Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   CPU Auslastung 100% Firefox- und anschließender Systemabsturz. Vermutung: sychost.exe-Virus (https://www.trojaner-board.de/110047-cpu-auslastung-100-firefox-anschliessender-systemabsturz-vermutung-sychost-exe-virus.html)

vivastern 16.02.2012 17:39

CPU Auslastung 100% Firefox- und anschließender Systemabsturz. Vermutung: sychost.exe-Virus
 
Hallo!
Wie toll, dass es euch gibt! Eure Hilfestellungen zu anderen Problemen machen mir jedenfalls große Hoffnung. Ich würde nämlich gern um eine Systemwiederherstellung herumkommen wenn möglich....mal schauen...

Seit ca. November passiert es immer häufiger, dass der Firefox auf meinem 64-Bit HP G62 Laptop (Win7) speziell beim Online-Streaming von Videos plötzlich abstürzt. Das Bild wird langsam, der Ton kratzt schrecklich und beim Neustart von firefox (nach einfachem Schließen) erscheint nur die Nachricht: firefox wird bereits ausgeführt.

Erst testete ich firefox selbst, mehrfache Neuinstallation, aber keine Änderung. Dann habe ich das AddOn für den Divx- sowie den Flash-Player erneuert. Mehr AddOns habe ich nebenbei auch nicht. Java bekam ein Update, alle Windowsupdates sind drauf. Ich benutze AVG als Antivirensoftware, McAfee ist zwar installiert, aber nicht aktiv. Ich habe Virenscans von AVG und mit Viprerescue (empfahl ein Kumpel für Trojaner) durchgeführt ohne Ergebnis.

Seitdem habe ich angefangen, den firefox nach einem Absturz nur noch mit dem Taskmanager zu schließen, was anfangs auch hervorragend funktionierte. Mir fiel auf, dass die CPU bei 90-100% lag. Nach dem Schließen durch den Taskmanager ging die CPU nach wenigen Momenten wieder auf 0%. Leider funktioniert das bis heute nicht mehr so gut, sodass ich teilweise bis zu 5 Neustarts des ganzen Systems brauche, bis die extreme Auslastung und die Begleiterscheinungen wieder verschwinden. Allerdings dann auch nur bis zum nächsten Streamaufruf bzw. 1-5 Minuten nach Beginn des Streams oder spätestens einfach irgendwann beim sonstigen Gebrauch von firefox.

Im Taskmanager ist mir dann aufgefallen, dass der Prozess sychost.exe ganze 12mal in meinem Laptop vorkommt, mal als System-, dann als Netzwerk- dann als Lokaler Dienst-Prozess. Beim Versuch den sychost.exe anzuhalten, hat er sich einfach verdoppelt. Da hab ich dann lieber angefangen, die Finger von zu lassen. Leider bin ich Laie, geb zwar mein Bestes, konnte unter google oder hier aber keine konkrete Lösung finden, weshalb ich hoffe, dass ihr mir helfen könnt. Dafür schon mal im Voraus LIEBEN DANK!

Hier meine DDS:
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_30
Run by Verena at 16:15:21 on 2012-02-16
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3958.2538 [GMT 1:00]
.
AV: AVG Anti-Virus Free *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Program Files (x86)\AVG\AVG9\avgchsva.exe
C:\Program Files (x86)\AVG\AVG9\avgrsa.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
C:\Windows\SysWOW64\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe
C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe
C:\Program Files (x86)\AVG\AVG9\avgemc.exe
C:\Program Files (x86)\AVG\AVG9\avgnsa.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Users\Verena\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe
C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe
C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live Anmelde-Hilfsprogramm: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
uRun: [Google Update] "C:\Users\Verena\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [PCMAgent] "C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe"
mRun: [CLMLServer] "C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe"
mRun: [PlayMovie] "C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe"
mRun: [TVEService] "C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
StartupFolder: C:\Users\Verena\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Verena\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\Verena\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 0 (0x0)
IE: Free YouTube to Mp3 Converter - C:\Users\Verena\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{1836C5DF-6BD3-4F33-BA84-5AF63BF9A82A} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{1836C5DF-6BD3-4F33-BA84-5AF63BF9A82A}\14C4943454D275C414E44383 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{1836C5DF-6BD3-4F33-BA84-5AF63BF9A82A}\14C4943454D275C414E47353 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{1836C5DF-6BD3-4F33-BA84-5AF63BF9A82A}\35475627E69647A7B656 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{1836C5DF-6BD3-4F33-BA84-5AF63BF9A82A}\3596475636F6D6162373431663 : DhcpNameServer = 80.69.100.174 80.69.100.198
TCP: Interfaces\{1836C5DF-6BD3-4F33-BA84-5AF63BF9A82A}\64259445A51224F6870264F6E60275C414E40273234303 : DhcpNameServer = 192.168.178.1
TCP: Interfaces\{1836C5DF-6BD3-4F33-BA84-5AF63BF9A82A}\74962716D6F6E64696 : DhcpNameServer = 192.168.200.1
TCP: Interfaces\{19E8CE94-6224-4CBE-9FD3-BEA45CE821E9} : DhcpNameServer = 192.168.1.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
SEH: EasyBits ShellExecute Hook: {e54729e8-bb3d-4270-9d49-7389ea579090} - C:\Windows\SysWow64\EZUPBH~1.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{326E768D-4182-46FD-9C16-1449A49795F4}
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun-x64: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun-x64: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
mRun-x64: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun-x64: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun-x64: [PCMAgent] "C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe"
mRun-x64: [CLMLServer] "C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe"
mRun-x64: [PlayMovie] "C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe"
mRun-x64: [TVEService] "C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun-x64: [(Standard)]
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
SEH-X64: {E54729E8-BB3D-4270-9D49-7389EA579090}: EasyBits Security Shield Hook - prevents launching insecure programs by kids
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Verena\AppData\Roaming\Mozilla\Firefox\Profiles\lheuqom4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=13
FF - component: C:\Program Files (x86)\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Verena\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 AvgLdx64;AVG Free AVI Loader Driver x64;C:\Windows\system32\Drivers\avgldx64.sys --> C:\Windows\system32\Drivers\avgldx64.sys [?]
R1 AvgMfx64;AVG Free On-access Scanner Minifilter Driver x64;C:\Windows\system32\Drivers\avgmfx64.sys --> C:\Windows\system32\Drivers\avgmfx64.sys [?]
R1 AvgTdiA;AVG Free Network Redirector x64;C:\Windows\system32\Drivers\avgtdia.sys --> C:\Windows\system32\Drivers\avgtdia.sys [?]
R1 SBRE;SBRE;\??\C:\Windows\system32\drivers\SBREdrv.sys --> C:\Windows\system32\drivers\SBREdrv.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2010-4-20 98208]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 avg9emc;AVG Free E-mail Scanner;C:\Program Files (x86)\AVG\AVG9\avgemc.exe [2010-7-7 921952]
R2 avg9wd;AVG Free WatchDog;C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe [2010-7-7 308136]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
R2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\system32\svchost.exe -k netsvcs [2009-7-14 20992]
R2 TVECapSvc;TVEnhance Background Capture Service (TBCS);C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe [2011-9-27 464224]
R2 TVESched;TVEnhance Task Scheduler (TTS));C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe [2011-9-27 189792]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-4-20 2320920]
R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-1-23 227896]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 HP Support Assistant Service;HP Support Assistant Service;"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe" --> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [?]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2010-4-20 225280]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
.
=============== Created Last 30 ================
.
2012-02-16 09:16:54 634880 ----a-w- C:\Windows\System32\msvcrt.dll
2012-02-16 09:16:54 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
2012-02-16 09:16:53 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2012-02-16 09:15:02 3145728 ----a-w- C:\Windows\System32\win32k.sys
2012-02-01 12:24:39 -------- d-----w- C:\Program Files (x86)\Audiograbber
2012-01-22 22:52:04 -------- d-----w- C:\Users\Verena\AppData\Local\DDMSettings
.
==================== Find3M ====================
.
2012-01-10 22:21:10 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-01-04 00:48:42 354176 ----a-w- C:\Windows\SysWow64\DivXControlPanelApplet.cpl
2011-11-30 12:50:41 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-11-30 12:50:41 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-11-19 14:58:00 77312 ----a-w- C:\Windows\System32\packager.dll
2011-11-19 14:01:00 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2011-11-19 00:08:32 136 ----a-w- C:\Users\Verena\AppData\Roaming\srvblck2.tmp
.
============= FINISH: 16:17:02,95 ===============

cosinus 17.02.2012 20:47

Zitat:

speziell beim Online-Streaming von Videos plötzlich abstürzt.
In diesem Zusammenhang: Wozu nutzt du diesen DivX-Player? Seiten wie Youtube brauchen nichtmal mehr Flash, es reicht HTML5

Zitat:

der Ton kratzt schrecklich und beim Neustart von firefox (nach einfachem Schließen) erscheint nur die Nachricht: firefox wird bereits ausgeführt.
(...)Dann habe ich das AddOn für den Divx- sowie den Flash-Player erneuert
Wenn man aucf so komische Nachfolgerseiten wie das vom kürzlich geschlossenen illegalen Portal geht, würde mich das nicht wundern. Aber dazu gibt es leider keine Infos von dir was für Streamingseiten du nun genau meinst :glaskugel:

vivastern 18.02.2012 16:30

Lieber Arne,

mir ist durchaus bewusst, dass das Onlinestreaming Risiken birgt. Ich denke über legal/illegal sollten wir hier nicht diskutieren, da mein Problem auch vollkommen unabhängig vom Streamen auftritt. Außerdem schaue ich sowieso nur Videos, die in den USA frei zugänglich sind, an die ich aber nicht rankomme, weil ich mich nicht so gut auskenne, als dass ich meine IP anonymisieren, o.ä. könnte. Ich denke also meine Nutzung ist legitim und du bist beruhigt. Und natürlich verschlägt es auch mich das ein oder andere Mal auf diese bekannte Seite...

