Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Security Shield - Virus eingefangen

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 10.07.2012, 22:06   #16
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 11.07.2012, 21:21   #17
PuritySH
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



Hallo,

hier die Datei:

Code:
ATTFilter
# AdwCleaner v1.701 - Logfile created 07/11/2012 at 22:20:08
# Updated 02/07/2012 by Xplode
# Operating system : Windows 7 Home Premium  (64 bits)
# User : Euronics - EURONICS-VAIO
# Running from : C:\Users\Euronics\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Users\Euronics\AppData\Local\Conduit
Folder Found : C:\Users\Euronics\AppData\LocalLow\Conduit
Folder Found : C:\Users\Euronics\AppData\Roaming\Complitly
Folder Found : C:\Users\Euronics\AppData\Roaming\pdfforge
Folder Found : C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\ConduitCommon
Folder Found : C:\Program Files (x86)\Complitly
Folder Found : C:\Program Files (x86)\Conduit

***** [Registry] *****
[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT1060933
Key Found : HKCU\Software\Ask&Record
Key Found : HKCU\Software\Complitly
Key Found : HKCU\Software\Conduit
Key Found : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO
Key Found : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dlfienamagdnkekbbbocojppncdambda
Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
[x64] Key Found : HKCU\Software\Ask&Record
[x64] Key Found : HKCU\Software\Complitly
[x64] Key Found : HKCU\Software\Conduit
[x64] Key Found : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO
[x64] Key Found : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1
[x64] Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7600.16385

[OK] Registry is clean.

-\\ Mozilla Firefox v13.0.1 (de)

Profile name : default 
File : C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\prefs.js

Found : user_pref("CT1060933..clientLogIsEnabled", false);
Found : user_pref("CT1060933..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT1060933..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT1060933.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Found : user_pref("CT1060933.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT1060933.BrowserCompStateIsOpen_129633202291172081", true);
Found : user_pref("CT1060933.BrowserCompStateIsOpen_129652058719725628", true);
Found : user_pref("CT1060933.BrowserCompStateIsOpen_129681785283868963", true);
Found : user_pref("CT1060933.BrowserCompStateIsOpen_129686665230467549", true);
Found : user_pref("CT1060933.CTID", "CT1060933");
Found : user_pref("CT1060933.CurrentServerDate", "10-7-2012");
Found : user_pref("CT1060933.DSInstall", false);
Found : user_pref("CT1060933.DialogsAlignMode", "LTR");
Found : user_pref("CT1060933.DialogsGetterLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Found : user_pref("CT1060933.DownloadReferralCookieData", "");
Found : user_pref("CT1060933.EnableClickToSearchBox", false);
Found : user_pref("CT1060933.EnableSearchHistory", false);
Found : user_pref("CT1060933.EnableSearchSuggest", false);
Found : user_pref("CT1060933.FirstServerDate", "10-11-2011");
Found : user_pref("CT1060933.FirstTime", true);
Found : user_pref("CT1060933.FirstTimeFF3", true);
Found : user_pref("CT1060933.FixPageNotFoundErrors", false);
Found : user_pref("CT1060933.GroupingServerCheckInterval", 1440);
Found : user_pref("CT1060933.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT1060933.HPInstall", false);
Found : user_pref("CT1060933.HasUserGlobalKeys", true);
Found : user_pref("CT1060933.HomePageProtectorEnabled", false);
Found : user_pref("CT1060933.HomepageBeforeUnload", "hxxp://www.google.de/");
Found : user_pref("CT1060933.Initialize", true);
Found : user_pref("CT1060933.InitializeCommonPrefs", true);
Found : user_pref("CT1060933.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT1060933.InstallationId", "ConduitStubGeneric");
Found : user_pref("CT1060933.InstallationType", "ConduitStubIntegration");
Found : user_pref("CT1060933.InstalledDate", "Thu Nov 10 2011 19:06:42 GMT+0100");
Found : user_pref("CT1060933.InvalidateCache", false);
Found : user_pref("CT1060933.IsAlertDBUpdated", true);
Found : user_pref("CT1060933.IsGrouping", false);
Found : user_pref("CT1060933.IsInitSetupIni", true);
Found : user_pref("CT1060933.IsMulticommunity", false);
Found : user_pref("CT1060933.IsOpenThankYouPage", false);
Found : user_pref("CT1060933.IsOpenUninstallPage", true);
Found : user_pref("CT1060933.LanguagePackLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Found : user_pref("CT1060933.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT1060933.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT1060933.LastLogin_3.12.0.7", "Thu Apr 26 2012 19:22:06 GMT+0200");
Found : user_pref("CT1060933.LastLogin_3.12.2.3", "Wed May 30 2012 18:23:36 GMT+0200");
Found : user_pref("CT1060933.LastLogin_3.13.0.6", "Tue Jul 10 2012 19:46:22 GMT+0200");
Found : user_pref("CT1060933.LastLogin_3.8.0.8", "Thu Nov 10 2011 19:06:43 GMT+0100");
Found : user_pref("CT1060933.LatestVersion", "3.13.0.6");
Found : user_pref("CT1060933.Locale", "en-us");
Found : user_pref("CT1060933.MCDetectTooltipHeight", "83");
Found : user_pref("CT1060933.MCDetectTooltipShow", false);
Found : user_pref("CT1060933.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT1060933.MCDetectTooltipWidth", "295");
Found : user_pref("CT1060933.MyStuffEnabledAtInstallation", true);
Found : user_pref("CT1060933.OriginalFirstVersion", "3.8.0.8");
Found : user_pref("CT1060933.RadioIsPodcast", false);
Found : user_pref("CT1060933.RadioLastCheckTime", "Thu Nov 10 2011 19:06:44 GMT+0100");
Found : user_pref("CT1060933.RadioLastUpdateIPServer", "0");
Found : user_pref("CT1060933.RadioLastUpdateServer", "129326918102570000");
Found : user_pref("CT1060933.RadioMediaID", "21504191");
Found : user_pref("CT1060933.RadioMediaType", "Media Player");
Found : user_pref("CT1060933.RadioMenuSelectedID", "EBRadioMenu_CT106093321504191");
Found : user_pref("CT1060933.RadioShrinkedFromSetup", false);
Found : user_pref("CT1060933.RadioStationName", "KFOG");
Found : user_pref("CT1060933.RadioStationURL", "hxxp://live.cumulusstreaming.com/KFOG-FM");
Found : user_pref("CT1060933.SHRINK_TOOLBAR", 1);
Found : user_pref("CT1060933.SearchBackToDefaultEngine", false);
Found : user_pref("CT1060933.SearchCaption", "Freecorder Customized Web Search");
Found : user_pref("CT1060933.SearchEngineBeforeUnload", "ICQ Search");
Found : user_pref("CT1060933.SearchFromAddressBarIsInit", true);
Found : user_pref("CT1060933.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT106[...]
Found : user_pref("CT1060933.SearchInNewTabEnabled", true);
Found : user_pref("CT1060933.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT1060933.SearchInNewTabLastCheckTime", "Tue Jul 10 2012 19:46:21 GMT+0200");
Found : user_pref("CT1060933.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT1060933.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]
Found : user_pref("CT1060933.SearchInNewTabUserEnabled", false);
Found : user_pref("CT1060933.SearchProtectorEnabled", false);
Found : user_pref("CT1060933.SearchProtectorToolbarDisabled", false);
Found : user_pref("CT1060933.SendProtectorDataViaLogin", true);
Found : user_pref("CT1060933.ServiceMapLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Found : user_pref("CT1060933.SettingsLastCheckTime", "Tue Jul 10 2012 19:46:21 GMT+0200");
Found : user_pref("CT1060933.SettingsLastUpdate", "1341409951");
Found : user_pref("CT1060933.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT1060933&SearchSource=13");
Found : user_pref("CT1060933.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT1060933.ThirdPartyComponentsLastCheck", "Thu Nov 10 2011 19:06:42 GMT+0100");
Found : user_pref("CT1060933.ThirdPartyComponentsLastUpdate", "1312887586");
Found : user_pref("CT1060933.ToolbarShrinkedFromSetup", false);
Found : user_pref("CT1060933.TrusteLinkUrl", "hxxp://trust.conduit.com/CT1060933");
Found : user_pref("CT1060933.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Found : user_pref("CT1060933.UserID", "UN04397635592770677");
Found : user_pref("CT1060933.ValidationData_Search", 0);
Found : user_pref("CT1060933.ValidationData_Toolbar", 2);
Found : user_pref("CT1060933.alertChannelId", "15651");
Found : user_pref("CT1060933.appApproved.129272674122038321", true);
Found : user_pref("CT1060933.approveUntrustedApps", false);
Found : user_pref("CT1060933.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Found : user_pref("CT1060933.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Found : user_pref("CT1060933.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Found : user_pref("CT1060933.backendstorage./9b+7e.:2z527", "2423");
Found : user_pref("CT1060933.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Found : user_pref("CT1060933.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Found : user_pref("CT1060933.backendstorage./9b+7e06cg5el8:", "6E6D6F726A706D736E6F");
Found : user_pref("CT1060933.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737578707673797475242F4B4947[...]
Found : user_pref("CT1060933.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Found : user_pref("CT1060933.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Found : user_pref("CT1060933.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Found : user_pref("CT1060933.backendstorage./9b+7e31;cj7fk;kg#ncep@mc+vkn", "247E61393F236B25737471712A212C6[...]
Found : user_pref("CT1060933.backendstorage./9b+7e31;cjc<=fbj#mm", "247E61393F236B257576737A2A212C6E414F444D[...]
Found : user_pref("CT1060933.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Found : user_pref("CT1060933.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Found : user_pref("CT1060933.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Found : user_pref("CT1060933.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Found : user_pref("CT1060933.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Found : user_pref("CT1060933.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Found : user_pref("CT1060933.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Found : user_pref("CT1060933.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Found : user_pref("CT1060933.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Found : user_pref("CT1060933.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Found : user_pref("CT1060933.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Found : user_pref("CT1060933.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Found : user_pref("CT1060933.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Found : user_pref("CT1060933.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Found : user_pref("CT1060933.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Found : user_pref("CT1060933.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Found : user_pref("CT1060933.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Found : user_pref("CT1060933.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Found : user_pref("CT1060933.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Found : user_pref("CT1060933.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Found : user_pref("CT1060933.backendstorage./9b-0?3g>d", "6C6C6D3D3D4175447A78754648207D4C797925507D50242A28[...]
Found : user_pref("CT1060933.backendstorage./9b-0?3g@6:5;", "");
Found : user_pref("CT1060933.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
Found : user_pref("CT1060933.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E424[...]
Found : user_pref("CT1060933.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Found : user_pref("CT1060933.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484777213F3E484F4E4D464[...]
Found : user_pref("CT1060933.backendstorage./9b5ba==9cjag", "3D676C71707471447A7043777A7A487C784D4E227A");
Found : user_pref("CT1060933.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6F726A706D727773787474");
Found : user_pref("CT1060933.backendstorage./9b9643g3/9e", "6A");
Found : user_pref("CT1060933.backendstorage./9b<:222h64<", "393F352F3E");
Found : user_pref("CT1060933.backendstorage./9b=+03eh8h8j?:", "4443");
Found : user_pref("CT1060933.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Found : user_pref("CT1060933.backendstorage./9b?b0d:8aj62<h", "6D");
Found : user_pref("CT1060933.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Found : user_pref("CT1060933.components.1000082", false);
Found : user_pref("CT1060933.components.129032145384800518", false);
Found : user_pref("CT1060933.components.129032148247613461", false);
Found : user_pref("CT1060933.components.129032152822456983", false);
Found : user_pref("CT1060933.components.129032154330894193", false);
Found : user_pref("CT1060933.components.129032155426050046", false);
Found : user_pref("CT1060933.components.129032157011675027", false);
Found : user_pref("CT1060933.components.129032162642925076", false);
Found : user_pref("CT1060933.components.129078058382649592", false);
Found : user_pref("CT1060933.components.129272674122038321", false);
Found : user_pref("CT1060933.components.129633202291172081", false);
Found : user_pref("CT1060933.components.129639980260409734", false);
Found : user_pref("CT1060933.components.129652058719725628", false);
Found : user_pref("CT1060933.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT1060933.globalFirstTimeInfoLastCheckTime", "Fri Nov 11 2011 03:06:43 GMT+0100");
Found : user_pref("CT1060933.homepageProtectorEnableByLogin", true);
Found : user_pref("CT1060933.initDone", true);
Found : user_pref("CT1060933.isAppTrackingManagerOn", true);
Found : user_pref("CT1060933.isFirstRadioInstallation", false);
Found : user_pref("CT1060933.isSearchProtectorNotifyChanges", false);
Found : user_pref("CT1060933.myStuffEnabled", true);
Found : user_pref("CT1060933.myStuffPublihserMinWidth", 400);
Found : user_pref("CT1060933.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT1060933.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT1060933.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT1060933.oldAppsList", "128346981843587669,128280995260143876,111,129272674122038321,129[...]
Found : user_pref("CT1060933.revertSettingsEnabled", true);
Found : user_pref("CT1060933.searchProtectorDialogDelayInSec", 10);
Found : user_pref("CT1060933.searchProtectorEnableByLogin", true);
Found : user_pref("CT1060933.testingCtid", "");
Found : user_pref("CT1060933.toolbarAppMetaDataLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Found : user_pref("CT1060933.toolbarContextMenuLastCheckTime", "Thu Nov 10 2011 19:06:43 GMT+0100");
Found : user_pref("CT1060933.usageEnabled", false);
Found : user_pref("CT1060933.usagesFlag", 2);
Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT1060933/CT1060933[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/15651/15317/DE", "\"0\"");
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT1060933", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT1060933",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT1060933&octid=[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/equaliz[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/minimiz[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play.gi[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/stop.gi[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/vol.gif[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...]
Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Euronics\\AppData\\Roaming\\Mozilla[...]
Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.8.0.8");
Found : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://freecorder.com/fc6/gadget/video.html", "833x3[...]
Found : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...]
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.icq.com/search/afe_results[...]
Found : user_pref("CommunityToolbar.ToolbarsList", "CT1060933");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT1060933");
Found : user_pref("CommunityToolbar.ToolbarsList4", "CT1060933");
Found : user_pref("CommunityToolbar.globalUserId", "96545c57-4b65-4045-b007-ac128590f878");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Thu Nov 10 2011 19:06:4[...]
Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Thu Nov 10 2011 20:06:56 GMT+010[...]
Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.notifications.locale", "en");
Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Nov 10 2011 19:06:43 GMT+0100");
Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.notifications.userId", "2492309d-1eb1-45f4-9456-e80b40798fae");
Found : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.google.de/");
Found : user_pref("CommunityToolbar.originalSearchEngine", "ICQ Search");

-\\ Google Chrome v20.0.1132.47

File : C:\Users\Euronics\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [23109 octets] - [11/07/2012 22:20:08]

########## EOF - C:\AdwCleaner[R1].txt - [23238 octets] ##########
         
__________________


Alt 12.07.2012, 10:11   #18
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.
__________________
__________________

Alt 12.07.2012, 20:10   #19
PuritySH
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



Guten Abend,

hier die Textdatei:

Code:
ATTFilter
# AdwCleaner v1.701 - Logfile created 07/12/2012 at 19:49:59
# Updated 02/07/2012 by Xplode
# Operating system : Windows 7 Home Premium  (64 bits)
# User : Euronics - EURONICS-VAIO
# Running from : C:\Users\Euronics\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\Euronics\AppData\Local\Conduit
Folder Deleted : C:\Users\Euronics\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Euronics\AppData\Roaming\Complitly
Folder Deleted : C:\Users\Euronics\AppData\Roaming\pdfforge
Folder Deleted : C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\ConduitCommon
Folder Deleted : C:\Program Files (x86)\Complitly
Folder Deleted : C:\Program Files (x86)\Conduit

***** [Registry] *****
[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1060933
Key Deleted : HKCU\Software\Ask&Record
Key Deleted : HKCU\Software\Complitly
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO
Key Deleted : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlfienamagdnkekbbbocojppncdambda
Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7600.16385

[OK] Registry is clean.

-\\ Mozilla Firefox v13.0.1 (de)

Profile name : default 
File : C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\prefs.js

C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\user.js ... Deleted !

