|
Plagegeister aller Art und deren Bekämpfung: Searchcompletion.com hat mein Google übernommenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.09.2011, 10:51 | #1 |
| Searchcompletion.com hat mein Google übernommen Hallo liebe Community, ich bin leider in Sicherheitsfragen nicht sehr befähigt, werde aber mein bestes tun um eure Anweisungen zu befolgen und euch so gut es geht zu unterstützen. Ich stecke mitten in meiner Diplomarbeit und bin daher etwas im Stress und evtl. ist mein Problem kein großes. Aber google hat leider nicht weitergeholfen und meine Scanner (AVAST, Spybot, Superantispyware, hijack) auch nicht. Nun zu meinem Problem: Mein google wurde wohl von searchcompletion.com gehijackt, zumindest laufen alle Suchanfragen darüber. Ist mir erstmal nicht aufgefallen, da ich dachte die Veränderung im Design rühre mit dem Firefox update einher. Darauf gebracht hat mich aber eine nervige BOX unten links, die mir search suggestions gibt. Beim Blick auf andere Browser (Chrome, IE) zeigte sich das selbe Phänomen. Deshalb bin ich auch endlich skeptisch geworden. Ich habesowohl den defogger und auch otl laufen lassen. Hier die logfiles (gehört das eigentlich so einfach hier rein?): defogger defogger_disable by jpshortstuff (23.02.10.1) Log created at 10:32 on 22/09/2011 (***) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- otl und extras habe ich als Anhang beigefügt. Wäre über schnelle Hilfe dankbar. Da ich meine Diplomarbeit in Gefahr sehe... VG Kaan |
22.09.2011, 12:32 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Searchcompletion.com hat mein Google übernommen Bitte routinemäßig einen Vollscan mit Malwarebytes machen und Log posten.
__________________Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! Führe danach auch bitte ESET aus, danach sehen wir weiter. ESET Online Scanner
n.
__________________ |
22.09.2011, 16:38 | #3 |
| Searchcompletion.com hat mein Google übernommen Hallo,
__________________danke das das so schnell ging. Habe die Scans gemacht. Hier erstmal die LOGs Das sind die Logs von Malwarebytes und ESET (dort scheint etwas gefunden worden zu sein): Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 6533 Windows 6.1.7601 Service Pack 1 Internet Explorer 8.0.7601.17514 08.05.2011 22:44:10 mbam-log-2011-05-08 (22-44-10).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 164493 Laufzeit: 1 Minute(n), 35 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Datenbank Version: 7766 Windows 6.1.7601 Service Pack 1 Internet Explorer 9.0.8112.16421 22.09.2011 00:43:46 mbam-log-2011-09-22 (00-43-46).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 190662 Laufzeit: 4 Minute(n), 12 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Datenbank Version: 7770 Windows 6.1.7601 Service Pack 1 Internet Explorer 9.0.8112.16421 22.09.2011 14:09:01 mbam-log-2011-09-22 (14-09-01).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 305523 Laufzeit: 29 Minute(n), 52 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) Und hier die Log von ESET ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=1eed96c58e169d4f9aa46026d7daae7c # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-09-22 02:14:11 # local_time=2011-09-22 04:14:11 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 184464 68324069 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=125770 # found=1 # cleaned=0 # scan_time=6631 D:\KAAN-PC\Backup Set 2011-06-15 155241\Backup Files 2011-06-15 155241\Backup files 2.zip HTML/ScrInject.B.Gen virus (unable to clean) 00000000000000000000000000000000 I Hoffentlich reicht das zum Auswerten. Vielen Dank. Kaan |
22.09.2011, 20:16 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Searchcompletion.com hat mein Google übernommen Sieht aus als hättest du keinen CustomScan mit OTL gemacht. CustomScan mit OTL Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
__________________ Logfiles bitte immer in CODE-Tags posten |
22.09.2011, 20:52 | #5 |
| Searchcompletion.com hat mein Google übernommen Hallo, entschuldige Bitte. Das habe ich wohl beim ersten Versuch nicht richtig gelesen. So, hier nun der hoffentlich richtige Log: OTL Logfile: Code:
ATTFilter OTL logfile created on: 22.09.2011 21:35:48 - Run 2 OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Kaan\Desktop 64bit- An unknown product Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,75 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 63,50% Memory free 7,49 Gb Paging File | 6,13 Gb Available in Paging File | 81,77% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 78,03 Gb Total Space | 40,92 Gb Free Space | 52,44% Space Free | Partition Type: NTFS Drive D: | 219,96 Gb Total Space | 115,03 Gb Free Space | 52,29% Space Free | Partition Type: NTFS Computer Name: KAAN-PC | User Name: Kaan | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011.09.22 10:25:18 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Kaan\Desktop\OTL.exe PRC - [2011.09.06 22:45:30 | 003,722,416 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe PRC - [2011.09.06 22:45:28 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe PRC - [2011.03.31 16:08:14 | 000,080,896 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe PRC - [2011.01.17 18:50:34 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe PRC - [2011.01.17 18:50:34 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin PRC - [2009.03.30 15:00:54 | 000,221,184 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe ========== Modules (No Company Name) ========== MOD - [2011.04.15 15:28:53 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll MOD - [2011.04.15 15:28:53 | 000,170,496 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxslt.dll MOD - [2009.02.27 16:38:22 | 000,139,264 | R--- | M] () -- C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll ========== Win32 Services (SafeList) ========== SRV:64bit: - [2011.09.06 22:45:28 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV:64bit: - [2011.09.06 22:45:27 | 000,127,192 | ---- | M] (AVAST Software) [Auto | Stopped] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall) SRV:64bit: - [2011.08.12 01:38:04 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE) SRV:64bit: - [2010.03.17 04:48:42 | 000,244,736 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\stacsv64.exe -- (STacSV) SRV:64bit: - [2009.08.18 02:36:20 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV:64bit: - [2009.03.03 02:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe -- (AESTFilters) SRV - [2011.06.17 09:34:18 | 000,359,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ) SRV - [2011.06.02 18:31:42 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2011.03.31 16:08:14 | 000,080,896 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service) SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService) ========== Driver Services (SafeList) ========== DRV:64bit: - [2011.09.06 22:39:00 | 000,140,120 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswFW.sys -- (aswFW) DRV:64bit: - [2011.09.06 22:38:18 | 000,601,944 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx) DRV:64bit: - [2011.09.06 22:38:16 | 000,301,912 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP) DRV:64bit: - [2011.09.06 22:37:45 | 000,258,392 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswNdis2.sys -- (aswNdis2) DRV:64bit: - [2011.09.06 22:36:41 | 000,058,200 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi) DRV:64bit: - [2011.09.06 22:36:41 | 000,042,328 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr.sys -- (aswRdr) DRV:64bit: - [2011.09.06 22:36:30 | 000,065,368 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt) DRV:64bit: - [2011.09.06 22:36:14 | 000,024,408 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk) DRV:64bit: - [2011.07.04 13:12:07 | 000,012,368 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswNdis.sys -- (aswNdis) DRV:64bit: - [2011.04.30 13:59:22 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt) DRV:64bit: - [2011.04.30 13:59:22 | 000,060,184 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt) DRV:64bit: - [2011.04.14 00:57:28 | 003,063,360 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX) DRV:64bit: - [2011.03.21 13:22:06 | 000,452,200 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010.11.21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc) DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:64bit: - [2010.06.25 16:08:10 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot) DRV:64bit: - [2010.06.03 19:18:56 | 001,379,376 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:64bit: - [2010.03.17 04:48:42 | 000,505,856 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA) DRV:64bit: - [2009.11.01 19:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64) DRV:64bit: - [2009.08.18 03:48:48 | 006,037,504 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag) DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV - [2011.07.22 18:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV) DRV - [2011.07.12 23:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL) DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0C DB 95 58 B4 78 CC 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "mydealz.de" FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?q=" FF - prefs.js..network.proxy.type: 0 FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: D:\Tools\Picasa\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: D:\Tools\TVUPlayer\npTVUAx.dll (TVU networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011.09.12 13:38:44 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}: C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2011.08.11 02:06:15 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.09.08 23:00:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.09.10 15:57:01 | 000,000,000 | ---D | M] [2011.04.14 02:15:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kaan\AppData\Roaming\mozilla\Extensions [2011.09.21 22:14:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kaan\AppData\Roaming\mozilla\Firefox\Profiles\1g3uy9i8.default\extensions [2011.07.29 09:17:51 | 000,000,000 | ---D | M] (BitDefender QuickScan) -- C:\Users\Kaan\AppData\Roaming\mozilla\Firefox\Profiles\1g3uy9i8.