Ich habe vorgestern noch einmal Firefox aktualisiert, AVG und Malwarebytes drüber laufen lassen (unabhängig voneinander). Log von mwb ist angehängt, AVG versteh ich leider nicht, wie ich an die Datei rankomme, sorry.
Seltsam war, dass in der Zeit, in der AVG deinstalliert war, ein sog. Windows-Defender ansprang, den ich nicht kenne und in der Systemsteuerung nicht als Programm aufgeführt ist. Muss der da sein oder könnte sich der sogar mit anderen Programmen nicht vertragen?

Naja, danach lief 1 Tag alles gut, dann wieder CPU bei 100%. Normalerweise liegt der Wert bei durchschnittlich 5%, auch während ich streame.

Vielleicht hast du ja noch weitere Ideen, wie du mir helfen könntest!?
LG

cosinus 19.02.2012 18:43

Zitat:

Ich denke über legal/illegal sollten wir hier nicht diskutieren,
Doch das ist immer ein Thema. Gerade solche Seiten verteilen Malware! Also lass einfach die Finger davon in Zukunft!

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

vivastern 20.02.2012 12:27

Lieber Arne,
du hast ja recht....und vielleicht kennst du ja nachdem wir mein Problem gelöst haben ein paar gute Möglichkeiten bzw. Empfehlungen, wie ich doch in den Genuß der neusten Episoden komme ohne mein System erneut in Gefahr zu bringen...

Die angeforderten Logs sind im Anhang. Sorry, da sind diverse abgebrochene dabei, bei denen ich die Aktualisierung vorher vergessen hatte oder es ein Absturz unmöglich gemacht hat, auch nur den Quick-Scan laufen zu lassen.

Neuerdings hat sich sychost.exe noch um ein paar weitere vermehrt. Es existiert nun als Lokaler Dienst, Netzwerkdienst und Systemprozess...bei jedem Versuch des Neustarts bekomme ich den Hinweis: "Hintergrundprogramme müssen noch geschlossen werden" obwohl kein von mir geöffnetes mehr läuft. Ist jetzt halt die Frage, was da hintenrum noch so läuft außer meinem AVG...?

cosinus 20.02.2012 13:00

Zitat:

wie ich doch in den Genuß der neusten Episoden komme ohne mein System erneut in Gefahr zu bringen...
Schonmal was von Videotheken gehört? Gibt auch Online-Videotheken. Und man kann sich auch DVDs kaufen, ja wer hätte das gedacht. Aber von diesen Streamingseiten lässt du mal schön die Finger in Zukunft. :pfui:

Bitte nun routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

vivastern 20.02.2012 14:07

Zitat:

Schonmal was von Videotheken gehört?
Ich leihe mir ordnungsgemäß alles Filme aus der Videothek aus oder gehe ins Kino, mir fällrt es nur so schwer, die Finger von den Serien zu lassen, die am Vortag brandneu im US-Tv liefen....naja....

Malwarebytes rattert, wollte nur noch schnell fragen, ob es ausreicht, einfach Beenden zu klicken, um den AVG komplett "AUS" zu machen??? Wenn schon reparieren, dann richtig :aufsmaul:

Danke & bis später!

cosinus 20.02.2012 15:27

Zitat:

mir fällrt es nur so schwer, die Finger von den Serien zu lassen, die am Vortag brandneu im US-Tv liefen....naja....
Dann musst du aber auch nicht über einen infizierten Rechner jammern, wenn du diese Drecksschleuderseiten immer wieder besuchst :balla:
Und ja, AVG am besten deaktivieren

vivastern 20.02.2012 16:09

ok... ich war kurz weg vom Schreibtisch, als ich wiederkam, war der laptop gerade am Neustarten. Ich weiß also nicht, ob das eset fertig war, oder evtl. vom Virus geblockt wurde...? Möglich?

Zitat:

Und ja, AVG am besten deaktivieren
Wie ges/fragt, habe im AVG nur unter Datei -> Beenden geklickt, weiß ja nicht, ob das ausreicht, den ganz abzuschalten?

Sorry, das mit dem Code check ich nicht.... hab das log mal in den Anhang getan.

cosinus 20.02.2012 16:11

Also ich weiß einfach nicht wie man das einfacher erklären soll :balla:
http://www.trojaner-board.de/misc.php?do=bbcode#code

Und ESET hast du falsch ausgeführt! => Anmerkung für Vista und Win7 User: Bitte den Browser unbedingt so öffnen: per Rechtsklick => als Administrator ausführen

vivastern 20.02.2012 18:40

Entschuldige bitte meine Fehler. Das Programm läuft gerade nochmal drüber... aber ist das normal, dass das sooo lange dauert? Er ist erst bei 30% und läuft schon 2:21h...

vivastern 20.02.2012 23:17

Code:

ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=53251
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=ad476985132a8b45a77d84f3b9b24509
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-02-20 06:43:10
# local_time=2012-02-20 07:43:10 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1024 16777215 100 0 254557 254557 0 0
# compatibility_mode=5893 16776574 100 94 255844 81380922 0 0
# compatibility_mode=8192 67108863 100 0 8235 8235 0 0
# scanned=212194
# found=1
# cleaned=0
# scan_time=12339
C:\Users\Verena\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\5ef93b75-1207685f        multiple threats (unable to clean)        00000000000000000000000000000000        I

Mal sehen, ob das in deinem Sinne war... und wie es wohl so weitergeht....

cosinus 21.02.2012 12:58

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


vivastern 21.02.2012 16:36

Hier die "normale" Log (er hat noch eine Extra-Log erstellt s.u.)
Code:

OTL logfile created on: 21.02.2012 16:10:28 - Run 1
OTL by OldTimer - Version 3.2.33.1    Folder = C:\Users\Verena\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,87 Gb Total Physical Memory | 2,55 Gb Available Physical Memory | 65,86% Memory free
7,73 Gb Paging File | 6,08 Gb Available in Paging File | 78,70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452,56 Gb Total Space | 363,78 Gb Free Space | 80,38% Space Free | Partition Type: NTFS
Drive D: | 12,90 Gb Total Space | 2,15 Gb Free Space | 16,67% Space Free | Partition Type: NTFS
Drive E: | 99,02 Mb Total Space | 95,14 Mb Free Space | 96,08% Space Free | Partition Type: FAT32
 
