Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Schwarzer Desktop, Startmenü verschwunden, Meldung "Festplatte Defekt" (https://www.trojaner-board.de/104743-schwarzer-desktop-startmenue-verschwunden-meldung-festplatte-defekt.html)

Atomfrosch 03.11.2011 15:53

Schwarzer Desktop, Startmenü verschwunden, Meldung "Festplatte Defekt"
 
Hallo zusammen

Gestern Abend gingen spontan 1000 Fenster, die behauptet haben, dass meine Festplatte kaputt sei. War mir direkt klar, dass ich mir irgendwas eingefangen hab. Meinen Taskmanager konnte ich auch nicht mehr benutzen, da irgendwas ihn blockierte.

Direkt mit
Antivir
Spybot
SUPERAntiSpyware
Malwarebytes' Anti-Malware

gescannt, die haben zwar alle was gefunden und mein Taskmanager funktioniert wieder, aber mein Desktop ist immer noch schwarz und meine Startmenüeinträge sind auch verschwunden.

http://www.abload.de/thumb/007nd7gb.jpg

Ich dachte mir "Reparaturmodus"... F8 beim Booten, Dell hat auf meine zweite Partition ein Windowsbackup gelegt. Ar...lecken, da keine Domäne wurde bzw angeblich mein Passwort / Benutzername falsch ist kann ich mich nicht anmelden.


OTL sagt:

Code:

OTL logfile created on: 03.11.2011 14:24:06 - Run 2
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Benedikt\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,93 Gb Available Physical Memory | 64,51% Memory free
6,19 Gb Paging File | 5,10 Gb Available in Paging File | 82,44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138,91 Gb Total Space | 11,25 Gb Free Space | 8,10% Space Free | Partition Type: NTFS
Drive D: | 10,00 Gb Total Space | 5,62 Gb Free Space | 56,25% Space Free | Partition Type: NTFS
 
Computer Name: HERBERT | User Name: Benedikt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011.11.03 12:58:02 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Benedikt\Desktop\OTL.exe
PRC - [2011.10.25 13:38:10 | 000,542,672 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
PRC - [2011.10.17 18:18:23 | 004,615,552 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011.08.12 00:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe
PRC - [2011.07.11 20:51:21 | 000,269,480 | -H-- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.04.30 18:19:56 | 000,136,360 | -H-- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010.11.05 07:58:45 | 000,281,768 | -H-- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.09.06 17:56:38 | 000,247,096 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PRC - [2010.01.14 21:10:53 | 000,076,968 | -H-- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009.05.21 11:14:02 | 001,025,264 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\gs_agent\dsc.exe
PRC - [2009.05.21 11:13:58 | 000,206,064 | -H-- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009.04.10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008.08.14 00:04:44 | 000,201,968 | -H-- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008.06.30 11:28:24 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2008.06.30 11:28:14 | 000,196,608 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2008.06.30 11:28:12 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2008.06.30 11:28:12 | 000,046,376 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2008.06.26 12:10:06 | 000,442,467 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
PRC - [2008.06.26 12:10:00 | 000,221,273 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\stacsv.exe
PRC - [2008.06.26 12:09:50 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\AEstSrv.exe
PRC - [2008.04.28 15:56:28 | 000,161,048 | -H-- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008.01.21 03:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008.01.21 03:23:24 | 000,215,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdSync.exe
PRC - [2007.10.03 14:45:02 | 000,358,936 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007.10.03 14:44:58 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2007.09.02 12:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.exe
PRC - [2003.08.05 09:43:04 | 000,045,056 | R--- | M] (Prolific Technology Inc.) -- C:\Windows\System32\HotFixQ0306270.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.11.03 14:23:06 | 000,063,488 | ---- | M] () -- C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
MOD - [2011.11.03 14:23:06 | 000,052,736 | ---- | M] () -- C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll
MOD - [2011.11.03 12:57:31 | 000,117,760 | ---- | M] () -- C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
MOD - [2011.11.03 12:57:31 | 000,052,224 | ---- | M] () -- C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
MOD - [2010.10.28 08:29:34 | 011,804,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\62dfd8797881fd7a0d0de3f448a18c01\System.Web.ni.dll
MOD - [2010.10.28 08:29:25 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\9b8e883fd5fa51f026577156a0ee9d57\System.Runtime.Remoting.ni.dll
MOD - [2010.10.28 08:23:55 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\88593f5f0fc6de5d5f4a85aa2b1466f3\System.Xml.ni.dll
MOD - [2010.10.28 08:23:38 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d9ab6e29eba6cb0d8459fcbb2c40c1a7\System.Windows.Forms.ni.dll
MOD - [2010.10.28 08:23:27 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\887fa2d6b76e7302b0c664effad4f91f\System.Drawing.ni.dll
MOD - [2010.10.28 08:21:46 | 007,949,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ed6ae2749d12c4729ee43ff339de4bb8\System.ni.dll
MOD - [2010.10.28 08:21:28 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\98bbdd8c400493ad228b8283665cc9da\mscorlib.ni.dll
MOD - [2009.03.29 21:42:14 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll
MOD - [2009.03.29 21:42:14 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll
MOD - [2009.03.29 21:42:12 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2008.05.04 09:42:20 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
MOD - [2008.03.12 06:37:52 | 000,055,808 | ---- | M] () -- C:\Windows\System32\bcmwlrmt.dll
MOD - [2007.09.02 12:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.exe
MOD - [2007.09.02 12:57:36 | 000,069,632 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.10.28 11:02:02 | 001,117,624 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe -- (sdCoreService)
SRV - [2011.10.27 21:49:32 | 000,402,336 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe -- (sdAuxService)
SRV - [2011.10.25 13:38:10 | 000,542,672 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.08.12 00:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2011.07.11 20:51:21 | 000,269,480 | -H-- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.30 18:19:56 | 000,136,360 | -H-- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010.09.06 17:56:38 | 000,247,096 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2009.09.28 14:48:15 | 000,316,664 | -H-- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008.08.22 09:03:20 | 000,016,680 | -H-- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2008.08.14 00:04:44 | 000,201,968 | -H-- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008.06.26 12:10:00 | 000,221,273 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\stacsv.exe -- (STacSV)
SRV - [2008.06.26 12:09:50 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\AEstSrv.exe -- (AESTFilters)
SRV - [2008.04.28 15:56:28 | 000,161,048 | -H-- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV - [2008.01.21 03:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008.01.21 03:23:24 | 000,365,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2008.01.21 03:23:24 | 000,167,936 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2008.01.09 11:30:08 | 000,121,360 | -H-- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2007.10.03 14:45:02 | 000,358,936 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.10.28 11:02:54 | 000,185,560 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\Windows\System32\drivers\PCTSD.sys -- (PCTSD)
DRV - [2011.10.22 15:11:14 | 000,331,880 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2011.10.07 17:52:06 | 000,341,656 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\pctDS.sys -- (pctDS)
DRV - [2011.09.28 13:14:02 | 000,056,840 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PCTBD.sys -- (PCTBD)
DRV - [2011.08.31 17:00:50 | 000,022,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011.07.22 17:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011.07.12 22:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011.07.11 20:51:22 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.07.11 20:51:22 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.09.03 20:40:46 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009.05.21 12:59:12 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2009.05.11 09:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.02.13 11:35:01 | 000,011,608 | -H-- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008.07.30 06:51:30 | 000,277,736 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2008.06.30 11:28:10 | 000,170,032 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2008.06.26 12:10:08 | 000,380,928 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2008.05.04 09:42:18 | 003,548,672 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2008.05.04 09:42:18 | 003,548,672 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2008.05.04 09:42:18 | 003,548,672 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2008.03.14 14:04:26 | 000,054,784 | ---- | M] (ITE Tech. Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\itecir.sys -- (itecir)
DRV - [2008.03.12 06:37:46 | 000,018,424 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bcm42rly.sys -- (BCM42RLY)
DRV - [2008.03.11 07:42:24 | 000,203,264 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\k57nd60x.sys -- (k57nd60x) Broadcom NetLink (TM)
DRV - [2008.03.11 07:24:46 | 000,038,400 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2008.03.11 07:24:44 | 000,046,592 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2008.03.11 07:24:42 | 000,043,008 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2008.01.21 03:23:25 | 000,251,904 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VSTBS23.SYS -- (VSTHWBS2)
DRV - [2008.01.21 03:23:25 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel(R)
DRV - [2007.11.29 01:17:56 | 000,036,368 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2007.11.29 01:17:48 | 000,035,088 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2007.05.11 10:59:00 | 000,017,536 | ---- | M] (Olivetti-Engineering SA) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\desrvusb.sys -- (DESVUSB)
DRV - [2003.10.06 10:29:08 | 000,007,424 | R--- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\plff.sys -- (PLFF)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
 
 
IE - HKU\.DEFAULT\..\URLSearchHook:  - No CLSID value found
IE - HKU\.DEFAULT\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKU\S-1-5-18\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-2775041620-371297593-3811378524-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKU\S-1-5-21-2775041620-371297593-3811378524-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2775041620-371297593-3811378524-1000\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-2775041620-371297593-3811378524-1000\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-2775041620-371297593-3811378524-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2775041620-371297593-3811378524-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0: C:\Program Files\Picasa2\npPicasa2.dll File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2852: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2910: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1662: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Benedikt\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools\PC Tools Security\BDT\Firefox\ [2011.11.02 21:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.10.06 16:18:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.03.21 10:33:49 | 000,000,000 | ---D | M]
 
[2010.04.28 14:13:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Extensions
[2010.04.28 14:13:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009.06.26 12:12:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Extensions\uploadr@flickr.com
[2011.10.24 16:37:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\9gbwpvs7.default\extensions
[2010.04.27 20:10:58 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\9gbwpvs7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.02.16 19:52:59 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\9gbwpvs7.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2009.06.02 19:04:48 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\9gbwpvs7.default\extensions\moveplayer@movenetworks.com
[2011.10.26 18:43:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010.10.04 09:05:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.10.05 19:44:58 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.11.27 21:25:51 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011.02.20 21:36:11 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.06.17 12:56:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011.10.26 18:43:38 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011.10.06 16:18:24 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010.12.09 11:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2011.10.06 16:18:21 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.06 16:18:21 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.10.06 16:18:21 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.06 16:18:21 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.06 16:18:21 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.06 16:18:21 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2010.09.22 17:43:12 | 000,000,057 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKU\S-1-5-21-2775041620-371297593-3811378524-1000\..\Toolbar\WebBrowser: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKU\S-1-5-21-2775041620-371297593-3811378524-1000\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PLFFAP] C:\Windows\System32\HotFixQ0306270.exe (Prolific Technology Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-18..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-2775041620-371297593-3811378524-1000..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKU\S-1-5-21-2775041620-371297593-3811378524-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-2775041620-371297593-3811378524-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2775041620-371297593-3811378524-1000\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-2775041620-371297593-3811378524-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0
O7 - HKU\S-1-5-21-2775041620-371297593-3811378524-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Programs\PartyGaming.Net\PartyPokerNet\RunPF.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Programs\PartyGaming.Net\PartyPokerNet\RunPF.exe ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2D5B2A83-26CD-4993-A422-1070C2D311AA}: DhcpNameServer = 195.50.140.118 195.50.140.248
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F12C023B-96A9-4254-A2BC-45E07E338589}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.11.03 12:58:05 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Benedikt\Desktop\OTL.exe
[2011.11.03 12:57:23 | 000,000,000 | ---D | C] -- C:\Users\Benedikt\AppData\Roaming\SUPERAntiSpyware.com
[2011.11.03 12:56:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011.11.03 12:56:12 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011.11.03 12:56:12 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011.11.03 12:55:33 | 012,837,560 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\Benedikt\Desktop\SUPERAntiSpyware501134.exe
[2011.11.02 22:23:10 | 009,852,544 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\Benedikt\Desktop\mbam-setup-1.51.2.1300.exe
[2011.11.02 22:05:19 | 000,000,000 | ---D | C] -- C:\Users\Benedikt\AppData\Local\Threat Expert
[2011.11.02 21:55:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011.11.02 21:55:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011.11.02 21:55:46 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2011.11.02 21:45:43 | 000,149,456 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2011.11.02 21:45:43 | 000,056,840 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTBD.sys
[2011.11.02 21:45:42 | 002,291,664 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2011.11.02 21:45:42 | 001,681,360 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2011.11.02 21:45:04 | 000,252,840 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2011.11.02 21:45:04 | 000,105,792 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2011.11.02 21:45:00 | 000,017,848 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctBTFix.sys
[2011.11.02 21:45:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2011.11.02 21:44:57 | 000,070,536 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2011.11.02 21:44:50 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools
[2011.11.02 21:41:40 | 000,660,992 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctEFA.sys
[2011.11.02 21:41:40 | 000,341,656 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctDS.sys
[2011.11.02 21:41:35 | 000,331,880 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2011.11.02 21:41:35 | 000,162,584 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2011.11.02 21:41:33 | 000,185,560 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTSD.sys
[2011.11.02 21:41:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2011.11.02 21:41:13 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2011.10.31 13:00:44 | 000,000,000 | -H-D | C] -- C:\Users\Benedikt\AppData\Local\O&O
[2011.10.30 12:24:58 | 000,000,000 | -H-D | C] -- C:\Users\Benedikt\AppData\Local\Downloaded Installations
[2011.10.30 12:14:03 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.10.30 12:14:02 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.10.26 18:43:35 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011.10.26 18:43:35 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011.10.26 18:43:35 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
 
========== Files - Modified Within 30 Days ==========
 
[2011.11.03 14:27:09 | 000,670,946 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.11.03 14:27:09 | 000,631,636 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.11.03 14:27:09 | 000,144,082 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.11.03 14:27:09 | 000,118,262 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.11.03 14:27:07 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2011.11.03 14:25:19 | 000,000,424 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{50F6F6D8-62B8-44EE-8129-9F539D72EE3C}.job
[2011.11.03 14:21:55 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.11.03 14:20:53 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.11.03 14:20:53 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.11.03 14:20:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.11.03 13:34:12 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.11.03 12:58:02 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Benedikt\Desktop\OTL.exe
[2011.11.03 12:57:56 | 000,000,120 | ---- | M] () -- C:\Users\Benedikt\Desktop\UdlzgwzW.htm.part.htm
[2011.11.03 12:56:17 | 000,001,762 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.11.03 12:55:56 | 012,837,560 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\Benedikt\Desktop\SUPERAntiSpyware501134.exe
[2011.11.03 07:32:47 | 000,000,868 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.11.02 22:23:16 | 009,852,544 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\Benedikt\Desktop\mbam-setup-1.51.2.1300.exe
[2011.11.02 21:45:00 | 000,001,911 | ---- | M] () -- C:\Users\Public\Desktop\PC Tools Spyware Doctor.lnk
[2011.11.01 09:59:25 | 000,061,952 | -H-- | M] () -- C:\Users\Benedikt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.10.30 19:59:21 | 000,000,042 | ---- | M] () -- C:\Windows\oodjobd.INI
[2011.10.29 07:50:34 | 000,000,000 | ---- | M] () -- C:\Windows\System32\null
[2011.10.28 11:03:18 | 000,070,536 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2011.10.28 11:02:54 | 000,185,560 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\PCTSD.sys
[2011.10.28 11:01:36 | 000,017,848 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctBTFix.sys
[2011.10.28 10:41:04 | 000,105,792 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2011.10.28 10:40:58 | 000,252,840 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2011.10.25 13:38:20 | 000,149,456 | ---- | M] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2011.10.25 13:38:18 | 002,291,664 | ---- | M] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2011.10.25 13:38:18 | 001,681,360 | ---- | M] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2011.10.25 13:38:08 | 000,767,952 | ---- | M] () -- C:\Windows\BDTSupport.dll
[2011.10.22 15:11:14 | 000,331,880 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2011.10.22 15:11:08 | 000,162,584 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2011.10.07 17:52:12 | 000,660,992 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctEFA.sys
[2011.10.07 17:52:06 | 000,341,656 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctDS.sys
 
========== Files Created - No Company Name ==========
 
[2011.11.03 12:57:53 | 000,000,120 | ---- | C] () -- C:\Users\Benedikt\Desktop\UdlzgwzW.htm.part.htm
[2011.11.03 12:56:17 | 000,001,762 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.11.03 07:32:47 | 000,000,868 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.11.02 21:45:43 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2011.11.02 21:45:43 | 000,000,882 | ---- | C] () -- C:\Windows\RegSDImport.xml
[2011.11.02 21:45:43 | 000,000,879 | ---- | C] () -- C:\Windows\RegISSImport.xml
[2011.11.02 21:45:43 | 000,000,131 | ---- | C] () -- C:\Windows\IDB.zip
[2011.11.02 21:45:42 | 000,003,488 | ---- | C] () -- C:\Windows\UDB.zip
[2011.11.02 21:45:00 | 000,001,911 | ---- | C] () -- C:\Users\Public\Desktop\PC Tools Spyware Doctor.lnk
[2011.10.30 19:59:21 | 000,000,042 | ---- | C] () -- C:\Windows\oodjobd.INI
[2011.05.18 15:07:05 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011.03.16 11:38:37 | 000,000,074 | ---- | C] () -- C:\Windows\FinalAlert2.ini
[2011.01.02 18:37:22 | 000,000,132 | ---- | C] () -- C:\Users\Benedikt\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011.01.01 16:18:49 | 000,000,132 | ---- | C] () -- C:\Users\Benedikt\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2010.11.26 03:15:14 | 000,023,040 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2010.10.30 18:42:03 | 000,001,456 | -H-- | C] () -- C:\Users\Benedikt\AppData\Local\Adobe Für Web speichern 12.0 Prefs
[2010.08.10 13:59:27 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010.08.10 13:59:27 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010.08.10 13:59:27 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010.08.10 13:59:27 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010.08.10 13:59:27 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010.08.07 21:22:11 | 000,016,968 | ---- | C] () -- C:\Windows\System32\drivers\hitmanpro35.sys
[2010.07.04 11:54:11 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010.05.15 16:36:51 | 000,000,122 | ---- | C] () -- C:\Windows\wa.INI
[2010.05.13 19:31:28 | 000,000,113 | ---- | C] () -- C:\Windows\(null)toolkit.ini
[2009.10.29 17:56:18 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.10.29 17:55:21 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.10.29 14:00:01 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009.08.27 12:02:55 | 000,000,144 | ---- | C] () -- C:\Windows\Sierra.ini
[2009.08.13 19:37:07 | 000,000,020 | ---- | C] () -- C:\Windows\mafosav.INI
[2009.06.21 20:12:59 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2009.05.22 16:45:33 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2009.05.22 16:45:22 | 000,007,119 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2009.03.24 10:17:44 | 000,032,256 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2009.02.19 18:25:54 | 000,022,328 | ---- | C] () -- C:\Users\Benedikt\AppData\Roaming\PnkBstrK.sys
[2009.01.18 13:00:13 | 000,149,504 | ---- | C] () -- C:\Windows\UNWISE.EXE
[2008.12.10 15:04:41 | 000,225,256 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2008.11.24 16:51:30 | 000,000,118 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2008.11.21 22:44:16 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll
[2008.10.03 15:33:59 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini
[2008.09.16 01:14:24 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2008.09.12 10:38:02 | 000,010,752 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2008.09.09 15:37:53 | 000,061,952 | -H-- | C] () -- C:\Users\Benedikt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.08.31 20:27:50 | 000,001,461 | ---- | C] () -- C:\Windows\mozver.dat
[2008.08.31 15:28:57 | 000,000,304 | ---- | C] () -- C:\Users\Benedikt\AppData\Roaming\wklnhst.dat
[2008.08.31 15:04:57 | 000,000,018 | ---- | C] () -- C:\Windows\wininit.ini
[2008.08.31 14:44:51 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008.08.31 14:37:02 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2008.08.31 10:41:04 | 000,001,356 | -H-- | C] () -- C:\Users\Benedikt\AppData\Local\d3d9caps.dat
[2008.08.22 18:32:09 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2008.08.22 18:32:09 | 000,168,883 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2008.08.22 18:32:09 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008.08.22 18:32:09 | 000,090,112 | ---- | C] () -- C:\Windows\System32\atibrtmon.exe
[2008.08.22 10:38:23 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2008.08.22 08:56:25 | 000,055,808 | ---- | C] () -- C:\Windows\System32\bcmwlrmt.dll
[2008.08.22 08:56:25 | 000,024,064 | ---- | C] () -- C:\Windows\System32\WLTRYSVC.EXE
[2008.01.21 08:15:58 | 000,670,946 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008.01.21 08:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008.01.21 08:15:58 | 000,144,082 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008.01.21 08:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2007.06.06 07:32:00 | 000,002,699 | ---- | C] () -- C:\Windows\System32\d1wiaUiStr.bin
[2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:47:37 | 004,173,840 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 11:33:01 | 000,631,636 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,118,262 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2000.02.09 23:00:00 | 000,047,104 | ---- | C] () -- C:\Windows\System32\wrkgadm.exe
[2000.02.09 23:00:00 | 000,012,288 | ---- | C] () -- C:\Windows\System32\HLINKPRX.DLL
[1996.04.03 20:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 170 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84

< End of report >

Ich hoffe ihr könnt mir helfen.

cosinus 03.11.2011 15:57

Zitat:

Antivir
Spybot
SUPERAntiSpyware
Malwarebytes' Anti-Malware

gescannt, die haben zwar alle was gefunden und mein Taskmanager funktioniert wieder,
Würdest du dann auch bitte alle Logs von diesen eingesetzten Tools posten?