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2011.09.18 18:47:30 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Users\Kaan\AppData\Roaming\mozilla\Firefox\Profiles\1g3uy9i8.default\extensions\firefox@tvunetworks.com [2011.09.22 00:30:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2011.04.15 15:27:53 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2011.04.15 19:08:06 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011.06.15 14:12:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [2011.09.12 13:38:44 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF () (No name found) -- C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI () (No name found) -- C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\EXTENSIONS\{DD05FD3D-18DF-4CE4-AE53-E795339C5F01}.XPI [2011.09.08 23:00:53 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2011.05.04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2011.09.08 23:00:50 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2011.09.08 23:00:50 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2011.09.08 23:00:50 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2011.09.08 23:00:50 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2011.09.08 23:00:50 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2011.09.08 23:00:50 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms} CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Kaan\AppData\Local\Google\Chrome\Application\13.0.782.107\gcswf32.dll CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: Chrome NaCl (Disabled) = C:\Users\Kaan\AppData\Local\Google\Chrome\Application\13.0.782.107\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Kaan\AppData\Local\Google\Chrome\Application\13.0.782.107\pdf.dll CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll CHR - plugin: Picasa (Enabled) = D:\Tools\Picasa\Picasa3\npPicasa3.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin CHR - Extension: avast! WebRep = C:\Users\Kaan\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1289_0\ CHR - Extension: BitDefender QuickScan = C:\Users\Kaan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.99_0\ O1 HOSTS File: ([2011.05.08 22:38:22 | 000,433,994 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 127.0.0.1 123fporn.info O1 - Hosts: 14934 more lines... O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray64.exe (IDT, Inc.) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com) O4 - Startup: C:\Users\Kaan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Kaan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Kaan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} hxxp://download.bitdefender.com/resources/scanner/sources/de/scan8/oscan8.cab (BDSCANONLINE Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60E89D9A-B282-4C7F-8244-E180B3C99E12}: DhcpNameServer = 192.168.1.1 O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Programme\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) MsConfig:64bit - StartUpReg: ControlCenter3 - hkey= - key= - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.) MsConfig:64bit - StartUpReg: HTC Sync Loader - hkey= - key= - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe () MsConfig:64bit - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation) MsConfig:64bit - StartUpReg: Steam - hkey= - key= - D:\Games\Steam\Steam.exe (Valve Corporation) MsConfig:64bit - State: "startup" - Reg Error: Key error. SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com) SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SafeBootMin:64bit: Base - Driver Group SafeBootMin:64bit: Boot Bus Extender - Driver Group SafeBootMin:64bit: Boot file system - Driver Group SafeBootMin:64bit: File system - Driver Group SafeBootMin:64bit: Filter - Driver Group SafeBootMin:64bit: HelpSvc - Service SafeBootMin:64bit: PCI Configuration - Driver Group SafeBootMin:64bit: PNP Filter - Driver Group SafeBootMin:64bit: Primary disk - Driver Group SafeBootMin:64bit: sacsvr - Service SafeBootMin:64bit: SCSI Class - Driver Group SafeBootMin:64bit: System Bus Extender - Driver Group SafeBootMin:64bit: vmms - Service SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vmms - Service SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com) SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SafeBootNet:64bit: Base - Driver Group SafeBootNet:64bit: Boot Bus Extender - Driver Group SafeBootNet:64bit: Boot file system - Driver Group SafeBootNet:64bit: File system - Driver Group SafeBootNet:64bit: Filter - Driver Group SafeBootNet:64bit: HelpSvc - Service SafeBootNet:64bit: Messenger - Service SafeBootNet:64bit: NDIS Wrapper - Driver Group SafeBootNet:64bit: NetBIOSGroup - Driver Group SafeBootNet:64bit: NetDDEGroup - Driver Group SafeBootNet:64bit: Network - Driver Group SafeBootNet:64bit: NetworkProvider - Driver Group SafeBootNet:64bit: PCI Configuration - Driver Group SafeBootNet:64bit: PNP Filter - Driver Group SafeBootNet:64bit: PNP_TDI - Driver Group SafeBootNet:64bit: Primary disk - Driver Group SafeBootNet:64bit: rdsessmgr - Service SafeBootNet:64bit: sacsvr - Service SafeBootNet:64bit: SCSI Class - Driver Group SafeBootNet:64bit: Streams Drivers - Driver Group SafeBootNet:64bit: System Bus Extender - Driver Group SafeBootNet:64bit: TDI - Driver Group SafeBootNet:64bit: vmms - Service SafeBootNet:64bit: WudfUsbccidDriver - Driver SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vmms - Service SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2011.09.22 14:20:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET [2011.09.22 14:19:42 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Kaan\Desktop\esetsmartinstaller_enu.exe [2011.09.22 10:25:16 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Users\Kaan\Desktop\OTL.exe [2011.09.22 01:01:25 | 000,000,000 | ---D | C] -- C:\Users\Kaan\AppData\Roaming\SUPERAntiSpyware.com [2011.09.22 01:00:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware [2011.09.22 01:00:50 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com [2011.09.22 01:00:50 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware [2011.09.22 00:28:23 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt [2011.09.18 18:47:36 | 000,000,000 | ---D | C] -- C:\Users\Kaan\AppData\Local\TVU Networks [2011.09.18 18:47:36 | 000,000,000 | ---D | C] -- C:\ProgramData\TVU Networks [2011.09.18 18:47:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TVUPlayer [2011.09.16 18:38:10 | 000,000,000 | ---D | C] -- C:\Users\Kaan\Desktop\VOICE [2011.09.15 14:18:40 | 000,000,000 | ---D | C] -- C:\Users\Kaan\Documents\Handelsblatt [2011.09.14 00:35:48 | 000,000,000 | ---D | C] -- C:\Users\Kaan\Desktop\Seminararbeit [2011.09.01 17:22:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype ========== Files - Modified Within 30 Days ========== [2011.09.22 21:30:38 | 000,018,227 | ---- | M] () -- C:\Users\Kaan\Desktop\Anforderungen an SMM.odt [2011.09.22 19:30:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.09.22 14:19:50 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Kaan\Desktop\esetsmartinstaller_enu.exe [2011.09.22 11:49:29 | 000,016,417 | ---- | M] () -- C:\Users\Kaan\Desktop\Desktop.zip [2011.09.22 11:48:22 | 000,012,217 | ---- | M] () -- C:\Users\Kaan\Desktop\Desktop.7z [2011.09.22 11:10:35 | 000,022,000 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011.09.22 11:10:35 | 000,022,000 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011.09.22 11:03:08 | 3017,195,520 | -HS- | M] () -- C:\hiberfil.sys [2011.09.22 10:32:33 | 000,000,000 | ---- | M] () -- C:\Users\Kaan\defogger_reenable [2011.09.22 10:25:18 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Kaan\Desktop\OTL.exe [2011.09.22 10:24:13 | 000,050,477 | ---- | M] () -- C:\Users\Kaan\Desktop\Defogger.exe [2011.09.22 10:22:53 | 000,000,432 | ---- | M] () -- C:\Windows\BRWMARK.INI [2011.09.22 01:00:53 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk [2011.09.19 15:04:16 | 000,174,731 | ---- | M] () -- C:\Users\Kaan\Documents\SpringerLink - Fulltext.pdf [2011.09.19 10:13:16 | 000,012,680 | ---- | M] () -- C:\Users\Kaan\Desktop\Unbenannt 1.odt [2011.09.18 18:47:30 | 000,000,646 | ---- | M] () -- C:\Users\Public\Desktop\TVUPlayer.lnk [2011.09.18 17:10:57 | 000,017,323 | ---- | M] () -- C:\Users\Kaan\Desktop\Lebenslauf-Alara.odt [2011.09.18 01:40:10 | 001,519,874 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2011.09.18 01:40:10 | 000,654,166 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2011.09.18 01:40:10 | 000,616,008 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2011.09.18 01:40:10 | 000,130,006 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2011.09.18 01:40:10 | 000,106,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2011.09.17 00:32:32 | 000,013,932 | ---- | M] () -- C:\Users\Kaan\Desktop\widerspruch.odt [2011.09.16 10:45:01 | 000,011,618 | ---- | M] () -- C:\Users\Kaan\Desktop\Vollmacht.odt [2011.09.16 10:44:34 | 000,042,998 | ---- | M] () -- C:\Users\Kaan\Desktop\Vollmacht.pdf [2011.09.15 14:55:00 | 000,445,189 | ---- | M] () -- C:\Users\Kaan\Desktop\Semesterbescheinigung.jpg [2011.09.13 01:31:02 | 000,060,878 | ---- | M] () -- C:\Users\Kaan\Desktop\Antrag_auf_Zulassung.pdf [2011.09.13 00:12:45 | 000,015,133 | ---- | M] () -- C:\Users\Kaan\Documents\SemStart.odt [2011.09.12 15:26:17 | 000,014,078 | ---- | M] () -- C:\Users\Kaan\Desktop\OpenDocument Text (neu).odt [2011.09.12 13:38:45 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt [2011.09.06 22:45:29 | 000,199,304 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe [2011.09.06 22:45:29 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2011.09.06 22:45:17 | 000,254,400 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe [2011.09.06 22:39:00 | 000,140,120 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFW.sys [2011.09.06 22:38:18 | 000,601,944 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys [2011.09.06 22:38:16 | 000,301,912 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys [2011.09.06 22:37:45 | 000,258,392 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswNdis2.sys [2011.09.06 22:36:41 | 000,058,200 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys [2011.09.06 22:36:41 | 000,042,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys [2011.09.06 22:36:30 | 000,065,368 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys [2011.09.06 22:36:14 | 000,024,408 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys [2011.08.31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2011.08.26 01:03:14 | 001,383,226 | ---- | M] () -- C:\Users\Kaan\Desktop\Lebenslauf aktuell.pdf ========== Files Created - No Company Name ========== [2011.09.22 21:30:36 | 000,018,227 | ---- | C] () -- C:\Users\Kaan\Desktop\Anforderungen an SMM.odt [2011.09.22 11:49:29 | 000,016,417 | ---- | C] () -- C:\Users\Kaan\Desktop\Desktop.zip [2011.09.22 11:48:22 | 000,012,217 | ---- | C] () -- C:\Users\Kaan\Desktop\Desktop.7z [2011.09.22 10:32:33 | 000,000,000 | ---- | C] () -- C:\Users\Kaan\defogger_reenable [2011.09.22 10:24:13 | 000,050,477 | ---- | C] () -- C:\Users\Kaan\Desktop\Defogger.exe [2011.09.22 01:00:53 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk [2011.09.19 15:04:15 | 000,174,731 | ---- | C] () -- C:\Users\Kaan\Documents\SpringerLink - Fulltext.pdf [2011.09.19 10:13:14 | 000,012,680 | ---- | C] () -- C:\Users\Kaan\Desktop\Unbenannt 1.odt [2011.09.18 18:47:30 | 000,000,646 | ---- | C] () -- C:\Users\Public\Desktop\TVUPlayer.lnk [2011.09.18 17:10:55 | 000,017,323 | ---- | C] () -- C:\Users\Kaan\Desktop\Lebenslauf-Alara.odt [2011.09.17 00:32:26 | 000,013,932 | ---- | C] () -- C:\Users\Kaan\Desktop\widerspruch.odt [2011.09.16 10:44:59 | 000,011,618 | ---- | C] () -- C:\Users\Kaan\Desktop\Vollmacht.odt [2011.09.16 10:44:32 | 000,042,998 | ---- | C] () -- C:\Users\Kaan\Desktop\Vollmacht.pdf [2011.09.15 14:55:00 | 000,445,189 | ---- | C] () -- C:\Users\Kaan\Desktop\Semesterbescheinigung.jpg [2011.09.13 01:31:02 | 000,060,878 | ---- | C] () -- C:\Users\Kaan\Desktop\Antrag_auf_Zulassung.pdf [2011.08.26 00:53:42 | 001,383,226 | ---- | C] () -- C:\Users\Kaan\Desktop\Lebenslauf aktuell.pdf [2011.06.23 14:30:39 | 000,000,034 | ---- | C] () -- C:\Windows\SysWow64\BD2030.DAT [2011.04.15 15:49:21 | 000,000,432 | ---- | C] () -- C:\Windows\BRWMARK.INI [2011.04.15 15:49:21 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI [2011.04.14 01:06:07 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat [2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT [2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat [2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat [2009.01.05 14:44:10 | 000,053,248 | ---- | C] () -- C:\Windows\bdoscandel.exe [2009.01.05 14:44:10 | 000,000,483 | ---- | C] () -- C:\Windows\bdoscandellang.ini ========== LOP Check ========== [2011.05.18 17:27:19 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\DVDVideoSoftIEHelpers [2011.08.08 18:02:47 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\HTC [2011.08.08 18:03:37 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1 [2011.07.21 14:21:03 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\Leadertech [2011.04.15 16:16:03 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\OpenOffice.org [2011.09.22 10:05:14 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\QuickScan [2011.08.11 02:24:39 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\Swiss Academic Software [2011.09.06 22:07:56 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2011.08.08 17:59:26 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\Adobe [2011.04.15 16:35:08 | 000,000,000 | R--D | M] -- C:\Users\Kaan\AppData\Roaming\Brother [2011.05.18 17:27:19 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\DVDVideoSoftIEHelpers [2011.08.08 18:02:47 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\HTC [2011.08.08 18:03:37 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1 [2011.04.14 00:43:53 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\Identities [2011.04.15 15:46:43 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\InstallShield [2011.07.21 14:21:03 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\Leadertech [2011.07.21 14:18:32 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\Logishrd [2011.07.21 14:21:56 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\Logitech [2011.04.14 02:24:44 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\Macromedia [2011.05.08 22:41:38 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\Malwarebytes [2010.11.21 09:00:36 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\Media Center Programs [2011.07.21 14:21:02 | 000,000,000 | --SD | M] -- C:\Users\Kaan\AppData\Roaming\Microsoft [2011.04.14 02:15:36 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\Mozilla [2011.04.15 16:16:03 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\OpenOffice.org [2011.09.22 10:05:14 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\QuickScan [2011.09.01 23:48:20 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\Skype [2011.09.22 01:01:25 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\SUPERAntiSpyware.com [2011.08.11 02:24:39 | 000,000,000 | ---D | M] -- C:\Users\Kaan\AppData\Roaming\Swiss Academic Software < %APPDATA%\*.exe /s > [2011.07.21 14:21:02 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Kaan\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS > [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys < MD5 for: ATAPI.SYS > [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys < MD5 for: CNGAUDIT.DLL > [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll [2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll [2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll < MD5 for: IASTORV.SYS > [2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys [2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys [2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys [2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys [2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys [2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys < MD5 for: NETLOGON.DLL > [2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll [2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll [2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll [2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll < MD5 for: NVSTOR.SYS > [2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys [2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys [2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys [2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys [2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys [2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys < MD5 for: SCECLI.DLL > [2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll [2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll [2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll [2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll < MD5 for: USER32.DLL > [2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll [2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll [2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll [2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll < MD5 for: USERINIT.EXE > [2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe [2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe [2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe [2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe [2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe < MD5 for: WS2IFSL.SYS > [2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys [2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < End of report > Danke nochmals. |
22.09.2011, 21:02 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Searchcompletion.com hat mein Google übernommen Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0C DB 95 58 B4 78 CC 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - prefs.js..browser.startup.homepage: "mydealz.de" FF - prefs.js..keyword.URL: "http://www.google.com/search?q=" :Commands [emptytemp] [resethosts] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.
__________________ --> Searchcompletion.com hat mein Google übernommen |
22.09.2011, 21:16 | #7 |
| Searchcompletion.com hat mein Google übernommen So, bitte schön. Das ist der Log: All processes killed ========== OTL ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Prefs.js: "mydealz.de" removed from browser.startup.homepage Prefs.js: "hxxp://www.google.com/search?q=" removed from keyword.URL ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Kaan ->Temp folder emptied: 716908 bytes ->Temporary Internet Files folder emptied: 112009396 bytes ->Java cache emptied: 146237167 bytes ->FireFox cache emptied: 256471302 bytes ->Google Chrome cache emptied: 361970765 bytes ->Flash cache emptied: 44236 bytes User: Public User: Ümran ->Temp folder emptied: 32799 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->FireFox cache emptied: 45793071 bytes ->Flash cache emptied: 611 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 90870107 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50568 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 967,00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.29.1 log created on 09222011_220805 Files\Folders moved on Reboot... C:\Users\Kaan\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Windows\temp\_avast_\Webshlock.txt not found! Registry entries deleted on Reboot... |
22.09.2011, 21:23 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Searchcompletion.com hat mein Google übernommen Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html Das Tool so einstellen wie unten im Bild angegeben - also beide Haken setzen, auf Start scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen: Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop. Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern ) Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen!
