Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Aus Sicherheitsgründen wurde Ihr Windowssystem blockiert (https://www.trojaner-board.de/107154-sicherheitsgruenden-wurde-windowssystem-blockiert.html)

Toolman 29.12.2011 11:16

Aus Sicherheitsgründen wurde Ihr Windowssystem blockiert
 
Hallo,

vor ein paar Tagen hat es mein Laptop auch erwischt: "Achtung! Aus Sicherheitsgründen ...".
Durch googlen bin ich auf dieses Forum gelangt.
Was habe ich bisher getan: Malewarebytes drüber laufen lassen (wie empfohlen) auch Avira. Außerdem habe ich OTL runtergeladen, die Dateien habe ich angehängt.
Ich muß mich gleich mal outen, daß ich nur ein Anwender-Depp bin :party:, d.h. ich wahrscheinlich ein wenig länger brauche um die Lösungsschritte zu verstehen. Bitte habt Geduld mit mir. Vielen Dank!!!!
Greetz Toolman

Nachtrag:
Malewarebytes und Avira hatte ich auch vor Weihnachten drüber laufen lassen, seitdem läuft der Rechner wieder und die Anzeige (Aus Sicherheits....) kommt nicht mehr.

cosinus 29.12.2011 17:52

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

Toolman 30.12.2011 15:07

Hallo,

hier sind die Dateien.
Danke schonmal fürs Helfen.
Gruß Toolman

cosinus 30.12.2011 19:24

Bitte nun routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

Toolman 30.12.2011 21:32

thanx a lot!
Ich werde es die nächsten Tage, nach deiner Anleitung, machen und melde mich dann wieder.
Auf jedenfall schonmal einen guten Rutsch.
greetz Toolman

Toolman 30.12.2011 23:17

Hier der Vollscan von Malewarebytes, der Rest folgt dann Morgen:


Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 911122204

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

30.12.2011 23:13:46
mbam-log-2011-12-30 (23-13-46).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Durchsuchte Objekte: 311657
Laufzeit: 1 Stunde(n), 31 Minute(n), 7 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Toolman 31.12.2011 12:57

jetzt habe ich auch das mit den Code-Tags kapiert :rolleyes:
hier sind die früheren Ergebnisse von Avira:

Code:

In der Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

Code:

In der Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

Code:

In der Datei 'C:\Users\*****\AppData\Local\Temp\wpbt0.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

Code:

In der Datei 'C:\Users\*****\AppData\Local\Temp\wpbt0.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

Code:

Die Datei 'C:\Users\*****\AppData\Local\Temp\wpbt0.dll'
enthielt einen Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan].
Durchgeführte Aktion(en):
Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4a1421e0.qua' verschoben!

Code:

In der Datei 'C:\Users\*****\AppData\Local\Temp\wpbt0.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

Code:

In der Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

Code:

In der Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

Code:

In der Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern

Code:

Die Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
enthielt einen Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan].
Durchgeführte Aktion(en):
Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4a3c3791.qua' verschoben!

Code:

Die Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
enthielt einen Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan].
Durchgeführte Aktion(en):
Beim Versuch eine Sicherungskopie der Datei anzulegen ist ein Fehler aufgetreten und die Datei wurde nicht gelöscht. Fehlernummer: 26004.
Die Quelldatei konnte nicht gefunden werden.
Es wird versucht die Aktion mit Hilfe der ARK Library durchzuführen.
Die Datei konnte nicht ins Quarantäneverzeichnis verschoben werden!
Die Datei existiert nicht!

Das Ergebnis vom ESET-Online-Scanner folgt später auch noch.

Toolman 31.12.2011 18:16

hier der log-file vom ESET Online Scanner:

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=c7a3da6080e28e4885483560b5110904
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-12-31 04:51:05
# local_time=2011-12-31 05:51:05 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7600 NT
# compatibility_mode=1797 16775165 100 94 1198843 61867171 420063 0
# compatibility_mode=5893 16776573 100 94 4036 76956565 0 0
# compatibility_mode=8192 67108863 100 0 3846 3846 0 0
# scanned=185031
# found=0
# cleaned=0
# scan_time=23550

dann mal guten Rutsch:party:

greetz Toolman

cosinus 02.01.2012 11:02

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Toolman 02.01.2012 21:20

hi,

hier das Teil vom OTL:

Code:

OTL logfile created on: 1/2/2012 9:11:27 PM - Run 2
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\****\Downloads
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.97 Gb Total Physical Memory | 2.81 Gb Available Physical Memory | 70.93% Memory free
7.93 Gb Paging File | 6.51 Gb Available in Paging File | 82.06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 198.29 Gb Total Space | 55.91 Gb Free Space | 28.20% Space Free | Partition Type: NTFS
Drive D: | 252.37 Gb Total Space | 0.01 Gb Free Space | 0.00% Space Free | Partition Type: NTFS
 
Computer Name: KARLE-PC | User Name: Karle | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\***\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe (DivX, LLC)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (SAMSUNG Electronics)
PRC - C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe (SEC)
PRC - C:\Windows\SysWOW64\Rezip.exe ()
PRC - C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe ()
PRC - C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (yksvc) -- C:\Windows\SysNative\yk62x64.dll (Marvell)
SRV:64bit: - (AgereModemAudio) -- C:\Program Files\LSI SoftModem\agr64svc.exe (LSI Corporation)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Rezip) -- C:\Windows\SysWOW64\Rezip.exe ()
SRV - (AAV UpdateService) -- C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe ()
SRV - (BcmSqlStartupSvc) -- C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (yukonw7) -- C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation                                            )
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (SABI) -- C:\Windows\SysNative\drivers\SABI.sys (SAMSUNG ELECTRONICS)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Sichere Suche"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.5
FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2
FF - prefs.js..extensions.enabledItems: 5
FF - prefs.js..extensions.enabledItems: 3
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=mcafee&p="
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files (x86)\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/06/01 08:56:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2010/12/10 17:47:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2010/12/10 17:47:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/12/31 11:11:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/08/31 22:02:30 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/06/01 08:56:20 | 000,000,000 | ---D | M]
 
[2009/12/29 15:37:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\****\AppData\Roaming\mozilla\Extensions
[2011/08/31 11:55:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\4n9ebtwp.default\extensions
[2010/09/16 20:14:47 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\4n9ebtwp.default\extensions\firefox@tvunetworks.com
[2011/08/31 22:02:33 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2010/05/17 20:27:26 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/12/31 11:11:37 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/05/17 20:27:09 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/12/31 11:11:34 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011/12/31 11:11:34 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/12/31 11:11:34 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011/12/31 11:11:34 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011/03/23 23:20:32 | 000,002,027 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2011/12/31 11:11:34 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011/12/31 11:11:34 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
 
O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg64.dll (Google Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87C6C7B7-D575-4782-94B9-3A82028B3821}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D07C869-74F5-43C7-8DCC-BD925A258217}: DhcpNameServer = 192.168.80.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D07C869-74F5-43C7-8DCC-BD925A258217}: NameServer = 192.168.2.1,194.25.2.129
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{7dff7414-ced9-11de-a2f1-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7dff7414-ced9-11de-a2f1-806e6f6e6963}\Shell\AutoRun\command - "" = E:\AutoMenu.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011/12/31 11:14:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2011/12/28 21:30:12 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CASIO
[2011/12/28 21:30:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CASIO
[2011/12/28 21:13:50 | 000,000,000 | ---D | C] -- C:\windows\SysNative\EventProviders
[2011/12/22 20:49:52 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\Malwarebytes
[2011/12/22 20:49:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/12/22 20:49:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/12/22 20:49:39 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2011/12/22 20:49:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/12/21 20:57:38 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\Avira
[2011/12/17 10:10:14 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\csrsrv.dll
[2011/12/17 10:09:49 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msfeeds.dll
[2011/12/17 10:09:48 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\iepeers.dll
[2011/12/17 10:09:48 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieui.dll
[2011/12/17 10:09:48 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieui.dll
[2011/12/17 10:09:47 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iepeers.dll
[2011/12/17 10:09:47 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mshtmled.dll
[2011/12/17 10:09:47 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmled.dll
[2011/12/17 10:09:46 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\html.iec
[2011/12/17 10:09:46 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\html.iec
[2011/12/17 10:09:46 | 000,134,144 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\url.dll
[2011/12/17 10:09:46 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\url.dll
[2011/12/17 10:09:46 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\licmgr10.dll
[2011/12/17 10:09:46 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\licmgr10.dll
[2011/12/17 10:09:46 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msfeedssync.exe
[2011/12/17 10:09:46 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msfeedssync.exe
[2011/12/17 10:08:32 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\EncDec.dll
[2011/12/17 10:08:32 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\EncDec.dll
[2011/12/12 22:46:44 | 000,000,000 | ---D | C] -- C:\Users\****\Documents\Fotobuch-Datei Lana und Ella 2011_mcf-Dateien
 
========== Files - Modified Within 30 Days ==========
 
[2012/01/02 21:15:00 | 001,572,864 | -HS- | M] () -- C:\Users\****\ntuser.dat
[2012/01/02 21:06:25 | 000,001,104 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/02 21:00:00 | 000,013,936 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/02 21:00:00 | 000,013,936 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/02 20:52:31 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
[2012/01/02 20:52:27 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/01/02 20:52:15 | 3193,393,152 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/01 21:20:00 | 000,001,108 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/31 18:17:48 | 016,204,142 | -H-- | M] () -- C:\Users\****\AppData\Local\IconCache.db
[2011/12/28 21:42:52 | 005,364,274 | ---- | M] () -- C:\Users\****\Documents\Casio_Anleitung.pdf
[2011/12/28 21:30:16 | 000,001,157 | ---- | M] () -- C:\Users\****\Desktop\Photo Transport.lnk
[2011/12/27 11:05:49 | 000,524,288 | -HS- | M] () -- C:\Users\****\ntuser.dat{ad98db59-306a-11e1-aec3-00245419b635}.TMContainer00000000000000000002.regtrans-ms
[2011/12/27 11:05:49 | 000,524,288 | -HS- | M] () -- C:\Users\****\ntuser.dat{ad98db59-306a-11e1-aec3-00245419b635}.TMContainer00000000000000000001.regtrans-ms
[2011/12/27 11:05:49 | 000,065,536 | -HS- | M] () -- C:\Users\****\ntuser.dat{ad98db59-306a-11e1-aec3-00245419b635}.TM.blf
[2011/12/25 11:02:16 | 001,646,182 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2011/12/25 11:02:16 | 000,711,370 | ---- | M] () -- C:\windows\SysNative\perfh007.dat
[2011/12/25 11:02:16 | 000,662,950 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2011/12/25 11:02:16 | 000,153,766 | ---- | M] () -- C:\windows\SysNative\perfc007.dat
[2011/12/25 11:02:16 | 000,124,144 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2011/12/22 20:49:45 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/17 15:20:04 | 000,434,192 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2011/12/12 22:46:44 | 000,024,771 | ---- | M] () -- C:\Users\****\Documents\Fotobuch-Datei ***** 2011.mcf
[2011/12/12 22:46:44 | 000,000,000 | ---- | M] () -- C:\Users\****\Documents\Fotobuch-Datei *****.mcf~
 