Computer Name: VERENAS-PC | User Name: Verena | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.02.21 16:05:43 | 000,583,168 | ---- | M] (OldTimer Tools) -- C:\Users\Verena\Desktop\OTL.exe
PRC - [2012.02.17 18:36:30 | 000,939,872 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
PRC - [2012.02.17 18:36:30 | 000,909,152 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe
PRC - [2012.01.24 17:24:26 | 002,416,480 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
PRC - [2012.01.18 19:54:06 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Users\Verena\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2012.01.03 14:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.10.12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011.08.02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
PRC - [2011.07.29 00:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.05.20 23:59:30 | 011,312,128 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2010.05.20 23:59:28 | 011,318,784 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2009.10.01 05:01:32 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009.10.01 05:01:30 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009.09.29 16:56:26 | 000,464,224 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe
PRC - [2009.09.29 16:56:26 | 000,189,792 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe
PRC - [2009.09.29 16:56:04 | 000,226,536 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe
PRC - [2009.09.16 10:34:20 | 000,202,024 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe
PRC - [2009.09.16 10:34:02 | 000,148,776 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe
PRC - [2009.09.08 17:07:24 | 000,177,384 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.02.17 18:36:30 | 000,939,872 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
MOD - [2012.02.16 19:17:36 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\cb5bd98ffa4c82327b0e4db02bb58d2d\System.Management.ni.dll
MOD - [2012.02.16 10:38:41 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\74fcc0f56435d0396f9524cd4293d3e5\PresentationFramework.Aero.ni.dll
MOD - [2012.02.16 10:38:07 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a1c4a635721f85bef0ea4194b888b871\System.Runtime.Remoting.ni.dll
MOD - [2012.02.16 10:38:03 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\eedf95f16a7e81ca43dd8accf11498a3\System.Data.ni.dll
MOD - [2012.02.16 10:37:45 | 014,339,072 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\02f7846cbc5c02a5dbf50fd34325eb61\PresentationFramework.ni.dll
MOD - [2012.02.16 10:37:16 | 012,433,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6c51e152e7404188914c9fa4d8503ff9\System.Windows.Forms.ni.dll
MOD - [2012.02.16 10:37:02 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ab87129c2b603f218e4aa5300c9b1bdd\System.Drawing.ni.dll
MOD - [2012.02.16 10:36:57 | 012,234,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\f4b2424c1b32fbd11130482bb899b7ae\PresentationCore.ni.dll
MOD - [2012.02.16 10:36:40 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\47b9e7f070271ff50f988f75ea68fa3e\WindowsBase.ni.dll
MOD - [2012.02.16 10:36:33 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll
MOD - [2012.02.16 10:36:25 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll
MOD - [2012.02.16 10:36:23 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll
MOD - [2011.12.02 03:24:29 | 000,185,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\93df5ea9646ad11a21517e4ab1d803d9\UIAutomationTypes.ni.dll
MOD - [2011.12.02 03:23:43 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011.07.29 00:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.07.29 00:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2011.03.04 11:02:54 | 007,745,536 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
MOD - [2011.03.04 11:02:52 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
MOD - [2011.03.04 11:02:50 | 002,121,728 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
MOD - [2010.11.13 00:26:08 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.11.05 02:58:05 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2010.05.04 15:36:28 | 000,970,752 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2010.01.23 23:30:31 | 000,249,856 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_de_31bf3856ad364e35\PresentationFramework.resources.dll
MOD - [2010.01.23 23:30:15 | 000,167,936 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml.resources\2.0.0.0_de_b77a5c561934e089\System.Xml.resources.dll
MOD - [2009.09.29 16:57:00 | 000,034,024 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Shared files\richvideops.dll
MOD - [2009.09.29 16:56:28 | 000,034,024 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLSchedps.dll
MOD - [2009.09.29 16:56:26 | 000,312,680 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLCapEngine.dll
MOD - [2009.09.29 16:56:26 | 000,042,216 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLCapSvcps.dll
MOD - [2009.09.29 15:25:46 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll
MOD - [2009.09.29 15:25:38 | 000,040,960 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingServer.dll
MOD - [2009.09.29 15:25:38 | 000,036,864 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingClients.dll
MOD - [2009.09.29 15:25:38 | 000,007,680 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\RemotingClient.dll
MOD - [2009.09.29 15:25:36 | 000,005,632 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingInterface.dll
MOD - [2009.09.29 15:25:28 | 000,018,944 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingMessages.dll
MOD - [2009.09.29 15:25:18 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll
MOD - [2009.09.16 10:34:26 | 000,873,768 | ---- | M] () -- C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMediaLibrary.dll
MOD - [2009.09.16 10:34:16 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvcPS.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2009.11.25 07:17:18 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2012.02.17 18:36:30 | 000,909,152 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe -- (vToolbarUpdater)
SRV - [2012.01.03 14:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.10.12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011.08.02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.11.18 03:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Programme\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
SRV - [2009.10.01 05:01:32 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2009.10.01 05:01:30 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2009.09.29 16:56:26 | 000,464,224 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe -- (TVECapSvc) TVEnhance Background Capture Service (TBCS)
SRV - [2009.09.29 16:56:26 | 000,189,792 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe -- (TVESched) TVEnhance Task Scheduler (TTS))
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.02.22 11:00:00 | 000,129,584 | ---- | M] (EasyBits Sofware AS) [Auto | Running] -- C:\Windows\SysWOW64\ezsvc7.dll -- (ezSharedSvc)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2011.10.07 06:23:46 | 000,283,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2011.09.13 06:30:08 | 000,037,456 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2011.08.08 06:08:58 | 000,046,672 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2011.07.11 01:14:36 | 000,375,376 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2011.07.11 01:14:08 | 000,029,776 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV:64bit: - [2011.07.11 01:14:06 | 000,120,400 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV:64bit: - [2011.07.11 01:14:06 | 000,026,704 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AVGIDSEH.sys -- (AVGIDSEH)
DRV:64bit: - [2011.06.10 06:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 10:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010.11.09 14:56:12 | 000,049,752 | ---- | M] (Sunbelt Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SBREDrv.sys -- (SBRE)
DRV:64bit: - [2010.05.27 22:32:56 | 000,320,560 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010.04.19 19:47:42 | 000,050,688 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2009.11.25 07:52:16 | 006,174,720 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009.11.19 03:30:56 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009.10.13 10:16:40 | 000,409,624 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.10.05 08:34:00 | 001,542,656 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009.09.23 02:39:00 | 000,225,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2009.09.17 21:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
DRV:64bit: - [2009.09.01 14:29:56 | 000,157,712 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\kl1.sys -- (kl1)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009.06.10 22:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009.06.10 22:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009.06.10 22:01:06 | 001,146,880 | ---- | M] (LSI Corp) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
DRV:64bit: - [2009.06.10 21:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009.06.10 21:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009.06.10 21:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel(R)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009.04.29 08:48:32 | 000,018,432 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2009.09.23 02:39:00 | 000,225,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4
IE - HKU\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4
IE - HKU\S-1-5-21-2604564059-764910878-3552578447-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultthis.engineName: "DVDVideoSoftTB Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.startup.homepage: "hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=13"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2
FF - prefs.js..keyword.URL: "hxxp://isearch.avg.com/search?cid=%7B9403eeb4-0520-49ea-b0c1-62b1eb9e3793%7D&mid=5b0d75e38c0da276cb56abf84b374079-831f635ca31915cbf27df9f3e079de75575703db&ds=AVG&v=10.0.0.7&lang=de&pr=fr&d=2012-02-17%2018%3A36%3A31&sap=ku&q="
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Verena\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Verena\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.01.22 23:44:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012.02.17 18:36:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\10.0.0.7\ [2012.02.17 18:36:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.02.17 18:40:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.02.04 16:33:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.02.17 18:40:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.02.04 16:33:38 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\extensions\\{184AA5E6-741D-464a-820E-94B3ABC2F3B4}: C:\Users\Verena\AppData\Roaming\5050 [2011.11.26 04:09:29 | 000,000,000 | ---D | M]
 
[2010.07.02 11:38:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Verena\AppData\Roaming\mozilla\Extensions
[2012.02.14 18:38:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions
[2011.03.28 13:10:17 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2012.02.14 18:38:05 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2011.07.23 16:01:50 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.07.31 14:49:50 | 000,000,931 | ---- | M] () -- C:\Users\Verena\AppData\Roaming\Mozilla\Firefox\Profiles\lheuqom4.default\searchplugins\conduit.xml
[2012.02.17 18:40:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.02.17 18:36:37 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX4
[2012.01.22 23:44:37 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 &lt;video&gt;) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2012.02.17 18:36:36 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\PROGRAMDATA\AVG SECURE SEARCH\10.0.0.7
[2011.11.26 04:09:29 | 000,000,000 | ---D | M] (Java String Helper) -- C:\USERS\VERENA\APPDATA\ROAMING\5050
[2012.02.16 15:55:53 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.11.10 05:54:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.02.16 12:02:53 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.02.16 11:48:01 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.02.16 12:02:53 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.16 12:02:53 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.16 12:02:53 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.16 12:02:53 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Verena\AppData\Local\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.210.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U21 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Verena\AppData\Local\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Verena\AppData\Local\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Verena\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Verena\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
 
