Archives wird nicht unterstützt
C:\Users\User\Documents\Mixed\Rest\t-online\EMAIL2\ANLAGEN\winzip80.exe
[WARNUNG] Die Datei ist kennwortgeschützt
C:\Users\User\Downloads\avira_free_antivirus_de(1).exe
[WARNUNG] Die Datei ist kennwortgeschützt
C:\Users\User\Downloads\avira_free_antivirus_de(2).exe
[WARNUNG] Die Datei ist kennwortgeschützt
C:\Users\User\Downloads\avira_free_antivirus_de.exe
[WARNUNG] Die Datei ist kennwortgeschützt
Beginne mit der Suche in 'D:\'
Beginne mit der Suche in 'F:\' <Expansion Drive>
F:\Dateien\Mixed\Rest\t-online\EMAIL2\ANLAGEN\winamp3_0-full.exe
[WARNUNG] Die Version dieses Archives wird nicht unterstützt
F:\Dateien\Mixed\Rest\t-online\EMAIL2\ANLAGEN\winzip80.exe
[WARNUNG] Die Datei ist kennwortgeschützt
F:\Musik\Eigene Musik\StationRipper\uninst.exe
[WARNUNG] Die Version dieses Archives wird nicht unterstützt
F:\ROBERT\Backup Set 2011-07-11 162042\Backup Files 2011-07-11 162042\Backup files 2.zip
[WARNUNG] Die Version dieses Archives wird nicht unterstützt
F:\ROBERT\Backup Set 2011-10-02 190002\Backup Files 2011-10-02 190002\Backup files 2.zip
[WARNUNG] Die Version dieses Archives wird nicht unterstützt
F:\ROBERT\Backup Set 2011-10-02 190002\Backup Files 2011-10-16 190002\Backup files 9.zip
[WARNUNG] Die Datei ist kennwortgeschützt
F:\ROBERT\Backup Set 2011-10-02 190002\Backup Files 2011-10-23 190002\Backup files 7.zip
[WARNUNG] Die Datei ist kennwortgeschützt
F:\ROBERT\Backup Set 2012-01-22 190002\Backup Files 2012-01-22 190002\Backup files 41.zip
[WARNUNG] Die Datei ist kennwortgeschützt
F:\ROBERT\Backup Set 2012-01-22 190002\Backup Files 2012-02-12 190003\Backup files 5.zip
[WARNUNG] Die Datei ist kennwortgeschützt
F:\ROBERT\Backup Set 2012-04-15 190004\Backup Files 2012-04-15 190004\Backup files 38.zip
[WARNUNG] Die Datei ist kennwortgeschützt
F:\ROBERT\Backup Set 2012-04-15 190004\Backup Files 2012-04-15 190004\Backup files 39.zip
[WARNUNG] Die Datei ist kennwortgeschützt
F:\ROBERT\Backup Set 2012-04-15 190004\Backup Files 2012-06-17 190004\Backup files 1.zip
[0] Archivtyp: ZIP
--> C/Users/User/AppData/Local/Microsoft/Windows Live Mail/Online (rob 7cc/Deleted Items/3D88358A-00003527.eml
[1] Archivtyp: MIME
--> FedEx_Label_ID_Order_83-27-4534US.zip
[2] Archivtyp: ZIP
--> FedEx_Label_ID_Order_83-27-4534US.exe
[FUND] Ist das Trojanische Pferd TR/Dropper.Gen
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-07-15 190006\Backup files 18.zip
[0] Archivtyp: ZIP
--> C/Users/User/AppData/Local/Mozilla/Firefox/Profiles/kdie60r2.default/Cache/4/BF/E0BD2d01
[FUND] Enthält Erkennungsmuster des Java-Scriptvirus JS/Expack.WJ
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-07-15 190006\Backup files 22.zip
[0] Archivtyp: ZIP
--> C/Users/User/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/36/77b39d24-59a13b5b
[1] Archivtyp: ZIP
--> t6a/t6c.class
[FUND] Enthält Erkennungsmuster des Java-Virus JAVA/Dldr.Lamar.DY
--> t6a/t6a.class
[FUND] Enthält Erkennungsmuster des Exploits EXP/CVE-2012-1723.X
--> t6a/t6d.class
[FUND] Enthält Erkennungsmuster des Exploits EXP/CVE-2012-0507.CJ
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-07-15 190006\Backup files 30.zip
[WARNUNG] Die Datei ist kennwortgeschützt
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-07-15 190006\Backup files 31.zip
[WARNUNG] Die Datei ist kennwortgeschützt
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-07-15 190006\Backup files 7.zip
[0] Archivtyp: ZIP
--> C/Users/User/AppData/Local/Microsoft/Windows Live Mail/Online (rob 7cc/Deleted Items/3D88358A-00003527.eml
[1] Archivtyp: MIME
--> FedEx_Label_ID_Order_83-27-4534US.zip
[2] Archivtyp: ZIP
--> FedEx_Label_ID_Order_83-27-4534US.exe
[FUND] Ist das Trojanische Pferd TR/Dropper.Gen

Beginne mit der Desinfektion:
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-07-15 190006\Backup files 7.zip
[FUND] Ist das Trojanische Pferd TR/Dropper.Gen
[HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '5523fea2.qua' verschoben!
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-07-15 190006\Backup files 22.zip
[FUND] Enthält Erkennungsmuster des Exploits EXP/CVE-2012-0507.CJ
[HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4db4d108.qua' verschoben!
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-07-15 190006\Backup files 18.zip
[FUND] Enthält Erkennungsmuster des Java-Scriptvirus JS/Expack.WJ
[HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '1feb8bfd.qua' verschoben!
F:\ROBERT\Backup Set 2012-04-15 190004\Backup Files 2012-06-17 190004\Backup files 1.zip
[FUND] Ist das Trojanische Pferd TR/Dropper.Gen
[HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '79dcc439.qua' verschoben!
C:\Users\User\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\77b39d24-59a13b5b
[FUND] Enthält Erkennungsmuster des Exploits EXP/CVE-2012-0507.CJ
[HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '3c27e966.qua' verschoben!
C:\Users\User\AppData\Local\Microsoft\Windows Live Mail\Online (rob 7cc\Deleted Items\3D88358A-00003527.eml
[FUND] Ist das Trojanische Pferd TR/Dropper.Gen
[HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4316db72.qua' verschoben!


Ende des Suchlaufs: Samstag, 22. September 2012 07:58
Benötigte Zeit: 5:54:24 Stunde(n)

Der Suchlauf wurde vollständig durchgeführt.

25235 Verzeichnisse wurden überprüft
6143898 Dateien wurden geprüft
10 Viren bzw. unerwünschte Programme wurden gefunden
0 Dateien wurden als verdächtig eingestuft
0 Dateien wurden gelöscht
0 Viren bzw. unerwünschte Programme wurden repariert
6 Dateien wurden in die Quarantäne verschoben
0 Dateien wurden umbenannt
0 Dateien konnten nicht durchsucht werden
6143888 Dateien ohne Befall
523668 Archive wurden durchsucht
24 Warnungen
6 Hinweise
490799 Objekte wurden beim Rootkitscan durchsucht
0 Versteckte Objekte wurden gefunden

cosinus 22.09.2012 14:49

Bitte erstmal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

rwt69 23.09.2012 11:12

Erstmal vielen Dank, dass jemand so nett ist und sich meiner Probleme annimmt, wirklich super !!

Hier das Ergebnis des Vollscans mit Malwarebytes (hat ein wenig gedauert, das Microsoft-Update kam dazwischen), jetzt mach ich mich an ESET ran.

Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.22.06

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
User :: ROBERT [Administrator]

Schutz: Aktiviert

23.09.2012 09:40:44
mbam-log-2012-09-23 (09-40-44).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 536633
Laufzeit: 2 Stunde(n), 6 Minute(n), 41 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 1
HKLM\System\CurrentControlSet\Services\SkyNetU2CBDA (Rootkit.TDSS) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\User\Downloads\7ZipSetup.exe (PUP.BundleInstaller.BI) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\System32\drivers\SkyNetU2CBDA.sys (Rootkit.TDSS) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Ähm, ich glaub ich hab mit meinem Router im Keller ne Firewall, aber keine Ahunung wie man so was ein bzw. ausschaltet. Kann ich ESET trotzdem starten ?

cosinus 23.09.2012 17:34

Am Router musst du nichts ändern! Und die Windows-Firewall kann auch aktiv bleiben

rwt69 24.09.2012 05:37

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=5297c7c2aa2cd24791fb30662b5d056c
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-09-24 04:01:22
# local_time=2012-09-24 06:01:22 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 19369873 19369873 0 0
# compatibility_mode=5893 16776574 100 94 42067376 100026627 0 0
# compatibility_mode=8192 67108863 100 0 103 103 0 0
# scanned=356046
# found=47
# cleaned=0
# scan_time=63846
C:\myTeVii\MyTheatre.exe        a variant of Win32/Packed.Themida application (unable to clean)        00000000000000000000000000000000        I
C:\Users\User\AppData\Local\Temp\ICReinstall_VideoConverterSetup.exe        a variant of Win32/InstallCore.AW application (unable to clean)        00000000000000000000000000000000        I
C:\Users\User\AppData\Local\Temp\jar_cache9033468498248240580.tmp        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\Users\User\AppData\Local\Temp\is357113909\FunmoodsLatest.exe        a variant of Win32/Toolbar.Funmoods application (unable to clean)        00000000000000000000000000000000        I
C:\Users\User\AppData\Local\Temp\is357113909\GiantSavings_US.exe        a variant of Win32/Toolbar.CrossRider.A application (unable to clean)        00000000000000000000000000000000        I
C:\Users\User\Documents\Mixed\Computer\washandgo.exe        a variant of MSIL/Packed.PvLogNetProtector.B application (unable to clean)        00000000000000000000000000000000        I
C:\Users\User\Documents\Mixed\Rest\t-online\EMAIL2\ANLAGEN\filme\einfach_gut.zip        probably a variant of Win32/Agent.JWCZWXL trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\User\Downloads\VideoConverterSetup.exe        a variant of Win32/InstallCore.AW application (unable to clean)        00000000000000000000000000000000        I
C:\Users\User\Downloads\WinMaximizer.exe        a variant of Win32/SlowPCfighter application (unable to clean)        00000000000000000000000000000000        I
F:\Dateien\Mixed\Computer\washandgo.exe        a variant of MSIL/Packed.PvLogNetProtector.B application (unable to clean)        00000000000000000000000000000000        I
F:\Dateien\Mixed\Rest\t-online\EMAIL2\ANLAGEN\filme\einfach_gut.zip        probably a variant of Win32/Agent.JWCZWXL trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2010-07-05 133749\Backup Files 2010-07-11 190000\Backup files 1.zip        a variant of MSIL/Packed.PvLogNetProtector.B application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2010-07-05 133749\Backup Files 2010-07-11 190000\Backup files 11.zip        probably a variant of Win32/Agent.JWCZWXL trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2010-09-05 195607\Backup Files 2010-09-05 195607\Backup files 1.zip        a variant of MSIL/Packed.PvLogNetProtector.B application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2010-09-05 195607\Backup Files 2010-09-05 195607\Backup files 19.zip        probably a variant of Win32/Agent.JWCZWXL trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2010-09-05 195607\Backup Files 2010-10-03 190000\Backup files 1.zip        a variant of Win32/SlowPCfighter application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2010-10-31 190000\Backup Files 2010-10-31 190000\Backup files 1.zip        a variant of MSIL/Packed.PvLogNetProtector.B application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2010-10-31 190000\Backup Files 2010-10-31 190000\Backup files 10.zip        a variant of Win32/SlowPCfighter application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2010-10-31 190000\Backup Files 2010-10-31 190000\Backup files 18.zip        probably a variant of Win32/Agent.JWCZWXL trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2011-01-23 190000\Backup Files 2011-01-23 190000\Backup files 1.zip        a variant of MSIL/Packed.PvLogNetProtector.B application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2011-01-23 190000\Backup Files 2011-01-23 190000\Backup files 13.zip        a variant of Win32/SlowPCfighter application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2011-01-23 190000\Backup Files 2011-01-23 190000\Backup files 20.zip        probably a variant of Win32/Agent.JWCZWXL trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2011-04-10 190000\Backup Files 2011-04-10 190000\Backup files 1.zip        a variant of MSIL/Packed.PvLogNetProtector.B application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2011-04-10 190000\Backup Files 2011-04-10 190000\Backup files 13.zip        a variant of Win32/SlowPCfighter application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2011-04-10 190000\Backup Files 2011-04-10 190000\Backup files 20.zip        probably a variant of Win32/Agent.JWCZWXL trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2011-07-11 162042\Backup Files 2011-07-11 162042\Backup files 1.zip        a variant of MSIL/Packed.PvLogNetProtector.B application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2011-07-11 162042\Backup Files 2011-07-11 162042\Backup files 16.zip        a variant of Win32/SlowPCfighter application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2011-07-11 162042\Backup Files 2011-07-11 162042\Backup files 26.zip        probably a variant of Win32/Agent.JWCZWXL trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2011-10-02 190002\Backup Files 2011-10-02 190002\Backup files 1.zip        a variant of MSIL/Packed.PvLogNetProtector.B application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2011-10-02 190002\Backup Files 2011-10-02 190002\Backup files 17.zip        a variant of Win32/SlowPCfighter application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2011-10-02 190002\Backup Files 2011-10-02 190002\Backup files 25.zip        probably a variant of Win32/Agent.JWCZWXL trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-01-22 190002\Backup Files 2012-01-22 190002\Backup files 1.zip        a variant of MSIL/Packed.PvLogNetProtector.B application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-01-22 190002\Backup Files 2012-01-22 190002\Backup files 34.zip        a variant of Win32/SlowPCfighter application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-01-22 190002\Backup Files 2012-01-22 190002\Backup files 45.zip        probably a variant of Win32/Agent.JWCZWXL trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-04-15 190004\Backup Files 2012-04-15 190004\Backup files 1.zip        a variant of MSIL/Packed.PvLogNetProtector.B application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-04-15 190004\Backup Files 2012-04-15 190004\Backup files 33.zip        a variant of Win32/SlowPCfighter application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-04-15 190004\Backup Files 2012-04-15 190004\Backup files 43.zip        probably a variant of Win32/Agent.JWCZWXL trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-04-15 190004\Backup Files 2012-07-08 190005\Backup files 3.zip        JS/TrojanDownloader.Iframe.NKE trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-04-15 190004\Backup Files 2012-07-08 190005\Backup files 5.zip        HTML/ScrInject.B.Gen virus (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-04-15 190004\Backup Files 2012-07-08 190005\Backup files 7.zip        JS/TrojanDownloader.Iframe.NKE trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-04-15 190004\Backup Files 2012-07-08 190005\Backup files 9.zip        JS/TrojanDownloader.Iframe.NKE trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-07-15 190006\Backup files 1.zip        a variant of MSIL/Packed.PvLogNetProtector.B application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-07-15 190006\Backup files 17.zip        JS/TrojanDownloader.Iframe.NKE trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-07-15 190006\Backup files 19.zip        JS/TrojanDownloader.Iframe.NKE trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-07-15 190006\Backup files 24.zip        a variant of Win32/SlowPCfighter application (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-07-15 190006\Backup files 35.zip        probably a variant of Win32/Agent.JWCZWXL trojan (unable to clean)        00000000000000000000000000000000        I
F:\ROBERT\Backup Set 2012-07-15 190006\Backup Files 2012-09-23 190005\Backup files 1.zip        a variant of Win32/InstallCore.AW application (unable to clean)        00000000000000000000000000000000        I


cosinus 24.09.2012 14:48

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.