========== Files Created - No Company Name ==========
 
[2011/12/28 21:42:52 | 005,364,274 | ---- | C] () -- C:\Users\****\Documents\Casio_Anleitung.pdf
[2011/12/28 21:30:16 | 000,001,157 | ---- | C] () -- C:\Users\****\Desktop\Photo Transport.lnk
[2011/12/27 11:05:49 | 000,524,288 | -HS- | C] () -- C:\Users\****\ntuser.dat{ad98db59-306a-11e1-aec3-00245419b635}.TMContainer00000000000000000002.regtrans-ms
[2011/12/27 11:05:49 | 000,524,288 | -HS- | C] () -- C:\Users\****\ntuser.dat{ad98db59-306a-11e1-aec3-00245419b635}.TMContainer00000000000000000001.regtrans-ms
[2011/12/27 11:05:49 | 000,065,536 | -HS- | C] () -- C:\Users\****\ntuser.dat{ad98db59-306a-11e1-aec3-00245419b635}.TM.blf
[2011/12/22 20:49:45 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/12 22:46:43 | 000,024,771 | ---- | C] () -- C:\Users\****\Documents\Fotobuch-Datei Lana und Ella 2011.mcf
[2011/12/12 22:46:43 | 000,000,000 | ---- | C] () -- C:\Users\****\Documents\Fotobuch-Datei Lana und Ella 2011.mcf~
[2011/05/15 07:49:21 | 000,006,656 | ---- | C] () -- C:\Users\****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/16 19:49:32 | 000,017,408 | ---- | C] () -- C:\Users\****\AppData\Local\WebpageIcons.db
[2010/06/01 08:45:46 | 000,181,714 | ---- | C] () -- C:\windows\hpoins44.dat
[2009/12/30 21:15:54 | 000,000,331 | ---- | C] () -- C:\windows\game.ini
[2009/12/29 14:18:05 | 016,204,142 | -H-- | C] () -- C:\Users\****\AppData\Local\IconCache.db
[2009/12/29 14:12:56 | 000,000,002 | ---- | C] () -- C:\windows\HotFixList.ini
[2009/12/29 14:07:25 | 001,526,948 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2009/12/29 14:05:11 | 000,114,616 | ---- | C] () -- C:\Users\****\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/10/28 23:06:34 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2009/10/28 07:31:35 | 000,307,200 | ---- | C] () -- C:\windows\SetDisplayResolution.exe
[2009/10/28 07:16:46 | 000,311,296 | ---- | C] () -- C:\windows\SysWow64\Rezip.exe
[2009/07/14 06:38:36 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat
[2009/07/14 03:35:51 | 000,000,741 | ---- | C] () -- C:\windows\SysWow64\NOISE.DAT
[2009/07/14 03:35:42 | 000,001,405 | ---- | C] () -- C:\windows\msdfmap.ini
[2009/07/14 03:34:57 | 000,000,545 | ---- | C] () -- C:\windows\win.ini
[2009/07/14 03:34:57 | 000,000,219 | ---- | C] () -- C:\windows\system.ini
[2009/07/14 03:34:42 | 000,215,943 | ---- | C] () -- C:\windows\SysWow64\dssec.dat
[2009/07/14 01:10:29 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:59:36 | 000,982,196 | ---- | C] () -- C:\windows\SysWow64\igkrng500.bin
[2009/07/13 22:59:36 | 000,139,824 | ---- | C] () -- C:\windows\SysWow64\igfcg500.bin
[2009/07/13 22:59:36 | 000,097,448 | ---- | C] () -- C:\windows\SysWow64\igfcg500m.bin
[2009/07/13 22:59:35 | 000,417,344 | ---- | C] () -- C:\windows\SysWow64\igcompkrng500.bin
[2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\windows\SysWow64\msjetoledb40.dll
[2009/06/11 10:30:02 | 000,000,586 | ---- | C] () -- C:\windows\hpomdl44.dat
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\windows\SysWow64\mlang.dat
 
========== LOP Check ==========
 
[2011/05/15 23:14:13 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Canneverbe Limited
[2010/12/10 17:47:22 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Local
[2010/12/26 11:48:27 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\OpenOffice.org
[2011/06/02 07:48:48 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Sony
[2011/10/22 12:52:21 | 000,032,640 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >

und hier der custom-scan:

Code:

OTL logfile created on: 1/2/2012 9:22:54 PM - Run 2
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\****\Downloads
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.97 Gb Total Physical Memory | 2.88 Gb Available Physical Memory | 72.71% Memory free
7.93 Gb Paging File | 6.57 Gb Available in Paging File | 82.80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 198.29 Gb Total Space | 55.92 Gb Free Space | 28.20% Space Free | Partition Type: NTFS
Drive D: | 252.37 Gb Total Space | 0.01 Gb Free Space | 0.00% Space Free | Partition Type: NTFS
 
Computer Name: KARLE-PC | User Name: **** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\****\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe (DivX, LLC)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (SAMSUNG Electronics)
PRC - C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe (SEC)
PRC - C:\Windows\SysWOW64\Rezip.exe ()
PRC - C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe ()
PRC - C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (yksvc) -- C:\Windows\SysNative\yk62x64.dll (Marvell)
SRV:64bit: - (AgereModemAudio) -- C:\Program Files\LSI SoftModem\agr64svc.exe (LSI Corporation)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Rezip) -- C:\Windows\SysWOW64\Rezip.exe ()
SRV - (AAV UpdateService) -- C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe ()
SRV - (BcmSqlStartupSvc) -- C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (yukonw7) -- C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation                                            )
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (SABI) -- C:\Windows\SysNative\drivers\SABI.sys (SAMSUNG ELECTRONICS)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Sichere Suche"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.5
FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2
FF - prefs.js..extensions.enabledItems: 5
FF - prefs.js..extensions.enabledItems: 3
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=mcafee&p="
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files (x86)\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/06/01 08:56:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2010/12/10 17:47:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2010/12/10 17:47:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/12/31 11:11:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/08/31 22:02:30 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/06/01 08:56:20 | 000,000,000 | ---D | M]
 
[2009/12/29 15:37:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\****\AppData\Roaming\mozilla\Extensions
[2011/08/31 11:55:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\4n9ebtwp.default\extensions
[2010/09/16 20:14:47 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\4n9ebtwp.default\extensions\firefox@tvunetworks.com
[2011/08/31 22:02:33 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2010/05/17 20:27:26 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/12/31 11:11:37 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/05/17 20:27:09 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/12/31 11:11:34 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011/12/31 11:11:34 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/12/31 11:11:34 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011/12/31 11:11:34 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011/03/23 23:20:32 | 000,002,027 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2011/12/31 11:11:34 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011/12/31 11:11:34 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
 
O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg64.dll (Google Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87C6C7B7-D575-4782-94B9-3A82028B3821}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D07C869-74F5-43C7-8DCC-BD925A258217}: DhcpNameServer = 192.168.80.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D07C869-74F5-43C7-8DCC-BD925A258217}: NameServer = 192.168.2.1,194.25.2.129
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{7dff7414-ced9-11de-a2f1-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7dff7414-ced9-11de-a2f1-806e6f6e6963}\Shell\AutoRun\command - "" = E:\AutoMenu.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: mcmscsvc - Service
SafeBootMin:64bit: MCODS - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: mcmscsvc - Service
SafeBootMin: MCODS - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: mcmscsvc - Service
SafeBootNet:64bit: MCODS - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: MpfService - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: mcmscsvc - Service
SafeBootNet: MCODS - Service
SafeBootNet: Messenger - Service
SafeBootNet: MpfService - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011/12/31 11:14:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2011/12/28 21:30:12 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CASIO
[2011/12/28 21:30:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CASIO
[2011/12/28 21:13:50 | 000,000,000 | ---D | C] -- C:\windows\SysNative\EventProviders
[2011/12/22 20:49:52 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\Malwarebytes
[2011/12/22 20:49:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/12/22 20:49:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/12/22 20:49:39 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2011/12/22 20:49:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/12/21 20:57:38 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\Avira
[2011/12/12 22:46:44 | 000,000,000 | ---D | C] -- C:\Users\****\Documents\Fotobuch-Datei ***** 2011_mcf-Dateien
 
========== Files - Modified Within 30 Days ==========
 
[2012/01/02 21:20:03 | 000,001,108 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/02 21:06:25 | 000,001,104 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/02 21:00:00 | 000,013,936 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/02 21:00:00 | 000,013,936 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/02 20:52:27 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/01/02 20:52:15 | 3193,393,152 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/28 21:42:52 | 005,364,274 | ---- | M] () -- C:\Users\****\Documents\Casio_Anleitung.pdf
[2011/12/28 21:30:16 | 000,001,157 | ---- | M] () -- C:\Users\****\Desktop\Photo Transport.lnk
[2011/12/25 11:02:16 | 001,646,182 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2011/12/25 11:02:16 | 000,711,370 | ---- | M] () -- C:\windows\SysNative\perfh007.dat
[2011/12/25 11:02:16 | 000,662,950 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2011/12/25 11:02:16 | 000,153,766 | ---- | M] () -- C:\windows\SysNative\perfc007.dat
[2011/12/25 11:02:16 | 000,124,144 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2011/12/22 20:49:45 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/17 15:20:04 | 000,434,192 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2011/12/12 22:46:44 | 000,024,771 | ---- | M] () -- C:\Users\****\Documents\Fotobuch-Datei ***** 2011.mcf
[2011/12/12 22:46:44 | 000,000,000 | ---- | M] () -- C:\Users\****\Documents\Fotobuch-Datei ***** 2011.mcf~
 
========== Files Created - No Company Name ==========
 
[2011/12/28 21:42:52 | 005,364,274 | ---- | C] () -- C:\Users\****\Documents\Casio_Anleitung.pdf
[2011/12/28 21:30:16 | 000,001,157 | ---- | C] () -- C:\Users\****\Desktop\Photo Transport.lnk
[2011/12/22 20:49:45 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/12 22:46:43 | 000,024,771 | ---- | C] () -- C:\Users\****\Documents\Fotobuch-Datei ***** 2011.mcf
[2011/12/12 22:46:43 | 000,000,000 | ---- | C] () -- C:\Users\****\Documents\Fotobuch-Datei ***** 2011.mcf~
[2011/05/15 07:49:21 | 000,006,656 | ---- | C] () -- C:\Users\****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/16 19:49:32 | 000,017,408 | ---- | C] () -- C:\Users\****\AppData\Local\WebpageIcons.db
[2010/06/01 08:45:46 | 000,181,714 | ---- | C] () -- C:\windows\hpoins44.dat
[2009/12/30 21:15:54 | 000,000,331 | ---- | C] () -- C:\windows\game.ini
[2009/12/29 14:12:56 | 000,000,002 | ---- | C] () -- C:\windows\HotFixList.ini
[2009/12/29 14:07:25 | 001,526,948 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2009/10/28 23:06:34 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2009/10/28 07:31:35 | 000,307,200 | ---- | C] () -- C:\windows\SetDisplayResolution.exe
[2009/10/28 07:16:46 | 000,311,296 | ---- | C] () -- C:\windows\SysWow64\Rezip.exe
[2009/07/14 06:38:36 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat
[2009/07/14 03:35:51 | 000,000,741 | ---- | C] () -- C:\windows\SysWow64\NOISE.DAT
[2009/07/14 03:34:42 | 000,215,943 | ---- | C] () -- C:\windows\SysWow64\dssec.dat
[2009/07/14 01:10:29 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:59:36 | 000,982,196 | ---- | C] () -- C:\windows\SysWow64\igkrng500.bin
[2009/07/13 22:59:36 | 000,139,824 | ---- | C] () -- C:\windows\SysWow64\igfcg500.bin
[2009/07/13 22:59:36 | 000,097,448 | ---- | C] () -- C:\windows\SysWow64\igfcg500m.bin
[2009/07/13 22:59:35 | 000,417,344 | ---- | C] () -- C:\windows\SysWow64\igcompkrng500.bin
[2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\windows\SysWow64\msjetoledb40.dll
[2009/06/11 10:30:02 | 000,000,586 | ---- | C] () -- C:\windows\hpomdl44.dat
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\windows\SysWow64\mlang.dat
 
