Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Deutsche Bank Trojaner

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 14.10.2010, 07:05   #16
Chris4You
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



Hi,

der Trojaner greift dann wohl auch Passwörter ab, sofort von einem sauberen Rechner aus alle Passwörter ändern...

Bitte packe alle Files unter dem Verzeichnis C:\_OTL und lade das gepackte File dann hier hoch:

Datei hochladen:
http://www.trojaner-board.de/54791-a...ner-board.html

Zur Sicherheit noch:
http://www.trojaner-board.de/59299-a...eb-cureit.html
Nach Beendigung des Scans findes Du das Log unter %USERPROFILE%\DoctorWeb\CureIt.log.
Bevor du irgendwelche Aktionen unternimmst, kopiere bitte den Inhalt des Logs und poste ihn.
Die Log Datei ist sehr groß, ca. über 5MB Text. Benutzt einfach die Suche nach "infiziert" und kopiert betreffende Teile heraus, bevor Du sie postet.

Generell sollte noch so einer Infektion Neuaufgesetzt werden...

chris
__________________
Don't bring me down
Vor dem posten beachten!
Spenden
(Wer spenden will, kann sich gerne melden )

Alt 14.10.2010, 08:58   #17
Burg1
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



Über Nacht wurde auch mein zweiter ebay account gesperrt, da stimmt etwas ganz gewaltig nicht....
__________________


Alt 14.10.2010, 09:05   #18
Burg1
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



OTL zip ist unterwegs.....
__________________

Alt 14.10.2010, 09:31   #19
Chris4You
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



Hi,

denke mal nach, ob Du nach der Infektion auf den Ebayseiten warst...
Leider änder die Malware das Filedatum und gleicht es an die Fileumgebund an, d.h. wenn die Mehrzahl der Files der Windowsinstallation mehrer Jahre alt ist, dann hat die DLL auch dieses Datum...

Lasse bei Virustotal.com diese Datei unbedingt untersuchen:
C:\Windows\System32\IMPLODE.DLL

Die DLL die wir mit OLT erwischt haben ist der Banker bzw. Passwortspy!

Wir prüfen noch auf ein Rootkit (wobei auch CureIT da ganz gut ist)!
TDSS-Killer
Download und Anweisung unter: http://www.trojaner-board.de/82358-t...tml#post640150
Entpacke alle Dateien in einem eigenen Verzeichnis (z. B: C:\TDSS)!
Aufruf über den Explorer duch Doppelklick auf die TDSSKiller.exe.
Nach dem Start erscheint ein Fenster, dort dann "Start Scan".
Wenn der Scan fertig ist bitte "Report" anwählen. Es öffnet sich ein Fenster, den Text abkopieren und hier posten...

chris
__________________
Don't bring me down
Vor dem posten beachten!
Spenden
(Wer spenden will, kann sich gerne melden )

Geändert von Chris4You (14.10.2010 um 09:43 Uhr)

Alt 14.10.2010, 10:03   #20
Burg1
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



Wo Finde ich die Log datei von Cure it? Mein zweiter ebay account wurde gestern Nacht ca. 3 Stunden nachdem ich sämtliche Passwörter geändert hatte und dachte alles sei wieder sauber gesperrt


Alt 14.10.2010, 10:05   #21
Burg1
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



Hier das Ergebnis von virustotal:

File already submitted: The file sent has already been analysed by VirusTotal in the past. This is same basic info regarding the sample itself and its last analysis:

MD5: 0a0324a4282df0f2c3129e5bd84077bc
Date first seen: 2006-09-10 11:50:43 (UTC)
Date last seen: 2010-10-07 11:21:27 (UTC)
Detection ratio: 0/42

What do you wish to do

TDSS Killer findet auch nichts:

2010/10/14 11:10:26.0743 TDSS rootkit removing tool 2.4.4.0 Oct 4 2010 09:06:59
2010/10/14 11:10:26.0743 ================================================================================
2010/10/14 11:10:26.0743 SystemInfo:
2010/10/14 11:10:26.0743
2010/10/14 11:10:26.0743 OS Version: 6.0.6002 ServicePack: 2.0
2010/10/14 11:10:26.0743 Product type: Workstation
2010/10/14 11:10:26.0743 ComputerName: CAROLIN3-PC
2010/10/14 11:10:26.0743 UserName: carolin3
2010/10/14 11:10:26.0743 Windows directory: C:\Windows
2010/10/14 11:10:26.0743 System windows directory: C:\Windows
2010/10/14 11:10:26.0743 Processor architecture: Intel x86
2010/10/14 11:10:26.0743 Number of processors: 2
2010/10/14 11:10:26.0743 Page size: 0x1000
2010/10/14 11:10:26.0743 Boot type: Normal boot
2010/10/14 11:10:26.0743 ================================================================================
2010/10/14 11:10:28.0271 Initialize success
2010/10/14 11:10:31.0563 ================================================================================
2010/10/14 11:10:31.0563 Scan started
2010/10/14 11:10:31.0563 Mode: Manual;
2010/10/14 11:10:31.0563 ================================================================================
2010/10/14 11:10:33.0014 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2010/10/14 11:10:33.0373 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
2010/10/14 11:10:33.0513 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
2010/10/14 11:10:33.0653 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
2010/10/14 11:10:33.0856 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
2010/10/14 11:10:34.0231 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
2010/10/14 11:10:34.0449 AgereSoftModem (5d97943c128ed756d1b0a08302c1b1f8) C:\Windows\system32\DRIVERS\AGRSM.sys
2010/10/14 11:10:35.0057 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2010/10/14 11:10:35.0338 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
2010/10/14 11:10:35.0510 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
2010/10/14 11:10:35.0619 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
2010/10/14 11:10:35.0681 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
2010/10/14 11:10:35.0728 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
2010/10/14 11:10:35.0869 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
2010/10/14 11:10:35.0915 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
2010/10/14 11:10:36.0009 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/10/14 11:10:36.0087 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2010/10/14 11:10:36.0165 ATSWPDRV (69e65a2ce11619f0c868967ca9540b80) C:\Windows\system32\DRIVERS\ATSwpDrv.sys
2010/10/14 11:10:36.0305 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2010/10/14 11:10:36.0415 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
2010/10/14 11:10:36.0508 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2010/10/14 11:10:36.0555 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2010/10/14 11:10:36.0633 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2010/10/14 11:10:36.0695 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2010/10/14 11:10:36.0758 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2010/10/14 11:10:36.0805 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2010/10/14 11:10:36.0867 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2010/10/14 11:10:37.0070 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2010/10/14 11:10:37.0132 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2010/10/14 11:10:37.0241 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
2010/10/14 11:10:37.0335 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2010/10/14 11:10:37.0444 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
2010/10/14 11:10:37.0522 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
2010/10/14 11:10:37.0569 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
2010/10/14 11:10:37.0616 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
2010/10/14 11:10:37.0663 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
2010/10/14 11:10:37.0897 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
2010/10/14 11:10:38.0193 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2010/10/14 11:10:38.0349 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys
2010/10/14 11:10:38.0521 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2010/10/14 11:10:38.0599 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys
2010/10/14 11:10:38.0755 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2010/10/14 11:10:39.0129 DXGKrnl (5c7e2097b91d689ded7a6ff90f0f3a25) C:\Windows\System32\drivers\dxgkrnl.sys
2010/10/14 11:10:39.0363 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
2010/10/14 11:10:39.0566 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2010/10/14 11:10:39.0722 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
2010/10/14 11:10:40.0049 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2010/10/14 11:10:40.0221 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2010/10/14 11:10:40.0471 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
2010/10/14 11:10:40.0798 FETNDIS (b2b2c38e916184ff8523c7439ddd417f) C:\Windows\system32\DRIVERS\fetnd5.sys
2010/10/14 11:10:41.0110 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2010/10/14 11:10:41.0531 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2010/10/14 11:10:42.0093 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/10/14 11:10:42.0343 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2010/10/14 11:10:42.0514 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2010/10/14 11:10:42.0686 FTDIBUS (7c17235845d5ae3fb33ead47b5881521) C:\Windows\system32\drivers\ftdibus.sys
2010/10/14 11:10:42.0857 FTSER2K (678a73f56ddf84a08c31123c386e9967) C:\Windows\system32\drivers\ftser2k.sys
2010/10/14 11:10:43.0107 FWLANUSB (b45f1df1cce34e2af422f0ed78cd70ef) C:\Windows\system32\DRIVERS\fwlanusb.sys
2010/10/14 11:10:43.0357 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
2010/10/14 11:10:43.0606 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
2010/10/14 11:10:43.0731 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/10/14 11:10:43.0871 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2010/10/14 11:10:43.0965 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2010/10/14 11:10:44.0137 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2010/10/14 11:10:44.0215 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
2010/10/14 11:10:44.0339 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2010/10/14 11:10:44.0480 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
2010/10/14 11:10:44.0542 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/10/14 11:10:44.0605 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
2010/10/14 11:10:44.0683 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2010/10/14 11:10:44.0761 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2010/10/14 11:10:44.0807 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2010/10/14 11:10:44.0885 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/10/14 11:10:44.0963 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
2010/10/14 11:10:45.0057 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2010/10/14 11:10:45.0135 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2010/10/14 11:10:45.0182 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
2010/10/14 11:10:45.0244 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/10/14 11:10:45.0291 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2010/10/14 11:10:45.0338 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2010/10/14 11:10:45.0400 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/10/14 11:10:45.0447 kbdhid (d2600cb17b7408b4a83f231dc9a11ac3) C:\Windows\system32\drivers\kbdhid.sys
2010/10/14 11:10:45.0541 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2010/10/14 11:10:45.0650 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2010/10/14 11:10:45.0759 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
2010/10/14 11:10:45.0806 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
2010/10/14 11:10:45.0868 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
2010/10/14 11:10:45.0931 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2010/10/14 11:10:45.0993 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
2010/10/14 11:10:46.0071 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2010/10/14 11:10:46.0133 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2010/10/14 11:10:46.0180 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2010/10/14 11:10:46.0227 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2010/10/14 11:10:46.0289 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2010/10/14 11:10:46.0383 MpFilter (c98301ad8173a2235a9ab828955c32bb) C:\Windows\system32\DRIVERS\MpFilter.sys
2010/10/14 11:10:46.0445 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
2010/10/14 11:10:46.0508 MpNWMon (aeb186afff5d9cfed823c15d846aac3b) C:\Windows\system32\DRIVERS\MpNWMon.sys
2010/10/14 11:10:46.0555 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2010/10/14 11:10:46.0648 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2010/10/14 11:10:46.0711 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2010/10/14 11:10:46.0789 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/10/14 11:10:46.0867 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/10/14 11:10:46.0945 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/10/14 11:10:47.0023 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys
2010/10/14 11:10:47.0085 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
2010/10/14 11:10:47.0163 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2010/10/14 11:10:47.0241 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2010/10/14 11:10:47.0319 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2010/10/14 11:10:47.0413 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/10/14 11:10:47.0491 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2010/10/14 11:10:47.0553 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2010/10/14 11:10:47.0600 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/10/14 11:10:47.0647 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2010/10/14 11:10:47.0709 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2010/10/14 11:10:47.0803 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2010/10/14 11:10:47.0896 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2010/10/14 11:10:47.0959 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/10/14 11:10:48.0037 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/10/14 11:10:48.0099 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/10/14 11:10:48.0177 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2010/10/14 11:10:48.0255 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2010/10/14 11:10:48.0349 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2010/10/14 11:10:48.0551 netr28 (b05ffe38336193a9b988b00b230c5b80) C:\Windows\system32\DRIVERS\netr28.sys
2010/10/14 11:10:48.0661 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2010/10/14 11:10:48.0723 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2010/10/14 11:10:48.0801 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2010/10/14 11:10:48.0926 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2010/10/14 11:10:49.0019 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2010/10/14 11:10:49.0082 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2010/10/14 11:10:49.0597 nvlddmkm (c8cb6135884cbc2a10225c4c3cef0f95) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2010/10/14 11:10:50.0018 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
2010/10/14 11:10:50.0080 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
2010/10/14 11:10:50.0143 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
2010/10/14 11:10:50.0205 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\DRIVERS\ohci1394.sys
2010/10/14 11:10:50.0361 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\DRIVERS\parport.sys
2010/10/14 11:10:50.0455 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2010/10/14 11:10:50.0501 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\DRIVERS\parvdm.sys
2010/10/14 11:10:50.0579 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2010/10/14 11:10:50.0642 pciide (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys
2010/10/14 11:10:50.0704 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2010/10/14 11:10:50.0813 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2010/10/14 11:10:51.0094 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2010/10/14 11:10:51.0172 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
2010/10/14 11:10:51.0281 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2010/10/14 11:10:51.0391 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
2010/10/14 11:10:51.0500 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2010/10/14 11:10:51.0578 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2010/10/14 11:10:51.0718 R300 (e642b131fb74caf4bb8a014f31113142) C:\Windows\system32\DRIVERS\atikmdag.sys
2010/10/14 11:10:51.0859 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2010/10/14 11:10:51.0983 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/10/14 11:10:52.0061 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/10/14 11:10:52.0139 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2010/10/14 11:10:52.0233 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2010/10/14 11:10:52.0436 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/10/14 11:10:52.0529 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
2010/10/14 11:10:52.0639 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2010/10/14 11:10:52.0732 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2010/10/14 11:10:52.0857 RimUsb (c48ed71f500f07a01aa8ac274e144e93) C:\Windows\system32\Drivers\RimUsb.sys
2010/10/14 11:10:52.0951 RimVSerPort (32d6ab810537ce38cbffe04ed9f6709a) C:\Windows\system32\DRIVERS\RimSerial.sys
2010/10/14 11:10:53.0029 ROOTMODEM (75e8a6bfa7374aba833ae92bf41ae4e6) C:\Windows\system32\Drivers\RootMdm.sys
2010/10/14 11:10:53.0138 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2010/10/14 11:10:53.0216 RTL8169 (b8b159fa669c6386a458fcd468ebb1e6) C:\Windows\system32\DRIVERS\Rtlh86.sys
2010/10/14 11:10:53.0325 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2010/10/14 11:10:53.0450 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2010/10/14 11:10:53.0528 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\DRIVERS\serenum.sys
2010/10/14 11:10:53.0621 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\DRIVERS\serial.sys
2010/10/14 11:10:53.0731 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2010/10/14 11:10:53.0824 sffdisk (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys
2010/10/14 11:10:53.0871 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
2010/10/14 11:10:53.0933 sffp_sd (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys
2010/10/14 11:10:53.0980 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2010/10/14 11:10:54.0074 Si3531 (4346d5bbdde7756d8614a3f193d60984) C:\Windows\system32\DRIVERS\Si3531.sys
2010/10/14 11:10:54.0121 SiFilter (e853c341bbf4ac0007a8db0858dbb09d) C:\Windows\system32\DRIVERS\SiWinAcc.sys
2010/10/14 11:10:54.0167 SiRemFil (d80e6f142eb4963e82a8537dd745f51b) C:\Windows\system32\DRIVERS\SiRemFil.sys
2010/10/14 11:10:54.0308 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
2010/10/14 11:10:54.0339 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
2010/10/14 11:10:54.0433 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2010/10/14 11:10:54.0557 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2010/10/14 11:10:54.0635 srv (96a5e2c642af8f591a7366429809506b) C:\Windows\system32\DRIVERS\srv.sys
2010/10/14 11:10:54.0729 srv2 (71da2d64880c97e5ffc3c81761632751) C:\Windows\system32\DRIVERS\srv2.sys
2010/10/14 11:10:54.0823 srvnet (0c5ab1892ae0fa504218db094bf6d041) C:\Windows\system32\DRIVERS\srvnet.sys
2010/10/14 11:10:54.0947 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2010/10/14 11:10:55.0041 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2010/10/14 11:10:55.0088 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2010/10/14 11:10:55.0135 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2010/10/14 11:10:55.0275 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2010/10/14 11:10:55.0369 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2010/10/14 11:10:55.0447 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2010/10/14 11:10:55.0525 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2010/10/14 11:10:55.0587 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2010/10/14 11:10:55.0665 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2010/10/14 11:10:55.0743 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2010/10/14 11:10:55.0868 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/10/14 11:10:55.0961 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2010/10/14 11:10:56.0024 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2010/10/14 11:10:56.0117 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\DRIVERS\uagp35.sys
2010/10/14 11:10:56.0180 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2010/10/14 11:10:56.0305 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
2010/10/14 11:10:56.0351 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
2010/10/14 11:10:56.0398 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2010/10/14 11:10:56.0461 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2010/10/14 11:10:56.0539 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2010/10/14 11:10:56.0648 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/10/14 11:10:56.0710 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2010/10/14 11:10:56.0788 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2010/10/14 11:10:56.0851 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2010/10/14 11:10:56.0944 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
2010/10/14 11:10:57.0007 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
2010/10/14 11:10:57.0147 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
2010/10/14 11:10:57.0256 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/10/14 11:10:57.0365 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/10/14 11:10:57.0506 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
2010/10/14 11:10:57.0646 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/10/14 11:10:57.0709 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2010/10/14 11:10:57.0787 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
2010/10/14 11:10:57.0849 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
2010/10/14 11:10:57.0896 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys
2010/10/14 11:10:57.0958 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2010/10/14 11:10:58.0036 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2010/10/14 11:10:58.0099 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2010/10/14 11:10:58.0177 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
2010/10/14 11:10:58.0270 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2010/10/14 11:10:58.0348 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2010/10/14 11:10:58.0411 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2010/10/14 11:10:58.0504 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
2010/10/14 11:10:58.0582 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2010/10/14 11:10:58.0879 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2010/10/14 11:10:59.0035 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
2010/10/14 11:10:59.0128 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2010/10/14 11:10:59.0269 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2010/10/14 11:10:59.0393 ================================================================================
2010/10/14 11:10:59.0393 Scan finished
2010/10/14 11:10:59.0393 ================================================================================

Alt 14.10.2010, 11:12   #22
Chris4You
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



Hi,

dann müssen wir jetzt mal tiefer graben:

Rootkit Unhooker
Downloade Dir bitte RKUnhookerLE und speichere die Datei auf deinem Desktop.
  • Deaktiviere alle Hintergrundwächter. Besonders den deiner Anti Virensoftware.
  • Starte die RKUnhookerLE.exe
  • Klicke auf den Report Tab und danach auf Scan
  • Setze ein Häckchen bei
    • Drivers
    • Stealth Code
    • Files
    • Code Hooks
    Entferne alle anderen Hacken
  • Wenn Du gefragt wirst welcher Bereich gescannt werden soll, gehe sicher das deine Systemplatte ( meistens C: ) angehackt ist.
  • Klicke OK
  • Wenn der Scan beendet wurde
    File --> Save Report
    klicken.
  • Speichere die Datei als RKU.txt auf dem Desktop.
  • Klicke Close
Hinweis:
Solltest Du folgende Warnung bekommen
Zitat:
"Rootkit Unhooker has detected a parasite inside itself! It is recommended to remove parasite, okay?"
Klicke auf OK

Und Prevx:
Prevx:
Das Tool neigt zu Fehlalarmen und kann in der freien Version auch nichts löschen, ist aber sonst recht gut... (und läuft auch auf 64Bit-Plattformen)
Prevx 3.0 for Home and Family
Falls das Tool was findet, nicht das Log posten sondern einen Screenshot des dann angezeigten Fensters...

Poste auch noch mal ein aktuelles OTL-Log, nicht das sich was neues eingeschlichen hat.
Leider weiss ich nicht, wie schnell EBay reagiert, nicht dass sich die Sperrung auf Aktivitäten vor der Äderung des Passwortes beziehen!

Das Problem bei dieser Art von Malware ist, man weiss nicht was alles geändert wurde, daher wird generell "Neuaufsetzen" empfohlen, besonderst wenn Du Homebanking von dem Rechner aus machst....

chris
__________________
Don't bring me down
Vor dem posten beachten!
Spenden
(Wer spenden will, kann sich gerne melden )

Alt 14.10.2010, 11:43   #23
Burg1
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



Servus, kurze Frage dazu, wie schalte ich die Microsoft Security Essentials temporär ab???

habs schon...

Rootkit läuft schon ziemlich lange, bin mir nicht sicher, obs sich aufgehangen hat....

Alt 14.10.2010, 13:59   #24
Chris4You
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



Hi,

das kann dauern, der durchforstet alles...
Rödelt die Festplatte noch?

chris
__________________
Don't bring me down
Vor dem posten beachten!
Spenden
(Wer spenden will, kann sich gerne melden )

Alt 14.10.2010, 14:48   #25
Burg1
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



War schon fertig, habe dummerweise den Report mit "possible root defection" nicht richtig gespeichert, lasse nochmals scannen...