Falls der adwCleaner schon mal in der runtergeladen wurde, bitte die alte adwcleaner.exe löschen und neu runterladen!!
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Rx].txt. (x=fortlaufende Nummer)

rwt69 24.09.2012 16:24

Voila ....
Code:

# AdwCleaner v2.003 - Datei am 09/24/2012 um 17:23:59 erstellt
# Aktualisiert am 23/09/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzer : User - ROBERT
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\User\Downloads\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gefunden : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
Datei Gefunden : C:\user.js
Ordner Gefunden : C:\ProgramData\Babylon

***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKCU\Software\Conduit
Schlüssel Gefunden : HKCU\Software\IM
Schlüssel Gefunden : HKCU\Software\ImInstaller
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Schlüssel Gefunden : HKLM\Software\Babylon
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Software
Schlüssel Gefunden : HKLM\Software\Web Assistant
Schlüssel Gefunden : HKU\S-1-5-21-2451268535-3787092718-403381534-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gefunden : HKU\S-1-5-21-2451268535-3787092718-403381534-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://mystart.incredibar.com/mb174?a=6R8FQJiBhA&i=26

-\\ Mozilla Firefox v15.0.1 (de)

*************************

AdwCleaner[R1].txt - [2504 octets] - [24/09/2012 17:23:59]

########## EOF - C:\AdwCleaner[R1].txt - [2564 octets] ##########

Dieses babylondingens kann gerne auch gleich runter, dachte ich bin das schon los ... ?

cosinus 24.09.2012 20:13

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Sx].txt. (x=fortlaufende Nummer)

rwt69 24.09.2012 22:39

Gemacht:

Code:

# AdwCleaner v2.003 - Datei am 09/24/2012 um 23:31:48 erstellt
# Aktualisiert am 23/09/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzer : User - ROBERT
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\User\Downloads\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
Datei Gelöscht : C:\user.js
Ordner Gelöscht : C:\ProgramData\Babylon

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\ImInstaller
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Software
Schlüssel Gelöscht : HKLM\Software\Web Assistant
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://mystart.incredibar.com/mb174?a=6R8FQJiBhA&i=26 --> hxxp://www.google.com

-\\ Mozilla Firefox v15.0.1 (de)

*************************

AdwCleaner[R1].txt - [2633 octets] - [24/09/2012 17:23:59]
AdwCleaner[R2].txt - [2693 octets] - [24/09/2012 17:33:13]
AdwCleaner[S1].txt - [2736 octets] - [24/09/2012 23:31:48]

########## EOF - C:\AdwCleaner[S1].txt - [2796 octets] ##########


cosinus 25.09.2012 11:56

Hätte da mal drei Fragen bevor es weiter geht (wir sind noch nicht fertig!)

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?
3.) Die Werbeeinblendungen bzw Weiterleitungen wie zB Incredibar oder Mystart sind nun weg?

rwt69 25.09.2012 16:12

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?

=> Bei Windows hatte ich keine Einschränkungen bemerkt. Gibt es da etwas auf was man ein besonderes Augenmerk haben müsste ?

2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

=> Keine leeren Ordner und soweit ich das überblicke fehlt auch nichts.

3.) Die Werbeeinblendungen bzw Weiterleitungen wie zB Incredibar oder Mystart sind nun weg?

Also im IE (den ich weniger benutze scheint alles normal zu sein). In Firefox ist zwar die Toolbar von Incredibar weg, aber die Startseite wart bis jetzt immer noch Mystart. Ich hab jetzt mal Google wieder als neue Startseite eingerichtet .... klappt !
Google ist nun wieder Startseite. (Hab sogar unwissentlich was dazugelernt, man kann sogar mehrere Startseiten gleichzeitig speichern ;-) )

Das einzige, was noch erkennbar anders ist: Im IE ist die obere Leiste (Menueleiste) wie früher, die untere Leiste (Lesezeichen-Symbolleiste) erscheint mir in etwas größerer Schrift und anderer Schriftart als früher.

Bis jetzt ist das Ergebnis jedenfalls schon super, vielen vielen Dank für die Hilfe !
(Kann man das Trojanerboard eigentlich mit Spenden unterstützen ?)

cosinus 25.09.2012 19:15

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


rwt69 25.09.2012 19:48

Also, wie spenden hier geht hab ich gefunden und auch schon gemacht ... hier jetzt das neue OTL-Tag:

OTL Logfile:
Code:

OTL logfile created on: 25.09.2012 20:32:33 - Run 2
OTL by OldTimer - Version 3.2.68.0    Folder = C:\Users\User\Downloads
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 2,13 Gb Available Physical Memory | 65,63% Memory free
6,50 Gb Paging File | 5,23 Gb Available in Paging File | 80,43% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 195,21 Gb Total Space | 72,48 Gb Free Space | 37,13% Space Free | Partition Type: NTFS
Drive D: | 270,45 Gb Total Space | 270,09 Gb Free Space | 99,87% Space Free | Partition Type: NTFS
Drive F: | 931,51 Gb Total Space | 393,01 Gb Free Space | 42,19% Space Free | Partition Type: NTFS
 
Computer Name: ROBERT | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.09.25 20:29:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\User\Downloads\OTL(1).exe
PRC - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.07 17:04:44 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.08.08 09:21:43 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.05.08 20:06:11 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.08 20:06:10 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.08 20:06:10 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.11.01 16:40:04 | 001,053,056 | ---- | M] (Nokia) -- C:\Programme\Nokia\Nokia Suite\NokiaSuite.exe
PRC - [2011.10.27 11:34:30 | 000,718,384 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe
PRC - [2011.10.27 11:33:58 | 000,173,104 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2011.10.27 11:33:32 | 000,148,016 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
PRC - [2011.06.24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.11.20 14:16:54 | 000,100,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
PRC - [2010.10.28 10:06:42 | 000,328,024 | ---- | M] (TeVii Technology Ltd.) -- C:\Windows\TeViiRC.exe
PRC - [2010.07.21 18:07:04 | 001,778,064 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft IntelliType Pro\itype.exe
PRC - [2010.07.21 17:51:42 | 001,797,008 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft IntelliPoint\ipoint.exe
PRC - [2010.05.20 23:59:30 | 011,312,128 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.bin
PRC - [2010.05.20 23:59:28 | 011,318,784 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.exe
PRC - [2009.10.13 09:39:04 | 000,935,208 | ---- | M] (Nero AG) -- C:\Programme\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2009.08.28 11:43:14 | 001,486,848 | R--- | M] (VIA) -- C:\Programme\VIA\VIAudioi\VDeck\VDeck.exe
PRC - [2009.08.19 14:41:26 | 003,618,104 | ---- | M] (brother) -- C:\Programme\Brownie\BrStsWnd.exe
PRC - [2009.07.14 13:28:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009.07.14 03:14:41 | 000,354,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\StikyNot.exe
PRC - [2008.10.17 16:52:16 | 000,099,632 | ---- | M] (brother) -- C:\Programme\Brownie\brpjp04a.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.11.01 16:42:14 | 000,392,064 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\ssoengine.dll
MOD - [2011.11.01 16:42:12 | 000,058,240 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\securestorage.dll
MOD - [2011.11.01 16:42:08 | 000,095,104 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\qjson.dll
MOD - [2011.11.01 16:42:06 | 000,272,768 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\phonon4.dll
MOD - [2011.11.01 16:41:38 | 000,165,248 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QxtWeb.dll
MOD - [2011.11.01 16:41:36 | 000,384,896 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QxtCore.dll
MOD - [2011.11.01 16:41:34 | 002,557,312 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtXmlPatterns4.dll
MOD - [2011.11.01 16:41:32 | 000,346,496 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtXml4.dll
MOD - [2011.11.01 16:41:30 | 010,843,520 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtWebKit4.dll
MOD - [2011.11.01 16:41:24 | 000,196,480 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtSql4.dll
MOD - [2011.11.01 16:41:22 | 001,294,208 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtScript4.dll
MOD - [2011.11.01 16:41:20 | 000,682,880 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtOpenGL4.dll
MOD - [2011.11.01 16:41:18 | 000,919,936 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtNetwork4.dll
MOD - [2011.11.01 16:41:16 | 000,517,504 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtMultimediaKit1.dll
MOD - [2011.11.01 16:41:14 | 008,172,928 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtGui4.dll
MOD - [2011.11.01 16:41:12 | 002,252,672 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtDeclarative4.dll
MOD - [2011.11.01 16:41:10 | 002,288,512 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\QtCore4.dll
MOD - [2011.11.01 16:41:06 | 000,422,272 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll
MOD - [2011.11.01 16:40:56 | 000,202,624 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\Imageformats\qjpeg4.dll
MOD - [2011.11.01 16:40:54 | 000,034,688 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\Imageformats\qico4.dll
MOD - [2011.11.01 16:40:52 | 000,032,640 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\Imageformats\qgif4.dll
MOD - [2011.11.01 16:40:08 | 000,388,480 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\OviShareLib.dll
MOD - [2011.11.01 16:40:00 | 000,438,144 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\NService.dll
MOD - [2011.11.01 16:39:36 | 001,041,792 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\Maps Service API.dll
MOD - [2011.11.01 16:39:06 | 000,740,736 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\CommonUpdateChecker.dll
MOD - [2011.11.01 15:57:42 | 000,112,640 | ---- | M] () -- C:\Programme\Nokia\Nokia Suite\mediaservice\dsengine.dll
MOD - [2010.05.04 15:36:28 | 000,970,752 | ---- | M] () -- C:\Programme\OpenOffice.org 3\program\libxml2.dll
MOD - [2009.08.28 05:31:08 | 047,628,288 | R--- | M] () -- C:\Programme\VIA\VIAudioi\VDeck\skin.dll
MOD - [2009.05.07 10:53:18 | 000,106,496 | R--- | M] () -- C:\Programme\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
MOD - [2009.05.07 10:50:46 | 000,073,728 | R--- | M] () -- C:\Programme\VIA\VIAudioi\VDeck\QsApoApi.dll
MOD - [2008.02.14 07:57:00 | 000,094,208 | R--- | M] () -- C:\Programme\VIA\VIAudioi\VDeck\VMicApi.dll
 
 
========== Services (SafeList) ==========
 
SRV - [2012.09.21 15:09:08 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.09.10 18:59:46 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.05.08 20:06:11 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.08 20:06:10 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.10.27 11:34:30 | 000,718,384 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2009.10.13 09:39:04 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Programme\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2009.07.14 13:28:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.05.08 20:06:11 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.05.08 20:06:11 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.12.15 16:00:00 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.10.28 10:06:40 | 000,128,344 | ---- | M] (TeVii Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\TeViiS2.sys -- (SAllBDA)
DRV - [2010.07.07 19:18:56 | 000,044,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.05.10 09:09:34 | 000,248,920 | ---- | M] (TechniSat Digital, S.A.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SkyNetU2C.sys -- (SKYNETU2C)
DRV - [2009.12.15 15:19:26 | 000,034,112 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\emOEM.sys -- (USB28xxOEM)
DRV - [2009.12.15 15:19:16 | 000,385,088 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\emBDA.sys -- (USB28xxBGA)
DRV - [2009.08.17 13:17:44 | 001,077,760 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009.07.30 11:12:54 | 000,287,392 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmf6232.sys -- (NVNET)
DRV - [2009.07.16 05:36:30 | 000,013,216 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2009.07.14 05:54:00 | 009,557,216 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009.07.14 00:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2009.06.28 18:36:36 | 000,017,920 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2004.10.14 06:29:54 | 000,021,888 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\eps2kt1.sys -- (token)
DRV - [2004.09.28 17:01:28 | 000,012,800 | ---- | M] (OEM) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smccard.sys -- (R5BaseSmc)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-2451268535-3787092718-403381534-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-2451268535-3787092718-403381534-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-2451268535-3787092718-403381534-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-2451268535-3787092718-403381534-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 F8 0C 37 F4 CB CA 01  [binary data]
IE - HKU\S-1-5-21-2451268535-3787092718-403381534-1000\..\SearchScopes,DefaultScope = {FF1CABE9-894B-4960-8563-0C6C910D353B}
IE - HKU\S-1-5-21-2451268535-3787092718-403381534-1000\..\SearchScopes\{FF1CABE9-894B-4960-8563-0C6C910D353B}: "URL" = hxxp://www.google.de/search?q={searchTerms}
IE - HKU\S-1-5-21-2451268535-3787092718-403381534-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: {dd3d7613-0246-469d-bc65-2a3cc1668adc}:0.7.1.1
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}:6.0.33
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}:6.0.35
FF - prefs.js..extensions.enabledAddons: ffxtlbr@incredibar.com:1.5.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {dd3d7613-0246-469d-bc65-2a3cc1668adc}:0.7.1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://mystart.incredibar.com/mb174/?loc=IB_DS&a=6R8FQJiBhA&&i=26&search="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.10 18:59:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.08.17 10:54:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_7.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_7.0 [2011.12.26 16:08:28 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.10 18:59:47 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.08.17 10:54:55 | 000,000,000 | ---D | M]
 
[2010.04.19 21:53:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Extensions
[2012.09.21 16:18:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions
[2010.11.08 17:08:35 | 000,000,000 | ---D | M] (BlockSite) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
[2012.09.21 16:18:25 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions\ffxtlbr@incredibar.com
[2012.09.21 16:18:18 | 000,002,203 | ---- | M] () -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\kdie60r2.default\searchplugins\MyStart Search.xml
[2012.09.01 14:02:40 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.07.01 20:46:42 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.09.01 14:02:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.07.01 20:46:42 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.09.01 14:02:40 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.09.10 18:59:47 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.06.25 19:48:13 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.09.10 18:59:45 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.06.25 19:48:13 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.25 19:48:13 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.25 19:48:13 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.25 19:48:13 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (GretechBHO Class) - {F0181C6E-9218-4792-9F3C-E8DF52B2F1AC} - C:\Programme\GRETECH\GomPicker\GomPickerBHO.dll (Gretech Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe (brother)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [TeViiRC] C:\Windows\TeViiRC.exe (TeVii Technology Ltd.)
O4 - HKU\S-1-5-21-2451268535-3787092718-403381534-1000..\Run: []  File not found
O4 - HKU\S-1-5-21-2451268535-3787092718-403381534-1000..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4 - HKU\S-1-5-21-2451268535-3787092718-403381534-1000..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3CFF6DC9-BF64-4944-A914-75D25565DFAC}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{89D51DB1-15A5-4A74-BA0F-272D3A60C09C}: DhcpNameServer = 0.0.0.0
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - Unable to obtain root file information for disk F:\
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.divxa32 - C:\Windows\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.23 12:15:33 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.09.22 17:53:47 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Malwarebytes
[2012.09.22 17:53:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.09.22 17:53:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.09.22 17:53:28 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.22 17:53:28 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.09.21 16:18:42 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.25 20:34:00 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.09.25 20:09:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.25 17:02:47 | 000,017,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.25 17:02:47 | 000,017,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.25 16:55:36 | 000,000,338 | ---- | M] () -- C:\Windows\Brownie.ini
[2012.09.25 16:55:35 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.09.25 16:55:34 | 000,000,306 | ---- | M] () -- C:\Windows\tasks\WinMaximizer-User-Startup.job
[2012.09.25 16:55:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.25 16:54:51 | 2616,643,584 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.24 23:41:24 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.09.24 23:41:24 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.09.24 23:41:24 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.09.24 23:41:24 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.09.22 17:53:30 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.21 18:29:11 | 000,000,000 | ---- | M] () -- C:\Users\User\defogger_reenable
[2012.09.21 18:03:27 | 000,001,150 | ---- | M] () -- C:\Users\User\Desktop\Continue Video Converter Installation.lnk
[2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.05 12:23:28 | 000,029,679 | R--- | M] () -- C:\Users\User\Desktop\Vereinsspielplan_20120905122313.csv
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.09.22 17:53:30 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.21 18:29:11 | 000,000,000 | ---- | C] () -- C:\Users\User\defogger_reenable
[2012.09.21 18:03:27 | 000,001,150 | ---- | C] () -- C:\Users\User\Desktop\Continue Video Converter Installation.lnk
[2012.09.05 12:23:32 | 000,029,679 | R--- | C] () -- C:\Users\User\Desktop\Vereinsspielplan_20120905122313.csv
[2012.07.01 16:05:32 | 000,338,432 | ---- | C] () -- C:\Windows\System32\sqlite36_engine.dll
[2011.07.07 12:24:52 | 000,000,367 | ---- | C] () -- C:\Users\User\Heimnetzgruppe - Verknüpfung.lnk
[2010.06.24 15:38:47 | 000,017,408 | ---- | C] () -- C:\Users\User\AppData\Local\WebpageIcons.db
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2010.06.05 12:59:54 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Amazon
[2010.04.24 23:03:04 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Canon
[2012.07.01 21:48:58 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DesktopIconForAmazon
[2012.08.02 12:23:03 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\elsterformular
[2010.09.01 22:57:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\OpenOffice.org
[2011.12.26 16:08:48 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\PC Suite
[2012.07.01 21:48:11 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Systweak
[2010.04.22 20:37:58 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TerraTec
[2010.10.07 22:52:15 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\UDC Profiles
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.02.20 20:47:13 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Adobe
[2010.06.05 12:59:54 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Amazon
[2011.01.21 15:19:05 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Apple Computer
[2012.02.12 08:51:36 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Avira
[2010.04.19 15:02:54 | 000,000,000 | R--D | M] -- C:\Users\User\AppData\Roaming\Brother
[2010.04.24 23:03:04 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Canon
[2012.07.01 21:48:58 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DesktopIconForAmazon
[2012.08.02 12:23:03 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\elsterformular
[2012.02.16 07:28:51 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Gretech
[2010.03.24 06:58:27 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Identities
[2010.04.19 18:15:56 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\InstallShield
[2010.04.19 18:16:30 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Ipswitch
[2010.03.25 10:23:54 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Macromedia
[2012.09.22 17:53:47 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Malwarebytes
[2009.07.14 10:56:41 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Media Center Programs
[2011.02.20 20:47:13 | 000,000,000 | --SD | M] -- C:\Users\User\AppData\Roaming\Microsoft
[2010.04.19 17:25:26 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Microsoft Web Folders
[2010.04.19 21:53:28 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Mozilla
[2010.06.19 22:31:53 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Nero
[2010.09.01 22:57:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\OpenOffice.org
[2011.12.26 16:08:48 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\PC Suite
[2012.07.01 21:48:11 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Systweak
[2010.04.22 20:37:58 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TerraTec
[2010.10.07 22:52:15 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\UDC Profiles
[2010.04.24 23:03:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ZoomBrowser EX
 