========== LOP Check ==========
 
[2011/05/15 23:14:13 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Canneverbe Limited
[2010/12/10 17:47:22 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Local
[2010/12/26 11:48:27 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\OpenOffice.org
[2011/06/02 07:48:48 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Sony
[2011/10/22 12:52:21 | 000,032,640 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010/04/12 10:55:46 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Adobe
[2009/12/29 14:15:29 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\ATI
[2011/12/21 20:57:38 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Avira
[2011/05/15 23:14:13 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Canneverbe Limited
[2011/06/02 07:12:17 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\DivX
[2010/02/11 12:38:08 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\dvdcss
[2009/12/29 15:06:38 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Google
[2010/06/01 08:59:53 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\HP
[2009/12/29 14:14:50 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Identities
[2010/12/10 17:47:22 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Local
[2009/12/29 15:22:59 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Macromedia
[2011/12/22 20:49:52 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Malwarebytes
[2009/10/28 22:15:07 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Media Center Programs
[2011/01/02 22:14:54 | 000,000,000 | --SD | M] -- C:\Users\****\AppData\Roaming\Microsoft
[2009/12/29 15:37:48 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Mozilla
[2011/05/15 07:40:02 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Nero
[2010/12/26 11:48:27 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\OpenOffice.org
[2011/06/02 07:48:48 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Sony
[2011/03/07 21:02:52 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\vlc
[2011/05/15 07:50:55 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2009/12/30 18:20:07 | 000,010,134 | R--- | M] () -- C:\Users\****\AppData\Roaming\Microsoft\Installer\{844BD550-45F4-AD73-412F-CF40CFAFA5E9}\ARPPRODUCTICON.exe
[2011/12/28 21:30:12 | 000,049,152 | R--- | M] (Acresso Software Inc.) -- C:\Users\****\AppData\Roaming\Microsoft\Installer\{CDC7F188-3A08-45C3-8C3C-99BE32911949}\ARPPRODUCTICON.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\windows\SysNative\drivers\AGP440.sys
[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\windows\SysNative\drivers\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\windows\SysNative\cngaudit.dll
[2009/07/14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2009/06/04 10:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2009/06/04 10:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\windows\SysNative\drivers\iaStor.sys
[2009/06/04 10:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_7fb62b08f6b7117a\iaStor.sys
[2009/06/04 10:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010/11/20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011/03/11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011/03/11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011/03/11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\windows\SysNative\drivers\iaStorV.sys
[2011/03/11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0033117673c16921\iaStorV.sys
[2011/03/11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011/03/11 07:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009/07/14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009/07/14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\windows\SysNative\netlogon.dll
[2009/07/14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010/11/20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010/11/20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009/07/14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011/03/11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\windows\SysNative\drivers\nvstor.sys
[2011/03/11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_38e464dbe521cc7f\nvstor.sys
[2011/03/11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011/03/11 07:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011/03/11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011/03/11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010/11/20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\windows\SysNative\scecli.dll
[2009/07/14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010/11/20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010/11/20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009/07/14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\windows\SysNative\user32.dll
[2009/07/14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009/07/14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll
[2009/07/14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010/11/20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010/11/20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\windows\SysNative\userinit.exe
[2009/07/14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009/07/14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\windows\SysNative\wininit.exe
[2009/07/14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009/07/14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009/07/14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010/11/20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\windows\SysNative\winlogon.exe
[2009/10/28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009/07/14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\windows\SysNative\drivers\ws2ifsl.sys
[2009/07/14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >


war das so richtig?

greetz Toolman

cosinus 02.01.2012 22:00

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Hinweis: Falls Du Deinen Benutzernamen unkenntlich gemacht hast, musst Du das Ausgesternte in Deinen richtigen Benutzernamen wieder verwandeln, sonst funktioniert das Script nicht!!

Code:

:OTL
PRC - C:\Windows\SysWOW64\Rezip.exe ()
SRV - (Rezip) -- C:\Windows\SysWOW64\Rezip.exe ()
FF - prefs.js..browser.search.defaultenginename: "Sichere Suche"
FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=mcafee&p="
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg64.dll (Google Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{7dff7414-ced9-11de-a2f1-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7dff7414-ced9-11de-a2f1-806e6f6e6963}\Shell\AutoRun\command - "" = E:\AutoMenu.exe
[2009/10/28 07:16:46 | 000,311,296 | ---- | C] () -- C:\windows\SysWow64\Rezip.exe
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Toolman 02.01.2012 22:20

Hinweis: Falls Du Deinen Benutzernamen unkenntlich gemacht hast, musst Du das Ausgesternte in Deinen richtigen Benutzernamen wieder verwandeln, sonst funktioniert das Script nicht!!

Ja, ich habe meinen Benutzernamen unkenntlich gemacht. Ich kann aber in deinem geposteten code keine Sterne finden. Was soll ich tun? Den Code trotzdem reinkopieren?

Danke für dein Verständnis:confused:

cosinus 02.01.2012 22:42

Ja dann natürlich nicht :pfeiff:
Aber mach bitte aus den hxxp ein http
Normalerweise editiert ich das immer wieder zurück nur hier hab ich nicht dran gedacht

Toolman 02.01.2012 22:58

das habe ich dabei herausbekommen:

Code:

All processes killed
========== OTL ==========
Process Rezip.exe killed successfully!
Service Rezip stopped successfully!
Service Rezip deleted successfully!
C:\Windows\SysWOW64\Rezip.exe moved successfully.
Prefs.js: "Sichere Suche" removed from browser.search.defaultenginename
Prefs.js: "hxxp://de.search.yahoo.com/search?fr=mcafee&p=" removed from keyword.URL
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}\ deleted successfully.
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll moved successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg64.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{326E768D-4182-46FD-9C16-1449A49795F4}\ deleted successfully.
C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}\ deleted successfully.
File C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{2318C2B1-4965-11d4-9B18-009027A5CD4F} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}\ deleted successfully.
File C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
64bit-Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
File C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7dff7414-ced9-11de-a2f1-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7dff7414-ced9-11de-a2f1-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7dff7414-ced9-11de-a2f1-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7dff7414-ced9-11de-a2f1-806e6f6e6963}\ not found.
File E:\AutoMenu.exe not found.
File C:\windows\SysWow64\Rezip.exe not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Karle
->Temp folder emptied: 781000 bytes
->Temporary Internet Files folder emptied: 507305 bytes
->Java cache emptied: 979874 bytes
->FireFox cache emptied: 174687496 bytes
->Flash cache emptied: 4104 bytes
 
User: Karlo
->Temp folder emptied: 12122 bytes
->Temporary Internet Files folder emptied: 440432 bytes
->Java cache emptied: 2444305 bytes
->FireFox cache emptied: 51137349 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 3096039 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5466572 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes
RecycleBin emptied: 55084796 bytes
 
Total Files Cleaned = 281.00 mb
 
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.31.0 log created on 01022012_225029

Files\Folders moved on Reboot...
C:\Users\Karle\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\windows\temp\TMP00000315E6817F6B982D7412 not found!

Registry entries deleted on Reboot...


cosinus 02.01.2012 23:08

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

Toolman 02.01.2012 23:18

ich werde mich Morgen Abend dran machen.......ich dank dir schonmal recht sackrisch.

greetz Toolman

Toolman 03.01.2012 20:52

nabend....ich hoffe es kann weitergehen.

Das ist das Ergebnis vom TDSS-Killer:

Code:

20:40:16.0083 1648        TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
20:40:16.0301 1648        ============================================================
20:40:16.0301 1648        Current date / time: 2012/01/03 20:40:16.0301
20:40:16.0301 1648        SystemInfo:
20:40:16.0301 1648       
20:40:16.0301 1648        OS Version: 6.1.7600 ServicePack: 0.0
20:40:16.0301 1648        Product type: Workstation
20:40:16.0301 1648        ComputerName: KARLE-PC
20:40:16.0301 1648        UserName: Karle
20:40:16.0301 1648        Windows directory: C:\windows
20:40:16.0301 1648        System windows directory: C:\windows
20:40:16.0301 1648        Running under WOW64
20:40:16.0301 1648        Processor architecture: Intel x64
20:40:16.0301 1648        Number of processors: 2
20:40:16.0301 1648        Page size: 0x1000
20:40:16.0301 1648        Boot type: Normal boot
20:40:16.0301 1648        ============================================================
20:40:16.0832 1648        Initialize success
20:41:10.0527 1112        ============================================================
20:41:10.0527 1112        Scan started
20:41:10.0527 1112        Mode: Manual; SigCheck; TDLFS;
20:41:10.0527 1112        ============================================================
20:41:10.0886 1112        1394ohci        (1b00662092f9f9568b995902f0cc40d5) C:\windows\system32\DRIVERS\1394ohci.sys
20:41:11.0026 1112        1394ohci - ok
20:41:11.0167 1112        ACPI            (6f11e88748cdefd2f76aa215f97ddfe5) C:\windows\system32\DRIVERS\ACPI.sys
20:41:11.0198 1112        ACPI - ok
20:41:11.0229 1112        AcpiPmi        (63b05a0420ce4bf0e4af6dcc7cada254) C:\windows\system32\DRIVERS\acpipmi.sys
20:41:11.0338 1112        AcpiPmi - ok
20:41:11.0448 1112        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\DRIVERS\adp94xx.sys
20:41:11.0494 1112        adp94xx - ok
20:41:11.0541 1112        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\DRIVERS\adpahci.sys
20:41:11.0572 1112        adpahci - ok
20:41:11.0604 1112        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\DRIVERS\adpu320.sys
20:41:11.0635 1112        adpu320 - ok
20:41:11.0728 1112        AFD            (6ef20ddf3172e97d69f596fb90602f29) C:\windows\system32\drivers\afd.sys
20:41:11.0806 1112        AFD - ok
20:41:11.0931 1112        AgereSoftModem  (c98356d813b581e9c425b42a5d146ce0) C:\windows\system32\DRIVERS\agrsm64.sys
20:41:12.0072 1112        AgereSoftModem - ok
20:41:12.0165 1112        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\DRIVERS\agp440.sys
20:41:12.0196 1112        agp440 - ok
20:41:12.0243 1112        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\DRIVERS\aliide.sys
20:41:12.0259 1112        aliide - ok
20:41:12.0352 1112        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\DRIVERS\amdide.sys
20:41:12.0368 1112        amdide - ok
20:41:12.0399 1112        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\DRIVERS\amdk8.sys
20:41:12.0462 1112        AmdK8 - ok
20:41:12.0493 1112        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\DRIVERS\amdppm.sys
20:41:12.0540 1112        AmdPPM - ok
20:41:12.0664 1112        amdsata        (ec7ebab00a4d8448bab68d1e49b4beb9) C:\windows\system32\drivers\amdsata.sys
20:41:12.0680 1112        amdsata - ok
20:41:12.0727 1112        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\DRIVERS\amdsbs.sys
20:41:12.0758 1112        amdsbs - ok
20:41:12.0774 1112        amdxata        (db27766102c7bf7e95140a2aa81d042e) C:\windows\system32\drivers\amdxata.sys
20:41:12.0805 1112        amdxata - ok
20:41:12.0961 1112        AppID          (42fd751b27fa0e9c69bb39f39e409594) C:\windows\system32\drivers\appid.sys
20:41:13.0101 1112        AppID - ok
20:41:13.0210 1112        arc            (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\DRIVERS\arc.sys
20:41:13.0242 1112        arc - ok
20:41:13.0257 1112        arcsas          (019af6924aefe7839f61c830227fe79c) C:\windows\system32\DRIVERS\arcsas.sys
20:41:13.0288 1112        arcsas - ok
20:41:13.0320 1112        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys
20:41:13.0491 1112        AsyncMac - ok
20:41:13.0600 1112        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\DRIVERS\atapi.sys
20:41:13.0616 1112        atapi - ok
20:41:13.0678 1112        athr            (88a02b6046356e6be4e387faa7451439) C:\windows\system32\DRIVERS\athrx.sys
20:41:13.0834 1112        athr - ok
20:41:14.0068 1112        atikmdag        (9746d950c3cf6434b2d1b385edab7ae5) C:\windows\system32\DRIVERS\atikmdag.sys
20:41:14.0396 1112        atikmdag - ok
20:41:14.0521 1112        avgntflt        (b1224e6b086cd6548315b04ab575a23e) C:\windows\system32\DRIVERS\avgntflt.sys
20:41:14.0583 1112        avgntflt - ok
20:41:14.0724 1112        avipbb          (ed45f12cfa62b83765c9c1496758cc87) C:\windows\system32\DRIVERS\avipbb.sys
20:41:14.0739 1112        avipbb - ok
20:41:14.0833 1112        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\windows\system32\DRIVERS\bxvbda.sys
20:41:14.0926 1112        b06bdrv - ok
20:41:15.0036 1112        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys
20:41:15.0098 1112        b57nd60a - ok
20:41:15.0223 1112        Beep            (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys
20:41:15.0301 1112        Beep - ok
20:41:15.0426 1112        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys
20:41:15.0472 1112        blbdrive - ok
20:41:15.0535 1112        bowser          (19d20159708e152267e53b66677a4995) C:\windows\system32\DRIVERS\bowser.sys
20:41:15.0597 1112        bowser - ok
20:41:15.0691 1112        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\DRIVERS\BrFiltLo.sys
20:41:15.0738 1112        BrFiltLo - ok
20:41:15.0753 1112        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\DRIVERS\BrFiltUp.sys
20:41:15.0784 1112        BrFiltUp - ok
20:41:15.0816 1112        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys
20:41:15.0894 1112        Brserid - ok
20:41:15.0956 1112        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys
20:41:16.0003 1112        BrSerWdm - ok
20:41:16.0050 1112        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys
20:41:16.0096 1112        BrUsbMdm - ok
20:41:16.0143 1112        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys
20:41:16.0174 1112        BrUsbSer - ok
20:41:16.0252 1112        BthEnum        (cf98190a94f62e405c8cb255018b2315) C:\windows\system32\drivers\BthEnum.sys
20:41:16.0299 1112        BthEnum - ok
20:41:16.0346 1112        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\DRIVERS\bthmodem.sys
20:41:16.0393 1112        BTHMODEM - ok
20:41:16.0471 1112        BthPan          (02dd601b708dd0667e1331fa8518e9ff) C:\windows\system32\DRIVERS\bthpan.sys
20:41:16.0518 1112        BthPan - ok
20:41:16.0642 1112        BTHPORT        (21084ceb85280468c9aca3c805c0f8cf) C:\windows\System32\Drivers\BTHport.sys
20:41:16.0705 1112        BTHPORT - ok
20:41:16.0814 1112        BTHUSB          (8504842634dd144c075b6b0c982ccec4) C:\windows\System32\Drivers\BTHUSB.sys
20:41:16.0861 1112        BTHUSB - ok
20:41:16.0908 1112        cdfs            (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys
20:41:17.0001 1112        cdfs - ok
20:41:17.0126 1112        cdrom          (83d2d75e1efb81b3450c18131443f7db) C:\windows\system32\DRIVERS\cdrom.sys
20:41:17.0173 1112        cdrom - ok
20:41:17.0298 1112        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\DRIVERS\circlass.sys
20:41:17.0344 1112        circlass - ok
20:41:17.0391 1112        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys
20:41:17.0422 1112        CLFS - ok
20:41:17.0547 1112        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys
20:41:17.0594 1112        CmBatt - ok
20:41:17.0625 1112        cmdide          (e19d3f095812725d88f9001985b94edd) C:\windows\system32\DRIVERS\cmdide.sys
20:41:17.0641 1112        cmdide - ok
20:41:17.0672 1112        CNG            (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\windows\system32\Drivers\cng.sys
20:41:17.0734 1112        CNG - ok
20:41:17.0828 1112        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys
20:41:17.0844 1112        Compbatt - ok
20:41:17.0875 1112        CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\windows\system32\DRIVERS\CompositeBus.sys
20:41:17.0937 1112        CompositeBus - ok
20:41:18.0031 1112        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\windows\system32\DRIVERS\crcdisk.sys
20:41:18.0046 1112        crcdisk - ok
20:41:18.0187 1112        DfsC            (9c253ce7311ca60fc11c774692a13208) C:\windows\system32\Drivers\dfsc.sys
20:41:18.0249 1112        DfsC - ok
20:41:18.0296 1112        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys
20:41:18.0374 1112        discache - ok
20:41:18.0483 1112        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\DRIVERS\disk.sys
20:41:18.0514 1112        Disk - ok
20:41:18.0577 1112        Dot4            (b42ed0320c6e41102fde0005154849bb) C:\windows\system32\DRIVERS\Dot4.sys
20:41:18.0639 1112        Dot4 - ok
20:41:18.0733 1112        Dot4Print      (85135ad27e79b689335c08167d917cde) C:\windows\system32\DRIVERS\Dot4Prt.sys
20:41:18.0764 1112        Dot4Print - ok
20:41:18.0811 1112        dot4usb        (fd05a02b0370bc3000f402e543ca5814) C:\windows\system32\DRIVERS\dot4usb.sys
20:41:18.0858 1112        dot4usb - ok
20:41:18.0967 1112        drmkaud        (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys
20:41:19.0014 1112        drmkaud - ok
20:41:19.0092 1112        DXGKrnl        (1633b9abf52784a1331476397a48cbef) C:\windows\System32\drivers\dxgkrnl.sys
20:41:19.0138 1112        DXGKrnl - ok
20:41:19.0248 1112        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\DRIVERS\evbda.sys
20:41:19.0419 1112        ebdrv - ok
20:41:19.0560 1112        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\DRIVERS\elxstor.sys
20:41:19.0591 1112        elxstor - ok
20:41:19.0622 1112        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\windows\system32\DRIVERS\errdev.sys
20:41:19.0684 1112        ErrDev - ok
20:41:19.0794 1112        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys
20:41:19.0887 1112        exfat - ok
20:41:19.0918 1112        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys
20:41:19.0996 1112        fastfat - ok
20:41:20.0106 1112        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\DRIVERS\fdc.sys
20:41:20.0121 1112        fdc - ok
20:41:20.0168 1112        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys
20:41:20.0184 1112        FileInfo - ok
20:41:20.0215 1112        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys
20:41:20.0308 1112        Filetrace - ok
20:41:20.0418 1112        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\DRIVERS\flpydisk.sys
20:41:20.0464 1112        flpydisk - ok
20:41:20.0511 1112        FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\windows\system32\drivers\fltmgr.sys
20:41:20.0542 1112        FltMgr - ok
20:41:20.0589 1112        FsDepends      (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys
20:41:20.0605 1112        FsDepends - ok
20:41:20.0652 1112        fssfltr        (53dab1791917a72738539ad25c4eed7f) C:\windows\system32\DRIVERS\fssfltr.sys
20:41:20.0683 1112        fssfltr - ok
20:41:20.0776 1112        Fs_Rec          (e95ef8547de20cf0603557c0cf7a9462) C:\windows\system32\drivers\Fs_Rec.sys
20:41:20.0792 1112        Fs_Rec - ok
20:41:20.0870 1112        fvevol          (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\windows\system32\DRIVERS\fvevol.sys
20:41:20.0901 1112        fvevol - ok
20:41:20.0932 1112        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\DRIVERS\gagp30kx.sys
20:41:20.0964 1112        gagp30kx - ok
20:41:21.0104 1112        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys
20:41:21.0182 1112        hcw85cir - ok
20:41:21.0229 1112        HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\windows\system32\drivers\HdAudio.sys
20:41:21.0291 1112        HdAudAddService - ok
20:41:21.0369 1112        HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\windows\system32\DRIVERS\HDAudBus.sys
20:41:21.0416 1112        HDAudBus - ok
20:41:21.0447 1112        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\DRIVERS\HidBatt.sys
20:41:21.0494 1112        HidBatt - ok
20:41:21.0541 1112        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\DRIVERS\hidbth.sys
20:41:21.0603 1112        HidBth - ok