Alt 14.10.2010, 14:59   #26
Chris4You
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



Hi,

dann hätten wir da was ganz neues am wickel, was weder TDSSKiller noch ComboFix kennt...
Das kann ja heiter werden... ;o)

chris
__________________
Don't bring me down
Vor dem posten beachten!
Spenden
(Wer spenden will, kann sich gerne melden )

Alt 14.10.2010, 16:39   #27
Burg1
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



und hier der log:

RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows Vista
Version 6.0.6002 (Service Pack 2)
Number of processors #2
==============================================
>Drivers
==============================================
0x8E406000 C:\Windows\system32\DRIVERS\nvlddmkm.sys 11567104 bytes (NVIDIA Corporation, NVIDIA Windows Kernel Mode Driver, Version 197.45 )
0x82039000 C:\Windows\system32\ntkrnlpa.exe 3903488 bytes (Microsoft Corporation, NT Kernel & System)
0x82039000 PnpManager 3903488 bytes
0x82039000 RAW 3903488 bytes
0x82039000 WMIxWDM 3903488 bytes
0x97010000 Win32k 2109440 bytes
0x97010000 C:\Windows\System32\win32k.sys 2109440 bytes (Microsoft Corporation, Mehrbenutzer-Win32-Treiber)
0x8A40C000 C:\Windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, NT-Dateisystemtreiber)
0x826BB000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver)
0x8F605000 C:\Windows\system32\DRIVERS\AGRSM.sys 1028096 bytes (Agere Systems, SoftModem Device Driver)
0x8A249000 C:\Windows\System32\drivers\tcpip.sys 958464 bytes (Microsoft Corporation, TCP/IP Driver)
0x804DD000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Codeintegritätsmodul)
0x9CC6B000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver)
0x8FB21000 C:\Windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor)
0x8EF10000 C:\Windows\System32\drivers\dxgkrnl.sys 659456 bytes (Microsoft Corporation, DirectX Graphics Kernel)
0x8F00E000 C:\Windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver)
0x80604000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic)
0x8264A000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0x80413000 C:\Windows\system32\mcupdate_GenuineIntel.dll 458752 bytes (Microsoft Corporation, Intel Microcode Update Library)
0x9C44C000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP-Protokollstapel)
0x8F0B3000 C:\Windows\system32\DRIVERS\netr28.sys 356352 bytes (Ralink Technology, Corp., Ralink 802.11 Wireless Adapter Driver)
0x9CC05000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver)
0x80736000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver)
0x8F523000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x8068D000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI-Treiber für NT)
0x8049C000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver)
0x8F17E000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver)
0x8F492000 C:\Windows\system32\drivers\HdAudio.sys 258048 bytes (Microsoft Corporation, High Definition Audio Function Driver)
0x8A37A000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0x8F5A2000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0x8A20E000 C:\Windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem)
0x9C544000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr)
0x8A51C000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volumeschattenkopie-Treiber)
0x805BD000 C:\Windows\system32\DRIVERS\Si3531.sys 221184 bytes (Silicon Image, Inc, SATA Controller miniport driver)
0x8F44C000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB)
0x82006000 ACPI_HAL 208896 bytes
0x82006000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0x82605000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Dateisystem-Filter-Manager)
0x8F7C5000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver)
0x8F14F000 C:\Windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver)
0x8F4D1000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0x827C6000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider)
0x8F40B000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library)
0x9C405000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver)
0x8FA3B000 C:\Windows\System32\Drivers\fastfat.SYS 163840 bytes (Microsoft Corporation, Fast FAT File System Driver)
0x8A57F000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache)
0x806E4000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT-Plug & Play PCI-Enumerator)
0x9C595000 C:\Windows\System32\DRIVERS\srv2.sys 159744 bytes (Microsoft Corporation, Smb 2.0 Server driver)
0x807D5000 C:\Windows\system32\DRIVERS\SCSIPORT.SYS 155648 bytes (Microsoft Corporation, SCSI Port Driver)
0x8F4FE000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0x8FA63000 C:\Windows\system32\DRIVERS\ATSwpDrv.sys 143360 bytes (AuthenTec, Inc., Slide Fingerprint USB Driver)
0x8F702000 C:\Windows\system32\DRIVERS\MpFilter.sys 143360 bytes (Microsoft Corporation, Microsoft antimalware file system filter driver)
0x8EFD7000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0x8A5B7000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll)
0x9C504000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0x8FA1A000 C:\Windows\System32\Drivers\usbvideo.sys 135168 bytes (Microsoft Corporation, USB Video Class Driver)
0x8F748000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver)
0x9C525000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0x807AD000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension)
0x9C4B9000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver)
0x8A333000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API)
0x8FAFE000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA-Filtertreiber zur Dateivirtualisierung)
0x9C4D6000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver)
0x8F137000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0x9C57D000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector)
0x8F09B000 C:\Windows\system32\DRIVERS\Rtlh86.sys 98304 bytes (Realtek Corporation , Realtek 8101E/8168/8169 NDIS6 32-bit Driver )
0x8F5E8000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver)
0x8F1DF000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0x8FA03000 C:\Windows\system32\DRIVERS\usbccgp.sys 94208 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver)
0x9CD86000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver)
0x8F56B000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS-Paketplaner)
0x8F79B000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver)
0x9C4EF000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver)
0x8A3DB000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager)
0x8FA86000 C:\Windows\system32\DRIVERS\USBSTOR.SYS 86016 bytes (Microsoft Corporation, USB Mass Storage Class Driver)
0x9CD5F000 C:\Windows\system32\DRIVERS\WUDFRd.sys 86016 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Reflector)
0x8A3C7000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0x8F7B1000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver)
0x8F10E000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042-Anschlusstreiber)
0x9C439000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6)
0x8F58F000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0x9CD74000 C:\Windows\system32\DRIVERS\WUDFPf.sys 73728 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver)
0x8A5A6000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver)
0x8F481000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy)
0x80483000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Plattformspezifischer Hardwarefehlertreiber)
0x8A555000 C:\Windows\system32\DRIVERS\uagp35.sys 69632 bytes (Microsoft Corporation, MS AGPv3.5-Filter)
0x82637000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver)
0x8FAA4000 C:\Windows\system32\DRIVERS\HIDCLASS.SYS 65536 bytes (Microsoft Corporation, Hid Class Library)
0x8FBD1000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver)
0x80795000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager)
0x8A3F0000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver)
0x8A36B000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver)
0x8FAEF000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver)
0x8A570000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0x8070B000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver)
0x8A3B8000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0x8EFC8000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0x80727000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver)
0x97250000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver)
0x8F581000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver)
0x8F784000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver)
0x80787000 C:\Windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0x8FAC3000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver)
0x8F1D2000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modemgerätetreiber)
0x8F43F000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator)
0x80680000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR)
0x9CD53000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver)
0x8F73C000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0x8EFB1000 C:\Windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver)
0x8FAD0000 C:\Windows\System32\Drivers\dump_dumpata.sys 45056 bytes
0x8F121000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Tastaturklassentreiber)
0x8F12C000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mausklassentreiber)
0x8F779000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver)
0x8F000000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0x8F1BF000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper)
0x8A34E000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x8EFBD000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0x8071D000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver)
0x8FADB000 C:\Windows\System32\Drivers\dump_msahci.sys 40960 bytes
0x8FAE5000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver)
0x807CB000 C:\Windows\system32\drivers\msahci.sys 40960 bytes (Microsoft Corporation, MS AHCI 1.0 Standard Driver)
0x8F435000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver)
0x9C42F000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver)
0x8F5DE000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy)
0x9CD49000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)
0x8A5D8000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver)
0x8F725000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver)
0x8FA9B000 C:\Windows\system32\DRIVERS\hidusb.sys 36864 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)
0x9CD9C000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0x8F792000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0x97230000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver)
0x8A359000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x8A362000 C:\Windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI)
0x806D3000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0x807A5000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)
0x80494000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver)
0x8FABB000 C:\Windows\system32\DRIVERS\mouhid.sys 32768 bytes (Microsoft Corporation, HID-Mausfiltertreiber)
0x806DC000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver)
0x8F769000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x8F771000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x8F1CA000 C:\Windows\System32\Drivers\RootMdm.sys 32768 bytes (Microsoft Corporation, Legacy Non-Pnp Modem Device Driver)
0x8A566000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor)
0x8F735000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver)
0x8FAB4000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
0x80780000 C:\Windows\system32\drivers\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver)
0x8040C000 C:\Windows\system32\kdcom.dll 28672 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0x8F72E000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver)
0x8F1F6000 C:\Windows\system32\DRIVERS\RimSerial.sys 28672 bytes (Research in Motion Ltd, RIM Virtual Serial Driver)
0x8F10A000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0x8071A000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)
0x82647000 C:\Windows\system32\DRIVERS\SiWinAcc.sys 12288 bytes (Silicon Image, Inc., Windows Accelerator Driver)
0x8EF0E000 C:\Windows\system32\DRIVERS\nvBridge.kmd 8192 bytes (NVIDIA Corporation, NVIDIA Compatible Windows Vista Kernel Mode Driver, Version 197.45 )
0x8A56E000 C:\Windows\system32\DRIVERS\SiRemFil.sys 8192 bytes (Silicon Image, Inc., Filter driver for Silicon Image SATALink controllers.)
0x8F1FD000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0x8F700000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
==============================================
>Stealth
==============================================
==============================================
>Files
==============================================
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0488B.log
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000D.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000D.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000D.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000E.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000E.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000E.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010010.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010010.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010010.wid
!-->[Hidden] C:\ProgramData\Real\setup\config.ini::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{937F86E1-D79A-11DF-906B-0016D38A22B2}.dat
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{E1101821-D79A-11DF-906B-0016D38A22B2}.dat
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\{7C9D5280-D79B-11DF-906B-0016D38A22B2}.dat
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LDS4JA43\favicon[11].ico
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&category=homepage&special=popup&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=3589647142969531012345678 910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&category=homepage&special=popup&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=3926998382235201701234567 8910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&category=homepage&special=popup&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=7964513685799122012345678 910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&special=hp_onsite&adsize=470x60&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=7964513685799122012345678 910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&special=hp_onsite&adsize=790x15&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=7964513685799122012345678 910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&special=rectangle&adsize=310x120&adsize=150x120&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=459251715 38134585012345678910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&special=rectangle&adsize=310x120&adsize=150x120&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=796451368 5799122012345678910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\01_uim_150x85_lieselott[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\1033930600[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\11350702[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\3204271357508080_1[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\60x40_duo[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\60x40_hot14[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\728x90_classfotosearch_DE_0071_a_4_f_0804[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\80[11].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\80[9].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\bg_activeNotificationForm[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\bg_body[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\bg_footer_content_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\bg_tabNavigation_li.currentView[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\bg_tabNavigation_li[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\blank[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\blank[4].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\creativeproxy_uimserv_net[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\creativeproxy_uimserv_net[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\DartRichMedia_1_03[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\ebay_de[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\emailfilter[2].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\france[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\gle&adsize=300x600&adsize=300x250&adsize=310x120&adsize=310x170&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated &tile=39269983822352017012345678910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\homepage[5].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\homepage[6].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\homepage[7].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\ic_activeNotification_close[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\ic_calendar[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\ic_content_anchor[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\ic_pageFunction_printDisabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\index[4].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\index[5].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\index[6].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\logout_hybrid[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\sers;seg=AdvGL3rdP;sz=728x90;ord=1287064568816;dcopt=ist;tile=1;um=7;us=11;eb_trk=133252;pr=22;xp=32;np=22;uz=85625;cg= a65ae2f312b0a47a44607650ff4120e8[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\Sommer_Super_26_40W_100608[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\t11350184[2].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\t11350834[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\track[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\Typo_webde_300x250[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\usenext_koffer_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\11350314[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\3101700957198080_1[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\80[5].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\bg_globalNavigation_li.currentPage[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\blank[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\btnRespond[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\bt_standard[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\calendar-de[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\calendar.utils[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\calendar[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\clown_wahl_60x40[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\freemail_[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\germany[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\getseal[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\GH-ZAM_RedesignSigninEbay_e689i12205587_de_DE_s[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\gradient_body_blue[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\ic_pageFunction_pdfEnabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\n11350834[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\spacer[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\winner[1].png
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\!!d6Zdd!!WM~$(KGrHqUH-D8EtYz6hy5mBLg7HtdlT!~~_0[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\&special=hp_onsite&adsize=790x15&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=3589647142969531012345678 910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\&special=hp_onsite&adsize=790x15&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=3926998382235201701234567 8910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\&special=rectangle&adsize=310x120&params[1].styles=hp_promobox_html%2Chp_promobox_img&tile=45925171538134585012345678910a
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\014_lederjacken[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\050_nachtwaesche[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\077_boxershorts[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\100411_DC_728x90_karte_basis_tag_klein[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\1603587893178080_2[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\80[8].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\badge_copyright_de[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\base[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\bg-tab-laston[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\bg_globalNavigation_a.currentPage[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\client[2].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\creativeproxy_uimserv_net[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\creativeproxy_uimserv_net[2]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\directline_kfz_neu_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\dsize=468x60&content=webde&pageview=ng_outer&adsize=728x90&pageview=loggedin&pageview=no_tprof&pg=m&pa=46&pp=D__85640&p n=3B&bd=0&si=yW6BaXEsb6v2rjquysy_013[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\header_featurenav[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\ic_pageFunction_pdfDisabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\ic_phishingDistractor[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\ic_secondaryNavigation_currentPage[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\ic_sort_up_current[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\img_btn_feedback_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\img_go_button_weiss_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\info_48[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\logout_mb[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\myebaymymessages;sz=728x90;ord=1287049877234;dcopt=ist;tile=1;um=7;us=11;eb_trk=156378;pr=22;xp=32;np=22;uz=85625;cg=a6 5ae2f312b0a47a44607650ff4120e8[1].htmtm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\n11350184[2].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\n11350834[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\overwrite[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\picounter[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\rtm[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\rtm[6].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\rtm[7].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\sitestat[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\Sommer_Super_26_40W_100608[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\viruscheckpage-5.7.2a[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\webde[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\web_de[2].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\white17x17[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\&special=hp_onsite&adsize=790x15&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=4592517153813458501234567 8910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\100827_otto_jacken_728x90_vielfalt[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\100920_webde_targobank_300x250_fbrauch[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\11349064[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\11350702[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\1705284665078080_1[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\183_winterraeder[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\60x40_jewels[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\80[4].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\all-5.7.2a.css;jsessionid=A90304F4366A7FAF585A50CA9E01E652[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\all-5.7.2a.css;jsessionid=DBD9EE84E0AB0B4E773CD584EBC8A6C1[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\all-5.7.2a.js;jsessionid=DBD9EE84E0AB0B4E773CD584EBC8A6C1[1].06310