Deleted : user_pref("CT1060933..clientLogIsEnabled", false);
Deleted : user_pref("CT1060933..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT1060933..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT1060933.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Deleted : user_pref("CT1060933.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT1060933.BrowserCompStateIsOpen_129633202291172081", true);
Deleted : user_pref("CT1060933.BrowserCompStateIsOpen_129652058719725628", true);
Deleted : user_pref("CT1060933.BrowserCompStateIsOpen_129681785283868963", true);
Deleted : user_pref("CT1060933.BrowserCompStateIsOpen_129686665230467549", true);
Deleted : user_pref("CT1060933.CTID", "CT1060933");
Deleted : user_pref("CT1060933.CurrentServerDate", "10-7-2012");
Deleted : user_pref("CT1060933.DSInstall", false);
Deleted : user_pref("CT1060933.DialogsAlignMode", "LTR");
Deleted : user_pref("CT1060933.DialogsGetterLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Deleted : user_pref("CT1060933.DownloadReferralCookieData", "");
Deleted : user_pref("CT1060933.EnableClickToSearchBox", false);
Deleted : user_pref("CT1060933.EnableSearchHistory", false);
Deleted : user_pref("CT1060933.EnableSearchSuggest", false);
Deleted : user_pref("CT1060933.FirstServerDate", "10-11-2011");
Deleted : user_pref("CT1060933.FirstTime", true);
Deleted : user_pref("CT1060933.FirstTimeFF3", true);
Deleted : user_pref("CT1060933.FixPageNotFoundErrors", false);
Deleted : user_pref("CT1060933.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT1060933.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT1060933.HPInstall", false);
Deleted : user_pref("CT1060933.HasUserGlobalKeys", true);
Deleted : user_pref("CT1060933.HomePageProtectorEnabled", false);
Deleted : user_pref("CT1060933.HomepageBeforeUnload", "hxxp://www.google.de/");
Deleted : user_pref("CT1060933.Initialize", true);
Deleted : user_pref("CT1060933.InitializeCommonPrefs", true);
Deleted : user_pref("CT1060933.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT1060933.InstallationId", "ConduitStubGeneric");
Deleted : user_pref("CT1060933.InstallationType", "ConduitStubIntegration");
Deleted : user_pref("CT1060933.InstalledDate", "Thu Nov 10 2011 19:06:42 GMT+0100");
Deleted : user_pref("CT1060933.InvalidateCache", false);
Deleted : user_pref("CT1060933.IsAlertDBUpdated", true);
Deleted : user_pref("CT1060933.IsGrouping", false);
Deleted : user_pref("CT1060933.IsInitSetupIni", true);
Deleted : user_pref("CT1060933.IsMulticommunity", false);
Deleted : user_pref("CT1060933.IsOpenThankYouPage", false);
Deleted : user_pref("CT1060933.IsOpenUninstallPage", true);
Deleted : user_pref("CT1060933.LanguagePackLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Deleted : user_pref("CT1060933.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT1060933.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT1060933.LastLogin_3.12.0.7", "Thu Apr 26 2012 19:22:06 GMT+0200");
Deleted : user_pref("CT1060933.LastLogin_3.12.2.3", "Wed May 30 2012 18:23:36 GMT+0200");
Deleted : user_pref("CT1060933.LastLogin_3.13.0.6", "Tue Jul 10 2012 19:46:22 GMT+0200");
Deleted : user_pref("CT1060933.LastLogin_3.8.0.8", "Thu Nov 10 2011 19:06:43 GMT+0100");
Deleted : user_pref("CT1060933.LatestVersion", "3.13.0.6");
Deleted : user_pref("CT1060933.Locale", "en-us");
Deleted : user_pref("CT1060933.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT1060933.MCDetectTooltipShow", false);
Deleted : user_pref("CT1060933.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT1060933.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT1060933.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT1060933.OriginalFirstVersion", "3.8.0.8");
Deleted : user_pref("CT1060933.RadioIsPodcast", false);
Deleted : user_pref("CT1060933.RadioLastCheckTime", "Thu Nov 10 2011 19:06:44 GMT+0100");
Deleted : user_pref("CT1060933.RadioLastUpdateIPServer", "0");
Deleted : user_pref("CT1060933.RadioLastUpdateServer", "129326918102570000");
Deleted : user_pref("CT1060933.RadioMediaID", "21504191");
Deleted : user_pref("CT1060933.RadioMediaType", "Media Player");
Deleted : user_pref("CT1060933.RadioMenuSelectedID", "EBRadioMenu_CT106093321504191");
Deleted : user_pref("CT1060933.RadioShrinkedFromSetup", false);
Deleted : user_pref("CT1060933.RadioStationName", "KFOG");
Deleted : user_pref("CT1060933.RadioStationURL", "hxxp://live.cumulusstreaming.com/KFOG-FM");
Deleted : user_pref("CT1060933.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT1060933.SearchBackToDefaultEngine", false);
Deleted : user_pref("CT1060933.SearchCaption", "Freecorder Customized Web Search");
Deleted : user_pref("CT1060933.SearchEngineBeforeUnload", "ICQ Search");
Deleted : user_pref("CT1060933.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT1060933.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT106[...]
Deleted : user_pref("CT1060933.SearchInNewTabEnabled", true);
Deleted : user_pref("CT1060933.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT1060933.SearchInNewTabLastCheckTime", "Tue Jul 10 2012 19:46:21 GMT+0200");
Deleted : user_pref("CT1060933.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT1060933.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]
Deleted : user_pref("CT1060933.SearchInNewTabUserEnabled", false);
Deleted : user_pref("CT1060933.SearchProtectorEnabled", false);
Deleted : user_pref("CT1060933.SearchProtectorToolbarDisabled", false);
Deleted : user_pref("CT1060933.SendProtectorDataViaLogin", true);
Deleted : user_pref("CT1060933.ServiceMapLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Deleted : user_pref("CT1060933.SettingsLastCheckTime", "Tue Jul 10 2012 19:46:21 GMT+0200");
Deleted : user_pref("CT1060933.SettingsLastUpdate", "1341409951");
Deleted : user_pref("CT1060933.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT1060933&SearchSource=13");
Deleted : user_pref("CT1060933.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT1060933.ThirdPartyComponentsLastCheck", "Thu Nov 10 2011 19:06:42 GMT+0100");
Deleted : user_pref("CT1060933.ThirdPartyComponentsLastUpdate", "1312887586");
Deleted : user_pref("CT1060933.ToolbarShrinkedFromSetup", false);
Deleted : user_pref("CT1060933.TrusteLinkUrl", "hxxp://trust.conduit.com/CT1060933");
Deleted : user_pref("CT1060933.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Deleted : user_pref("CT1060933.UserID", "UN04397635592770677");
Deleted : user_pref("CT1060933.ValidationData_Search", 0);
Deleted : user_pref("CT1060933.ValidationData_Toolbar", 2);
Deleted : user_pref("CT1060933.alertChannelId", "15651");
Deleted : user_pref("CT1060933.appApproved.129272674122038321", true);
Deleted : user_pref("CT1060933.approveUntrustedApps", false);
Deleted : user_pref("CT1060933.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e.:2z527", "2423");
Deleted : user_pref("CT1060933.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e06cg5el8:", "6E6D6F726A706D736E6F");
Deleted : user_pref("CT1060933.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737578707673797475242F4B4947[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e31;cj7fk;kg#ncep@mc+vkn", "247E61393F236B25737471712A212C6[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e31;cjc<=fbj#mm", "247E61393F236B257576737A2A212C6E414F444D[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Deleted : user_pref("CT1060933.backendstorage./9b-0?3g>d", "6C6C6D3D3D4175447A78754648207D4C797925507D50242A28[...]
Deleted : user_pref("CT1060933.backendstorage./9b-0?3g@6:5;", "");
Deleted : user_pref("CT1060933.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
Deleted : user_pref("CT1060933.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E424[...]
Deleted : user_pref("CT1060933.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Deleted : user_pref("CT1060933.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484777213F3E484F4E4D464[...]
Deleted : user_pref("CT1060933.backendstorage./9b5ba==9cjag", "3D676C71707471447A7043777A7A487C784D4E227A");
Deleted : user_pref("CT1060933.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6F726A706D727773787474");
Deleted : user_pref("CT1060933.backendstorage./9b9643g3/9e", "6A");
Deleted : user_pref("CT1060933.backendstorage./9b<:222h64<", "393F352F3E");
Deleted : user_pref("CT1060933.backendstorage./9b=+03eh8h8j?:", "4443");
Deleted : user_pref("CT1060933.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Deleted : user_pref("CT1060933.backendstorage./9b?b0d:8aj62<h", "6D");
Deleted : user_pref("CT1060933.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Deleted : user_pref("CT1060933.components.1000082", false);
Deleted : user_pref("CT1060933.components.129032145384800518", false);
Deleted : user_pref("CT1060933.components.129032148247613461", false);
Deleted : user_pref("CT1060933.components.129032152822456983", false);
Deleted : user_pref("CT1060933.components.129032154330894193", false);
Deleted : user_pref("CT1060933.components.129032155426050046", false);
Deleted : user_pref("CT1060933.components.129032157011675027", false);
Deleted : user_pref("CT1060933.components.129032162642925076", false);
Deleted : user_pref("CT1060933.components.129078058382649592", false);
Deleted : user_pref("CT1060933.components.129272674122038321", false);
Deleted : user_pref("CT1060933.components.129633202291172081", false);
Deleted : user_pref("CT1060933.components.129639980260409734", false);
Deleted : user_pref("CT1060933.components.129652058719725628", false);
Deleted : user_pref("CT1060933.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Deleted : user_pref("CT1060933.globalFirstTimeInfoLastCheckTime", "Fri Nov 11 2011 03:06:43 GMT+0100");
Deleted : user_pref("CT1060933.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT1060933.initDone", true);
Deleted : user_pref("CT1060933.isAppTrackingManagerOn", true);
Deleted : user_pref("CT1060933.isFirstRadioInstallation", false);
Deleted : user_pref("CT1060933.isSearchProtectorNotifyChanges", false);
Deleted : user_pref("CT1060933.myStuffEnabled", true);
Deleted : user_pref("CT1060933.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT1060933.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT1060933.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT1060933.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT1060933.oldAppsList", "128346981843587669,128280995260143876,111,129272674122038321,129[...]
Deleted : user_pref("CT1060933.revertSettingsEnabled", true);
Deleted : user_pref("CT1060933.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT1060933.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT1060933.testingCtid", "");
Deleted : user_pref("CT1060933.toolbarAppMetaDataLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Deleted : user_pref("CT1060933.toolbarContextMenuLastCheckTime", "Thu Nov 10 2011 19:06:43 GMT+0100");
Deleted : user_pref("CT1060933.usageEnabled", false);
Deleted : user_pref("CT1060933.usagesFlag", 2);
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT1060933/CT1060933[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/15651/15317/DE", "\"0\"");
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT1060933", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT1060933",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT1060933&octid=[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/equaliz[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/minimiz[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play.gi[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/stop.gi[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/vol.gif[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...]
Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Euronics\\AppData\\Roaming\\Mozilla[...]
Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.8.0.8");
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://freecorder.com/fc6/gadget/video.html", "833x3[...]
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...]
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.icq.com/search/afe_results[...]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT1060933");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT1060933");
Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT1060933");
Deleted : user_pref("CommunityToolbar.globalUserId", "96545c57-4b65-4045-b007-ac128590f878");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Thu Nov 10 2011 19:06:4[...]
Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Thu Nov 10 2011 20:06:56 GMT+010[...]
Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Nov 10 2011 19:06:43 GMT+0100");
Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.notifications.userId", "2492309d-1eb1-45f4-9456-e80b40798fae");
Deleted : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.google.de/");
Deleted : user_pref("CommunityToolbar.originalSearchEngine", "ICQ Search");

-\\ Google Chrome v20.0.1132.47

File : C:\Users\Euronics\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [23214 octets] - [11/07/2012 22:20:08]
AdwCleaner[S1].txt - [22714 octets] - [12/07/2012 19:49:59]

########## EOF - C:\AdwCleaner[S1].txt - [22843 octets] ##########
         

Alt 12.07.2012, 21:17   #20
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!


__________________
Logfiles bitte immer in CODE-Tags posten

Alt 13.07.2012, 17:29   #21
PuritySH
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



Schönen Freitag Abend

hier das Log:

Code:
ATTFilter
 18:25:18.0570 4000	TDSS rootkit removing tool 2.7.45.0 Jul  9 2012 12:46:35
18:25:19.0038 4000	============================================================
18:25:19.0038 4000	Current date / time: 2012/07/13 18:25:19.0038
18:25:19.0038 4000	SystemInfo:
18:25:19.0038 4000	
18:25:19.0038 4000	OS Version: 6.1.7600 ServicePack: 0.0
18:25:19.0038 4000	Product type: Workstation
18:25:19.0038 4000	ComputerName: EURONICS-VAIO
18:25:19.0038 4000	UserName: Euronics
18:25:19.0038 4000	Windows directory: C:\Windows
18:25:19.0038 4000	System windows directory: C:\Windows
18:25:19.0038 4000	Running under WOW64
18:25:19.0038 4000	Processor architecture: Intel x64
18:25:19.0038 4000	Number of processors: 4
18:25:19.0038 4000	Page size: 0x1000
18:25:19.0038 4000	Boot type: Normal boot
18:25:19.0038 4000	============================================================
18:25:21.0550 4000	Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
18:25:21.0659 4000	Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
18:25:21.0659 4000	============================================================
18:25:21.0659 4000	\Device\Harddisk0\DR0:
18:25:21.0659 4000	MBR partitions:
18:25:21.0659 4000	\Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1ABF000, BlocksNum 0x32000
18:25:21.0659 4000	\Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1AF1000, BlocksNum 0x38894830
18:25:21.0659 4000	\Device\Harddisk1\DR1:
18:25:21.0659 4000	MBR partitions:
18:25:21.0846 4000	\Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x1000, BlocksNum 0x3A384800
18:25:21.0846 4000	============================================================
18:25:21.0909 4000	C: <-> \Device\Harddisk0\DR0\Partition1
18:25:21.0940 4000	D: <-> \Device\Harddisk1\DR1\Partition0
18:25:21.0940 4000	============================================================
18:25:21.0940 4000	Initialize success
18:25:21.0940 4000	============================================================
18:26:06.0603 4640	============================================================
18:26:06.0603 4640	Scan started
18:26:06.0603 4640	Mode: Manual; SigCheck; TDLFS; 
18:26:06.0603 4640	============================================================
18:26:07.0320 4640	1394ohci        (969c91060cbb5d17cb8440b5f78b4c51) C:\Windows\system32\drivers\1394ohci.sys
18:26:07.0414 4640	1394ohci - ok
18:26:07.0523 4640	ACDaemon        (adc420616c501b45d26c0fd3ef1e54e4) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
18:26:07.0820 4640	ACDaemon - ok
18:26:07.0882 4640	ACPI            (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\drivers\ACPI.sys
18:26:07.0898 4640	ACPI - ok
18:26:07.0929 4640	AcpiPmi         (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\drivers\acpipmi.sys
18:26:08.0038 4640	AcpiPmi - ok
18:26:08.0116 4640	AdobeActiveFileMonitor8.0 (34400005de52842c4d6d4ee978b4d7ce) C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
18:26:08.0132 4640	AdobeActiveFileMonitor8.0 - ok
18:26:08.0210 4640	adp94xx         (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys
18:26:08.0225 4640	adp94xx - ok
18:26:08.0303 4640	adpahci         (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys
18:26:08.0319 4640	adpahci - ok
18:26:08.0366 4640	adpu320         (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys
18:26:08.0366 4640	adpu320 - ok
18:26:08.0412 4640	AeLookupSvc     (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
18:26:08.0568 4640	AeLookupSvc - ok
18:26:08.0646 4640	AFD             (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
18:26:08.0709 4640	AFD - ok
18:26:08.0756 4640	agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
18:26:08.0756 4640	agp440 - ok
18:26:08.0787 4640	ALG             (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
18:26:08.0849 4640	ALG - ok
18:26:08.0896 4640	aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
18:26:08.0912 4640	aliide - ok
18:26:08.0958 4640	AMD External Events Utility (27429a457fca8f50923863a965fe0c6c) C:\Windows\system32\atiesrxx.exe
18:26:08.0990 4640	AMD External Events Utility - ok
18:26:08.0990 4640	amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
18:26:09.0005 4640	amdide - ok
18:26:09.0052 4640	AmdK8           (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys
18:26:09.0130 4640	AmdK8 - ok
18:26:09.0177 4640	AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys
18:26:09.0239 4640	AmdPPM - ok
18:26:09.0302 4640	amdsata         (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
18:26:09.0317 4640	amdsata - ok
18:26:09.0348 4640	amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys
18:26:09.0364 4640	amdsbs - ok
18:26:09.0395 4640	amdxata         (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
18:26:09.0395 4640	amdxata - ok
18:26:09.0504 4640	AntiVirSchedulerService (c27d46b06d340293670450fce9dfb166) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
18:26:09.0504 4640	AntiVirSchedulerService - ok
18:26:09.0551 4640	AntiVirService  (72d90e56563165984224493069c69ed4) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
18:26:09.0567 4640	AntiVirService - ok
18:26:09.0629 4640	ApfiltrService  (2d45f2dfbc3d8f53df7ebeffa8c9bc38) C:\Windows\system32\drivers\Apfiltr.sys
18:26:09.0645 4640	ApfiltrService - ok
18:26:09.0676 4640	AppID           (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
18:26:09.0770 4640	AppID - ok
18:26:09.0816 4640	AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
18:26:09.0879 4640	AppIDSvc - ok
18:26:09.0941 4640	Appinfo         (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
18:26:09.0972 4640	Appinfo - ok
18:26:10.0019 4640	arc             (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys
18:26:10.0035 4640	arc - ok
18:26:10.0050 4640	arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys
18:26:10.0066 4640	arcsas - ok
18:26:10.0082 4640	ArcSoftKsUFilter (c130bc4a51b1382b2be8e44579ec4c0a) C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys
18:26:10.0097 4640	ArcSoftKsUFilter - ok
18:26:10.0113 4640	AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
18:26:10.0175 4640	AsyncMac - ok
18:26:10.0222 4640	atapi           (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
18:26:10.0238 4640	atapi - ok
18:26:10.0362 4640	athr            (cca705cdf038d5bc243203ce4416b345) C:\Windows\system32\DRIVERS\athrx.sys
18:26:10.0440 4640	athr - ok
18:26:10.0971 4640	atikmdag        (eaea2ce49de0cca80beb9134107e5dd7) C:\Windows\system32\DRIVERS\atikmdag.sys
18:26:11.0142 4640	atikmdag - ok
18:26:11.0314 4640	atksgt          (fc0e8778c000291caf60eb88c011e931) C:\Windows\system32\DRIVERS\atksgt.sys
18:26:11.0330 4640	atksgt - ok
18:26:11.0408 4640	AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
18:26:11.0470 4640	AudioEndpointBuilder - ok
18:26:11.0470 4640	AudioSrv        (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
18:26:11.0517 4640	AudioSrv - ok
18:26:11.0548 4640	avgntflt        (b1224e6b086cd6548315b04ab575a23e) C:\Windows\system32\DRIVERS\avgntflt.sys
18:26:11.0564 4640	avgntflt - ok
18:26:11.0579 4640	avipbb          (ed45f12cfa62b83765c9c1496758cc87) C:\Windows\system32\DRIVERS\avipbb.sys
18:26:11.0595 4640	avipbb - ok
18:26:11.0642 4640	AxInstSV        (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
18:26:11.0720 4640	AxInstSV - ok
18:26:11.0782 4640	b06bdrv         (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys
18:26:11.0844 4640	b06bdrv - ok
18:26:11.0891 4640	b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
18:26:11.0938 4640	b57nd60a - ok
18:26:11.0985 4640	BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
18:26:12.0047 4640	BDESVC - ok
18:26:12.0063 4640	Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
18:26:12.0125 4640	Beep - ok
18:26:12.0219 4640	BFE             (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
18:26:12.0281 4640	BFE - ok
18:26:12.0375 4640	BITS            (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
18:26:12.0468 4640	BITS - ok
18:26:12.0531 4640	blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\drivers\blbdrive.sys
18:26:12.0562 4640	blbdrive - ok
18:26:12.0640 4640	bowser          (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
18:26:12.0702 4640	bowser - ok
18:26:12.0734 4640	BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys
18:26:12.0765 4640	BrFiltLo - ok
18:26:12.0796 4640	BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys
18:26:12.0843 4640	BrFiltUp - ok
18:26:12.0921 4640	Browser         (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
18:26:12.0983 4640	Browser - ok
18:26:13.0030 4640	Brserid         (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
18:26:13.0061 4640	Brserid - ok
18:26:13.0077 4640	BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
18:26:13.0108 4640	BrSerWdm - ok
18:26:13.0155 4640	BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
18:26:13.0202 4640	BrUsbMdm - ok
18:26:13.0233 4640	BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
18:26:13.0264 4640	BrUsbSer - ok
18:26:13.0342 4640	BthEnum         (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\drivers\BthEnum.sys
18:26:13.0389 4640	BthEnum - ok
18:26:13.0420 4640	BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
18:26:13.0451 4640	BTHMODEM - ok
18:26:13.0498 4640	BthPan          (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
18:26:13.0545 4640	BthPan - ok
18:26:13.0670 4640	BTHPORT         (21084ceb85280468c9aca3c805c0f8cf) C:\Windows\System32\Drivers\BTHport.sys
18:26:13.0748 4640	BTHPORT - ok
18:26:13.0779 4640	bthserv         (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
18:26:13.0841 4640	bthserv - ok
18:26:13.0904 4640	BTHUSB          (8504842634dd144c075b6b0c982ccec4) C:\Windows\System32\Drivers\BTHUSB.sys
18:26:13.0935 4640	BTHUSB - ok
18:26:14.0028 4640	btwampfl        (59e3510784548c6939c1b3b985c232e3) C:\Windows\system32\drivers\btwampfl.sys
18:26:14.0044 4640	btwampfl - ok
18:26:14.0075 4640	btwaudio        (1872074ed0a3fb22e3f1e3197b984bfa) C:\Windows\system32\drivers\btwaudio.sys
18:26:14.0091 4640	btwaudio - ok
18:26:14.0153 4640	btwavdt         (691cf076c33ab1c3a5b2fd5450300733) C:\Windows\system32\DRIVERS\btwavdt.sys
18:26:14.0169 4640	btwavdt - ok
18:26:14.0309 4640	btwdins         (8ba6e93a182126781952a7895ec1e4b2) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
18:26:14.0340 4640	btwdins - ok
18:26:14.0372 4640	btwl2cap        (07096d2bc22ccb6cea5a532df0be8a75) C:\Windows\system32\DRIVERS\btwl2cap.sys
18:26:14.0372 4640	btwl2cap - ok
18:26:14.0418 4640	btwrchid        (c9273b20dec8ce38dbce5d29de63c907) C:\Windows\system32\DRIVERS\btwrchid.sys
18:26:14.0418 4640	btwrchid - ok
18:26:14.0450 4640	cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
18:26:14.0496 4640	cdfs - ok
18:26:14.0543 4640	cdrom           (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
18:26:14.0590 4640	cdrom - ok
18:26:14.0621 4640	CertPropSvc     (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
18:26:14.0684 4640	CertPropSvc - ok
18:26:14.0730 4640	circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys
18:26:14.0762 4640	circlass - ok
18:26:14.0824 4640	CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
18:26:14.0824 4640	CLFS - ok
18:26:14.0886 4640	clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:26:14.0902 4640	clr_optimization_v2.0.50727_32 - ok
18:26:14.0933 4640	clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
18:26:14.0949 4640	clr_optimization_v2.0.50727_64 - ok
18:26:15.0011 4640	clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:26:15.0027 4640	clr_optimization_v4.0.30319_32 - ok
18:26:15.0042 4640	clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
18:26:15.0058 4640	clr_optimization_v4.0.30319_64 - ok
18:26:15.0105 4640	CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys
18:26:15.0136 4640	CmBatt - ok
18:26:15.0167 4640	cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
18:26:15.0167 4640	cmdide - ok
18:26:15.0230 4640	CNG             (ca7720b73446fddec5c69519c1174c98) C:\Windows\system32\Drivers\cng.sys
18:26:15.0245 4640	CNG - ok
18:26:15.0261 4640	Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys
18:26:15.0276 4640	Compbatt - ok
18:26:15.0292 4640	CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\drivers\CompositeBus.sys
18:26:15.0339 4640	CompositeBus - ok
18:26:15.0370 4640	COMSysApp - ok
18:26:15.0370 4640	crcdisk         (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys
18:26:15.0386 4640	crcdisk - ok
18:26:15.0448 4640	CryptSvc        (f02786b66375292e58c8777082d4396d) C:\Windows\system32\cryptsvc.dll
18:26:15.0510 4640	CryptSvc - ok
18:26:15.0698 4640	cvhsvc          (72794d112cbaff3bc0c29bf7350d4741) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
18:26:15.0713 4640	cvhsvc - ok
18:26:15.0776 4640	DcomLaunch      (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
18:26:15.0838 4640	DcomLaunch - ok
18:26:15.0885 4640	defragsvc       (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
18:26:15.0947 4640	defragsvc - ok
18:26:16.0025 4640	DfsC            (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
18:26:16.0088 4640	DfsC - ok
18:26:16.0150 4640	Dhcp            (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
18:26:16.0212 4640	Dhcp - ok
18:26:16.0244 4640	discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
18:26:16.0290 4640	discache - ok
18:26:16.0368 4640	Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys
18:26:16.0368 4640	Disk - ok
18:26:16.0415 4640	Dnscache        (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
18:26:16.0478 4640	Dnscache - ok
18:26:16.0524 4640	dot3svc         (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
18:26:16.0587 4640	dot3svc - ok
18:26:16.0618 4640	DPS             (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
18:26:16.0680 4640	DPS - ok
18:26:16.0727 4640	drmkaud         (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
18:26:16.0743 4640	drmkaud - ok
18:26:16.0805 4640	DXGKrnl         (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys
18:26:16.0836 4640	DXGKrnl - ok
18:26:16.0868 4640	EapHost         (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
18:26:16.0914 4640	EapHost - ok
18:26:17.0133 4640	ebdrv           (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys
18:26:17.0226 4640	ebdrv - ok
18:26:17.0367 4640	EFS             (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
18:26:17.0429 4640	EFS - ok
18:26:17.0507 4640	ehRecvr         (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
18:26:17.0570 4640	ehRecvr - ok
18:26:17.0616 4640	ehSched         (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
18:26:17.0648 4640	ehSched - ok
18:26:17.0726 4640	elxstor         (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys
18:26:17.0741 4640	elxstor - ok
18:26:17.0772 4640	ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
18:26:17.0819 4640	ErrDev - ok
18:26:17.0882 4640	EventSystem     (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
18:26:17.0944 4640	EventSystem - ok
18:26:17.0975 4640	exfat           (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
18:26:18.0038 4640	exfat - ok
18:26:18.0069 4640	fastfat         (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
18:26:18.0131 4640	fastfat - ok
18:26:18.0225 4640	Fax             (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
18:26:18.0287 4640	Fax - ok
18:26:18.0303 4640	fdc             (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys
18:26:18.0350 4640	fdc - ok
18:26:18.0396 4640	fdPHost         (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
18:26:18.0459 4640	fdPHost - ok
18:26:18.0474 4640	FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
18:26:18.0506 4640	FDResPub - ok
18:26:18.0521 4640	FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
18:26:18.0537 4640	FileInfo - ok
18:26:18.0552 4640	Filetrace       (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
18:26:18.0584 4640	Filetrace - ok
18:26:18.0677 4640	FLEXnet Licensing Service (abedfd48ac042c6aaad32452e77217a1) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
18:26:18.0708 4640	FLEXnet Licensing Service - ok
18:26:18.0724 4640	flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys
18:26:18.0740 4640	flpydisk - ok
18:26:18.0771 4640	FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
18:26:18.0786 4640	FltMgr - ok
18:26:18.0864 4640	FontCache       (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll
18:26:18.0942 4640	FontCache - ok
18:26:19.0020 4640	FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
18:26:19.0036 4640	FontCache3.0.0.0 - ok
18:26:19.0067 4640	FsDepends       (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
18:26:19.0083 4640	FsDepends - ok
18:26:19.0130 4640	Fs_Rec          (d3e3f93d67821a2db2b3d9fac2dc2064) C:\Windows\system32\drivers\Fs_Rec.sys
18:26:19.0130 4640	Fs_Rec - ok
18:26:19.0208 4640	fvevol          (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
18:26:19.0223 4640	fvevol - ok
18:26:19.0254 4640	gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys
18:26:19.0270 4640	gagp30kx - ok
18:26:19.0379 4640	GamesAppService (c403c5db49a0f9aaf4f2128edc0106d8) C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
18:26:19.0395 4640	GamesAppService - ok
18:26:19.0473 4640	gpsvc           (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
18:26:19.0535 4640	gpsvc - ok
18:26:19.0582 4640	gupdate         (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:26:19.0598 4640	gupdate - ok
18:26:19.0613 4640	gupdatem        (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:26:19.0629 4640	gupdatem - ok
18:26:19.0644 4640	hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
18:26:19.0691 4640	hcw85cir - ok
18:26:19.0722 4640	HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
18:26:19.0769 4640	HdAudAddService - ok
18:26:19.0832 4640	HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\drivers\HDAudBus.sys
18:26:19.0863 4640	HDAudBus - ok
18:26:19.0910 4640	HECIx64         (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\drivers\HECIx64.sys
18:26:19.0925 4640	HECIx64 - ok
18:26:19.0941 4640	HidBatt         (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys
18:26:19.0972 4640	HidBatt - ok
18:26:19.0988 4640	HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys
18:26:20.0034 4640	HidBth - ok
18:26:20.0081 4640	HidIr           (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys
18:26:20.0112 4640	HidIr - ok
18:26:20.0144 4640	hidserv         (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
18:26:20.0206 4640	hidserv - ok
18:26:20.0268 4640	HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
18:26:20.0300 4640	HidUsb - ok
18:26:20.0331 4640	hkmsvc          (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
18:26:20.0393 4640	hkmsvc - ok
18:26:20.0424 4640	HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
18:26:20.0487 4640	HomeGroupListener - ok
18:26:20.0518 4640	HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
18:26:20.0565 4640	HomeGroupProvider - ok
18:26:20.0612 4640	HpSAMD          (0886d440058f203eba0e1825e4355914) C:\Windows\system32\drivers\HpSAMD.sys
18:26:20.0612 4640	HpSAMD - ok