20:41:21.0634 1112        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\DRIVERS\hidir.sys
20:41:21.0681 1112        HidIr - ok
20:41:21.0759 1112        HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\windows\system32\DRIVERS\hidusb.sys
20:41:21.0806 1112        HidUsb - ok
20:41:21.0946 1112        HpSAMD          (0886d440058f203eba0e1825e4355914) C:\windows\system32\DRIVERS\HpSAMD.sys
20:41:21.0978 1112        HpSAMD - ok
20:41:22.0009 1112        HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\windows\system32\drivers\HTTP.sys
20:41:22.0102 1112        HTTP - ok
20:41:22.0118 1112        hwpolicy        (f17766a19145f111856378df337a5d79) C:\windows\system32\drivers\hwpolicy.sys
20:41:22.0149 1112        hwpolicy - ok
20:41:22.0227 1112        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\DRIVERS\i8042prt.sys
20:41:22.0258 1112        i8042prt - ok
20:41:22.0305 1112        iaStor          (1d004cb1da6323b1f55caef7f94b61d9) C:\windows\system32\DRIVERS\iaStor.sys
20:41:22.0321 1112        iaStor - ok
20:41:22.0383 1112        iaStorV        (b75e45c564e944a2657167d197ab29da) C:\windows\system32\drivers\iaStorV.sys
20:41:22.0430 1112        iaStorV - ok
20:41:22.0617 1112        igfx            (a87261ef1546325b559374f5689cf5bc) C:\windows\system32\DRIVERS\igdkmd64.sys
20:41:22.0914 1112        igfx - ok
20:41:23.0007 1112        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\DRIVERS\iirsp.sys
20:41:23.0023 1112        iirsp - ok
20:41:23.0116 1112        IntcAzAudAddService (f04d22d7a49a1b2210dbadf0b803e870) C:\windows\system32\drivers\RTKVHD64.sys
20:41:23.0194 1112        IntcAzAudAddService - ok
20:41:23.0226 1112        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\DRIVERS\intelide.sys
20:41:23.0241 1112        intelide - ok
20:41:23.0272 1112        intelppm        (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys
20:41:23.0319 1112        intelppm - ok
20:41:23.0382 1112        IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\windows\system32\DRIVERS\ipfltdrv.sys
20:41:23.0475 1112        IpFilterDriver - ok
20:41:23.0569 1112        IPMIDRV        (e2b4a4494db7cb9b89b55ca268c337c5) C:\windows\system32\DRIVERS\IPMIDrv.sys
20:41:23.0616 1112        IPMIDRV - ok
20:41:23.0647 1112        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys
20:41:23.0725 1112        IPNAT - ok
20:41:23.0772 1112        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys
20:41:23.0803 1112        IRENUM - ok
20:41:23.0818 1112        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\DRIVERS\isapnp.sys
20:41:23.0834 1112        isapnp - ok
20:41:23.0865 1112        iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\windows\system32\DRIVERS\msiscsi.sys
20:41:23.0896 1112        iScsiPrt - ok
20:41:23.0943 1112        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\DRIVERS\kbdclass.sys
20:41:23.0974 1112        kbdclass - ok
20:41:24.0006 1112        kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\windows\system32\DRIVERS\kbdhid.sys
20:41:24.0068 1112        kbdhid - ok
20:41:24.0084 1112        KSecDD          (e8b6fcc9c83535c67f835d407620bd27) C:\windows\system32\Drivers\ksecdd.sys
20:41:24.0115 1112        KSecDD - ok
20:41:24.0146 1112        KSecPkg        (a8c63880ef6f4d3fec7b616b9c060215) C:\windows\system32\Drivers\ksecpkg.sys
20:41:24.0177 1112        KSecPkg - ok
20:41:24.0224 1112        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys
20:41:24.0302 1112        ksthunk - ok
20:41:24.0442 1112        lltdio          (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys
20:41:24.0520 1112        lltdio - ok
20:41:24.0583 1112        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\DRIVERS\lsi_fc.sys
20:41:24.0614 1112        LSI_FC - ok
20:41:24.0645 1112        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\DRIVERS\lsi_sas.sys
20:41:24.0676 1112        LSI_SAS - ok
20:41:24.0692 1112        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\DRIVERS\lsi_sas2.sys
20:41:24.0723 1112        LSI_SAS2 - ok
20:41:24.0754 1112        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\DRIVERS\lsi_scsi.sys
20:41:24.0770 1112        LSI_SCSI - ok
20:41:24.0832 1112        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys
20:41:24.0926 1112        luafv - ok
20:41:24.0957 1112        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\DRIVERS\megasas.sys
20:41:24.0973 1112        megasas - ok
20:41:25.0004 1112        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\DRIVERS\MegaSR.sys
20:41:25.0035 1112        MegaSR - ok
20:41:25.0082 1112        Modem          (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys
20:41:25.0144 1112        Modem - ok
20:41:25.0191 1112        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys
20:41:25.0238 1112        monitor - ok
20:41:25.0285 1112        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys
20:41:25.0316 1112        mouclass - ok
20:41:25.0394 1112        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys
20:41:25.0441 1112        mouhid - ok
20:41:25.0488 1112        mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\windows\system32\drivers\mountmgr.sys
20:41:25.0503 1112        mountmgr - ok
20:41:25.0550 1112        mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\windows\system32\DRIVERS\mpio.sys
20:41:25.0581 1112        mpio - ok
20:41:25.0628 1112        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys
20:41:25.0706 1112        mpsdrv - ok
20:41:25.0753 1112        MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\windows\system32\drivers\mrxdav.sys
20:41:25.0815 1112        MRxDAV - ok
20:41:25.0893 1112        mrxsmb          (040d62a9d8ad28922632137acdd984f2) C:\windows\system32\DRIVERS\mrxsmb.sys
20:41:25.0940 1112        mrxsmb - ok
20:41:25.0987 1112        mrxsmb10        (f0067552f8f9b33d7c59403ab808a3cb) C:\windows\system32\DRIVERS\mrxsmb10.sys
20:41:26.0049 1112        mrxsmb10 - ok
20:41:26.0096 1112        mrxsmb20        (3c142d31de9f2f193218a53fe2632051) C:\windows\system32\DRIVERS\mrxsmb20.sys
20:41:26.0127 1112        mrxsmb20 - ok
20:41:26.0174 1112        msahci          (5c37497276e3b3a5488b23a326a754b7) C:\windows\system32\DRIVERS\msahci.sys
20:41:26.0205 1112        msahci - ok
20:41:26.0221 1112        msdsm          (8d27b597229aed79430fb9db3bcbfbd0) C:\windows\system32\DRIVERS\msdsm.sys
20:41:26.0268 1112        msdsm - ok
20:41:26.0299 1112        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys
20:41:26.0392 1112        Msfs - ok
20:41:26.0408 1112        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys
20:41:26.0486 1112        mshidkmdf - ok
20:41:26.0517 1112        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\DRIVERS\msisadrv.sys
20:41:26.0548 1112        msisadrv - ok
20:41:26.0580 1112        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys
20:41:26.0642 1112        MSKSSRV - ok
20:41:26.0673 1112        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys
20:41:26.0767 1112        MSPCLOCK - ok
20:41:26.0767 1112        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys
20:41:26.0845 1112        MSPQM - ok
20:41:26.0876 1112        MsRPC          (89cb141aa8616d8c6a4610fa26c60964) C:\windows\system32\drivers\MsRPC.sys
20:41:26.0923 1112        MsRPC - ok
20:41:26.0938 1112        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\DRIVERS\mssmbios.sys
20:41:26.0954 1112        mssmbios - ok
20:41:27.0001 1112        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys
20:41:27.0079 1112        MSTEE - ok
20:41:27.0094 1112        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\DRIVERS\MTConfig.sys
20:41:27.0141 1112        MTConfig - ok
20:41:27.0172 1112        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys
20:41:27.0188 1112        Mup - ok
20:41:27.0250 1112        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys
20:41:27.0313 1112        NativeWifiP - ok
20:41:27.0422 1112        NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\windows\system32\drivers\ndis.sys
20:41:27.0469 1112        NDIS - ok
20:41:27.0516 1112        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys
20:41:27.0594 1112        NdisCap - ok
20:41:27.0656 1112        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys
20:41:27.0734 1112        NdisTapi - ok
20:41:27.0796 1112        Ndisuio        (f105ba1e22bf1f2ee8f005d4305e4bec) C:\windows\system32\DRIVERS\ndisuio.sys
20:41:27.0890 1112        Ndisuio - ok
20:41:27.0921 1112        NdisWan        (557dfab9ca1fcb036ac77564c010dad3) C:\windows\system32\DRIVERS\ndiswan.sys
20:41:28.0015 1112        NdisWan - ok
20:41:28.0030 1112        NDProxy        (659b74fb74b86228d6338d643cd3e3cf) C:\windows\system32\drivers\NDProxy.sys
20:41:28.0124 1112        NDProxy - ok
20:41:28.0233 1112        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys
20:41:28.0311 1112        NetBIOS - ok
20:41:28.0358 1112        NetBT          (9162b273a44ab9dce5b44362731d062a) C:\windows\system32\DRIVERS\netbt.sys
20:41:28.0420 1112        NetBT - ok
20:41:28.0514 1112        nfrd960        (77889813be4d166cdab78ddba990da92) C:\windows\system32\DRIVERS\nfrd960.sys
20:41:28.0545 1112        nfrd960 - ok
20:41:28.0623 1112        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys
20:41:28.0701 1112        Npfs - ok
20:41:28.0748 1112        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys
20:41:28.0810 1112        nsiproxy - ok
20:41:28.0888 1112        Ntfs            (378e0e0dfea67d98ae6ea53adbbd76bc) C:\windows\system32\drivers\Ntfs.sys
20:41:28.0998 1112        Ntfs - ok
20:41:29.0076 1112        Null            (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys
20:41:29.0185 1112        Null - ok
20:41:29.0294 1112        nvraid          (a4d9c9a608a97f59307c2f2600edc6a4) C:\windows\system32\drivers\nvraid.sys
20:41:29.0320 1112        nvraid - ok
20:41:29.0350 1112        nvstor          (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\windows\system32\drivers\nvstor.sys
20:41:29.0390 1112        nvstor - ok
20:41:29.0430 1112        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\DRIVERS\nv_agp.sys
20:41:29.0460 1112        nv_agp - ok
20:41:29.0500 1112        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\DRIVERS\ohci1394.sys
20:41:29.0550 1112        ohci1394 - ok
20:41:29.0700 1112        Parport        (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\DRIVERS\parport.sys
20:41:29.0740 1112        Parport - ok
20:41:29.0770 1112        partmgr        (7daa117143316c4a1537e074a5a9eaf0) C:\windows\system32\drivers\partmgr.sys
20:41:29.0800 1112        partmgr - ok
20:41:29.0830 1112        pci            (f36f6504009f2fb0dfd1b17a116ad74b) C:\windows\system32\DRIVERS\pci.sys
20:41:29.0850 1112        pci - ok
20:41:29.0870 1112        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\DRIVERS\pciide.sys
20:41:29.0890 1112        pciide - ok
20:41:29.0920 1112        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\DRIVERS\pcmcia.sys
20:41:29.0960 1112        pcmcia - ok
20:41:29.0980 1112        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys
20:41:30.0010 1112        pcw - ok
20:41:30.0050 1112        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys
20:41:30.0160 1112        PEAUTH - ok
20:41:30.0310 1112        PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\windows\system32\DRIVERS\raspptp.sys
20:41:30.0400 1112        PptpMiniport - ok
20:41:30.0430 1112        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\DRIVERS\processr.sys
20:41:30.0476 1112        Processor - ok
20:41:30.0586 1112        Psched          (ee992183bd8eaefd9973f352e587a299) C:\windows\system32\DRIVERS\pacer.sys
20:41:30.0664 1112        Psched - ok
20:41:30.0742 1112        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\DRIVERS\ql2300.sys
20:41:30.0835 1112        ql2300 - ok
20:41:30.0866 1112        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\DRIVERS\ql40xx.sys
20:41:30.0898 1112        ql40xx - ok
20:41:30.0944 1112        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys
20:41:30.0991 1112        QWAVEdrv - ok
20:41:31.0022 1112        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys
20:41:31.0100 1112        RasAcd - ok
20:41:31.0147 1112        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys
20:41:31.0225 1112        RasAgileVpn - ok
20:41:31.0241 1112        Rasl2tp        (87a6e852a22991580d6d39adc4790463) C:\windows\system32\DRIVERS\rasl2tp.sys