Atomfrosch 03.11.2011 16:04

SuperAntiSpyware:

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 11/03/2011 at 01:54 PM

Application Version : 5.0.1134

Core Rules Database Version : 7890
Trace Rules Database Version: 5702

Scan type      : Complete Scan
Total Scan Time : 00:54:59

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC Off - Administrator

Memory items scanned      : 704
Memory threats detected  : 0
Registry items scanned    : 37642
Registry threats detected : 0
File items scanned        : 54250
File threats detected    : 955

Adware.Tracking Cookie
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@ad.yieldmanager[2].txt [ /ad.yieldmanager ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@ad1.adfarm.adtelligence[2].txt [ /ad1.adfarm.adtelligence ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@ad1.adfarm1.adition[2].txt [ /ad1.adfarm1.adition ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@ad2.adfarm1.adition[2].txt [ /ad2.adfarm1.adition ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@adfarm1.adition[2].txt [ /adfarm1.adition ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@ads.creative-serving[2].txt [ /ads.creative-serving ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@ads.pubmatic[1].txt [ /ads.pubmatic ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@adtech[1].txt [ /adtech ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@adx.chip[2].txt [ /adx.chip ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@apmebf[1].txt [ /apmebf ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@atdmt.combing[1].txt [ /atdmt.combing ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@atdmt[1].txt [ /atdmt ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@atwola[2].txt [ /atwola ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@bs.serving-sys[2].txt [ /bs.serving-sys ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@content.yieldmanager[2].txt [ /content.yieldmanager ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@content.yieldmanager[3].txt [ /content.yieldmanager ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@doubleclick[2].txt [ /doubleclick ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@eyewonder[2].txt [ /eyewonder ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@fastclick[1].txt [ /fastclick ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@imrworldwide[2].txt [ /imrworldwide ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@invitemedia[2].txt [ /invitemedia ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@mediaplex[1].txt [ /mediaplex ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@microsoftwllivemkt.112.2o7[1].txt [ /microsoftwllivemkt.112.2o7 ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@questionmarket[2].txt [ /questionmarket ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@revsci[1].txt [ /revsci ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@serving-sys[2].txt [ /serving-sys ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@sevenoneintermedia.112.2o7[1].txt [ /sevenoneintermedia.112.2o7 ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@smartadserver[1].txt [ /smartadserver ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@tracking.quisma[2].txt [ /tracking.quisma ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@tradedoubler[1].txt [ /tradedoubler ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@www.active-tracking[1].txt [ /www.active-tracking ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@xiti[1].txt [ /xiti ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@yadro[2].txt [ /yadro ]
        C:\USERS\BENEDIKT\Cookies\benedikt@content.yieldmanager[3].txt [ Cookie:benedikt@content.yieldmanager.com/ak/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@atdmt.combing[1].txt [ Cookie:benedikt@atdmt.combing.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@xiti[1].txt [ Cookie:benedikt@xiti.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@adtech[1].txt [ Cookie:benedikt@adtech.de/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@eyewonder[2].txt [ Cookie:benedikt@eyewonder.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@content.yieldmanager[2].txt [ Cookie:benedikt@content.yieldmanager.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@mediaplex[1].txt [ Cookie:benedikt@mediaplex.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@adx.chip[2].txt [ Cookie:benedikt@adx.chip.de/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@bs.serving-sys[2].txt [ Cookie:benedikt@bs.serving-sys.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@www.active-tracking[1].txt [ Cookie:benedikt@www.active-tracking.de/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@tradedoubler[1].txt [ Cookie:benedikt@tradedoubler.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@ad2.adfarm1.adition[2].txt [ Cookie:benedikt@ad2.adfarm1.adition.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@adfarm1.adition[2].txt [ Cookie:benedikt@adfarm1.adition.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@yadro[2].txt [ Cookie:benedikt@yadro.ru/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@microsoftwllivemkt.112.2o7[1].txt [ Cookie:benedikt@microsoftwllivemkt.112.2o7.net/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@serving-sys[2].txt [ Cookie:benedikt@serving-sys.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@revsci[1].txt [ Cookie:benedikt@revsci.net/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@doubleclick[2].txt [ Cookie:benedikt@doubleclick.net/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@ad.yieldmanager[2].txt [ Cookie:benedikt@ad.yieldmanager.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@smartadserver[1].txt [ Cookie:benedikt@smartadserver.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@invitemedia[2].txt [ Cookie:benedikt@invitemedia.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@apmebf[1].txt [ Cookie:benedikt@apmebf.com/ ]
        ia.media-imdb.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\W7KWBK5V ]
        media.adxpansion.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\W7KWBK5V ]
        media.rockstargames.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\W7KWBK5V ]
        secure-uk.imrworldwide.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\W7KWBK5V ]
        www.adservercentral.info [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\W7KWBK5V ]
        .im.banner.t-online.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .gostats.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .usenext.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.cheapfinders.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.adultshop.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .mm.chitika.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        in.getclicky.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adserver.adtechus.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .trafficmp.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .indieclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adtechus.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .twittercounter.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .twittercounter.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .googleads.g.doubleclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .getclicky.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .static.getclicky.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .mtvn.112.2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .rambler.ru [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .rambler.ru [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .rambler.ru [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        stat.onestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        stat.onestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .harrenmedianetwork.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        track.webtrekk.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        uk.sitestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        uk.sitestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        stat.onestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .trafficmp.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .trafficmp.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .trafficmp.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.medianord.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        sso-de.bestofmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .content.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .associatedcontent.112.2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .frontlinegmbh.122.2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        s2.netxmedia.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        s2.netxmedia.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        s2.netxmedia.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .komtrack.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .traffichaus.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads2.zeusclicks.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        testfindweb.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        testfindweb.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        testfindweb.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        testfindweb.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        testfindweb.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        testfindweb.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .teenbff.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads.zeusclicks.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        pornografish.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.gwarez.cc [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.mobile.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .socialmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .zieltrack.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.star-advertising.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.star-advertising.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webstats4u.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .philips.112.2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .msnportal.112.2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .azjmp.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .azjmp.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .trafficmp.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .trafficmp.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.gwarez.cc [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.gwarez.cc [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        wstat.wibiya.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        imagevenue.advertserve.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        imagevenue.advertserve.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .accounts.spartzmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        gotacha.rotator.hadj7.adjuggler.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        gotacha.rotator.hadj7.adjuggler.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        optimize.indieclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        optimize.indieclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .www.traffictrack.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        f.blogads.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .deutschepostag.112.2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        s09.flagcounter.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        d.mediadakine.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .warezslavez.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .www.warezslavez.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        toi-rvp-ticker-01.odmedia.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.porntv.bz [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .banners.bookofsex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.sim-technik.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        adserv.legitreviews.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.cheapfinders.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        toi-rvp-ticker-01.odmedia.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        toi-rvp-ticker-01.odmedia.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .myclickfind.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .myclickfind.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adnetxchange.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .sexxxdoll.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .sexxxdoll.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        r2.unicornmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .komtrack.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .s1.tldadserv.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .s1.tldadserv.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        adserv.kwick.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        adserv.kwick.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        adserver.pc-cooling.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6ael4ukd5eho.stats.esomniture.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .homairvacances.solution.weborama.fr [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .homairvacances.solution.weborama.fr [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .homairvacances.solution.weborama.fr [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .homairvacances.solution.weborama.fr [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        static.freewebs.getclicky.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ar.atwola.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .gametracker.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        zbox.zanox.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .247realmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        track.webtrekk.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        4fuckr.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        sextasytube.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .toplist.eu [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .toplist.sk [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        sextasytube.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .xm.xtendmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .bedavasexizle.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .bedavasexizle.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .bedavasexizle.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .freeyouporn.org [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .freeyouporn.org [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .legsex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .legsex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .porntube.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        1xxx.cqcounter.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www4.addfreestats.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .freeporn.hu [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .freeporn.hu [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .novoporn.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .novoporn.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .www.mediaversand.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        stats.internet-yadro.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        media-mgmt.armorgames.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .server.cpmstar.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .server.cpmstar.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .server.cpmstar.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .cdn.complexmedianetwork.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .cdn.complexmedianetwork.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .viewablemedia.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .stats.complex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .stats.complex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        adserver.adreactor.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        s03.flagcounter.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .myroitracking.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .xxxmsncam.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .xxxmsncam.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        traffic.tcmagnet.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        traffic.tcmagnet.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .porntube.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .porntube.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .girlsteachsex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adxpansion.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .realgfporn.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .realgfporn.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.mediahitmetrics.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adultadworld.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adultadworld.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .de.partypoker.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .sexyandshocking.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .sexyandshocking.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .sexyclips.org [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .sexyclips.org [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        delivery.trafficbroker.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adnetxchange.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .pornoeye.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .pornoeye.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .xxxprivates.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .xxxprivates.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .toplist.cz [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.star-advertising.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        globalgroup.missioncontrol.global-media.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.tldadserv.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .18clicks.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.adservercentral.info [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        fidelity.rotator.hadj7.adjuggler.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        fidelity.rotator.hadj7.adjuggler.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .track.gridlockparadise.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .track.gridlockparadise.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .homemadecelebrityporn.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .homemadecelebrityporn.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        hollywood-naked.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        hollywood-naked.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        hollywood-naked.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .warnerbros.112.2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.adultrevads.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        adserver.bremen.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        optimize.indieclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        optimize.indieclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .indieclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        optimize.indieclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        toplisted.us [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        warez-load.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.pornbb.org [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .banners.bookofsex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .banners.bookofsex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .banners.bookofsex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .banners.bookofsex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .banners.bookofsex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        frankwalder.traffective-tracking.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        frankwalder.traffective-tracking.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        frankwalder.traffective-tracking.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        frankwalder.traffective-tracking.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        frankwalder.traffective-tracking.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .exoclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.crakmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        tracking.hostgator.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        adserver2.exgfnetwork.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.star-advertising.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.star-advertising.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.crakmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adxpansion.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .exoclick.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .trinitymirror.112.2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        stats.computecmedia.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.usenext.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        adserv.adservercentral.info [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.adservercentral.info [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ads.crakmedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        sales.liveperson.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        stats.computecmedia.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        view.advert-layer.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        view.advert-layer.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .advert-layer.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .advert-layer.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .advert-layer.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .track.webgains.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .track.webgains.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .komtrack.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .komtrack.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        teufel-media.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        delivery.way2traffic.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        stats.computecmedia.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad1.dyntracker.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        dc.tremormedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .4fuckr.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        adserver.gunaxin.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        4fuckr.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .4fuckr.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .4fuckr.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .4fuckr.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        delivery.way2traffic.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        delivery.way2traffic.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        delivery.way2traffic.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracker.icerocket.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracker.icerocket.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .googleads.g.doubleclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\BENEDIKT@MYROITRACKING[1].TXT [ /MYROITRACKING ]

Malwarebytes 1

Code:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8072

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

02.11.2011 22:31:31
mbam-log-2011-11-02 (22-31-31).txt

Art des Suchlaufs: Flash-Scan
Durchsuchte Objekte: 132049
Laufzeit: 1 Minute(n), 20 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 2
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Malwarebytes 2

Code:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8074

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

03.11.2011 09:47:47
mbam-log-2011-11-03 (09-47-47).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 345961
Laufzeit: 1 Stunde(n), 54 Minute(n), 31 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\Qoobox\quarantine\C\Users\Benedikt\AppData\Roaming\Ywylag\tawa.exe.vir (Trojan.FraudLoad) -> Quarantined and deleted successfully.


cosinus 03.11.2011 16:07

Gibt es noch weitere Logs von Malwarebytes? Wenn ja bitte alle posten, die in Malwarebytes im Reiter Logdateien sichtbar sind.

Atomfrosch 03.11.2011 16:10

Nein, nur die beiden. Antivir hat nichts gefunden, hab mich geirrt.

Spybot

Code:

02.11.2011 21:56:20 - ##### check started #####
02.11.2011 21:56:20 - ### Version: 1.6.2
02.11.2011 21:56:20 - ### Date: 02.11.2011 21:56:20
02.11.2011 21:56:24 - ##### checking bots #####
02.11.2011 21:59:35 - found: Fraud.DefenseCenter Einstellungen


--- Report generated: 2011-11-02 22:00 ---

Fraud.DefenseCenter: [SBI $400D394B] Einstellungen (Registrierungsdatenbank-Änderung, nothing done)
  HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr


--- Spybot - Search & Destroy version: 1.6.2  (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-01-26 TeaTimer.exe (1.6.4.26)
2011-11-02 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-01-26 advcheck.dll (1.6.2.15)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2011-03-18 Includes\Adware.sbi (*)
2011-08-29 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-03-08 Includes\DialerC.sbi (*)
2011-02-24 Includes\HeavyDuty.sbi (*)
2011-03-29 Includes\Hijackers.sbi (*)
2011-10-04 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2011-09-27 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2011-10-31 Includes\Malware.sbi (*)
2011-10-31 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2011-10-11 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2011-02-24 Includes\Security.sbi (*)
2011-05-03 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2011-10-18 Includes\Spyware.sbi (*)
2011-10-18 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2011-09-28 Includes\Trojans.sbi (*)
2011-10-31 Includes\TrojansC-02.sbi (*)
2011-10-31 Includes\TrojansC-03.sbi (*)
2011-10-28 Includes\TrojansC-04.sbi (*)
2011-10-31 Includes\TrojansC-05.sbi (*)
2011-09-27 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll


cosinus 03.11.2011 16:12

Führ bitte auch ESET aus, danach sehen wir weiter:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Atomfrosch 03.11.2011 17:24

Zwischenstand (er ist gerade bei 43%)

Zitat:

Infected Files: 1

Threads found!

a variant of Java/Agend.DW trojan

Atomfrosch 03.11.2011 18:08

So:
Code:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=e32b6420ee5990489406f9b8c9fbdf86
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-11-03 05:05:55
# local_time=2011-11-03 06:05:55 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1797 16775165 100 100 66762 95230042 59999 0
# compatibility_mode=5892 16776573 100 100 10641 157866206 0 0
# compatibility_mode=8192 67108863 100 0 3814 3814 0 0
# scanned=184697
# found=1
# cleaned=0
# scan_time=6477
C:\Users\Benedikt\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\d8b9bf1-63ad81bd        a variant of Java/Agent.DW trojan (unable to clean)        00000000000000000000000000000000        I


cosinus 03.11.2011 18:29

CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Atomfrosch 03.11.2011 18:44

Ok, werde ich machen, ich poste das Ergebnis wenn's fertig ist.

Wenn Windows startet kommt jetzt:
http://www.abload.de/img/2_160x160nzz1.jpg

Atomfrosch 03.11.2011 19:05

Customscan OTL

Code:

OTL logfile created on: 03.11.2011 18:46:11 - Run 3
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Benedikt\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 66,72% Memory free
6,19 Gb Paging File | 5,22 Gb Available in Paging File | 84,35% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138,91 Gb Total Space | 11,02 Gb Free Space | 7,94% Space Free | Partition Type: NTFS
Drive D: | 10,00 Gb Total Space | 5,62 Gb Free Space | 56,25% Space Free | Partition Type: NTFS
 
Computer Name: HERBERT | User Name: Benedikt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011.11.03 12:58:02 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Benedikt\Desktop\OTL.exe
PRC - [2011.10.25 13:38:10 | 000,542,672 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
PRC - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011.08.12 00:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe
PRC - [2011.07.11 20:51:21 | 000,269,480 | -H-- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.04.30 18:19:56 | 000,136,360 | -H-- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010.11.05 07:58:45 | 000,281,768 | -H-- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.09.06 17:56:38 | 000,247,096 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PRC - [2010.01.14 21:10:53 | 000,076,968 | -H-- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009.05.21 11:13:58 | 000,206,064 | -H-- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009.04.10 23:28:16 | 000,117,248 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE
PRC - [2009.04.10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008.08.14 00:04:44 | 000,201,968 | -H-- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008.06.30 11:28:24 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2008.06.30 11:28:14 | 000,196,608 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2008.06.30 11:28:12 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2008.06.30 11:28:12 | 000,046,376 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2008.06.26 12:10:06 | 000,442,467 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
PRC - [2008.06.26 12:10:00 | 000,221,273 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\stacsv.exe
PRC - [2008.06.26 12:09:50 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\AEstSrv.exe
PRC - [2008.04.28 15:56:28 | 000,161,048 | -H-- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008.01.21 03:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008.01.21 03:23:24 | 000,215,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdSync.exe
PRC - [2007.10.03 14:45:02 | 000,358,936 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007.10.03 14:44:58 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2003.08.05 09:43:04 | 000,045,056 | R--- | M] (Prolific Technology Inc.) -- C:\Windows\System32\HotFixQ0306270.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2010.10.28 08:29:34 | 011,804,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\62dfd8797881fd7a0d0de3f448a18c01\System.Web.ni.dll
MOD - [2010.10.28 08:29:25 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\9b8e883fd5fa51f026577156a0ee9d57\System.Runtime.Remoting.ni.dll
MOD - [2010.10.28 08:23:55 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\88593f5f0fc6de5d5f4a85aa2b1466f3\System.Xml.ni.dll
MOD - [2010.10.28 08:21:46 | 007,949,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ed6ae2749d12c4729ee43ff339de4bb8\System.ni.dll
MOD - [2010.10.28 08:21:28 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\98bbdd8c400493ad228b8283665cc9da\mscorlib.ni.dll
MOD - [2009.08.07 21:23:44 | 000,043,520 | ---- | M] () -- C:\Windows\System32\CmdLineExt03.dll
MOD - [2008.08.29 09:55:00 | 000,132,608 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2008.05.04 09:42:20 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
MOD - [2008.05.02 05:15:37 | 000,010,240 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerCOM.dll
MOD - [2008.03.12 06:37:52 | 000,055,808 | ---- | M] () -- C:\Windows\System32\bcmwlrmt.dll
MOD - [2007.09.02 12:57:36 | 000,069,632 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.10.28 11:02:02 | 001,117,624 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe -- (sdCoreService)
SRV - [2011.10.27 21:49:32 | 000,402,336 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe -- (sdAuxService)
SRV - [2011.10.25 13:38:10 | 000,542,672 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.08.12 00:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2011.07.11 20:51:21 | 000,269,480 | -H-- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.30 18:19:56 | 000,136,360 | -H-- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010.09.06 17:56:38 | 000,247,096 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2009.09.28 14:48:15 | 000,316,664 | -H-- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008.08.22 09:03:20 | 000,016,680 | -H-- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2008.08.14 00:04:44 | 000,201,968 | -H-- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008.06.26 12:10:00 | 000,221,273 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\stacsv.exe -- (STacSV)
SRV - [2008.06.26 12:09:50 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\AEstSrv.exe -- (AESTFilters)
SRV - [2008.04.28 15:56:28 | 000,161,048 | -H-- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV - [2008.01.21 03:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008.01.21 03:23:24 | 000,365,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2008.01.21 03:23:24 | 000,167,936 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2008.01.09 11:30:08 | 000,121,360 | -H-- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2007.10.03 14:45:02 | 000,358,936 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.10.28 11:02:54 | 000,185,560 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\Windows\System32\drivers\PCTSD.sys -- (PCTSD)
DRV - [2011.10.22 15:11:14 | 000,331,880 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2011.10.07 17:52:06 | 000,341,656 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\pctDS.sys -- (pctDS)
DRV - [2011.09.28 13:14:02 | 000,056,840 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PCTBD.sys -- (PCTBD)
DRV - [2011.08.31 17:00:50 | 000,022,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011.07.22 17:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011.07.12 22:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011.07.11 20:51:22 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.07.11 20:51:22 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.09.03 20:40:46 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009.05.21 12:59:12 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2009.05.11 09:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.02.13 11:35:01 | 000,011,608 | -H-- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008.07.30 06:51:30 | 000,277,736 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2008.06.30 11:28:10 | 000,170,032 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2008.06.26 12:10:08 | 000,380,928 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2008.05.04 09:42:18 | 003,548,672 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2008.05.04 09:42:18 | 003,548,672 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2008.05.04 09:42:18 | 003,548,672 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2008.03.14 14:04:26 | 000,054,784 | ---- | M] (ITE Tech. Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\itecir.sys -- (itecir)
DRV - [2008.03.12 06:37:46 | 000,018,424 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bcm42rly.sys -- (BCM42RLY)
DRV - [2008.03.11 07:42:24 | 000,203,264 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\k57nd60x.sys -- (k57nd60x) Broadcom NetLink (TM)
DRV - [2008.03.11 07:24:46 | 000,038,400 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2008.03.11 07:24:44 | 000,046,592 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2008.03.11 07:24:42 | 000,043,008 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2008.01.21 03:23:25 | 000,251,904 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VSTBS23.SYS -- (VSTHWBS2)
DRV - [2008.01.21 03:23:25 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel(R)
DRV - [2007.11.29 01:17:56 | 000,036,368 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2007.11.29 01:17:48 | 000,035,088 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2007.05.11 10:59:00 | 000,017,536 | ---- | M] (Olivetti-Engineering SA) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\desrvusb.sys -- (DESVUSB)
DRV - [2003.10.06 10:29:08 | 000,007,424 | R--- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\plff.sys -- (PLFF)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0: C:\Program Files\Picasa2\npPicasa2.dll File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2852: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2910: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1662: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Benedikt\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools\PC Tools Security\BDT\Firefox\ [2011.11.02 21:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.10.06 16:18:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.03.21 10:33:49 | 000,000,000 | ---D | M]
 