< %APPDATA%\*.exe /s >
[2012.07.01 16:05:29 | 000,753,664 | ---- | M] (Microsoft) -- C:\Users\User\AppData\Roaming\DesktopIconForAmazon\IconForAmazon.exe
[2012.08.04 10:57:48 | 004,158,816 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_dfv_10_8623_9066.exe
[2012.08.04 10:57:56 | 004,158,616 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_dfv_11_8623_9066.exe
[2012.08.04 10:58:04 | 004,158,880 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_dfv_12_8623_9066.exe
[2012.08.04 10:58:12 | 004,380,992 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_09_8623_9066.exe
[2012.08.04 10:58:21 | 004,650,840 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_10_8623_9066.exe
[2012.08.04 10:58:31 | 005,229,592 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_11_8623_9066.exe
[2012.08.04 10:58:41 | 004,169,424 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_eur_09_8623_9066.exe
[2012.08.04 10:58:49 | 004,194,184 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_eur_10_8623_9066.exe
[2012.08.04 10:58:58 | 004,282,320 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_eur_11_8623_9066.exe
[2012.08.04 10:59:34 | 004,142,944 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_gstz_09_8623_9066.exe
[2012.08.04 10:59:42 | 004,166,112 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_gstz_10_8623_9066.exe
[2012.08.04 10:59:51 | 004,267,600 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_gstz_11_8623_9066.exe
[2012.08.04 10:59:07 | 004,174,952 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_gst_09_8623_9066.exe
[2012.08.04 10:59:15 | 004,172,360 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_gst_10_8623_9066.exe
[2012.08.04 10:59:24 | 004,288,400 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_gst_11_8623_9066.exe
[2012.08.04 11:00:00 | 004,159,936 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_lsta_10_8623_9066.exe
[2012.08.04 11:00:09 | 004,142,080 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_lsta_11_8623_9066.exe
[2012.08.04 11:00:18 | 004,162,872 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_lsta_12_8623_9066.exe
[2012.08.04 11:00:27 | 004,196,864 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_lstb_10_8623_9066.exe
[2012.08.04 11:00:36 | 004,195,616 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_lstb_11_8623_9066.exe
[2012.08.04 11:00:46 | 004,197,384 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_lstb_12_8623_9066.exe
[2012.08.04 11:00:56 | 004,252,240 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_par34a_09_8623_9066.exe
[2012.08.04 11:01:05 | 004,252,928 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_par34a_10_8623_9066.exe
[2012.08.04 11:01:14 | 004,257,944 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_par34a_11_8623_9066.exe
[2012.08.04 10:57:30 | 006,013,856 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_pica_0_8623_9066.exe
[2012.08.04 11:01:53 | 004,169,824 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_ustva_10_8623_9066.exe
[2012.08.04 11:02:03 | 004,166,720 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_ustva_11_8623_9066.exe
[2012.08.04 11:02:13 | 004,182,552 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_ustva_12_8623_9066.exe
[2012.08.04 11:01:24 | 004,175,632 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_ust_09_8623_9066.exe
[2012.08.04 11:01:33 | 004,151,560 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_ust_10_8623_9066.exe
[2012.08.04 11:01:43 | 004,177,200 | ---- | M] (Landesfinanzdirektion Thüringen) -- C:\Users\User\AppData\Roaming\elsterformular\pluginmanager\tmp\update_ust_11_8623_9066.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\drivers\iaStorV.sys
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys
[2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys
[2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\drivers\nvstor.sys
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys
[2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\System32\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

--- --- ---
[/code]

cosinus 26.09.2012 10:36

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
FF - user.js - File not found
FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..extensions.enabledAddons: ffxtlbr@incredibar.com:1.5.0
FF - prefs.js..keyword.URL: "http://mystart.incredibar.com/mb174/?loc=IB_DS&a=6R8FQJiBhA&&i=26&search="
[2010.11.08 17:08:35 | 000,000,000 | ---D | M] (BlockSite) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
[2012.09.21 16:18:25 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions\ffxtlbr@incredibar.com
[2012.09.21 16:18:18 | 000,002,203 | ---- | M] () -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\kdie60r2.default\searchplugins\MyStart Search.xml
O4 - HKU\S-1-5-21-2451268535-3787092718-403381534-1000..\Run: []  File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
:Files
C:\myTeVii
C:\Users\User\Documents\Mixed\Computer\washandgo.exe
C:\Users\User\Documents\Mixed\Rest\t-online\EMAIL2\ANLAGEN\filme\einfach_gut.zip
F:\Dateien\Mixed\Rest\t-online\EMAIL2\ANLAGEN\filme\einfach_gut.zip
C:\Users\User\Downloads\VideoConverterSetup.exe
C:\Users\User\Downloads\WinMaximizer.exe
F:\Dateien\Mixed\Computer\washandgo.exe
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

rwt69 26.09.2012 13:21

Schaut gut aus (also auch die Schrift in Firefox ist wieder normal). hier das ERgebnis von otl fix:

Code:

All processes killed
========== OTL ==========
Prefs.js: "MyStart Search" removed from browser.search.defaultenginename
Prefs.js: ffxtlbr@incredibar.com:1.5.0 removed from extensions.enabledAddons
Prefs.js: "hxxp://mystart.incredibar.com/mb174/?loc=IB_DS&a=6R8FQJiBhA&&i=26&search=" removed from keyword.URL
C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}\chrome folder moved successfully.
C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc} folder moved successfully.
C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions\ffxtlbr@incredibar.com\content\imgs\flgs folder moved successfully.
C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions\ffxtlbr@incredibar.com\content\imgs folder moved successfully.
C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions\ffxtlbr@incredibar.com\content folder moved successfully.
C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\kdie60r2.default\extensions\ffxtlbr@incredibar.com folder moved successfully.
C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\kdie60r2.default\searchplugins\MyStart Search.xml moved successfully.
Registry value HKEY_USERS\S-1-5-21-2451268535-3787092718-403381534-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
========== FILES ==========
C:\myTeVii\Skins folder moved successfully.
C:\myTeVii\Plugins folder moved successfully.
C:\myTeVii\Languages folder moved successfully.
C:\myTeVii\Decoders folder moved successfully.
C:\myTeVii folder moved successfully.
C:\Users\User\Documents\Mixed\Computer\washandgo.exe moved successfully.
C:\Users\User\Documents\Mixed\Rest\t-online\EMAIL2\ANLAGEN\filme\einfach_gut.zip moved successfully.
F:\Dateien\Mixed\Rest\t-online\EMAIL2\ANLAGEN\filme\einfach_gut.zip moved successfully.
C:\Users\User\Downloads\VideoConverterSetup.exe moved successfully.
C:\Users\User\Downloads\WinMaximizer.exe moved successfully.
F:\Dateien\Mixed\Computer\washandgo.exe moved successfully.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\User\Downloads\cmd.bat deleted successfully.
C:\Users\User\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: User
->Temp folder emptied: 685446088 bytes
->Temporary Internet Files folder emptied: 3254434890 bytes
->Java cache emptied: 3708450 bytes
->FireFox cache emptied: 350997802 bytes
->Flash cache emptied: 14803 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 538764146 bytes
RecycleBin emptied: 1460621607 bytes
 
Total Files Cleaned = 6.002,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.68.0 log created on 09262012_134005

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


cosinus 26.09.2012 16:04

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

rwt69 26.09.2012 16:24

ok ...

Code:

17:20:05.0254 5488  TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
17:20:05.0322 5488  ============================================================
17:20:05.0322 5488  Current date / time: 2012/09/26 17:20:05.0322
17:20:05.0322 5488  SystemInfo:
17:20:05.0322 5488 
17:20:05.0323 5488  OS Version: 6.1.7601 ServicePack: 1.0
17:20:05.0323 5488  Product type: Workstation
17:20:05.0323 5488  ComputerName: ROBERT
17:20:05.0323 5488  UserName: User
17:20:05.0323 5488  Windows directory: C:\Windows
17:20:05.0323 5488  System windows directory: C:\Windows
17:20:05.0323 5488  Processor architecture: Intel x86
17:20:05.0323 5488  Number of processors: 4
17:20:05.0323 5488  Page size: 0x1000
17:20:05.0323 5488  Boot type: Normal boot
17:20:05.0323 5488  ============================================================
17:20:06.0220 5488  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
17:20:06.0224 5488  Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
17:20:12.0466 5488  Drive \Device\Harddisk2\DR2 - Size: 0x1E3000000 (7.55 Gb), SectorSize: 0x200, Cylinders: 0x3D9, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
17:20:12.0468 5488  ============================================================
17:20:12.0468 5488  \Device\Harddisk0\DR0:
17:20:12.0468 5488  MBR partitions:
17:20:12.0468 5488  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
17:20:12.0468 5488  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1866D800
17:20:12.0468 5488  \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x186A0000, BlocksNum 0x21CE5800
17:20:12.0468 5488  \Device\Harddisk1\DR1:
17:20:12.0480 5488  MBR partitions:
17:20:12.0480 5488  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x747059C1
17:20:12.0480 5488  \Device\Harddisk2\DR2:
17:20:12.0481 5488  MBR partitions:
17:20:12.0481 5488  \Device\Harddisk2\DR2\Partition1: MBR, Type 0xC, StartLBA 0x20, BlocksNum 0xF17FE0
17:20:12.0481 5488  ============================================================
17:20:12.0501 5488  C: <-> \Device\Harddisk0\DR0\Partition2
17:20:12.0536 5488  D: <-> \Device\Harddisk0\DR0\Partition3
17:20:12.0546 5488  F: <-> \Device\Harddisk1\DR1\Partition1
17:20:12.0547 5488  ============================================================
17:20:12.0547 5488  Initialize success
17:20:12.0547 5488  ============================================================
17:22:12.0005 5560  ============================================================
17:22:12.0005 5560  Scan started
17:22:12.0005 5560  Mode: Manual; SigCheck; TDLFS;
17:22:12.0005 5560  ============================================================
17:22:12.0267 5560  ================ Scan system memory ========================
17:22:12.0267 5560  System memory - ok
17:22:12.0268 5560  ================ Scan services =============================
17:22:12.0387 5560  [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
17:22:12.0519 5560  1394ohci - ok
17:22:12.0561 5560  [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
17:22:12.0580 5560  ACPI - ok
17:22:12.0597 5560  [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
17:22:12.0654 5560  AcpiPmi - ok
17:22:12.0775 5560  [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
17:22:12.0789 5560  AdobeARMservice - ok
17:22:12.0855 5560  [ E12CFCF1DDBFC50948A75E6E38793225 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
17:22:12.0869 5560  AdobeFlashPlayerUpdateSvc - ok
17:22:12.0900 5560  [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx        C:\Windows\system32\DRIVERS\adp94xx.sys
17:22:12.0923 5560  adp94xx - ok
17:22:12.0939 5560  [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci        C:\Windows\system32\DRIVERS\adpahci.sys
17:22:12.0951 5560  adpahci - ok
17:22:12.0959 5560  [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320        C:\Windows\system32\DRIVERS\adpu320.sys
17:22:12.0969 5560  adpu320 - ok
17:22:12.0995 5560  [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
17:22:13.0042 5560  AeLookupSvc - ok
17:22:13.0085 5560  [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD            C:\Windows\system32\drivers\afd.sys
17:22:13.0119 5560  AFD - ok
17:22:13.0150 5560  [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440          C:\Windows\system32\drivers\agp440.sys
17:22:13.0164 5560  agp440 - ok
17:22:13.0182 5560  [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx        C:\Windows\system32\DRIVERS\djsvs.sys
17:22:13.0196 5560  aic78xx - ok
17:22:13.0220 5560  [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG            C:\Windows\System32\alg.exe
17:22:13.0263 5560  ALG - ok
17:22:13.0276 5560  [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide          C:\Windows\system32\drivers\aliide.sys
17:22:13.0295 5560  aliide - ok
17:22:13.0304 5560  [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
17:22:13.0318 5560  amdagp - ok
17:22:13.0329 5560  [ CD5914170297126B6266860198D1D4F0 ] amdide          C:\Windows\system32\drivers\amdide.sys
17:22:13.0342 5560  amdide - ok
17:22:13.0362 5560  [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8          C:\Windows\system32\DRIVERS\amdk8.sys
17:22:13.0394 5560  AmdK8 - ok
17:22:13.0414 5560  [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
17:22:13.0437 5560  AmdPPM - ok
17:22:13.0469 5560  [ D320BF87125326F996D4904FE24300FC ] amdsata        C:\Windows\system32\drivers\amdsata.sys
17:22:13.0498 5560  amdsata - ok
17:22:13.0520 5560  [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
17:22:13.0533 5560  amdsbs - ok
17:22:13.0542 5560  [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata        C:\Windows\system32\drivers\amdxata.sys
17:22:13.0552 5560  amdxata - ok
17:22:13.0624 5560  [ 466A0D95960DAD3222C896D2CEA99993 ] AntiVirSchedulerService C:\Program Files\Avira\AntiVir Desktop\sched.exe
17:22:13.0659 5560  AntiVirSchedulerService - ok
17:22:13.0697 5560  [ A489BE6BB0AA1FF406B488B60542314B ] AntiVirService  C:\Program Files\Avira\AntiVir Desktop\avguard.exe
17:22:13.0709 5560  AntiVirService - ok
17:22:13.0750 5560  [ AEA177F783E20150ACE5383EE368DA19 ] AppID          C:\Windows\system32\drivers\appid.sys
17:22:13.0841 5560  AppID - ok
17:22:13.0864 5560  [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
17:22:13.0929 5560  AppIDSvc - ok
17:22:13.0955 5560  [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo        C:\Windows\System32\appinfo.dll
17:22:13.0991 5560  Appinfo - ok
17:22:14.0000 5560  [ 2932004F49677BD84DBC72EDB754FFB3 ] arc            C:\Windows\system32\DRIVERS\arc.sys
17:22:14.0012 5560  arc - ok
17:22:14.0024 5560  [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
17:22:14.0034 5560  arcsas - ok
17:22:14.0054 5560  [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
17:22:14.0139 5560  AsyncMac - ok
17:22:14.0167 5560  [ 338C86357871C167A96AB976519BF59E ] atapi          C:\Windows\system32\drivers\atapi.sys
17:22:14.0179 5560  atapi - ok
17:22:14.0216 5560  [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:22:14.0285 5560  AudioEndpointBuilder - ok
17:22:14.0292 5560  [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
17:22:14.0315 5560  Audiosrv - ok
17:22:14.0378 5560  [ D5541F0AFB767E85FC412FC609D96A74 ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
17:22:14.0407 5560  avgntflt - ok
17:22:14.0451 5560  [ 7D967A682D4694DF7FA57D63A2DB01FE ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
17:22:14.0465 5560  avipbb - ok
17:22:14.0490 5560  [ 271CFD1A989209B1964E24D969552BF7 ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
17:22:14.0502 5560  avkmgr - ok
17:22:14.0533 5560  [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV        C:\Windows\System32\AxInstSV.dll
17:22:14.0604 5560  AxInstSV - ok
17:22:14.0627 5560  [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv        C:\Windows\system32\DRIVERS\bxvbdx.sys
17:22:14.0668 5560  b06bdrv - ok
17:22:14.0706 5560  [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x        C:\Windows\system32\DRIVERS\b57nd60x.sys
17:22:14.0722 5560  b57nd60x - ok
17:22:14.0747 5560  [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC          C:\Windows\System32\bdesvc.dll
17:22:14.0785 5560  BDESVC - ok
17:22:14.0799 5560  [ 505506526A9D467307B3C393DEDAF858 ] Beep            C:\Windows\system32\drivers\Beep.sys
17:22:14.0837 5560  Beep - ok
17:22:14.0883 5560  [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE            C:\Windows\System32\bfe.dll
17:22:14.0936 5560  BFE - ok
17:22:14.0978 5560  [ E585445D5021971FAE10393F0F1C3961 ] BITS            C:\Windows\System32\qmgr.dll
17:22:15.0032 5560  BITS - ok
17:22:15.0050 5560  [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
17:22:15.0066 5560  blbdrive - ok
17:22:15.0092 5560  [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
17:22:15.0118 5560  bowser - ok
17:22:15.0128 5560  [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
17:22:15.0195 5560  BrFiltLo - ok
17:22:15.0204 5560  [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
17:22:15.0241 5560  BrFiltUp - ok
17:22:15.0271 5560  [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser        C:\Windows\System32\browser.dll
17:22:15.0292 5560  Browser - ok
17:22:15.0315 5560  [ 845B8CE732E67F3B4133164868C666EA ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
17:22:15.0357 5560  Brserid - ok
17:22:15.0366 5560  [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
17:22:15.0375 5560  BrSerWdm - ok
17:22:15.0388 5560  [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
17:22:15.0403 5560  BrUsbMdm - ok
17:22:15.0405 5560  [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
17:22:15.0428 5560  BrUsbSer - ok
17:22:15.0438 5560  [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
17:22:15.0463 5560  BTHMODEM - ok
17:22:15.0502 5560  [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv        C:\Windows\system32\bthserv.dll
17:22:15.0552 5560  bthserv - ok
17:22:15.0577 5560  [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
17:22:15.0617 5560  cdfs - ok
17:22:15.0654 5560  [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom          C:\Windows\system32\drivers\cdrom.sys
17:22:15.0682 5560  cdrom - ok
17:22:15.0718 5560  [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc    C:\Windows\System32\certprop.dll
17:22:15.0764 5560  CertPropSvc - ok
17:22:15.0780 5560  [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
17:22:15.0795 5560  circlass - ok
17:22:15.0818 5560  [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS            C:\Windows\system32\CLFS.sys
17:22:15.0835 5560  CLFS - ok
17:22:15.0891 5560  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:22:15.0919 5560  clr_optimization_v2.0.50727_32 - ok
17:22:15.0998 5560  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:22:16.0022 5560  clr_optimization_v4.0.30319_32 - ok
17:22:16.0033 5560  [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
17:22:16.0046 5560  CmBatt - ok
17:22:16.0052 5560  [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
17:22:16.0065 5560  cmdide - ok
17:22:16.0104 5560  [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG            C:\Windows\system32\Drivers\cng.sys
17:22:16.0139 5560  CNG - ok
17:22:16.0149 5560  [ A6023D3823C37043986713F118A89BEE ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
17:22:16.0157 5560  Compbatt - ok
17:22:16.0179 5560  [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
17:22:16.0199 5560  CompositeBus - ok
17:22:16.0202 5560  COMSysApp - ok
17:22:16.0216 5560  [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk        C:\Windows\system32\DRIVERS\crcdisk.sys
17:22:16.0224 5560  crcdisk - ok
17:22:16.0262 5560  [ 06E771AA596B8761107AB57E99F128D7 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
17:22:16.0301 5560  CryptSvc - ok
17:22:16.0344 5560  [ 91C1736E77CFF029302728B431D0EEDB ] dc3d            C:\Windows\system32\DRIVERS\dc3d.sys
17:22:16.0367 5560  dc3d - ok
17:22:16.0415 5560  [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch      C:\Windows\system32\rpcss.dll
17:22:16.0466 5560  DcomLaunch - ok
17:22:16.0487 5560  [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc      C:\Windows\System32\defragsvc.dll
17:22:16.0554 5560  defragsvc - ok
17:22:16.0585 5560  [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
17:22:16.0652 5560  DfsC - ok
17:22:16.0689 5560  [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp            C:\Windows\system32\dhcpcore.dll
17:22:16.0751 5560  Dhcp - ok
17:22:16.0762 5560  [ 1A050B0274BFB3890703D490F330C0DA ] discache        C:\Windows\system32\drivers\discache.sys
17:22:16.0793 5560  discache - ok
17:22:16.0811 5560  [ 565003F326F99802E68CA78F2A68E9FF ] Disk            C:\Windows\system32\DRIVERS\disk.sys
17:22:16.0820 5560  Disk - ok
17:22:16.0840 5560  [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
17:22:16.0859 5560  Dnscache - ok
17:22:16.0884 5560  [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc        C:\Windows\System32\dot3svc.dll
17:22:16.0912 5560  dot3svc - ok
17:22:16.0944 5560  [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS            C:\Windows\system32\dps.dll
17:22:17.0003 5560  DPS - ok
17:22:17.0026 5560  [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
17:22:17.0039 5560  drmkaud - ok
17:22:17.0081 5560  [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
17:22:17.0116 5560  DXGKrnl - ok
17:22:17.0136 5560  [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost        C:\Windows\System32\eapsvc.dll
17:22:17.0167 5560  EapHost - ok
17:22:17.0219 5560  [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv          C:\Windows\system32\DRIVERS\evbdx.sys
17:22:17.0275 5560  ebdrv - ok
17:22:17.0308 5560  [ 81951F51E318AECC2D68559E47485CC4 ] EFS            C:\Windows\System32\lsass.exe
17:22:17.0350 5560  EFS - ok
17:22:17.0403 5560  [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
17:22:17.0447 5560  ehRecvr - ok
17:22:17.0474 5560  [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched        C:\Windows\ehome\ehsched.exe
17:22:17.0515 5560  ehSched - ok
17:22:17.0547 5560  [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor        C:\Windows\system32\DRIVERS\elxstor.sys
17:22:17.0588 5560  elxstor - ok
17:22:17.0621 5560  [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
17:22:17.0639 5560  ErrDev - ok
17:22:17.0667 5560  [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem    C:\Windows\system32\es.dll
17:22:17.0706 5560  EventSystem - ok
17:22:17.0721 5560  [ 2DC9108D74081149CC8B651D3A26207F ] exfat          C:\Windows\system32\drivers\exfat.sys
17:22:17.0747 5560  exfat - ok
17:22:17.0760 5560  [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
17:22:17.0783 5560  fastfat - ok
17:22:17.0829 5560  [ 967EA5B213E9984CBE270205DF37755B ] Fax            C:\Windows\system32\fxssvc.exe
17:22:17.0879 5560  Fax - ok
17:22:17.0890 5560  [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
17:22:17.0911 5560  fdc - ok
17:22:17.0924 5560  [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost        C:\Windows\system32\fdPHost.dll
17:22:17.0962 5560  fdPHost - ok
17:22:17.0966 5560  [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub        C:\Windows\system32\fdrespub.dll
17:22:17.0994 5560  FDResPub - ok
17:22:18.0012 5560  [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
17:22:18.0021 5560  FileInfo - ok
17:22:18.0033 5560  [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
17:22:18.0064 5560  Filetrace - ok
17:22:18.0087 5560  [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
17:22:18.0101 5560  flpydisk - ok
17:22:18.0116 5560  [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
17:22:18.0127 5560  FltMgr - ok
17:22:18.0164 5560  [ B3A5EC6B6B6673DB7E87C2BCDBDDC074 ] FontCache      C:\Windows\system32\FntCache.dll
17:22:18.0188 5560  FontCache - ok
17:22:18.0229 5560  [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
17:22:18.0236 5560  FontCache3.0.0.0 - ok
17:22:18.0247 5560  [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
17:22:18.0255 5560  FsDepends - ok
17:22:18.0292 5560  [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
17:22:18.0307 5560  Fs_Rec - ok
17:22:18.0349 5560  [ 8A73E79089B282100B9393B644CB853B ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
17:22:18.0389 5560  fvevol - ok
17:22:18.0406 5560  [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
17:22:18.0417 5560  gagp30kx - ok
17:22:18.0455 5560  [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc          C:\Windows\System32\gpsvc.dll
17:22:18.0509 5560  gpsvc - ok
17:22:18.0590 5560  [ F02A533F517EB38333CB12A9E8963773 ] gupdate        C:\Program Files\Google\Update\GoogleUpdate.exe
17:22:18.0615 5560  gupdate - ok
17:22:18.0629 5560  [ F02A533F517EB38333CB12A9E8963773 ] gupdatem        C:\Program Files\Google\Update\GoogleUpdate.exe
17:22:18.0641 5560  gupdatem - ok
17:22:18.0651 5560  [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
17:22:18.0680 5560  hcw85cir - ok
17:22:18.0727 5560  [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:22:18.0778 5560  HdAudAddService - ok
17:22:18.0795 5560  [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus        C:\Windows\system32\drivers\HDAudBus.sys
17:22:18.0820 5560  HDAudBus - ok
17:22:18.0834 5560  [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt        C:\Windows\system32\DRIVERS\HidBatt.sys
17:22:18.0855 5560  HidBatt - ok
17:22:18.0871 5560  [ 89448F40E6DF260C206A193A4683BA78 ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
17:22:18.0891 5560  HidBth - ok
17:22:18.0906 5560  [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr          C:\Windows\system32\DRIVERS\hidir.sys
17:22:18.0929 5560  HidIr - ok
17:22:18.0951 5560  [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv        C:\Windows\system32\hidserv.dll
17:22:18.0991 5560  hidserv - ok
17:22:19.0051 5560  [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb          C:\Windows\system32\drivers\hidusb.sys
17:22:19.0078 5560  HidUsb - ok
17:22:19.0103 5560  [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc          C:\Windows\system32\kmsvc.dll
17:22:19.0139 5560  hkmsvc - ok
17:22:19.0168 5560  [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
17:22:19.0248 5560  HomeGroupListener - ok
17:22:19.0288 5560  [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
17:22:19.0321 5560  HomeGroupProvider - ok
17:22:19.0338 5560  [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
17:22:19.0352 5560  HpSAMD - ok
17:22:19.0403 5560  [ 871917B07A141BFF43D76D8844D48106 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
17:22:19.0437 5560  HTTP - ok
17:22:19.0474 5560  [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
17:22:19.0500 5560  hwpolicy - ok
17:22:19.0536 5560  [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
17:22:19.0555 5560  i8042prt - ok
17:22:19.0574 5560  [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
17:22:19.0594 5560  iaStorV - ok
17:22:19.0637 5560  [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc          C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:22:19.0667 5560  idsvc - ok
17:22:19.0703 5560  [ 4173FF5708F3236CF25195FECD742915 ] iirsp          C:\Windows\system32\DRIVERS\iirsp.sys
17:22:19.0712 5560  iirsp - ok