20:41:31.0334 1112        Rasl2tp - ok
20:41:31.0350 1112        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys
20:41:31.0444 1112        RasPppoe - ok
20:41:31.0522 1112        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys
20:41:31.0600 1112        RasSstp - ok
20:41:31.0615 1112        rdbss          (3bac8142102c15d59a87757c1d41dce5) C:\windows\system32\DRIVERS\rdbss.sys
20:41:31.0709 1112        rdbss - ok
20:41:31.0787 1112        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\DRIVERS\rdpbus.sys
20:41:31.0849 1112        rdpbus - ok
20:41:31.0880 1112        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys
20:41:31.0958 1112        RDPCDD - ok
20:41:31.0990 1112        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys
20:41:32.0052 1112        RDPENCDD - ok
20:41:32.0068 1112        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys
20:41:32.0161 1112        RDPREFMP - ok
20:41:32.0192 1112        RDPWD          (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\windows\system32\drivers\RDPWD.sys
20:41:32.0286 1112        RDPWD - ok
20:41:32.0348 1112        rdyboost        (634b9a2181d98f15941236886164ec8b) C:\windows\system32\drivers\rdyboost.sys
20:41:32.0380 1112        rdyboost - ok
20:41:32.0458 1112        RFCOMM          (3dd798846e2c28102b922c56e71b7932) C:\windows\system32\DRIVERS\rfcomm.sys
20:41:32.0520 1112        RFCOMM - ok
20:41:32.0629 1112        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys
20:41:32.0692 1112        rspndr - ok
20:41:32.0738 1112        RTL8167        (baefee35d27a5440d35092ce10267bec) C:\windows\system32\DRIVERS\Rt64win7.sys
20:41:32.0785 1112        RTL8167 - ok
20:41:32.0910 1112        SABI            (62db6cc4b0818f1b5f3441241b098f12) C:\windows\system32\Drivers\SABI.sys
20:41:32.0941 1112        SABI - ok
20:41:32.0988 1112        sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\windows\system32\DRIVERS\sbp2port.sys
20:41:33.0019 1112        sbp2port - ok
20:41:33.0035 1112        scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\windows\system32\DRIVERS\scfilter.sys
20:41:33.0097 1112        scfilter - ok
20:41:33.0128 1112        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys
20:41:33.0222 1112        secdrv - ok
20:41:33.0300 1112        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\DRIVERS\serenum.sys
20:41:33.0331 1112        Serenum - ok
20:41:33.0394 1112        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\DRIVERS\serial.sys
20:41:33.0456 1112        Serial - ok
20:41:33.0534 1112        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\DRIVERS\sermouse.sys
20:41:33.0565 1112        sermouse - ok
20:41:33.0596 1112        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\windows\system32\DRIVERS\sffdisk.sys
20:41:33.0628 1112        sffdisk - ok
20:41:33.0628 1112        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\DRIVERS\sffp_mmc.sys
20:41:33.0659 1112        sffp_mmc - ok
20:41:33.0674 1112        sffp_sd        (5588b8c6193eb1522490c122eb94dffa) C:\windows\system32\DRIVERS\sffp_sd.sys
20:41:33.0721 1112        sffp_sd - ok
20:41:33.0752 1112        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\DRIVERS\sfloppy.sys
20:41:33.0799 1112        sfloppy - ok
20:41:33.0846 1112        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\DRIVERS\SiSRaid2.sys
20:41:33.0862 1112        SiSRaid2 - ok
20:41:33.0893 1112        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\DRIVERS\sisraid4.sys
20:41:33.0924 1112        SiSRaid4 - ok
20:41:33.0955 1112        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys
20:41:34.0049 1112        Smb - ok
20:41:34.0142 1112        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys
20:41:34.0174 1112        spldr - ok
20:41:34.0267 1112        srv            (2408c0366d96bcdf63e8f1c78e4a29c5) C:\windows\system32\DRIVERS\srv.sys
20:41:34.0361 1112        srv - ok
20:41:34.0454 1112        srv2            (76548f7b818881b47d8d1ae1be9c11f8) C:\windows\system32\DRIVERS\srv2.sys
20:41:34.0548 1112        srv2 - ok
20:41:34.0642 1112        srvnet          (0af6e19d39c70844c5caa8fb0183c36e) C:\windows\system32\DRIVERS\srvnet.sys
20:41:34.0673 1112        srvnet - ok
20:41:34.0735 1112        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\DRIVERS\stexstor.sys
20:41:34.0766 1112        stexstor - ok
20:41:34.0829 1112        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\DRIVERS\swenum.sys
20:41:34.0844 1112        swenum - ok
20:41:34.0938 1112        SynTP          (929c9fa0b18ad2ebc8340591c4bf00ff) C:\windows\system32\DRIVERS\SynTP.sys
20:41:34.0969 1112        SynTP - ok
20:41:35.0078 1112        Tcpip          (f18f56efc0bfb9c87ba01c37b27f4da5) C:\windows\system32\drivers\tcpip.sys
20:41:35.0156 1112        Tcpip - ok
20:41:35.0250 1112        TCPIP6          (f18f56efc0bfb9c87ba01c37b27f4da5) C:\windows\system32\DRIVERS\tcpip.sys
20:41:35.0312 1112        TCPIP6 - ok
20:41:35.0359 1112        tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\windows\system32\drivers\tcpipreg.sys
20:41:35.0437 1112        tcpipreg - ok
20:41:35.0468 1112        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys
20:41:35.0562 1112        TDPIPE - ok
20:41:35.0562 1112        TDTCP          (e4245bda3190a582d55ed09e137401a9) C:\windows\system32\drivers\tdtcp.sys
20:41:35.0656 1112        TDTCP - ok
20:41:35.0702 1112        tdx            (079125c4b17b01fcaeebce0bcb290c0f) C:\windows\system32\DRIVERS\tdx.sys
20:41:35.0796 1112        tdx - ok
20:41:35.0827 1112        TermDD          (c448651339196c0e869a355171875522) C:\windows\system32\DRIVERS\termdd.sys
20:41:35.0843 1112        TermDD - ok
20:41:35.0921 1112        tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\windows\system32\DRIVERS\tssecsrv.sys
20:41:35.0999 1112        tssecsrv - ok
20:41:36.0046 1112        tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\windows\system32\DRIVERS\tunnel.sys
20:41:36.0124 1112        tunnel - ok
20:41:36.0155 1112        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\DRIVERS\uagp35.sys
20:41:36.0186 1112        uagp35 - ok
20:41:36.0202 1112        udfs            (d47baead86c65d4f4069d7ce0a4edceb) C:\windows\system32\DRIVERS\udfs.sys
20:41:36.0295 1112        udfs - ok
20:41:36.0311 1112        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\DRIVERS\uliagpkx.sys
20:41:36.0342 1112        uliagpkx - ok
20:41:36.0373 1112        umbus          (eab6c35e62b1b0db0d1b48b671d3a117) C:\windows\system32\DRIVERS\umbus.sys
20:41:36.0420 1112        umbus - ok
20:41:36.0451 1112        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\DRIVERS\umpass.sys
20:41:36.0498 1112        UmPass - ok
20:41:36.0545 1112        usbccgp        (7b6a127c93ee590e4d79a5f2a76fe46f) C:\windows\system32\DRIVERS\usbccgp.sys
20:41:36.0607 1112        usbccgp - ok
20:41:36.0701 1112        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\DRIVERS\usbcir.sys
20:41:36.0763 1112        usbcir - ok
20:41:36.0794 1112        usbehci        (92969ba5ac44e229c55a332864f79677) C:\windows\system32\DRIVERS\usbehci.sys
20:41:36.0841 1112        usbehci - ok
20:41:36.0950 1112        usbhub          (e7df1cfd28ca86b35ef5add0735ceef3) C:\windows\system32\DRIVERS\usbhub.sys
20:41:36.0982 1112        usbhub - ok
20:41:37.0013 1112        usbohci        (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\windows\system32\drivers\usbohci.sys
20:41:37.0060 1112        usbohci - ok
20:41:37.0106 1112        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\DRIVERS\usbprint.sys
20:41:37.0138 1112        usbprint - ok
20:41:37.0184 1112        usbscan        (aaa2513c8aed8b54b189fd0c6b1634c0) C:\windows\system32\DRIVERS\usbscan.sys
20:41:37.0231 1112        usbscan - ok
20:41:37.0278 1112        USBSTOR        (f39983647bc1f3e6100778ddfe9dce29) C:\windows\system32\drivers\USBSTOR.SYS
20:41:37.0340 1112        USBSTOR - ok
20:41:37.0387 1112        usbuhci        (bc3070350a491d84b518d7cca9abd36f) C:\windows\system32\DRIVERS\usbuhci.sys
20:41:37.0434 1112        usbuhci - ok
20:41:37.0512 1112        usbvideo        (7cb8c573c6e4a2714402cc0a36eab4fe) C:\windows\System32\Drivers\usbvideo.sys
20:41:37.0574 1112        usbvideo - ok
20:41:37.0684 1112        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\DRIVERS\vdrvroot.sys
20:41:37.0699 1112        vdrvroot - ok
20:41:37.0746 1112        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys
20:41:37.0777 1112        vga - ok
20:41:37.0793 1112        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys
20:41:37.0886 1112        VgaSave - ok
20:41:37.0918 1112        vhdmp          (c82e748660f62a242b2dfac1442f22a4) C:\windows\system32\DRIVERS\vhdmp.sys
20:41:37.0964 1112        vhdmp - ok
20:41:37.0980 1112        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\DRIVERS\viaide.sys
20:41:37.0996 1112        viaide - ok
20:41:38.0011 1112        volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\windows\system32\DRIVERS\volmgr.sys
20:41:38.0042 1112        volmgr - ok
20:41:38.0074 1112        volmgrx        (99b0cbb569ca79acaed8c91461d765fb) C:\windows\system32\drivers\volmgrx.sys
20:41:38.0105 1112        volmgrx - ok
20:41:38.0120 1112        volsnap        (58f82eed8ca24b461441f9c3e4f0bf5c) C:\windows\system32\DRIVERS\volsnap.sys
20:41:38.0152 1112        volsnap - ok
20:41:38.0198 1112        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\DRIVERS\vsmraid.sys
20:41:38.0230 1112        vsmraid - ok
20:41:38.0245 1112        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys
20:41:38.0276 1112        vwifibus - ok
20:41:38.0323 1112        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys
20:41:38.0386 1112        vwififlt - ok
20:41:38.0401 1112        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\DRIVERS\wacompen.sys
20:41:38.0432 1112        WacomPen - ok
20:41:38.0510 1112        WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys
20:41:38.0573 1112        WANARP - ok
20:41:38.0588 1112        Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys
20:41:38.0651 1112        Wanarpv6 - ok
20:41:38.0698 1112        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\DRIVERS\wd.sys
20:41:38.0729 1112        Wd - ok
20:41:38.0760 1112        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys
20:41:38.0822 1112        Wdf01000 - ok
20:41:38.0869 1112        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys
20:41:38.0932 1112        WfpLwf - ok
20:41:38.0963 1112        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys
20:41:38.0994 1112        WIMMount - ok
20:41:39.0103 1112        WinUsb          (817eaff5d38674edd7713b9dfb8e9791) C:\windows\system32\DRIVERS\WinUsb.sys
20:41:39.0150 1112        WinUsb - ok
20:41:39.0197 1112        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\DRIVERS\wmiacpi.sys
20:41:39.0244 1112        WmiAcpi - ok
20:41:39.0290 1112        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys
20:41:39.0368 1112        ws2ifsl - ok
20:41:39.0415 1112        WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\windows\system32\drivers\WudfPf.sys
20:41:39.0493 1112        WudfPf - ok
20:41:39.0540 1112        WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\windows\system32\DRIVERS\WUDFRd.sys
20:41:39.0634 1112        WUDFRd - ok
20:41:39.0696 1112        yukonw7        (6affd75c6807b3dd3ab018e27b88ef95) C:\windows\system32\DRIVERS\yk62x64.sys
20:41:39.0774 1112        yukonw7 - ok
20:41:39.0805 1112        MBR (0x1B8)    (2e5debb2116b3417023e0d6562d7ed07) \Device\Harddisk0\DR0
20:41:40.0414 1112        \Device\Harddisk0\DR0 - ok
20:41:40.0414 1112        Boot (0x1200)  (743d22f6e500b872f7ebf7a22433c560) \Device\Harddisk0\DR0\Partition0
20:41:40.0414 1112        \Device\Harddisk0\DR0\Partition0 - ok
20:41:40.0429 1112        Boot (0x1200)  (15b48d38c08f8fcd2bd450089e58d391) \Device\Harddisk0\DR0\Partition1
20:41:40.0429 1112        \Device\Harddisk0\DR0\Partition1 - ok
20:41:40.0460 1112        Boot (0x1200)  (b76c2fdceaea5595d54ad33d57042339) \Device\Harddisk0\DR0\Partition2
20:41:40.0460 1112        \Device\Harddisk0\DR0\Partition2 - ok
20:41:40.0460 1112        ============================================================
20:41:40.0460 1112        Scan finished
20:41:40.0460 1112        ============================================================
20:41:40.0476 2292        Detected object count: 0
20:41:40.0476 2292        Actual detected object count: 0