[2010.04.28 14:13:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Extensions
[2010.04.28 14:13:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009.06.26 12:12:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Extensions\uploadr@flickr.com
[2011.10.24 16:37:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\9gbwpvs7.default\extensions
[2010.04.27 20:10:58 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\9gbwpvs7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.02.16 19:52:59 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\9gbwpvs7.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2009.06.02 19:04:48 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\9gbwpvs7.default\extensions\moveplayer@movenetworks.com
[2011.10.26 18:43:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010.10.04 09:05:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.10.05 19:44:58 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.11.27 21:25:51 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011.02.20 21:36:11 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.06.17 12:56:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011.10.26 18:43:38 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011.10.06 16:18:24 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010.12.09 11:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2011.10.06 16:18:21 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.06 16:18:21 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.10.06 16:18:21 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.06 16:18:21 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.06 16:18:21 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.06 16:18:21 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2010.09.22 17:43:12 | 000,000,057 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PLFFAP] C:\Windows\System32\HotFixQ0306270.exe (Prolific Technology Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKCU..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Programs\PartyGaming.Net\PartyPokerNet\RunPF.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Programs\PartyGaming.Net\PartyPokerNet\RunPF.exe ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2D5B2A83-26CD-4993-A422-1070C2D311AA}: DhcpNameServer = 195.50.140.118 195.50.140.248
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F12C023B-96A9-4254-A2BC-45E07E338589}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img29.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img29.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe - (Logitech Inc.)
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe - (Logitech, Inc.)
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Privoxy.lnk -  - File not found
MsConfig - StartUpFolder: C:^Users^Benedikt^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk - C:\Program Files\Dell\DellDock\DellDock.exe - (Stardock Corporation)
MsConfig - StartUpFolder: C:^Users^Benedikt^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE - (Microsoft Corporation)
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: AdobeAAMUpdater-1.0 - hkey= - key= - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: AdobeCS4ServiceManager - hkey= - key= -  File not found
MsConfig - StartUpReg: CORSAIR_PLUtil - hkey= - key= - C:\Program Files\Corsair\Corsair Flash Voyager Utility\PLBkMon.exe (Prolific Technology Inc.)
MsConfig - StartUpReg: DellSupportCenter - hkey= - key= - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
MsConfig - StartUpReg: dscactivate - hkey= - key= - C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
MsConfig - StartUpReg: ehTray.exe - hkey= - key= - C:\Windows\ehome\ehtray.exe (Microsoft Corporation)
MsConfig - StartUpReg: ICQ - hkey= - key= -  File not found
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: Kernel and Hardware Abstraction Layer - hkey= - key= - C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
MsConfig - StartUpReg: MgKPyEORiQUvGj.exe - hkey= - key= -  File not found
MsConfig - StartUpReg: OODefragTray - hkey= - key= -  File not found
MsConfig - StartUpReg: PCMService - hkey= - key= - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
MsConfig - StartUpReg: pdfFactory Dispatcher v3 - hkey= - key= -  File not found
MsConfig - StartUpReg: PDVD9LanguageShortcut - hkey= - key= -  File not found
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
MsConfig - StartUpReg: RemoteControl9 - hkey= - key= -  File not found
MsConfig - StartUpReg: Skype - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig - State: "startup" - 2
MsConfig - State: "bootini" - 2
 
SafeBootMin: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SafeBootMin: AppMgmt -  File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sdAuxService - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe (PC Tools)
SafeBootMin: sdCoreService - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe (PC Tools)
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SafeBootNet: AppMgmt -  File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: hitmanpro35 - Reg Error: Value error.
SafeBootNet: hitmanpro35.sys - Reg Error: Value error.
SafeBootNet: HitmanPro35Crusader - Reg Error: Value error.
SafeBootNet: Messenger -  File not found
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sdAuxService - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe (PC Tools)
SafeBootNet: sdCoreService - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe (PC Tools)
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 10.4
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 10.4
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {62097C1F-D4E1-9563-B095-55F70FC01E1B} - Browser Customizations
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {AB3EFB54-4244-8ABE-3888-9CC991A60ED0} - Microsoft Windows Media Player
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EE58D085-42E4-F49F-D517-C0CF20713DD4} - Browser Customizations
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\System32\lhacm.acm (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.I420 - C:\Windows\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.yv12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.11.03 16:16:14 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Benedikt\Desktop\esetsmartinstaller_enu.exe
[2011.11.03 16:14:24 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011.11.03 12:58:05 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Benedikt\Desktop\OTL.exe
[2011.11.03 12:57:23 | 000,000,000 | ---D | C] -- C:\Users\Benedikt\AppData\Roaming\SUPERAntiSpyware.com
[2011.11.03 12:56:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011.11.03 12:56:12 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011.11.03 12:56:12 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011.11.03 12:55:33 | 012,837,560 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\Benedikt\Desktop\SUPERAntiSpyware501134.exe
[2011.11.02 22:23:10 | 009,852,544 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\Benedikt\Desktop\mbam-setup-1.51.2.1300.exe
[2011.11.02 22:05:19 | 000,000,000 | ---D | C] -- C:\Users\Benedikt\AppData\Local\Threat Expert
[2011.11.02 21:55:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011.11.02 21:55:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011.11.02 21:55:46 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2011.11.02 21:45:43 | 000,149,456 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2011.11.02 21:45:43 | 000,056,840 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTBD.sys
[2011.11.02 21:45:42 | 002,291,664 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2011.11.02 21:45:42 | 001,681,360 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2011.11.02 21:45:04 | 000,252,840 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2011.11.02 21:45:04 | 000,105,792 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2011.11.02 21:45:00 | 000,017,848 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctBTFix.sys
[2011.11.02 21:45:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2011.11.02 21:44:57 | 000,070,536 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2011.11.02 21:44:50 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools
[2011.11.02 21:41:40 | 000,660,992 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctEFA.sys
[2011.11.02 21:41:40 | 000,341,656 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctDS.sys
[2011.11.02 21:41:35 | 000,331,880 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2011.11.02 21:41:35 | 000,162,584 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2011.11.02 21:41:33 | 000,185,560 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTSD.sys
[2011.11.02 21:41:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2011.11.02 21:41:13 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2011.10.31 13:00:44 | 000,000,000 | -H-D | C] -- C:\Users\Benedikt\AppData\Local\O&O
[2011.10.30 12:24:58 | 000,000,000 | -H-D | C] -- C:\Users\Benedikt\AppData\Local\Downloaded Installations
[2011.10.30 12:14:03 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.10.30 12:14:02 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
 
========== Files - Modified Within 30 Days ==========
 
[2011.11.03 18:50:05 | 000,000,424 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{50F6F6D8-62B8-44EE-8129-9F539D72EE3C}.job
[2011.11.03 18:47:01 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2011.11.03 18:46:59 | 000,670,946 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.11.03 18:46:59 | 000,631,636 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.11.03 18:46:59 | 000,144,082 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.11.03 18:46:59 | 000,118,262 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.11.03 18:43:00 | 000,065,445 | ---- | M] () -- C:\Users\Benedikt\Desktop\2_160x160.jpg
[2011.11.03 18:41:12 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.11.03 18:41:10 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.11.03 18:41:10 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.11.03 18:40:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.11.03 17:34:03 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.11.03 16:16:14 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Benedikt\Desktop\esetsmartinstaller_enu.exe
[2011.11.03 12:58:02 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Benedikt\Desktop\OTL.exe
[2011.11.03 12:57:56 | 000,000,120 | ---- | M] () -- C:\Users\Benedikt\Desktop\UdlzgwzW.htm.part.htm
[2011.11.03 12:56:17 | 000,001,762 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.11.03 12:55:56 | 012,837,560 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\Benedikt\Desktop\SUPERAntiSpyware501134.exe
[2011.11.03 07:32:47 | 000,000,868 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.11.02 22:23:16 | 009,852,544 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\Benedikt\Desktop\mbam-setup-1.51.2.1300.exe
[2011.11.02 21:45:00 | 000,001,911 | ---- | M] () -- C:\Users\Public\Desktop\PC Tools Spyware Doctor.lnk
[2011.11.01 09:59:25 | 000,061,952 | -H-- | M] () -- C:\Users\Benedikt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.10.30 19:59:21 | 000,000,042 | ---- | M] () -- C:\Windows\oodjobd.INI
[2011.10.29 07:50:34 | 000,000,000 | ---- | M] () -- C:\Windows\System32\null
[2011.10.28 11:03:18 | 000,070,536 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2011.10.28 11:02:54 | 000,185,560 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\PCTSD.sys
[2011.10.28 11:01:36 | 000,017,848 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctBTFix.sys
[2011.10.28 10:41:04 | 000,105,792 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2011.10.28 10:40:58 | 000,252,840 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2011.10.25 13:38:20 | 000,149,456 | ---- | M] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2011.10.25 13:38:18 | 002,291,664 | ---- | M] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2011.10.25 13:38:18 | 001,681,360 | ---- | M] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2011.10.25 13:38:08 | 000,767,952 | ---- | M] () -- C:\Windows\BDTSupport.dll
[2011.10.22 15:11:14 | 000,331,880 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2011.10.22 15:11:08 | 000,162,584 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2011.10.07 17:52:12 | 000,660,992 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctEFA.sys
[2011.10.07 17:52:06 | 000,341,656 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctDS.sys
 
========== Files Created - No Company Name ==========
 
[2011.11.03 18:43:00 | 000,065,445 | ---- | C] () -- C:\Users\Benedikt\Desktop\2_160x160.jpg
[2011.11.03 12:57:53 | 000,000,120 | ---- | C] () -- C:\Users\Benedikt\Desktop\UdlzgwzW.htm.part.htm
[2011.11.03 12:56:17 | 000,001,762 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.11.03 07:32:47 | 000,000,868 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.11.02 21:45:43 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2011.11.02 21:45:43 | 000,000,882 | ---- | C] () -- C:\Windows\RegSDImport.xml
[2011.11.02 21:45:43 | 000,000,879 | ---- | C] () -- C:\Windows\RegISSImport.xml
[2011.11.02 21:45:43 | 000,000,131 | ---- | C] () -- C:\Windows\IDB.zip
[2011.11.02 21:45:42 | 000,003,488 | ---- | C] () -- C:\Windows\UDB.zip
[2011.11.02 21:45:00 | 000,001,911 | ---- | C] () -- C:\Users\Public\Desktop\PC Tools Spyware Doctor.lnk
[2011.10.30 19:59:21 | 000,000,042 | ---- | C] () -- C:\Windows\oodjobd.INI
[2011.05.18 15:07:05 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011.03.16 11:38:37 | 000,000,074 | ---- | C] () -- C:\Windows\FinalAlert2.ini
[2011.01.02 18:37:22 | 000,000,132 | ---- | C] () -- C:\Users\Benedikt\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011.01.01 16:18:49 | 000,000,132 | ---- | C] () -- C:\Users\Benedikt\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2010.11.26 03:15:14 | 000,023,040 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2010.10.30 18:42:03 | 000,001,456 | -H-- | C] () -- C:\Users\Benedikt\AppData\Local\Adobe Für Web speichern 12.0 Prefs
[2010.08.10 13:59:27 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010.08.10 13:59:27 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010.08.10 13:59:27 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010.08.10 13:59:27 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010.08.10 13:59:27 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010.08.07 21:22:11 | 000,016,968 | ---- | C] () -- C:\Windows\System32\drivers\hitmanpro35.sys
[2010.07.04 11:54:11 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010.05.15 16:36:51 | 000,000,122 | ---- | C] () -- C:\Windows\wa.INI
[2010.05.13 19:31:28 | 000,000,113 | ---- | C] () -- C:\Windows\(null)toolkit.ini
[2009.10.29 17:56:18 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.10.29 17:55:21 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.10.29 14:00:01 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009.08.27 12:02:55 | 000,000,144 | ---- | C] () -- C:\Windows\Sierra.ini
[2009.08.13 19:37:07 | 000,000,020 | ---- | C] () -- C:\Windows\mafosav.INI
[2009.06.21 20:12:59 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2009.05.22 16:45:33 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2009.05.22 16:45:22 | 000,007,119 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2009.03.24 10:17:44 | 000,032,256 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2009.02.19 18:25:54 | 000,022,328 | ---- | C] () -- C:\Users\Benedikt\AppData\Roaming\PnkBstrK.sys
[2009.01.18 13:00:13 | 000,149,504 | ---- | C] () -- C:\Windows\UNWISE.EXE
[2008.12.10 15:04:41 | 000,225,256 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2008.11.24 16:51:30 | 000,000,118 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2008.11.21 22:44:16 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll
[2008.10.03 15:33:59 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini
[2008.09.16 01:14:24 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2008.09.12 10:38:02 | 000,010,752 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2008.09.09 15:37:53 | 000,061,952 | -H-- | C] () -- C:\Users\Benedikt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.08.31 20:27:50 | 000,001,461 | ---- | C] () -- C:\Windows\mozver.dat
[2008.08.31 15:28:57 | 000,000,304 | ---- | C] () -- C:\Users\Benedikt\AppData\Roaming\wklnhst.dat
[2008.08.31 15:04:57 | 000,000,018 | ---- | C] () -- C:\Windows\wininit.ini
[2008.08.31 14:44:51 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008.08.31 14:37:02 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2008.08.31 10:41:04 | 000,001,356 | -H-- | C] () -- C:\Users\Benedikt\AppData\Local\d3d9caps.dat
[2008.08.22 18:32:09 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2008.08.22 18:32:09 | 000,168,883 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2008.08.22 18:32:09 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008.08.22 18:32:09 | 000,090,112 | ---- | C] () -- C:\Windows\System32\atibrtmon.exe
[2008.08.22 10:38:23 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2008.08.22 08:56:25 | 000,055,808 | ---- | C] () -- C:\Windows\System32\bcmwlrmt.dll
[2008.08.22 08:56:25 | 000,024,064 | ---- | C] () -- C:\Windows\System32\WLTRYSVC.EXE
[2008.01.21 08:15:58 | 000,670,946 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008.01.21 08:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008.01.21 08:15:58 | 000,144,082 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008.01.21 08:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2007.06.06 07:32:00 | 000,002,699 | ---- | C] () -- C:\Windows\System32\d1wiaUiStr.bin
[2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:47:37 | 004,173,840 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 11:33:01 | 000,631,636 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,118,262 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2000.02.09 23:00:00 | 000,047,104 | ---- | C] () -- C:\Windows\System32\wrkgadm.exe
[2000.02.09 23:00:00 | 000,012,288 | ---- | C] () -- C:\Windows\System32\HLINKPRX.DLL
[1996.04.03 20:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys
 
========== LOP Check ==========
 
[2011.09.20 16:18:55 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\.minecraft
[2009.01.23 13:05:53 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Alien Skin
[2010.08.10 13:54:09 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Arvau
[2009.06.21 20:15:53 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Atari
[2010.05.26 18:28:32 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Audacity
[2010.03.28 17:11:46 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Canon
[2011.01.02 19:25:27 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009.12.28 21:32:34 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2009.01.12 18:24:04 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Crayon Physics Deluxe
[2008.09.04 13:16:55 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\DAEMON Tools
[2011.10.30 12:07:53 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\DAEMON Tools Lite
[2009.08.19 13:57:24 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\de.makesoft.twhirl.0EA062BC275E7ED1E6EC3762EFFD73C7158ADF33.1
[2008.12.02 18:06:06 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Exif Viewer
[2008.09.20 18:00:25 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\FDRLab
[2009.06.26 12:12:26 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Flickr
[2011.07.10 12:24:53 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\FreeFLVConverter
[2008.09.14 10:37:16 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\GHISLER
[2009.09.11 13:32:36 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\gtk-2.0
[2011.09.26 20:11:23 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Hobbyist Software
[2009.03.01 16:54:19 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\L4dOgerLauncher
[2011.02.25 18:40:35 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\LolClient
[2009.05.22 16:51:47 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\MAGIX
[2010.04.18 10:50:49 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\ManyCam
[2011.03.04 19:48:13 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Miranda
[2011.08.18 18:54:03 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Mymaz
[2008.10.22 18:50:14 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\OpenOffice.org
[2009.11.23 19:04:40 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Planetside Software
[2008.11.13 19:40:20 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\ProtectDisc
[2008.12.10 17:44:51 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\QIP
[2008.11.21 16:18:25 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Red Alert 3
[2008.09.22 13:10:12 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\ScreenSeven
[2009.04.25 16:05:05 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Soldat
[2010.10.31 19:02:16 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2008.09.20 09:14:29 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\T-Online
[2008.11.09 11:50:26 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Teeworlds
[2008.08.31 15:28:58 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Template
[2009.01.22 17:18:55 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Thinstall
[2010.04.28 14:13:40 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Thunderbird
[2010.03.02 13:31:37 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Trillian
[2011.10.30 12:07:02 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\TS3Client
[2009.11.23 19:04:40 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\uk.co.planetside
[2010.12.22 19:49:32 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Unity
[2009.09.13 19:40:42 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\uTorrent
[2009.10.03 19:05:16 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Walea GmbH
[2010.05.16 09:04:28 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\xWeasel
[2011.08.18 16:22:54 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Ytxyl
[2010.08.10 14:12:41 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Ywylag
[2011.11.03 18:21:35 | 000,032,514 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.11.03 18:50:05 | 000,000,424 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{50F6F6D8-62B8-44EE-8129-9F539D72EE3C}.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.09.20 16:18:55 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\.minecraft
[2010.09.22 17:52:23 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Adobe
[2010.10.31 19:02:16 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Adobe Mini Bridge CS5
[2009.01.23 13:05:53 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Alien Skin
[2010.12.28 18:29:16 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Apple Computer
[2010.08.10 13:54:09 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Arvau
[2009.06.21 20:15:53 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Atari
[2008.08.31 10:42:44 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\ATI
[2010.05.26 18:28:32 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Audacity
[2010.03.27 07:55:19 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Avira
[2010.03.28 17:11:46 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Canon
[2011.01.02 19:25:27 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009.12.28 21:32:34 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2009.01.12 18:24:04 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Crayon Physics Deluxe
[2010.03.12 11:02:00 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Creative
[2009.07.14 13:26:15 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\CyberLink
[2008.09.04 13:16:55 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\DAEMON Tools
[2011.10.30 12:07:53 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\DAEMON Tools Lite
[2009.08.19 13:57:24 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\de.makesoft.twhirl.0EA062BC275E7ED1E6EC3762EFFD73C7158ADF33.1
[2008.08.31 10:41:00 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Dell
[2008.10.11 18:00:45 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\DivX
[2011.03.09 11:49:51 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Download Manager
[2011.08.21 14:44:21 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\dvdcss
[2008.12.02 18:06:06 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Exif Viewer
[2008.09.20 18:00:25 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\FDRLab
[2009.06.26 12:12:26 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Flickr
[2011.07.10 12:24:53 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\FreeFLVConverter
[2008.09.14 10:37:16 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\GHISLER
[2008.09.14 19:21:16 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Google
[2009.09.11 13:32:36 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\gtk-2.0
[2009.05.21 13:21:02 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Hamachi
[2011.09.26 20:11:23 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Hobbyist Software
[2008.08.31 10:41:46 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Identities
[2008.09.02 09:34:37 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\InstallShield
[2009.03.01 16:54:19 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\L4dOgerLauncher
[2008.09.02 09:38:32 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Logitech
[2011.02.25 18:40:35 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\LolClient
[2008.08.31 14:35:02 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Macromedia
[2009.05.22 16:51:47 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\MAGIX
[2010.08.10 11:55:45 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Malwarebytes
[2010.04.18 10:50:49 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\ManyCam
[2006.11.02 13:37:34 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Media Center Programs
[2010.09.23 17:33:51 | 000,000,000 | --SD | M] -- C:\Users\Benedikt\AppData\Roaming\Microsoft
[2011.03.04 19:48:13 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Miranda
[2011.02.28 14:02:19 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\mIRC
[2009.06.26 12:12:27 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Mozilla
[2009.09.20 17:36:57 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Mozilla-Cache
[2011.08.18 18:54:03 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Mymaz
[2011.01.01 19:02:39 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Nero
[2008.10.22 18:50:14 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\OpenOffice.org
[2009.11.23 19:04:40 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Planetside Software
[2008.11.13 19:40:20 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\ProtectDisc
[2008.12.10 17:44:51 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\QIP
[2008.11.04 12:44:06 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Real
[2008.11.21 16:18:25 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Red Alert 3
[2008.09.22 13:10:12 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\ScreenSeven
[2010.07.09 06:54:41 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Skype
[2010.07.04 11:54:08 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\skypePM
[2009.04.25 16:05:05 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Soldat
[2010.10.31 19:02:16 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.11.03 12:57:23 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\SUPERAntiSpyware.com
[2008.09.20 09:14:29 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\T-Online
[2010.02.03 19:59:24 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\teamspeak2
[2008.11.09 11:50:26 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Teeworlds
[2008.08.31 15:28:58 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Template
[2009.01.22 17:18:55 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Thinstall
[2010.04.28 14:13:40 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Thunderbird
[2010.03.02 13:31:37 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Trillian
[2011.10.30 12:07:02 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\TS3Client
[2010.01.28 13:34:02 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\U3
[2009.11.23 19:04:40 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\uk.co.planetside
[2010.12.22 19:49:32 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Unity
[2009.09.13 19:40:42 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\uTorrent
[2011.10.15 14:40:12 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\vlc
[2009.10.03 19:05:16 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Walea GmbH
[2011.10.31 12:28:32 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Winamp
[2008.09.01 07:49:17 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\WinRAR
[2010.05.16 09:04:28 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\xWeasel
[2008.09.02 11:00:53 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Yahoo!
[2011.08.18 16:22:54 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Ytxyl
[2010.08.10 14:12:41 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Ywylag
 