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKU\S-1-5-21-2604564059-764910878-3552578447-1001\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtkOSD] C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe (EasyBits Software AS)
O4 - HKLM..\Run: [PCMAgent] C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TVEService] C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" File not found
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Verena\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKU\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKU\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Verena\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Verena\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1836C5DF-6BD3-4F33-BA84-5AF63BF9A82A}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{19E8CE94-6224-4CBE-9FD3-BEA45CE821E9}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll ()
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: ezSharedSvc - C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Macromedia Shockwave Director 10.1
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Macromedia Shockwave Director 10.1
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.XVID - xvidvfw.dll ()
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.02.21 16:05:42 | 000,583,168 | ---- | C] (OldTimer Tools) -- C:\Users\Verena\Desktop\OTL.exe
[2012.02.20 15:00:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.02.20 14:56:16 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Verena\Desktop\esetsmartinstaller_enu.exe
[2012.02.20 12:17:57 | 000,000,000 | ---D | C] -- C:\Users\Verena\Desktop\mbamlogs
[2012.02.18 14:15:30 | 000,000,000 | -H-D | C] -- C:\$AVG
[2012.02.17 18:37:25 | 000,000,000 | ---D | C] -- C:\Users\Verena\AppData\Roaming\AVG2012
[2012.02.17 18:36:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012
[2012.02.17 18:36:30 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search
[2012.02.17 18:36:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVG Secure Search
[2012.02.17 18:36:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search
[2012.02.17 18:35:56 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012
[2012.02.17 18:35:56 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\AVG
[2012.02.17 18:34:08 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2012.02.17 12:45:15 | 000,000,000 | ---D | C] -- C:\Users\Verena\AppData\Roaming\Malwarebytes
[2012.02.17 12:44:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.02.17 12:44:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.02.17 12:44:56 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.02.17 12:44:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.02.16 17:45:54 | 000,000,000 | ---D | C] -- C:\Users\Verena\Desktop\Privat
[2012.02.16 16:12:44 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Verena\Desktop\dds.com
[2012.02.16 10:50:09 | 002,061,360 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Verena\Desktop\tdsskiller.exe
[2012.02.01 13:24:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audiograbber
[2012.02.01 13:24:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audiograbber
[2012.01.22 23:52:04 | 000,000,000 | ---D | C] -- C:\Users\Verena\AppData\Local\DDMSettings
[2012.01.22 23:43:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus
[1 C:\Users\Verena\AppData\Roaming\*.tmp files -> C:\Users\Verena\AppData\Roaming\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.02.21 16:09:05 | 000,023,024 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.02.21 16:09:05 | 000,023,024 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.02.21 16:08:01 | 089,642,738 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012.02.21 16:05:43 | 000,583,168 | ---- | M] (OldTimer Tools) -- C:\Users\Verena\Desktop\OTL.exe
[2012.02.21 16:01:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.02.21 16:01:39 | 3112,587,264 | -HS- | M] () -- C:\hiberfil.sys
[2012.02.20 23:12:24 | 001,522,540 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.02.20 23:12:24 | 000,669,012 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.02.20 23:12:24 | 000,616,242 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.02.20 23:12:24 | 000,134,796 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.02.20 23:12:24 | 000,110,712 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.02.20 23:11:11 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2604564059-764910878-3552578447-1001UA.job
[2012.02.20 15:32:14 | 540,912,834 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.02.20 14:56:17 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Verena\Desktop\esetsmartinstaller_enu.exe
[2012.02.18 09:33:05 | 000,001,072 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2604564059-764910878-3552578447-1001Core.job
[2012.02.17 18:40:09 | 000,001,090 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.02.17 18:36:20 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\avg\incavi.avm
[2012.02.17 18:36:20 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\avg\iavichjw.avm
[2012.02.17 12:58:19 | 000,000,336 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForVerena.job
[2012.02.17 12:44:58 | 000,001,069 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.02.16 17:35:36 | 000,002,558 | ---- | M] () -- C:\Users\Verena\Desktop\Attach.zip
[2012.02.16 17:00:43 | 000,008,209 | ---- | M] () -- C:\Users\Verena\Desktop\defogger_disable.zip
[2012.02.16 16:12:44 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Verena\Desktop\dds.com
[2012.02.16 15:46:38 | 000,000,000 | ---- | M] () -- C:\Users\Verena\defogger_reenable
[2012.02.16 15:44:17 | 000,002,404 | ---- | M] () -- C:\Users\Verena\Desktop\Google Chrome.lnk
[2012.02.16 15:43:42 | 000,050,477 | ---- | M] () -- C:\Users\Verena\Desktop\Defogger.exe
[2012.02.16 10:50:09 | 002,061,360 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Verena\Desktop\tdsskiller.exe
[2012.02.16 10:35:10 | 000,372,888 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.02.04 16:43:38 | 000,001,022 | ---- | M] () -- C:\Users\Verena\Desktop\Dropbox.lnk
[2012.02.04 16:43:38 | 000,001,002 | ---- | M] () -- C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012.02.02 00:41:11 | 000,000,034 | ---- | M] () -- C:\Windows\cdplayer.ini
[2012.02.01 13:24:41 | 000,001,083 | ---- | M] () -- C:\Users\Public\Desktop\Audiograbber.lnk
[1 C:\Users\Verena\AppData\Roaming\*.tmp files -> C:\Users\Verena\AppData\Roaming\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.02.21 16:08:01 | 089,642,738 | ---- | C] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012.02.17 18:40:09 | 000,001,102 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.02.17 18:40:09 | 000,001,090 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.02.17 12:44:58 | 000,001,069 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.02.16 17:35:35 | 000,002,558 | ---- | C] () -- C:\Users\Verena\Desktop\Attach.zip
[2012.02.16 17:00:42 | 000,008,209 | ---- | C] () -- C:\Users\Verena\Desktop\defogger_disable.zip
[2012.02.16 15:46:38 | 000,000,000 | ---- | C] () -- C:\Users\Verena\defogger_reenable
[2012.02.16 15:43:41 | 000,050,477 | ---- | C] () -- C:\Users\Verena\Desktop\Defogger.exe
[2012.02.02 00:41:11 | 000,000,034 | ---- | C] () -- C:\Windows\cdplayer.ini
[2012.02.01 13:24:41 | 000,001,083 | ---- | C] () -- C:\Users\Public\Desktop\Audiograbber.lnk
[2011.11.19 11:58:00 | 000,645,632 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011.11.19 11:58:00 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011.11.19 01:08:34 | 000,000,072 | ---- | C] () -- C:\Users\Verena\AppData\Roaming\blckdom.res
[2011.03.16 15:50:00 | 000,001,854 | ---- | C] () -- C:\Users\Verena\AppData\Roaming\GhostObjGAFix.xml
[2010.07.13 09:30:46 | 000,001,102 | ---- | C] () -- C:\Users\Verena\AppData\Roaming\wklnhst.dat
[2010.07.01 12:55:52 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010.04.20 01:30:31 | 000,009,868 | ---- | C] () -- C:\Windows\SysWow64\ezdigsgn.dat
[2010.04.20 01:27:16 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.04.20 01:20:27 | 000,000,268 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog2.ini
[2010.04.20 01:20:27 | 000,000,209 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog.ini
 
========== LOP Check ==========
 
[2011.11.19 01:08:44 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5043
[2011.11.20 13:58:27 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5044
[2011.11.21 12:34:48 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5045
[2011.11.22 13:01:29 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5047
[2011.11.23 11:31:27 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5048
[2011.11.24 10:26:31 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5049
[2011.11.26 04:09:29 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5050
[2012.02.17 18:37:25 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\AVG2012
[2012.02.21 16:02:21 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Dropbox
[2011.07.23 16:01:55 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\DVDVideoSoft
[2011.07.23 16:01:50 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.11.19 01:08:23 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\kock
[2012.01.12 14:24:31 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Langenscheidt
[2011.11.08 18:11:51 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Mobipocket
[2010.12.07 14:06:39 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\OpenOffice.org
[2012.01.25 20:12:50 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\PowerCinema
[2010.07.13 09:30:49 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Template
[2010.07.03 11:50:19 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Tific
[2012.01.09 18:11:46 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\uTorrent
[2012.01.12 16:20:44 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Vocup
[2012.01.13 13:26:10 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Wise Registry Cleaner
[2011.11.19 01:08:26 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\xmldm
[2010.07.01 12:55:46 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\_MDLogs
[2012.02.16 10:09:11 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.11.19 01:08:44 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5043
[2011.11.20 13:58:27 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5044
[2011.11.21 12:34:48 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5045
[2011.11.22 13:01:29 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5047
[2011.11.23 11:31:27 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5048
[2011.11.24 10:26:31 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5049
[2011.11.26 04:09:29 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\5050
[2010.12.07 11:51:57 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Adobe
[2010.08.01 14:21:29 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Apple Computer
[2010.07.01 12:56:24 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\ATI
[2012.02.17 18:37:25 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\AVG2012
[2011.09.27 11:01:05 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\CyberLink
[2010.09.15 20:38:47 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\DivX
[2012.02.21 16:02:21 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Dropbox
[2011.07.23 16:01:55 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\DVDVideoSoft
[2011.07.23 16:01:50 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.12.16 16:18:23 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Hewlett-Packard
[2010.07.07 11:10:08 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\HP Support Assistant
[2011.07.01 15:07:08 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\hpqLog
[2012.01.13 09:58:40 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\HpUpdate
[2010.07.01 12:55:01 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Identities
[2011.11.19 01:08:23 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\kock
[2012.01.12 14:24:31 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Langenscheidt
[2010.07.02 09:48:35 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Macromedia
[2012.02.17 12:45:15 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Malwarebytes
[2010.04.20 10:14:09 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Media Center Programs
[2012.02.17 18:15:06 | 000,000,000 | --SD | M] -- C:\Users\Verena\AppData\Roaming\Microsoft
[2011.11.08 18:11:51 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Mobipocket
[2010.07.02 11:38:21 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Mozilla
[2010.11.03 13:21:11 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\MozillaControl
[2011.09.27 11:34:15 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Nero
[2010.12.07 14:06:39 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\OpenOffice.org
[2012.01.25 20:12:50 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\PowerCinema
[2011.11.12 00:00:32 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Skype
[2010.07.13 09:30:49 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Template
[2010.07.03 11:50:19 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Tific
[2012.01.09 18:11:46 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\uTorrent
[2012.01.09 16:19:11 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\vlc
[2012.01.12 16:20:44 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Vocup
[2011.08.24 15:56:31 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\WinRAR
[2012.01.13 13:26:10 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\Wise Registry Cleaner
[2011.11.19 01:08:26 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\xmldm
[2010.07.01 12:55:46 | 000,000,000 | ---D | M] -- C:\Users\Verena\AppData\Roaming\_MDLogs
 