18:26:20.0674 4640	HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
18:26:20.0721 4640	HTTP - ok
18:26:20.0736 4640	hwpolicy        (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
18:26:20.0736 4640	hwpolicy - ok
18:26:20.0783 4640	i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
18:26:20.0799 4640	i8042prt - ok
18:26:20.0846 4640	iaStor          (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\drivers\iaStor.sys
18:26:20.0861 4640	iaStor - ok
18:26:20.0908 4640	IAStorDataMgrSvc (31a0e93cdf29007d6c6fffb632f375ed) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
18:26:20.0908 4640	IAStorDataMgrSvc - ok
18:26:20.0971 4640	iaStorV         (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
18:26:20.0986 4640	iaStorV - ok
18:26:21.0080 4640	ICQ Service     (b1a28fa1afde10b95ff9354b15701d70) C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
18:26:21.0095 4640	ICQ Service - ok
18:26:21.0205 4640	idsvc           (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
18:26:21.0236 4640	idsvc - ok
18:26:21.0985 4640	igfx            (2a22ab054f4630d2ef4bab2853f6d5f6) C:\Windows\system32\DRIVERS\igdkmd64.sys
18:26:22.0250 4640	igfx ( UnsignedFile.Multi.Generic ) - warning
18:26:22.0250 4640	igfx - detected UnsignedFile.Multi.Generic (1)
18:26:22.0406 4640	iirsp           (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys
18:26:22.0421 4640	iirsp - ok
18:26:22.0484 4640	IKEEXT          (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
18:26:22.0546 4640	IKEEXT - ok
18:26:22.0624 4640	Impcd           (dd587a55390ed2295bce6d36ad567da9) C:\Windows\system32\drivers\Impcd.sys
18:26:22.0640 4640	Impcd - ok
18:26:22.0811 4640	IntcAzAudAddService (526e482afb586cb1cdd687869decf686) C:\Windows\system32\drivers\RTKVHD64.sys
18:26:22.0874 4640	IntcAzAudAddService - ok
18:26:22.0999 4640	IntcDAud        (58cf58dee26c909bd6f977b61d246295) C:\Windows\system32\DRIVERS\IntcDAud.sys
18:26:23.0045 4640	IntcDAud ( UnsignedFile.Multi.Generic ) - warning
18:26:23.0045 4640	IntcDAud - detected UnsignedFile.Multi.Generic (1)
18:26:23.0077 4640	intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
18:26:23.0092 4640	intelide - ok
18:26:23.0123 4640	intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\drivers\intelppm.sys
18:26:23.0155 4640	intelppm - ok
18:26:23.0217 4640	IPBusEnum       (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
18:26:23.0248 4640	IPBusEnum - ok
18:26:23.0264 4640	IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:26:23.0295 4640	IpFilterDriver - ok
18:26:23.0373 4640	iphlpsvc        (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
18:26:23.0435 4640	iphlpsvc - ok
18:26:23.0467 4640	IPMIDRV         (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\drivers\IPMIDrv.sys
18:26:23.0498 4640	IPMIDRV - ok
18:26:23.0545 4640	IPNAT           (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
18:26:23.0623 4640	IPNAT - ok
18:26:23.0638 4640	IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
18:26:23.0654 4640	IRENUM - ok
18:26:23.0669 4640	isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
18:26:23.0685 4640	isapnp - ok
18:26:23.0716 4640	iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\drivers\msiscsi.sys
18:26:23.0732 4640	iScsiPrt - ok
18:26:23.0763 4640	kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
18:26:23.0763 4640	kbdclass - ok
18:26:23.0794 4640	kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
18:26:23.0825 4640	kbdhid - ok
18:26:23.0872 4640	KeyIso          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
18:26:23.0888 4640	KeyIso - ok
18:26:23.0919 4640	KSecDD          (4f4b5fde429416877de7143044582eb5) C:\Windows\system32\Drivers\ksecdd.sys
18:26:23.0935 4640	KSecDD - ok
18:26:23.0950 4640	KSecPkg         (6f40465a44ecdc1731befafec5bdd03c) C:\Windows\system32\Drivers\ksecpkg.sys
18:26:23.0966 4640	KSecPkg - ok
18:26:23.0997 4640	ksthunk         (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
18:26:24.0059 4640	ksthunk - ok
18:26:24.0106 4640	KtmRm           (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
18:26:24.0169 4640	KtmRm - ok
18:26:24.0231 4640	LanmanServer    (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
18:26:24.0309 4640	LanmanServer - ok
18:26:24.0340 4640	LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
18:26:24.0387 4640	LanmanWorkstation - ok
18:26:24.0465 4640	lirsgt          (156ab2e56dc3ca0b582e3362e07cded7) C:\Windows\system32\DRIVERS\lirsgt.sys
18:26:24.0481 4640	lirsgt - ok
18:26:24.0496 4640	lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
18:26:24.0559 4640	lltdio - ok
18:26:24.0605 4640	lltdsvc         (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
18:26:24.0683 4640	lltdsvc - ok
18:26:24.0715 4640	lmhosts         (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
18:26:24.0746 4640	lmhosts - ok
18:26:24.0824 4640	LMS             (3d23191672d83e90d1cf63927ee98136) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
18:26:24.0839 4640	LMS - ok
18:26:24.0886 4640	LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys
18:26:24.0902 4640	LSI_FC - ok
18:26:24.0933 4640	LSI_SAS         (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys
18:26:24.0949 4640	LSI_SAS - ok
18:26:24.0964 4640	LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys
18:26:24.0964 4640	LSI_SAS2 - ok
18:26:24.0980 4640	LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys
18:26:24.0995 4640	LSI_SCSI - ok
18:26:25.0011 4640	luafv           (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
18:26:25.0073 4640	luafv - ok
18:26:25.0167 4640	MBAMProtector   (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
18:26:25.0183 4640	MBAMProtector - ok
18:26:25.0245 4640	MBAMService     (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
18:26:25.0261 4640	MBAMService - ok
18:26:25.0307 4640	Mcx2Svc         (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
18:26:25.0339 4640	Mcx2Svc - ok
18:26:25.0370 4640	megasas         (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys
18:26:25.0370 4640	megasas - ok
18:26:25.0417 4640	MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys
18:26:25.0432 4640	MegaSR - ok
18:26:25.0448 4640	MMCSS           (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
18:26:25.0510 4640	MMCSS - ok
18:26:25.0541 4640	Modem           (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
18:26:25.0588 4640	Modem - ok
18:26:25.0619 4640	monitor         (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
18:26:25.0651 4640	monitor - ok
18:26:25.0713 4640	mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
18:26:25.0713 4640	mouclass - ok
18:26:25.0744 4640	mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
18:26:25.0744 4640	mouhid - ok
18:26:25.0760 4640	mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
18:26:25.0775 4640	mountmgr - ok
18:26:25.0931 4640	MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
18:26:25.0947 4640	MozillaMaintenance - ok
18:26:25.0978 4640	mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\drivers\mpio.sys
18:26:25.0994 4640	mpio - ok
18:26:26.0009 4640	mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
18:26:26.0041 4640	mpsdrv - ok
18:26:26.0103 4640	MpsSvc          (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
18:26:26.0181 4640	MpsSvc - ok
18:26:26.0228 4640	MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
18:26:26.0259 4640	MRxDAV - ok
18:26:26.0306 4640	mrxsmb          (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
18:26:26.0337 4640	mrxsmb - ok
18:26:26.0384 4640	mrxsmb10        (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:26:26.0415 4640	mrxsmb10 - ok
18:26:26.0446 4640	mrxsmb20        (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:26:26.0477 4640	mrxsmb20 - ok
18:26:26.0540 4640	msahci          (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\drivers\msahci.sys
18:26:26.0540 4640	msahci - ok
18:26:26.0571 4640	msdsm           (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\drivers\msdsm.sys
18:26:26.0587 4640	msdsm - ok
18:26:26.0602 4640	MSDTC           (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
18:26:26.0618 4640	MSDTC - ok
18:26:26.0649 4640	Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
18:26:26.0680 4640	Msfs - ok
18:26:26.0680 4640	mshidkmdf       (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
18:26:26.0743 4640	mshidkmdf - ok
18:26:26.0758 4640	msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
18:26:26.0774 4640	msisadrv - ok
18:26:26.0805 4640	MSiSCSI         (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
18:26:26.0867 4640	MSiSCSI - ok
18:26:26.0867 4640	msiserver - ok
18:26:26.0930 4640	MSKSSRV         (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
18:26:26.0977 4640	MSKSSRV - ok
18:26:26.0992 4640	MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
18:26:27.0055 4640	MSPCLOCK - ok
18:26:27.0086 4640	MSPQM           (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
18:26:27.0148 4640	MSPQM - ok
18:26:27.0195 4640	MsRPC           (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
18:26:27.0211 4640	MsRPC - ok
18:26:27.0242 4640	mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
18:26:27.0242 4640	mssmbios - ok
18:26:27.0273 4640	MSTEE           (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
18:26:27.0320 4640	MSTEE - ok
18:26:27.0351 4640	MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys
18:26:27.0398 4640	MTConfig - ok
18:26:27.0413 4640	Mup             (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
18:26:27.0429 4640	Mup - ok
18:26:27.0523 4640	MySQL - ok
18:26:27.0569 4640	napagent        (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
18:26:27.0647 4640	napagent - ok
18:26:27.0694 4640	NativeWifiP     (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
18:26:27.0710 4640	NativeWifiP - ok
18:26:27.0772 4640	NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
18:26:27.0803 4640	NDIS - ok
18:26:27.0819 4640	NdisCap         (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
18:26:27.0866 4640	NdisCap - ok
18:26:27.0928 4640	NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
18:26:27.0975 4640	NdisTapi - ok
18:26:28.0006 4640	Ndisuio         (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
18:26:28.0069 4640	Ndisuio - ok
18:26:28.0100 4640	NdisWan         (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
18:26:28.0131 4640	NdisWan - ok
18:26:28.0147 4640	NDProxy         (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
18:26:28.0178 4640	NDProxy - ok
18:26:28.0209 4640	NetBIOS         (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
18:26:28.0240 4640	NetBIOS - ok
18:26:28.0271 4640	NetBT           (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
18:26:28.0334 4640	NetBT - ok
18:26:28.0381 4640	Netlogon        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
18:26:28.0381 4640	Netlogon - ok
18:26:28.0443 4640	Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
18:26:28.0505 4640	Netman - ok
18:26:28.0552 4640	netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
18:26:28.0615 4640	netprofm - ok
18:26:28.0708 4640	NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:26:28.0724 4640	NetTcpPortSharing - ok
18:26:28.0755 4640	nfrd960         (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys
18:26:28.0771 4640	nfrd960 - ok
18:26:28.0817 4640	NlaSvc          (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
18:26:28.0880 4640	NlaSvc - ok
18:26:29.0129 4640	NOBU            (5839a8027d6d324a7cd494051a96628c) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
18:26:29.0192 4640	NOBU - ok
18:26:29.0317 4640	Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
18:26:29.0379 4640	Npfs - ok
18:26:29.0410 4640	nsi             (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
18:26:29.0473 4640	nsi - ok
18:26:29.0488 4640	nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
18:26:29.0519 4640	nsiproxy - ok
18:26:29.0675 4640	Ntfs            (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
18:26:29.0722 4640	Ntfs - ok
18:26:29.0847 4640	Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
18:26:29.0878 4640	Null - ok
18:26:29.0941 4640	nvraid          (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
18:26:29.0956 4640	nvraid - ok
18:26:29.0972 4640	nvstor          (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
18:26:29.0987 4640	nvstor - ok
18:26:30.0003 4640	nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
18:26:30.0019 4640	nv_agp - ok
18:26:30.0050 4640	ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
18:26:30.0065 4640	ohci1394 - ok
18:26:30.0143 4640	ose             (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:26:30.0159 4640	ose - ok
18:26:30.0471 4640	osppsvc         (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
18:26:30.0611 4640	osppsvc - ok
18:26:30.0736 4640	p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
18:26:30.0799 4640	p2pimsvc - ok
18:26:30.0845 4640	p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
18:26:30.0861 4640	p2psvc - ok
18:26:30.0892 4640	Parport         (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys
18:26:30.0908 4640	Parport - ok
18:26:30.0939 4640	partmgr         (90061b1acfe8ccaa5345750ffe08d8b8) C:\Windows\system32\drivers\partmgr.sys
18:26:30.0939 4640	partmgr - ok
18:26:30.0970 4640	PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
18:26:30.0986 4640	PcaSvc - ok
18:26:31.0017 4640	pci             (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\drivers\pci.sys
18:26:31.0033 4640	pci - ok
18:26:31.0048 4640	pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
18:26:31.0048 4640	pciide - ok
18:26:31.0079 4640	pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys
18:26:31.0079 4640	pcmcia - ok
18:26:31.0111 4640	pcw             (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
18:26:31.0111 4640	pcw - ok
18:26:31.0157 4640	PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
18:26:31.0235 4640	PEAUTH - ok
18:26:31.0313 4640	PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
18:26:31.0360 4640	PerfHost - ok
18:26:31.0469 4640	pla             (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
18:26:31.0563 4640	pla - ok
18:26:31.0610 4640	PlugPlay        (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
18:26:31.0641 4640	PlugPlay - ok
18:26:31.0735 4640	PMBDeviceInfoProvider (80e85394d8cd7f84340b1c6f4b9d698f) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
18:26:31.0750 4640	PMBDeviceInfoProvider - ok
18:26:31.0781 4640	PNRPAutoReg     (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
18:26:31.0813 4640	PNRPAutoReg - ok
18:26:31.0859 4640	PNRPsvc         (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
18:26:31.0859 4640	PNRPsvc - ok
18:26:31.0922 4640	PolicyAgent     (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
18:26:31.0984 4640	PolicyAgent - ok
18:26:32.0015 4640	Power           (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
18:26:32.0078 4640	Power - ok
18:26:32.0156 4640	PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
18:26:32.0203 4640	PptpMiniport - ok
18:26:32.0249 4640	Processor       (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys
18:26:32.0281 4640	Processor - ok
18:26:32.0343 4640	ProfSvc         (97293447431311c06703368ad0f6c4be) C:\Windows\system32\profsvc.dll
18:26:32.0359 4640	ProfSvc - ok
18:26:32.0405 4640	ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
18:26:32.0421 4640	ProtectedStorage - ok
18:26:32.0452 4640	Psched          (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
18:26:32.0483 4640	Psched - ok
18:26:32.0499 4640	PxHlpa64        (fbf4db6d53585437e41a113300002a2b) C:\Windows\system32\Drivers\PxHlpa64.sys
18:26:32.0515 4640	PxHlpa64 - ok
18:26:32.0624 4640	ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys
18:26:32.0671 4640	ql2300 - ok
18:26:32.0811 4640	ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys
18:26:32.0827 4640	ql40xx - ok
18:26:32.0858 4640	QWAVE           (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
18:26:32.0889 4640	QWAVE - ok
18:26:32.0920 4640	QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
18:26:32.0951 4640	QWAVEdrv - ok
18:26:32.0983 4640	RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
18:26:33.0045 4640	RasAcd - ok
18:26:33.0092 4640	RasAgileVpn     (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
18:26:33.0123 4640	RasAgileVpn - ok
18:26:33.0170 4640	RasAuto         (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
18:26:33.0217 4640	RasAuto - ok
18:26:33.0248 4640	Rasl2tp         (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
18:26:33.0279 4640	Rasl2tp - ok
18:26:33.0326 4640	RasMan          (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
18:26:33.0388 4640	RasMan - ok
18:26:33.0419 4640	RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
18:26:33.0482 4640	RasPppoe - ok
18:26:33.0529 4640	RasSstp         (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
18:26:33.0591 4640	RasSstp - ok
18:26:33.0638 4640	rdbss           (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
18:26:33.0669 4640	rdbss - ok
18:26:33.0685 4640	rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys
18:26:33.0731 4640	rdpbus - ok
18:26:33.0763 4640	RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
18:26:33.0794 4640	RDPCDD - ok
18:26:33.0809 4640	RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
18:26:33.0856 4640	RDPENCDD - ok
18:26:33.0856 4640	RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
18:26:33.0887 4640	RDPREFMP - ok
18:26:33.0934 4640	RDPWD           (447de7e3dea39d422c1504f245b668b1) C:\Windows\system32\drivers\RDPWD.sys
18:26:34.0012 4640	RDPWD - ok
18:26:34.0043 4640	rdyboost        (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\Windows\system32\drivers\rdyboost.sys
18:26:34.0059 4640	rdyboost - ok
18:26:34.0090 4640	RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
18:26:34.0137 4640	RemoteAccess - ok
18:26:34.0184 4640	RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
18:26:34.0246 4640	RemoteRegistry - ok
18:26:34.0293 4640	RFCOMM          (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
18:26:34.0324 4640	RFCOMM - ok
18:26:34.0371 4640	rimspci         (fa6abc06b629da29634d31f1fe0347bd) C:\Windows\system32\drivers\rimssne64.sys
18:26:34.0387 4640	rimspci - ok
18:26:34.0433 4640	risdsnpe        (8f8539a7f5c117d4407b2985995671f2) C:\Windows\system32\drivers\risdsne64.sys
18:26:34.0496 4640	risdsnpe - ok
18:26:34.0527 4640	RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
18:26:34.0574 4640	RpcEptMapper - ok
18:26:34.0621 4640	RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
18:26:34.0636 4640	RpcLocator - ok
18:26:34.0667 4640	RpcSs           (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
18:26:34.0699 4640	RpcSs - ok
18:26:34.0730 4640	rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
18:26:34.0792 4640	rspndr - ok
18:26:34.0855 4640	RTHDMIAzAudService (d6d381b76056c668679723938f06f16c) C:\Windows\system32\drivers\RtHDMIVX.sys
18:26:34.0870 4640	RTHDMIAzAudService - ok
18:26:34.0901 4640	SamSs           (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