cosinus 03.01.2012 21:12

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

Toolman 03.01.2012 21:35

hier das ergebnis von combofix:

Code:

ComboFix 12-01-03.04 - Karle 03.01.2012  21:24:17.1.2 - x64
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.49.1031.18.4061.2688 [GMT 1:00]
ausgeführt von:: c:\users\Karle\Downloads\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Karle\AppData\Roaming\Local
D:\install.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-12-03 bis 2012-01-03  ))))))))))))))))))))))))))))))
.
.
2012-01-03 20:29 . 2012-01-03 20:29        --------        d-----w-        c:\users\Karlo\AppData\Local\temp
2012-01-03 20:29 . 2012-01-03 20:29        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-01-03 19:29 . 2012-01-03 19:29        69000        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{7132A023-0FCC-4A6C-BA74-C4F5397803CD}\offreg.dll
2012-01-03 16:56 . 2011-11-30 01:21        8822856        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{7132A023-0FCC-4A6C-BA74-C4F5397803CD}\mpengine.dll
2012-01-02 21:50 . 2012-01-02 21:50        --------        d-----w-        C:\_OTL
2011-12-31 10:14 . 2011-12-31 10:14        --------        d-----w-        c:\program files (x86)\ESET
2011-12-28 20:30 . 2011-12-28 20:30        49152        ----a-r-        c:\users\Karle\AppData\Roaming\Microsoft\Installer\{CDC7F188-3A08-45C3-8C3C-99BE32911949}\ARPPRODUCTICON.exe
2011-12-28 20:30 . 2011-12-28 20:30        --------        d-----w-        c:\program files (x86)\CASIO
2011-12-28 20:13 . 2011-12-28 20:13        --------        d-----w-        c:\windows\system32\EventProviders
2011-12-27 09:43 . 2011-11-15 13:29        270720        ------w-        c:\windows\system32\MpSigStub.exe
2011-12-23 12:38 . 2011-12-23 12:38        --------        d-----w-        c:\users\Karlo\AppData\Roaming\Malwarebytes
2011-12-22 19:49 . 2011-12-22 19:49        --------        d-----w-        c:\users\Karle\AppData\Roaming\Malwarebytes
2011-12-22 19:49 . 2011-12-22 19:49        --------        d-----w-        c:\programdata\Malwarebytes
2011-12-22 19:49 . 2011-12-22 19:49        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2011-12-22 19:49 . 2011-08-31 16:00        25416        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-12-21 19:57 . 2011-12-21 19:57        --------        d-----w-        c:\users\Karle\AppData\Roaming\Avira
2011-12-17 09:10 . 2011-10-26 05:19        43520        ----a-w-        c:\windows\system32\csrsrv.dll
2011-12-17 09:08 . 2011-11-24 05:00        3141632        ----a-w-        c:\windows\system32\win32k.sys
2011-12-17 09:08 . 2011-10-15 06:25        723456        ----a-w-        c:\windows\system32\EncDec.dll
2011-12-17 09:08 . 2011-10-15 05:48        534528        ----a-w-        c:\windows\SysWow64\EncDec.dll
2011-12-17 09:08 . 2011-11-05 05:17        2048        ----a-w-        c:\windows\system32\tzres.dll
2011-12-17 09:08 . 2011-11-05 04:30        2048        ----a-w-        c:\windows\SysWow64\tzres.dll
2011-12-11 16:26 . 2011-12-11 16:26        2300696        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2011-12-11 16:25 . 2011-12-11 16:25        42776        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-18 08:38 . 2010-08-13 19:26        1248080        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-11-18 19:17 . 2011-09-28 20:50        414368        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-08 15:24 . 2010-08-29 15:04        1092400        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-01 98304]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"UCam_Menu"="c:\program files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-11-02 281768]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2010-12-08 1226608]
"DivX Download Manager"="c:\program files (x86)\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
.
c:\users\Karle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-10 135664]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-10 135664]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AAV UpdateService;AAV UpdateService;c:\program files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [2008-10-24 128296]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-29 136360]
S2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe [2009-07-14 27136]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 95876641
*Deregistered* - 95876641
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt        REG_MULTI_SZ          hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2012-01-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-10 16:44]
.
2012-01-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-10 16:44]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-19 8067616]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{9D07C869-74F5-43C7-8DCC-BD925A258217}: NameServer = 192.168.2.1,194.25.2.129
FF - ProfilePath - c:\users\Karle\AppData\Roaming\Mozilla\Firefox\Profiles\4n9ebtwp.default\
FF - prefs.js: browser.search.selectedEngine - Google
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-mcmscsvc
SafeBoot-MCODS
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-01-03  21:32:12
ComboFix-quarantined-files.txt  2012-01-03 20:32
.
Vor Suchlauf: 9 Verzeichnis(se), 60.389.941.248 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 60.034.105.344 Bytes frei
.
- - End Of File - - 451F73EC31ED38D60557801322BA7901

bitteschön......dankeschön......

cosinus 03.01.2012 21:54

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe Vista und Win7 User aswMBR per Rechtsklick "als Administrator ausführen"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

Toolman 03.01.2012 22:18

und weiter geht es:

Code:

aswMBR version 0.9.9.1124 Copyright(c) 2011 AVAST Software
Run date: 2012-01-03 22:03:40
-----------------------------
22:03:40.439    OS Version: Windows x64 6.1.7600
22:03:40.439    Number of processors: 2 586 0x170A
22:03:40.440    ComputerName: KARLE-PC  UserName: Karle
22:03:41.371    Initialize success
22:07:58.743    AVAST engine defs: 12010300
22:08:35.850    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:08:35.854    Disk 0 Vendor: ST950032 0001 Size: 476940MB BusType: 3
22:08:35.903    Disk 0 MBR read successfully
22:08:35.907    Disk 0 MBR scan
22:08:35.916    Disk 0 unknown MBR code
22:08:35.927    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        15360 MB offset 2048
22:08:35.954    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 31459328
22:08:35.973    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      203049 MB offset 31664128
22:08:36.000    Disk 0 Partition 4 00    07    HPFS/NTFS NTFS      258429 MB offset 447508480
22:08:36.009    Service scanning
22:08:38.004    Modules scanning
22:08:38.011    Disk 0 trace - called modules:
22:08:38.070    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
22:08:38.409    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80047f3060]
22:08:38.417    3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800474f050]
22:08:39.517    AVAST engine scan C:\windows
22:08:45.565    AVAST engine scan C:\windows\system32
22:10:57.384    AVAST engine scan C:\windows\system32\drivers
22:11:09.986    AVAST engine scan C:\Users\Karle
22:13:22.050    AVAST engine scan C:\ProgramData
22:14:19.221    Scan finished successfully
22:16:37.454    Disk 0 MBR has been saved successfully to "C:\MBR.dat"
22:16:37.460    The log file has been saved successfully to "C:\aswMBR.txt"


cosinus 04.01.2012 17:26

Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.

Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.

Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.
Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

Toolman 04.01.2012 20:03

Hi Arne,

nochmals Danke fürs Helfen. Trotzdem mal ne Fragen zwischendurch zwecks "Wasserstandsmeldung": Kannst du was erkennen ob da noch was ist oder hat es sich vielleicht schon erledigt?
Laut dem Avira-Scan vom 31.12. wurde ja was gefunden und entfernt, bzw. in Quarantäneverzeichnis verschoben:

hier ist nochmal der Eintrag von Seite 1 vom 31.12.2011

greetz vom Toolman

Code:

In der Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern


Code:

In der Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern


Code:

In der Datei 'C:\Users\*****\AppData\Local\Temp\wpbt0.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern


Code:

In der Datei 'C:\Users\*****\AppData\Local\Temp\wpbt0.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern


Code:

Die Datei 'C:\Users\*****\AppData\Local\Temp\wpbt0.dll'
enthielt einen Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan].
Durchgeführte Aktion(en):
Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4a1421e0.qua' verschoben!


Code:

In der Datei 'C:\Users\*****\AppData\Local\Temp\wpbt0.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern


Code:

In der Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern


Code:

In der Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern


Code:

In der Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern


Code:

Die Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
enthielt einen Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan].
Durchgeführte Aktion(en):
Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4a3c3791.qua' verschoben!


Code:

Die Datei 'C:\Users\*****\AppData\Roaming\Opera\Opera\opera.exe'
enthielt einen Virus oder unerwünschtes Programm 'TR/Lebag.Ive.1' [trojan].
Durchgeführte Aktion(en):
Beim Versuch eine Sicherungskopie der Datei anzulegen ist ein Fehler aufgetreten und die Datei wurde nicht gelöscht. Fehlernummer: 26004.
Die Quelldatei konnte nicht gefunden werden.
Es wird versucht die Aktion mit Hilfe der ARK Library durchzuführen.
Die Datei konnte nicht ins Quarantäneverzeichnis verschoben werden!
Die Datei existiert nicht!

cosinus 04.01.2012 20:19

Du weißt, was eine Quarantäne ist? Ob da die schädliche Datei drinbleibt oder nicht, das hat keine Auswirkungen. Schädlinge in der Quarantäne können nichts mehr anrichten, sie sind dort isoliert. Du solltest grundsätzlich mit der Quarantäne arbeiten, denn falls der Virenscanner durch einen Fehlalarm was wichtiges löscht, kannst Du notfalls noch über die Quarantäne an die Datei ran.

Toolman 04.01.2012 20:36

ja, das mit der Quarantäne habe ich verstanden. Die gefundenen Teile sind isoliert...passt soweit.
Die anderen Scanner haben ja anscheinend nichts mehr gefunden, soweit ich das lesen konnte, ist das richtig?

Ich kann mich erst am Wochenende um die Datensicherung kümmern.....melde mich dann wieder.....thanx a lot.