< %APPDATA%\*.exe /s >
[2012.01.18 19:54:06 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Users\Verena\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2012.01.18 19:54:36 | 000,174,752 | ---- | M] (Dropbox, Inc.) -- C:\Users\Verena\AppData\Roaming\Dropbox\bin\Uninstall.exe
[2011.11.08 18:09:03 | 000,007,406 | R--- | M] () -- C:\Users\Verena\AppData\Roaming\Microsoft\Installer\{E888E5BE-1BF6-4B5C-967A-5336490E56C6}\_18be6784.exe
[2011.11.08 18:09:03 | 000,007,406 | R--- | M] () -- C:\Users\Verena\AppData\Roaming\Microsoft\Installer\{E888E5BE-1BF6-4B5C-967A-5336490E56C6}\_294823.exe
[2011.11.08 18:09:03 | 000,007,406 | R--- | M] () -- C:\Users\Verena\AppData\Roaming\Microsoft\Installer\{E888E5BE-1BF6-4B5C-967A-5336490E56C6}\_4ae13d6c.exe
 
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 08:44:20 | 000,855,040 | ---- | M] (Microsoft Corporation) -- C:\install.exe
 
 
< MD5 for: AGP440.SYS  >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2007.05.17 21:34:04 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll
 
< MD5 for: IASTOR.SYS  >
[2009.10.13 10:09:36 | 000,331,288 | ---- | M] (Intel Corporation) MD5=0BAA4115DFFFD6A6D809A89D65E1281A -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2009.10.13 10:16:40 | 000,409,624 | ---- | M] (Intel Corporation) MD5=BE7D72FCF442C26975942007E0831241 -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2009.10.13 10:16:40 | 000,409,624 | ---- | M] (Intel Corporation) MD5=BE7D72FCF442C26975942007E0831241 -- C:\Windows\SysNative\drivers\iaStor.sys
[2009.10.13 10:16:40 | 000,409,624 | ---- | M] (Intel Corporation) MD5=BE7D72FCF442C26975942007E0831241 -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_6fca727099cdabf1\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 07:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 07:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.01.13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2009.07.14 02:15:21 | 000,462,848 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\FirewallAPI.dll

< End of report >


vivastern 21.02.2012 16:38

Hier noch die Extra-Log:

OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 21.02.2012 16:10:28 - Run 1
OTL by OldTimer - Version 3.2.33.1    Folder = C:\Users\Verena\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,87 Gb Total Physical Memory | 2,55 Gb Available Physical Memory | 65,86% Memory free
7,73 Gb Paging File | 6,08 Gb Available in Paging File | 78,70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452,56 Gb Total Space | 363,78 Gb Free Space | 80,38% Space Free | Partition Type: NTFS
Drive D: | 12,90 Gb Total Space | 2,15 Gb Free Space | 16,67% Space Free | Partition Type: NTFS
Drive E: | 99,02 Mb Total Space | 95,14 Mb Free Space | 96,08% Space Free | Partition Type: FAT32
 
Computer Name: VERENAS-PC | User Name: Verena | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FBBDC2C-0ED4-A201-7EA3-EE6A848F76D5}" = ccc-utility64
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{68201122-5B1D-70CF-6B4B-AB7732A782A5}" = ATI Catalyst Install Manager
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{C459FF28-B6DB-4C17-B54F-4175BF7F8D5B}" = AVG 2012
"{D050583D-5CEC-47B1-88AA-8B328CAA8621}" = AVG 2012
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F83779DF-E1F5-43A2-A7BE-732F856FADB7}" = Microsoft SQL Server Compact 3.5 SP1 x64 English
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"AVG" = AVG 2012
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"SynTPDeinstKey" = Synaptics Pointing Device Driver
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{0893F6E8-D9F5-6225-6C08-F05E509BB84A}" = CCC Help French
"{109F3C58-CC58-777F-B937-3347F0A6A5E5}" = CCC Help Danish
"{114B6A6A-3B55-7796-3250-AA3FC23743A9}" = CCC Help Czech
"{11D0053C-4160-6257-91F6-0EDBAD10B66B}" = CCC Help Spanish
"{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{24D188C8-4071-5F61-42AF-F45115DEC4AA}" = CCC Help Thai
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = CyberLink PowerCinema
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 30
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{32D95703-A0EC-C75C-1D49-542887F73B89}" = Catalyst Control Center Localization All
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons
"{3718C4EC-BF5C-79FF-87FF-C08E8D21E052}" = CCC Help Chinese Standard
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works
"{3A057951-7CF8-BB44-C823-3E6E8AF6BFB7}" = CCC Help Chinese Traditional
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3BD8D466-E5ED-AE3D-A089-BBDDA1EA2AB5}" = CCC Help Greek
"{3EFEF049-23D4-4B46-8903-4592FEA51018}" = Windows Live Movie Maker
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{49404BCA-BC5F-519A-9822-07F4C0711C75}" = Catalyst Control Center Graphics Previews Vista
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C6C8AA5-24BD-6AEA-1091-7056CEC7E7C0}" = Catalyst Control Center Graphics Light
"{4D3D893B-51CF-E89A-D536-0A658AE46140}" = CCC Help Swedish
"{4D5927FF-F3A0-4E03-9DE9-8265499164CF}" = HP User Guides
"{51119170-3D3F-B137-E735-AE9D315B5CF4}" = Catalyst Control Center Graphics Full Existing
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{68A0F54D-DB64-0ED9-C563-CE85C26CEE15}" = Catalyst Control Center Graphics Full New
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75053DEE-4BE5-3C4B-3FFC-3DA37ADE0347}" = CCC Help Hungarian
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync
"{77973724-A5B7-4A2A-CAB5-D6EEE02C06FC}" = CCC Help Korean
"{7A852BDE-016A-CDAC-1401-E99317CB956C}" = CCC Help Italian
"{8132E9B3-7B40-8577-9CFE-8CB2DD0F21B3}" = ccc-core-static
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84CE8562-9563-DEDA-FA31-F3BCF58B670B}" = CCC Help Polish
"{85E15059-42E9-4EAF-3CE9-17374870BA85}" = CCC Help German
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8D1E61D1-1395-4E97-997F-D002DB3A5074}" = OpenOffice.org 3.2
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0407-1000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{935BEAF7-6AAC-18BA-A8FF-8198602502DA}" = CCC Help Portuguese
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9AA66F70-CCBB-8E9E-0D8D-59E23EF770A4}" = Catalyst Control Center Core Implementation
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A8F4F0BB-0A1C-3A5A-97B8-F7150725C173}" = CCC Help Turkish
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.2) - Deutsch
"{AE6FD3D5-6302-815B-B27D-61A2D296BD94}" = CCC Help Finnish
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C93CFC00-267B-3564-273A-E2061DCF0DD1}" = CCC Help Norwegian
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{D668BFA1-12CA-0692-D3BA-15CED8E126D2}" = CCC Help English
"{D8DFA46A-39F7-4368-810D-18AFCFDDAEAF}" = Adobe Shockwave Player
"{E0897770-46C9-4322-AD44-8BFA6BE217B2}" = Catalyst Control Center - Branding
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E0E55FC1-C53D-4F8D-B14B-B59C312747C8}" = LightScribe System Software
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E5D5AC01-2095-566B-D92F-759DA0CB382B}" = Catalyst Control Center Graphics Previews Common
"{E888E5BE-1BF6-4B5C-967A-5336490E56C6}" = Mobipocket Reader 6.0
"{E8CF5CE7-02DC-042B-70B8-4A47F394663A}" = Catalyst Control Center InstallProxy
"{EF15B806-FF50-B61F-490D-29373E8C0623}" = CCC Help Japanese
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{F9A43C0C-F274-4EC0-B02E-202C15C09C00}" = HP Wireless Assistant
"{FAEE8E0C-4D05-7079-2E05-23BB831BBA73}" = CCC Help Dutch
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FDAB5C9C-76E1-E1D9-9CD6-9DAEFF8B9ECB}" = CCC Help Russian
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Audiograbber" = Audiograbber 1.83 SE
"DivX Setup" = DivX-Setup
"EasyBits Magic Desktop" = Magic Desktop
"ESET Online Scanner" = ESET Online Scanner v3
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = CyberLink PowerCinema
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.1.1000
"Mozilla Firefox 10.0.2 (x86 de)" = Mozilla Firefox 10.0.2 (x86 de)
"VLC media player" = VLC media player 1.0.1
"Vocup_is1" = Vocup 1.4.3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.01 (32-Bit)
"Wise Registry Cleaner_is1" = Wise Registry Cleaner 6.14
"Xvid Video Codec 1.3.2" = Xvid Video Codec
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 01.02.2012 21:40:30 | Computer Name = Verenas-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei
 "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile  8.  Die
im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente
 überein.  Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition:
 WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Verwenden Sie
 das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
Error - 03.02.2012 09:32:35 | Computer Name = Verenas-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 03.02.2012 11:23:57 | Computer Name = Verenas-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 03.02.2012 11:24:22 | Computer Name = Verenas-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei
 "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile  8.  Die
im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente
 überein.  Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition:
 WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Verwenden Sie
 das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
Error - 04.02.2012 11:36:37 | Computer Name = Verenas-PC | Source = MsiInstaller | ID = 11704
Description =
 