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\atf;sz=300x250;ord=1287064492693;dcopt=ist;tile=1;um=7;us=11;eb_trk=162278;pr=22;xp=32;np=22;uz=85625;cg=a65ae2f312b0a4 7a44607650ff4120e8[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\autotab[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\background[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\bg_activeNotification[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\bg_pageFunctions_pictured[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\bol_pras_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\btf;sz=300x250;ord=1287064492802;tile=2;um=7;us=11;eb_trk=162279;pr=22;xp=32;np=22;uz=85625;cg=a65ae2f312b0a47a44607650 ff4120e8[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\bt_nextStep[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\bt_teaser[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\client[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\D53F11BF8AED0FA9D89BF10265B66[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\DCC0114CDC254C8EB7F3399B76C72[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\dot_clear[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\freemail_[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\GH-ZAM_RedesignSigninEbay_e689i12205598_1_de_DE[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\gle&adsize=300x600&adsize=300x250&adsize=310x120&adsize=310x170&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated &tile=3589647142969531012345678910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\ic_advice_headline[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\ic_fontsize_sprite[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\ic_logout[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\ic_pageFunction_printEnabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\img_btn_arrow_orange_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\index[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\jquery[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\logoEbay_x45[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\logo_db[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\myebaymymessages;sz=728x90;ord=1287042389517;dcopt=ist;tile=1;um=7;us=11;eb_trk=156378;pr=22;xp=32;np=22;uz=85640;cg=a6 5ae2f312b0a47a44607650ff4120e8[1].htmtm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\myebaymymessages;sz=728x90;ord=1287064534744;dcopt=ist;tile=1;um=7;us=11;eb_trk=156378;pr=22;xp=32;np=22;uz=85625;cg=a6 5ae2f312b0a47a44607650ff4120e8[1].htmtm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\navigator-style.min[2].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\poland[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\SignInApp_SignIn_e689i12186845_de_DE_s[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\stew_60x40[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\t11349866[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\t11349866[2].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\&category=homepage&special=popup&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=4592517153813458501234567 8910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\&special=hp_onsite&adsize=470x60&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=3589647142969531012345678 910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\&special=rectangle&adsize=310x120&params[1].styles=hp_promobox_html%2Chp_promobox_img&tile=39269983822352017012345678910a
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\&special=rectangle&adsize=310x250&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=392699838223520170123456 78910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\&special=rectangle&adsize=310x250&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=796451368579912201234567 8910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\04_uim_60x40_felix[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\05_uim_60x40_blanca[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\100608_mcb_creditplus_01_728x90_webde_dasch[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\100924_150x85_teaser_netbank_mibe[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\1009_otto_stiefel_728x90_preis[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\11349064[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\150x85_pyramidensolitaire[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\2904186654858080_1[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\60x40_knobeln[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\80CAKWRNNN.jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\all-5.7.2a.css;jsessionid=0095EC22DFFFE38D529CBCCBA4909D5C[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\all-5.7.2a.css;jsessionid=DBCC22453CD9E4C5626F2928F4D28D63[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\all-5.7.2a.js;jsessionid=0095EC22DFFFE38D529CBCCBA4909D5C[1].01310
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\all-5.7.2a.js;jsessionid=DBCC22453CD9E4C5626F2928F4D28D63[1].01410
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\background_gradient[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\bg_directLinks[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\bg_h1_login[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\bg_tabNavigation_a.currentView[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\D1A04F32BB6CF3FD20E9F1B6C45E26[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\dsize=468x60&content=webde&pageview=ng_outer&adsize=728x90&pageview=loggedin&pageview=no_tprof&pg=m&pa=46&pp=D__85640&p n=3B&bd=0&si=bCd5pbGcHdVjofj-qZz_016[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\fc_logo_de[1].png
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\framebreaker[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\friendscout2_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\header_trxm_logout_mb_nta[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\homepage[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\homepage[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\HttpErrorPagesScripts[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\ic_advice_list[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\ic_pageFunction_csvBottom_enabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\ic_secondaryNavigation[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\ic_sort_down[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\IE7[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\img_btn_kontakt_txm[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\img_btn_login_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\kicker[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\n11349866[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\rtm[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\sign_maxdome_090430_300x250_2[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\turkiye[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\vw_sharan_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\webde[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\&special=hp_onsite&adsize=470x60&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=4592517153813458501234567 8910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\100809_150x85_teaser_parship_patrick[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\100921_tsr_topvis_etf_xtrackers_v2[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\100930_eteleon_728x90_mibe_final[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\101007_tsr_topvisual_vr_helmutkaiser[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\1503689758308080_2[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\all-5.7.2a.js;jsessionid=A90304F4366A7FAF585A50CA9E01E652[1].06210
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\basic_css_dynamisch[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\bg_activeNotificationContent[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\bg_globalNavigation_li[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\bg_header[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\bg_tabNavigation_a[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\conversion[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\elefant_ind_60x40[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\freemail_[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\ic_addInfo_help[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\ic_loginSticker_de[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\ic_pageFunction_printBottom_enabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\ic_sort_up[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\logoNewVeriSign_100x65[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\n11349866[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\prototype[2].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\red_button[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\rtm[4].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\rtm[7].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\r[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\sgd_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\SignInApp_SignIn_e689i12185480_3_de_DE[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\sprBtnCore[2].png
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\sprpanelcrns[1].png
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\SYS-ZAM_vjo_e689i12205598_1_de_DE[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\s[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\t11350834[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\tableCell[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\white17x17[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\!!d9N8G!CGM~$(KGrHqMOKkUEyO0nijV(BMtYdeO18Q~~_0[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\&special=hp_onsite&adsize=470x60&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=3926998382235201701234567 8910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\&special=rectangle&adsize=310x120&adsize=150x120&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=392699838 22352017012345678910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\&special=rectangle&adsize=310x120&params[1].styles=hp_promobox_html%2Chp_promobox_img&tile=3589647142969531012345678910ab
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\&special=rectangle&adsize=310x120&params[1].styles=hp_promobox_html%2Chp_promobox_img&tile=7964513685799122012345678910ab
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\&special=rectangle&adsize=310x250&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=358964714296953101234567 8910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\&special=rectangle&adsize=310x250&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=459251715381345850123456 78910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\02_uim_60x40_tom[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\03_uim_60x40_emma[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\100811_webde_mobile_android_superbanner_728x90_01A_ahuhn[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\100911_mcb_banner_bos_300x250_erce[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\100924_mcb_banner_netbank_728x90_mibe_webde[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\11350314[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\80[6].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\80[7].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\all-5.7.2a.css;jsessionid=3E37B807810DD0B21F12160552906A52[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\all-5.7.2a.css;jsessionid=AAC798830DD15CA39A6B6EE894644AF0[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\all-5.7.2a.js;jsessionid=3E37B807810DD0B21F12160552906A52[1].01610
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\all-5.7.2a.js;jsessionid=AAC798830DD15CA39A6B6EE894644AF0[1].01610
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\arrow_red[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\badge_author_de[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\bg_globalNavigation_a[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\bg_h1[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\blank[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\bt_confirm[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\bullet[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\client[3].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\eBayISAPI[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\errorpagestrings[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\freemail_[3].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\gle&adsize=300x600&adsize=300x250&adsize=310x120&adsize=310x170&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated &tile=7964513685799122012345678910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\global[2].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\homepage[3].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\homepage[4].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\homepage[5].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\ic_addInfo_list[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\ic_help[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\ic_pageFunction_csvDisabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\ic_pageFunction_pdfBottom_enabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\img[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\img_btn_onlinebanking_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\index[4].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\landing[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\netherland[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\popup3[2].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\romania[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\scripts[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\site=webde&special=icons&category=mail&pp=D__85640&pa=46&pg=m[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\style[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\syntax[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\t11350184[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\tho_ums_081106_ms[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\vistaprint_visitenkarten_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\webde[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\11349436[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\728x90_002[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\80[4].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\badge_contents_de[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\badge_help_de[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\blank[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\BTG-Superbanner-Sale_WEBDE_100830[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\client[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\creativeproxy_uimserv_net[3].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\dcfc[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\dsize=468x60&content=webde&pageview=ng_outer&adsize=728x90&pageview=loggedin&pageview=no_tprof&pg=m&pa=46&pp=D__85640&p n=3B&bd=0&si=9at3oXkXlKN_qBmJ3Ou_013[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\dsize=468x60&content=webde&pageview=ng_outer&adsize=728x90&pageview=loggedin&pageview=no_tprof&pg=m&pa=46&pp=D__85640&p n=3B&bd=0&si=YQBkQV4279uPI4wMzCd_063[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\england[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\epson_wfi_standard_728x90[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\ErrorPageTemplate[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\getseal[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\gle&adsize=300x600&adsize=300x250&adsize=310x120&adsize=310x170&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated &tile=45925171538134585012345678910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\ic_addInfo_onlinebanking[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\ic_error[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\ic_pageFunction_csvEnabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\img_btn_kurseundmaerkte_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\img_btn_produkte_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\logo_db_pbc[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\n11350184[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\planet_neu_60x40[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\position7_motivkarte_specialmoments[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\rtm[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\sers;seg=AdvGL3rdP;sz=728x90;ord=1287064529376;dcopt=ist;tile=1;um=7;us=11;eb_trk=133252;pr=22;xp=32;np=22;uz=85625;cg= a65ae2f312b0a47a44607650ff4120e8[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\tableHead[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\__utm[3].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF3C2C.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF3C32.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF3C81.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF3C87.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF3CB1.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF3CB7.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF69B1.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF7681.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFBE6E.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFC3CE.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFD14A.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFD97.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFD9C.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFDE1.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFDE6.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFE38.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFEF4.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@de.ebayrtm[1].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@ebayrtm[2].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@fussballcup[1].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@gmads[2].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@meine.deutsche-bank[2].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@metalyzer[1].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@newtention[2].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@scorecardresearch[2].txt
!-->[Hidden] C:\Users\carolin3\Documents\LoaderBackup-(2009-09-30).ipd::$DATA
!-->[Hidden] C:\Windows\SoftwareDistribution\DataStore\Logs\tmp.edb
==============================================
>Hooks
==============================================
ntkrnlpa.exe+0x000A87AA, Type: Inline - RelativeJump 0x820E17AA-->820E17B1 [ntkrnlpa.exe]
[1656]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x76501305-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x7653847D-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x76522EF5-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x76538152-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x765210B0-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x7654D639-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x7654D65D-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x7654D4D9-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x7654D5D3-->00000000 [ieframe.dll]
[3544]iexplore.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77B61130-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77B6119C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77B611BC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B61170-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77B6111C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77B61110-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77B61174-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77B611AC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->mswsock.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x6D64123C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll+0x000889B0, Type: Inline - RelativeJump 0x76B989B0-->00000000 [shell32.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x768E125C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateDirectoryW, Type: IAT modification 0x768E13B0-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x768E1460-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateHardLinkW, Type: IAT modification 0x768E11A4-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x768E12E8-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x768E13B4-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x768E132C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x768E1328-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x768E1114-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetBinaryTypeW, Type: IAT modification 0x768E1280-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesA, Type: IAT modification 0x768E1370-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesExW, Type: IAT modification 0x768E14A4-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesW, Type: IAT modification 0x768E13BC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetLongPathNameW, Type: IAT modification 0x768E14EC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileIntW, Type: IAT modification 0x768E1390-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionNamesW, Type: IAT modification 0x768E1164-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionW, Type: IAT modification 0x768E1100-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x768E13A0-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameA, Type: IAT modification 0x768E136C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameW, Type: IAT modification 0x768E1428-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x768E14E0-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x768E1284-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x768E1448-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileExW, Type: IAT modification 0x768E13C0-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x768E130C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->RemoveDirectoryW, Type: IAT modification 0x768E13AC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->ReplaceFileW, Type: IAT modification 0x768E1140-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x768E1384-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x768E124C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->SetFileAttributesW, Type: IAT modification 0x768E13B8-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileSectionW, Type: IAT modification 0x768E1168-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x768E116C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->ntdll.dll-->NtQueryDirectoryFile, Type: IAT modification 0x768E2320-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->user32.dll-->LoadImageW, Type: IAT modification 0x768E1890-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->user32.dll-->PrivateExtractIconsW, Type: IAT modification 0x768E1A6C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->user32.dll-->WinHelpW, Type: IAT modification 0x768E191C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegCloseKey, Type: IAT modification 0x77D5154C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegCreateKeyExW, Type: IAT modification 0x77D51548-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegDeleteKeyW, Type: IAT modification 0x77D51544-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegEnumValueW, Type: IAT modification 0x77D51524-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegOpenKeyExW, Type: IAT modification 0x77D51528-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryInfoKeyW, Type: IAT modification 0x77D51520-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryValueExW, Type: IAT modification 0x77D5152C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->CallNextHookEx, Type: Inline - RelativeJump 0x764F8E3B-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->CreateDialogIndirectParamA, Type: Inline - RelativeJump 0x765126F1-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->CreateDialogIndirectParamW, Type: Inline - RelativeJump 0x76519A62-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->CreateDialogParamA, Type: Inline - RelativeJump 0x765117AA-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->CreateDialogParamW, Type: Inline - RelativeJump 0x764F72A2-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x76501305-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x7653847D-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x76522EF5-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x76538152-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x765210B0-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->EnableWindow, Type: Inline - RelativeJump 0x764FCD8B-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->EndDialog, Type: Inline - RelativeJump 0x7652326E-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->GetAsyncKeyState, Type: Inline - RelativeJump 0x764F863C-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->GetKeyState, Type: Inline - RelativeJump 0x76508CB1-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->IsDialogMessage, Type: Inline - RelativeJump 0x76511847-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->IsDialogMessageW, Type: Inline - RelativeJump 0x76510745-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77D511A8-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77D512B8-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x77D511B4-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77D511B0-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x77D511E4-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x77D511EC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x77D511E8-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x77D51328-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77D51250-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77D5115C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77D512FC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x77D511AC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77D51154-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x77D511D8-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x77D512BC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->keybd_event, Type: Inline - RelativeJump 0x7654D972-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x7654D639-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x7654D65D-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x7654D4D9-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x7654D5D3-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->SendInput, Type: Inline - RelativeJump 0x76522F75-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->SetCursorPos, Type: Inline - RelativeJump 0x76536FB2-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->SetKeyboardState, Type: Inline - RelativeJump 0x76520987-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x764F87AD-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x764F98DB-->00000000 [ieframe.dll]
[3544]iexplore.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x704114B0-->00000000 [IEShims.dll]
[3544]iexplore.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [IEShims.dll]