< %APPDATA%\*.exe /s >
[2011.02.25 20:25:53 | 000,053,632 | -H-- | M] (Adobe Systems Inc.) -- C:\Users\Benedikt\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2009.06.17 17:27:31 | 001,878,984 | -H-- | M] (Adobe Systems Incorporated) -- C:\Users\Benedikt\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
[2008.09.02 09:38:25 | 000,010,134 | RH-- | M] () -- C:\Users\Benedikt\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2010.05.06 18:23:52 | 000,026,582 | RH-- | M] () -- C:\Users\Benedikt\AppData\Roaming\Microsoft\Installer\{6583D00E-0924-4950-8BE9-5D09FE70B333}\_43651A41F8B233F970CAD4.exe
[2010.05.06 18:23:52 | 000,026,582 | RH-- | M] () -- C:\Users\Benedikt\AppData\Roaming\Microsoft\Installer\{6583D00E-0924-4950-8BE9-5D09FE70B333}\_AAFEC972C6A808875A25F1.exe
[2009.04.07 17:43:18 | 000,040,960 | RH-- | M] (InstallShield Software Corp.) -- C:\Users\Benedikt\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
[2009.04.07 17:43:19 | 000,040,960 | RH-- | M] (InstallShield Software Corp.) -- C:\Users\Benedikt\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
[2009.04.07 17:43:19 | 000,008,854 | RH-- | M] () -- C:\Users\Benedikt\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\Uninstall_Project64__9559F7CA5E344237A2D9D856464AD727.exe
[2009.01.22 17:19:06 | 000,007,680 | ---- | M] () -- C:\Users\Benedikt\AppData\Roaming\Thinstall\Diablo II\4000001100002i\Game.exe
[2007.10.23 09:27:20 | 000,110,592 | ---- | M] () -- C:\Users\Benedikt\AppData\Roaming\U3\temp\cleanup.exe
[2008.05.02 10:41:48 | 003,493,888 | -H-- | M] (SanDisk Corporation) -- C:\Users\Benedikt\AppData\Roaming\U3\temp\Launchpad Removal.exe
 
< %SYSTEMDRIVE%\*.exe >
[2007.05.03 16:32:29 | 000,000,385 | ---- | M] () -- C:\hsyte12.exe
 
 
< MD5 for: AGP440.SYS  >
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\ERDNT\cache\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.08.22 18:27:10 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\ERDNT\cache\atapi.sys
[2008.08.22 18:27:10 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\System32\drivers\atapi.sys
[2008.08.22 18:27:10 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys
[2008.08.22 18:27:10 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2009.04.10 23:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.10 23:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.08.22 18:27:10 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=96DC4E1A9F90CCD489950A8935425C59 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\ERDNT\cache\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2007.09.29 22:03:32 | 000,384,024 | ---- | M] (Intel Corporation) MD5=16A4671255CFB842225F0FDB6DBDB414 -- C:\Program Files\Intel\Intel Matrix Storage Manager\Driver64\IaStor.sys
[2008.03.11 07:44:12 | 000,305,176 | -H-- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\Drivers\storage\R180982\iastor.sys
[2008.03.11 07:44:12 | 000,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\Windows\System32\drivers\iaStor.sys
[2008.03.11 07:44:12 | 000,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_cfa1dde4\iaStor.sys
[2008.03.11 07:44:12 | 000,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_ec8a8d1b\iaStor.sys
[2007.09.29 22:03:12 | 000,308,248 | ---- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F -- C:\Program Files\Intel\Intel Matrix Storage Manager\Driver\IaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 03:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008.01.21 03:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.21 03:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\ERDNT\cache\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.21 03:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.21 03:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008.01.21 03:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.21 03:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 03:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\ERDNT\cache\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
[2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.04.10 23:28:26 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows\ERDNT\cache\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
[2008.01.21 03:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2009.04.10 23:28:26 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.10 23:28:26 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 03:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\ERDNT\cache\userinit.exe
[2008.01.21 03:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.21 03:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 03:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.21 03:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\ERDNT\cache\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2009.04.10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 03:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 03:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.21 03:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.09.03 20:40:46 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- C:\Windows\system32\drivers\sptd.sys
 
< %systemroot%\System32\config\*.sav >
[2008.01.21 04:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008.01.21 04:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008.01.21 04:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 11:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 11:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2008.03.12 06:37:52 | 000,055,808 | ---- | M] () Unable to obtain MD5 -- C:\Windows\system32\bcmwlrmt.dll
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 170 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84

< End of report >



Edit:

Der Internetexplorer ist übrigens permanent im Hintergrund an. Wenn ich den Prozess beende, startet er sich wieder automatisch.

cosinus 03.11.2011 19:55

Zitat:

[2010.08.10 13:59:27 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010.08.10 13:59:27 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010.08.10 13:59:27 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010.08.10 13:59:27 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010.08.10 13:59:27 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
Wer hat dich im August 2010 angewiesen Combofix auszuführen?

Zitat:

O1 - Hosts: 127.0.0.1 activate.adobe.com
[2011.01.02 18:37:22 | 000,000,132 | ---- | C] () -- C:\Users\Benedikt\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011.01.01 16:18:49 | 000,000,132 | ---- | C] () -- C:\Users\Benedikt\AppData\Roaming\Adobe GIF Format CS5 Prefs
Woher stammt das CS5? Welche Quelle?

Atomfrosch 03.11.2011 20:03

Keine Ahnung, ich hatte Combofix bisher noch nie drauf, weiss nicht wo das herkommt.

CS5 war die Trial direkt von Adobe.

cosinus 03.11.2011 20:10

Ich brauch den Quarantäneordner von Combofix. Bitte folgendes machen:

1.) GANZ WICHTIG!! Virenscanner deaktivieren, der darf das Packen nicht beeinflussen!
2.) Ordner Quarantine in C:\Qoobox in eine Datei zippen
3.) die erstellte ZIP-Datei hier hochladen => http://www.trojaner-board.de/54791-a...ner-board.html

Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang in den Thread posten!

4.) Wenns erfolgreich war Bescheid sagen
5.) Erst dann wieder den Virenscanner einschalten

Atomfrosch 03.11.2011 20:15

Hab ich gerade gemacht.

Zitat:

Datei: Quarantine.zip empfangen

Vorgang erfolgreich abgeschlossen.

cosinus 03.11.2011 20:24

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
[2011.11.02 21:45:43 | 000,000,131 | ---- | C] () -- C:\Windows\IDB.zip
[2011.11.02 21:45:42 | 000,003,488 | ---- | C] () -- C:\Windows\UDB.zip
[2011.01.02 18:37:22 | 000,000,132 | ---- | C] () -- C:\Users\Benedikt\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011.01.01 16:18:49 | 000,000,132 | ---- | C] () -- C:\Users\Benedikt\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2011.08.18 16:22:54 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Ytxyl
[2010.08.10 14:12:41 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Ywylag
[2010.10.31 19:02:16 | 000,000,000 | ---D | M] -- C:\Users\Benedikt\AppData\Roaming\Adobe Mini Bridge CS5
@Alternate Data Stream - 170 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Atomfrosch 03.11.2011 20:34

Code:

All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully.
C:\Program Files\ICQ6Toolbar\ICQToolBar.dll moved successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\StartPageCache| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
File C:\Program Files\ICQ6Toolbar\ICQToolBar.dll not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
C:\Program Files\Ask.com\GenericAskToolbar.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{472734EA-242A-422B-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422B-ADF8-83D1E48CC825}\ deleted successfully.
C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found.
File C:\Program Files\ICQ6Toolbar\ICQToolBar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{472734EA-242A-422B-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422B-ADF8-83D1E48CC825}\ not found.
File C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files\Ask.com\GenericAskToolbar.dll not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
C:\Windows\IDB.zip moved successfully.
C:\Windows\UDB.zip moved successfully.
C:\Users\Benedikt\AppData\Roaming\Adobe PNG Format CS5 Prefs moved successfully.
C:\Users\Benedikt\AppData\Roaming\Adobe GIF Format CS5 Prefs moved successfully.
C:\Users\Benedikt\AppData\Roaming\Ytxyl folder moved successfully.
C:\Users\Benedikt\AppData\Roaming\Ywylag folder moved successfully.
C:\Users\Benedikt\AppData\Roaming\Adobe Mini Bridge CS5 folder moved successfully.
ADS C:\ProgramData\Temp:DFC5A2B2 deleted successfully.
ADS C:\ProgramData\Temp:430C6D84 deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Benedikt
->Temp folder emptied: 2846994 bytes
->Temporary Internet Files folder emptied: 14963290 bytes
->Java cache emptied: 12079853 bytes
->FireFox cache emptied: 24071688 bytes
->Flash cache emptied: 1966009 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56502 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 246440 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 54,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.31.0 log created on 11032011_202916

Files\Folders moved on Reboot...
C:\Users\Benedikt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLE1YZ2S\ac3[2].htm moved successfully.
C:\Users\Benedikt\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat moved successfully.

Registry entries deleted on Reboot...

Keine Ahnung ob der Fix jetzt für alles war, aber:

Starteinträge sind noch weg.

Internetexplorer startet sich noch immer selbst.

Diese
http://www.abload.de/img/2_160x160nzz1.jpg

Fehler kommen auch noch.

cosinus 03.11.2011 20:40

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

Atomfrosch 03.11.2011 20:52

Code:

20:51:12.0653 3152        TDSS rootkit removing tool 2.6.15.0 Nov  3 2011 17:15:49
20:51:12.0832 3152        ============================================================
20:51:12.0833 3152        Current date / time: 2011/11/03 20:51:12.0832
20:51:12.0833 3152        SystemInfo:
20:51:12.0833 3152       
20:51:12.0833 3152        OS Version: 6.0.6002 ServicePack: 2.0
20:51:12.0833 3152        Product type: Workstation
20:51:12.0833 3152        ComputerName: HERBERT
20:51:12.0833 3152        UserName: Benedikt
20:51:12.0833 3152        Windows directory: C:\Windows
20:51:12.0833 3152        System windows directory: C:\Windows
20:51:12.0833 3152        Processor architecture: Intel x86
20:51:12.0833 3152        Number of processors: 2
20:51:12.0833 3152        Page size: 0x1000
20:51:12.0834 3152        Boot type: Normal boot
20:51:12.0834 3152        ============================================================
20:51:13.0278 3152        Initialize success
20:51:30.0997 4968        ============================================================
20:51:30.0997 4968        Scan started
20:51:30.0997 4968        Mode: Manual; SigCheck; TDLFS;
20:51:30.0997 4968        ============================================================
20:51:31.0535 4968        acedrv11        (27f954120babb8a00f8745d8f5bc9b82) C:\Windows\system32\drivers\acedrv11.sys
20:51:31.0674 4968        acedrv11 - ok
20:51:31.0750 4968        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
20:51:31.0767 4968        ACPI - ok
20:51:31.0840 4968        adfs - ok
20:51:31.0918 4968        adp94xx        (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
20:51:31.0941 4968        adp94xx - ok
20:51:32.0070 4968        adpahci        (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
20:51:32.0087 4968        adpahci - ok
20:51:32.0133 4968        adpu160m        (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
20:51:32.0145 4968        adpu160m - ok
20:51:32.0183 4968        adpu320        (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
20:51:32.0196 4968        adpu320 - ok
20:51:32.0363 4968        AFD            (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
20:51:32.0451 4968        AFD - ok
20:51:32.0559 4968        agp440          (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
20:51:32.0570 4968        agp440 - ok
20:51:32.0601 4968        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
20:51:32.0614 4968        aic78xx - ok
20:51:32.0642 4968        aliide          (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
20:51:32.0653 4968        aliide - ok
20:51:32.0714 4968        amdagp          (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
20:51:32.0725 4968        amdagp - ok
20:51:32.0792 4968        amdide          (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
20:51:32.0802 4968        amdide - ok
20:51:32.0840 4968        AmdK7          (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
20:51:32.0982 4968        AmdK7 - ok
20:51:33.0096 4968        AmdK8          (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
20:51:33.0159 4968        AmdK8 - ok
20:51:33.0353 4968        amdkmdag        (be4d8fdc6b2598c46b2b5e6e4fbaafc5) C:\Windows\system32\DRIVERS\atikmdag.sys
20:51:33.0521 4968        amdkmdag - ok
20:51:33.0607 4968        amdkmdap - ok
20:51:33.0677 4968        ApfiltrService  (1de27858a431a5749e0f3df54ba935b9) C:\Windows\system32\DRIVERS\Apfiltr.sys
20:51:33.0701 4968        ApfiltrService - ok
20:51:33.0820 4968        arc            (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
20:51:33.0831 4968        arc - ok
20:51:33.0871 4968        arcsas          (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
20:51:33.0883 4968        arcsas - ok
20:51:34.0017 4968        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
20:51:34.0063 4968        AsyncMac - ok
20:51:34.0149 4968        atapi          (0d83c87a801a3dfcd1bf73893fe7518c) C:\Windows\system32\drivers\atapi.sys
20:51:34.0160 4968        atapi - ok
20:51:34.0353 4968        atikmdag        (be4d8fdc6b2598c46b2b5e6e4fbaafc5) C:\Windows\system32\DRIVERS\atikmdag.sys
20:51:34.0444 4968        atikmdag - ok
20:51:34.0577 4968        avgio          (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys
20:51:34.0593 4968        avgio - ok
20:51:34.0683 4968        avgntflt        (1e4114685de1ffa9675e09c6a1fb3f4b) C:\Windows\system32\DRIVERS\avgntflt.sys
20:51:34.0692 4968        avgntflt - ok
20:51:34.0748 4968        avipbb          (0f78d3dae6dedd99ae54c9491c62adf2) C:\Windows\system32\DRIVERS\avipbb.sys
20:51:34.0759 4968        avipbb - ok
20:51:34.0816 4968        BCM42RLY        (bcb27987aaf7962c72b0f337a201cc28) C:\Windows\system32\drivers\BCM42RLY.sys
20:51:34.0825 4968        BCM42RLY - ok
20:51:34.0932 4968        BCM43XX        (b2134f695efd5eb392e906ac2413452e) C:\Windows\system32\DRIVERS\bcmwl6.sys
20:51:34.0981 4968        BCM43XX - ok
20:51:35.0125 4968        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
20:51:35.0189 4968        Beep - ok
20:51:35.0336 4968        blbdrive        (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
20:51:35.0398 4968        blbdrive - ok
20:51:35.0518 4968        bowser          (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
20:51:35.0563 4968        bowser - ok
20:51:35.0601 4968        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
20:51:35.0635 4968        BrFiltLo - ok
20:51:35.0728 4968        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
20:51:35.0763 4968        BrFiltUp - ok
20:51:35.0901 4968        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
20:51:35.0970 4968        Brserid - ok
20:51:36.0004 4968        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
20:51:36.0072 4968        BrSerWdm - ok
20:51:36.0181 4968        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
20:51:36.0245 4968        BrUsbMdm - ok
20:51:36.0284 4968        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
20:51:36.0356 4968        BrUsbSer - ok
20:51:36.0496 4968        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
20:51:36.0562 4968        BTHMODEM - ok
20:51:36.0714 4968        catchme - ok
20:51:36.0841 4968        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
20:51:36.0885 4968        cdfs - ok
20:51:37.0007 4968        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
20:51:37.0054 4968        cdrom - ok
20:51:37.0136 4968        circlass        (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys
20:51:37.0191 4968        circlass - ok
20:51:37.0318 4968        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
20:51:37.0335 4968        CLFS - ok
20:51:37.0587 4968        CmBatt          (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
20:51:37.0645 4968        CmBatt - ok
20:51:37.0920 4968        cmdide          (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
20:51:37.0930 4968        cmdide - ok
20:51:38.0134 4968        Compbatt        (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
20:51:38.0144 4968        Compbatt - ok
20:51:38.0369 4968        cpuz130 - ok
20:51:38.0708 4968        crcdisk        (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
20:51:38.0718 4968        crcdisk - ok
20:51:38.0984 4968        Crusoe          (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
20:51:39.0053 4968        Crusoe - ok
20:51:39.0303 4968        DESVUSB        (92ade7f1b2e1c69e85a3a9040eec37b4) C:\Windows\system32\DRIVERS\desrvusb.sys
20:51:39.0353 4968        DESVUSB - ok
20:51:39.0532 4968        DfsC            (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
20:51:39.0567 4968        DfsC - ok
20:51:39.0733 4968        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
20:51:39.0746 4968        disk - ok
20:51:39.0813 4968        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
20:51:39.0849 4968        drmkaud - ok
20:51:39.0969 4968        DXGKrnl        (5c7e2097b91d689ded7a6ff90f0f3a25) C:\Windows\System32\drivers\dxgkrnl.sys
20:51:40.0053 4968        DXGKrnl - ok
20:51:40.0203 4968        e1express      (908ed85b7806e8af3af5e9b74f7809d4) C:\Windows\system32\DRIVERS\e1e6032.sys
20:51:40.0263 4968        e1express - ok
20:51:40.0312 4968        E1G60          (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
20:51:40.0352 4968        E1G60 - ok
20:51:40.0488 4968        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
20:51:40.0502 4968        Ecache - ok
20:51:40.0575 4968        elxstor        (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
20:51:40.0625 4968        elxstor - ok
20:51:40.0783 4968        ENTECH          (16ebd8bf1d5090923694cc972c7ce1b4) C:\Windows\system32\DRIVERS\ENTECH.sys
20:51:40.0793 4968        ENTECH - ok
20:51:40.0862 4968        ErrDev          (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
20:51:40.0898 4968        ErrDev - ok
20:51:41.0039 4968        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
20:51:41.0092 4968        exfat - ok
20:51:41.0154 4968        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
20:51:41.0178 4968        fastfat - ok
20:51:41.0305 4968        fdc            (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
20:51:41.0341 4968        fdc - ok
20:51:41.0376 4968        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
20:51:41.0387 4968        FileInfo - ok
20:51:41.0412 4968        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
20:51:41.0451 4968        Filetrace - ok
20:51:41.0543 4968        flpydisk        (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
20:51:41.0619 4968        flpydisk - ok
20:51:41.0668 4968        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
20:51:41.0682 4968        FltMgr - ok
20:51:41.0820 4968        Fs_Rec          (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
20:51:41.0854 4968        Fs_Rec - ok
20:51:41.0890 4968        gagp30kx        (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
20:51:41.0902 4968        gagp30kx - ok
20:51:41.0958 4968        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
20:51:41.0967 4968        GEARAspiWDM - ok
20:51:42.0187 4968        hamachi        (7929a161f9951d173ca9900fe7067391) C:\Windows\system32\DRIVERS\hamachi.sys
20:51:42.0196 4968        hamachi - ok
20:51:42.0287 4968        HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
20:51:42.0337 4968        HdAudAddService - ok
20:51:42.0465 4968        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
20:51:42.0553 4968        HDAudBus - ok
20:51:42.0683 4968        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
20:51:42.0769 4968        HidBth - ok
20:51:42.0796 4968        HidIr          (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys
20:51:42.0818 4968        HidIr - ok
20:51:42.0929 4968        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
20:51:42.0970 4968        HidUsb - ok
20:51:43.0018 4968        HpCISSs        (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
20:51:43.0030 4968        HpCISSs - ok
20:51:43.0155 4968        HTTP            (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
20:51:43.0206 4968        HTTP - ok
20:51:43.0258 4968        i2omp          (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
20:51:43.0270 4968        i2omp - ok
20:51:43.0386 4968        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
20:51:43.0422 4968        i8042prt - ok
20:51:43.0492 4968        iaStor          (2358c53f30cb9dcd1d3843c4e2f299b2) C:\Windows\system32\drivers\iastor.sys
20:51:43.0506 4968        iaStor - ok
20:51:43.0608 4968        iaStorV        (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
20:51:43.0623 4968        iaStorV - ok
20:51:43.0767 4968        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
20:51:43.0782 4968        iirsp - ok
20:51:43.0848 4968        intelide        (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
20:51:43.0858 4968        intelide - ok
20:51:43.0961 4968        intelppm        (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
20:51:44.0006 4968        intelppm - ok
20:51:44.0049 4968        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:51:44.0111 4968        IpFilterDriver - ok
20:51:44.0186 4968        IpInIp - ok
20:51:44.0230 4968        IPMIDRV        (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
20:51:44.0258 4968        IPMIDRV - ok
20:51:44.0291 4968        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
20:51:44.0319 4968        IPNAT - ok
20:51:44.0353 4968        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
20:51:44.0394 4968        IRENUM - ok
20:51:44.0493 4968        isapnp          (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
20:51:44.0504 4968        isapnp - ok
20:51:44.0554 4968        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
20:51:44.0568 4968        iScsiPrt - ok
20:51:44.0593 4968        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
20:51:44.0603 4968        iteatapi - ok
20:51:44.0701 4968        itecir          (8bcd857c7932ad005d5f9c89329da2e1) C:\Windows\system32\DRIVERS\itecir.sys
20:51:44.0725 4968        itecir - ok
20:51:44.0759 4968        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
20:51:44.0769 4968        iteraid - ok
20:51:44.0814 4968        k57nd60x        (a67e8cfcad7d4f8b35643d6c79ba64c3) C:\Windows\system32\DRIVERS\k57nd60x.sys
20:51:44.0857 4968        k57nd60x - ok
20:51:44.0946 4968        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
20:51:44.0957 4968        kbdclass - ok
20:51:45.0015 4968        kbdhid          (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
20:51:45.0055 4968        kbdhid - ok
20:51:45.0192 4968        KSecDD          (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
20:51:45.0215 4968        KSecDD - ok
20:51:45.0286 4968        LHidFilt        (23d84187822a0020b9f1ea71c7db3193) C:\Windows\system32\DRIVERS\LHidFilt.Sys
20:51:45.0295 4968        LHidFilt - ok
20:51:45.0401 4968        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
20:51:45.0444 4968        lltdio - ok
20:51:45.0501 4968        LMouFilt        (596499c81cb4b5841f91cfe3f514d202) C:\Windows\system32\DRIVERS\LMouFilt.Sys
20:51:45.0510 4968        LMouFilt - ok
20:51:45.0600 4968        LSI_FC          (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
20:51:45.0612 4968        LSI_FC - ok
20:51:45.0640 4968        LSI_SAS        (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
20:51:45.0652 4968        LSI_SAS - ok
20:51:45.0707 4968        LSI_SCSI        (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
20:51:45.0719 4968        LSI_SCSI - ok
20:51:45.0812 4968        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
20:51:45.0853 4968        luafv - ok
20:51:45.0882 4968        ManyCam - ok
20:51:46.0009 4968        MBAMProtector  (69a6268d7f81e53d568ab4e7e991caf3) C:\Windows\system32\drivers\mbam.sys
20:51:46.0022 4968        MBAMProtector - ok
20:51:46.0054 4968        MBAMSwissArmy - ok
20:51:46.0113 4968        megasas        (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
20:51:46.0124 4968        megasas - ok
20:51:46.0219 4968        MegaSR          (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
20:51:46.0239 4968        MegaSR - ok
20:51:46.0308 4968        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
20:51:46.0351 4968        Modem - ok
20:51:46.0432 4968        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
20:51:46.0467 4968        monitor - ok
20:51:46.0495 4968        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
20:51:46.0507 4968        mouclass - ok
20:51:46.0526 4968        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
20:51:46.0566 4968        mouhid - ok
20:51:46.0634 4968        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
20:51:46.0645 4968        MountMgr - ok
20:51:46.0692 4968        mpio            (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
20:51:46.0704 4968        mpio - ok
20:51:46.0737 4968        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
20:51:46.0789 4968        mpsdrv - ok
20:51:46.0897 4968        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
20:51:46.0907 4968        Mraid35x - ok
20:51:46.0959 4968        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
20:51:47.0016 4968        MRxDAV - ok
20:51:47.0144 4968        mrxsmb          (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
20:51:47.0221 4968        mrxsmb - ok
20:51:47.0349 4968        mrxsmb10        (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:51:47.0379 4968        mrxsmb10 - ok
20:51:47.0393 4968        mrxsmb20        (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:51:47.0413 4968        mrxsmb20 - ok
20:51:47.0505 4968        msahci          (f70590424eefbf5c27a40c67afdb8383) C:\Windows\system32\drivers\msahci.sys
20:51:47.0516 4968        msahci - ok
20:51:47.0540 4968        msdsm          (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
20:51:47.0552 4968        msdsm - ok
20:51:47.0594 4968        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
20:51:47.0636 4968        Msfs - ok
20:51:47.0747 4968        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
20:51:47.0758 4968        msisadrv - ok
20:51:47.0812 4968        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
20:51:47.0840 4968        MSKSSRV - ok
20:51:47.0858 4968        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
20:51:47.0886 4968        MSPCLOCK - ok
20:51:47.0977 4968        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
20:51:48.0013 4968        MSPQM - ok
20:51:48.0076 4968        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
20:51:48.0091 4968        MsRPC - ok
20:51:48.0127 4968        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
20:51:48.0138 4968        mssmbios - ok
20:51:48.0228 4968        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
20:51:48.0265 4968        MSTEE - ok
20:51:48.0323 4968        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
20:51:48.0335 4968        Mup - ok
20:51:48.0390 4968        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
20:51:48.0408 4968        NativeWifiP - ok
20:51:48.0506 4968        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
20:51:48.0531 4968        NDIS - ok
20:51:48.0564 4968        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
20:51:48.0596 4968        NdisTapi - ok
20:51:48.0672 4968        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
20:51:48.0699 4968        Ndisuio - ok
20:51:48.0767 4968        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
20:51:48.0805 4968        NdisWan - ok
20:51:48.0889 4968        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
20:51:48.0912 4968        NDProxy - ok
20:51:48.0940 4968        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
20:51:48.0986 4968        NetBIOS - ok
20:51:49.0041 4968        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
20:51:49.0092 4968        netbt - ok
20:51:49.0226 4968        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
20:51:49.0237 4968        nfrd960 - ok
20:51:49.0351 4968        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
20:51:49.0391 4968        Npfs - ok
20:51:49.0419 4968        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
20:51:49.0456 4968        nsiproxy - ok
20:51:49.0596 4968        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
20:51:49.0640 4968        Ntfs - ok
20:51:49.0674 4968        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
20:51:49.0732 4968        ntrigdigi - ok
20:51:49.0816 4968        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
20:51:49.0843 4968        Null - ok
20:51:49.0873 4968        nvraid          (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
20:51:49.0885 4968        nvraid - ok
20:51:49.0912 4968        nvstor          (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
20:51:49.0923 4968        nvstor - ok
20:51:49.0960 4968        nv_agp          (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
20:51:49.0972 4968        nv_agp - ok
20:51:50.0059 4968        NwlnkFlt - ok
20:51:50.0074 4968        NwlnkFwd - ok
20:51:50.0161 4968        ohci1394        (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
20:51:50.0195 4968        ohci1394 - ok
20:51:50.0257 4968        Parport        (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
20:51:50.0380 4968        Parport - ok
20:51:50.0475 4968        partmgr        (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
20:51:50.0488 4968        partmgr - ok
20:51:50.0515 4968        Parvdm          (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
20:51:50.0580 4968        Parvdm - ok
20:51:50.0616 4968        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
20:51:50.0631 4968        pci - ok
20:51:50.0675 4968        pciide          (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
20:51:50.0685 4968        pciide - ok
20:51:50.0789 4968        pcmcia          (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
20:51:50.0802 4968        pcmcia - ok
20:51:50.0853 4968        PCTBD          (3a0262b85b5bb4d4cfc096ea00ed610b) C:\Windows\system32\Drivers\PCTBD.sys
20:51:50.0863 4968        PCTBD - ok
20:51:50.0924 4968        PCTCore        (3a1efee38dcc8db0b0ee8bb98edd950d) C:\Windows\system32\drivers\PCTCore.sys
20:51:50.0954 4968        PCTCore - ok
20:51:51.0072 4968        pctDS          (af08ec0f2093867ab955e24121ee7002) C:\Windows\system32\drivers\pctDS.sys
20:51:51.0127 4968        pctDS - ok
20:51:51.0220 4968        PCTSD          (6f8c66b756eccff3e75d362a8c66b21e) C:\Windows\system32\Drivers\PCTSD.sys
20:51:51.0233 4968        PCTSD - ok
20:51:51.0334 4968        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
20:51:51.0409 4968        PEAUTH - ok
20:51:51.0523 4968        PLFF            (a20ac92609f3b246be3b761bb72fc6a5) C:\Windows\system32\Drivers\PLFF.sys
20:51:51.0528 4968        PLFF ( UnsignedFile.Multi.Generic ) - warning
20:51:51.0528 4968        PLFF - detected UnsignedFile.Multi.Generic (1)
20:51:51.0618 4968        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
20:51:51.0657 4968        PptpMiniport - ok
20:51:51.0686 4968        Processor      (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
20:51:51.0735 4968        Processor - ok
20:51:51.0848 4968        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
20:51:51.0886 4968        PSched - ok
20:51:51.0944 4968        PxHelp20        (153d02480a0a2f45785522e814c634b6) C:\Windows\system32\Drivers\PxHelp20.sys
20:51:51.0953 4968        PxHelp20 - ok
20:51:52.0115 4968        ql2300          (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
20:51:52.0164 4968        ql2300 - ok
20:51:52.0339 4968        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
20:51:52.0351 4968        ql40xx - ok
20:51:52.0380 4968        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
20:51:52.0422 4968        QWAVEdrv - ok
20:51:52.0612 4968        R300            (be4d8fdc6b2598c46b2b5e6e4fbaafc5) C:\Windows\system32\DRIVERS\atikmdag.sys
20:51:52.0703 4968        R300 - ok
20:51:52.0813 4968        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
20:51:52.0847 4968        RasAcd - ok
20:51:52.0881 4968        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
20:51:52.0917 4968        Rasl2tp - ok
20:51:52.0955 4968        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
20:51:53.0000 4968        RasPppoe - ok
20:51:53.0078 4968        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
20:51:53.0095 4968        RasSstp - ok
20:51:53.0135 4968        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
20:51:53.0170 4968        rdbss - ok
20:51:53.0202 4968        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
20:51:53.0247 4968        RDPCDD - ok
20:51:53.0405 4968        rdpdr          (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
20:51:53.0436 4968        rdpdr - ok
20:51:53.0450 4968        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
20:51:53.0498 4968        RDPENCDD - ok
20:51:53.0553 4968        RDPWD          (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
20:51:53.0594 4968        RDPWD - ok
20:51:53.0686 4968        rimmptsk        (c2ef513bbe069f0d4ee0938a76f975d3) C:\Windows\system32\DRIVERS\rimmptsk.sys
20:51:53.0726 4968        rimmptsk - ok
20:51:53.0831 4968        rimsptsk        (c398bca91216755b098679a8da8a2300) C:\Windows\system32\DRIVERS\rimsptsk.sys
20:51:53.0869 4968        rimsptsk - ok
20:51:53.0883 4968        rismxdp        (2a2554cb24506e0a0508fc395c4a1b42) C:\Windows\system32\DRIVERS\rixdptsk.sys
20:51:53.0947 4968        rismxdp - ok
20:51:54.0039 4968        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
20:51:54.0069 4968        rspndr - ok
20:51:54.0164 4968        SASDIFSV        (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
20:51:54.0173 4968        SASDIFSV - ok
20:51:54.0202 4968        SASKUTIL        (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
20:51:54.0211 4968        SASKUTIL - ok
20:51:54.0327 4968        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
20:51:54.0339 4968        sbp2port - ok
20:51:54.0430 4968        sdbus          (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys
20:51:54.0471 4968        sdbus - ok
20:51:54.0575 4968        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
20:51:54.0636 4968        secdrv - ok
20:51:54.0668 4968        Serenum        (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
20:51:54.0717 4968        Serenum - ok
20:51:54.0745 4968        Serial          (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
20:51:54.0795 4968        Serial - ok
20:51:54.0897 4968        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
20:51:54.0926 4968        sermouse - ok
20:51:54.0973 4968        sffdisk        (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
20:51:54.0998 4968        sffdisk - ok
20:51:55.0028 4968        sffp_mmc        (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
20:51:55.0088 4968        sffp_mmc - ok
20:51:55.0198 4968        sffp_sd        (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys
20:51:55.0221 4968        sffp_sd - ok
20:51:55.0259 4968        sfloppy        (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
20:51:55.0321 4968        sfloppy - ok
20:51:55.0365 4968        sisagp          (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
20:51:55.0376 4968        sisagp - ok
20:51:55.0472 4968        SiSRaid2        (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
20:51:55.0483 4968        SiSRaid2 - ok
20:51:55.0532 4968        SiSRaid4        (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
20:51:55.0544 4968        SiSRaid4 - ok
20:51:55.0600 4968        Smb            (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
20:51:55.0633 4968        Smb - ok
20:51:55.0750 4968        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
20:51:55.0761 4968        spldr - ok
20:51:55.0854 4968        sptd            (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
20:51:55.0854 4968        Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
20:51:55.0864 4968        sptd ( LockedFile.Multi.Generic ) - warning
20:51:55.0864 4968        sptd - detected LockedFile.Multi.Generic (1)
20:51:55.0952 4968        srv            (96a5e2c642af8f591a7366429809506b) C:\Windows\system32\DRIVERS\srv.sys
20:51:55.0995 4968        srv - ok
20:51:56.0028 4968        srv2            (71da2d64880c97e5ffc3c81761632751) C:\Windows\system32\DRIVERS\srv2.sys
20:51:56.0063 4968        srv2 - ok
20:51:56.0114 4968        srvnet          (0c5ab1892ae0fa504218db094bf6d041) C:\Windows\system32\DRIVERS\srvnet.sys
20:51:56.0157 4968        srvnet - ok
20:51:56.0255 4968        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
20:51:56.0268 4968        ssmdrv - ok
20:51:56.0395 4968        STHDA          (805b1fc7e25613ce2dc93c0759d0aa30) C:\Windows\system32\DRIVERS\stwrt.sys
20:51:56.0451 4968        STHDA - ok
20:51:56.0559 4968        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
20:51:56.0570 4968        swenum - ok
20:51:56.0607 4968        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
20:51:56.0617 4968        Symc8xx - ok
20:51:56.0638 4968        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
20:51:56.0648 4968        Sym_hi - ok
20:51:56.0676 4968        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
20:51:56.0686 4968        Sym_u3 - ok
20:51:56.0835 4968        Tcpip          (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
20:51:56.0877 4968        Tcpip - ok
20:51:56.0907 4968        Tcpip6          (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
20:51:56.0943 4968        Tcpip6 - ok
20:51:56.0987 4968        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
20:51:57.0022 4968        tcpipreg - ok
20:51:57.0122 4968        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
20:51:57.0169 4968        TDPIPE - ok
20:51:57.0209 4968        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
20:51:57.0237 4968        TDTCP - ok
20:51:57.0355 4968        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
20:51:57.0378 4968        tdx - ok
20:51:57.0481 4968        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
20:51:57.0495 4968        TermDD - ok
20:51:57.0557 4968        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
20:51:57.0604 4968        tssecsrv - ok
20:51:57.0664 4968        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
20:51:57.0705 4968        tunmp - ok
20:51:57.0785 4968        tunnel          (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
20:51:57.0808 4968        tunnel - ok
20:51:57.0870 4968        uagp35          (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
20:51:57.0881 4968        uagp35 - ok
20:51:57.0937 4968        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
20:51:57.0962 4968        udfs - ok
20:51:58.0037 4968        uliagpkx        (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
20:51:58.0048 4968        uliagpkx - ok
20:51:58.0156 4968        uliahci        (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
20:51:58.0171 4968        uliahci - ok
20:51:58.0208 4968        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
20:51:58.0219 4968        UlSata - ok
20:51:58.0352 4968        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
20:51:58.0364 4968        ulsata2 - ok
20:51:58.0396 4968        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
20:51:58.0446 4968        umbus - ok
20:51:58.0525 4968        UMPass          (88bd96a1baeed33ee8bdf9499c07a841) C:\Windows\system32\DRIVERS\umpass.sys
20:51:58.0559 4968        UMPass - ok
20:51:58.0658 4968        UnlockerDriver5 (4847639d852763ee39415c929470f672) C:\Program Files\Unlocker\UnlockerDriver5.sys
20:51:58.0679 4968        UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - warning
20:51:58.0679 4968        UnlockerDriver5 - detected UnsignedFile.Multi.Generic (1)
20:51:58.0812 4968        USBAAPL        (5c2bdc152bbab34f36473deaf7713f22) C:\Windows\system32\Drivers\usbaapl.sys
20:51:58.0843 4968        USBAAPL - ok
20:51:58.0908 4968        usbaudio        (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
20:51:58.0941 4968        usbaudio - ok
20:51:59.0036 4968        usbccgp        (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
20:51:59.0059 4968        usbccgp - ok
20:51:59.0096 4968        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
20:51:59.0144 4968        usbcir - ok
20:51:59.0199 4968        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
20:51:59.0240 4968        usbehci - ok
20:51:59.0413 4968        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
20:51:59.0451 4968        usbhub - ok
20:51:59.0487 4968        usbohci        (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
20:51:59.0534 4968        usbohci - ok
20:51:59.0588 4968        usbprint        (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
20:51:59.0616 4968        usbprint - ok
20:51:59.0709 4968        usbscan        (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
20:51:59.0754 4968        usbscan - ok
20:51:59.0800 4968        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:51:59.0834 4968        USBSTOR - ok
20:51:59.0927 4968        usbuhci        (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
20:51:59.0967 4968        usbuhci - ok
20:52:00.0017 4968        usb_rndisx      (35c9095fa7076466afbfc5b9ec4b779e) C:\Windows\system32\DRIVERS\usb8023x.sys
20:52:00.0039 4968        usb_rndisx - ok
20:52:00.0158 4968        vga            (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
20:52:00.0194 4968        vga - ok
20:52:00.0229 4968        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
20:52:00.0267 4968        VgaSave - ok
20:52:00.0368 4968        viaagp          (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
20:52:00.0379 4968        viaagp - ok
20:52:00.0407 4968        ViaC7          (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
20:52:00.0436 4968        ViaC7 - ok
20:52:00.0456 4968        viaide          (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
20:52:00.0466 4968        viaide - ok
20:52:00.0500 4968        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
20:52:00.0511 4968        volmgr - ok
20:52:00.0623 4968        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
20:52:00.0641 4968        volmgrx - ok
20:52:00.0684 4968        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
20:52:00.0700 4968        volsnap - ok
20:52:00.0750 4968        vsmraid        (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
20:52:00.0763 4968        vsmraid - ok
20:52:00.0857 4968        VSTHWBS2        (c466021d31ff6c0a6069d12299d80c0b) C:\Windows\system32\DRIVERS\VSTBS23.SYS
20:52:00.0907 4968        VSTHWBS2 - ok
20:52:00.0996 4968        VST_DPV        (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
20:52:01.0063 4968        VST_DPV - ok
20:52:01.0156 4968        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
20:52:01.0227 4968        WacomPen - ok
20:52:01.0283 4968        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
20:52:01.0322 4968        Wanarp - ok
20:52:01.0338 4968        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
20:52:01.0362 4968        Wanarpv6 - ok
20:52:01.0439 4968        Wd              (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
20:52:01.0449 4968        Wd - ok
20:52:01.0507 4968        Wdf01000        (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
20:52:01.0563 4968        Wdf01000 - ok
20:52:01.0647 4968        winachsf        (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
20:52:01.0722 4968        winachsf - ok
20:52:01.0830 4968        WmiAcpi        (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
20:52:01.0867 4968        WmiAcpi - ok
20:52:01.0986 4968        WpdUsb          (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
20:52:02.0010 4968        WpdUsb - ok
20:52:02.0116 4968        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
20:52:02.0144 4968        ws2ifsl - ok
20:52:02.0226 4968        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
20:52:02.0265 4968        WUDFRd - ok
20:52:02.0330 4968        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
20:52:02.0356 4968        \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - infected
20:52:02.0356 4968        \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.b (0)
20:52:03.0202 4968        \Device\Harddisk0\DR0 ( TDSS File System ) - warning
20:52:03.0202 4968        \Device\Harddisk0\DR0 - detected TDSS File System (1)
20:52:03.0232 4968        Boot (0x1200)  (c0d0f91d1a210114d0cc7e292f7d9040) \Device\Harddisk0\DR0\Partition0
20:52:03.0233 4968        \Device\Harddisk0\DR0\Partition0 - ok
20:52:03.0250 4968        Boot (0x1200)  (8f50811674ff470fd2f737a7672f309e) \Device\Harddisk0\DR0\Partition1
20:52:03.0251 4968        \Device\Harddisk0\DR0\Partition1 - ok
20:52:03.0252 4968        ============================================================
20:52:03.0252 4968        Scan finished
20:52:03.0252 4968        ============================================================
20:52:03.0268 3080        Detected object count: 5
20:52:03.0268 3080        Actual detected object count: 5
20:52:13.0493 3080        PLFF ( UnsignedFile.Multi.Generic ) - skipped by user
20:52:13.0494 3080        PLFF ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:52:13.0496 3080        sptd ( LockedFile.Multi.Generic ) - skipped by user
20:52:13.0500 3080        sptd ( LockedFile.Multi.Generic ) - User select action: Skip
20:52:13.0500 3080        UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - skipped by user
20:52:13.0500 3080        UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:52:13.0582 3080        \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - will be cured on reboot
20:52:13.0583 3080        \Device\Harddisk0\DR0 - ok
20:52:13.0583 3080        \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - User select action: Cure
20:52:13.0583 3080        \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
20:52:13.0583 3080        \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip


Atomfrosch 03.11.2011 20:58

Er hat mich gerade direkt danach aufgefordert neuzustarten. Vorher hatte ich schon Unhide benutzt.