17:22:19.0734 5560  [ F95622F161474511B8D80D6B093AA610 ] IKEEXT          C:\Windows\System32\ikeext.dll
17:22:19.0794 5560  IKEEXT - ok
17:22:19.0819 5560  [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide        C:\Windows\system32\drivers\intelide.sys
17:22:19.0827 5560  intelide - ok
17:22:19.0854 5560  [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
17:22:19.0911 5560  intelppm - ok
17:22:20.0032 5560  [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
17:22:20.0102 5560  IPBusEnum - ok
17:22:20.0113 5560  [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:22:20.0194 5560  IpFilterDriver - ok
17:22:20.0293 5560  [ 4D65A07B795D6674312F879D09AA7663 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
17:22:20.0334 5560  iphlpsvc - ok
17:22:20.0392 5560  [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
17:22:20.0472 5560  IPMIDRV - ok
17:22:20.0510 5560  [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
17:22:20.0541 5560  IPNAT - ok
17:22:20.0567 5560  [ 42996CFF20A3084A56017B7902307E9F ] IRENUM          C:\Windows\system32\drivers\irenum.sys
17:22:20.0592 5560  IRENUM - ok
17:22:20.0600 5560  [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
17:22:20.0610 5560  isapnp - ok
17:22:20.0633 5560  [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
17:22:20.0645 5560  iScsiPrt - ok
17:22:20.0671 5560  [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass        C:\Windows\system32\drivers\kbdclass.sys
17:22:20.0680 5560  kbdclass - ok
17:22:20.0727 5560  [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid          C:\Windows\system32\drivers\kbdhid.sys
17:22:20.0743 5560  kbdhid - ok
17:22:20.0752 5560  [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso          C:\Windows\system32\lsass.exe
17:22:20.0761 5560  KeyIso - ok
17:22:20.0796 5560  [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
17:22:20.0806 5560  KSecDD - ok
17:22:20.0845 5560  [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
17:22:20.0876 5560  KSecPkg - ok
17:22:20.0893 5560  [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm          C:\Windows\system32\msdtckrm.dll
17:22:20.0933 5560  KtmRm - ok
17:22:20.0967 5560  [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer    C:\Windows\system32\srvsvc.dll
17:22:21.0016 5560  LanmanServer - ok
17:22:21.0028 5560  [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:22:21.0060 5560  LanmanWorkstation - ok
17:22:21.0095 5560  [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
17:22:21.0123 5560  lltdio - ok
17:22:21.0154 5560  [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
17:22:21.0184 5560  lltdsvc - ok
17:22:21.0188 5560  [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts        C:\Windows\System32\lmhsvc.dll
17:22:21.0211 5560  lmhosts - ok
17:22:21.0232 5560  [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
17:22:21.0242 5560  LSI_FC - ok
17:22:21.0258 5560  [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS        C:\Windows\system32\DRIVERS\lsi_sas.sys
17:22:21.0268 5560  LSI_SAS - ok
17:22:21.0283 5560  [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
17:22:21.0292 5560  LSI_SAS2 - ok
17:22:21.0304 5560  [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
17:22:21.0314 5560  LSI_SCSI - ok
17:22:21.0328 5560  [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv          C:\Windows\system32\drivers\luafv.sys
17:22:21.0358 5560  luafv - ok
17:22:21.0412 5560  [ 65E794E86468B61F2BC79ABC48BC4433 ] MBAMProtector  C:\Windows\system32\drivers\mbam.sys
17:22:21.0421 5560  MBAMProtector - ok
17:22:21.0470 5560  [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler  C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
17:22:21.0483 5560  MBAMScheduler - ok
17:22:21.0531 5560  [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
17:22:21.0547 5560  MBAMService - ok
17:22:21.0591 5560  [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
17:22:21.0601 5560  Mcx2Svc - ok
17:22:21.0613 5560  [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas        C:\Windows\system32\DRIVERS\megasas.sys
17:22:21.0621 5560  megasas - ok
17:22:21.0637 5560  [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
17:22:21.0649 5560  MegaSR - ok
17:22:21.0677 5560  [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS          C:\Windows\system32\mmcss.dll
17:22:21.0731 5560  MMCSS - ok
17:22:21.0746 5560  [ F001861E5700EE84E2D4E52C712F4964 ] Modem          C:\Windows\system32\drivers\modem.sys
17:22:21.0778 5560  Modem - ok
17:22:21.0813 5560  [ 79D10964DE86B292320E9DFE02282A23 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
17:22:21.0855 5560  monitor - ok
17:22:21.0884 5560  [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass        C:\Windows\system32\drivers\mouclass.sys
17:22:21.0898 5560  mouclass - ok
17:22:21.0910 5560  [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
17:22:21.0933 5560  mouhid - ok
17:22:21.0960 5560  [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
17:22:21.0974 5560  mountmgr - ok
17:22:22.0033 5560  [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
17:22:22.0062 5560  MozillaMaintenance - ok
17:22:22.0081 5560  [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio            C:\Windows\system32\drivers\mpio.sys
17:22:22.0096 5560  mpio - ok
17:22:22.0105 5560  [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
17:22:22.0142 5560  mpsdrv - ok
17:22:22.0176 5560  [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc          C:\Windows\system32\mpssvc.dll
17:22:22.0213 5560  MpsSvc - ok
17:22:22.0244 5560  [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
17:22:22.0262 5560  MRxDAV - ok
17:22:22.0295 5560  [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
17:22:22.0329 5560  mrxsmb - ok
17:22:22.0368 5560  [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:22:22.0406 5560  mrxsmb10 - ok
17:22:22.0425 5560  [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:22:22.0438 5560  mrxsmb20 - ok
17:22:22.0445 5560  [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci          C:\Windows\system32\drivers\msahci.sys
17:22:22.0458 5560  msahci - ok
17:22:22.0490 5560  [ 55055F8AD8BE27A64C831322A780A228 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
17:22:22.0505 5560  msdsm - ok
17:22:22.0523 5560  [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC          C:\Windows\System32\msdtc.exe
17:22:22.0544 5560  MSDTC - ok
17:22:22.0580 5560  [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs            C:\Windows\system32\drivers\Msfs.sys
17:22:22.0609 5560  Msfs - ok
17:22:22.0616 5560  [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
17:22:22.0635 5560  mshidkmdf - ok
17:22:22.0661 5560  [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
17:22:22.0669 5560  msisadrv - ok
17:22:22.0696 5560  [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
17:22:22.0720 5560  MSiSCSI - ok
17:22:22.0724 5560  msiserver - ok
17:22:22.0741 5560  [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
17:22:22.0770 5560  MSKSSRV - ok
17:22:22.0784 5560  [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
17:22:22.0809 5560  MSPCLOCK - ok
17:22:22.0822 5560  [ F456E973590D663B1073E9C463B40932 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
17:22:22.0855 5560  MSPQM - ok
17:22:22.0870 5560  [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
17:22:22.0881 5560  MsRPC - ok
17:22:22.0892 5560  [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
17:22:22.0900 5560  mssmbios - ok
17:22:22.0911 5560  [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
17:22:22.0930 5560  MSTEE - ok
17:22:22.0934 5560  [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
17:22:22.0942 5560  MTConfig - ok
17:22:22.0977 5560  [ CBE71C122434805CB73FFB6619F60598 ] MTsensor        C:\Windows\system32\DRIVERS\ASACPI.sys
17:22:23.0000 5560  MTsensor - ok
17:22:23.0016 5560  [ 159FAD02F64E6381758C990F753BCC80 ] Mup            C:\Windows\system32\Drivers\mup.sys
17:22:23.0030 5560  Mup - ok
17:22:23.0063 5560  [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent        C:\Windows\system32\qagentRT.dll
17:22:23.0106 5560  napagent - ok
17:22:23.0144 5560  [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
17:22:23.0164 5560  NativeWifiP - ok
17:22:23.0204 5560  [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS            C:\Windows\system32\drivers\ndis.sys
17:22:23.0232 5560  NDIS - ok
17:22:23.0256 5560  [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
17:22:23.0291 5560  NdisCap - ok
17:22:23.0309 5560  [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
17:22:23.0346 5560  NdisTapi - ok
17:22:23.0377 5560  [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
17:22:23.0402 5560  Ndisuio - ok
17:22:23.0440 5560  [ 38FBE267E7E6983311179230FACB1017 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
17:22:23.0468 5560  NdisWan - ok
17:22:23.0480 5560  [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
17:22:23.0504 5560  NDProxy - ok
17:22:23.0600 5560  [ 7D2633295EB6FF2B938185874884059D ] Nero BackItUp Scheduler 4.0 C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
17:22:23.0645 5560  Nero BackItUp Scheduler 4.0 - ok
17:22:23.0660 5560  [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
17:22:23.0692 5560  NetBIOS - ok
17:22:23.0723 5560  [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
17:22:23.0789 5560  NetBT - ok
17:22:23.0807 5560  [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon        C:\Windows\system32\lsass.exe
17:22:23.0818 5560  Netlogon - ok
17:22:23.0852 5560  [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman          C:\Windows\System32\netman.dll
17:22:23.0904 5560  Netman - ok
17:22:23.0924 5560  [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm        C:\Windows\System32\netprofm.dll
17:22:23.0947 5560  netprofm - ok
17:22:23.0964 5560  [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
17:22:23.0972 5560  NetTcpPortSharing - ok
17:22:23.0997 5560  [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960        C:\Windows\system32\DRIVERS\nfrd960.sys
17:22:24.0006 5560  nfrd960 - ok
17:22:24.0039 5560  [ 912084381D30D8B89EC4E293053F4710 ] NlaSvc          C:\Windows\System32\nlasvc.dll
17:22:24.0069 5560  NlaSvc - ok
17:22:24.0079 5560  [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs            C:\Windows\system32\drivers\Npfs.sys
17:22:24.0109 5560  Npfs - ok
17:22:24.0127 5560  [ BA387E955E890C8A88306D9B8D06BF17 ] nsi            C:\Windows\system32\nsisvc.dll
17:22:24.0146 5560  nsi - ok
17:22:24.0155 5560  [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
17:22:24.0186 5560  nsiproxy - ok
17:22:24.0229 5560  [ 81189C3D7763838E55C397759D49007A ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
17:22:24.0255 5560  Ntfs - ok
17:22:24.0270 5560  [ F9756A98D69098DCA8945D62858A812C ] Null            C:\Windows\system32\drivers\Null.sys
17:22:24.0289 5560  Null - ok
17:22:24.0317 5560  [ B5E37E31C053BC9950455A257526514B ] NVENETFD        C:\Windows\system32\DRIVERS\nvm62x32.sys
17:22:24.0330 5560  NVENETFD - ok
17:22:24.0505 5560  [ E572EBF0A86A76E7CFCAAB00648F0F83 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
17:22:24.0673 5560  nvlddmkm - ok
17:22:24.0701 5560  [ 5BF9C11586F4764446407F509F1BECA8 ] NVNET          C:\Windows\system32\DRIVERS\nvmf6232.sys
17:22:24.0713 5560  NVNET - ok
17:22:24.0729 5560  [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
17:22:24.0740 5560  nvraid - ok
17:22:24.0761 5560  [ F13618F0CB1E95232F4C2401592A59E9 ] nvsmu          C:\Windows\system32\DRIVERS\nvsmu.sys
17:22:24.0797 5560  nvsmu - ok
17:22:24.0829 5560  [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
17:22:24.0863 5560  nvstor - ok
17:22:24.0885 5560  [ A511F04A121F52CFA538407A77BB7E92 ] nvsvc          C:\Windows\system32\nvvsvc.exe
17:22:24.0901 5560  nvsvc - ok
17:22:24.0915 5560  [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
17:22:24.0930 5560  nv_agp - ok
17:22:24.0944 5560  [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
17:22:24.0968 5560  ohci1394 - ok
17:22:24.0993 5560  [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
17:22:25.0036 5560  p2pimsvc - ok
17:22:25.0052 5560  [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc          C:\Windows\system32\p2psvc.dll
17:22:25.0076 5560  p2psvc - ok
17:22:25.0098 5560  [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport        C:\Windows\system32\DRIVERS\parport.sys
17:22:25.0132 5560  Parport - ok
17:22:25.0159 5560  [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr        C:\Windows\system32\drivers\partmgr.sys
17:22:25.0173 5560  partmgr - ok
17:22:25.0185 5560  [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm          C:\Windows\system32\DRIVERS\parvdm.sys
17:22:25.0205 5560  Parvdm - ok
17:22:25.0220 5560  [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc          C:\Windows\System32\pcasvc.dll
17:22:25.0239 5560  PcaSvc - ok
17:22:25.0248 5560  [ 673E55C3498EB970088E812EA820AA8F ] pci            C:\Windows\system32\drivers\pci.sys
17:22:25.0262 5560  pci - ok
17:22:25.0270 5560  [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide          C:\Windows\system32\drivers\pciide.sys
17:22:25.0278 5560  pciide - ok
17:22:25.0293 5560  [ F396431B31693E71E8A80687EF523506 ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
17:22:25.0304 5560  pcmcia - ok
17:22:25.0317 5560  [ 250F6B43D2B613172035C6747AEEB19F ] pcw            C:\Windows\system32\drivers\pcw.sys
17:22:25.0326 5560  pcw - ok
17:22:25.0345 5560  [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
17:22:25.0371 5560  PEAUTH - ok
17:22:25.0438 5560  [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla            C:\Windows\system32\pla.dll
17:22:25.0507 5560  pla - ok
17:22:25.0574 5560  [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
17:22:25.0635 5560  PlugPlay - ok
17:22:25.0667 5560  [ 379F7A0EC9FBE07629FD3F244D3E3E44 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
17:22:25.0691 5560  Pml Driver HPZ12 - ok
17:22:25.0713 5560  [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
17:22:25.0734 5560  PNRPAutoReg - ok
17:22:25.0754 5560  [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
17:22:25.0770 5560  PNRPsvc - ok
17:22:25.0806 5560  [ 60A044879C4FA76314494F5FDDC43B93 ] Point32        C:\Windows\system32\DRIVERS\point32.sys
17:22:25.0817 5560  Point32 - ok
17:22:25.0832 5560  [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
17:22:25.0875 5560  PolicyAgent - ok
17:22:25.0903 5560  [ F87D30E72E03D579A5199CCB3831D6EA ] Power          C:\Windows\system32\umpo.dll
17:22:25.0922 5560  Power - ok
17:22:25.0947 5560  [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
17:22:25.0977 5560  PptpMiniport - ok
17:22:25.0989 5560  [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor      C:\Windows\system32\DRIVERS\processr.sys
17:22:25.0998 5560  Processor - ok
17:22:26.0029 5560  [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc        C:\Windows\system32\profsvc.dll
17:22:26.0071 5560  ProfSvc - ok
17:22:26.0085 5560  [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:22:26.0112 5560  ProtectedStorage - ok
17:22:26.0136 5560  [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
17:22:26.0163 5560  Psched - ok
17:22:26.0195 5560  [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
17:22:26.0224 5560  ql2300 - ok
17:22:26.0241 5560  [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
17:22:26.0251 5560  ql40xx - ok
17:22:26.0277 5560  [ 31AC809E7707EB580B2BDB760390765A ] QWAVE          C:\Windows\system32\qwave.dll
17:22:26.0299 5560  QWAVE - ok
17:22:26.0312 5560  [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
17:22:26.0322 5560  QWAVEdrv - ok
17:22:26.0374 5560  [ E545DE0D80BFD0D03788DB1D6D028DE3 ] R5BaseSmc      C:\Windows\system32\DRIVERS\smccard.sys
17:22:26.0409 5560  R5BaseSmc - ok
17:22:26.0426 5560  [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
17:22:26.0475 5560  RasAcd - ok
17:22:26.0494 5560  [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
17:22:26.0511 5560  RasAgileVpn - ok
17:22:26.0523 5560  [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto        C:\Windows\System32\rasauto.dll
17:22:26.0543 5560  RasAuto - ok
17:22:26.0549 5560  [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
17:22:26.0616 5560  Rasl2tp - ok
17:22:26.0650 5560  [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan          C:\Windows\System32\rasmans.dll
17:22:26.0684 5560  RasMan - ok
17:22:26.0693 5560  [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
17:22:26.0718 5560  RasPppoe - ok
17:22:26.0741 5560  [ 44101F495A83EA6401D886E7FD70096B ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
17:22:26.0794 5560  RasSstp - ok
17:22:26.0830 5560  [ D528BC58A489409BA40334EBF96A311B ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
17:22:26.0860 5560  rdbss - ok
17:22:26.0874 5560  [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
17:22:26.0886 5560  rdpbus - ok
17:22:26.0924 5560  [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
17:22:26.0981 5560  RDPCDD - ok
17:22:27.0004 5560  [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
17:22:27.0037 5560  RDPENCDD - ok
17:22:27.0055 5560  [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
17:22:27.0082 5560  RDPREFMP - ok
17:22:27.0112 5560  [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
17:22:27.0153 5560  RDPWD - ok
17:22:27.0199 5560  [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
17:22:27.0234 5560  rdyboost - ok
17:22:27.0260 5560  [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess    C:\Windows\System32\mprdim.dll
17:22:27.0307 5560  RemoteAccess - ok
17:22:27.0323 5560  [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
17:22:27.0359 5560  RemoteRegistry - ok
17:22:27.0375 5560  [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
17:22:27.0405 5560  RpcEptMapper - ok
17:22:27.0422 5560  [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator      C:\Windows\system32\locator.exe
17:22:27.0431 5560  RpcLocator - ok
17:22:27.0448 5560  [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs          C:\Windows\system32\rpcss.dll
17:22:27.0469 5560  RpcSs - ok
17:22:27.0482 5560  [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
17:22:27.0502 5560  rspndr - ok
17:22:27.0550 5560  [ F2D71913A0299A1ED4CC0B75C44529D9 ] SAllBDA        C:\Windows\system32\Drivers\TeViiS2.sys
17:22:27.0584 5560  SAllBDA - ok
17:22:27.0600 5560  [ 81951F51E318AECC2D68559E47485CC4 ] SamSs          C:\Windows\system32\lsass.exe
17:22:27.0627 5560  SamSs - ok
17:22:27.0649 5560  [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
17:22:27.0681 5560  sbp2port - ok
17:22:27.0705 5560  [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
17:22:27.0748 5560  SCardSvr - ok
17:22:27.0762 5560  [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
17:22:27.0789 5560  scfilter - ok
17:22:27.0824 5560  [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule        C:\Windows\system32\schedsvc.dll
17:22:27.0860 5560  Schedule - ok
17:22:27.0872 5560  [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc    C:\Windows\System32\certprop.dll
17:22:27.0890 5560  SCPolicySvc - ok
17:22:27.0919 5560  [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