Error - 04.02.2012 11:48:04 | Computer Name = Verenas-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: MsiExec.exe, Version: 5.0.7601.17514,
 Zeitstempel: 0x4ce792c4  Name des fehlerhaften Moduls: QuickTime.qts_unloaded, Version:
 0.0.0.0, Zeitstempel: 0x4ba307c0  Ausnahmecode: 0xc0000005  Fehleroffset: 0x6443bb69
ID
 des fehlerhaften Prozesses: 0xe08  Startzeit der fehlerhaften Anwendung: 0x01cce35460981cdc
Pfad
 der fehlerhaften Anwendung: C:\Windows\syswow64\MsiExec.exe  Pfad des fehlerhaften
 Moduls: QuickTime.qts  Berichtskennung: 9fae78e6-4f47-11e1-861a-c80aa9757637
 
Error - 07.02.2012 12:52:24 | Computer Name = Verenas-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 07.02.2012 12:53:03 | Computer Name = Verenas-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei
 "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile  8.  Die
im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente
 überein.  Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition:
 WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Verwenden Sie
 das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
Error - 10.02.2012 21:59:24 | Computer Name = Verenas-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 10.02.2012 22:00:02 | Computer Name = Verenas-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei
 "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile  8.  Die
im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente
 überein.  Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition:
 WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Verwenden Sie
 das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
[ Hewlett-Packard Events ]
Error - 04.06.2011 18:21:12 | Computer Name = Verenas-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\061104122138.xml
 File not created by asset agent
 
Error - 04.06.2011 18:51:31 | Computer Name = Verenas-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\061105125126.xml
 File not created by asset agent
 
Error - 04.06.2011 18:51:34 | Computer Name = Verenas-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\061105125131.xml
 File not created by asset agent
 
Error - 08.07.2011 10:12:34 | Computer Name = Verenas-PC | Source = Hewlett-Packard | ID = 0
Description =
 
Error - 26.08.2011 12:14:14 | Computer Name = Verenas-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\081126061406.xml
 File not created by asset agent
 
Error - 21.09.2011 15:32:16 | Computer Name = Verenas-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\091121093208.xml
 File not created by asset agent
 
Error - 04.11.2011 19:04:48 | Computer Name = Verenas-PC | Source = HPSF.exe | ID = 4000
Description =
 
Error - 16.11.2011 04:22:11 | Computer Name = Verenas-PC | Source = HPSF.exe | ID = 4000
Description =
 
Error - 16.11.2011 05:15:42 | Computer Name = Verenas-PC | Source = HPSF.exe | ID = 4000
Description =
 
Error - 16.11.2011 05:15:52 | Computer Name = Verenas-PC | Source = HPSF.exe | ID = 4000
Description =
 
[ System Events ]
Error - 19.02.2012 20:11:01 | Computer Name = Verenas-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "HP Support Assistant Service" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%2
 
Error - 19.02.2012 20:16:03 | Computer Name = Verenas-PC | Source = Service Control Manager | ID = 7031
Description = Der Dienst "Superfetch" wurde unerwartet beendet. Dies ist bereits
 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt:
 Neustart des Diensts.
 
Error - 19.02.2012 20:23:54 | Computer Name = Verenas-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "HP Support Assistant Service" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%2
 
Error - 20.02.2012 06:56:20 | Computer Name = Verenas-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "HP Support Assistant Service" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%2
 
Error - 20.02.2012 10:32:57 | Computer Name = Verenas-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?20.?02.?2012 um 15:29:47 unerwartet heruntergefahren.
 
Error - 20.02.2012 10:33:06 | Computer Name = VERENAS-PC | Source = BugCheck | ID = 1001
Description =
 
Error - 20.02.2012 10:36:42 | Computer Name = Verenas-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "HP Support Assistant Service" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%2
 
Error - 20.02.2012 10:43:01 | Computer Name = Verenas-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?20.?02.?2012 um 15:41:20 unerwartet heruntergefahren.
 
Error - 20.02.2012 10:45:56 | Computer Name = Verenas-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "HP Support Assistant Service" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%2
 
Error - 21.02.2012 11:03:58 | Computer Name = Verenas-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "HP Support Assistant Service" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%2
 
 
< End of report >

--- --- ---

cosinus 21.02.2012 18:55

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
[2011.03.28 13:10:17 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2012.02.14 18:38:05 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2011.07.23 16:01:50 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.07.31 14:49:50 | 000,000,931 | ---- | M] () -- C:\Users\Verena\AppData\Roaming\Mozilla\Firefox\Profiles\lheuqom4.default\searchplugins\conduit.xml
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKU\S-1-5-21-2604564059-764910878-3552578447-1001\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKU\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKU\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
:Files
C:\Users\Verena\AppData\Roaming\50??
C:\Users\Verena\AppData\Roaming\xmldm
C:\Users\Verena\AppData\Roaming\kock
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

vivastern 21.02.2012 21:30

Code:

All processes killed
========== OTL ==========
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}\modules folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}\META-INF folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}\defaults\preferences folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}\defaults folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}\chrome folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250} folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\searchplugin folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\modules folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\META-INF folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\defaults folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}\chrome folder moved successfully.
C:\Users\Verena\AppData\Roaming\mozilla\Firefox\Profiles\lheuqom4.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} folder moved successfully.
C:\Users\Verena\AppData\Roaming\Mozilla\Firefox\Profiles\lheuqom4.default\searchplugins\conduit.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_USERS\S-1-5-21-2604564059-764910878-3552578447-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate deleted successfully.
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\WinampAgent deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideFastUserSwitching deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoLowDiskSpaceChecks deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableLockWorkstation deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2604564059-764910878-3552578447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableChangePassword deleted successfully.
========== FILES ==========
C:\Users\Verena\AppData\Roaming\5043\components folder moved successfully.
C:\Users\Verena\AppData\Roaming\5043 folder moved successfully.
C:\Users\Verena\AppData\Roaming\5044\components folder moved successfully.
C:\Users\Verena\AppData\Roaming\5044 folder moved successfully.
C:\Users\Verena\AppData\Roaming\5045\components folder moved successfully.
C:\Users\Verena\AppData\Roaming\5045 folder moved successfully.
C:\Users\Verena\AppData\Roaming\5047\components folder moved successfully.
C:\Users\Verena\AppData\Roaming\5047 folder moved successfully.
C:\Users\Verena\AppData\Roaming\5048\components folder moved successfully.
C:\Users\Verena\AppData\Roaming\5048 folder moved successfully.
C:\Users\Verena\AppData\Roaming\5049\components folder moved successfully.
C:\Users\Verena\AppData\Roaming\5049 folder moved successfully.
C:\Users\Verena\AppData\Roaming\5050\components folder moved successfully.
C:\Users\Verena\AppData\Roaming\5050 folder moved successfully.
C:\Users\Verena\AppData\Roaming\xmldm folder moved successfully.
C:\Users\Verena\AppData\Roaming\kock folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: Verena
->Temp folder emptied: 17747200100 bytes
->Temporary Internet Files folder emptied: 87600151 bytes
->Java cache emptied: 11388679 bytes
->FireFox cache emptied: 58849563 bytes
->Google Chrome cache emptied: 110837984 bytes
->Flash cache emptied: 4990 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 866188903 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 84962 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 749 bytes
RecycleBin emptied: 232695720 bytes
 
Total Files Cleaned = 18.229,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.33.1 log created on 02212012_211728

Files\Folders moved on Reboot...
C:\Users\Verena\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

Sind wir nun wieder komplett gesund ?

cosinus 21.02.2012 21:40

Zitat:

(Kaspersky Lab ZAO) -- C:\Users\Verena\Desktop\tdsskiller.exe
Was bitte hast du schon mit dem TDSS-Killer angestellt?! Log dazu?!

vivastern 21.02.2012 21:45

Oh ja... das war ein erster Versuch nach Selbstrecherche....