!!POSSIBLE ROOTKIT ACTIVITY DETECTED!! =)

Alt 14.10.2010, 17:04   #28
Burg1
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



prevx findet eine mögliche Bedrohung, bekomme den screenshot irgendwie nicht hin...

Alt 14.10.2010, 17:08   #29
Burg1
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



und hier der log:

RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows Vista
Version 6.0.6002 (Service Pack 2)
Number of processors #2
==============================================
>Drivers
==============================================
0x8E406000 C:\Windows\system32\DRIVERS\nvlddmkm.sys 11567104 bytes (NVIDIA Corporation, NVIDIA Windows Kernel Mode Driver, Version 197.45 )
0x82039000 C:\Windows\system32\ntkrnlpa.exe 3903488 bytes (Microsoft Corporation, NT Kernel & System)
0x82039000 PnpManager 3903488 bytes
0x82039000 RAW 3903488 bytes
0x82039000 WMIxWDM 3903488 bytes
0x97010000 Win32k 2109440 bytes
0x97010000 C:\Windows\System32\win32k.sys 2109440 bytes (Microsoft Corporation, Mehrbenutzer-Win32-Treiber)
0x8A40C000 C:\Windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, NT-Dateisystemtreiber)
0x826BB000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver)
0x8F605000 C:\Windows\system32\DRIVERS\AGRSM.sys 1028096 bytes (Agere Systems, SoftModem Device Driver)
0x8A249000 C:\Windows\System32\drivers\tcpip.sys 958464 bytes (Microsoft Corporation, TCP/IP Driver)
0x804DD000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Codeintegritätsmodul)
0x9CC6B000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver)
0x8FB21000 C:\Windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor)
0x8EF10000 C:\Windows\System32\drivers\dxgkrnl.sys 659456 bytes (Microsoft Corporation, DirectX Graphics Kernel)
0x8F00E000 C:\Windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver)
0x80604000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic)
0x8264A000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0x80413000 C:\Windows\system32\mcupdate_GenuineIntel.dll 458752 bytes (Microsoft Corporation, Intel Microcode Update Library)
0x9C44C000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP-Protokollstapel)
0x8F0B3000 C:\Windows\system32\DRIVERS\netr28.sys 356352 bytes (Ralink Technology, Corp., Ralink 802.11 Wireless Adapter Driver)
0x9CC05000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver)
0x80736000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver)
0x8F523000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x8068D000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI-Treiber für NT)
0x8049C000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver)
0x8F17E000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver)
0x8F492000 C:\Windows\system32\drivers\HdAudio.sys 258048 bytes (Microsoft Corporation, High Definition Audio Function Driver)
0x8A37A000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0x8F5A2000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0x8A20E000 C:\Windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem)
0x9C544000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr)
0x8A51C000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volumeschattenkopie-Treiber)
0x805BD000 C:\Windows\system32\DRIVERS\Si3531.sys 221184 bytes (Silicon Image, Inc, SATA Controller miniport driver)
0x8F44C000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB)
0x82006000 ACPI_HAL 208896 bytes
0x82006000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0x82605000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Dateisystem-Filter-Manager)
0x8F7C5000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver)
0x8F14F000 C:\Windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver)
0x8F4D1000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0x827C6000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider)
0x8F40B000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library)
0x9C405000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver)
0x8FA3B000 C:\Windows\System32\Drivers\fastfat.SYS 163840 bytes (Microsoft Corporation, Fast FAT File System Driver)
0x8A57F000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache)
0x806E4000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT-Plug & Play PCI-Enumerator)
0x9C595000 C:\Windows\System32\DRIVERS\srv2.sys 159744 bytes (Microsoft Corporation, Smb 2.0 Server driver)
0x807D5000 C:\Windows\system32\DRIVERS\SCSIPORT.SYS 155648 bytes (Microsoft Corporation, SCSI Port Driver)
0x8F4FE000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0x8FA63000 C:\Windows\system32\DRIVERS\ATSwpDrv.sys 143360 bytes (AuthenTec, Inc., Slide Fingerprint USB Driver)
0x8F702000 C:\Windows\system32\DRIVERS\MpFilter.sys 143360 bytes (Microsoft Corporation, Microsoft antimalware file system filter driver)
0x8EFD7000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0x8A5B7000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll)
0x9C504000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0x8FA1A000 C:\Windows\System32\Drivers\usbvideo.sys 135168 bytes (Microsoft Corporation, USB Video Class Driver)
0x8F748000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver)
0x9C525000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0x807AD000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension)
0x9C4B9000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver)
0x8A333000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API)
0x8FAFE000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA-Filtertreiber zur Dateivirtualisierung)
0x9C4D6000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver)
0x8F137000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0x9C57D000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector)
0x8F09B000 C:\Windows\system32\DRIVERS\Rtlh86.sys 98304 bytes (Realtek Corporation , Realtek 8101E/8168/8169 NDIS6 32-bit Driver )
0x8F5E8000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver)
0x8F1DF000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0x8FA03000 C:\Windows\system32\DRIVERS\usbccgp.sys 94208 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver)
0x9CD86000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver)
0x8F56B000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS-Paketplaner)
0x8F79B000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver)
0x9C4EF000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver)
0x8A3DB000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager)
0x8FA86000 C:\Windows\system32\DRIVERS\USBSTOR.SYS 86016 bytes (Microsoft Corporation, USB Mass Storage Class Driver)
0x9CD5F000 C:\Windows\system32\DRIVERS\WUDFRd.sys 86016 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Reflector)
0x8A3C7000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0x8F7B1000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver)
0x8F10E000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042-Anschlusstreiber)
0x9C439000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6)
0x8F58F000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0x9CD74000 C:\Windows\system32\DRIVERS\WUDFPf.sys 73728 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver)
0x8A5A6000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver)
0x8F481000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy)
0x80483000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Plattformspezifischer Hardwarefehlertreiber)
0x8A555000 C:\Windows\system32\DRIVERS\uagp35.sys 69632 bytes (Microsoft Corporation, MS AGPv3.5-Filter)
0x82637000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver)
0x8FAA4000 C:\Windows\system32\DRIVERS\HIDCLASS.SYS 65536 bytes (Microsoft Corporation, Hid Class Library)
0x8FBD1000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver)
0x80795000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager)
0x8A3F0000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver)
0x8A36B000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver)
0x8FAEF000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver)
0x8A570000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0x8070B000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver)
0x8A3B8000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0x8EFC8000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0x80727000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver)
0x97250000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver)
0x8F581000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver)
0x8F784000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver)
0x80787000 C:\Windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0x8FAC3000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver)
0x8F1D2000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modemgerätetreiber)
0x8F43F000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator)
0x80680000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR)
0x9CD53000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver)
0x8F73C000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0x8EFB1000 C:\Windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver)
0x8FAD0000 C:\Windows\System32\Drivers\dump_dumpata.sys 45056 bytes
0x8F121000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Tastaturklassentreiber)
0x8F12C000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mausklassentreiber)
0x8F779000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver)
0x8F000000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0x8F1BF000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper)
0x8A34E000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x8EFBD000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0x8071D000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver)
0x8FADB000 C:\Windows\System32\Drivers\dump_msahci.sys 40960 bytes
0x8FAE5000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver)
0x807CB000 C:\Windows\system32\drivers\msahci.sys 40960 bytes (Microsoft Corporation, MS AHCI 1.0 Standard Driver)
0x8F435000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver)
0x9C42F000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver)
0x8F5DE000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy)
0x9CD49000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)
0x8A5D8000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver)
0x8F725000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver)
0x8FA9B000 C:\Windows\system32\DRIVERS\hidusb.sys 36864 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)
0x9CD9C000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0x8F792000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0x97230000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver)
0x8A359000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x8A362000 C:\Windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI)
0x806D3000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0x807A5000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)
0x80494000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver)
0x8FABB000 C:\Windows\system32\DRIVERS\mouhid.sys 32768 bytes (Microsoft Corporation, HID-Mausfiltertreiber)
0x806DC000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver)
0x8F769000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x8F771000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x8F1CA000 C:\Windows\System32\Drivers\RootMdm.sys 32768 bytes (Microsoft Corporation, Legacy Non-Pnp Modem Device Driver)
0x8A566000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor)
0x8F735000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver)
0x8FAB4000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
0x80780000 C:\Windows\system32\drivers\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver)
0x8040C000 C:\Windows\system32\kdcom.dll 28672 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0x8F72E000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver)
0x8F1F6000 C:\Windows\system32\DRIVERS\RimSerial.sys 28672 bytes (Research in Motion Ltd, RIM Virtual Serial Driver)
0x8F10A000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0x8071A000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)
0x82647000 C:\Windows\system32\DRIVERS\SiWinAcc.sys 12288 bytes (Silicon Image, Inc., Windows Accelerator Driver)
0x8EF0E000 C:\Windows\system32\DRIVERS\nvBridge.kmd 8192 bytes (NVIDIA Corporation, NVIDIA Compatible Windows Vista Kernel Mode Driver, Version 197.45 )
0x8A56E000 C:\Windows\system32\DRIVERS\SiRemFil.sys 8192 bytes (Silicon Image, Inc., Filter driver for Silicon Image SATALink controllers.)
0x8F1FD000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0x8F700000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
==============================================
>Stealth
==============================================
==============================================
>Files
==============================================
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0488B.log
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000D.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000D.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000D.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000E.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000E.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000E.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.wid
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010010.ci
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010010.dir
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010010.wid
!-->[Hidden] C:\ProgramData\Real\setup\config.ini::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{937F86E1-D79A-11DF-906B-0016D38A22B2}.dat
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{E1101821-D79A-11DF-906B-0016D38A22B2}.dat
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\{7C9D5280-D79B-11DF-906B-0016D38A22B2}.dat
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LDS4JA43\favicon[11].ico
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&category=homepage&special=popup&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=3589647142969531012345678 910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&category=homepage&special=popup&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=3926998382235201701234567 8910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&category=homepage&special=popup&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=7964513685799122012345678 910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&special=hp_onsite&adsize=470x60&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=7964513685799122012345678 910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&special=hp_onsite&adsize=790x15&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=7964513685799122012345678 910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&special=rectangle&adsize=310x120&adsize=150x120&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=459251715 38134585012345678910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\&special=rectangle&adsize=310x120&adsize=150x120&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=796451368 5799122012345678910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\01_uim_150x85_lieselott[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\1033930600[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\11350702[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\3204271357508080_1[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\60x40_duo[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\60x40_hot14[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\728x90_classfotosearch_DE_0071_a_4_f_0804[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\80[11].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\80[9].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\bg_activeNotificationForm[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\bg_body[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\bg_footer_content_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\bg_tabNavigation_li.currentView[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\bg_tabNavigation_li[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\blank[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\blank[4].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\creativeproxy_uimserv_net[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\creativeproxy_uimserv_net[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\DartRichMedia_1_03[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\ebay_de[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\emailfilter[2].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\france[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\gle&adsize=300x600&adsize=300x250&adsize=310x120&adsize=310x170&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated &tile=39269983822352017012345678910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\homepage[5].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\homepage[6].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\homepage[7].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\ic_activeNotification_close[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\ic_calendar[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\ic_content_anchor[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\ic_pageFunction_printDisabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\index[4].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\index[5].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\index[6].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\logout_hybrid[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\sers;seg=AdvGL3rdP;sz=728x90;ord=1287064568816;dcopt=ist;tile=1;um=7;us=11;eb_trk=133252;pr=22;xp=32;np=22;uz=85625;cg= a65ae2f312b0a47a44607650ff4120e8[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\Sommer_Super_26_40W_100608[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\t11350184[2].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\t11350834[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\track[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\Typo_webde_300x250[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FOJ3RDR\usenext_koffer_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\11350314[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\3101700957198080_1[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\80[5].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\bg_globalNavigation_li.currentPage[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\blank[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\btnRespond[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\bt_standard[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\calendar-de[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\calendar.utils[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\calendar[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\clown_wahl_60x40[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\freemail_[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\germany[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\getseal[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\GH-ZAM_RedesignSigninEbay_e689i12205587_de_DE_s[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\gradient_body_blue[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\ic_pageFunction_pdfEnabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\n11350834[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\spacer[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4RA92IP8\winner[1].png