17:22:27.0960 5560  SDRSVC - ok
17:22:27.0978 5560  [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
17:22:28.0026 5560  secdrv - ok
17:22:28.0036 5560  [ A59B3A4442C52060CC7A85293AA3546F ] seclogon        C:\Windows\system32\seclogon.dll
17:22:28.0067 5560  seclogon - ok
17:22:28.0092 5560  [ DCB7FCDCC97F87360F75D77425B81737 ] SENS            C:\Windows\System32\sens.dll
17:22:28.0122 5560  SENS - ok
17:22:28.0144 5560  [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc        C:\Windows\system32\sensrsvc.dll
17:22:28.0180 5560  SensrSvc - ok
17:22:28.0198 5560  [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum        C:\Windows\system32\DRIVERS\serenum.sys
17:22:28.0237 5560  Serenum - ok
17:22:28.0267 5560  [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
17:22:28.0303 5560  Serial - ok
17:22:28.0320 5560  [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
17:22:28.0342 5560  sermouse - ok
17:22:28.0431 5560  [ 668043F192AB9659761A349A4703600D ] ServiceLayer    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
17:22:28.0473 5560  ServiceLayer - ok
17:22:28.0512 5560  [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv      C:\Windows\system32\sessenv.dll
17:22:28.0544 5560  SessionEnv - ok
17:22:28.0577 5560  [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
17:22:28.0614 5560  sffdisk - ok
17:22:28.0632 5560  [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
17:22:28.0647 5560  sffp_mmc - ok
17:22:28.0657 5560  [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
17:22:28.0672 5560  sffp_sd - ok
17:22:28.0679 5560  [ DB96666CC8312EBC45032F30B007A547 ] sfloppy        C:\Windows\system32\DRIVERS\sfloppy.sys
17:22:28.0688 5560  sfloppy - ok
17:22:28.0707 5560  [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
17:22:28.0744 5560  SharedAccess - ok
17:22:28.0765 5560  [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:22:28.0802 5560  ShellHWDetection - ok
17:22:28.0815 5560  [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp          C:\Windows\system32\drivers\sisagp.sys
17:22:28.0824 5560  sisagp - ok
17:22:28.0840 5560  [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
17:22:28.0849 5560  SiSRaid2 - ok
17:22:28.0857 5560  [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
17:22:28.0866 5560  SiSRaid4 - ok
17:22:28.0907 5560  [ 469C5507BD83EA0DDCAC55A73D67E043 ] SKYNETU2C      C:\Windows\system32\DRIVERS\SkyNetU2C.SYS
17:22:28.0918 5560  SKYNETU2C - ok
17:22:28.0932 5560  [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb            C:\Windows\system32\DRIVERS\smb.sys
17:22:28.0951 5560  Smb - ok
17:22:28.0986 5560  [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
17:22:28.0995 5560  SNMPTRAP - ok
17:22:28.0999 5560  [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr          C:\Windows\system32\drivers\spldr.sys
17:22:29.0007 5560  spldr - ok
17:22:29.0037 5560  [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler        C:\Windows\System32\spoolsv.exe
17:22:29.0072 5560  Spooler - ok
17:22:29.0163 5560  [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc          C:\Windows\system32\sppsvc.exe
17:22:29.0235 5560  sppsvc - ok
17:22:29.0266 5560  [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify    C:\Windows\system32\sppuinotify.dll
17:22:29.0290 5560  sppuinotify - ok
17:22:29.0328 5560  [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv            C:\Windows\system32\DRIVERS\srv.sys
17:22:29.0353 5560  srv - ok
17:22:29.0389 5560  [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
17:22:29.0406 5560  srv2 - ok
17:22:29.0416 5560  [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
17:22:29.0426 5560  srvnet - ok
17:22:29.0450 5560  [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
17:22:29.0484 5560  SSDPSRV - ok
17:22:29.0525 5560  [ A36EE93698802CD899F98BFD553D8185 ] ssmdrv          C:\Windows\system32\DRIVERS\ssmdrv.sys
17:22:29.0547 5560  ssmdrv - ok
17:22:29.0564 5560  [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc        C:\Windows\system32\sstpsvc.dll
17:22:29.0598 5560  SstpSvc - ok
17:22:29.0633 5560  [ F9506327BB18C51ED720CB9E83BBAB66 ] Stereo Service  C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
17:22:29.0657 5560  Stereo Service - ok
17:22:29.0681 5560  [ DB32D325C192B801DF274BFD12A7E72B ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
17:22:29.0694 5560  stexstor - ok
17:22:29.0742 5560  [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc          C:\Windows\System32\wiaservc.dll
17:22:29.0785 5560  StiSvc - ok
17:22:29.0812 5560  [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum          C:\Windows\system32\drivers\swenum.sys
17:22:29.0825 5560  swenum - ok
17:22:29.0840 5560  [ A28BD92DF340E57B024BA433165D34D7 ] swprv          C:\Windows\System32\swprv.dll
17:22:29.0864 5560  swprv - ok
17:22:29.0908 5560  [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain        C:\Windows\system32\sysmain.dll
17:22:29.0952 5560  SysMain - ok
17:22:29.0963 5560  [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:22:29.0986 5560  TabletInputService - ok
17:22:30.0024 5560  [ 613BF4820361543956909043A265C6AC ] TapiSrv        C:\Windows\System32\tapisrv.dll
17:22:30.0067 5560  TapiSrv - ok
17:22:30.0083 5560  [ B799D9FDB26111737F58288D8DC172D9 ] TBS            C:\Windows\System32\tbssvc.dll
17:22:30.0118 5560  TBS - ok
17:22:30.0172 5560  [ A5EBB8F648000E88B7D9390B514976BF ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
17:22:30.0212 5560  Tcpip - ok
17:22:30.0235 5560  [ A5EBB8F648000E88B7D9390B514976BF ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
17:22:30.0257 5560  TCPIP6 - ok
17:22:30.0286 5560  [ CCA24162E055C3714CE5A88B100C64ED ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
17:22:30.0335 5560  tcpipreg - ok
17:22:30.0351 5560  [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
17:22:30.0378 5560  TDPIPE - ok
17:22:30.0394 5560  [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
17:22:30.0414 5560  TDTCP - ok
17:22:30.0441 5560  [ B459575348C20E8121D6039DA063C704 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
17:22:30.0463 5560  tdx - ok
17:22:30.0494 5560  [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD          C:\Windows\system32\drivers\termdd.sys
17:22:30.0506 5560  TermDD - ok
17:22:30.0544 5560  [ 382C804C92811BE57829D8E550A900E2 ] TermService    C:\Windows\System32\termsrv.dll
17:22:30.0586 5560  TermService - ok
17:22:30.0616 5560  [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes          C:\Windows\system32\themeservice.dll
17:22:30.0657 5560  Themes - ok
17:22:30.0662 5560  [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER    C:\Windows\system32\mmcss.dll
17:22:30.0691 5560  THREADORDER - ok
17:22:30.0743 5560  [ 413DA3024DA08AED29E0ECD8C7DEED44 ] token          C:\Windows\system32\DRIVERS\eps2kt1.sys
17:22:30.0776 5560  token - ok
17:22:30.0805 5560  [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks          C:\Windows\System32\trkwks.dll
17:22:30.0856 5560  TrkWks - ok
17:22:30.0903 5560  [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:22:30.0966 5560  TrustedInstaller - ok
17:22:30.0989 5560  [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
17:22:31.0031 5560  tssecsrv - ok
17:22:31.0058 5560  [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
17:22:31.0104 5560  TsUsbFlt - ok
17:22:31.0155 5560  [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
17:22:31.0209 5560  tunnel - ok
17:22:31.0229 5560  [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
17:22:31.0244 5560  uagp35 - ok
17:22:31.0261 5560  [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
17:22:31.0301 5560  udfs - ok
17:22:31.0325 5560  [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
17:22:31.0353 5560  UI0Detect - ok
17:22:31.0366 5560  [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
17:22:31.0379 5560  uliagpkx - ok
17:22:31.0399 5560  [ D295BED4B898F0FD999FCFA9B32B071B ] umbus          C:\Windows\system32\drivers\umbus.sys
17:22:31.0408 5560  umbus - ok
17:22:31.0423 5560  [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
17:22:31.0442 5560  UmPass - ok
17:22:31.0461 5560  [ 833FBB672460EFCE8011D262175FAD33 ] upnphost        C:\Windows\System32\upnphost.dll
17:22:31.0487 5560  upnphost - ok
17:22:31.0533 5560  [ 61DD578A25A925C4B108F759FE9AE744 ] USB28xxBGA      C:\Windows\system32\DRIVERS\emBDA.sys
17:22:31.0564 5560  USB28xxBGA - ok
17:22:31.0578 5560  [ 06C235EC056B886B4759C916B3A628C5 ] USB28xxOEM      C:\Windows\system32\DRIVERS\emOEM.sys
17:22:31.0588 5560  USB28xxOEM - ok
17:22:31.0623 5560  [ 5C2BDC152BBAB34F36473DEAF7713F22 ] USBAAPL        C:\Windows\system32\Drivers\usbaapl.sys
17:22:31.0636 5560  USBAAPL ( UnsignedFile.Multi.Generic ) - warning
17:22:31.0636 5560  USBAAPL - detected UnsignedFile.Multi.Generic (1)
17:22:31.0669 5560  [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp        C:\Windows\system32\drivers\usbccgp.sys
17:22:31.0715 5560  usbccgp - ok
17:22:31.0751 5560  [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
17:22:31.0795 5560  usbcir - ok
17:22:31.0806 5560  [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
17:22:31.0819 5560  usbehci - ok
17:22:31.0841 5560  [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
17:22:31.0871 5560  usbhub - ok
17:22:31.0883 5560  [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci        C:\Windows\system32\DRIVERS\usbohci.sys
17:22:31.0901 5560  usbohci - ok
17:22:31.0920 5560  [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
17:22:31.0934 5560  usbprint - ok
17:22:31.0967 5560  [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
17:22:32.0005 5560  usbscan - ok
17:22:32.0021 5560  [ F991AB9CC6B908DB552166768176896A ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:22:32.0046 5560  USBSTOR - ok
17:22:32.0054 5560  [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci        C:\Windows\system32\drivers\usbuhci.sys
17:22:32.0067 5560  usbuhci - ok
17:22:32.0091 5560  [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms          C:\Windows\System32\uxsms.dll
17:22:32.0109 5560  UxSms - ok
17:22:32.0120 5560  [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc        C:\Windows\system32\lsass.exe
17:22:32.0129 5560  VaultSvc - ok
17:22:32.0147 5560  [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
17:22:32.0155 5560  vdrvroot - ok
17:22:32.0188 5560  [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds            C:\Windows\System32\vds.exe
17:22:32.0248 5560  vds - ok
17:22:32.0265 5560  [ 17C408214EA61696CEC9C66E388B14F3 ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
17:22:32.0275 5560  vga - ok
17:22:32.0278 5560  [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave        C:\Windows\System32\drivers\vga.sys
17:22:32.0297 5560  VgaSave - ok
17:22:32.0327 5560  [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
17:22:32.0337 5560  vhdmp - ok
17:22:32.0363 5560  [ C829317A37B4BEA8F39735D4B076E923 ] viaagp          C:\Windows\system32\drivers\viaagp.sys
17:22:32.0372 5560  viaagp - ok
17:22:32.0384 5560  [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7          C:\Windows\system32\DRIVERS\viac7.sys
17:22:32.0393 5560  ViaC7 - ok
17:22:32.0438 5560  [ 4906E025DD6B322C4BBD6B9E35C9993A ] VIAHdAudAddService C:\Windows\system32\drivers\viahduaa.sys
17:22:32.0498 5560  VIAHdAudAddService - ok
17:22:32.0503 5560  [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide          C:\Windows\system32\drivers\viaide.sys
17:22:32.0516 5560  viaide - ok
17:22:32.0529 5560  [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
17:22:32.0539 5560  volmgr - ok
17:22:32.0564 5560  [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
17:22:32.0579 5560  volmgrx - ok
17:22:32.0591 5560  [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
17:22:32.0603 5560  volsnap - ok
17:22:32.0621 5560  [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid        C:\Windows\system32\DRIVERS\vsmraid.sys
17:22:32.0631 5560  vsmraid - ok
17:22:32.0675 5560  [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS            C:\Windows\system32\vssvc.exe
17:22:32.0729 5560  VSS - ok
17:22:32.0743 5560  [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
17:22:32.0764 5560  vwifibus - ok
17:22:32.0790 5560  [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time        C:\Windows\system32\w32time.dll
17:22:32.0820 5560  W32Time - ok
17:22:32.0831 5560  [ DE3721E89C653AA281428C8A69745D90 ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
17:22:32.0851 5560  WacomPen - ok
17:22:32.0887 5560  [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
17:22:32.0945 5560  WANARP - ok
17:22:32.0949 5560  [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
17:22:32.0970 5560  Wanarpv6 - ok
17:22:32.0995 5560  [ 691E3285E53DCA558E1A84667F13E15A ] wbengine        C:\Windows\system32\wbengine.exe
17:22:33.0036 5560  wbengine - ok
17:22:33.0047 5560  [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
17:22:33.0060 5560  WbioSrvc - ok
17:22:33.0098 5560  [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc        C:\Windows\System32\wcncsvc.dll
17:22:33.0136 5560  wcncsvc - ok
17:22:33.0144 5560  [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:22:33.0178 5560  WcsPlugInService - ok
17:22:33.0186 5560  [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd              C:\Windows\system32\DRIVERS\wd.sys
17:22:33.0194 5560  Wd - ok
17:22:33.0207 5560  [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
17:22:33.0222 5560  Wdf01000 - ok
17:22:33.0232 5560  [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost  C:\Windows\system32\wdi.dll
17:22:33.0268 5560  WdiServiceHost - ok
17:22:33.0271 5560  [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost  C:\Windows\system32\wdi.dll
17:22:33.0282 5560  WdiSystemHost - ok
17:22:33.0311 5560  [ A9D880F97530D5B8FEE278923349929D ] WebClient      C:\Windows\System32\webclnt.dll
17:22:33.0325 5560  WebClient - ok
17:22:33.0330 5560  [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc          C:\Windows\system32\wecsvc.dll
17:22:33.0351 5560  Wecsvc - ok
17:22:33.0359 5560  [ AC804569BB2364FB6017370258A4091B ] wercplsupport  C:\Windows\System32\wercplsupport.dll
17:22:33.0387 5560  wercplsupport - ok
17:22:33.0415 5560  [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc          C:\Windows\System32\WerSvc.dll
17:22:33.0466 5560  WerSvc - ok
17:22:33.0482 5560  [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
17:22:33.0501 5560  WfpLwf - ok
17:22:33.0513 5560  [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
17:22:33.0521 5560  WIMMount - ok
17:22:33.0583 5560  [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend      C:\Program Files\Windows Defender\mpsvc.dll
17:22:33.0624 5560  WinDefend - ok
17:22:33.0630 5560  WinHttpAutoProxySvc - ok
17:22:33.0664 5560  [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
17:22:33.0696 5560  Winmgmt - ok
17:22:33.0740 5560  [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM          C:\Windows\system32\WsmSvc.dll
17:22:33.0780 5560  WinRM - ok
17:22:33.0828 5560  [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
17:22:33.0867 5560  WinUsb - ok
17:22:33.0914 5560  [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc        C:\Windows\System32\wlansvc.dll
17:22:33.0959 5560  Wlansvc - ok
17:22:33.0972 5560  [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
17:22:33.0980 5560  WmiAcpi - ok
17:22:33.0992 5560  [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
17:22:34.0010 5560  wmiApSrv - ok
17:22:34.0065 5560  [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc  C:\Program Files\Windows Media Player\wmpnetwk.exe
17:22:34.0124 5560  WMPNetworkSvc - ok
17:22:34.0132 5560  [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc          C:\Windows\System32\wpcsvc.dll
17:22:34.0152 5560  WPCSvc - ok
17:22:34.0186 5560  [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
17:22:34.0226 5560  WPDBusEnum - ok
17:22:34.0246 5560  [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
17:22:34.0297 5560  ws2ifsl - ok
17:22:34.0308 5560  [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc          C:\Windows\System32\wscsvc.dll
17:22:34.0330 5560  wscsvc - ok
17:22:34.0334 5560  WSearch - ok
17:22:34.0401 5560  [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv        C:\Windows\system32\wuaueng.dll
17:22:34.0448 5560  wuauserv - ok
17:22:34.0482 5560  [ E714A1C0354636837E20CCBF00888EE7 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
17:22:34.0500 5560  WudfPf - ok
17:22:34.0553 5560  [ 1023EE888C9B47178C5293ED5336AB69 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
17:22:34.0571 5560  WUDFRd - ok
17:22:34.0597 5560  [ 8D1E1E529A2C9E9B6A85B55A345F7629 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
17:22:34.0616 5560  wudfsvc - ok
17:22:34.0633 5560  [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc        C:\Windows\System32\wwansvc.dll
17:22:34.0653 5560  WwanSvc - ok
17:22:34.0670 5560  ================ Scan global ===============================
17:22:34.0700 5560  [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
17:22:34.0732 5560  [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
17:22:34.0747 5560  [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
17:22:34.0773 5560  [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
17:22:34.0795 5560  [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
17:22:34.0799 5560  [Global] - ok
17:22:34.0799 5560  ================ Scan MBR ==================================
17:22:34.0809 5560  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:22:35.0006 5560  \Device\Harddisk0\DR0 - ok
17:22:35.0015 5560  [ 739B36F7A373FC81121D831231B6D311 ] \Device\Harddisk1\DR1
17:22:35.0328 5560  \Device\Harddisk1\DR1 - ok
17:22:35.0336 5560  [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk2\DR2
17:22:37.0386 5560  \Device\Harddisk2\DR2 - ok
17:22:37.0387 5560  ================ Scan VBR ==================================
17:22:37.0393 5560  [ 883D9EBA01D2986318F0DA50B7DABF8B ] \Device\Harddisk0\DR0\Partition1
17:22:37.0396 5560  \Device\Harddisk0\DR0\Partition1 - ok
17:22:37.0428 5560  [ 2727E6D1D4D0A65A80183A347E1994C1 ] \Device\Harddisk0\DR0\Partition2
17:22:37.0429 5560  \Device\Harddisk0\DR0\Partition2 - ok
17:22:37.0447 5560  [ 0E05C9F3C296DEC988147888300F618F ] \Device\Harddisk0\DR0\Partition3
17:22:37.0450 5560  \Device\Harddisk0\DR0\Partition3 - ok
17:22:37.0457 5560  [ EA1D506E4D38B6775E64ED778B3B66C5 ] \Device\Harddisk1\DR1\Partition1
17:22:37.0461 5560  \Device\Harddisk1\DR1\Partition1 - ok
17:22:37.0469 5560  [ 554C56B1F91F62EF60328AC1882203A5 ] \Device\Harddisk2\DR2\Partition1
17:22:37.0471 5560  \Device\Harddisk2\DR2\Partition1 - ok
17:22:37.0473 5560  ============================================================
17:22:37.0473 5560  Scan finished
17:22:37.0473 5560  ============================================================
17:22:37.0500 5732  Detected object count: 1
17:22:37.0500 5732  Actual detected object count: 1
17:22:56.0158 5732  USBAAPL ( UnsignedFile.Multi.Generic ) - skipped by user
17:22:56.0158 5732  USBAAPL ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 27.09.2012 10:49