18:26:34.0917 4640	SamSs - ok
18:26:34.0964 4640	sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\drivers\sbp2port.sys
18:26:34.0964 4640	sbp2port - ok
18:26:35.0011 4640	SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
18:26:35.0042 4640	SCardSvr - ok
18:26:35.0057 4640	scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
18:26:35.0120 4640	scfilter - ok
18:26:35.0213 4640	Schedule        (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
18:26:35.0291 4640	Schedule - ok
18:26:35.0323 4640	SCPolicySvc     (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
18:26:35.0354 4640	SCPolicySvc - ok
18:26:35.0385 4640	sdbus           (2c8d162efaf73abd36d8bcbb6340cae7) C:\Windows\system32\DRIVERS\sdbus.sys
18:26:35.0416 4640	sdbus - ok
18:26:35.0447 4640	SDRSVC          (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
18:26:35.0510 4640	SDRSVC - ok
18:26:35.0525 4640	secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
18:26:35.0588 4640	secdrv - ok
18:26:35.0619 4640	seclogon        (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
18:26:35.0666 4640	seclogon - ok
18:26:35.0697 4640	SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
18:26:35.0759 4640	SENS - ok
18:26:35.0822 4640	SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
18:26:35.0884 4640	SensrSvc - ok
18:26:35.0915 4640	Serenum         (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys
18:26:35.0915 4640	Serenum - ok
18:26:35.0947 4640	Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys
18:26:35.0978 4640	Serial - ok
18:26:36.0025 4640	sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys
18:26:36.0071 4640	sermouse - ok
18:26:36.0118 4640	SessionEnv      (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
18:26:36.0165 4640	SessionEnv - ok
18:26:36.0196 4640	SFEP            (286d3889e6ab5589646ff8a63cb928ae) C:\Windows\system32\drivers\SFEP.sys
18:26:36.0227 4640	SFEP - ok
18:26:36.0259 4640	sffdisk         (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
18:26:36.0290 4640	sffdisk - ok
18:26:36.0321 4640	sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
18:26:36.0352 4640	sffp_mmc - ok
18:26:36.0383 4640	sffp_sd         (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\drivers\sffp_sd.sys
18:26:36.0415 4640	sffp_sd - ok
18:26:36.0446 4640	sfloppy         (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys
18:26:36.0446 4640	sfloppy - ok
18:26:36.0539 4640	Sftfs           (c6cc9297bd53e5229653303e556aa539) C:\Windows\system32\DRIVERS\Sftfslh.sys
18:26:36.0571 4640	Sftfs - ok
18:26:36.0680 4640	sftlist         (13693b6354dd6e72dc5131da7d764b90) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
18:26:36.0695 4640	sftlist - ok
18:26:36.0742 4640	Sftplay         (390aa7bc52cee43f6790cdea1e776703) C:\Windows\system32\DRIVERS\Sftplaylh.sys
18:26:36.0758 4640	Sftplay - ok
18:26:36.0773 4640	Sftredir        (617e29a0b0a2807466560d4c4e338d3e) C:\Windows\system32\DRIVERS\Sftredirlh.sys
18:26:36.0773 4640	Sftredir - ok
18:26:36.0789 4640	Sftvol          (8f571f016fa1976f445147e9e6c8ae9b) C:\Windows\system32\DRIVERS\Sftvollh.sys
18:26:36.0789 4640	Sftvol - ok
18:26:36.0820 4640	sftvsa          (c3cddd18f43d44ab713cf8c4916f7696) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
18:26:36.0836 4640	sftvsa - ok
18:26:36.0867 4640	SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
18:26:36.0929 4640	SharedAccess - ok
18:26:36.0992 4640	ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
18:26:37.0023 4640	ShellHWDetection - ok
18:26:37.0085 4640	SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys
18:26:37.0085 4640	SiSRaid2 - ok
18:26:37.0117 4640	SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys
18:26:37.0132 4640	SiSRaid4 - ok
18:26:37.0163 4640	Smb             (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
18:26:37.0226 4640	Smb - ok
18:26:37.0273 4640	SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
18:26:37.0304 4640	SNMPTRAP - ok
18:26:37.0382 4640	SOHCImp         (c3e69db0a4e59564230e053232f39ac7) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
18:26:37.0397 4640	SOHCImp - ok
18:26:37.0444 4640	SOHDms          (65cc4779a29c3e82b987bd4961790dff) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
18:26:37.0460 4640	SOHDms - ok
18:26:37.0475 4640	SOHDs           (f47d75cee1844eef4a9ea6ee768828fb) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
18:26:37.0491 4640	SOHDs - ok
18:26:37.0600 4640	SpfService      (5449fc97476f52e027409e703791e6a9) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
18:26:37.0616 4640	SpfService - ok
18:26:37.0647 4640	spldr           (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
18:26:37.0663 4640	spldr - ok
18:26:37.0741 4640	Spooler         (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
18:26:37.0803 4640	Spooler - ok
18:26:38.0037 4640	sppsvc          (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
18:26:38.0099 4640	sppsvc - ok
18:26:38.0209 4640	sppuinotify     (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
18:26:38.0255 4640	sppuinotify - ok
18:26:38.0333 4640	srv             (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
18:26:38.0396 4640	srv - ok
18:26:38.0427 4640	srv2            (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
18:26:38.0443 4640	srv2 - ok
18:26:38.0458 4640	srvnet          (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
18:26:38.0505 4640	srvnet - ok
18:26:38.0552 4640	SSDPSRV         (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
18:26:38.0614 4640	SSDPSRV - ok
18:26:38.0645 4640	SstpSvc         (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
18:26:38.0677 4640	SstpSvc - ok
18:26:38.0692 4640	stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys
18:26:38.0708 4640	stexstor - ok
18:26:38.0755 4640	stisvc          (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
18:26:38.0786 4640	stisvc - ok
18:26:38.0817 4640	swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
18:26:38.0817 4640	swenum - ok
18:26:38.0879 4640	swprv           (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
18:26:38.0942 4640	swprv - ok
18:26:39.0067 4640	SysMain         (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
18:26:39.0129 4640	SysMain - ok
18:26:39.0269 4640	TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
18:26:39.0301 4640	TabletInputService - ok
18:26:39.0347 4640	TapiSrv         (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
18:26:39.0410 4640	TapiSrv - ok
18:26:39.0441 4640	TBS             (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
18:26:39.0472 4640	TBS - ok
18:26:39.0644 4640	Tcpip           (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\drivers\tcpip.sys
18:26:39.0691 4640	Tcpip - ok
18:26:39.0940 4640	TCPIP6          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\DRIVERS\tcpip.sys
18:26:39.0971 4640	TCPIP6 - ok
18:26:40.0112 4640	tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
18:26:40.0143 4640	tcpipreg - ok
18:26:40.0159 4640	TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
18:26:40.0237 4640	TDPIPE - ok
18:26:40.0268 4640	TDTCP           (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
18:26:40.0330 4640	TDTCP - ok
18:26:40.0346 4640	tdx             (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
18:26:40.0408 4640	tdx - ok
18:26:40.0455 4640	TermDD          (c448651339196c0e869a355171875522) C:\Windows\system32\drivers\termdd.sys
18:26:40.0471 4640	TermDD - ok
18:26:40.0517 4640	TermService     (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
18:26:40.0595 4640	TermService - ok
18:26:40.0627 4640	Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
18:26:40.0658 4640	Themes - ok
18:26:40.0705 4640	THREADORDER     (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
18:26:40.0736 4640	THREADORDER - ok
18:26:40.0767 4640	TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
18:26:40.0814 4640	TrkWks - ok
18:26:40.0861 4640	TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
18:26:40.0892 4640	TrustedInstaller - ok
18:26:40.0939 4640	tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
18:26:41.0001 4640	tssecsrv - ok
18:26:41.0032 4640	tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
18:26:41.0095 4640	tunnel - ok
18:26:41.0095 4640	uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys
18:26:41.0110 4640	uagp35 - ok
18:26:41.0173 4640	uCamMonitor     (63f6d08c54d5b3c1b12a6172032055c7) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
18:26:41.0173 4640	uCamMonitor - ok
18:26:41.0219 4640	udfs            (0e5e962b5649d544be54e8c90761ea2b) C:\Windows\system32\DRIVERS\udfs.sys
18:26:41.0282 4640	udfs - ok
18:26:41.0313 4640	UI0Detect       (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
18:26:41.0313 4640	UI0Detect - ok
18:26:41.0360 4640	uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
18:26:41.0375 4640	uliagpkx - ok
18:26:41.0391 4640	umbus           (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
18:26:41.0422 4640	umbus - ok
18:26:41.0469 4640	UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys
18:26:41.0485 4640	UmPass - ok
18:26:41.0672 4640	UNS             (11a559e0f10cc5e788984023df400a6f) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
18:26:41.0703 4640	UNS - ok
18:26:41.0843 4640	upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
18:26:41.0906 4640	upnphost - ok
18:26:41.0968 4640	usbccgp         (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
18:26:42.0031 4640	usbccgp - ok
18:26:42.0062 4640	usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
18:26:42.0093 4640	usbcir - ok
18:26:42.0124 4640	usbehci         (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\drivers\usbehci.sys
18:26:42.0140 4640	usbehci - ok
18:26:42.0171 4640	usbhub          (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
18:26:42.0218 4640	usbhub - ok
18:26:42.0265 4640	usbohci         (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
18:26:42.0280 4640	usbohci - ok
18:26:42.0296 4640	usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
18:26:42.0311 4640	usbprint - ok
18:26:42.0343 4640	USBSTOR         (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:26:42.0405 4640	USBSTOR - ok
18:26:42.0421 4640	usbuhci         (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\drivers\usbuhci.sys
18:26:42.0452 4640	usbuhci - ok
18:26:42.0530 4640	usbvideo        (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys
18:26:42.0577 4640	usbvideo - ok
18:26:42.0608 4640	UxSms           (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
18:26:42.0639 4640	UxSms - ok
18:26:42.0701 4640	VAIO Event Service (a60605fc66552b421ee1f3d4ebb9a4e0) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
18:26:42.0701 4640	VAIO Event Service - ok
18:26:42.0795 4640	VAIO Power Management (d469be2723f79cf4b384680b1fdc577d) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
18:26:42.0811 4640	VAIO Power Management - ok
18:26:42.0889 4640	VaultSvc        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
18:26:42.0889 4640	VaultSvc - ok
18:26:43.0949 4640	VCFw            (96efa2698d6b9e2931609a3ea73fc5dc) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
18:26:43.0965 4640	VCFw - ok
18:26:44.0558 4640	VcmIAlzMgr      (7bebf6a5285ffc03c34a7297a4e177cb) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
18:26:44.0636 4640	VcmIAlzMgr - ok
18:26:44.0995 4640	VcmINSMgr       (e005b04dfca99f5880c5111933194ca9) C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
18:26:45.0041 4640	VcmINSMgr - ok
18:26:45.0244 4640	VcmXmlIfHelper  (829a32fd1334f72429ca0515760eb7a7) C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
18:26:45.0275 4640	VcmXmlIfHelper - ok
18:26:45.0837 4640	vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
18:26:45.0853 4640	vdrvroot - ok
18:26:45.0946 4640	vds             (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
18:26:45.0962 4640	vds - ok
18:26:46.0040 4640	vga             (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
18:26:46.0071 4640	vga - ok
18:26:46.0102 4640	VgaSave         (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
18:26:46.0165 4640	VgaSave - ok
18:26:46.0274 4640	vhdmp           (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\drivers\vhdmp.sys
18:26:46.0289 4640	vhdmp - ok
18:26:46.0321 4640	viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
18:26:46.0336 4640	viaide - ok
18:26:46.0352 4640	volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\drivers\volmgr.sys
18:26:46.0367 4640	volmgr - ok
18:26:46.0445 4640	volmgrx         (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
18:26:46.0445 4640	volmgrx - ok
18:26:46.0539 4640	volsnap         (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\drivers\volsnap.sys
18:26:46.0555 4640	volsnap - ok
18:26:46.0601 4640	vsmraid         (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys
18:26:46.0617 4640	vsmraid - ok
18:26:46.0929 4640	VSNService      (a7eb62c664a03901165290a714bd48d0) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
18:26:46.0960 4640	VSNService ( UnsignedFile.Multi.Generic ) - warning
18:26:46.0960 4640	VSNService - detected UnsignedFile.Multi.Generic (1)
18:26:47.0163 4640	VSS             (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
18:26:47.0241 4640	VSS - ok
18:26:47.0569 4640	VUAgent         (e55a44d8f9f713d5f5d5bbaef2ba0a34) C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
18:26:47.0615 4640	VUAgent - ok
18:26:47.0881 4640	vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
18:26:47.0896 4640	vwifibus - ok
18:26:47.0927 4640	vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
18:26:47.0974 4640	vwififlt - ok
18:26:48.0037 4640	W32Time         (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
18:26:48.0068 4640	W32Time - ok
18:26:48.0083 4640	WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys
18:26:48.0099 4640	WacomPen - ok
18:26:48.0146 4640	WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
18:26:48.0193 4640	WANARP - ok
18:26:48.0193 4640	Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
18:26:48.0224 4640	Wanarpv6 - ok
18:26:48.0395 4640	wbengine        (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
18:26:48.0442 4640	wbengine - ok
18:26:48.0583 4640	WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
18:26:48.0598 4640	WbioSrvc - ok
18:26:48.0645 4640	wcncsvc         (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
18:26:48.0707 4640	wcncsvc - ok
18:26:48.0723 4640	WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
18:26:48.0754 4640	WcsPlugInService - ok
18:26:48.0801 4640	Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys
18:26:48.0817 4640	Wd - ok
18:26:48.0848 4640	Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
18:26:48.0879 4640	Wdf01000 - ok
18:26:48.0895 4640	WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
18:26:48.0926 4640	WdiServiceHost - ok
18:26:48.0941 4640	WdiSystemHost   (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
18:26:48.0957 4640	WdiSystemHost - ok
18:26:49.0004 4640	WebClient       (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
18:26:49.0066 4640	WebClient - ok
18:26:49.0097 4640	Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
18:26:49.0160 4640	Wecsvc - ok
18:26:49.0191 4640	wercplsupport   (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
18:26:49.0253 4640	wercplsupport - ok
18:26:49.0285 4640	WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
18:26:49.0363 4640	WerSvc - ok
18:26:49.0425 4640	WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
18:26:49.0472 4640	WfpLwf - ok
18:26:49.0487 4640	WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
18:26:49.0503 4640	WIMMount - ok
18:26:49.0534 4640	WinDefend - ok
18:26:49.0550 4640	WinHttpAutoProxySvc - ok
18:26:49.0628 4640	Winmgmt         (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
18:26:49.0690 4640	Winmgmt - ok
18:26:49.0831 4640	WinRM           (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
18:26:49.0909 4640	WinRM - ok
18:26:50.0080 4640	Wlansvc         (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
18:26:50.0111 4640	Wlansvc - ok
18:26:50.0158 4640	WmiAcpi         (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
18:26:50.0174 4640	WmiAcpi - ok
18:26:50.0236 4640	wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
18:26:50.0283 4640	wmiApSrv - ok
18:26:50.0314 4640	WMPNetworkSvc - ok
18:26:50.0345 4640	WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
18:26:50.0377 4640	WPCSvc - ok
18:26:50.0392 4640	WPDBusEnum      (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
18:26:50.0439 4640	WPDBusEnum - ok
18:26:50.0470 4640	ws2ifsl         (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
18:26:50.0517 4640	ws2ifsl - ok
18:26:50.0564 4640	wscsvc          (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
18:26:50.0626 4640	wscsvc - ok
18:26:50.0626 4640	WSearch - ok
18:26:50.0798 4640	wuauserv        (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
18:26:50.0845 4640	wuauserv - ok
18:26:50.0985 4640	WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
18:26:51.0047 4640	WudfPf - ok
18:26:51.0094 4640	WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
18:26:51.0157 4640	WUDFRd - ok
18:26:51.0188 4640	wudfsvc         (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
18:26:51.0250 4640	wudfsvc - ok
18:26:51.0297 4640	WwanSvc         (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
18:26:51.0313 4640	WwanSvc - ok
18:26:51.0375 4640	yukonw7         (5250193ef8e173aa7491250f00eb367f) C:\Windows\system32\DRIVERS\yk62x64.sys
18:26:51.0391 4640	yukonw7 - ok
18:26:51.0422 4640	MBR (0x1B8)     (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
18:26:51.0749 4640	\Device\Harddisk0\DR0 - ok
18:26:51.0749 4640	MBR (0x1B8)     (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
18:26:52.0108 4640	\Device\Harddisk1\DR1 - ok
18:26:52.0124 4640	Boot (0x1200)   (7d4ae33e9d84f6d6153ebdececa63ed5) \Device\Harddisk0\DR0\Partition0
18:26:52.0124 4640	\Device\Harddisk0\DR0\Partition0 - ok
18:26:52.0139 4640	Boot (0x1200)   (28d667b0c2107fce1073698932cfdece) \Device\Harddisk0\DR0\Partition1
18:26:52.0139 4640	\Device\Harddisk0\DR0\Partition1 - ok
18:26:52.0139 4640	Boot (0x1200)   (44413b9e435770e9b69b090908e34489) \Device\Harddisk1\DR1\Partition0
18:26:52.0139 4640	\Device\Harddisk1\DR1\Partition0 - ok
18:26:52.0139 4640	============================================================
18:26:52.0139 4640	Scan finished
18:26:52.0139 4640	============================================================
18:26:52.0155 3108	Detected object count: 3
18:26:52.0155 3108	Actual detected object count: 3
18:27:42.0746 3108	igfx ( UnsignedFile.Multi.Generic ) - skipped by user
18:27:42.0746 3108	igfx ( UnsignedFile.Multi.Generic ) - User select action: Skip 
18:27:42.0746 3108	IntcDAud ( UnsignedFile.Multi.Generic ) - skipped by user
18:27:42.0746 3108	IntcDAud ( UnsignedFile.Multi.Generic ) - User select action: Skip 
18:27:42.0746 3108	VSNService ( UnsignedFile.Multi.Generic ) - skipped by user
18:27:42.0746 3108	VSNService ( UnsignedFile.Multi.Generic ) - User select action: Skip
         