Die beiden Fehlermeldungen sind verschwunden, mein Startmenü ist wieder komplett da und der Internetexplorer startet auch nicht mehr von alleine. Super! :D


Edit

Zu früh gefreut, die Startmenüeinträge sind zwar wieder da, aber "Leer". :(

cosinus 03.11.2011 21:53

Zitat:

20:52:13.0582 3080 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - will be cured on reboot
20:52:13.0583 3080 \Device\Harddisk0\DR0 - ok
20:52:13.0583 3080 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - User select action: Cure
20:52:13.0583 3080 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
20:52:13.0583 3080 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
Rootkit und TDSS bitte komplett entfernen!
Starte Windows danach neu und mach ein neues Log mit dem TDSS-Killer

Atomfrosch 03.11.2011 22:08

Code:

22:05:04.0197 5740        TDSS rootkit removing tool 2.6.15.0 Nov  3 2011 17:15:49
22:05:04.0353 5740        ============================================================
22:05:04.0353 5740        Current date / time: 2011/11/03 22:05:04.0353
22:05:04.0353 5740        SystemInfo:
22:05:04.0353 5740       
22:05:04.0353 5740        OS Version: 6.0.6002 ServicePack: 2.0
22:05:04.0353 5740        Product type: Workstation
22:05:04.0353 5740        ComputerName: HERBERT
22:05:04.0354 5740        UserName: Benedikt
22:05:04.0354 5740        Windows directory: C:\Windows
22:05:04.0354 5740        System windows directory: C:\Windows
22:05:04.0354 5740        Processor architecture: Intel x86
22:05:04.0354 5740        Number of processors: 2
22:05:04.0354 5740        Page size: 0x1000
22:05:04.0354 5740        Boot type: Normal boot
22:05:04.0354 5740        ============================================================
22:05:04.0801 5740        Initialize success
22:05:12.0163 5252        ============================================================
22:05:12.0163 5252        Scan started
22:05:12.0163 5252        Mode: Manual; SigCheck; TDLFS;
22:05:12.0163 5252        ============================================================
22:05:12.0680 5252        acedrv11        (27f954120babb8a00f8745d8f5bc9b82) C:\Windows\system32\drivers\acedrv11.sys
22:05:12.0878 5252        acedrv11 - ok
22:05:13.0050 5252        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
22:05:13.0069 5252        ACPI - ok
22:05:13.0190 5252        adfs - ok
22:05:13.0420 5252        adp94xx        (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
22:05:13.0446 5252        adp94xx - ok
22:05:14.0382 5252        adpahci        (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
22:05:14.0399 5252        adpahci - ok
22:05:15.0044 5252        adpu160m        (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
22:05:15.0059 5252        adpu160m - ok
22:05:15.0323 5252        adpu320        (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
22:05:15.0337 5252        adpu320 - ok
22:05:15.0937 5252        AFD            (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
22:05:15.0970 5252        AFD - ok
22:05:16.0221 5252        agp440          (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
22:05:16.0233 5252        agp440 - ok
22:05:16.0897 5252        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
22:05:16.0910 5252        aic78xx - ok
22:05:17.0227 5252        aliide          (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
22:05:17.0239 5252        aliide - ok
22:05:17.0642 5252        amdagp          (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
22:05:17.0655 5252        amdagp - ok
22:05:17.0832 5252        amdide          (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
22:05:17.0843 5252        amdide - ok
22:05:17.0947 5252        AmdK7          (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
22:05:17.0980 5252        AmdK7 - ok
22:05:18.0314 5252        AmdK8          (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
22:05:18.0343 5252        AmdK8 - ok
22:05:18.0929 5252        amdkmdag        (be4d8fdc6b2598c46b2b5e6e4fbaafc5) C:\Windows\system32\DRIVERS\atikmdag.sys
22:05:19.0026 5252        amdkmdag - ok
22:05:19.0504 5252        amdkmdap - ok
22:05:19.0784 5252        ApfiltrService  (1de27858a431a5749e0f3df54ba935b9) C:\Windows\system32\DRIVERS\Apfiltr.sys
22:05:19.0799 5252        ApfiltrService - ok
22:05:20.0004 5252        arc            (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
22:05:20.0019 5252        arc - ok
22:05:20.0218 5252        arcsas          (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
22:05:20.0230 5252        arcsas - ok
22:05:20.0496 5252        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
22:05:20.0525 5252        AsyncMac - ok
22:05:21.0239 5252        atapi          (0d83c87a801a3dfcd1bf73893fe7518c) C:\Windows\system32\drivers\atapi.sys
22:05:21.0256 5252        atapi - ok
22:05:22.0025 5252        atikmdag        (be4d8fdc6b2598c46b2b5e6e4fbaafc5) C:\Windows\system32\DRIVERS\atikmdag.sys
22:05:22.0116 5252        atikmdag - ok
22:05:22.0434 5252        avgio          (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys
22:05:22.0444 5252        avgio - ok
22:05:22.0596 5252        avgntflt        (1e4114685de1ffa9675e09c6a1fb3f4b) C:\Windows\system32\DRIVERS\avgntflt.sys
22:05:22.0896 5252        avgntflt - ok
22:05:23.0094 5252        avipbb          (0f78d3dae6dedd99ae54c9491c62adf2) C:\Windows\system32\DRIVERS\avipbb.sys
22:05:23.0114 5252        avipbb - ok
22:05:23.0264 5252        BCM42RLY        (bcb27987aaf7962c72b0f337a201cc28) C:\Windows\system32\drivers\BCM42RLY.sys
22:05:23.0768 5252        BCM42RLY - ok
22:05:23.0994 5252        BCM43XX        (b2134f695efd5eb392e906ac2413452e) C:\Windows\system32\DRIVERS\bcmwl6.sys
22:05:24.0147 5252        BCM43XX - ok
22:05:24.0343 5252        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
22:05:24.0371 5252        Beep - ok
22:05:24.0498 5252        blbdrive        (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
22:05:24.0527 5252        blbdrive - ok
22:05:24.0602 5252        bowser          (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
22:05:24.0658 5252        bowser - ok
22:05:24.0819 5252        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
22:05:24.0847 5252        BrFiltLo - ok
22:05:25.0113 5252        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
22:05:25.0141 5252        BrFiltUp - ok
22:05:25.0382 5252        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
22:05:25.0433 5252        Brserid - ok
22:05:25.0745 5252        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
22:05:25.0797 5252        BrSerWdm - ok
22:05:25.0929 5252        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
22:05:25.0979 5252        BrUsbMdm - ok
22:05:26.0032 5252        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
22:05:26.0091 5252        BrUsbSer - ok
22:05:26.0232 5252        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
22:05:26.0284 5252        BTHMODEM - ok
22:05:26.0579 5252        catchme - ok
22:05:26.0766 5252        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
22:05:26.0796 5252        cdfs - ok
22:05:26.0921 5252        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
22:05:26.0976 5252        cdrom - ok
22:05:27.0039 5252        circlass        (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys
22:05:27.0092 5252        circlass - ok
22:05:27.0220 5252        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
22:05:27.0238 5252        CLFS - ok
22:05:27.0390 5252        CmBatt          (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
22:05:27.0446 5252        CmBatt - ok
22:05:27.0501 5252        cmdide          (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
22:05:27.0512 5252        cmdide - ok
22:05:27.0603 5252        Compbatt        (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
22:05:27.0615 5252        Compbatt - ok
22:05:27.0764 5252        cpuz130 - ok
22:05:27.0977 5252        crcdisk        (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
22:05:27.0989 5252        crcdisk - ok
22:05:28.0165 5252        Crusoe          (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
22:05:28.0195 5252        Crusoe - ok
22:05:28.0428 5252        DESVUSB        (92ade7f1b2e1c69e85a3a9040eec37b4) C:\Windows\system32\DRIVERS\desrvusb.sys
22:05:28.0441 5252        DESVUSB - ok
22:05:28.0601 5252        DfsC            (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
22:05:28.0695 5252        DfsC - ok
22:05:28.0891 5252        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
22:05:28.0905 5252        disk - ok
22:05:29.0060 5252        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
22:05:29.0101 5252        drmkaud - ok
22:05:29.0166 5252        DXGKrnl        (5c7e2097b91d689ded7a6ff90f0f3a25) C:\Windows\System32\drivers\dxgkrnl.sys
22:05:29.0198 5252        DXGKrnl - ok
22:05:29.0355 5252        e1express      (908ed85b7806e8af3af5e9b74f7809d4) C:\Windows\system32\DRIVERS\e1e6032.sys
22:05:29.0386 5252        e1express - ok
22:05:29.0442 5252        E1G60          (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
22:05:29.0473 5252        E1G60 - ok
22:05:29.0674 5252        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
22:05:29.0689 5252        Ecache - ok
22:05:29.0828 5252        elxstor        (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
22:05:29.0847 5252        elxstor - ok
22:05:29.0947 5252        ENTECH          (16ebd8bf1d5090923694cc972c7ce1b4) C:\Windows\system32\DRIVERS\ENTECH.sys
22:05:29.0957 5252        ENTECH - ok
22:05:30.0159 5252        ErrDev          (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
22:05:30.0188 5252        ErrDev - ok
22:05:30.0430 5252        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
22:05:30.0457 5252        exfat - ok
22:05:30.0568 5252        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
22:05:30.0592 5252        fastfat - ok
22:05:30.0663 5252        fdc            (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
22:05:30.0692 5252        fdc - ok
22:05:30.0779 5252        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
22:05:30.0791 5252        FileInfo - ok
22:05:30.0848 5252        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
22:05:30.0878 5252        Filetrace - ok
22:05:30.0991 5252        flpydisk        (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
22:05:31.0018 5252        flpydisk - ok
22:05:31.0104 5252        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
22:05:31.0120 5252        FltMgr - ok
22:05:31.0301 5252        Fs_Rec          (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
22:05:31.0325 5252        Fs_Rec - ok
22:05:31.0504 5252        gagp30kx        (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
22:05:31.0516 5252        gagp30kx - ok
22:05:31.0650 5252        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
22:05:31.0659 5252        GEARAspiWDM - ok
22:05:31.0923 5252        hamachi        (7929a161f9951d173ca9900fe7067391) C:\Windows\system32\DRIVERS\hamachi.sys
22:05:31.0962 5252        hamachi - ok
22:05:32.0112 5252        HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
22:05:32.0151 5252        HdAudAddService - ok
22:05:32.0213 5252        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:05:32.0324 5252        HDAudBus - ok
22:05:32.0430 5252        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
22:05:32.0480 5252        HidBth - ok
22:05:32.0533 5252        HidIr          (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys
22:05:32.0555 5252        HidIr - ok
22:05:33.0157 5252        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
22:05:33.0181 5252        HidUsb - ok
22:05:33.0310 5252        HpCISSs        (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
22:05:33.0321 5252        HpCISSs - ok
22:05:33.0390 5252        HTTP            (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
22:05:33.0414 5252        HTTP - ok
22:05:33.0527 5252        i2omp          (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
22:05:33.0539 5252        i2omp - ok
22:05:33.0612 5252        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
22:05:33.0634 5252        i8042prt - ok
22:05:33.0750 5252        iaStor          (2358c53f30cb9dcd1d3843c4e2f299b2) C:\Windows\system32\drivers\iastor.sys
22:05:33.0875 5252        iaStor - ok
22:05:34.0045 5252        iaStorV        (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
22:05:34.0060 5252        iaStorV - ok
22:05:34.0303 5252        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
22:05:34.0315 5252        iirsp - ok
22:05:34.0506 5252        intelide        (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
22:05:34.0517 5252        intelide - ok
22:05:34.0664 5252        intelppm        (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
22:05:34.0693 5252        intelppm - ok
22:05:34.0885 5252        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:05:34.0915 5252        IpFilterDriver - ok
22:05:35.0149 5252        IpInIp - ok
22:05:35.0211 5252        IPMIDRV        (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
22:05:35.0240 5252        IPMIDRV - ok
22:05:35.0478 5252        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
22:05:35.0513 5252        IPNAT - ok
22:05:35.0717 5252        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
22:05:35.0746 5252        IRENUM - ok
22:05:35.0869 5252        isapnp          (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
22:05:35.0881 5252        isapnp - ok
22:05:35.0941 5252        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
22:05:35.0956 5252        iScsiPrt - ok
22:05:36.0080 5252        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
22:05:36.0091 5252        iteatapi - ok
22:05:36.0175 5252        itecir          (8bcd857c7932ad005d5f9c89329da2e1) C:\Windows\system32\DRIVERS\itecir.sys
22:05:36.0189 5252        itecir - ok
22:05:36.0334 5252        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
22:05:36.0345 5252        iteraid - ok
22:05:36.0400 5252        k57nd60x        (a67e8cfcad7d4f8b35643d6c79ba64c3) C:\Windows\system32\DRIVERS\k57nd60x.sys
22:05:36.0417 5252        k57nd60x - ok
22:05:36.0555 5252        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
22:05:36.0566 5252        kbdclass - ok
22:05:36.0651 5252        kbdhid          (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
22:05:36.0713 5252        kbdhid - ok
22:05:36.0940 5252        KSecDD          (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
22:05:36.0962 5252        KSecDD - ok
22:05:37.0311 5252        LHidFilt        (23d84187822a0020b9f1ea71c7db3193) C:\Windows\system32\DRIVERS\LHidFilt.Sys
22:05:37.0321 5252        LHidFilt - ok
22:05:37.0549 5252        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
22:05:37.0579 5252        lltdio - ok
22:05:37.0693 5252        LMouFilt        (596499c81cb4b5841f91cfe3f514d202) C:\Windows\system32\DRIVERS\LMouFilt.Sys
22:05:38.0139 5252        LMouFilt - ok
22:05:38.0214 5252        LSI_FC          (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
22:05:38.0227 5252        LSI_FC - ok
22:05:38.0310 5252        LSI_SAS        (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
22:05:38.0322 5252        LSI_SAS - ok
22:05:38.0399 5252        LSI_SCSI        (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
22:05:38.0411 5252        LSI_SCSI - ok
22:05:38.0492 5252        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
22:05:38.0522 5252        luafv - ok
22:05:38.0577 5252        ManyCam - ok
22:05:38.0701 5252        MBAMProtector  (69a6268d7f81e53d568ab4e7e991caf3) C:\Windows\system32\drivers\mbam.sys
22:05:38.0719 5252        MBAMProtector - ok
22:05:38.0773 5252        MBAMSwissArmy - ok
22:05:39.0183 5252        megasas        (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
22:05:39.0194 5252        megasas - ok
22:05:39.0289 5252        MegaSR          (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
22:05:39.0309 5252        MegaSR - ok
22:05:39.0389 5252        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
22:05:39.0417 5252        Modem - ok
22:05:39.0513 5252        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
22:05:39.0542 5252        monitor - ok
22:05:39.0576 5252        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
22:05:39.0587 5252        mouclass - ok
22:05:39.0629 5252        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
22:05:39.0687 5252        mouhid - ok
22:05:39.0804 5252        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
22:05:39.0816 5252        MountMgr - ok
22:05:39.0873 5252        mpio            (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
22:05:39.0885 5252        mpio - ok
22:05:39.0929 5252        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
22:05:40.0001 5252        mpsdrv - ok
22:05:40.0089 5252        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
22:05:40.0100 5252        Mraid35x - ok
22:05:40.0162 5252        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
22:05:40.0191 5252        MRxDAV - ok
22:05:40.0292 5252        mrxsmb          (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:05:40.0308 5252        mrxsmb - ok
22:05:40.0425 5252        mrxsmb10        (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:05:40.0444 5252        mrxsmb10 - ok
22:05:40.0548 5252        mrxsmb20        (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:05:40.0599 5252        mrxsmb20 - ok
22:05:40.0670 5252        msahci          (f70590424eefbf5c27a40c67afdb8383) C:\Windows\system32\drivers\msahci.sys
22:05:40.0681 5252        msahci - ok
22:05:40.0716 5252        msdsm          (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
22:05:40.0729 5252        msdsm - ok
22:05:41.0281 5252        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
22:05:41.0309 5252        Msfs - ok
22:05:41.0456 5252        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
22:05:41.0468 5252        msisadrv - ok
22:05:41.0576 5252        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
22:05:41.0605 5252        MSKSSRV - ok
22:05:41.0712 5252        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
22:05:41.0741 5252        MSPCLOCK - ok
22:05:41.0786 5252        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
22:05:41.0814 5252        MSPQM - ok
22:05:41.0878 5252        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
22:05:41.0893 5252        MsRPC - ok
22:05:42.0025 5252        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
22:05:42.0037 5252        mssmbios - ok
22:05:42.0070 5252        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
22:05:42.0098 5252        MSTEE - ok
22:05:42.0254 5252        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
22:05:42.0267 5252        Mup - ok
22:05:42.0344 5252        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
22:05:42.0362 5252        NativeWifiP - ok
22:05:42.0537 5252        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
22:05:42.0561 5252        NDIS - ok
22:05:42.0606 5252        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
22:05:42.0629 5252        NdisTapi - ok
22:05:42.0736 5252        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
22:05:42.0789 5252        Ndisuio - ok
22:05:42.0920 5252        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:05:42.0944 5252        NdisWan - ok
22:05:42.0987 5252        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
22:05:43.0010 5252        NDProxy - ok
22:05:43.0149 5252        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
22:05:43.0177 5252        NetBIOS - ok
22:05:43.0288 5252        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
22:05:43.0314 5252        netbt - ok
22:05:43.0480 5252        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
22:05:43.0491 5252        nfrd960 - ok
22:05:43.0627 5252        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
22:05:43.0650 5252        Npfs - ok
22:05:43.0795 5252        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
22:05:43.0824 5252        nsiproxy - ok
22:05:44.0016 5252        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
22:05:44.0075 5252        Ntfs - ok
22:05:44.0305 5252        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
22:05:44.0366 5252        ntrigdigi - ok
22:05:44.0447 5252        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
22:05:44.0481 5252        Null - ok
22:05:44.0538 5252        nvraid          (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
22:05:44.0550 5252        nvraid - ok
22:05:44.0699 5252        nvstor          (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
22:05:44.0720 5252        nvstor - ok
22:05:44.0781 5252        nv_agp          (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
22:05:44.0793 5252        nv_agp - ok
22:05:44.0864 5252        NwlnkFlt - ok
22:05:44.0885 5252        NwlnkFwd - ok
22:05:44.0964 5252        ohci1394        (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
22:05:44.0987 5252        ohci1394 - ok
22:05:45.0070 5252        Parport        (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
22:05:45.0121 5252        Parport - ok
22:05:45.0300 5252        partmgr        (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
22:05:45.0314 5252        partmgr - ok
22:05:45.0441 5252        Parvdm          (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
22:05:45.0498 5252        Parvdm - ok
22:05:45.0776 5252        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
22:05:45.0791 5252        pci - ok
22:05:46.0029 5252        pciide          (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
22:05:46.0040 5252        pciide - ok
22:05:46.0221 5252        pcmcia          (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
22:05:46.0234 5252        pcmcia - ok
22:05:46.0318 5252        PCTBD          (3a0262b85b5bb4d4cfc096ea00ed610b) C:\Windows\system32\Drivers\PCTBD.sys
22:05:46.0389 5252        PCTBD - ok
22:05:46.0601 5252        PCTCore        (3a1efee38dcc8db0b0ee8bb98edd950d) C:\Windows\system32\drivers\PCTCore.sys
22:05:46.0639 5252        PCTCore - ok
22:05:46.0759 5252        pctDS          (af08ec0f2093867ab955e24121ee7002) C:\Windows\system32\drivers\pctDS.sys
22:05:46.0811 5252        pctDS - ok
22:05:46.0885 5252        PCTSD          (6f8c66b756eccff3e75d362a8c66b21e) C:\Windows\system32\Drivers\PCTSD.sys
22:05:46.0919 5252        PCTSD - ok
22:05:47.0088 5252        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
22:05:47.0194 5252        PEAUTH - ok
22:05:47.0561 5252        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
22:05:47.0590 5252        PptpMiniport - ok
22:05:47.0696 5252        Processor      (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
22:05:47.0758 5252        Processor - ok
22:05:47.0812 5252        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
22:05:47.0875 5252        PSched - ok
22:05:47.0964 5252        PxHelp20        (153d02480a0a2f45785522e814c634b6) C:\Windows\system32\Drivers\PxHelp20.sys
22:05:47.0974 5252        PxHelp20 - ok
22:05:48.0090 5252        ql2300          (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
22:05:48.0284 5252        ql2300 - ok
22:05:48.0686 5252        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
22:05:48.0699 5252        ql40xx - ok
22:05:48.0834 5252        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
22:05:48.0881 5252        QWAVEdrv - ok
22:05:49.0066 5252        R300            (be4d8fdc6b2598c46b2b5e6e4fbaafc5) C:\Windows\system32\DRIVERS\atikmdag.sys
22:05:49.0219 5252        R300 - ok
22:05:49.0356 5252        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
22:05:49.0385 5252        RasAcd - ok
22:05:49.0435 5252        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:05:49.0465 5252        Rasl2tp - ok
22:05:49.0682 5252        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
22:05:49.0716 5252        RasPppoe - ok
22:05:49.0917 5252        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
22:05:49.0934 5252        RasSstp - ok
22:05:50.0034 5252        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
22:05:50.0154 5252        rdbss - ok
22:05:50.0233 5252        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:05:50.0305 5252        RDPCDD - ok
22:05:50.0347 5252        rdpdr          (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
22:05:50.0424 5252        rdpdr - ok
22:05:50.0492 5252        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
22:05:50.0520 5252        RDPENCDD - ok
22:05:50.0791 5252        RDPWD          (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
22:05:50.0816 5252        RDPWD - ok
22:05:51.0068 5252        rimmptsk        (c2ef513bbe069f0d4ee0938a76f975d3) C:\Windows\system32\DRIVERS\rimmptsk.sys
22:05:51.0081 5252        rimmptsk - ok
22:05:51.0247 5252        rimsptsk        (c398bca91216755b098679a8da8a2300) C:\Windows\system32\DRIVERS\rimsptsk.sys
22:05:51.0260 5252        rimsptsk - ok
22:05:51.0447 5252        rismxdp        (2a2554cb24506e0a0508fc395c4a1b42) C:\Windows\system32\DRIVERS\rixdptsk.sys
22:05:51.0465 5252        rismxdp - ok
22:05:51.0600 5252        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
22:05:51.0639 5252        rspndr - ok
22:05:51.0780 5252        SASDIFSV        (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
22:05:51.0788 5252        SASDIFSV - ok
22:05:51.0829 5252        SASKUTIL        (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
22:05:51.0838 5252        SASKUTIL - ok
22:05:51.0976 5252        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
22:05:51.0987 5252        sbp2port - ok
22:05:52.0213 5252        sdbus          (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys
22:05:52.0243 5252        sdbus - ok
22:05:52.0413 5252        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
22:05:52.0462 5252        secdrv - ok
22:05:52.0617 5252        Serenum        (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
22:05:52.0723 5252        Serenum - ok
22:05:52.0761 5252        Serial          (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
22:05:52.0850 5252        Serial - ok
22:05:52.0901 5252        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
22:05:52.0947 5252        sermouse - ok
22:05:52.0999 5252        sffdisk        (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
22:05:53.0022 5252        sffdisk - ok
22:05:53.0244 5252        sffp_mmc        (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
22:05:53.0273 5252        sffp_mmc - ok
22:05:53.0541 5252        sffp_sd        (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys
22:05:53.0565 5252        sffp_sd - ok
22:05:53.0724 5252        sfloppy        (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
22:05:53.0809 5252        sfloppy - ok
22:05:53.0974 5252        sisagp          (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
22:05:53.0986 5252        sisagp - ok
22:05:54.0048 5252        SiSRaid2        (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
22:05:54.0060 5252        SiSRaid2 - ok
22:05:54.0120 5252        SiSRaid4        (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
22:05:54.0132 5252        SiSRaid4 - ok
22:05:54.0401 5252        Smb            (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
22:05:54.0434 5252        Smb - ok
22:05:54.0593 5252        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
22:05:54.0605 5252        spldr - ok
22:05:54.0778 5252        srv            (96a5e2c642af8f591a7366429809506b) C:\Windows\system32\DRIVERS\srv.sys
22:05:54.0889 5252        srv - ok
22:05:54.0911 5252        srv2            (71da2d64880c97e5ffc3c81761632751) C:\Windows\system32\DRIVERS\srv2.sys
22:05:54.0956 5252        srv2 - ok
22:05:54.0984 5252        srvnet          (0c5ab1892ae0fa504218db094bf6d041) C:\Windows\system32\DRIVERS\srvnet.sys
22:05:55.0019 5252        srvnet - ok
22:05:55.0230 5252        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
22:05:55.0240 5252        ssmdrv - ok
22:05:55.0448 5252        STHDA          (805b1fc7e25613ce2dc93c0759d0aa30) C:\Windows\system32\DRIVERS\stwrt.sys
22:05:55.0469 5252        STHDA - ok
22:05:55.0624 5252        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
22:05:55.0635 5252        swenum - ok
22:05:55.0756 5252        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
22:05:55.0766 5252        Symc8xx - ok
22:05:55.0809 5252        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
22:05:55.0820 5252        Sym_hi - ok
22:05:55.0903 5252        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
22:05:55.0914 5252        Sym_u3 - ok
22:05:56.0032 5252        Tcpip          (2756186e287139310997090797e0182b) C:\Windows\system32\drivers\tcpip.sys
22:05:56.0071 5252        Tcpip - ok
22:05:56.0168 5252        Tcpip6          (2756186e287139310997090797e0182b) C:\Windows\system32\DRIVERS\tcpip.sys
22:05:56.0210 5252        Tcpip6 - ok
22:05:56.0280 5252        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
22:05:56.0570 5252        tcpipreg - ok
22:05:56.0749 5252        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
22:05:57.0016 5252        TDPIPE - ok
22:05:57.0136 5252        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
22:05:57.0391 5252        TDTCP - ok
22:05:57.0615 5252        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
22:05:57.0639 5252        tdx - ok
22:05:57.0764 5252        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
22:05:57.0777 5252        TermDD - ok
22:05:57.0895 5252        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:05:57.0946 5252        tssecsrv - ok
22:05:58.0147 5252        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
22:05:58.0163 5252        tunmp - ok
22:05:58.0357 5252        tunnel          (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
22:05:58.0372 5252        tunnel - ok
22:05:58.0463 5252        uagp35          (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
22:05:58.0475 5252        uagp35 - ok
22:05:58.0675 5252        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
22:05:58.0713 5252        udfs - ok
22:05:58.0852 5252        uliagpkx        (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
22:05:58.0865 5252        uliagpkx - ok
22:05:58.0927 5252        uliahci        (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
22:05:58.0948 5252        uliahci - ok
22:05:59.0068 5252        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
22:05:59.0081 5252        UlSata - ok
22:05:59.0157 5252        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
22:05:59.0170 5252        ulsata2 - ok
22:05:59.0223 5252        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
22:05:59.0256 5252        umbus - ok
22:05:59.0363 5252        UMPass          (88bd96a1baeed33ee8bdf9499c07a841) C:\Windows\system32\DRIVERS\umpass.sys
22:05:59.0395 5252        UMPass - ok
22:05:59.0573 5252        USBAAPL        (5c2bdc152bbab34f36473deaf7713f22) C:\Windows\system32\Drivers\usbaapl.sys
22:05:59.0587 5252        USBAAPL - ok
22:05:59.0846 5252        usbaudio        (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
22:05:59.0871 5252        usbaudio - ok
22:06:00.0040 5252        usbccgp        (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
22:06:00.0064 5252        usbccgp - ok
22:06:00.0201 5252        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
22:06:00.0257 5252        usbcir - ok
22:06:00.0326 5252        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
22:06:00.0349 5252        usbehci - ok
22:06:00.0518 5252        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
22:06:00.0543 5252        usbhub - ok
22:06:00.0591 5252        usbohci        (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
22:06:00.0641 5252        usbohci - ok
22:06:00.0899 5252        usbprint        (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
22:06:01.0024 5252        usbprint - ok
22:06:01.0320 5252        usbscan        (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
22:06:01.0343 5252        usbscan - ok
22:06:01.0545 5252        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:06:01.0572 5252        USBSTOR - ok
22:06:01.0694 5252        usbuhci        (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
22:06:01.0803 5252        usbuhci - ok
22:06:01.0861 5252        usb_rndisx      (35c9095fa7076466afbfc5b9ec4b779e) C:\Windows\system32\DRIVERS\usb8023x.sys
22:06:01.0887 5252        usb_rndisx - ok
22:06:01.0957 5252        vga            (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
22:06:01.0986 5252        vga - ok
22:06:02.0252 5252        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
22:06:02.0282 5252        VgaSave - ok
22:06:02.0639 5252        viaagp          (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
22:06:02.0652 5252        viaagp - ok
22:06:02.0845 5252        ViaC7          (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
22:06:02.0874 5252        ViaC7 - ok
22:06:03.0060 5252        viaide          (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
22:06:03.0072 5252        viaide - ok
22:06:03.0161 5252        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
22:06:03.0173 5252        volmgr - ok
22:06:03.0273 5252        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
22:06:03.0291 5252        volmgrx - ok
22:06:03.0487 5252        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
22:06:03.0503 5252        volsnap - ok
22:06:03.0655 5252        vsmraid        (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
22:06:03.0668 5252        vsmraid - ok
22:06:03.0818 5252        VSTHWBS2        (c466021d31ff6c0a6069d12299d80c0b) C:\Windows\system32\DRIVERS\VSTBS23.SYS
22:06:03.0850 5252        VSTHWBS2 - ok
22:06:04.0057 5252        VST_DPV        (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
22:06:04.0106 5252        VST_DPV - ok
22:06:04.0305 5252        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
22:06:04.0354 5252        WacomPen - ok
22:06:04.0532 5252        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
22:06:04.0558 5252        Wanarp - ok
22:06:04.0579 5252        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
22:06:04.0602 5252        Wanarpv6 - ok
22:06:04.0767 5252        Wd              (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
22:06:04.0792 5252        Wd - ok
22:06:05.0025 5252        Wdf01000        (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
22:06:05.0049 5252        Wdf01000 - ok
22:06:05.0277 5252        winachsf        (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
22:06:05.0320 5252        winachsf - ok
22:06:05.0513 5252        WmiAcpi        (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:06:05.0541 5252        WmiAcpi - ok
22:06:05.0713 5252        WpdUsb          (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
22:06:05.0728 5252        WpdUsb - ok
22:06:05.0849 5252        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
22:06:05.0879 5252        ws2ifsl - ok
22:06:06.0015 5252        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:06:06.0044 5252        WUDFRd - ok
22:06:06.0141 5252        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
22:06:06.0767 5252        \Device\Harddisk0\DR0 - ok
22:06:06.0809 5252        Boot (0x1200)  (c0d0f91d1a210114d0cc7e292f7d9040) \Device\Harddisk0\DR0\Partition0
22:06:06.0811 5252        \Device\Harddisk0\DR0\Partition0 - ok
22:06:06.0838 5252        Boot (0x1200)  (8f50811674ff470fd2f737a7672f309e) \Device\Harddisk0\DR0\Partition1
22:06:06.0840 5252        \Device\Harddisk0\DR0\Partition1 - ok
22:06:06.0844 5252        ============================================================
22:06:06.0844 5252        Scan finished
22:06:06.0844 5252        ============================================================
22:06:06.0862 4740        Detected object count: 0
22:06:06.0863 4740        Actual detected object count: 0