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

rwt69 27.09.2012 15:27

bitteschön ...
[code] Combofix Logfile:
Code:

ComboFix 12-09-27.01 - User 27.09.2012  16:01:30.1.4 - x86
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3327.2120 [GMT 2:00]
ausgeführt von:: c:\users\User\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\roboot.exe
F:\Autorun.inf
F:\install.exe
F:\Setup.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-08-27 bis 2012-09-27  ))))))))))))))))))))))))))))))
.
.
2012-09-27 14:07 . 2012-09-27 14:07        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-09-26 11:40 . 2012-09-26 11:40        --------        d-----w-        C:\_OTL
2012-09-26 11:35 . 2012-08-21 20:12        245760        ----a-w-        c:\windows\system32\OxpsConverter.exe
2012-09-23 10:15 . 2012-09-23 10:15        --------        d-----w-        c:\program files\ESET
2012-09-22 15:53 . 2012-09-22 15:53        --------        d-----w-        c:\users\User\AppData\Roaming\Malwarebytes
2012-09-22 15:53 . 2012-09-22 15:53        --------        d-----w-        c:\programdata\Malwarebytes
2012-09-22 15:53 . 2012-09-22 15:53        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2012-09-22 15:53 . 2012-09-07 15:04        22856        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-09-21 14:18 . 2012-09-21 15:50        --------        d-----w-        c:\program files\7-Zip
2012-09-13 06:33 . 2012-08-22 17:16        1292144        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-09-13 06:33 . 2012-08-22 17:16        712048        ----a-w-        c:\windows\system32\drivers\ndis.sys
2012-09-13 06:33 . 2012-07-04 19:45        33280        ----a-w-        c:\windows\system32\drivers\RNDISMP.sys
2012-09-13 06:33 . 2012-08-22 17:16        240496        ----a-w-        c:\windows\system32\drivers\netio.sys
2012-09-13 06:33 . 2012-08-22 17:16        187760        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-13 06:33 . 2012-08-02 16:57        490496        ----a-w-        c:\windows\system32\d3d10level9.dll
2012-09-10 16:59 . 2012-09-10 16:59        73696        ----a-w-        c:\program files\Mozilla Firefox\breakpadinjector.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-21 13:09 . 2012-04-03 05:45        696240        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-09-21 13:09 . 2011-05-25 04:44        73136        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-28 18:24 . 2012-07-01 18:46        477168        ----a-w-        c:\windows\system32\npdeployJava1.dll
2012-08-28 18:24 . 2010-07-02 07:21        473072        ----a-w-        c:\windows\system32\deployJava1.dll
2012-07-18 17:47 . 2012-08-15 06:51        2345984        ----a-w-        c:\windows\system32\win32k.sys
2012-07-04 21:14 . 2012-08-15 06:51        41984        ----a-w-        c:\windows\system32\browcli.dll
2012-07-04 21:14 . 2012-08-15 06:51        102912        ----a-w-        c:\windows\system32\browser.dll
2012-09-10 16:59 . 2011-05-02 13:59        266720        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaSuite.exe"="c:\program files\Nokia\Nokia Suite\NokiaSuite.exe" [2011-11-01 1053056]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2009-08-28 1486848]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2009-08-19 3618104]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2010-07-21 1778064]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-21 1797008]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"TeViiRC"="c:\windows\TeViiRC.exe" [2010-10-28 328024]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 gupdate;Google Update-Dienst (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 SKYNETU2C;TechniSat DVB-PC TV Star USB HD;c:\windows\system32\DRIVERS\SkyNetU2C.SYS [x]
R3 token;USB Token Service;c:\windows\system32\DRIVERS\eps2kt1.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 R5BaseSmc;USB Token Holder Service;c:\windows\system32\DRIVERS\smccard.sys [x]
S3 SAllBDA;TeVii DVB-S/S2 Receiver;c:\windows\system32\Drivers\TeViiS2.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 13:09]
.
2012-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-05 22:22]
.
2012-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-05 22:22]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.com
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\kdie60r2.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true);user_pref(extensions.BabylonToolbar_i.babTrack, affID=109958&tt=3012_6
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://www.google.com/search?babsrc=TB_ggl&q=
FF - user.js: extensions.BabylonToolbar.id - ec0f7e7900000000000090e6bae17256
FF - user.js: extensions.BabylonToolbar.instlDay - 15548
FF - user.js: extensions.BabylonToolbar.vrsn - 1.5.29.1
FF - user.js: extensions.BabylonToolbar.vrsni - 1.5.29.1
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.29.116:55
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6R8FQJiBhA&loc=IB_TB&i=26&search=
FF - user.js: extensions.incredibar_i.id - ec0f7e7900000000000090e6bae17256
FF - user.js: extensions.incredibar_i.instlDay - 15604
FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1416:18
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6R8FQJiBhA
FF - user.js: extensions.incredibar_i.upn2n - 92825094908365014
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10671
FF - user.js: extensions.incredibar_i.ppd - 7777720
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-MyTeVii - c:\mytevii\Uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-09-27  16:08:35
ComboFix-quarantined-files.txt  2012-09-27 14:08
.
Vor Suchlauf: 8 Verzeichnis(se), 83.348.381.696 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 83.018.895.360 Bytes frei
.
- - End Of File - - BC15A8427F9809F9ED97757BCEA0B83A

--- --- ---

cosinus 27.09.2012 16:35

Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.


Code:

Firefox::
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\kdie60r2.default\
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true);user_pref(extensions.BabylonToolbar_i.babTrack, affID=109958&tt=3012_6
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - http://www.google.com/search?babsrc=TB_ggl&q=
FF - user.js: extensions.BabylonToolbar.id - ec0f7e7900000000000090e6bae17256
FF - user.js: extensions.BabylonToolbar.instlDay - 15548
FF - user.js: extensions.BabylonToolbar.vrsn - 1.5.29.1
FF - user.js: extensions.BabylonToolbar.vrsni - 1.5.29.1
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.29.116:55
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - http://mystart.Incredibar.com/?a=6R8FQJiBhA&loc=IB_TB&i=26&search=
FF - user.js: extensions.incredibar_i.id - ec0f7e7900000000000090e6bae17256
FF - user.js: extensions.incredibar_i.instlDay - 15604
FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1416:18
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6R8FQJiBhA
FF - user.js: extensions.incredibar_i.upn2n - 92825094908365014
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10671
FF - user.js: extensions.incredibar_i.ppd - 7777720

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

rwt69 27.09.2012 17:22

Ist etwas peinlich, ab er ich weiß nicht wie das geht oder was ich machen muss:

Zitat:

1. Starte das Notepad (Start / Ausführen / notepad[Enter])
??

Muss ich auf Start gehen ? und dann ?
oder muss ich combofix starten ?

cosinus 27.09.2012 20:21

Notepad ist der Texteditor!!
Was in meiner CODE-Box im Beitrag steht musst du da reinkopieren und das als Textdatei CFScript.txt auf dem Desktop abspeichern

rwt69 28.09.2012 07:05

Combofix Logfile:
Code:

ComboFix 12-09-27.03 - User 28.09.2012  7:59.2.4 - x86
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3327.2420 [GMT 2:00]
ausgeführt von:: c:\users\User\Downloads\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\User\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-08-28 bis 2012-09-28  ))))))))))))))))))))))))))))))
.
.
2012-09-28 06:03 . 2012-09-28 06:03        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-09-26 11:40 . 2012-09-26 11:40        --------        d-----w-        C:\_OTL
2012-09-26 11:35 . 2012-08-21 20:12        245760        ----a-w-        c:\windows\system32\OxpsConverter.exe
2012-09-23 10:15 . 2012-09-23 10:15        --------        d-----w-        c:\program files\ESET
2012-09-22 15:53 . 2012-09-22 15:53        --------        d-----w-        c:\users\User\AppData\Roaming\Malwarebytes
2012-09-22 15:53 . 2012-09-22 15:53        --------        d-----w-        c:\programdata\Malwarebytes
2012-09-22 15:53 . 2012-09-22 15:53        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2012-09-22 15:53 . 2012-09-07 15:04        22856        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-09-21 14:18 . 2012-09-21 15:50        --------        d-----w-        c:\program files\7-Zip
2012-09-13 06:33 . 2012-08-22 17:16        1292144        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-09-13 06:33 . 2012-08-22 17:16        712048        ----a-w-        c:\windows\system32\drivers\ndis.sys
2012-09-13 06:33 . 2012-07-04 19:45        33280        ----a-w-        c:\windows\system32\drivers\RNDISMP.sys
2012-09-13 06:33 . 2012-08-22 17:16        240496        ----a-w-        c:\windows\system32\drivers\netio.sys
2012-09-13 06:33 . 2012-08-22 17:16        187760        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-13 06:33 . 2012-08-02 16:57        490496        ----a-w-        c:\windows\system32\d3d10level9.dll
2012-09-10 16:59 . 2012-09-10 16:59        73696        ----a-w-        c:\program files\Mozilla Firefox\breakpadinjector.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-21 13:09 . 2012-04-03 05:45        696240        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-09-21 13:09 . 2011-05-25 04:44        73136        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-28 18:24 . 2012-07-01 18:46        477168        ----a-w-        c:\windows\system32\npdeployJava1.dll
2012-08-28 18:24 . 2010-07-02 07:21        473072        ----a-w-        c:\windows\system32\deployJava1.dll
2012-07-18 17:47 . 2012-08-15 06:51        2345984        ----a-w-        c:\windows\system32\win32k.sys
2012-07-04 21:14 . 2012-08-15 06:51        41984        ----a-w-        c:\windows\system32\browcli.dll
2012-07-04 21:14 . 2012-08-15 06:51        102912        ----a-w-        c:\windows\system32\browser.dll
2012-09-10 16:59 . 2011-05-02 13:59        266720        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaSuite.exe"="c:\program files\Nokia\Nokia Suite\NokiaSuite.exe" [2011-11-01 1053056]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2009-08-28 1486848]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2009-08-19 3618104]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2010-07-21 1778064]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-21 1797008]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"TeViiRC"="c:\windows\TeViiRC.exe" [2010-10-28 328024]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 gupdate;Google Update-Dienst (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 SKYNETU2C;TechniSat DVB-PC TV Star USB HD;c:\windows\system32\DRIVERS\SkyNetU2C.SYS [x]
R3 token;USB Token Service;c:\windows\system32\DRIVERS\eps2kt1.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 R5BaseSmc;USB Token Holder Service;c:\windows\system32\DRIVERS\smccard.sys [x]
S3 SAllBDA;TeVii DVB-S/S2 Receiver;c:\windows\system32\Drivers\TeViiS2.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 13:09]
.
2012-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-05 22:22]
.
2012-09-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-05 22:22]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.com
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\kdie60r2.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-09-28  08:04:11
ComboFix-quarantined-files.txt  2012-09-28 06:04
ComboFix2.txt  2012-09-27 14:08
.
Vor Suchlauf: 10 Verzeichnis(se), 83.203.399.680 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 83.155.587.072 Bytes frei
.
- - End Of File - - D004A84D8C00898A48DFF8A42962402D

--- --- ---
[/code]

cosinus 28.09.2012 13:05

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

rwt69 30.09.2012 16:36

Hat ein bisschen gedauert, GMER ist immer abgestürzt.
Hier der OSAM-Report:

OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 16:03:15 on 30.09.2012

OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 32-bit
Default Browser: Mozilla Corporation Firefox 15.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"nvcpl.cpl" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Nero BurnRights" - "Nero AG" - C:\Program Files\Nero\Nero 9\Nero BurnRights\NeroBurnRights_cpl.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Apple Mobile USB Driver" (USBAAPL) - "Apple, Inc." - C:\Windows\System32\Drivers\usbaapl.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\Users\User\AppData\Local\Temp\catchme.sys  (File not found)
"Cinergy EM28xx Capture" (USB28xxBGA) - "eMPIA Technology, Inc." - C:\Windows\System32\DRIVERS\emBDA.sys
"Cinergy EM28xx OEM Filter" (USB28xxOEM) - "eMPIA Technology, Inc." - C:\Windows\System32\DRIVERS\emOEM.sys
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{BDEADF00-C265-11d0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{C9E60ED7-FEAE-477b-B6A6-7D62103A0C6B} "NeroDigitalColumnHandler Class" - "Nero AG" - C:\Program Files\Common Files\Nero\SMC\NeroDigitalExt.dll
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{653DCCC2-13DB-45B2-A389-427885776CFE} "Activities Property Page" - "Microsoft Corporation" - C:\Program Files\Microsoft IntelliPoint\ipcplact.dll
{124597D8-850A-41AE-849C-017A4FA99CA2} "Buttons Property Page" - "Microsoft Corporation" - C:\Program Files\Microsoft IntelliPoint\ipcplbtn.dll
{0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
{A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll
{3BEABCC1-BF31-42df-88D9-A2955D6B8528} "IntelliPoint Sensitivity Property Page" - "Microsoft Corporation" - C:\Program Files\Microsoft IntelliPoint\ipcplsens.dll
{ED6E87C6-8A83-43aa-8208-8DBC8247F4D2} "IntelliType Pro Key Settings Property Page" - "Microsoft Corporation" - C:\Program Files\Microsoft IntelliType Pro\itcplkey.dll
{111D8120-25EB-4E1C-A4DF-C9EE5FCA35CB} "IntelliType Pro Scrolling Property Page" - "Microsoft Corporation" - C:\Program Files\Microsoft IntelliType Pro\itcplwhl.dll
{1825D0FA-5B0C-4e20-A929-3EFD15B6DF71} "IntelliType Pro Touchpad Control Property Page" - "Microsoft Corporation" - C:\Program Files\Microsoft IntelliType Pro\itcpltp.dll
{A2569D1F-4E06-43EC-9825-0088B471BE47} "IntelliType Pro Wireless Control Panel Property Page" - "Microsoft Corporation" - C:\Program Files\Microsoft IntelliType Pro\itcplwir.dll
{97FA8AA2-EE77-4FF2-9449-424D8924EF21} "IntelliType Pro Zooming Property Page" - "Microsoft Corporation" - C:\Program Files\Microsoft IntelliType Pro\itcplzm.dll
{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2} "NeroCoverEdLiveIcons Class" - "Nero AG" - C:\Program Files\Nero\Nero 9\Nero CoverDesigner\CoverEdExtension.dll
{C9E60ED7-FEAE-477b-B6A6-7D62103A0C6B} "NeroDigitalColumnHandler Class" - "Nero AG" - C:\Program Files\Common Files\Nero\SMC\NeroDigitalExt.dll
{1CA6BBC9-E9FA-4021-822B-075DF1837B63} "NeroDigitalIconHandler Class" - "Nero AG" - C:\Program Files\Common Files\Nero\SMC\NeroDigitalExt.dll
{4FBFFA8D-F390-471a-AE46-FEB93623AD63} "NeroDigitalInfoHandler Class" - "Nero AG" - C:\Program Files\Common Files\Nero\SMC\NeroDigitalExt.dll
{846083A4-BFC6-4447-985C-6578B466A7D7} "NeroDigitalPropSheetHandler Class" - "Nero AG" - C:\Program Files\Common Files\Nero\SMC\NeroDigitalExt.dll
{EDCC595A-F0EE-4d81-B554-D5D01C7AFB87} "NeroDigitalThumbnailHandler Class" - "Nero AG" - C:\Program Files\Common Files\Nero\SMC\NeroDigitalExt.dll
{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll
{FFB699E0-306A-11d3-8BD1-00104B6F7516} "NVIDIA CPL Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{1184D0ED-DBCE-4170-8DBB-4D0C3905DA85} "Touch Property Page" - "Microsoft Corporation" - C:\Program Files\Microsoft IntelliPoint\ipcpltouch.dll
{AF90F543-6A3A-4C1B-8B16-ECEC073E69BE} "Wheel Property Page" - "Microsoft Corporation" - C:\Program Files\Microsoft IntelliPoint\ipcplwhl.dll
{20082881-FC36-4E47-9A7A-644C95FF749F} "Wireless Property Page" - "Microsoft Corporation" - C:\Program Files\Microsoft IntelliPoint\ipcplwir.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_35" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} "Java Plug-in 1.6.0_35" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_35" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_35.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{F0181C6E-9218-4792-9F3C-E8DF52B2F1AC} "GretechBHO Class" - "Gretech Corporation" - C:\Program Files\GRETECH\GomPicker\GomPickerBHO.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\ssv.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"OpenOffice.org 3.2.lnk" - ? - C:\Program Files\OpenOffice.org 3\program\quickstart.exe  (Shortcut exists | File found, but it contains no detailed information | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Microsoft Office.lnk" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office\OSA9.EXE  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"NokiaSuite.exe" - "Nokia" - C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"BrStsWnd" - "brother" - C:\Program Files\Brownie\BrstsWnd.exe Autorun
"HDAudDeck" - "VIA" - C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe -r
"IntelliPoint" - "Microsoft Corporation" - "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
"itype" - "Microsoft Corporation" - "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"Google Update-Dienst (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"MBAMScheduler" (MBAMScheduler) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
"Nero BackItUp Scheduler 4.0" (Nero BackItUp Scheduler 4.0) - "Nero AG" - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
"NVIDIA Display Driver Service" (nvsvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe
"NVIDIA Stereoscopic 3D Driver Service" (Stereo Service) - "NVIDIA Corporation" - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
"ServiceLayer" (ServiceLayer) - "Nokia" - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---