Janina

Alt 13.07.2012, 21:27   #22
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 15.07.2012, 20:49   #23
PuritySH
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



Guten Abend,

hier die nächte txt Datei:

Combofix Logfile:
Code:
ATTFilter
ComboFix 12-07-14.01 - Euronics 15.07.2012  21:21:56.1.4 - x64
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.49.1031.18.3950.2401 [GMT 2:00]
ausgeführt von:: c:\users\Euronics\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Euronics\AppData\Local\._Revolution_
c:\windows\security\Database\tmp.edb
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-06-15 bis 2012-07-15  ))))))))))))))))))))))))))))))
.
.
2012-07-15 19:27 . 2012-07-15 19:27	--------	d-----w-	c:\users\Default\AppData\Local\temp
2012-07-15 19:26 . 2012-07-15 19:26	69000	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{35ACDFE4-F131-45ED-87A6-670C418DA1C9}\offreg.dll
2012-07-13 15:38 . 2012-05-31 04:04	9013136	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{35ACDFE4-F131-45ED-87A6-670C418DA1C9}\mpengine.dll
2012-07-11 20:28 . 2012-06-12 03:02	3147264	----a-w-	c:\windows\system32\win32k.sys
2012-07-11 20:24 . 2012-06-02 05:37	459216	----a-w-	c:\windows\system32\drivers\cng.sys
2012-07-11 20:24 . 2012-06-02 05:27	340992	----a-w-	c:\windows\system32\schannel.dll
2012-07-11 20:24 . 2012-06-02 05:38	95088	----a-w-	c:\windows\system32\drivers\ksecdd.sys
2012-07-11 20:24 . 2012-06-02 05:38	152432	----a-w-	c:\windows\system32\drivers\ksecpkg.sys
2012-07-11 20:24 . 2012-06-02 05:27	307200	----a-w-	c:\windows\system32\ncrypt.dll
2012-07-11 20:24 . 2012-06-02 04:48	22016	----a-w-	c:\windows\SysWow64\secur32.dll
2012-07-11 20:24 . 2012-06-02 04:48	225280	----a-w-	c:\windows\SysWow64\schannel.dll
2012-07-11 20:24 . 2012-06-02 04:47	219136	----a-w-	c:\windows\SysWow64\ncrypt.dll
2012-07-11 20:24 . 2012-06-02 04:42	96768	----a-w-	c:\windows\SysWow64\sspicli.dll
2012-07-11 20:23 . 2012-06-06 05:50	2003968	----a-w-	c:\windows\system32\msxml6.dll
2012-07-11 20:23 . 2012-06-06 05:50	1880064	----a-w-	c:\windows\system32\msxml3.dll
2012-07-11 20:23 . 2012-06-06 05:09	1389568	----a-w-	c:\windows\SysWow64\msxml6.dll
2012-07-11 20:23 . 2012-06-06 05:09	1236992	----a-w-	c:\windows\SysWow64\msxml3.dll
2012-07-11 20:23 . 2012-06-06 05:50	1425408	----a-w-	c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 20:23 . 2012-06-06 05:09	987136	----a-w-	c:\program files (x86)\Common Files\System\ado\msado15.dll
2012-07-10 17:52 . 2012-07-10 17:52	--------	d-----w-	C:\_OTL
2012-07-02 18:39 . 2012-07-02 18:39	--------	d-----w-	c:\program files (x86)\ESET
2012-06-25 20:02 . 2012-06-25 20:02	--------	d-----w-	c:\users\Euronics\AppData\Roaming\Malwarebytes
2012-06-25 20:02 . 2012-06-25 20:02	--------	d-----w-	c:\programdata\Malwarebytes
2012-06-25 20:02 . 2012-04-04 13:56	24904	----a-w-	c:\windows\system32\drivers\mbam.sys
2012-06-25 20:02 . 2012-06-25 20:02	--------	d-----w-	c:\program files (x86)\Malwarebytes' Anti-Malware
2012-06-25 18:24 . 2012-06-25 18:24	--------	d-----w-	c:\users\Euronics\AppData\Roaming\Avira
2012-06-25 14:04 . 2012-06-25 14:04	1394248	----a-w-	c:\windows\SysWow64\msxml4.dll
2012-06-23 18:54 . 2012-06-23 18:54	--------	d-----w-	c:\program files (x86)\V5Play
2012-06-23 15:55 . 2012-06-23 18:56	--------	d-----w-	c:\users\Euronics\AppData\Roaming\V5 Play
2012-06-21 18:17 . 2012-06-21 18:17	--------	d-----w-	c:\users\Euronics\AppData\Roaming\Little Worlds Online
2012-06-21 18:12 . 2012-06-02 22:19	2428952	----a-w-	c:\windows\system32\wuaueng.dll
2012-06-21 18:12 . 2012-06-02 22:19	57880	----a-w-	c:\windows\system32\wuauclt.exe
2012-06-21 18:12 . 2012-06-02 22:19	44056	----a-w-	c:\windows\system32\wups2.dll
2012-06-21 18:12 . 2012-06-02 22:15	2622464	----a-w-	c:\windows\system32\wucltux.dll
2012-06-21 18:12 . 2012-06-02 22:19	38424	----a-w-	c:\windows\system32\wups.dll
2012-06-21 18:12 . 2012-06-02 22:19	701976	----a-w-	c:\windows\system32\wuapi.dll
2012-06-21 18:12 . 2012-06-02 22:15	99840	----a-w-	c:\windows\system32\wudriver.dll
2012-06-21 18:12 . 2012-06-02 13:19	186752	----a-w-	c:\windows\system32\wuwebv.dll
2012-06-21 18:12 . 2012-06-02 13:15	36864	----a-w-	c:\windows\system32\wuapp.exe
2012-06-18 20:19 . 2012-06-21 19:10	--------	d-----w-	c:\programdata\Fugazo
2012-06-18 18:49 . 2012-06-18 18:49	--------	d-----w-	c:\users\Euronics\AppData\Local\JollyBear
2012-06-18 18:49 . 2012-06-18 18:49	--------	d-----w-	c:\programdata\JollyBear
2012-06-16 11:22 . 2012-06-16 11:22	--------	d-----w-	c:\users\Euronics\AppData\Roaming\LegacyInteractive
2012-06-16 10:55 . 2012-06-18 18:31	--------	d-----w-	c:\users\Euronics\AppData\Roaming\WildTangent
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-15 03:56 . 2012-06-13 22:01	1197568	----a-w-	c:\windows\system32\wininet.dll
2012-05-15 03:08 . 2012-06-13 22:01	981504	----a-w-	c:\windows\SysWow64\wininet.dll
2012-05-04 10:52 . 2012-06-13 22:01	5505392	----a-w-	c:\windows\system32\ntoskrnl.exe
2012-05-04 10:08 . 2012-06-13 22:01	3958128	----a-w-	c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:08 . 2012-06-13 22:01	3902320	----a-w-	c:\windows\SysWow64\ntoskrnl.exe
2012-05-02 05:32 . 2012-06-13 22:01	208896	----a-w-	c:\windows\system32\profsvc.dll
2012-04-28 03:50 . 2012-06-13 22:01	204800	----a-w-	c:\windows\system32\drivers\rdpwd.sys
2012-04-26 05:34 . 2012-06-13 22:01	76288	----a-w-	c:\windows\system32\rdpwsx.dll
2012-04-26 05:34 . 2012-06-13 22:01	149504	----a-w-	c:\windows\system32\rdpcorekmts.dll
2012-04-26 05:28 . 2012-06-13 22:01	9216	----a-w-	c:\windows\system32\rdrmemptylst.exe
2012-04-24 05:59 . 2012-06-13 22:01	1460224	----a-w-	c:\windows\system32\crypt32.dll
2012-04-24 05:59 . 2012-06-13 22:01	182272	----a-w-	c:\windows\system32\cryptsvc.dll
2012-04-24 05:59 . 2012-06-13 22:01	140288	----a-w-	c:\windows\system32\cryptnet.dll
2012-04-24 04:47 . 2012-06-13 22:01	139264	----a-w-	c:\windows\SysWow64\cryptsvc.dll
2012-04-24 04:47 . 2012-06-13 22:01	103936	----a-w-	c:\windows\SysWow64\cryptnet.dll
2012-04-24 04:47 . 2012-06-13 22:01	1156608	----a-w-	c:\windows\SysWow64\crypt32.dll
2012-04-20 06:22 . 2012-06-13 22:01	57856	----a-w-	c:\windows\system32\licmgr10.dll
2012-04-20 05:05 . 2012-06-13 22:01	44544	----a-w-	c:\windows\SysWow64\licmgr10.dll
2012-04-20 05:00 . 2012-06-13 22:01	482816	----a-w-	c:\windows\system32\html.iec
2012-04-20 04:15 . 2012-06-13 22:01	1638912	----a-w-	c:\windows\system32\mshtml.tlb
2012-04-20 03:58 . 2012-06-13 22:01	386048	----a-w-	c:\windows\SysWow64\html.iec
2012-04-20 03:24 . 2012-06-13 22:01	1638912	----a-w-	c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2010-05-31 673136]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-09 98304]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]
"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-06-01 600928]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 281768]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
c:\users\Euronics\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-6-9 1128224]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-25 136176]
R3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-09 169312]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-25 136176]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-06-24 271872]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-21 113120]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SOHCImp;VAIO Media plus Content Importer;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2010-06-20 108400]
R3 SOHDms;VAIO Media plus Digital Media Server;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [2010-06-18 423280]
R3 SOHDs;VAIO Media plus Device Searcher;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [2010-06-20 67952]
R3 SpfService;VAIO Entertainment Common Service;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [2010-06-06 304496]
R3 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2010-06-17 851824]
R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2010-06-09 537456]
R3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [2010-06-09 384880]
R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2010-06-09 101232]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2008-06-16 55024]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-06-24 202752]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-27 136360]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]
S2 ICQ Service;ICQ Service;c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2010-06-01 367456]
S2 rimspci;rimspci;c:\windows\system32\drivers\rimssne64.sys [2010-06-23 94208]
S2 risdsnpe;risdsnpe;c:\windows\system32\drivers\risdsne64.sys [2010-06-23 78848]
S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe [2010-05-25 252416]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2008-09-18 104960]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-05-28 2320920]
S2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [2010-06-21 575856]
S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe [2010-06-08 836608]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2009-05-26 19968]
S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2010-06-23 342056]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-06-23 39464]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys [2010-05-28 56344]
S3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-05-28 158976]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 24904]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [2010-04-26 12032]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update 5\VUAgent.exe [2010-05-31 1250160]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2010-05-31 402720]
.
.
Inhalt des "geplante Tasks" Ordners
.
2012-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-25 07:36]
.
2012-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-25 07:36]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-05-31 10775584]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-05-31 2040352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = 
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: Free YouTube to MP3 Converter - c:\users\Euronics\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\
FF - prefs.js: browser.search.defaulturl - 
FF - prefs.js: browser.search.selectedEngine - 
FF - prefs.js: browser.startup.homepage - www.google.de
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-Freecorder FLV Service - c:\program files (x86)\Freecorder\FLVSrvc.exe
HKLM-Run-Apoint - c:\program files (x86)\Apoint\Apoint.exe
AddRemove-Freecorder5.07 - c:\program files (x86)\Freecorder\uninstall.exe
AddRemove-{4FFBB818-B13C-11E0-931D-B2664824019B}_is1 - c:\program files (x86)\Complitly\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=2000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=inteldata\""
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MySQL]
"ImagePath"="\"c:\program files (x86)\MySQL\MySQL Server 5.5\bin\mysqld\" --defaults-file=\"c:\program files (x86)\MySQL\MySQL Server 5.5\my.ini\" MySQL"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-07-15  21:30:36
ComboFix-quarantined-files.txt  2012-07-15 19:30
.
Vor Suchlauf: 13 Verzeichnis(se), 378.838.552.576 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 378.938.220.544 Bytes frei
.
- - End Of File - - 517CE895525B577B7DE5FD7F210EB058
         
--- --- ---


Danke sehr und einen schönen Abend euch noch!

Janina

Alt 16.07.2012, 10:02   #24
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 17.07.2012, 20:58   #25
PuritySH
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



Hallo und schönen Abend euch!

Hier die GMER Datei:

[code]
GMER Logfile:
Code:
ATTFilter
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-07-17 21:26:36
Windows 6.1.7600  
Running: 5hjwhmkq.exe


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c6076a27b11                      
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\18f46ae726bf                      
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\18f46ae726bf@0025676472f6         0xD8 0x0D 0xD6 0xAB ...
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\18f46ae726bf@d8b377838c0e         0xDA 0x4D 0xBF 0xBB ...
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0cb38ed7bd9                      
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c6076a27b11 (not active ControlSet)  
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\18f46ae726bf (not active ControlSet)  
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\18f46ae726bf@0025676472f6             0xD8 0x0D 0xD6 0xAB ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\18f46ae726bf@d8b377838c0e             0xDA 0x4D 0xBF 0xBB ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0cb38ed7bd9 (not active ControlSet)  

---- EOF - GMER 1.0.15 ----
         
--- --- ---


Nun das OSAM Log:

Code:
ATTFilter
OSAM Logfile:
Code:
ATTFilter
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 21:52:40 on 17.07.2012

OS: Windows 7 Home Premium Edition (Build 7600), 64-bit
Default Browser: Mozilla Corporation Firefox 13.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"igfxcpl.cpl" - "Intel Corporation" - C:\Windows\system32\igfxcpl.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys  (File found, but it contains no detailed information)
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"igfx" (igfx) - "Intel Corporation" - C:\Windows\System32\DRIVERS\igdkmd64.sys
"Intel(R) Display Audio" (IntcDAud) - "Intel(R) Corporation" - C:\Windows\System32\DRIVERS\IntcDAud.sys
"lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys  (File found, but it contains no detailed information)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"PxHlpa64" (PxHlpa64) - "Sonic Solutions" - C:\Windows\System32\Drivers\PxHlpa64.sys
"Sftfs" (Sftfs) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\Sftfslh.sys
"Sftplay" (Sftplay) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\Sftplaylh.sys
"Sftredir" (Sftredir) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\Sftredirlh.sys
"Sftvol" (Sftvol) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\Sftvollh.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files (x86)\7-Zip\7-zip.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "Catalyst Context Menu extension" - ? -   (File not found | COM-object registry key not found)
{0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEEE} "Add to Evernote" - "Evernote Corporation" - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "In Blog veröffentlichen" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"OpenOffice.org 3.3.lnk" - ? - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe  (Shortcut exists | File found, but it contains no detailed information | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Bluetooth.lnk" - ? - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File not found)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce )-----
"FlashPlayerUpdate" - "Adobe Systems, Inc." - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10q_Plugin.exe -update plugin
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"avgnt" - "Avira GmbH" - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"IAStorIcon" - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
"ISBMgr.exe" - ? - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"Norton Online Backup" - "Symantec Corporation" - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
"PMBVolumeWatcher" - "Sony Corporation" - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"EPSON SX210 Series 64MonitorBE" - "SEIKO EPSON CORPORATION" - C:\Windows\system32\E_ILMFDE.DLL
"PDFCreator" - ? - C:\Windows\system32\pdfcmnnt.dll  (File found, but it contains no detailed information)