__________________ Logfiles bitte immer in CODE-Tags posten |
22.09.2011, 21:40 | #9 |
| Searchcompletion.com hat mein Google übernommen Ich glaube, da ist nichts als Bedrohung erkannt worden. 2011/09/22 22:35:17.0007 2424 TDSS rootkit removing tool 2.5.23.0 Sep 20 2011 08:53:10 2011/09/22 22:35:17.0022 2424 ================================================================================ 2011/09/22 22:35:17.0022 2424 SystemInfo: 2011/09/22 22:35:17.0022 2424 2011/09/22 22:35:17.0022 2424 OS Version: 6.1.7601 ServicePack: 1.0 2011/09/22 22:35:17.0022 2424 Product type: Workstation 2011/09/22 22:35:17.0022 2424 ComputerName: KAAN-PC 2011/09/22 22:35:17.0022 2424 UserName: Kaan 2011/09/22 22:35:17.0022 2424 Windows directory: C:\Windows 2011/09/22 22:35:17.0022 2424 System windows directory: C:\Windows 2011/09/22 22:35:17.0022 2424 Running under WOW64 2011/09/22 22:35:17.0022 2424 Processor architecture: Intel x64 2011/09/22 22:35:17.0022 2424 Number of processors: 2 2011/09/22 22:35:17.0022 2424 Page size: 0x1000 2011/09/22 22:35:17.0022 2424 Boot type: Normal boot 2011/09/22 22:35:17.0022 2424 ================================================================================ 2011/09/22 22:35:18.0161 2424 Initialize success 2011/09/22 22:35:23.0824 4972 ================================================================================ 2011/09/22 22:35:23.0824 4972 Scan started 2011/09/22 22:35:23.0824 4972 Mode: Manual; 2011/09/22 22:35:23.0824 4972 ================================================================================ 2011/09/22 22:35:24.0947 4972 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys 2011/09/22 22:35:25.0072 4972 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys 2011/09/22 22:35:25.0197 4972 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys 2011/09/22 22:35:25.0337 4972 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys 2011/09/22 22:35:25.0477 4972 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys 2011/09/22 22:35:25.0524 4972 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys 2011/09/22 22:35:25.0665 4972 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys 2011/09/22 22:35:25.0727 4972 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys 2011/09/22 22:35:25.0836 4972 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys 2011/09/22 22:35:25.0945 4972 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys 2011/09/22 22:35:26.0070 4972 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys 2011/09/22 22:35:26.0179 4972 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 2011/09/22 22:35:26.0304 4972 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys 2011/09/22 22:35:26.0429 4972 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys 2011/09/22 22:35:26.0538 4972 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys 2011/09/22 22:35:26.0679 4972 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys 2011/09/22 22:35:26.0819 4972 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys 2011/09/22 22:35:26.0850 4972 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys 2011/09/22 22:35:27.0271 4972 aswFsBlk (5a68b880c16ad5a6aa20b49a47ffff24) C:\Windows\system32\drivers\aswFsBlk.sys 2011/09/22 22:35:27.0427 4972 aswFW (7f39d983a635f998b9b77595c0e26de6) C:\Windows\system32\drivers\aswFW.sys 2011/09/22 22:35:27.0552 4972 aswMonFlt (230613be2d3da8053879be5ed2848f2d) C:\Windows\system32\drivers\aswMonFlt.sys 2011/09/22 22:35:27.0693 4972 aswNdis (518b8d447a1975ab46da093a2e743256) C:\Windows\system32\DRIVERS\aswNdis.sys 2011/09/22 22:35:27.0817 4972 aswNdis2 (3ee92a414e103d0018f42494d9d0772d) C:\Windows\system32\drivers\aswNdis2.sys 2011/09/22 22:35:27.0942 4972 aswRdr (0dc1996ae4178d7d14744ef6b3082313) C:\Windows\system32\drivers\aswRdr.sys 2011/09/22 22:35:28.0129 4972 aswSnx (b6ff911c23775cdfdd49612d92637af4) C:\Windows\system32\drivers\aswSnx.sys 2011/09/22 22:35:28.0207 4972 aswSP (5a590d8516376aed1829fc07d3bdaa4b) C:\Windows\system32\drivers\aswSP.sys 2011/09/22 22:35:28.0379 4972 aswTdi (3239c0082fb0c1c4ee323730b85690a5) C:\Windows\system32\drivers\aswTdi.sys 2011/09/22 22:35:28.0473 4972 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/09/22 22:35:28.0597 4972 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys 2011/09/22 22:35:28.0863 4972 atikmdag (52bd95caa9cae8977fe043e9ad6d2d0e) C:\Windows\system32\DRIVERS\atikmdag.sys 2011/09/22 22:35:29.0143 4972 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys 2011/09/22 22:35:29.0284 4972 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 2011/09/22 22:35:29.0487 4972 BCM43XX (810be94a9e42309b3f74217ac28bc6ac) C:\Windows\system32\DRIVERS\bcmwl664.sys 2011/09/22 22:35:29.0658 4972 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 2011/09/22 22:35:29.0814 4972 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 2011/09/22 22:35:29.0955 4972 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys 2011/09/22 22:35:30.0079 4972 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys 2011/09/22 22:35:30.0157 4972 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys 2011/09/22 22:35:30.0235 4972 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 2011/09/22 22:35:30.0267 4972 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 2011/09/22 22:35:30.0376 4972 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 2011/09/22 22:35:30.0438 4972 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 2011/09/22 22:35:30.0547 4972 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\drivers\BthEnum.sys 2011/09/22 22:35:30.0610 4972 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys 2011/09/22 22:35:30.0719 4972 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys 2011/09/22 22:35:30.0844 4972 BTHPORT (64c198198501f7560ee41d8d1efa7952) C:\Windows\System32\Drivers\BTHport.sys 2011/09/22 22:35:30.0984 4972 BTHUSB (f188b7394d81010767b6df3178519a37) C:\Windows\System32\Drivers\BTHUSB.sys 2011/09/22 22:35:31.0109 4972 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 2011/09/22 22:35:31.0234 4972 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys 2011/09/22 22:35:31.0374 4972 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys 2011/09/22 22:35:31.0499 4972 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 2011/09/22 22:35:31.0686 4972 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 2011/09/22 22:35:31.0717 4972 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys 2011/09/22 22:35:31.0827 4972 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys 2011/09/22 22:35:31.0858 4972 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 2011/09/22 22:35:31.0967 4972 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys 2011/09/22 22:35:32.0061 4972 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys 2011/09/22 22:35:32.0201 4972 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys 2011/09/22 22:35:32.0575 4972 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys 2011/09/22 22:35:32.0653 4972 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 2011/09/22 22:35:32.0763 4972 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys 2011/09/22 22:35:32.0887 4972 dmvsc (5db085a8a6600be6401f2b24eecb5415) C:\Windows\system32\drivers\dmvsc.sys 2011/09/22 22:35:33.0043 4972 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 2011/09/22 22:35:33.0121 4972 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys 2011/09/22 22:35:33.0293 4972 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys 2011/09/22 22:35:33.0496 4972 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys 2011/09/22 22:35:33.0543 4972 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys 2011/09/22 22:35:33.0605 4972 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 2011/09/22 22:35:33.0636 4972 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 2011/09/22 22:35:33.0730 4972 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys 2011/09/22 22:35:33.0792 4972 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 2011/09/22 22:35:33.0823 4972 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 2011/09/22 22:35:33.0886 4972 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys 2011/09/22 22:35:33.0979 4972 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys 2011/09/22 22:35:34.0089 4972 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 2011/09/22 22:35:34.0167 4972 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 2011/09/22 22:35:34.0260 4972 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys 2011/09/22 22:35:34.0385 4972 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys 2011/09/22 22:35:34.0572 4972 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 2011/09/22 22:35:34.0728 4972 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys 2011/09/22 22:35:34.0869 4972 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/09/22 22:35:34.0915 4972 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys 2011/09/22 22:35:34.0931 4972 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys 2011/09/22 22:35:34.0947 4972 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys 2011/09/22 22:35:35.0009 4972 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys 2011/09/22 22:35:35.0071 4972 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys 2011/09/22 22:35:35.0212 4972 HTCAND64 (f47cec45fb85791d4ab237563ad0fa8f) C:\Windows\system32\Drivers\ANDROIDUSB.sys 2011/09/22 22:35:35.0368 4972 htcnprot (b8b1b284362e1d8135112573395d5da5) C:\Windows\system32\DRIVERS\htcnprot.sys 2011/09/22 22:35:35.0461 4972 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys 2011/09/22 22:35:35.0633 4972 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys 2011/09/22 22:35:35.0773 4972 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/09/22 22:35:35.0914 4972 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys 2011/09/22 22:35:36.0023 4972 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys 2011/09/22 22:35:36.0179 4972 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys 2011/09/22 22:35:36.0288 4972 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\drivers\intelppm.sys 2011/09/22 22:35:36.0351 4972 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/09/22 22:35:36.0382 4972 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys 2011/09/22 22:35:36.0413 4972 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 2011/09/22 22:35:36.0538 4972 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 2011/09/22 22:35:36.0678 4972 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys 2011/09/22 22:35:36.0819 4972 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys 2011/09/22 22:35:36.0959 4972 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/09/22 22:35:37.0115 4972 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/09/22 22:35:37.0271 4972 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys 2011/09/22 22:35:37.0411 4972 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys 2011/09/22 22:35:37.0661 4972 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 2011/09/22 22:35:37.0848 4972 LHidFilt (1074c77a47835e03c15bf92452f9a750) C:\Windows\system32\DRIVERS\LHidFilt.Sys 2011/09/22 22:35:38.0004 4972 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 2011/09/22 22:35:38.0191 4972 LMouFilt (96999c364c649e2866a268f7420a304a) C:\Windows\system32\DRIVERS\LMouFilt.Sys 2011/09/22 22:35:38.0316 4972 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys 2011/09/22 22:35:38.0472 4972 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys 2011/09/22 22:35:38.0628 4972 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys 2011/09/22 22:35:38.0800 4972 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys 2011/09/22 22:35:38.0940 4972 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 2011/09/22 22:35:39.0003 4972 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys 2011/09/22 22:35:39.0081 4972 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys 2011/09/22 22:35:39.0205 4972 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 2011/09/22 22:35:39.0315 4972 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 2011/09/22 22:35:39.0471 4972 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 2011/09/22 22:35:39.0564 4972 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 2011/09/22 22:35:39.0642 4972 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys 2011/09/22 22:35:39.0689 4972 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys 2011/09/22 22:35:39.0720 4972 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 2011/09/22 22:35:39.0814 4972 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys 2011/09/22 22:35:39.0892 4972 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/09/22 