Jetzt hab ich nur noch das Problem:
http://img20.myimg.de/klein1a444_thumb.jpg#

Jeder Menüeintrag (bis auf die Standardeinträge von Windows) sind "leer".

cosinus 04.11.2011 08:58

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

Atomfrosch 04.11.2011 15:40

Code:

ComboFix 11-11-04.02 - Benedikt 04.11.2011  15:22:08.2.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3069.1765 [GMT 1:00]
ausgeführt von:: c:\users\Benedikt\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\AutocompletePro
c:\program files\AutocompletePro\64\AutocompletePro64.dll
c:\program files\AutocompletePro\AutocompletePro.dll
c:\program files\AutocompletePro\chrome\autocompleteprochrome.crx
c:\program files\AutocompletePro\FireFoxExtension.exe
c:\program files\AutocompletePro\InstTracker.exe
c:\program files\AutocompletePro\support@predictad.com\chrome.manifest
c:\program files\AutocompletePro\support@predictad.com\chrome\content\browserOverlay.xul
c:\program files\AutocompletePro\support@predictad.com\chrome\content\options.js
c:\program files\AutocompletePro\support@predictad.com\chrome\content\options.xul
c:\program files\AutocompletePro\support@predictad.com\chrome\content\utils.js
c:\program files\AutocompletePro\support@predictad.com\defaults\preferences\predictad.js
c:\program files\AutocompletePro\support@predictad.com\install.rdf
c:\program files\AutocompletePro\unins000.dat
c:\program files\AutocompletePro\unins000.exe
c:\users\Benedikt\AppData\Roaming\mIRC\logs\status.log
c:\windows\bwUnin-8.1.1.50-8876480SL.exe
c:\windows\IsUn0407.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\security\Database\tmp.edb
c:\windows\ST6UNST.000
c:\windows\system32\HotFixQ0306270.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-10-04 bis 2011-11-04  ))))))))))))))))))))))))))))))
.
.
2011-11-04 14:34 . 2011-11-04 14:34        --------        d-----w-        c:\users\Benedikt\AppData\Local\temp
2011-11-04 14:34 . 2011-11-04 14:34        --------        d-----w-        c:\users\Public\AppData\Local\temp
2011-11-04 14:34 . 2011-11-04 14:34        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-11-04 14:15 . 2011-11-04 14:15        56200        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{8105B8C1-E0BC-4885-8FC0-0D327902207D}\offreg.dll
2011-11-03 20:54 . 2011-10-07 03:48        6668624        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{8105B8C1-E0BC-4885-8FC0-0D327902207D}\mpengine.dll
2011-11-03 20:23 . 2011-08-25 16:15        555520        ----a-w-        c:\windows\system32\UIAutomationCore.dll
2011-11-03 20:22 . 2010-10-15 13:48        1205080        ----a-w-        c:\windows\system32\ntdll.dll
2011-11-03 20:08 . 2011-04-29 15:59        276992        ----a-w-        c:\windows\system32\schannel.dll
2011-11-03 19:29 . 2011-11-03 19:29        --------        d-----w-        C:\_OTL
2011-11-03 15:14 . 2011-11-03 15:14        --------        d-----w-        c:\program files\ESET
2011-11-03 11:57 . 2011-11-03 11:57        --------        d-----w-        c:\users\Benedikt\AppData\Roaming\SUPERAntiSpyware.com
2011-11-03 11:56 . 2011-11-03 11:57        --------        d-----w-        c:\program files\SUPERAntiSpyware
2011-11-03 11:56 . 2011-11-03 11:56        --------        d-----w-        c:\programdata\SUPERAntiSpyware.com
2011-11-02 21:05 . 2011-11-02 21:05        --------        d-----w-        c:\users\Benedikt\AppData\Local\Threat Expert
2011-11-02 20:55 . 2011-11-02 21:13        --------        d-----w-        c:\program files\Spybot - Search & Destroy
2011-11-02 20:55 . 2011-11-02 21:01        --------        d-----w-        c:\programdata\Spybot - Search & Destroy
2011-11-02 20:45 . 2011-10-25 12:38        149456        ----a-w-        c:\windows\SGDetectionTool.dll
2011-11-02 20:45 . 2011-10-25 12:38        767952        ----a-w-        c:\windows\BDTSupport.dll
2011-11-02 20:41 . 2011-10-28 10:02        185560        ----a-w-        c:\windows\system32\drivers\PCTSD.sys
2011-11-02 20:41 . 2011-11-02 20:44        --------        d-----w-        c:\programdata\PC Tools
2011-10-31 12:00 . 2011-10-31 12:00        --------        d-----w-        c:\users\Benedikt\AppData\Local\O&O
2011-10-30 11:24 . 2011-10-30 11:24        --------        d-----w-        c:\users\Benedikt\AppData\Local\Downloaded Installations
2011-10-30 11:14 . 2011-10-30 11:14        --------        d-----w-        c:\program files\CCleaner
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-03 03:06 . 2010-10-04 08:05        472808        ----a-w-        c:\windows\system32\deployJava1.dll
2011-08-31 16:00 . 2010-08-10 10:54        22216        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-10-06 15:18 . 2011-03-21 09:33        134104        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-06-30 196608]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-03-12 3563520]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-05 281768]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-06-26 442467]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-11-25 98304]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-11-29 55824]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-5-13 1058088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54        551296        ----a-w-        c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-22 08:03        10536        ----a-w-        c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdAuxService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdCoreService]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Privoxy.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Privoxy.lnk
backup=c:\windows\pss\Privoxy.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Benedikt^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk]
path=c:\users\Benedikt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
backup=c:\windows\pss\Dell Dock.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Benedikt^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk]
path=c:\users\Benedikt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
backup=c:\windows\pss\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 01:06        40048        ----a-w-        c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 01:44        500208        ------w-        c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CORSAIR_PLUtil]
2004-11-11 16:37        90112        ----a-r-        c:\program files\Corsair\Corsair Flash Voyager Utility\PLBkMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
2009-05-21 10:13        206064        ----a-w-        c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2008-03-11 10:44        16384        ----a-w-        c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-21 02:25        125952        ----a-w-        c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 16:16        421160        ----a-w-        c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2007-11-29 00:17        55824        ----a-w-        c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2008-01-14 08:13        132392        ------w-        c:\program files\Dell\MediaDirect\PCMService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfFactory Dispatcher v3]
2008-03-05 09:21        516096        ----a-w-        c:\windows\System32\spool\drivers\w32x86\3\fppdis3a.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38        421888        ----a-w-        c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-05-13 14:12        26192168        ----a-r-        c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2775041620-371297593-3811378524-1000]
"EnableNotificationsRef"=dword:00000002
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1c989597b8740;Google Update Service (gupdate1c989597b8740);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-07 133104]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2008-05-04 3548672]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
R3 cpuz130;cpuz130;c:\users\Benedikt\AppData\Local\Temp\cpuz130\cpuz_x32.sys [x]
R3 DESVUSB;Dell service driver;c:\windows\system32\DRIVERS\desrvusb.sys [2007-05-11 17536]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-07 133104]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools\PC Tools Security\pctsAuxs.exe [2011-10-27 402336]
R3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2008-01-21 987648]
R3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [2008-01-21 251904]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-10-22 331880]
S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-10-07 341656]
S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD.sys [2011-10-28 185560]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-11 116608]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2008-07-30 277736]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\aestsrv.exe [2008-06-26 73728]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-04-30 136360]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [2011-10-25 542672]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-04-28 161048]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2008-03-14 54784]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2008-03-11 203264]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216]
S3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\Drivers\PCTBD.sys [2011-09-28 56840]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
WindowsMobile        REG_MULTI_SZ          wcescomm rapimgr
LocalServiceRestricted        REG_MULTI_SZ          WcesComm RapiMgr
.
Inhalt des "geplante Tasks" Ordners
.
2011-11-04 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-14 12:06]
.
2011-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-07 19:19]
.
2011-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-07 19:19]
.
2011-11-04 c:\windows\Tasks\User_Feed_Synchronization-{50F6F6D8-62B8-44EE-8129-9F539D72EE3C}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page =
mLocal Page =
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
TCP: DhcpNameServer = 192.168.2.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\9gbwpvs7.default\
FF - prefs.js: browser.search.selectedEngine - Amazon.de
FF - prefs.js: browser.startup.homepage - www.t-online.de
FF - prefs.js: keyword.URL - hxxp://www.google.de/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-PLFFAP - c:\windows\system32\HotfixQ0306270.exe
SafeBoot-28621050.sys
MSConfigStartUp-AdobeCS4ServiceManager - c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
MSConfigStartUp-ICQ - c:\program files\ICQ7.4\ICQ.exe
MSConfigStartUp-MgKPyEORiQUvGj - c:\programdata\MgKPyEORiQUvGj.exe
MSConfigStartUp-OODefragTray - c:\program files\OO Software\Defrag\oodtray.exe
MSConfigStartUp-PDVD9LanguageShortcut - c:\program files\CyberLink\PowerDVD9\Language\Language.exe
MSConfigStartUp-RemoteControl9 - c:\program files\CyberLink\PowerDVD9\PDVD9Serv.exe
AddRemove-AutocompletePro3_is1 - c:\program files\AutocompletePro\unins000.exe
AddRemove-Worms Armageddon - c:\windows\IsUn0407.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-11-04 15:34
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
.
c:\users\Benedikt\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 1
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-11-04  15:38:08
ComboFix-quarantined-files.txt  2011-11-04 14:38
ComboFix2.txt  2010-08-10 13:16
.
Vor Suchlauf: 22 Verzeichnis(se), 14.797.385.728 Bytes frei
Nach Suchlauf: 23 Verzeichnis(se), 14.580.854.784 Bytes frei
.
- - End Of File - - 19DFC8DF7C5430FDECEC4A3C177A481F


cosinus 04.11.2011 15:43

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).