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll  (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe"  (File not found)
"Adobe Active File Monitor V8" (AdobeActiveFileMonitor8.0) - "Adobe Systems Incorporated" - C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
"Application Virtualization Client" (sftlist) - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
"Application Virtualization Service Agent" (sftvsa) - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
"ArcSoft Connect Daemon" (ACDaemon) - "ArcSoft Inc." - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
"Bluetooth Service" (btwdins) - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
"CamMonitor" (uCamMonitor) - "ArcSoft, Inc." - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
"Client Virtualization Handler" (cvhsvc) - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Acresso Software Inc." - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
"GamesAppService" (GamesAppService) - "WildTangent, Inc." - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"ICQ Service" (ICQ Service) - ? - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
"Intel(R) Management & Security Application User Notification Service" (UNS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
"Intel(R) Management and Security Application Local Management Service" (LMS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
"Intel(R) Rapid Storage Technology" (IAStorDataMgrSvc) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
"MySQL" (MySQL) - ? - C:\Program Files (x86)\MySQL\MySQL Server 5.5\bin\mysqld.exe
"Norton Online Backup" (NOBU) - "Symantec Corporation" - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
"Office  Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"PMBDeviceInfoProvider" (PMBDeviceInfoProvider) - "Sony Corporation" - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
"VAIO Care Performance Service" (SampleCollector) - "Sony Corporation" - C:\Program Files\Sony\VAIO Care\VCPerfService.exe
"VAIO Content Folder Watcher" (VCFw) - "Sony Corporation" - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
"VAIO Content Metadata Intelligent Analyzing Manager" (VcmIAlzMgr) - "Sony Corporation" - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
"VAIO Content Metadata Intelligent Network Service Manager" (VcmINSMgr) - "Sony Corporation" - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
"VAIO Content Metadata XML Interface" (VcmXmlIfHelper) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
"VAIO Entertainment Common Service" (SpfService) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
"VAIO Event Service" (VAIO Event Service) - "Sony Corporation" - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
"VAIO Media plus Content Importer" (SOHCImp) - "Sony Corporation" - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
"VAIO Media plus Device Searcher" (SOHDs) - "Sony Corporation" - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
"VAIO Media plus Digital Media Server" (SOHDms) - "Sony Corporation" - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
"VAIO Power Management" (VAIO Power Management) - "Sony Corporation" - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
"VSNService" (VSNService) - "Sony Corporation" - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
"VUAgent" (VUAgent) - "Sony Corporation" - C:\Program Files\Sony\VAIO Update 5\VUAgent.exe

===[ Logfile end ]=========================================[ Logfile end ]===
         
--- --- --- If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
Und zuletzt das aswMBR Log:

Code:
ATTFilter
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-17 21:53:49
-----------------------------
21:53:49.237    OS Version: Windows x64 6.1.7600 
21:53:49.238    Number of processors: 4 586 0x2505
21:53:49.238    ComputerName: EURONICS-VAIO  UserName: Euronics
21:53:51.627    Initialize success
21:54:37.901    AVAST engine defs: 12071700
21:56:10.727    The log file has been saved successfully to "C:\Users\Euronics\Desktop\aswMBR.txt"
         

Vielen Dank mal wieder und schönen Abend noch!

Janina

Alt 18.07.2012, 16:01   #26
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



aswMBR ist unvollständig
Du musst JEDES Tool per Rechtsklick als Administrator ausführen!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 18.07.2012, 20:13   #27
PuritySH
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



Hoppala,

ich hoffe das es nun richtig ist... Sorry!

Code:
ATTFilter
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-18 21:00:56
-----------------------------
21:00:56.782    OS Version: Windows x64 6.1.7600 
21:00:56.783    Number of processors: 4 586 0x2505
21:00:56.783    ComputerName: EURONICS-VAIO  UserName: Euronics
21:01:00.516    Initialize success
21:01:04.998    AVAST engine defs: 12071700
21:01:32.336    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
21:01:32.337    Disk 0 Vendor: Hitachi_ PB4O Size: 476940MB BusType: 3
21:01:32.339    Disk 1  \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2
21:01:32.341    Disk 1 Vendor: Hitachi_ PB4O Size: 476940MB BusType: 3
21:01:32.383    Disk 0 MBR read successfully
21:01:32.386    Disk 0 MBR scan
21:01:32.390    Disk 0 Windows 7 default MBR code
21:01:32.404    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS        13693 MB offset 2048
21:01:32.424    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 28045312
21:01:32.462    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       463145 MB offset 28250112
21:01:32.500    Disk 0 scanning C:\Windows\system32\drivers
21:01:53.692    Service scanning
21:02:31.337    Modules scanning
21:02:31.671    Disk 0 trace - called modules:
21:02:31.694    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll 
21:02:31.699    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80063a2060]
21:02:31.703    3 CLASSPNP.SYS[fffff88001a3643f] -> nt!IofCallDriver -> [0xfffffa80043416f0]
21:02:31.707    5 ACPI.sys[fffff88000d75781] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800434a050]
21:02:33.444    AVAST engine scan C:\Windows
21:02:39.744    AVAST engine scan C:\Windows\system32
21:07:39.810    AVAST engine scan C:\Windows\system32\drivers
21:07:55.522    AVAST engine scan C:\Users\Euronics
21:11:12.797    Disk 0 MBR has been saved successfully to "C:\Users\Euronics\Desktop\MBR.dat"
21:11:12.804    The log file has been saved successfully to "C:\Users\Euronics\Desktop\aswMBR´2.txt"
         
Grüße

Alt 19.07.2012, 15:00   #28
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 21.07.2012, 11:11   #29
PuritySH
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



Hallo,

habe es nun endlich geschafft die Programme auszuführen. Hätte ich mein Antivir ausstellen sollen? Bei beiden Durchläufen kam folgende Fehlermeldung von Antivir:

Code:
ATTFilter
Avira AntiVir Personal
Erstellungsdatum der Reportdatei: Freitag, 20. Juli 2012  21:32

Es wird nach 3901355 Virenstämmen gesucht.

Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer   : Avira AntiVir Personal - Free Antivirus
Seriennummer   : 0000149996-ADJIE-0000001
Plattform      : Windows 7 x64
Windowsversion : (plain)  [6.1.7600]
Boot Modus     : Normal gebootet
Benutzername   : SYSTEM
Computername   : EURONICS-VAIO

Versionsinformationen:
BUILD.DAT      : 10.2.0.707     36070 Bytes  25.01.2012 12:53:00
AVSCAN.EXE     : 10.3.0.7      484008 Bytes  28.06.2011 17:53:19
AVSCAN.DLL     : 10.0.5.0       57192 Bytes  28.06.2011 17:53:19
LUKE.DLL       : 10.3.0.5       45416 Bytes  28.06.2011 17:53:20
LUKERES.DLL    : 10.0.0.0       13672 Bytes  14.01.2010 09:59:47
AVSCPLR.DLL    : 10.3.0.7      119656 Bytes  28.06.2011 17:53:21
AVREG.DLL      : 10.3.0.9       88833 Bytes  12.07.2011 16:48:55
VBASE000.VDF   : 7.10.0.0    19875328 Bytes  06.11.2009 07:05:36
VBASE001.VDF   : 7.11.0.0    13342208 Bytes  14.12.2010 12:36:27
VBASE002.VDF   : 7.11.19.170 14374912 Bytes  20.12.2011 21:28:19
VBASE003.VDF   : 7.11.21.238  4472832 Bytes  01.02.2012 19:30:19
VBASE004.VDF   : 7.11.26.44   4329472 Bytes  28.03.2012 16:23:47
VBASE005.VDF   : 7.11.34.116  4034048 Bytes  29.06.2012 17:50:24
VBASE006.VDF   : 7.11.34.117     2048 Bytes  29.06.2012 17:50:24
VBASE007.VDF   : 7.11.34.118     2048 Bytes  29.06.2012 17:50:24
VBASE008.VDF   : 7.11.34.119     2048 Bytes  29.06.2012 17:50:24
VBASE009.VDF   : 7.11.34.120     2048 Bytes  29.06.2012 17:50:24
VBASE010.VDF   : 7.11.34.121     2048 Bytes  29.06.2012 17:50:24
VBASE011.VDF   : 7.11.34.122     2048 Bytes  29.06.2012 17:50:24
VBASE012.VDF   : 7.11.34.123     2048 Bytes  29.06.2012 17:50:24
VBASE013.VDF   : 7.11.34.124     2048 Bytes  29.06.2012 17:50:24
VBASE014.VDF   : 7.11.34.201   169472 Bytes  02.07.2012 17:50:24
VBASE015.VDF   : 7.11.35.19    122368 Bytes  04.07.2012 19:33:33
VBASE016.VDF   : 7.11.35.87    146944 Bytes  06.07.2012 16:38:47
VBASE017.VDF   : 7.11.35.143   126464 Bytes  09.07.2012 17:19:59
VBASE018.VDF   : 7.11.35.235   151552 Bytes  12.07.2012 19:15:32
VBASE019.VDF   : 7.11.36.45    118784 Bytes  13.07.2012 19:15:33
VBASE020.VDF   : 7.11.36.107   123904 Bytes  16.07.2012 18:59:34
VBASE021.VDF   : 7.11.36.147   238592 Bytes  17.07.2012 18:59:34
VBASE022.VDF   : 7.11.36.148     2048 Bytes  17.07.2012 18:59:34
VBASE023.VDF   : 7.11.36.149     2048 Bytes  17.07.2012 18:59:34
VBASE024.VDF   : 7.11.36.150     2048 Bytes  17.07.2012 18:59:34
VBASE025.VDF   : 7.11.36.151     2048 Bytes  17.07.2012 18:59:34
VBASE026.VDF   : 7.11.36.152     2048 Bytes  17.07.2012 18:59:34
VBASE027.VDF   : 7.11.36.153     2048 Bytes  17.07.2012 18:59:34
VBASE028.VDF   : 7.11.36.154     2048 Bytes  17.07.2012 18:59:34
VBASE029.VDF   : 7.11.36.155     2048 Bytes  17.07.2012 18:59:34
VBASE030.VDF   : 7.11.36.156     2048 Bytes  17.07.2012 18:59:34
VBASE031.VDF   : 7.11.36.194   102912 Bytes  18.07.2012 18:59:35
Engineversion  : 8.2.10.114
AEVDF.DLL      : 8.1.2.10      102772 Bytes  10.07.2012 17:20:02
AESCRIPT.DLL   : 8.1.4.32      455034 Bytes  05.07.2012 20:18:33
AESCN.DLL      : 8.1.8.2       131444 Bytes  21.03.2012 19:30:26
AESBX.DLL      : 8.2.5.12      606578 Bytes  17.06.2012 21:15:00
AERDL.DLL      : 8.1.9.15      639348 Bytes  11.09.2011 20:05:55
AEPACK.DLL     : 8.3.0.14      807287 Bytes  15.07.2012 19:15:36
AEOFFICE.DLL   : 8.1.2.40      201082 Bytes  28.06.2012 21:46:12
AEHEUR.DLL     : 8.1.4.72     5038455 Bytes  15.07.2012 19:15:35
AEHELP.DLL     : 8.1.23.2      258422 Bytes  28.06.2012 21:46:10
AEGEN.DLL      : 8.1.5.32      434548 Bytes  08.07.2012 16:38:48
AEEXP.DLL      : 8.1.0.62       86389 Bytes  11.07.2012 20:17:00
AEEMU.DLL      : 8.1.3.2       393587 Bytes  10.07.2012 17:20:01
AECORE.DLL     : 8.1.27.2      201078 Bytes  10.07.2012 17:20:01
AEBB.DLL       : 8.1.1.0        53618 Bytes  04.03.2011 12:36:00
AVWINLL.DLL    : 10.0.0.0       19304 Bytes  04.03.2011 12:36:13
AVPREF.DLL     : 10.0.3.2       44904 Bytes  28.06.2011 17:53:19
AVREP.DLL      : 10.0.0.10     174120 Bytes  18.05.2011 08:47:20
AVARKT.DLL     : 10.0.26.1     255336 Bytes  28.06.2011 17:53:19
AVEVTLOG.DLL   : 10.0.0.9      203112 Bytes  28.06.2011 17:53:19
SQLITE3.DLL    : 3.6.19.0      355688 Bytes  17.06.2010 12:27:02
AVSMTP.DLL     : 10.0.0.17      63848 Bytes  04.03.2011 12:36:12
NETNT.DLL      : 10.0.0.0       11624 Bytes  17.06.2010 12:27:01
RCIMAGE.DLL    : 10.0.0.35    2589544 Bytes  28.06.2011 17:53:19
RCTEXT.DLL     : 10.0.64.0      98664 Bytes  28.06.2011 17:53:19

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: avguard_async_scan
Konfigurationsdatei...................: C:\ProgramData\Avira\AntiVir Desktop\TEMP\AVGUARD_50346e3a\guard_slideup.avp
Protokollierung.......................: standard
Primäre Aktion........................: interaktiv
Sekundäre Aktion......................: quarantäne
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: aus
Durchsuche aktive Programme...........: ein
Durchsuche Registrierung..............: aus
Suche nach Rootkits...................: aus
Integritätsprüfung von Systemdateien..: aus
Datei Suchmodus.......................: Alle Dateien
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: vollständig

Beginn des Suchlaufs: Freitag, 20. Juli 2012  21:32

Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'avscan.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'UNS.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'listener.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'plugin-container.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'IAStorDataMgrSvc.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'firefox.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbam.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'RunDll32.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbamgui.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'jusched.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'PMBVolumeWatcher.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'AdobeARM.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'soffice.bin' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'ISBMgr.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'soffice.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'IAStorIcon.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbamservice.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'VCSpt.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'CVHSVC.EXE' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'VESMgrSub.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'DllHost.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'sftlist.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'VESMgr.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'uCamMonitor.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'sftvsa.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'PMBDeviceInfoProvider.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'mysqld.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'LMS.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'ICQ Service.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'avguard.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'sched.exe' - '1' Modul(e) wurden durchsucht

Der Suchlauf über die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{E30DD24C-3942-FD8B-8FEA-295CA49BE026}-jsswnnqxb.exe'
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{E30DD24C-3942-FD8B-8FEA-295CA49BE026}-jsswnnqxb.exe
  [0] Archivtyp: HIDDEN
  --> FIL\\\?\C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{E30DD24C-3942-FD8B-8FEA-295CA49BE026}-jsswnnqxb.exe
      [FUND]      Ist das Trojanische Pferd TR/FakeAV.nfiv

Beginne mit der Desinfektion:
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{E30DD24C-3942-FD8B-8FEA-295CA49BE026}-jsswnnqxb.exe
  [FUND]      Ist das Trojanische Pferd TR/FakeAV.nfiv
  [WARNUNG]   Die Datei wurde ignoriert.


Ende des Suchlaufs: Freitag, 20. Juli 2012  21:32
Benötigte Zeit: 00:06 Minute(n)

Der Suchlauf wurde vollständig durchgeführt.

      0 Verzeichnisse wurden überprüft
     33 Dateien wurden geprüft
      1 Viren bzw. unerwünschte Programme wurden gefunden
      0 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw. unerwünschte Programme wurden repariert
      0 Dateien wurden in die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
     32 Dateien ohne Befall
      0 Archive wurden durchsucht
      1 Warnungen
      0 Hinweise


Die Suchergebnisse werden an den Guard übermittelt.
         