22:35:39.0954 4972 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/09/22 22:35:40.0001 4972 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/09/22 22:35:40.0048 4972 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys 2011/09/22 22:35:40.0079 4972 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys 2011/09/22 22:35:40.0110 4972 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 2011/09/22 22:35:40.0141 4972 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 2011/09/22 22:35:40.0173 4972 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys 2011/09/22 22:35:40.0344 4972 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 2011/09/22 22:35:40.0516 4972 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/09/22 22:35:40.0703 4972 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 2011/09/22 22:35:40.0875 4972 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys 2011/09/22 22:35:41.0077 4972 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/09/22 22:35:41.0249 4972 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 2011/09/22 22:35:41.0421 4972 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys 2011/09/22 22:35:41.0577 4972 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 2011/09/22 22:35:41.0811 4972 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 2011/09/22 22:35:42.0013 4972 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys 2011/09/22 22:35:42.0247 4972 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 2011/09/22 22:35:42.0419 4972 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/09/22 22:35:42.0622 4972 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/09/22 22:35:42.0793 4972 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/09/22 22:35:42.0965 4972 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys 2011/09/22 22:35:43.0168 4972 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 2011/09/22 22:35:43.0371 4972 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys 2011/09/22 22:35:43.0605 4972 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys 2011/09/22 22:35:43.0792 4972 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 2011/09/22 22:35:43.0963 4972 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 2011/09/22 22:35:44.0182 4972 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys 2011/09/22 22:35:44.0369 4972 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 2011/09/22 22:35:44.0525 4972 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys 2011/09/22 22:35:44.0681 4972 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys 2011/09/22 22:35:44.0884 4972 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys 2011/09/22 22:35:45.0055 4972 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys 2011/09/22 22:35:45.0243 4972 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys 2011/09/22 22:35:45.0414 4972 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys 2011/09/22 22:35:45.0617 4972 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys 2011/09/22 22:35:45.0820 4972 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys 2011/09/22 22:35:46.0007 4972 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys 2011/09/22 22:35:46.0194 4972 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 2011/09/22 22:35:46.0350 4972 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 2011/09/22 22:35:46.0600 4972 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys 2011/09/22 22:35:46.0771 4972 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys 2011/09/22 22:35:46.0959 4972 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys 2011/09/22 22:35:47.0146 4972 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys 2011/09/22 22:35:47.0317 4972 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys 2011/09/22 22:35:47.0489 4972 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 2011/09/22 22:35:47.0661 4972 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 2011/09/22 22:35:47.0817 4972 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 2011/09/22 22:35:47.0988 4972 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/09/22 22:35:48.0160 4972 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/09/22 22:35:48.0316 4972 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 2011/09/22 22:35:48.0503 4972 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys 2011/09/22 22:35:48.0643 4972 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 2011/09/22 22:35:48.0799 4972 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/09/22 22:35:48.0940 4972 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys 2011/09/22 22:35:49.0096 4972 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 2011/09/22 22:35:49.0267 4972 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 2011/09/22 22:35:49.0423 4972 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys 2011/09/22 22:35:49.0595 4972 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys 2011/09/22 22:35:49.0767 4972 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys 2011/09/22 22:35:49.0954 4972 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 2011/09/22 22:35:50.0125 4972 RTL8167 (16d4e350420baa7e63e16e3fc033e1f5) C:\Windows\system32\DRIVERS\Rt64win7.sys 2011/09/22 22:35:50.0297 4972 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys 2011/09/22 22:35:50.0422 4972 SASDIFSV (3289766038db2cb14d07dc84392138d5) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS 2011/09/22 22:35:50.0453 4972 SASKUTIL (58a38e75f3316a83c23df6173d41f2b5) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS 2011/09/22 22:35:50.0593 4972 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys 2011/09/22 22:35:50.0796 4972 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys 2011/09/22 22:35:50.0983 4972 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 2011/09/22 22:35:51.0155 4972 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys 2011/09/22 22:35:51.0342 4972 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys 2011/09/22 22:35:51.0514 4972 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys 2011/09/22 22:35:51.0717 4972 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys 2011/09/22 22:35:51.0873 4972 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys 2011/09/22 22:35:52.0029 4972 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys 2011/09/22 22:35:52.0185 4972 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys 2011/09/22 22:35:52.0356 4972 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys 2011/09/22 22:35:52.0528 4972 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys 2011/09/22 22:35:52.0699 4972 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 2011/09/22 22:35:52.0902 4972 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 2011/09/22 22:35:53.0105 4972 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys 2011/09/22 22:35:53.0277 4972 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys 2011/09/22 22:35:53.0448 4972 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys 2011/09/22 22:35:53.0682 4972 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys 2011/09/22 22:35:53.0869 4972 STHDA (4a9d087c9a97071b9d06db38567da906) C:\Windows\system32\DRIVERS\stwrt64.sys 2011/09/22 22:35:54.0057 4972 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys 2011/09/22 22:35:54.0244 4972 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys 2011/09/22 22:35:54.0400 4972 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 2011/09/22 22:35:54.0618 4972 SynTP (d268d2a0db2a2bbe963e688d0b039267) C:\Windows\system32\DRIVERS\SynTP.sys 2011/09/22 22:35:54.0852 4972 Tcpip (f0e98c00a09fdf791525829a1d14240f) C:\Windows\system32\drivers\tcpip.sys 2011/09/22 22:35:55.0086 4972 TCPIP6 (f0e98c00a09fdf791525829a1d14240f) C:\Windows\system32\DRIVERS\tcpip.sys 2011/09/22 22:35:55.0258 4972 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys 2011/09/22 22:35:55.0414 4972 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 2011/09/22 22:35:55.0570 4972 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 2011/09/22 22:35:55.0742 4972 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys 2011/09/22 22:35:55.0898 4972 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys 2011/09/22 22:35:56.0100 4972 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/09/22 22:35:56.0272 4972 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys 2011/09/22 22:35:56.0444 4972 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys 2011/09/22 22:35:56.0600 4972 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys 2011/09/22 22:35:56.0756 4972 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys 2011/09/22 22:35:56.0912 4972 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys 2011/09/22 22:35:57.0099 4972 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys 2011/09/22 22:35:57.0270 4972 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys 2011/09/22 22:35:57.0426 4972 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys 2011/09/22 22:35:57.0614 4972 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/09/22 22:35:57.0785 4972 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys 2011/09/22 22:35:57.0941 4972 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys 2011/09/22 22:35:58.0284 4972 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys 2011/09/22 22:35:58.0347 4972 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\DRIVERS\usbohci.sys 2011/09/22 22:35:58.0518 4972 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 2011/09/22 22:35:58.0690 4972 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys 2011/09/22 22:35:58.0830 4972 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/09/22 22:35:59.0018 4972 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys 2011/09/22 22:35:59.0205 4972 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys 2011/09/22 22:35:59.0392 4972 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys 2011/09/22 22:35:59.0548 4972 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/09/22 22:35:59.0720 4972 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 2011/09/22 22:35:59.0876 4972 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys 2011/09/22 22:36:00.0047 4972 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys 2011/09/22 22:36:00.0219 4972 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys 2011/09/22 22:36:00.0375 4972 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys 2011/09/22 22:36:00.0531 4972 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys 2011/09/22 22:36:00.0702 4972 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys 2011/09/22 22:36:00.0858 4972 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys 2011/09/22 22:36:01.0139 4972 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys 2011/09/22 22:36:01.0311 4972 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 2011/09/22 22:36:01.0467 4972 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 2011/09/22 22:36:01.0654 4972 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys 2011/09/22 22:36:01.0810 4972 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 2011/09/22 22:36:01.0841 4972 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 2011/09/22 22:36:02.0028 4972 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys 2011/09/22 22:36:02.0200 4972 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 2011/09/22 22:36:02.0418 4972 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 2011/09/22 22:36:02.0574 4972 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 2011/09/22 22:36:02.0808 4972 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys 2011/09/22 22:36:02.0980 4972 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys 2011/09/22 22:36:03.0183 4972 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 2011/09/22 22:36:03.0370 4972 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys 2011/09/22 22:36:03.0573 4972 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/09/22 22:36:03.0682 4972 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 2011/09/22 22:36:03.0698 4972 Boot (0x1200) (9870457a11d10cde51d3d6652d92e89c) \Device\Harddisk0\DR0\Partition0 2011/09/22 22:36:03.0729 4972 Boot (0x1200) (4b28668da013927ef61360ea2d657aa0) \Device\Harddisk0\DR0\Partition1 2011/09/22 22:36:03.0744 4972 ================================================================================ 2011/09/22 22:36:03.0744 4972 Scan finished 2011/09/22 22:36:03.0744 4972 ================================================================================ 2011/09/22 22:36:03.0744 4836 Detected object count: 0 2011/09/22 22:36:03.0744 4836 Actual detected object count: 0 In dem von dir verlinkten Thread steht, dass man danach nochmal Malwarebytes drüber laufen lassen sollte. Ist jetzt wohl aber nicht so wichtig bei mir!?! |