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\!!d6Zdd!!WM~$(KGrHqUH-D8EtYz6hy5mBLg7HtdlT!~~_0[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\&special=hp_onsite&adsize=790x15&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=3589647142969531012345678 910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\&special=hp_onsite&adsize=790x15&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=3926998382235201701234567 8910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\&special=rectangle&adsize=310x120&params[1].styles=hp_promobox_html%2Chp_promobox_img&tile=45925171538134585012345678910a
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\014_lederjacken[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\050_nachtwaesche[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\077_boxershorts[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\100411_DC_728x90_karte_basis_tag_klein[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\1603587893178080_2[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\80[8].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\badge_copyright_de[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\base[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\bg-tab-laston[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\bg_globalNavigation_a.currentPage[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\client[2].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\creativeproxy_uimserv_net[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\creativeproxy_uimserv_net[2]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\directline_kfz_neu_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\dsize=468x60&content=webde&pageview=ng_outer&adsize=728x90&pageview=loggedin&pageview=no_tprof&pg=m&pa=46&pp=D__85640&p n=3B&bd=0&si=yW6BaXEsb6v2rjquysy_013[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\header_featurenav[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\ic_pageFunction_pdfDisabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\ic_phishingDistractor[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\ic_secondaryNavigation_currentPage[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\ic_sort_up_current[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\img_btn_feedback_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\img_go_button_weiss_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\info_48[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\logout_mb[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\myebaymymessages;sz=728x90;ord=1287049877234;dcopt=ist;tile=1;um=7;us=11;eb_trk=156378;pr=22;xp=32;np=22;uz=85625;cg=a6 5ae2f312b0a47a44607650ff4120e8[1].htmtm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\n11350184[2].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\n11350834[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\overwrite[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\picounter[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\rtm[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\rtm[6].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\rtm[7].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\sitestat[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\Sommer_Super_26_40W_100608[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\viruscheckpage-5.7.2a[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\webde[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\web_de[2].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ES0QENHB\white17x17[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\&special=hp_onsite&adsize=790x15&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=4592517153813458501234567 8910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\100827_otto_jacken_728x90_vielfalt[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\100920_webde_targobank_300x250_fbrauch[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\11349064[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\11350702[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\1705284665078080_1[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\183_winterraeder[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\60x40_jewels[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\80[4].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\all-5.7.2a.css;jsessionid=A90304F4366A7FAF585A50CA9E01E652[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\all-5.7.2a.css;jsessionid=DBD9EE84E0AB0B4E773CD584EBC8A6C1[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\all-5.7.2a.js;jsessionid=DBD9EE84E0AB0B4E773CD584EBC8A6C1[1].06310
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\atf;sz=300x250;ord=1287064492693;dcopt=ist;tile=1;um=7;us=11;eb_trk=162278;pr=22;xp=32;np=22;uz=85625;cg=a65ae2f312b0a4 7a44607650ff4120e8[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\autotab[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\background[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\bg_activeNotification[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\bg_pageFunctions_pictured[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\bol_pras_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\btf;sz=300x250;ord=1287064492802;tile=2;um=7;us=11;eb_trk=162279;pr=22;xp=32;np=22;uz=85625;cg=a65ae2f312b0a47a44607650 ff4120e8[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\bt_nextStep[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\bt_teaser[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\client[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\D53F11BF8AED0FA9D89BF10265B66[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\DCC0114CDC254C8EB7F3399B76C72[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\dot_clear[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\freemail_[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\GH-ZAM_RedesignSigninEbay_e689i12205598_1_de_DE[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\gle&adsize=300x600&adsize=300x250&adsize=310x120&adsize=310x170&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated &tile=3589647142969531012345678910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\ic_advice_headline[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\ic_fontsize_sprite[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\ic_logout[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\ic_pageFunction_printEnabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\img_btn_arrow_orange_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\index[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\jquery[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\logoEbay_x45[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\logo_db[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\myebaymymessages;sz=728x90;ord=1287042389517;dcopt=ist;tile=1;um=7;us=11;eb_trk=156378;pr=22;xp=32;np=22;uz=85640;cg=a6 5ae2f312b0a47a44607650ff4120e8[1].htmtm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\myebaymymessages;sz=728x90;ord=1287064534744;dcopt=ist;tile=1;um=7;us=11;eb_trk=156378;pr=22;xp=32;np=22;uz=85625;cg=a6 5ae2f312b0a47a44607650ff4120e8[1].htmtm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\navigator-style.min[2].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\poland[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\SignInApp_SignIn_e689i12186845_de_DE_s[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\stew_60x40[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\t11349866[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HP7S16E9\t11349866[2].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\&category=homepage&special=popup&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=4592517153813458501234567 8910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\&special=hp_onsite&adsize=470x60&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=3589647142969531012345678 910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\&special=rectangle&adsize=310x120&params[1].styles=hp_promobox_html%2Chp_promobox_img&tile=39269983822352017012345678910a
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\&special=rectangle&adsize=310x250&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=392699838223520170123456 78910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\&special=rectangle&adsize=310x250&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=796451368579912201234567 8910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\04_uim_60x40_felix[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\05_uim_60x40_blanca[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\100608_mcb_creditplus_01_728x90_webde_dasch[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\100924_150x85_teaser_netbank_mibe[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\1009_otto_stiefel_728x90_preis[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\11349064[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\150x85_pyramidensolitaire[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\2904186654858080_1[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\60x40_knobeln[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\80CAKWRNNN.jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\all-5.7.2a.css;jsessionid=0095EC22DFFFE38D529CBCCBA4909D5C[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\all-5.7.2a.css;jsessionid=DBCC22453CD9E4C5626F2928F4D28D63[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\all-5.7.2a.js;jsessionid=0095EC22DFFFE38D529CBCCBA4909D5C[1].01310
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\all-5.7.2a.js;jsessionid=DBCC22453CD9E4C5626F2928F4D28D63[1].01410
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\background_gradient[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\bg_directLinks[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\bg_h1_login[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\bg_tabNavigation_a.currentView[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\D1A04F32BB6CF3FD20E9F1B6C45E26[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\dsize=468x60&content=webde&pageview=ng_outer&adsize=728x90&pageview=loggedin&pageview=no_tprof&pg=m&pa=46&pp=D__85640&p n=3B&bd=0&si=bCd5pbGcHdVjofj-qZz_016[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\fc_logo_de[1].png
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\framebreaker[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\friendscout2_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\header_trxm_logout_mb_nta[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\homepage[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\homepage[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\HttpErrorPagesScripts[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\ic_advice_list[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\ic_pageFunction_csvBottom_enabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\ic_secondaryNavigation[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\ic_sort_down[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\IE7[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\img_btn_kontakt_txm[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\img_btn_login_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\kicker[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\n11349866[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\rtm[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\sign_maxdome_090430_300x250_2[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\turkiye[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\vw_sharan_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LCPM6ZI7\webde[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\&special=hp_onsite&adsize=470x60&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=4592517153813458501234567 8910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\100809_150x85_teaser_parship_patrick[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\100921_tsr_topvis_etf_xtrackers_v2[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\100930_eteleon_728x90_mibe_final[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\101007_tsr_topvisual_vr_helmutkaiser[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\1503689758308080_2[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\all-5.7.2a.js;jsessionid=A90304F4366A7FAF585A50CA9E01E652[1].06210
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\basic_css_dynamisch[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\bg_activeNotificationContent[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\bg_globalNavigation_li[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\bg_header[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\bg_tabNavigation_a[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\conversion[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\elefant_ind_60x40[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\freemail_[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\ic_addInfo_help[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\ic_loginSticker_de[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\ic_pageFunction_printBottom_enabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\ic_sort_up[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\logoNewVeriSign_100x65[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\n11349866[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\prototype[2].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\red_button[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\rtm[4].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\rtm[7].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\r[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\sgd_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\SignInApp_SignIn_e689i12185480_3_de_DE[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\sprBtnCore[2].png
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\sprpanelcrns[1].png
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\SYS-ZAM_vjo_e689i12205598_1_de_DE[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\s[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\t11350834[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\tableCell[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PGYIUNQY\white17x17[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\!!d9N8G!CGM~$(KGrHqMOKkUEyO0nijV(BMtYdeO18Q~~_0[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\&special=hp_onsite&adsize=470x60&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=3926998382235201701234567 8910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\&special=rectangle&adsize=310x120&adsize=150x120&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=392699838 22352017012345678910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\&special=rectangle&adsize=310x120&params[1].styles=hp_promobox_html%2Chp_promobox_img&tile=3589647142969531012345678910ab
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\&special=rectangle&adsize=310x120&params[1].styles=hp_promobox_html%2Chp_promobox_img&tile=7964513685799122012345678910ab