Hier nun der Log von Malware:

Code:
ATTFilter
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.07.21.04

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Euronics :: EURONICS-VAIO [Administrator]

Schutz: Aktiviert

21.07.2012 09:10:29
mbam-log-2012-07-21 (09-10-29).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|Q:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 391010
Laufzeit: 56 Minute(n), 15 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         
Und der von SuperAntispyware:

Code:
ATTFilter
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 07/21/2012 at 12:03 PM

Application Version : 5.5.1006

Core Rules Database Version : 8938
Trace Rules Database Version: 6750

Scan type       : Complete Scan
Total Scan Time : 00:55:29

Operating System Information
Windows 7 Home Premium 64-bit (Build 6.01.7600)
UAC On - Administrator

Memory items scanned      : 834
Memory threats detected   : 0
Registry items scanned    : 66303
Registry threats detected : 0
File items scanned        : 80128
File threats detected     : 484

Adware.Tracking Cookie
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\euronics@adtech[1].txt [ /adtech ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\euronics@adx.chip[2].txt [ /adx.chip ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\euronics@atwola[1].txt [ /atwola ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\euronics@imrworldwide[2].txt [ /imrworldwide ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\euronics@sevenoneintermedia.112.2o7[1].txt [ /sevenoneintermedia.112.2o7 ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\B1ZRGWEQ.txt [ /www.zanox-affiliate.de ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\6KAQ2M10.txt [ /smartadserver.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\KBHIYJY8.txt [ /ru4.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\1ZORBFML.txt [ /zanox-affiliate.de ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\3HJ8R0T5.txt [ /specificclick.net ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\RA7HCIED.txt [ /zanox.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\8FSAZRRK.txt [ /adserv.kwick.de ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\8P9S7A1T.txt [ /www.usenext.de ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\U6LHCM2E.txt [ /webmasterplan.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\JVV5TQEB.txt [ /tradedoubler.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\8EHF9ET1.txt [ /server.adform.net ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\NN3F431S.txt [ /atdmt.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\A0E5P5XP.txt [ /doubleclick.net ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\TABS2DU3.txt [ /tracking.mlsat02.de ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\QX1KZ7VK.txt [ /traffictrack.de ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\BUGFC8FK.txt [ /tracking.quisma.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\PBU149ND.txt [ /questionmarket.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\8T44T119.txt [ /adform.net ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\184SXX0Q.txt [ /yieldmanager.net ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\JU4PL5Z5.txt [ /adbrite.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\HU6DRV5X.txt [ /advertising.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\25H721X4.txt [ /adviva.net ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\9Q49WXH7.txt [ /lucidmedia.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\SZJJGHSY.txt [ /eas.apm.emediate.eu ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\WTB0ZT8B.txt [ /ad1.adfarm1.adition.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\HO4U728W.txt [ /dyntracker.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\4TGDECA3.txt [ /track.adform.net ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\T2W982SX.txt [ /ad.adc-serv.net ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\6P15Z0YW.txt [ /mediaplex.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\OSSQK6N4.txt [ /ad4.adfarm1.adition.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\CCRSU5WR.txt [ /apmebf.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\YP5C3XGY.txt [ /invitemedia.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\VSRYKAWK.txt [ /www.windowsmedia.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\NAYYEX74.txt [ /media6degrees.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\T23YXTUJ.txt [ /microsoftwllivemkt.112.2o7.net ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\M6ZCRQ44.txt [ /snapfish.112.2o7.net ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\ULD9TOIZ.txt [ /serving-sys.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\5AKCAD40.txt [ /ad.123-template.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\7ROSIKU8.txt [ /fastclick.net ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\A8FEEPAX.txt [ /atdmt.combing.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\XZLVQG0L.txt [ /ad.dyntracker.de ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\H7M8UG2J.txt [ /adfarm1.adition.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\95X07YTW.txt [ /ads.creative-serving.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\Q5LJOTYO.txt [ /im.banner.t-online.de ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\9JYXC02P.txt [ /ad2.adfarm1.adition.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\CE0N0VVN.txt [ /content.yieldmanager.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\YASA40GB.txt [ /ad.yieldmanager.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\ZXA1EMV0.txt [ /ad3.adfarm1.adition.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\EOS1U2JR.txt [ /adserver.adtechus.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\OXD107DG.txt [ /counter.hitslink.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\BUS1KO9E.txt [ /ad.zanox.com ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\TV4W2JEN.txt [ /ad.movad.net ]
	C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\13L23KYV.txt [ /ads.audience2media.com ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\AVWSKR4H.txt [ Cookie:euronics@stati.mobilcom-debitel.de/track/ ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\F9360VLE.txt [ Cookie:euronics@specificclick.net/ ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\EB922BGH.txt [ Cookie:euronics@zanox.com/ ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\L3LW61FL.txt [ Cookie:euronics@webmasterplan.com/ ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\C7XED73T.txt [ Cookie:euronics@tradedoubler.com/ ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\L77QTG2V.txt [ Cookie:euronics@atdmt.com/ ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\S0YCPE7Q.txt [ Cookie:euronics@doubleclick.net/ ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\T7SMVAYH.txt [ Cookie:euronics@traffictrack.de/ ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\euronics@statse.webtrendslive[1].txt [ Cookie:euronics@statse.webtrendslive.com/ ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\AOUHS314.txt [ Cookie:euronics@adfarm1.adition.com/ ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\MHQJVG2J.txt [ Cookie:euronics@hightraffic.hugoboss.com/ ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZXJCI0OH.txt [ Cookie:euronics@ad2.adfarm1.adition.com/ ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\CGZMU23L.txt [ Cookie:euronics@yadro.ru/ ]
	C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\WR7H1QVQ.txt [ Cookie:euronics@ad.zanox.com/ ]
	C:\USERS\EURONICS\Cookies\B1ZRGWEQ.txt [ Cookie:euronics@www.zanox-affiliate.de/ ]
	C:\USERS\EURONICS\Cookies\6KAQ2M10.txt [ Cookie:euronics@smartadserver.com/ ]
	C:\USERS\EURONICS\Cookies\KBHIYJY8.txt [ Cookie:euronics@ru4.com/ ]
	C:\USERS\EURONICS\Cookies\1ZORBFML.txt [ Cookie:euronics@zanox-affiliate.de/ ]
	C:\USERS\EURONICS\Cookies\3HJ8R0T5.txt [ Cookie:euronics@specificclick.net/ ]
	C:\USERS\EURONICS\Cookies\RA7HCIED.txt [ Cookie:euronics@zanox.com/ ]
	C:\USERS\EURONICS\Cookies\8FSAZRRK.txt [ Cookie:euronics@adserv.kwick.de/ ]
	C:\USERS\EURONICS\Cookies\U6LHCM2E.txt [ Cookie:euronics@webmasterplan.com/ ]
	C:\USERS\EURONICS\Cookies\JVV5TQEB.txt [ Cookie:euronics@tradedoubler.com/ ]
	C:\USERS\EURONICS\Cookies\8EHF9ET1.txt [ Cookie:euronics@server.adform.net/ ]
	C:\USERS\EURONICS\Cookies\NN3F431S.txt [ Cookie:euronics@atdmt.com/ ]
	C:\USERS\EURONICS\Cookies\euronics@sevenoneintermedia.112.2o7[1].txt [ Cookie:euronics@sevenoneintermedia.112.2o7.net/ ]
	C:\USERS\EURONICS\Cookies\A0E5P5XP.txt [ Cookie:euronics@doubleclick.net/ ]
	C:\USERS\EURONICS\Cookies\TABS2DU3.txt [ Cookie:euronics@tracking.mlsat02.de/tmobile/ ]
	C:\USERS\EURONICS\Cookies\QX1KZ7VK.txt [ Cookie:euronics@traffictrack.de/ ]
	C:\USERS\EURONICS\Cookies\BUGFC8FK.txt [ Cookie:euronics@tracking.quisma.com/ ]
	C:\USERS\EURONICS\Cookies\PBU149ND.txt [ Cookie:euronics@questionmarket.com/ ]
	C:\USERS\EURONICS\Cookies\184SXX0Q.txt [ Cookie:euronics@yieldmanager.net/ ]
	C:\USERS\EURONICS\Cookies\JU4PL5Z5.txt [ Cookie:euronics@adbrite.com/ ]
	C:\USERS\EURONICS\Cookies\HU6DRV5X.txt [ Cookie:euronics@advertising.com/ ]
	C:\USERS\EURONICS\Cookies\9Q49WXH7.txt [ Cookie:euronics@lucidmedia.com/ ]
	C:\USERS\EURONICS\Cookies\SZJJGHSY.txt [ Cookie:euronics@eas.apm.emediate.eu/ ]
	C:\USERS\EURONICS\Cookies\HO4U728W.txt [ Cookie:euronics@dyntracker.com/ ]
	C:\USERS\EURONICS\Cookies\6P15Z0YW.txt [ Cookie:euronics@mediaplex.com/ ]
	C:\USERS\EURONICS\Cookies\OSSQK6N4.txt [ Cookie:euronics@ad4.adfarm1.adition.com/ ]
	C:\USERS\EURONICS\Cookies\CCRSU5WR.txt [ Cookie:euronics@apmebf.com/ ]
	C:\USERS\EURONICS\Cookies\YP5C3XGY.txt [ Cookie:euronics@invitemedia.com/ ]
	C:\USERS\EURONICS\Cookies\VSRYKAWK.txt [ Cookie:euronics@www.windowsmedia.com/ ]
	C:\USERS\EURONICS\Cookies\NAYYEX74.txt [ Cookie:euronics@media6degrees.com/ ]
	C:\USERS\EURONICS\Cookies\T23YXTUJ.txt [ Cookie:euronics@microsoftwllivemkt.112.2o7.net/ ]
	C:\USERS\EURONICS\Cookies\M6ZCRQ44.txt [ Cookie:euronics@snapfish.112.2o7.net/ ]
	C:\USERS\EURONICS\Cookies\ULD9TOIZ.txt [ Cookie:euronics@serving-sys.com/ ]
	C:\USERS\EURONICS\Cookies\A8FEEPAX.txt [ Cookie:euronics@atdmt.combing.com/ ]
	C:\USERS\EURONICS\Cookies\XZLVQG0L.txt [ Cookie:euronics@ad.dyntracker.de/ ]
	C:\USERS\EURONICS\Cookies\euronics@atwola[1].txt [ Cookie:euronics@atwola.com/ ]
	C:\USERS\EURONICS\Cookies\H7M8UG2J.txt [ Cookie:euronics@adfarm1.adition.com/ ]
	C:\USERS\EURONICS\Cookies\Q5LJOTYO.txt [ Cookie:euronics@im.banner.t-online.de/ ]
	C:\USERS\EURONICS\Cookies\9JYXC02P.txt [ Cookie:euronics@ad2.adfarm1.adition.com/ ]
	C:\USERS\EURONICS\Cookies\CE0N0VVN.txt [ Cookie:euronics@content.yieldmanager.com/ak/ ]
	C:\USERS\EURONICS\Cookies\YASA40GB.txt [ Cookie:euronics@ad.yieldmanager.com/ ]
	C:\USERS\EURONICS\Cookies\EOS1U2JR.txt [ Cookie:euronics@adserver.adtechus.com/ ]
	C:\USERS\EURONICS\Cookies\AVWSKR4H.txt [ Cookie:euronics@stati.mobilcom-debitel.de/track/ ]
	C:\USERS\EURONICS\Cookies\BUS1KO9E.txt [ Cookie:euronics@ad.zanox.com/ ]
	C:\USERS\EURONICS\Cookies\13L23KYV.txt [ Cookie:euronics@ads.audience2media.com/ ]
	.smartadserver.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.sonyeurope.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.xiti.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.liveperson.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.liveperson.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adserver.adtechus.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.msnportal.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.robert-half-media.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.robert-half-media.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.e-2dj6wjlyqpdjcgo.stats.esomniture.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.e-2dj6wjliwpajecq.stats.esomniture.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.e-2dj6wnmyeld5clq.stats.esomniture.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	fl01.ct2.comclick.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.e-2dj6wjlocpcpgap.stats.esomniture.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.ice.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.stepstone.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.ru4.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.guj.122.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.domainorganizer.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.yopi.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.komtrack.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.komtrack.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	track.effiliation.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.c.gigcount.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.findojobs.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.findojobs.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.findojobs.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.paypal.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.stats.paypal.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.yadro.ru [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.hansenet.122.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.eyewonder.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	zbox.zanox.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.ru4.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.lucidmedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.server.cpmstar.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	eas4.emediate.eu [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ox-d.w00tmedia.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	wstat.wibiya.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.bs.serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.hairfinder.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.hairfinder.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.hairfinder.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.zieltrack.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad.dyntracker.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	s2.trafficmaxx.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.game-advertising-online.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adviva.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	tracking.gameforge.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adserver.gs [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	s2.trafficmaxx.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.mmoga.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.mmoga.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.interclick.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.interclick.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.interclick.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.solution.weborama.fr [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.tribalfusion.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.mediabrandsww.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserving.versaneeds.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adviva.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.fastclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	tracking.hostgator.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.affiliates.commissionaccount.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.affiliates.commissionaccount.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	stats.justhost.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	pw1.nordclick.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.nordclick.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	counters.gigya.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	uk.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	uk.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adt.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adt.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adt.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adt.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.tto2.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.fastclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.superstats.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ads20.wwe-media.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.ep-solutions.org [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.ep-solutions.org [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.weborama.fr [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.loccitane.solution.weborama.fr [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.loccitane.solution.weborama.fr [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.loccitane.solution.weborama.fr [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.loccitane.solution.weborama.fr [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.sevenoneintermedia.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.tto2.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.layermedia-adserver.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.xm.xtendmedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.kontera.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.mm.chitika.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	stat.dealtime.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.nordclick.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.nordclick.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.kollermedia.at [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.kollermedia.at [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.partypoker.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.partypoker.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	statse.webtrendslive.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver2.clipkit.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.statcounter.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.adreactor.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.moviepilot.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.moviepilot.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	media.gan-online.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.nextag.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.nextag.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.eyewonder.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ads.mikinimedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	track.effiliation.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ads.mikinimedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.secmedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.mitfahrzentrale.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ads.mikinimedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad.zanox.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	in.getclicky.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.microsoftsto.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ads.sealmedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ads.sealmedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ads.sealmedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.zanox-affiliate.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.viewablemedia.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.zanox-affiliate.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.autoscout24.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.www.burstnet.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.gmeurope.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.audiag.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	fl01.ct2.comclick.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	fl01.ct2.comclick.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.statcounter.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adform.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	adserver.bravado.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.zanox-affiliate.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	studivz.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	studivz.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.secmedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.secmedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad.adserver01.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad4.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ww251.smartadserver.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.zanox.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.bs.serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad.zanox.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.fastclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.fastclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad1.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad1.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad2.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	ad3.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
         
Viele Grüße

Janina

Alt 23.07.2012, 12:57   #30
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Security Shield - Virus eingefangen - Standard

Security Shield - Virus eingefangen



Code:
ATTFilter
C:\ProgramData\Microsoft\Windows Defender\LocalCopy
         
Das sind nur Funde in der Q vom Windows-Defender!

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu Security Shield - Virus eingefangen
antivir, auftrag, avira, bho, converter, downloader, error, euro, failed, firefox, firefox 13.0.1, flash player, home, install.exe, logfile, microsoft office starter 2010, mp3, plug-in, realtek, registry, richtlinie, scan, searchscopes, secrets, security, server, software, svchost.exe, symantec, teamspeak, version=1.0, virus, wildtangent games, windows




Ähnliche Themen: Security Shield - Virus eingefangen


  1. Security shield virus
    Plagegeister aller Art und deren Bekämpfung - 05.09.2012 (7)
  2. Security Shield Virus (Ihavenet.redirect)
    Log-Analyse und Auswertung - 16.08.2012 (9)
  3. Security Shield eingefangen
    Log-Analyse und Auswertung - 08.08.2012 (8)
  4. Security Shield eingefangen
    Log-Analyse und Auswertung - 03.08.2012 (35)
  5. Security Shield eingefangen +LOGS (MB-AM,OTL,ESET)
    Log-Analyse und Auswertung - 27.07.2012 (3)
  6. habe mir den Security-shield-Virus eingefangen! Bitte um Hilfe!!
    Log-Analyse und Auswertung - 22.07.2012 (1)
  7. Security Shield Virus - wie werde ich ihn los?
    Plagegeister aller Art und deren Bekämpfung - 04.07.2012 (18)
  8. Security Shield 2012 Virus eingefangen - hier die Logs
    Log-Analyse und Auswertung - 03.07.2012 (3)
  9. Security Shield beim surfen eingefangen. Was tun.
    Plagegeister aller Art und deren Bekämpfung - 28.06.2012 (1)
  10. Security Shield durch Maillink eingefangen!
    Log-Analyse und Auswertung - 24.06.2012 (42)
  11. Security Shield auf dem Laptop (Win XP) eingefangen
    Plagegeister aller Art und deren Bekämpfung - 22.06.2012 (19)
  12. Security shield trojaner eingefangen und Internet nicht mehr funktionsfähig
    Plagegeister aller Art und deren Bekämpfung - 30.05.2012 (1)
  13. Nach Security Shield - Scan sind Kopien meiner Dateien da verursacht von Sec.Shield - Was tun ?
    Log-Analyse und Auswertung - 13.04.2012 (57)
  14. Security shield eingefangen und entfernt, gestern tauchte dann TR/Ransom.Birele.vb auf
    Plagegeister aller Art und deren Bekämpfung - 29.12.2011 (1)
  15. Security Shield - Virus beseitigen
    Log-Analyse und Auswertung - 12.12.2011 (21)
  16. Firefox startet immer mit Proxy und Security Shield eingefangen
    Log-Analyse und Auswertung - 01.08.2011 (23)
  17. My Security Shield Virus: Ist alles weg?
    Plagegeister aller Art und deren Bekämpfung - 30.12.2010 (20)

Zum Thema Security Shield - Virus eingefangen - adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren Downloade Dir bitte AdwCleaner auf deinen Desktop. Starte die adwcleaner.exe mit einem Doppelklick. Klicke auf Search . Nach Ende des Suchlaufs öffnet sich - Security Shield - Virus eingefangen...
Archiv
Du betrachtest: Security Shield - Virus eingefangen auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.