23.09.2011, 08:41 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Searchcompletion.com hat mein Google übernommen Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
__________________ Logfiles bitte immer in CODE-Tags posten |
23.09.2011, 09:50 | #11 |
| Searchcompletion.com hat mein Google übernommen Hallo, guten Morgen. Also, habe den ComboFix ausgeführt. Weder die Updates noch die Wiederherstellung wurden ausgeführt. Hier ist der Log Combofix Logfile: Code:
ATTFilter ComboFix 11-09-22.04 - Kaan 23.09.2011 10:39:16.1.2 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.3837.2558 [GMT 2:00] ausgeführt von:: c:\users\Kaan\Desktop\ComboFix.exe AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47} SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2011-08-23 bis 2011-09-23 )))))))))))))))))))))))))))))) . . 2011-09-23 08:43 . 2011-09-23 08:43 -------- d-----w- c:\users\Ümran\AppData\Local\temp 2011-09-23 08:43 . 2011-09-23 08:43 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-09-23 08:18 . 2011-09-23 08:18 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D984AE22-AB75-42DE-B7AA-8615625997B9}\offreg.dll 2011-09-23 08:18 . 2011-09-13 00:26 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D984AE22-AB75-42DE-B7AA-8615625997B9}\mpengine.dll 2011-09-22 20:08 . 2011-09-22 20:08 -------- d-----w- C:\_OTL 2011-09-22 12:20 . 2011-09-22 12:20 -------- d-----w- c:\program files (x86)\ESET 2011-09-21 23:01 . 2011-09-21 23:01 -------- d-----w- c:\users\Kaan\AppData\Roaming\SUPERAntiSpyware.com 2011-09-21 23:00 . 2011-09-21 23:01 -------- d-----w- c:\program files\SUPERAntiSpyware 2011-09-21 23:00 . 2011-09-21 23:00 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2011-09-21 22:28 . 2011-09-21 22:28 -------- d-----w- c:\windows\system32\appmgmt 2011-09-18 16:47 . 2011-09-18 16:47 -------- d-----w- c:\users\Kaan\AppData\Local\TVU Networks 2011-09-18 16:47 . 2011-09-18 16:47 -------- d-----w- c:\programdata\TVU Networks 2011-08-24 10:29 . 2011-07-09 05:26 2048 ----a-w- c:\windows\system32\tzres.dll 2011-08-24 10:29 . 2011-07-09 04:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-09-21 19:45 . 2011-08-10 00:28 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-09-06 20:45 . 2011-07-18 21:33 41184 ----a-w- c:\windows\avastSS.scr 2011-09-06 20:45 . 2011-07-18 21:33 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe 2011-09-06 20:45 . 2011-04-14 00:05 254400 ----a-w- c:\windows\system32\aswBoot.exe 2011-09-06 20:39 . 2011-07-18 21:34 140120 ----a-w- c:\windows\system32\drivers\aswFW.sys 2011-09-06 20:38 . 2011-07-18 21:33 601944 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2011-09-06 20:38 . 2011-07-18 21:34 301912 ----a-w- c:\windows\system32\drivers\aswSP.sys 2011-09-06 20:37 . 2011-07-18 21:33 258392 ----a-w- c:\windows\system32\drivers\aswNdis2.sys 2011-09-06 20:36 . 2011-07-18 21:33 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2011-09-06 20:36 . 2011-07-18 21:33 58200 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2011-09-06 20:36 . 2011-07-18 21:33 65368 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2011-09-06 20:36 . 2011-07-18 21:34 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-08-31 15:00 . 2011-05-08 20:41 25416 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-08-13 20:34 . 2011-06-05 17:18 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-08-04 14:43 . 2011-07-21 12:20 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys 2011-07-22 05:42 . 2011-08-11 19:26 2303488 ----a-w- c:\windows\system32\jscript9.dll 2011-07-22 05:36 . 2011-08-11 19:26 1389056 ----a-w- c:\windows\system32\wininet.dll 2011-07-22 05:32 . 2011-08-11 19:26 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2011-07-22 02:54 . 2011-08-11 19:26 1797632 ----a-w- c:\windows\SysWow64\jscript9.dll 2011-07-22 02:48 . 2011-08-11 19:26 1126912 ----a-w- c:\windows\SysWow64\wininet.dll 2011-07-22 02:44 . 2011-08-11 19:26 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb 2011-07-21 12:21 . 2011-07-21 12:21 53248 ----a-r- c:\users\Kaan\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2011-07-16 05:41 . 2011-08-11 08:31 362496 ----a-w- c:\windows\system32\wow64win.dll 2011-07-16 05:41 . 2011-08-11 08:31 243200 ----a-w- c:\windows\system32\wow64.dll 2011-07-16 05:41 . 2011-08-11 08:31 13312 ----a-w- c:\windows\system32\wow64cpu.dll 2011-07-16 05:39 . 2011-08-11 08:31 16384 ----a-w- c:\windows\system32\ntvdm64.dll 2011-07-16 05:37 . 2011-08-11 08:31 421888 ----a-w- c:\windows\system32\KernelBase.dll 2011-07-16 05:21 . 2011-08-11 08:31 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2011-07-16 05:21 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2011-07-16 04:29 . 2011-08-11 08:31 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2011-07-16 04:26 . 2011-08-11 08:31 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2011-07-16 04:25 . 2011-08-11 08:31 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2011-07-16 04:24 . 2011-08-11 08:31 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2011-07-16 04:24 . 2011-08-11 08:31 272384 ----a-w- c:\windows\SysWow64\KernelBase.dll 2011-07-16 04:15 . 2011-08-11 08:31 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 5120 ---ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll 2011-07-16 04:15 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll 2011-07-16 02:21 . 2011-08-11 08:31 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2011-07-16 02:21 . 2011-08-11 08:31 2048 ----a-w- c:\windows\SysWow64\user.exe 2011-07-16 02:17 . 2011-08-11 08:31 6144 ---ha-w- c:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2011-07-16 02:17 . 2011-08-11 08:31 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2011-07-16 02:17 . 2011-08-11 08:31 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2011-07-16 02:17 . 2011-08-11 08:31 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll 2011-07-09 02:46 . 2011-08-11 08:31 288768 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-07-04 11:12 . 2011-07-18 21:33 12368 ----a-w- c:\windows\system32\drivers\aswNdis.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-08-12 5471104] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "BrMfcWnd"="c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416] . c:\users\Kaan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . R2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2011-09-06 127192] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x] R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x] R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [x] S0 aswNdis2;avast! Firewall Core Firewall Service; [x] S1 aswFW;avast! TDI Firewall driver; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe [2009-03-03 89600] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2011-03-31 80896] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] . . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-09-06 20:45 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-17 487424] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-06-23 1744152] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Free YouTube to MP3 Converter - c:\users\Kaan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Kaan\AppData\Roaming\Mozilla\Firefox\Profiles\1g3uy9i8.default\ FF - prefs.js: browser.startup.homepage - FF - prefs.js: network.proxy.type - 0 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-ARIS Express 2.3 - c:\windows\system32\javaws.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{8E5E2654-AD2D-48BF-AC2D-D17F00898D06}"=hex:51,66,7a,6c,4c,1d,38,12,3a,25,4d, 8a,1f,e3,d1,0d,d3,3b,92,3f,05,d7,c9,12 "{53707962-6F74-2D53-2644-206D7942484F}"=hex:51,66,7a,6c,4c,1d,38,12,0c,7a,63, 57,46,21,3d,68,59,52,63,2d,7c,1c,0c,5b "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23, 94,30,02,d1,0f,f1,da,12,24,73,56,27,d2 "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:d4,c0,12,53,ba,57,cc,01 . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8f,93,ef,7b,4a,41,6a,4a,8d,dd,c5,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8f,93,ef,7b,4a,41,6a,4a,8d,dd,c5,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2011-09-23 10:45:52 ComboFix-quarantined-files.txt 2011-09-23 08:45 . Vor Suchlauf: 9 Verzeichnis(se), 47.132.712.960 Bytes frei Nach Suchlauf: 13 Verzeichnis(se), 46.844.260.352 Bytes frei . - - End Of File - - 96313F5FFC00166B215CCD5A784EA44A |
23.09.2011, 11:11 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Searchcompletion.com hat mein Google übernommen Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
23.09.2011, 11:25 | #13 |
| Searchcompletion.com hat mein Google übernommen Hallo nochmal, Avast ist jetzt ausgeführt, jedoch wurde ich nicht nach aktuellen Virendefinitionen gefragt. Ein download solcher hat m.E. auch nicht stattgefunden. Hier die Log: aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software Run date: 2011-09-23 12:16:06 ----------------------------- 12:16:06.349 OS Version: Windows x64 6.1.7601 Service Pack 1 12:16:06.349 Number of processors: 2 586 0x603 12:16:06.349 ComputerName: KAAN-PC UserName: Kaan 12:16:07.425 Initialize success 12:16:07.799 AVAST engine defs: 11092201 12:16:20.279 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 12:16:20.295 Disk 0 Vendor: WDC_WD3200BEVT-60A23T0 02.01A02 Size: 305245MB BusType: 11 12:16:22.339 Disk 0 MBR read successfully 12:16:22.339 Disk 0 MBR scan 12:16:22.354 Disk 0 Windows 7 default MBR code 12:16:22.354 Service scanning 12:16:24.195 Modules scanning 12:16:24.195 Disk 0 trace - called modules: 12:16:24.242 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys 12:16:24.242 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c95060] 12:16:24.257 3 CLASSPNP.SYS[fffff8800160143f] -> nt!IofCallDriver -> [0xfffffa8004758520] 12:16:24.257 5 ACPI.sys[fffff88000f3d7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004754680] 12:16:25.022 AVAST engine scan C:\Windows 12:16:27.034 AVAST engine scan C:\Windows\system32 12:17:37.063 AVAST engine scan C:\Windows\system32\drivers 12:17:44.613 AVAST engine scan C:\Users\Kaan 12:19:43.033 AVAST engine scan C:\ProgramData 12:20:48.319 Scan finished successfully 12:21:19.254 Disk 0 MBR has been saved successfully to "C:\Users\Kaan\Desktop\MBR.dat" 12:21:19.254 The log file has been saved successfully to "C:\Users\Kaan\Desktop\aswMBR.txt" |
23.09.2011, 11:39 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Searchcompletion.com hat mein Google übernommen Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
23.09.2011, 13:51 | #15 |
| Searchcompletion.com hat mein Google übernommen Hey, also Malwarebytes war wohl unauffällig, superantispyware hat 528 Bedrohungen festgestellt. Würdest du mir bitte nochmal erklären, Wie ich mit denen verfahren soll bevor ich eset ausführe? SUPERAntiSpyware Scan Log hxxp://www.superantispyware.com Generated 09/23/2011 at 02:47 PM Application Version : 5.0.1118 Core Rules Database Version : 7719 Trace Rules Database Version: 5531 Scan type : Complete Scan Total Scan Time : 01:07:05 Operating System Information Windows 7 Professional 64-bit, Service Pack 1 (Build 6.01.7601) UAC On - Limited User Memory items scanned : 545 Memory threats detected : 0 Registry items scanned : 70212 Registry threats detected : 0 File items scanned : 170003 File threats detected : 528 Adware.Tracking Cookie C:\Users\Kaan\AppData\Roaming\Microsoft\Windows\Cookies\kaan-pc$@2o7[1].txt C:\Users\Kaan\AppData\Roaming\Microsoft\Windows\Cookies\kaan@adtech[1].txt C:\Users\Kaan\AppData\Roaming\Microsoft\Windows\Cookies\kaan@questionmarket[2].txt C:\Users\Kaan\AppData\Roaming\Microsoft\Windows\Cookies\UA9F2YNT.txt C:\Users\Kaan\AppData\Roaming\Microsoft\Windows\Cookies\XYFCV374.txt C:\Users\Kaan\AppData\Roaming\Microsoft\Windows\Cookies\5B0BTLCK.txt C:\Users\Kaan\AppData\Roaming\Microsoft\Windows\Cookies\M4D6O53M.txt de.sitestat.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .serving-sys.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .atdmt.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] tracking.tchibo.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tracking.quisma.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] tracking.quisma.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] tracking.quisma.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] track.effiliation.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .specificclick.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .bs.serving-sys.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tracking.mindshare.