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\&special=rectangle&adsize=310x250&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=358964714296953101234567 8910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\&special=rectangle&adsize=310x250&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated&tile=459251715381345850123456 78910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\02_uim_60x40_tom[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\03_uim_60x40_emma[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\100811_webde_mobile_android_superbanner_728x90_01A_ahuhn[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\100911_mcb_banner_bos_300x250_erce[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\100924_mcb_banner_netbank_728x90_mibe_webde[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\11350314[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\80[6].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\80[7].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\all-5.7.2a.css;jsessionid=3E37B807810DD0B21F12160552906A52[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\all-5.7.2a.css;jsessionid=AAC798830DD15CA39A6B6EE894644AF0[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\all-5.7.2a.js;jsessionid=3E37B807810DD0B21F12160552906A52[1].01610
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\all-5.7.2a.js;jsessionid=AAC798830DD15CA39A6B6EE894644AF0[1].01610
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\arrow_red[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\badge_author_de[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\bg_globalNavigation_a[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\bg_h1[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\blank[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\bt_confirm[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\bullet[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\client[3].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\eBayISAPI[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\errorpagestrings[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\freemail_[3].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\gle&adsize=300x600&adsize=300x250&adsize=310x120&adsize=310x170&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated &tile=7964513685799122012345678910ab[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\global[2].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\homepage[3].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\homepage[4].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\homepage[5].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\ic_addInfo_list[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\ic_help[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\ic_pageFunction_csvDisabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\ic_pageFunction_pdfBottom_enabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\img[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\img_btn_onlinebanking_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\index[4].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\landing[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\netherland[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\popup3[2].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\romania[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\scripts[1].js
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\site=webde&special=icons&category=mail&pp=D__85640&pa=46&pg=m[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\style[1].css
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\syntax[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\t11350184[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\tho_ums_081106_ms[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\vistaprint_visitenkarten_150x85[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PQOWQBUB\webde[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\11349436[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\728x90_002[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\80[4].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\badge_contents_de[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\badge_help_de[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\blank[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\BTG-Superbanner-Sale_WEBDE_100830[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\client[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\creativeproxy_uimserv_net[3].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\dcfc[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\dsize=468x60&content=webde&pageview=ng_outer&adsize=728x90&pageview=loggedin&pageview=no_tprof&pg=m&pa=46&pp=D__85640&p n=3B&bd=0&si=9at3oXkXlKN_qBmJ3Ou_013[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\dsize=468x60&content=webde&pageview=ng_outer&adsize=728x90&pageview=loggedin&pageview=no_tprof&pg=m&pa=46&pp=D__85640&p n=3B&bd=0&si=YQBkQV4279uPI4wMzCd_063[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\england[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\epson_wfi_standard_728x90[1].swf
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\ErrorPageTemplate[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\getseal[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\gle&adsize=300x600&adsize=300x250&adsize=310x120&adsize=310x170&pageview=ng_outer&pageview=webdehp&pageview=vi_repeated &tile=45925171538134585012345678910a[1]
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\ic_addInfo_onlinebanking[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\ic_error[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\ic_pageFunction_csvEnabled[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\img_btn_kurseundmaerkte_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\img_btn_produkte_txm_2009[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\logo_db_pbc[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\n11350184[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\planet_neu_60x40[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\position7_motivkarte_specialmoments[1].jpg
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\rtm[2].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\sers;seg=AdvGL3rdP;sz=728x90;ord=1287064529376;dcopt=ist;tile=1;um=7;us=11;eb_trk=133252;pr=22;xp=32;np=22;uz=85625;cg= a65ae2f312b0a47a44607650ff4120e8[1].htm
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\tableHead[1].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UI4QJQNE\__utm[3].gif
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF3C2C.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF3C32.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF3C81.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF3C87.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF3CB1.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF3CB7.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF69B1.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DF7681.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFBE6E.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFC3CE.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFD14A.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFD97.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFD9C.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFDE1.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFDE6.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFE38.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Local\Temp\~DFEF4.tmp::$DATA
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@de.ebayrtm[1].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@ebayrtm[2].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@fussballcup[1].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@gmads[2].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@meine.deutsche-bank[2].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@metalyzer[1].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@newtention[2].txt
!-->[Hidden] C:\Users\carolin3\AppData\Roaming\Microsoft\Windows\Cookies\Low\carolin3@scorecardresearch[2].txt
!-->[Hidden] C:\Users\carolin3\Documents\LoaderBackup-(2009-09-30).ipd::$DATA
!-->[Hidden] C:\Windows\SoftwareDistribution\DataStore\Logs\tmp.edb
==============================================
>Hooks
==============================================
ntkrnlpa.exe+0x000A87AA, Type: Inline - RelativeJump 0x820E17AA-->820E17B1 [ntkrnlpa.exe]
[1656]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x76501305-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x7653847D-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x76522EF5-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x76538152-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x765210B0-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x7654D639-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x7654D65D-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x7654D4D9-->00000000 [ieframe.dll]
[1656]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x7654D5D3-->00000000 [ieframe.dll]
[3544]iexplore.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77B61130-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77B6119C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77B611BC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B61170-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77B6111C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77B61110-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77B61174-->00000000 [IEShims.dll]
[3544]iexplore.exe-->gdi32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77B611AC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->mswsock.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x6D64123C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll+0x000889B0, Type: Inline - RelativeJump 0x76B989B0-->00000000 [shell32.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x768E125C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateDirectoryW, Type: IAT modification 0x768E13B0-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x768E1460-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateHardLinkW, Type: IAT modification 0x768E11A4-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x768E12E8-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x768E13B4-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x768E132C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x768E1328-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x768E1114-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetBinaryTypeW, Type: IAT modification 0x768E1280-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesA, Type: IAT modification 0x768E1370-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesExW, Type: IAT modification 0x768E14A4-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesW, Type: IAT modification 0x768E13BC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetLongPathNameW, Type: IAT modification 0x768E14EC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileIntW, Type: IAT modification 0x768E1390-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionNamesW, Type: IAT modification 0x768E1164-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionW, Type: IAT modification 0x768E1100-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x768E13A0-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameA, Type: IAT modification 0x768E136C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameW, Type: IAT modification 0x768E1428-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x768E14E0-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x768E1284-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x768E1448-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileExW, Type: IAT modification 0x768E13C0-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x768E130C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->RemoveDirectoryW, Type: IAT modification 0x768E13AC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->ReplaceFileW, Type: IAT modification 0x768E1140-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x768E1384-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x768E124C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->SetFileAttributesW, Type: IAT modification 0x768E13B8-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileSectionW, Type: IAT modification 0x768E1168-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x768E116C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->ntdll.dll-->NtQueryDirectoryFile, Type: IAT modification 0x768E2320-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->user32.dll-->LoadImageW, Type: IAT modification 0x768E1890-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->user32.dll-->PrivateExtractIconsW, Type: IAT modification 0x768E1A6C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->shell32.dll-->user32.dll-->WinHelpW, Type: IAT modification 0x768E191C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegCloseKey, Type: IAT modification 0x77D5154C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegCreateKeyExW, Type: IAT modification 0x77D51548-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegDeleteKeyW, Type: IAT modification 0x77D51544-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegEnumValueW, Type: IAT modification 0x77D51524-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegOpenKeyExW, Type: IAT modification 0x77D51528-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryInfoKeyW, Type: IAT modification 0x77D51520-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryValueExW, Type: IAT modification 0x77D5152C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->CallNextHookEx, Type: Inline - RelativeJump 0x764F8E3B-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->CreateDialogIndirectParamA, Type: Inline - RelativeJump 0x765126F1-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->CreateDialogIndirectParamW, Type: Inline - RelativeJump 0x76519A62-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->CreateDialogParamA, Type: Inline - RelativeJump 0x765117AA-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->CreateDialogParamW, Type: Inline - RelativeJump 0x764F72A2-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x76501305-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x7653847D-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x76522EF5-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x76538152-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x765210B0-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->EnableWindow, Type: Inline - RelativeJump 0x764FCD8B-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->EndDialog, Type: Inline - RelativeJump 0x7652326E-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->GetAsyncKeyState, Type: Inline - RelativeJump 0x764F863C-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->GetKeyState, Type: Inline - RelativeJump 0x76508CB1-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->IsDialogMessage, Type: Inline - RelativeJump 0x76511847-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->IsDialogMessageW, Type: Inline - RelativeJump 0x76510745-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77D511A8-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77D512B8-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x77D511B4-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77D511B0-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x77D511E4-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x77D511EC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x77D511E8-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x77D51328-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77D51250-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77D5115C-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77D512FC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x77D511AC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77D51154-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x77D511D8-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x77D512BC-->00000000 [IEShims.dll]
[3544]iexplore.exe-->user32.dll-->keybd_event, Type: Inline - RelativeJump 0x7654D972-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x7654D639-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x7654D65D-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x7654D4D9-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x7654D5D3-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->SendInput, Type: Inline - RelativeJump 0x76522F75-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->SetCursorPos, Type: Inline - RelativeJump 0x76536FB2-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->SetKeyboardState, Type: Inline - RelativeJump 0x76520987-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x764F87AD-->00000000 [ieframe.dll]
[3544]iexplore.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x764F98DB-->00000000 [ieframe.dll]
[3544]iexplore.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x704114B0-->00000000 [IEShims.dll]
[3544]iexplore.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [IEShims.dll]