Toolman 07.01.2012 16:49

hi,

ich habe jetzt den FIX MBR gemacht und dann das Log erstellt:

Code:

aswMBR version 0.9.9.1124 Copyright(c) 2011 AVAST Software
Run date: 2012-01-07 16:32:10
-----------------------------
16:32:10.598    OS Version: Windows x64 6.1.7601 Service Pack 1
16:32:10.598    Number of processors: 2 586 0x170A
16:32:10.598    ComputerName: KARLE-PC  UserName: Karle
16:32:12.314    Initialize success
16:36:30.827    AVAST engine defs: 12010700
16:36:51.804    Verifying
16:37:01.850    Disk 0 Windows 601 MBR fixed successfully
16:37:45.821    Verifying
16:37:55.883    Disk 0 Windows 601 MBR fixed successfully
16:38:26.038    Disk 0 MBR has been saved successfully to "C:\Users\Public\Documents\MBR.dat"
16:38:26.038    The log file has been saved successfully to "C:\Users\Public\Documents\aswMBR.txt"


cosinus 07.01.2012 17:04

Du solltest Windows neu starten und ein neues Log mit aswMBR machen. Das Fixlog selbst wollte ich eigentlich nicht sehen.

Toolman 07.01.2012 17:25

jetzt habe ich nochmal mit dem Button SCAn gearbeitet. Hier ist der log:

Code:

aswMBR version 0.9.9.1124 Copyright(c) 2011 AVAST Software
Run date: 2012-01-07 16:32:10
-----------------------------
16:32:10.598    OS Version: Windows x64 6.1.7601 Service Pack 1
16:32:10.598    Number of processors: 2 586 0x170A
16:32:10.598    ComputerName: KARLE-PC  UserName: Karle
16:32:12.314    Initialize success
16:36:30.827    AVAST engine defs: 12010700
16:36:51.804    Verifying
16:37:01.850    Disk 0 Windows 601 MBR fixed successfully
16:37:45.821    Verifying
16:37:55.883    Disk 0 Windows 601 MBR fixed successfully
16:38:26.038    Disk 0 MBR has been saved successfully to "C:\Users\Public\Documents\MBR.dat"
16:38:26.038    The log file has been saved successfully to "C:\Users\Public\Documents\aswMBR.txt"


aswMBR version 0.9.9.1124 Copyright(c) 2011 AVAST Software
Run date: 2012-01-07 17:12:55
-----------------------------
17:12:55.555    OS Version: Windows x64 6.1.7601 Service Pack 1
17:12:55.556    Number of processors: 2 586 0x170A
17:12:55.557    ComputerName: KARLE-PC  UserName: Karle
17:12:56.589    Initialize success
17:13:03.141    AVAST engine defs: 12010700
17:13:26.213    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
17:13:26.217    Disk 0 Vendor: ST950032 0001 Size: 476940MB BusType: 3
17:13:26.236    Disk 0 MBR read successfully
17:13:26.241    Disk 0 MBR scan
17:13:26.270    Disk 0 Windows 7 default MBR code
17:13:26.293    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        15360 MB offset 2048
17:13:26.309    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 31459328
17:13:26.318    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      203049 MB offset 31664128
17:13:26.344    Disk 0 Partition 4 00    07    HPFS/NTFS NTFS      258429 MB offset 447508480
17:13:26.355    Service scanning
17:13:31.074    Modules scanning
17:13:31.081    Disk 0 trace - called modules:
17:13:31.176    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
17:13:31.186    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80057843d0]
17:13:31.195    3 CLASSPNP.SYS[fffff88001b8543f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800476a050]
17:13:32.121    AVAST engine scan C:\windows
17:13:37.811    AVAST engine scan C:\windows\system32
17:16:08.581    AVAST engine scan C:\windows\system32\drivers
17:16:23.770    AVAST engine scan C:\Users\Karle
17:19:10.956    AVAST engine scan C:\ProgramData
17:20:15.115    Scan finished successfully
17:21:59.352    Disk 0 MBR has been saved successfully to "C:\Users\Public\Documents\MBR.dat"
17:21:59.390    The log file has been saved successfully to "C:\Users\Public\Documents\aswMBR.txt"

wolltest du das haben? oder muß ich was anderes machen?!?!
greetz Toolman

cosinus 07.01.2012 17:47

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!


Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Toolman 07.01.2012 19:29

hier das ergebnis von MALEWAREBYTES:

Code:

Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.07.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Karle :: KARLE-PC [Administrator]

07.01.2012 18:21:21
mbam-log-2012-01-07 (18-21-21).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 372652
Laufzeit: 1 Stunde(n), 6 Minute(n), 6 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


Toolman 07.01.2012 22:49

....und hier das Ergebnis von SUPERANTISPYWARE:

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 01/07/2012 at 10:40 PM

Application Version : 5.0.1142

Core Rules Database Version : 8112
Trace Rules Database Version: 5924

Scan type      : Complete Scan
Total Scan Time : 02:22:10

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 664
Memory threats detected  : 0
Registry items scanned    : 72550
Registry threats detected : 0
File items scanned        : 232461
File threats detected    : 564

Adware.Tracking Cookie
        s0.2mdn.net [ C:\USERS\KARLE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TJ2U9Z3L ]
        .paypal.112.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        data.coremetrics.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .dealtime.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        stat.dealtime.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wgkyakd5gdo.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wdl4ukazccq.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .myhammer.122.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjkywpcjgho.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        delivery.atkmedia.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjlikodjclo.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aekycpdzkgp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wblyokczcep.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjlyqjczofo.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .cunda.122.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wakioidzwfo.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .media2.legacy.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .peoplefinders.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .peoplefinders.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tele2de.112.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wbkoulcjgbo.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aekokncpkcq.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjl4soajoco.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wfkiejd5glp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        tracking.tchibo.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ads5.wwe.biz [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ads20.wwe-media.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .3pagen.112.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjlooicjigp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wfliejdzeko.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjlychdpgfp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wfkokmdzckp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wcloelcpiao.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .deutschepostag.112.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wdkoaoczeao.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .usenext.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .vinvest.122.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjlywjczeco.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .loyaltypartner.122.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .roitracking.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .usenext.122.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wblyaidpmdp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjkyqhczogp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wfkisjcpkbo.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wnmiokajkkq.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wml4sjazkbp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aeliakdjsco.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .movitex.122.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6whkiugazklp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjk4oldjgfp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjlyupd5ehq.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .nextag.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .nextag.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .nextag.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wfkycgdjclq.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        urbia.wwe-media.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adcentriconline.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.elitepartner.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        1.bfugmedia.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wfmychcjkeq.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wnkoegdpidp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wmmykhazwap.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .bizrate.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .cheaptickets.122.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wbl4ggazwbq.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjliapczagq.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wgkiuhdzolq.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.adserverhome.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .olympiaverlag.122.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wcmiahc5ecp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wfkialajehp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aek4sidpsdo.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .wissende.122.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        stats.limango-outlet.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjliqldjoeo.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .secmedia.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        tracking.sim-technik.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .sevenoneintermedia.112.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        frankwalder.traffective-tracking.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        frankwalder.traffective-tracking.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        frankwalder.traffective-tracking.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        frankwalder.traffective-tracking.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        frankwalder.traffective-tracking.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        frankwalder.traffective-tracking.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .zeg-radnetz.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .zeg-radnetz.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .zeg-radnetz.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aeloojdzacp.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .snapfish.112.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aelywidzifo.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wdlyapdpcko.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .viewablemedia.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .richmedia.yahoo.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6whmismazwep.stats.esomniture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad1.dyntracker.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        s0.2mdn.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        tomtailor.dyntracker.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        adserver.ps3m.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .aka-cdn-ns.adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .cewecolor.112.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .www.burstnet.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .kaspersky.122.2o7.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        advert-server.combrella.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.usenext.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .dyntracker.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        zbox.zanox.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        www.traffective-tracking.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\KARLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4N9EBTWP.DEFAULT\COOKIES.SQLITE ]

Trojan.Dropper/Gen-NV
        C:\USERS\KARLO\MUSIC\MUSIK-A-Z\S\SUM 41 - UNDERCLASS HERO (2007)\_____PADDING_FILE_4_IF YOU SEE THIS FILE, PLEASE UPDATE TO BITCOMET 0.85 OR ABOVE____

hier kam was raus! Ich habe noch nichts gelöscht oder in Quaratäne verschoben, warte auf deine Anweisungen.

Muß ich den ESET Online Scanner noch machen? Auf Seite 1 habe ich den schonmal gemacht und das Ergebnis eingestellt.

Gruß Toolman

cosinus 07.01.2012 23:45

Die Cookies können weg.
Was ist das in deinem Musikordner?

Toolman 07.01.2012 23:51

Keine Ahnung, was das ist????? Meinst du die Gruppe (Sum41)? Soll ich es auch löschen? Bin da ein wenig überfragt:confused:

cosinus 07.01.2012 23:59

Tja, da hast wohl Musik bekommen, die über Tauschbörsen verbreitet wird => BitComet :pfeiff:

Toolman 08.01.2012 00:14

ok, dann weiß ich das jetzt auch..........war sowieso nicht der burner, die cd:daumenrunter: hab gleich mal gelöscht.

was nun? hast du mal einen kleinen zwischenbericht?

ich danke dir für deine Hilfe:daumenhoc

gruß Toolman

cosinus 08.01.2012 01:01

Ich warte immer noch auf ESET :pfeiff:

Toolman 08.01.2012 14:30

der ESET Online Scanner dauert bei mir sehr lange (ca. 4-5 Stunden).
Wird heute im laufe des Tages geliefert:daumenhoc

grüße Toolman

Toolman 09.01.2012 07:09

habe den ESET Online Scanner die ganze Nacht drüber laufen lassen, gefunden wurde auch nichts. Leider kann ich den log.txt nicht finden, bin nach deinen Anweisungen vorgegangen, aber es kommt immer wieder: "..........konnte nicht gefunden werden, Stellen Sie sicher.....".

Was nun?:confused::confused:

cosinus 09.01.2012 11:18

:pfeiff:

Hinweis: Falls du ein 64-Bit-Windows einsetzt, lautet der Pfad so:

Code:

"%PROGRAMFILES(X86)%\Eset\Eset Online Scanner\log.txt"

Toolman 09.01.2012 21:16

yep, hab ich genau so gemacht......ging trotzdem nichts.........:confused:

cosinus 09.01.2012 22:27

Hat ESET denn überhaupt was gefunden?

Toolman 11.01.2012 21:32

Nein, gefunden hat ESET nichts.

grüße Toolman

cosinus 11.01.2012 21:46

Dann ist es auch fast wurscht :D
Rechner soweit wieder im Lot?

Toolman 11.01.2012 21:57

Ja, der Rechner läuft, wie schon in meinem ersten post geschrieben. Nachdem AVIRA 2 Sachen in Quarantäne verschoben hat kam die Abzocker-Anzeige nicht mehr.
Denkst du, das nach den ganzen Programmen die ich drüber laufen gelast habe, alles i.o. ist? Wäre sehr beruhigend für mich:applaus:

cosinus 12.01.2012 15:23

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

Toolman 16.01.2012 22:47

Hi,

vielen Dank fürs Helfen:dankeschoen:

Wenn ich noch Fragen habe, werde ich mich wieder an Dich/Euch wenden:daumenhoc

Spende ist unterwegs.:party:

Greetz Toolman


Alle Zeitangaben in WEZ +1. Es ist jetzt 20:40 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27