Hier das von aswmbr:

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-30 16:12:35
-----------------------------
16:12:35.554    OS Version: Windows 6.1.7601 Service Pack 1
16:12:35.554    Number of processors: 4 586 0x403
16:12:35.555    ComputerName: ROBERT  UserName: User
16:12:57.203    Initialize success
16:15:25.500    AVAST engine defs: 12093000
16:15:42.708    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3
16:15:42.716    Disk 0 Vendor: SAMSUNG_HD502HJ 1AJ100E4 Size: 476940MB BusType: 3
16:15:42.729    Disk 0 MBR read successfully
16:15:42.736    Disk 0 MBR scan
16:15:42.743    Disk 0 Windows 7 default MBR code
16:15:42.751    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
16:15:42.764    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      199899 MB offset 206848
16:15:42.783    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      276939 MB offset 409600000
16:15:42.791    Disk 0 scanning sectors +976771072
16:15:42.857    Disk 0 scanning C:\Windows\system32\drivers
16:15:50.227    Service scanning
16:16:06.061    Modules scanning
16:16:14.754    Disk 0 trace - called modules:
16:16:14.796    ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
16:16:14.804    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x863bc440]
16:16:14.813    3 CLASSPNP.SYS[8bd8159e] -> nt!IofCallDriver -> [0x85587638]
16:16:14.821    5 ACPI.sys[833ad3d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-3[0x85eac030]
16:16:15.228    AVAST engine scan C:\Windows
16:16:17.221    AVAST engine scan C:\Windows\system32
16:18:18.555    AVAST engine scan C:\Windows\system32\drivers
16:18:27.930    AVAST engine scan C:\Users\User
16:41:01.067    AVAST engine scan C:\ProgramData
16:42:06.301    Scan finished successfully
17:34:09.848    Disk 0 MBR has been saved successfully to "C:\Users\User\Desktop\MBR.dat"
17:34:09.852    The log file has been saved successfully to "C:\Users\User\Desktop\aswMBR.txt"


cosinus 01.10.2012 12:55

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

rwt69 02.10.2012 22:15

Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.10.02.07

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
User :: ROBERT [Administrator]

Schutz: Aktiviert

02.10.2012 18:42:11
mbam-log-2012-10-02 (18-42-11).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 423598
Laufzeit: 1 Stunde(n), 10 Minute(n), 37 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 10/03/2012 at 00:34 AM

Application Version : 5.5.1022

Core Rules Database Version : 9329
Trace Rules Database Version: 7141

Scan type      : Complete Scan
Total Scan Time : 00:53:43

Operating System Information
Windows 7 Home Premium 32-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 808
Memory threats detected  : 0
Registry items scanned    : 34819
Registry threats detected : 0
File items scanned        : 62233
File threats detected    : 533

Adware.Tracking Cookie
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@discount24[1].txt [ /discount24 ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@www.adultshop[1].txt [ /www.adultshop ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\02K342ZB.txt [ /imrworldwide.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\6QZMUT9H.txt [ /fastclick.net ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\ROGF60ZY.txt [ /ad.zanox.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\XH8UFWEO.txt [ /apmebf.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\Y78448ZC.txt [ /atdmt.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\GQGUE2BL.txt [ /adform.net ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\959EB0Y8.txt [ /tradedoubler.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\C3FI6DZG.txt [ /doubleclick.net ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\8DE1U265.txt [ /mediaplex.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\LXPWIOYD.txt [ /track.adform.net ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\KKH23ZOI.txt [ /adfarm1.adition.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\5YMJGTDY.txt [ /zanox.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\QT0QLM5X.txt [ /ad1.adfarm1.adition.com ]
        C:\USERS\USER\Cookies\6QZMUT9H.txt [ Cookie:user@fastclick.net/ ]
        C:\USERS\USER\Cookies\ROGF60ZY.txt [ Cookie:user@ad.zanox.com/ ]
        C:\USERS\USER\Cookies\XH8UFWEO.txt [ Cookie:user@apmebf.com/ ]
        C:\USERS\USER\Cookies\Y78448ZC.txt [ Cookie:user@atdmt.com/ ]
        C:\USERS\USER\Cookies\GQGUE2BL.txt [ Cookie:user@adform.net/ ]
        C:\USERS\USER\Cookies\959EB0Y8.txt [ Cookie:user@tradedoubler.com/ ]
        C:\USERS\USER\Cookies\LXPWIOYD.txt [ Cookie:user@track.adform.net/ ]
        C:\USERS\USER\Cookies\KKH23ZOI.txt [ Cookie:user@adfarm1.adition.com/ ]
        C:\USERS\USER\Cookies\user@discount24[1].txt [ Cookie:user@discount24.de/ ]
        C:\USERS\USER\Cookies\QT0QLM5X.txt [ Cookie:user@ad1.adfarm1.adition.com/ ]
        aka-cdn-ns.adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XHRRPDTA ]
        imagesrv.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XHRRPDTA ]
        mediathek-audio.br.de [ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XHRRPDTA ]
        s0.2mdn.net [ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XHRRPDTA ]
        C:\USERS\USER\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\USER@IM.BANNER.T-ONLINE[1].TXT [ /IM.BANNER.T-ONLINE ]
        .imrworldwide.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .googleads.g.doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .view.atdmt.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .stats.ebay.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .aka-cdn-ns.adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        img-cdn.mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tto2.traffictrack.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .dealtime.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ww251.smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revenuemax.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mm.chitika.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6afkyomcjgep.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjmygoajoaq.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .nissaneurope.112.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tyredating.122.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adserver.planetoutdoor.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        wbr-ads-01.odmedia.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        wbr-ads-01.odmedia.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.sim-technik.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adserver.mainz05.onvert.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .s.clickability.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .s.clickability.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wmkougczwgp.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.3gnet.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.zalando.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        fr.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        fr.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ar.atwola.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .premiumtv.122.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .atwola.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .conrad.122.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediasports.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediasports.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6walysmajmgq.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aemiajazmdp.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aekoeldjgco.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .estat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        teufel-media.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        api.zanox.ws [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        api.zanox.ws [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        targeting.revenuemax.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        traffic.brand-wall.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .prisacom.112.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wgkoomcpsbp.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        media.antenne-bayern.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revenuemax.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        stat.novasol.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .track.trafficmaxx.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.trafficmaxx.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        aimfar.solution.weborama.fr [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .weboramapublishertrackinguk2.solution.weborama.fr [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .weboramapublishertrackinguk2.solution.weborama.fr [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .deutschepostag.112.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wclyqkdjkbp.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .paypal.112.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        count.asnetworks.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revenuemax.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tags.toolbarsmedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tags.toolbarsmedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ads20.wwe-media.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ads20.wwe-media.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ads20.wwe-media.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ads20.wwe-media.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ads20.wwe-media.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adserver.adtechus.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tags.toolbarsmedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.usenext.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .kontera.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        stat.dealtime.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        server.adformdsp.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adformdsp.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .bizrate.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .fls.doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.thelabelfinder.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.thelabelfinder.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adserver-landshut.teamcommerce.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjkoaicpkap.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracker.vinsight.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        s1.trafficmaxx.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adserver.anschlusstor.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adserver.bfv.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas5.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas5.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        server.iad.liveperson.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adserver.mundo-service.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .olympiaverlag.122.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tomtailor.dyntracker.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]

Trojan.Dropper/Gen
        F:\DATEIEN\MIXED\REST\T-ONLINE\BSW3\DRELREST.EXE
        C:\USERS\USER\DOCUMENTS\MIXED\REST\T-ONLINE\BSW3\DRELREST.EXE

Trojan.Agent/Gen-MSFake
        C:\USERS\USER\APPDATA\ROAMING\DESKTOPICONFORAMAZON\ICONFORAMAZON.EXE


cosinus 03.10.2012 18:11

Code:

UAC On - Limited User
Wie hast du sasw gestartet? Einfach per Doppelklick?

rwt69 03.10.2012 19:03

Ich glaube ich habe vergessen im Reiter "Scann-Kontrolle" die richtigen Häkchen zu setzen. Soll ich es nochmal machen ?

cosinus 03.10.2012 20:02

Nein - starte SASW doch einfach wie in der Anleitung im großen Punkt zwei beschrieben!

Zitat:

Zitat von cosinus (Beitrag 324870)
Teil 2: Programm ausführen
Das Programm wurde nun installiert, eine Verknüpfung auf dem Desktop sollte erstellt worden sein. Nachdem du es gestartet hast, wird es sich erstmalig beim Updateserver nach neuen Schädlingssignaturen umsehen und Updates installieren. Diesen Vorgang NICHT abbrechen!

Benutzer mit Windows Vista und Windows 7 starten das Tool bitte wieder per Rechtsklick => als Administrator ausführen!


rwt69 04.10.2012 05:46

Habs nochmal gemacht, kommt irgendwie das Gleiche raus ..


Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 10/04/2012 at 00:46 AM

Application Version : 5.5.1022

Core Rules Database Version : 9335
Trace Rules Database Version: 7147

Scan type      : Complete Scan
Total Scan Time : 03:15:26

Operating System Information
Windows 7 Home Premium 32-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 820
Memory threats detected  : 0
Registry items scanned    : 34819
Registry threats detected : 0
File items scanned        : 243983
File threats detected    : 542

Adware.Tracking Cookie
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@discount24[1].txt [ /discount24 ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@www.adultshop[1].txt [ /www.adultshop ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\02K342ZB.txt [ /imrworldwide.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\6QZMUT9H.txt [ /fastclick.net ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\JM5IDPPB.txt [ /ad.zanox.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\XH8UFWEO.txt [ /apmebf.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\Y78448ZC.txt [ /atdmt.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\GQGUE2BL.txt [ /adform.net ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\959EB0Y8.txt [ /tradedoubler.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\C3FI6DZG.txt [ /doubleclick.net ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\N7ZGGOSN.txt [ /mediaplex.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\LXPWIOYD.txt [ /track.adform.net ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\KKH23ZOI.txt [ /adfarm1.adition.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\OOHE1L8R.txt [ /zanox.com ]
        C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\QT0QLM5X.txt [ /ad1.adfarm1.adition.com ]
        C:\USERS\USER\Cookies\6QZMUT9H.txt [ Cookie:user@fastclick.net/ ]
        C:\USERS\USER\Cookies\JM5IDPPB.txt [ Cookie:user@ad.zanox.com/ ]
        C:\USERS\USER\Cookies\XH8UFWEO.txt [ Cookie:user@apmebf.com/ ]
        C:\USERS\USER\Cookies\Y78448ZC.txt [ Cookie:user@atdmt.com/ ]
        C:\USERS\USER\Cookies\GQGUE2BL.txt [ Cookie:user@adform.net/ ]
        C:\USERS\USER\Cookies\959EB0Y8.txt [ Cookie:user@tradedoubler.com/ ]
        C:\USERS\USER\Cookies\LXPWIOYD.txt [ Cookie:user@track.adform.net/ ]
        C:\USERS\USER\Cookies\KKH23ZOI.txt [ Cookie:user@adfarm1.adition.com/ ]
        C:\USERS\USER\Cookies\user@discount24[1].txt [ Cookie:user@discount24.de/ ]
        C:\USERS\USER\Cookies\QT0QLM5X.txt [ Cookie:user@ad1.adfarm1.adition.com/ ]
        aka-cdn-ns.adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XHRRPDTA ]
        imagesrv.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XHRRPDTA ]
        mediathek-audio.br.de [ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XHRRPDTA ]
        s0.2mdn.net [ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XHRRPDTA ]
        C:\USERS\USER\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\USER@AD.MITTELBAYERISCHE[1].TXT [ /AD.MITTELBAYERISCHE ]
        C:\USERS\USER\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\USER@IM.BANNER.T-ONLINE[1].TXT [ /IM.BANNER.T-ONLINE ]
        .imrworldwide.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .googleads.g.doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .view.atdmt.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .stats.ebay.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .aka-cdn-ns.adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        img-cdn.mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tto2.traffictrack.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .dealtime.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ww251.smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revenuemax.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mm.chitika.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6afkyomcjgep.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjmygoajoaq.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .nissaneurope.112.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tyredating.122.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adserver.planetoutdoor.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        wbr-ads-01.odmedia.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        wbr-ads-01.odmedia.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.sim-technik.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adserver.mainz05.onvert.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .s.clickability.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .s.clickability.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wmkougczwgp.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.3gnet.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.zalando.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        fr.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        fr.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ar.atwola.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .premiumtv.122.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .atwola.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .conrad.122.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediasports.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediasports.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6walysmajmgq.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aemiajazmdp.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aekoeldjgco.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .estat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        teufel-media.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        api.zanox.ws [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        api.zanox.ws [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        targeting.revenuemax.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        traffic.brand-wall.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .prisacom.112.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wgkoomcpsbp.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        media.antenne-bayern.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revenuemax.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        stat.novasol.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .track.trafficmaxx.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.trafficmaxx.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        aimfar.solution.weborama.fr [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .weboramapublishertrackinguk2.solution.weborama.fr [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .weboramapublishertrackinguk2.solution.weborama.fr [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .deutschepostag.112.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wclyqkdjkbp.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .paypal.112.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        count.asnetworks.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revenuemax.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tags.toolbarsmedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tags.toolbarsmedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ads20.wwe-media.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ads20.wwe-media.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ads20.wwe-media.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ads20.wwe-media.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ads20.wwe-media.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adserver.adtechus.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tags.toolbarsmedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.usenext.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .kontera.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        stat.dealtime.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        server.adformdsp.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adformdsp.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .bizrate.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .fls.doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.thelabelfinder.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.thelabelfinder.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adserver-landshut.teamcommerce.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjkoaicpkap.stats.esomniture.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracker.vinsight.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        s1.trafficmaxx.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adserver.anschlusstor.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas5.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas5.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        server.iad.liveperson.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        tomtailor.dyntracker.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .www.mitrack.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .www.mitrack.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .trackedbylav.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .trackedbylav.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adserver.mundo-service.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .olympiaverlag.122.2o7.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        adserver.bfv.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDIE60R2.DEFAULT\COOKIES.SQLITE ]

Trojan.Dropper/Gen
        F:\DATEIEN\MIXED\REST\T-ONLINE\BSW3\DRELREST.EXE
        C:\USERS\USER\DOCUMENTS\MIXED\REST\T-ONLINE\BSW3\DRELREST.EXE

Trojan.Agent/Gen-MSFake
        C:\USERS\USER\APPDATA\ROAMING\DESKTOPICONFORAMAZON\ICONFORAMAZON.EXE


cosinus 04.10.2012 09:35

Dann ist das ein Bug von sasw ignorieren wir es

Sieht ok aus, da wurden nur Cookies gefunden. Die anderen drei Funde sehen mir nach Fehlalarmen aus.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

rwt69 04.10.2012 21:31

Vielen Dank !!
Das System schaut so aus, als ob es in Ordnung wäre.
Soll ich also die Funde in SASW nicht löschen ?

Am Ende bleibt mir nur, dass ich mich nochmal sehr herzlich für die tolle Hilfe bedanke. :bussi:
Ans Board hab ich schon gespendet .. ;-)
:dankeschoen::dankeschoen::dankeschoen:

cosinus 05.10.2012 13:07

Doch die Cookies sollten weg!

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 09:07 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19