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .emeraldinsight.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .emeraldinsight.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .emeraldinsight.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.yieldmanager.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adxpose.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .smartadserver.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .smartadserver.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.dyntracker.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .imrworldwide.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .imrworldwide.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .premiumtv.122.2o7.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .interclick.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .interclick.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .im.banner.t-online.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .olympiaverlag.122.2o7.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] track.adform.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] eas.apm.emediate.eu [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.etracker.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.googleadservices.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.etracker.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .opodo.122.2o7.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.zanox-affiliate.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .yieldmanager.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .collective-media.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .advertising.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ltur.112.2o7.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.etracker.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .media6degrees.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .socialmediaexaminer.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .socialmediaexaminer.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .www.socialmediaexaminer.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] wstat.wibiya.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] marketingsocialmedia.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] marketingsocialmedia.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] marketingsocialmedia.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.socialmediaexaminer.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.etracker.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tracking.quisma.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] finden.nationallizenzen.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] finden.nationallizenzen.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] finden.nationallizenzen.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .socialmediaexaminer.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ad.adnet.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ad.adnet.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .stepstone.112.2o7.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .rambler.ru [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .yadro.ru [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] banners.victor.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .content.yieldmanager.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.yieldmanager.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] banners.victor.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .banners.victor.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] counters.gigya.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tracking.quisma.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] tracking.quisma.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .2o7.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.adition.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] audit.median.hu [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] tracking.quisma.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .smartadserver.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .smartadserver.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .xiti.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .sonyeurope.112.2o7.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .serving-sys.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ads.quartermedia.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .insightexpressai.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .insightexpressai.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .insightexpressai.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] airfrance.bannerfactory.fr [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .collective-media.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adbrite.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adbrite.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adbrite.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .paypal.112.2o7.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] accounts.youtube.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .smartadserver.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adbrite.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adbrite.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .insightexpressai.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .doubleclick.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .atdmt.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .liveperson.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] server.iad.liveperson.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .liveperson.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .kontera.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] adx.chip.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] adx.chip.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] adx.chip.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] adx.chip.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] adx.chip.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] adx.chip.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] adx.chip.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] adx.chip.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] adx.chip.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] adx.chip.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] adx.chip.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] adx.chip.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] adx.chip.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .rambler.ru [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.yieldmanager.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tradedoubler.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.zanox.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .e-2dj6wjkownczclo.stats.esomniture.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .apmebf.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .mediaplex.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tracking.quisma.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .unitymedia.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .unitymedia.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tracking.quisma.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] media.gan-online.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .a.revenuemax.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ad.adnet.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .im.banner.t-online.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .fastclick.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] track.effiliation.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] track.effiliation.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] track.effiliation.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] track.effiliation.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.googleadservices.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tracking.quisma.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] eas.apm.emediate.eu [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .euros4click.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad1.adfarm1.adition.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .smartadserver.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .smartadserver.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .smartadserver.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .media6degrees.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tracking.quisma.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.etracker.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.etracker.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .bs.serving-sys.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ads.quartermedia.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .questionmarket.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .questionmarket.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad3.adfarm1.adition.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.adserver01.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .traffictrack.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .serving-sys.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .serving-sys.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .serving-sys.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ads.quartermedia.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.zanox-affiliate.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .zanox-affiliate.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .zanox.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .insightexpressai.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .insightexpressai.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .insightexpressai.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .insightexpressai.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ads.quartermedia.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ads.quartermedia.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .e-2dj6aekycgd5ihq.stats.esomniture.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tradedoubler.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tradedoubler.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tradedoubler.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .e-2dj6wnmiuhcpsho.stats.esomniture.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] track.adform.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adform.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] eas.apm.emediate.eu [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .histats.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .histats.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] zbox.zanox.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.zanox.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] statse.webtrendslive.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] server.lon.liveperson.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .liveperson.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] partners.webmasterplan.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .socialmediaexaminer.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .collective-media.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .collective-media.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .collective-media.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .collective-media.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .collective-media.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .collective-media.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .collective-media.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .collective-media.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adfarm1.adition.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adfarm1.adition.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adfarm1.adition.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad4.adfarm1.adition.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .socialmediaexaminer.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adfarm1.adition.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .im.banner.t-online.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .clickfuse.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adfarm1.adition.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad2.adfarm1.adition.