!!POSSIBLE ROOTKIT ACTIVITY DETECTED!! =)

Alt 14.10.2010, 17:11   #30
Burg1
 
Deutsche Bank Trojaner - Standard

Deutsche Bank Trojaner



Häh, wieso ist denn der RKU log zweimal gepostet??? das war ich nicht! Meine Internetverbindung geht auch immer an und wieder aus, aber nur so kurz, dass ich mich nicht neu einloggen muss....Wenn ich das A... erwische, dann gibts aber Saueres, auf die italienische Art!

Geändert von Burg1 (14.10.2010 um 17:19 Uhr)

Antwort

Themen zu Deutsche Bank Trojaner
abfrage, anti-malware, bösartige, dateien, deutsche, deutsche bank, ergebnis, explorer, folge, folgendes, hallo zusammen, malware, microsoft, minute, nicht mehr, programm, service, sobald, tan abfrage, tans, troja, trojane, trojaner, version, verzeichnisse, virenprogramm, vollständiger, zusammen




Ähnliche Themen: Deutsche Bank Trojaner


  1. Deutsche Bank Trojaner fordert 20 TANs an
    Plagegeister aller Art und deren Bekämpfung - 14.12.2014 (9)
  2. Deutsche Bank Trojaner 100 Tan
    Log-Analyse und Auswertung - 12.04.2013 (7)
  3. Deutsche Bank Trojaner fordert 100 Tan´s
    Plagegeister aller Art und deren Bekämpfung - 03.12.2012 (3)
  4. Deutsche Bank Tan Trojaner
    Plagegeister aller Art und deren Bekämpfung - 07.07.2011 (3)
  5. 100 Tan Trojaner Deutsche Bank
    Plagegeister aller Art und deren Bekämpfung - 08.06.2011 (15)
  6. Deutsche Bank 100 TAN Trojaner - Was nun?
    Plagegeister aller Art und deren Bekämpfung - 29.05.2011 (34)
  7. Deutsche Bank Trojaner c:\recycle.bin (Trojan.Spyeyes)
    Plagegeister aller Art und deren Bekämpfung - 20.05.2011 (37)
  8. Deutsche Bank Trojaner, TAN Abfrage
    Plagegeister aller Art und deren Bekämpfung - 24.03.2011 (4)
  9. Deutsche Bank 30 tan trojaner
    Plagegeister aller Art und deren Bekämpfung - 08.01.2011 (22)
  10. Und nochmal Deutsche Bank TAN-Trojaner
    Plagegeister aller Art und deren Bekämpfung - 03.11.2010 (16)
  11. Trojaner deutsche Bank TAN eingeben
    Plagegeister aller Art und deren Bekämpfung - 28.10.2010 (1)
  12. Trojaner Deutsche Bank
    Plagegeister aller Art und deren Bekämpfung - 27.10.2010 (34)
  13. deutsche bank 30 tan trojaner
    Plagegeister aller Art und deren Bekämpfung - 12.10.2010 (6)
  14. 20 TAN Trojaner in Firefox- Deutsche Bank
    Plagegeister aller Art und deren Bekämpfung - 02.10.2010 (4)
  15. Deutsche Bank Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 22.09.2010 (13)
  16. 20 Tan Trojaner Deutsche Bank
    Plagegeister aller Art und deren Bekämpfung - 08.09.2010 (1)
  17. Trojaner? Deutsche Bank will 30 Tans
    Plagegeister aller Art und deren Bekämpfung - 09.08.2010 (10)

Zum Thema Deutsche Bank Trojaner - Hi, der Trojaner greift dann wohl auch Passwörter ab, sofort von einem sauberen Rechner aus alle Passwörter ändern... Bitte packe alle Files unter dem Verzeichnis C:\_OTL und lade das gepackte - Deutsche Bank Trojaner...
Archiv
Du betrachtest: Deutsche Bank Trojaner auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.