Atomfrosch 04.11.2011 17:03

GMER
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2011-11-04 16:50:37
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.LV01
Running: 4w2e80sm.exe; Driver: C:\Users\Benedikt\AppData\Local\Temp\ufrdipog.sys


---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools)  ZwCreateProcess [0x82EF2C0C]
SSDT            \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools)  ZwCreateProcessEx [0x82EF2ED4]
SSDT            8D497426                                                                      ZwCreateSection
SSDT            8D49742B                                                                      ZwSetContextThread
SSDT            \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools)  ZwTerminateProcess [0x82EF280A]
SSDT            \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools)  ZwCreateUserProcess [0x82EF31D0]

---- Kernel code sections - GMER 1.0.15 ----

.text          ntkrnlpa.exe!KeSetEvent + 209                                                828EE98C 3 Bytes  [0C, 2C, EF] {OR AL, 0x2c; OUT DX, EAX}
.text          ntkrnlpa.exe!KeSetEvent + 20D                                                828EE990 3 Bytes  [D4, 2E, EF] {AAM 0x2e; OUT DX, EAX}
.text          ntkrnlpa.exe!KeSetEvent + 215                                                828EE998 4 Bytes  [26, 74, 49, 8D]
.text          ntkrnlpa.exe!KeSetEvent + 56D                                                828EECF0 4 Bytes  [2B, 74, 49, 8D] {SUB ESI, [ECX+ECX*2-0x73]}
.text          ntkrnlpa.exe!KeSetEvent + 621                                                828EEDA4 3 Bytes  [0A, 28, EF] {OR CH, [EAX]; OUT DX, EAX}
.text          ...                                                                         
.text          C:\Windows\system32\DRIVERS\atikmdag.sys                                      section is writeable [0x8EC0D000, 0x1FB0FA, 0xE8000020]
.reloc          C:\Windows\system32\drivers\acedrv11.sys                                      section is executable [0xA0F22600, 0x25B0C, 0xE0000060]
?              C:\Windows\system32\Drivers\PROCEXP113.SYS                                    Das System kann die angegebene Datei nicht finden. !
?              C:\Users\Benedikt\AppData\Local\Temp\catchme.sys                              Das System kann die angegebene Datei nicht finden. !

---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\fastfat \Fat                                                      fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

OSAM
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 15:47:32 on 04.11.2011

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 7.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Software Updater.job" - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"BCMWLCPL.CPL" - "Dell Inc." - C:\Windows\system32\BCMWLCPL.CPL
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"bcmwlcpl.cpl" - "Dell Inc." - C:\Windows\System32\bcmwlcpl.cpl
"Pando" - "Pando Networks" - C:\Program Files\Pando Networks\Media Booster\PMB.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"acedrv11" (acedrv11) - "Protect Software GmbH" - C:\Windows\system32\drivers\acedrv11.sys
"adfs" (adfs) - ? - C:\Windows\system32\drivers\adfs.sys  (File not found)
"amdkmdap" (amdkmdap) - ? - C:\Windows\System32\DRIVERS\atikmpag.sys  (File not found)
"avgio" (avgio) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avgio.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"BCM42RLY" (BCM42RLY) - "Broadcom Corporation" - C:\Windows\System32\drivers\BCM42RLY.sys
"catchme" (catchme) - ? - C:\Users\Benedikt\AppData\Local\Temp\catchme.sys  (File not found)
"cpuz130" (cpuz130) - ? - C:\Users\Benedikt\AppData\Local\Temp\cpuz130\cpuz_x32.sys  (File not found)
"ENTECH" (ENTECH) - "EnTech Taiwan" - C:\Windows\system32\DRIVERS\ENTECH.sys
"Hamachi Network Interface" (hamachi) - "LogMeIn, Inc." - C:\Windows\System32\DRIVERS\hamachi.sys
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"ManyCam Virtual Webcam, WDM Video Capture Driver" (ManyCam) - ? - C:\Windows\System32\DRIVERS\ManyCam.sys  (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"MBAMSwissArmy" (MBAMSwissArmy) - ? - C:\Windows\system32\drivers\mbamswissarmy.sys  (File not found)
"mbr" (mbr) - ? - C:\ComboFix\mbr.sys  (Hidden registry entry, rootkit activity | File not found)
"PC Tools Browser Defender Driver" (PCTBD) - "PC Tools" - C:\Windows\System32\Drivers\PCTBD.sys
"PC Tools Data Store" (pctDS) - "PC Tools" - C:\Windows\System32\drivers\pctDS.sys
"PC Tools Spyware Doctor Driver" (PCTSD) - "PC Tools" - C:\Windows\System32\Drivers\PCTSD.sys
"PCTools KDS" (PCTCore) - "PC Tools" - C:\Windows\System32\drivers\PCTCore.sys
"SASDIFSV" (SASDIFSV) - "SUPERAdBlocker.com and SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
"SASKUTIL" (SASKUTIL) - "SUPERAdBlocker.com and SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{9462A756-7B47-47BC-8C80-C34B9B80B32B} "BackWeb GA Pluggable Protocol" - "Logitech Inc." - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} "SABShellExecuteHook Class" - "SuperAdBlocker.com" - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{872A9397-E0D6-4e28-B64D-52B8D0A7EA35} "DisplayCplExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiamaxx.dll
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{5A7B2149-7840-4531-B7B4-58F0F1CB0A6E} "IMAPIShlXt Class" - "Dell Inc" - C:\Windows\IMAPIShellExt.dll
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{DC70C4A5-2044-4c59-B806-DEFB9AE0DF7C} "KbLogiExt Class" - "Logitech, Inc." - C:\Program Files\Logitech\SetPoint\kbcplext.dll
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? -  (File not found | COM-object registry key not found)
{B9B9F083-2B04-452A-8691-83694AC1037B} "LogiExt Class" - "Logitech, Inc." - C:\Program Files\Logitech\SetPoint\mcplext.dll
{BB7DF450-F119-11CD-8465-00AA00425D90} "Microsoft Access Custom Icon Handler" - "Microsoft Corporation" - C:\Programme\Microsoft Office\Office\soa800.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\ONFILTER.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - C:\Program Files\Real\RealPlayer\rpshell.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} "UnlockerShellExtension" - ? - C:\Program Files\Unlocker\UnlockerCOM.dll  (File found, but it contains no detailed information)
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Program Files\WinRAR\rarext.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBarLayout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_29.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{7530BFB8-7293-4D34-9923-61A11451AFC5} "OnlineScanner Control" - "ESET" - C:\PROGRA~1\ESET\ESETON~1\ONLINE~1.OCX / hxxp://download.eset.com/special/eos/OnlineScanner.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
{53707962-6F74-2D53-2644-206D7942484F} "ClsidExtension" - "Safer Networking Limited" - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "In Blog veröffentlichen" - "Microsoft Corporation" - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
"PartyPoker.net" - ? - C:\Programs\PartyGaming.Net\PartyPokerNet\RunPF.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype add-on for Internet Explorer" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{0FB6A909-6086-458F-BD92-1F8EE10042A0} "AC-Pro" - ? - C:\Program Files\AutocompletePro\AutocompletePro.dll  (File not found)
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
{CA6319C0-31B7-401E-A518-A07C3DB8F777} "CBrowserHelperObject Object" - "Dell Inc." - C:\Program Files\Dell\BAE\BAE.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" - "Google Inc." - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{2A0F3D1B-0909-4FF4-B272-609CCE6054E7} "PC Tools Browser Defender BHO" - ? - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll  (File not found)
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype add-on for Internet Explorer" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{53707962-6F74-2D53-2644-206D7942484F} "Spybot-S&D IE Protection" - "Safer Networking Limited" - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"RocketDock" - ? - "C:\Program Files\RocketDock\RocketDock.exe"  (File found, but it contains no detailed information)
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"Broadcom Wireless Manager UI" - "Dell Inc." - C:\Windows\system32\WLTRAY.exe
"dellsupportcenter" - "SupportSoft, Inc." - "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
"ECenter" - " " - C:\Dell\E-Center\EULALauncher.exe
"IAAnotif" - "Intel Corporation" - "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

[Network Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order )-----
"Dell Wireless WLAN Card Logon Provider" - "Dell Inc." - C:\Windows\System32\BCMLogon.dll

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"FPP3:" - "FinePrint Software, LLC" - C:\Windows\system32\fppmon3.dll
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"ASP.NET State Service" (aspnet_state) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"Browser Defender Update Service" (Browser Defender Update Service) - "Threat Expert Ltd." - C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
"Dell Wireless WLAN Tray Service" (wltrysvc) - ? - C:\Windows\System32\WLTRYSVC.EXE  (File found, but it contains no detailed information)
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"Dock Login Service" (DockLoginService) - "Stardock Corporation" - C:\Program Files\Dell\DellDock\DockLogin.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate1c989597b8740)" (gupdate1c989597b8740) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoToAssist" (GoToAssist) - "Citrix Online, a division of Citrix Systems, Inc." - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
"ICQ Service" (ICQ Service) - ? - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
"Intel(R) Matrix Storage Event Monitor" (IAANTMON) - "Intel Corporation" - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"Logitech Bluetooth Service" (LBTServ) - "Logitech, Inc." - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"PC Tools Auxiliary Service" (sdAuxService) - "PC Tools" - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe
"PC Tools Security Service" (sdCoreService) - "PC Tools" - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe
"PLFlash DeviceIoControl Service" (PLFlash DeviceIoControl Service) - "Prolific Technology Inc." - C:\Windows\System32\IoctlSvc.exe
"SAS Core Service" (!SASCORE) - "SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
"SBSD Security Center Service" (SBSDWSCService) - "Safer Networking Ltd." - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files\Common Files\Steam\SteamService.exe
"SupportSoft Sprocket Service (dellsupportcenter)" (sprtsvc_dellsupportcenter) - "SupportSoft, Inc." - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

[Winlogon]
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )-----
"!SASWinLogon" - "SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
"GoToAssist" - "Citrix Online, a division of Citrix Systems, Inc." - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries )-----
"PCTOOLS CONTENT FILTER PROVIDER" - "PC Tools Research Pty Ltd." - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

aswMBR ist im Scan mit nem Bluescreen abgestürzt, irgendwas mit NTFS.sys stand auf dem Bluescreen.

Windows sagt:

Code:

Problemsignatur:
  Problemereignisname:        BlueScreen
  Betriebsystemversion:        6.0.6002.2.2.0.768.3
  Gebietsschema-ID:        1031

Zusatzinformationen zum Problem:
  BCCode:        24
  BCP1:        001904AA
  BCP2:        A9572A14
  BCP3:        A9572710
  BCP4:        8AE1BF1E
  OS Version:        6_0_6002
  Service Pack:        2_0
  Product:        768_1

Dateien, die bei der Beschreibung des Problems hilfreich sind:
  C:\Windows\Minidump\Mini110411-01.dmp
  C:\Users\Benedikt\AppData\Local\temp\WER-56175-0.sysdata.xml
  C:\Users\Benedikt\AppData\Local\temp\WER7915.tmp.version.txt


cosinus 04.11.2011 19:17

Starte Windows neu und probier aswMBR bitte nochmal.

Atomfrosch 04.11.2011 19:58

Jetzt hat's geklappt

Code:

aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-11-04 19:34:23
-----------------------------
19:34:23.551    OS Version: Windows 6.0.6002 Service Pack 2
19:34:23.551    Number of processors: 2 586 0xF0D
19:34:23.552    ComputerName: HERBERT  UserName:
19:34:24.360    Initialize success
19:34:29.514    AVAST engine defs: 11110400
19:34:36.426    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:34:36.430    Disk 0 Vendor: TOSHIBA_ LV01 Size: 152627MB BusType: 3
19:34:36.448    Disk 0 MBR read successfully
19:34:36.451    Disk 0 MBR scan
19:34:36.456    Disk 0 Windows VISTA default MBR code
19:34:36.461    Disk 0 scanning sectors +312578048
19:34:36.570    Disk 0 scanning C:\Windows\system32\drivers
19:34:51.309    Service scanning
19:34:53.663    Modules scanning
19:35:18.833    Disk 0 trace - called modules:
19:35:18.858    ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys iastor.sys hal.dll
19:35:18.863    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86df7820]
19:35:18.870    3 CLASSPNP.SYS[8afa08b3] -> nt!IofCallDriver -> [0x8681e760]
19:35:18.877    5 PCTCore.sys[82eec407] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x85d30030]
19:35:19.936    AVAST engine scan C:\Windows
19:35:27.238    AVAST engine scan C:\Windows\system32
19:38:53.365    AVAST engine scan C:\Windows\system32\drivers
19:39:28.359    AVAST engine scan C:\Users\Benedikt
19:52:04.732    AVAST engine scan C:\ProgramData
19:55:48.621    Scan finished successfully
19:57:34.145    Disk 0 MBR has been saved successfully to "C:\Users\Benedikt\Desktop\MBR.dat"
19:57:34.161    The log file has been saved successfully to "C:\Users\Benedikt\Desktop\aswMBR.txt"


cosinus 04.11.2011 20:27

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!


Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Atomfrosch 04.11.2011 20:34

Werde ich gleich machen, kannst du mir auch irgendwie bei dem Problem helfen, dass alle meine Startmenüeinträge "leer" sind?

cosinus 04.11.2011 20:37

mach bitte erst die Kontrollscans

Atomfrosch 04.11.2011 21:26

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 11/04/2011 at 09:26 PM

Application Version : 5.0.1134

Core Rules Database Version : 7899
Trace Rules Database Version: 5711

Scan type      : Complete Scan
Total Scan Time : 00:49:59

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC Off - Administrator

Memory items scanned      : 731
Memory threats detected  : 0
Registry items scanned    : 39473
Registry threats detected : 0
File items scanned        : 52372
File threats detected    : 64

Adware.Tracking Cookie
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@ad.ad-srv[2].txt [ /ad.ad-srv ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@ad.adc-serv[2].txt [ /ad.adc-serv ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@ad.adition[2].txt [ /ad.adition ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@ad.zanox[2].txt [ /ad.zanox ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@adfarm1.adition[1].txt [ /adfarm1.adition ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@ads.pubmatic[1].txt [ /ads.pubmatic ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@atdmt[1].txt [ /atdmt ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@invitemedia[1].txt [ /invitemedia ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@webmasterplan[2].txt [ /webmasterplan ]
        C:\Users\Benedikt\AppData\Roaming\Microsoft\Windows\Cookies\benedikt@zanox[1].txt [ /zanox ]
        C:\USERS\BENEDIKT\Cookies\benedikt@webmasterplan[2].txt [ Cookie:benedikt@webmasterplan.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@zanox[1].txt [ Cookie:benedikt@zanox.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@adfarm1.adition[1].txt [ Cookie:benedikt@adfarm1.adition.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@ad.zanox[2].txt [ Cookie:benedikt@ad.zanox.com/ ]
        C:\USERS\BENEDIKT\Cookies\benedikt@invitemedia[1].txt [ Cookie:benedikt@invitemedia.com/ ]
        .im.banner.t-online.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .countomat.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .deutschepostag.112.2o7.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tns-counter.ru [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\BENEDIKT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GBWPVS7.DEFAULT\COOKIES.SQLITE ]

Code:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8084

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

04.11.2011 21:34:36
mbam-log-2011-11-04 (21-34-36).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 174918
Laufzeit: 4 Minute(n), 16 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


Atomfrosch 05.11.2011 09:30

Code:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=e32b6420ee5990489406f9b8c9fbdf86
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-11-03 05:05:55
# local_time=2011-11-03 06:05:55 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1797 16775165 100 100 66762 95230042 59999 0
# compatibility_mode=5892 16776573 100 100 10641 157866206 0 0
# compatibility_mode=8192 67108863 100 0 3814 3814 0 0
# scanned=184697
# found=1
# cleaned=0
# scan_time=6477
C:\Users\Benedikt\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\d8b9bf1-63ad81bd        a variant of Java/Agent.DW trojan (unable to clean)        00000000000000000000000000000000        I
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=e32b6420ee5990489406f9b8c9fbdf86
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-11-04 08:37:28
# local_time=2011-11-04 09:37:28 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1797 16775165 100 100 172302 95335582 165539 0
# compatibility_mode=5892 16776573 100 100 4133 157971746 0 0
# compatibility_mode=8192 67108863 100 0 109354 109354 0 0
# scanned=369
# found=0
# cleaned=0
# scan_time=29
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=53251
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=e32b6420ee5990489406f9b8c9fbdf86
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-11-05 08:26:16
# local_time=2011-11-05 09:26:16 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1797 16775165 100 100 207899 95371179 201136 0
# compatibility_mode=5892 16776573 100 100 3861 158007343 0 0
# compatibility_mode=8192 67108863 100 0 144951 144951 0 0
# scanned=198805
# found=0
# cleaned=0
# scan_time=6961


cosinus 07.11.2011 08:19

Zitat:

Art des Suchlaufs: Quick-Scan
Sry aber ich wollte einen Vollscan sehen...bitte nachholen und Log posten!
Denk dran vorher die Signaturen von Malwarebytes zu aktualisieren, da gibt es sehr häufig neue Updates!

Atomfrosch 08.11.2011 20:57

Code:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8115

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

08.11.2011 20:56:35
mbam-log-2011-11-08 (20-56-34).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 360095
Laufzeit: 3 Stunde(n), 10 Minute(n), 58 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


cosinus 08.11.2011 21:06

Sieht ok aus, da wurden nur Cookies gefunden.
Noch Probleme oder weitere Funde in der Zwischenzeit?

Atomfrosch 08.11.2011 21:11

Ja, mein Startmenü ist immer noch leer, keine Ahnung wie ich das hinbiegen kann.

z.B.: Start -> Alle Programme -> AntiVir -> Leer (statt irgendwelchen Einträgen)

So sieht das bei allen Einträgen aus, nur "Zubehör" und "WinRar" sind komplett da.

Sonst hab ich aber keine Probleme mehr, keine Fehler, keine Meldungen, keine Viren.

cosinus 09.11.2011 08:46

Erstell dir mal ein neues Benutzerkonto in der Systemsteuerung und log dich dann darin ein. Ist dort das Startmenü auch leer?

Atomfrosch 09.11.2011 15:21

Jepp, die Einträge sind da, aber die Ordner sind leer.

cosinus 10.11.2011 09:49

Hm, vor ca. einem 3/4 jahr hatten wir hier häufig die Problematik, dass das Startmenü leer war nach einer Infektion. Ich hab damals immer den u.z. Text gepostet. Ich fürchte aber die Verknüpfungen sind bei dir weg. Wenn die nicht im genannten Ordner liegen, könnte eine Dateisuche nach den Verknüpfungen mit etwas Glück noch helfen.

Zitat:

Durch die Infektion wurde dein Startmenü leergefegt, bei mir bisher bekannten Varianten verschiebt der Schädling alle Verknüpfungen nach %tmp%\smtmp

Eigentlich sollte unhide die Verküpfungen selbst zurück an die richtige Stelle kopieren. Wenn nicht, mach es selbst.

Deine Verknüpfungen sollten jetzt hier sein: (lass dir vorher alle Dateien anzeigen => http://www.trojaner-board.de/59624-a...-sichtbar.html )

C:\Dokumente und Einstellungen\[DEIN_NAME]\Lokale Einstellungen\Temp\smtmp

Sie müssen passend nach

C:\Dokumente und Einstellungen\[DEIN_NAME]\Startmenü

kopiert werden.



Schau bitte nach ob der Ordner smtmp entweder hier

=> C:\Qoobox\Quarantine\C\Dokumente und Einstellungen\[DEIN_NAME]\Lokale Einstellungen\Temp\smtmp

oder hier

=> Dokumente und Einstellungen\[DEIN_NAME]\Lokale Einstellungen\Temp\smtmp

zu finden ist. Stell sicher, dass dir alle Dateien angezeigt werden => http://www.trojaner-board.de/59624-a...-sichtbar.html

Atomfrosch 10.11.2011 17:44

Den Ordner SMTMP gibts bei mir nicht, den Ordner "TMP" auch nicht.

Zitat:

Der Pfad ist nicht verfügbar

Auf C:\Users\Benedikt\Startmenü kann nicht zugegriffen werden.

Zugriff verweigert.
Bei "C:\Dokumente und Einstellungen\Benedikt\Startmenü" kommt der Fehler ebenfalls.

In "C:\Qoobox\Quarantine\C\..." ist auch nichts zu finden.

Auf "...\Lokale Einstellungen\" kann ich nicht zugreifen,

Zitat:

Der Pfad ist nicht verfügbar.

...

Zugriff verweigert
:(

cosinus 10.11.2011 21:36

Zitat:

Auf C:\Users\Benedikt\Startmenü kann nicht zugegriffen werden.

Zugriff verweigert.
Dann navigier mal C:\Users\Benedikt\
Rechtsklick auf Starmenü => Eigenschaften => Sicherheit
Prüf dort die Zugriffsrechte.

Atomfrosch 10.11.2011 21:58

Ist das denn korrekt, das "Startmdenü" nur eine Verknüpfung ist?

"System" / "Benedikt" / "Administratoren" hat vollen Zugriff, nur "Spezielle Berechtigungen" hat keinen Haken, kein Haken ist bei "Verweigern" gesetzt.
"Jeder" hat nur einen Haken bei "Spezielle Berechtigungen", bei "Verweigern".

cosinus 10.11.2011 22:07

Zitat:

Ist das denn korrekt, das "Startmdenü" nur eine Verknüpfung ist?
Bin ich mir jetzt nicht so sicher, hab hier auch gerade kein Win7 da um das zu prüfen.
Das Betreten des Ordners wird aber immer noch verweigert? Mit vollem Zugriff solltest du da eigentlich rankommen

Atomfrosch 11.11.2011 20:38

Ja, ich kann da gar nicht drauf zugreifen, immer wieder "Zugriff verweigert".

Atomfrosch 15.11.2011 06:53

Haste keine Idee mehr wie ich das wieder hinbiegen kann? :(

cosinus 15.11.2011 09:32

Du könntest den Rechner mal von einer Live-CD wie Knoppix oder Ubuntu im Probiermodus starten. Damit solltest du an den Ordner rankommen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 08:07 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131