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adfarm1.adition.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .media6degrees.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .media6degrees.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .socialmediaexaminer.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .socialmediaexaminer.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .socialmediaexaminer.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.socialmediaexaminer.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.socialmediaexaminer.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] accounts.google.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ww251.smartadserver.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.yieldmanager.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.yieldmanager.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .fastclick.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .www.burstnet.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tribalfusion.com [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .collective-media.net [ C:\USERS\KAAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] secure-uk.imrworldwide.com [ C:\USERS\KAAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\UASWC6RV ] C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@MEDIAPLEX[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@AD2.ADFARM1.ADITION[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@ADFARM1.ADITION[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@AD.AD-SRV[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@WWW.ROBERT-HALF-MEDIA[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@TRADEDOUBLER[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@WEBMASTERPLAN[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@APMEBF[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@BS.SERVING-SYS[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@TRACK.EFFILIATION[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@TRACK.EFFILIATION[3].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@WWW.USENEXT[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@ADX.CHIP[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@MICROSOFTINTERNETEXPLORER.112.2O7[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@2O7[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@AD.YIELDMANAGER[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@AD.ZANOX[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@AD1.ADFARM1.ADITION[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@AD3.ADFARM1.ADITION[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@ADFORM[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@ATDMT[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@CONTENT.YIELDMANAGER[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@EAS.APM.EMEDIATE[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@KASPERSKY.122.2O7[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@MM.CHITIKA[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@QUESTIONMARKET[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@SEVENONEINTERMEDIA.112.2O7[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@TRACK.ADFORM[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@TRAFFICTRACK[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@YADRO[2].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@ZANOX-AFFILIATE[1].TXT C:\USERS\KAAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\KAAN@ZANOX[1].TXT .2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .msnportal.112.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .sevenoneintermedia.112.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .opodo.122.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .xiti.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.mediamarkt.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .liveperson.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .imrworldwide.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .imrworldwide.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] in.getclicky.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .smartadserver.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .smartadserver.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .smartadserver.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .rambler.ru [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .tracking.quisma.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] audit.median.hu [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .ncp.imrworldwide.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .paypal.112.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .guj.122.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] fr.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] fr.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .dealtime.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] tracking.tchibo.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .deutschepostag.112.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .olympiaverlag.122.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] medianac.nacamar.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .conrad.122.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .ltur.112.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .surveymonkey.122.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .moviepilot.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .moviepilot.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .stepstone.112.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .multimedia.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .multimedia.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .jobscanner.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .jobscanner.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] int.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] int.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .e-2dj6wnloupajago.stats.esomniture.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .liveperson.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .estat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .getclicky.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .static.getclicky.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .cmp.112.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .mediamarkt.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .centaurpublications.122.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .trackalyzer.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .gmeurope.112.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] stat.aldi.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .siemens.112.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .philips.112.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] tracking.mobile.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .partnersearchmetrics.sbx1.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .e-2dj6aekiogazmko.stats.esomniture.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] tracker.softgarden.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .yadro.ru [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .112.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] rts.pgmediaserve.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] rts.pgmediaserve.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] rts.pgmediaserve.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .de.partypoker.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] tracking.sim-technik.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .tracking.quisma.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .webmasterplan.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .premiumtv.122.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] stats.o2more.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] tracking.klicktel.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] tracking.klicktel.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .dealtime.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .dealtime.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] stat.dealtime.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.dealtime.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .autoscout24.112.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] stats.bmw.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] stats.bmw.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .socialmediaakademie.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .socialmediaakademie.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] accounts.youtube.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .social-media-seminare.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .social-media-seminare.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .sportdiscount.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .sportdiscount.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .sportdiscount.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .sportdiscount.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .sportdiscount.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .sportdiscount.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .sportdiscount.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .sportdiscount.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .sportdiscount.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .online-marketing-insights.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .media-treff.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .media-treff.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .generaltracking.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .tracking.quisma.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .chilimedia.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .chilimedia.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .adlegend.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .adlegend.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .wilson.122.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .bizrate.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .bizrate.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .bizrate.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .bizrate.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .bizrate.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.bizrate.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .bizrate.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .bizrate.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .bizrate.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .bizrate.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .mediaforge.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .mediaforge.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] ad.zanox.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .hansenet.122.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .112.2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .find.keywordblocks.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .clickaider.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .smartadserver.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] accounts.google.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .twittercounter.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .twittercounter.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .twittercounter.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .twittercounter.com [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .online-marketing-insights.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .online-marketing-insights.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .online-marketing-insights.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .online-marketing-insights.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.trafficmaxx.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] www.etracker.de [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] sales.liveperson.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] .liveperson.net [ C:\USERS\KAAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1G3UY9I8.DEFAULT\COOKIES.SQLITE ] |
Themen zu Searchcompletion.com hat mein Google übernommen |
.com, anhang, autostart, avast, browser, design, diplomarbeit, einfach, firefox, gefahr, google, hijack, laufen, links, logfiles, nervige, problem, scan, scanner, schnelle, schnelle hilfe, spybot, stress, superantispyware, update |