Code:

21:44:10.0985 3996        TDSS rootkit removing tool 2.7.12.0 Feb 11 2012 16:58:52
21:44:30.0844 3996        ============================================================
21:44:30.0844 3996        Current date / time: 2012/02/21 21:44:30.0844
21:44:30.0844 3996        SystemInfo:
21:44:30.0844 3996       
21:44:30.0844 3996        OS Version: 6.1.7601 ServicePack: 1.0
21:44:30.0844 3996        Product type: Workstation
21:44:30.0844 3996        ComputerName: VERENAS-PC
21:44:30.0844 3996        UserName: Verena
21:44:30.0844 3996        Windows directory: C:\Windows
21:44:30.0844 3996        System windows directory: C:\Windows
21:44:30.0844 3996        Running under WOW64
21:44:30.0844 3996        Processor architecture: Intel x64
21:44:30.0844 3996        Number of processors: 4
21:44:30.0844 3996        Page size: 0x1000
21:44:30.0844 3996        Boot type: Normal boot
21:44:30.0844 3996        ============================================================
21:44:31.0499 3996        Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:44:31.0499 3996        \Device\Harddisk0\DR0:
21:44:31.0499 3996        MBR used
21:44:31.0499 3996        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x63800
21:44:31.0499 3996        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x64000, BlocksNum 0x3891F800
21:44:31.0499 3996        \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x38983800, BlocksNum 0x19CE800
21:44:31.0499 3996        \Device\Harddisk0\DR0\Partition3: MBR, Type 0xC, StartLBA 0x3A352000, BlocksNum 0x33830
21:44:31.0577 3996        Initialize success
21:44:31.0577 3996        ============================================================


cosinus 21.02.2012 21:54

Das war wohl ein Satz mit X! :zunge:

Bitte richtig machen: Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehlalarm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

vivastern 21.02.2012 22:14

Code:

22:03:35.0423 4368        TDSS rootkit removing tool 2.7.13.0 Feb 15 2012 19:33:14
22:03:35.0633 4368        ============================================================
22:03:35.0633 4368        Current date / time: 2012/02/21 22:03:35.0633
22:03:35.0633 4368        SystemInfo:
22:03:35.0633 4368       
22:03:35.0633 4368        OS Version: 6.1.7601 ServicePack: 1.0
22:03:35.0633 4368        Product type: Workstation
22:03:35.0633 4368        ComputerName: VERENAS-PC
22:03:35.0633 4368        UserName: Verena
22:03:35.0633 4368        Windows directory: C:\Windows
22:03:35.0633 4368        System windows directory: C:\Windows
22:03:35.0633 4368        Running under WOW64
22:03:35.0633 4368        Processor architecture: Intel x64
22:03:35.0633 4368        Number of processors: 4
22:03:35.0633 4368        Page size: 0x1000
22:03:35.0633 4368        Boot type: Normal boot
22:03:35.0633 4368        ============================================================
22:03:36.0383 4368        Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:03:36.0383 4368        \Device\Harddisk0\DR0:
22:03:36.0393 4368        MBR used
22:03:36.0393 4368        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x63800
22:03:36.0393 4368        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x64000, BlocksNum 0x3891F800
22:03:36.0393 4368        \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x38983800, BlocksNum 0x19CE800
22:03:36.0393 4368        \Device\Harddisk0\DR0\Partition3: MBR, Type 0xC, StartLBA 0x3A352000, BlocksNum 0x33830
22:03:36.0473 4368        Initialize success
22:03:36.0473 4368        ============================================================
22:10:00.0503 3668        ============================================================
22:10:00.0503 3668        Scan started
22:10:00.0503 3668        Mode: Manual; SigCheck; TDLFS;
22:10:00.0503 3668        ============================================================
22:10:00.0768 3668        1394ohci        (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
22:10:00.0924 3668        1394ohci - ok
22:10:00.0955 3668        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
22:10:01.0018 3668        ACPI - ok
22:10:01.0033 3668        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
22:10:01.0111 3668        AcpiPmi - ok
22:10:01.0158 3668        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
22:10:01.0205 3668        adp94xx - ok
22:10:01.0298 3668        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
22:10:01.0345 3668        adpahci - ok
22:10:01.0376 3668        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
22:10:01.0423 3668        adpu320 - ok
22:10:01.0470 3668        AFD            (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
22:10:01.0548 3668        AFD - ok
22:10:01.0626 3668        AgereSoftModem  (98022774d9930ecbb292e70db7601df6) C:\Windows\system32\DRIVERS\agrsm64.sys
22:10:01.0735 3668        AgereSoftModem - ok
22:10:01.0782 3668        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
22:10:01.0813 3668        agp440 - ok
22:10:01.0844 3668        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
22:10:01.0876 3668        aliide - ok
22:10:01.0938 3668        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
22:10:01.0985 3668        amdide - ok
22:10:02.0016 3668        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
22:10:02.0063 3668        AmdK8 - ok
22:10:02.0094 3668        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
22:10:02.0156 3668        AmdPPM - ok
22:10:02.0188 3668        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
22:10:02.0234 3668        amdsata - ok
22:10:02.0266 3668        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
22:10:02.0312 3668        amdsbs - ok
22:10:02.0359 3668        amdxata        (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
22:10:02.0390 3668        amdxata - ok
22:10:02.0437 3668        AppID          (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
22:10:02.0562 3668        AppID - ok
22:10:02.0609 3668        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
22:10:02.0640 3668        arc - ok
22:10:02.0656 3668        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
22:10:02.0702 3668        arcsas - ok
22:10:02.0734 3668        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
22:10:02.0843 3668        AsyncMac - ok
22:10:02.0905 3668        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
22:10:02.0936 3668        atapi - ok
22:10:02.0999 3668        athr            (0acc06fcf46f64ed4f11e57ee461c1f4) C:\Windows\system32\DRIVERS\athrx.sys
22:10:03.0108 3668        athr - ok
22:10:03.0186 3668        AtiHdmiService  (d481083348138b4933acfe95812db71c) C:\Windows\system32\drivers\AtiHdmi.sys
22:10:03.0280 3668        AtiHdmiService - ok
22:10:03.0436 3668        atikmdag        (19b5c61cb09bff2bd69e063ee54b56c3) C:\Windows\system32\DRIVERS\atikmdag.sys
22:10:03.0685 3668        atikmdag - ok
22:10:03.0779 3668        AVGIDSDriver    (e29ea1a0ec7ab9fa2dc7e75a03f12a4f) C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys
22:10:03.0810 3668        AVGIDSDriver - ok
22:10:03.0841 3668        AVGIDSEH        (f823d184b8e8ffb8da3ead45dbf5bd6a) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys
22:10:03.0872 3668        AVGIDSEH - ok
22:10:03.0888 3668        AVGIDSFilter    (ed2b25bd7fe35d1944211968842d30da) C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys
22:10:03.0919 3668        AVGIDSFilter - ok
22:10:03.0950 3668        Avgldx64        (979cf8912449a10b987218bff80a1fa3) C:\Windows\system32\DRIVERS\avgldx64.sys
22:10:03.0997 3668        Avgldx64 - ok
22:10:04.0013 3668        Avgmfx64        (36b1a5843695766eac714daffc5b84d1) C:\Windows\system32\DRIVERS\avgmfx64.sys
22:10:04.0044 3668        Avgmfx64 - ok
22:10:04.0075 3668        Avgrkx64        (1102239fb724527f1febbbbccf6bf313) C:\Windows\system32\DRIVERS\avgrkx64.sys
22:10:04.0106 3668        Avgrkx64 - ok
22:10:04.0184 3668        Avgtdia        (11f36d3ea82d9db9aa05a476a210551b) C:\Windows\system32\DRIVERS\avgtdia.sys
22:10:04.0216 3668        Avgtdia - ok
22:10:04.0247 3668        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
22:10:04.0325 3668        b06bdrv - ok
22:10:04.0403 3668        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
22:10:04.0465 3668        b57nd60a - ok
22:10:04.0481 3668        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
22:10:04.0590 3668        Beep - ok
22:10:04.0621 3668        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
22:10:04.0668 3668        blbdrive - ok
22:10:04.0699 3668        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
22:10:04.0746 3668        bowser - ok
22:10:04.0777 3668        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:10:04.0824 3668        BrFiltLo - ok
22:10:04.0886 3668        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:10:04.0918 3668        BrFiltUp - ok
22:10:04.0949 3668        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
22:10:05.0011 3668        Brserid - ok
22:10:05.0042 3668        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
22:10:05.0089 3668        BrSerWdm - ok
22:10:05.0120 3668        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:10:05.0167 3668        BrUsbMdm - ok
22:10:05.0198 3668        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
22:10:05.0230 3668        BrUsbSer - ok
22:10:05.0292 3668        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
22:10:05.0339 3668        BTHMODEM - ok
22:10:05.0386 3668        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
22:10:05.0479 3668        cdfs - ok
22:10:05.0526 3668        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
22:10:05.0573 3668        cdrom - ok
22:10:05.0620 3668        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
22:10:05.0682 3668        circlass - ok
22:10:05.0744 3668        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
22:10:05.0776 3668        CLFS - ok
22:10:05.0822 3668        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
22:10:05.0869 3668        CmBatt - ok
22:10:05.0885 3668        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
22:10:05.0900 3668        cmdide - ok
22:10:05.0963 3668        CNG            (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
22:10:06.0010 3668        CNG - ok
22:10:06.0072 3668        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
22:10:06.0103 3668        Compbatt - ok
22:10:06.0166 3668        CompositeBus    (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
22:10:06.0228 3668        CompositeBus - ok
22:10:06.0259 3668        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
22:10:06.0290 3668        crcdisk - ok
22:10:06.0337 3668        DfsC            (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
22:10:06.0446 3668        DfsC - ok
22:10:06.0462 3668        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
22:10:06.0556 3668        discache - ok
22:10:06.0602 3668        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
22:10:06.0618 3668        Disk - ok
22:10:06.0665 3668        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
22:10:06.0712 3668        drmkaud - ok
22:10:06.0758 3668        DXGKrnl        (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
22:10:06.0821 3668        DXGKrnl - ok
22:10:06.0930 3668        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
22:10:07.0055 3668        ebdrv - ok
22:10:07.0133 3668        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
22:10:07.0164 3668        elxstor - ok
22:10:07.0195 3668        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
22:10:07.0242 3668        ErrDev - ok
22:10:07.0289 3668        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
22:10:07.0398 3668        exfat - ok
22:10:07.0445 3668        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
22:10:07.0554 3668        fastfat - ok
22:10:07.0585 3668        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
22:10:07.0632 3668        fdc - ok
22:10:07.0679 3668        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
22:10:07.0710 3668        FileInfo - ok
22:10:07.0726 3668        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
22:10:07.0835 3668        Filetrace - ok
22:10:07.0882 3668        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
22:10:07.0913 3668        flpydisk - ok
22:10:07.0960 3668        FltMgr          (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
22:10:07.0991 3668        FltMgr - ok
22:10:08.0038 3668        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
22:10:08.0069 3668        FsDepends - ok
22:10:08.0084 3668        Fs_Rec          (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
22:10:08.0116 3668        Fs_Rec - ok
22:10:08.0147 3668        fvevol          (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
22:10:08.0178 3668        fvevol - ok
22:10:08.0209 3668        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:10:08.0240 3668        gagp30kx - ok
22:10:08.0272 3668        GEARAspiWDM    (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
22:10:08.0287 3668        GEARAspiWDM - ok
22:10:08.0318 3668        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
22:10:08.0381 3668        hcw85cir - ok
22:10:08.0443 3668        HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
22:10:08.0490 3668        HdAudAddService - ok
22:10:08.0506 3668        HDAudBus        (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
22:10:08.0552 3668        HDAudBus - ok
22:10:08.0615 3668        HECIx64        (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
22:10:08.0630 3668        HECIx64 - ok
22:10:08.0646 3668        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
22:10:08.0693 3668        HidBatt - ok
22:10:08.0724 3668        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
22:10:08.0771 3668        HidBth - ok
22:10:08.0802 3668        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
22:10:08.0849 3668        HidIr - ok
22:10:08.0880 3668        HidUsb          (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
22:10:08.0927 3668        HidUsb - ok
22:10:08.0989 3668        HpqKbFiltr      (9af482d058be59cc28bce52e7c4b747c) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
22:10:09.0020 3668        HpqKbFiltr - ok
22:10:09.0083 3668        HpSAMD          (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
22:10:09.0098 3668        HpSAMD - ok
22:10:09.0161 3668        HTTP            (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
22:10:09.0286 3668        HTTP - ok
22:10:09.0364 3668        hwpolicy        (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
22:10:09.0379 3668        hwpolicy - ok
22:10:09.0410 3668        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
22:10:09.0442 3668        i8042prt - ok
22:10:09.0488 3668        iaStor          (be7d72fcf442c26975942007e0831241) C:\Windows\system32\DRIVERS\iaStor.sys
22:10:09.0520 3668        iaStor - ok
22:10:09.0566 3668        iaStorV        (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
22:10:09.0598 3668        iaStorV - ok
22:10:09.0754 3668        igfx            (a87261ef1546325b559374f5689cf5bc) C:\Windows\system32\DRIVERS\igdkmd64.sys
22:10:09.0972 3668        igfx - ok
22:10:10.0050 3668        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
22:10:10.0066 3668        iirsp - ok
22:10:10.0128 3668        IntcAzAudAddService (181e4ff75674a7105ecd0a02c35ef43a) C:\Windows\system32\drivers\RTKVHD64.sys
22:10:10.0237 3668        IntcAzAudAddService - ok
22:10:10.0284 3668        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
22:10:10.0300 3668        intelide - ok
22:10:10.0315 3668        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
22:10:10.0362 3668        intelppm - ok
22:10:10.0440 3668        IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:10:10.0549 3668        IpFilterDriver - ok
22:10:10.0580 3668        IPMIDRV        (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
22:10:10.0612 3668        IPMIDRV - ok
22:10:10.0643 3668        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
22:10:10.0752 3668        IPNAT - ok
22:10:10.0768 3668        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
22:10:10.0814 3668        IRENUM - ok
22:10:10.0877 3668        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
22:10:10.0892 3668        isapnp - ok
22:10:10.0939 3668        iScsiPrt        (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
22:10:10.0970 3668        iScsiPrt - ok
22:10:10.0986 3668        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
22:10:11.0002 3668        kbdclass - ok
22:10:11.0033 3668        kbdhid          (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
22:10:11.0048 3668        kbdhid - ok
22:10:11.0095 3668        kl1            (db449f50e5141458eb58e64ffac4863f) C:\Windows\system32\DRIVERS\kl1.sys
22:10:11.0126 3668        kl1 - ok
22:10:11.0158 3668        KSecDD          (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
22:10:11.0189 3668        KSecDD - ok
22:10:11.0204 3668        KSecPkg        (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
22:10:11.0220 3668        KSecPkg - ok
22:10:11.0298 3668        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
22:10:11.0392 3668        ksthunk - ok
22:10:11.0423 3668        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
22:10:11.0516 3668        lltdio - ok
22:10:11.0563 3668        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:10:11.0594 3668        LSI_FC - ok
22:10:11.0641 3668        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:10:11.0657 3668        LSI_SAS - ok
22:10:11.0688 3668        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:10:11.0719 3668        LSI_SAS2 - ok
22:10:11.0750 3668        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:10:11.0766 3668        LSI_SCSI - ok
22:10:11.0828 3668        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
22:10:11.0938 3668        luafv - ok
22:10:11.0984 3668        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
22:10:12.0000 3668        megasas - ok
22:10:12.0031 3668        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
22:10:12.0062 3668        MegaSR - ok
22:10:12.0094 3668        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
22:10:12.0203 3668        Modem - ok
22:10:12.0234 3668        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
22:10:12.0281 3668        monitor - ok
22:10:12.0343 3668        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
22:10:12.0359 3668        mouclass - ok
22:10:12.0374 3668        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
22:10:12.0421 3668        mouhid - ok
22:10:12.0452 3668        mountmgr        (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
22:10:12.0484 3668        mountmgr - ok
22:10:12.0530 3668        mpio            (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
22:10:12.0562 3668        mpio - ok
22:10:12.0593 3668        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
22:10:12.0702 3668        mpsdrv - ok
22:10:12.0780 3668        MRxDAV          (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
22:10:12.0874 3668        MRxDAV - ok
22:10:12.0920 3668        mrxsmb          (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:10:12.0967 3668        mrxsmb - ok
22:10:13.0045 3668        mrxsmb10        (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:10:13.0092 3668        mrxsmb10 - ok
22:10:13.0123 3668        mrxsmb20        (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:10:13.0154 3668        mrxsmb20 - ok
22:10:13.0186 3668        msahci          (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
22:10:13.0201 3668        msahci - ok
22:10:13.0248 3668        msdsm          (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
22:10:13.0279 3668        msdsm - ok
22:10:13.0326 3668        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
22:10:13.0420 3668        Msfs - ok
22:10:13.0435 3668        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
22:10:13.0529 3668        mshidkmdf - ok
22:10:13.0607 3668        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
22:10:13.0622 3668        msisadrv - ok
22:10:13.0654 3668        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
22:10:13.0747 3668        MSKSSRV - ok
22:10:13.0778 3668        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
22:10:13.0888 3668        MSPCLOCK - ok
22:10:13.0934 3668        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
22:10:14.0044 3668        MSPQM - ok
22:10:14.0075 3668        MsRPC          (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
22:10:14.0122 3668        MsRPC - ok
22:10:14.0184 3668        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
22:10:14.0215 3668        mssmbios - ok
22:10:14.0231 3668        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
22:10:14.0324 3668        MSTEE - ok
22:10:14.0356 3668        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
22:10:14.0402 3668        MTConfig - ok
22:10:14.0449 3668        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
22:10:14.0465 3668        Mup - ok
22:10:14.0496 3668        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
22:10:14.0558 3668        NativeWifiP - ok
22:10:14.0652 3668        NDIS            (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
22:10:14.0714 3668        NDIS - ok
22:10:14.0730 3668        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
22:10:14.0824 3668        NdisCap - ok
22:10:14.0870 3668        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
22:10:14.0964 3668        NdisTapi - ok
22:10:14.0995 3668        Ndisuio        (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
22:10:15.0104 3668        Ndisuio - ok
22:10:15.0167 3668        NdisWan        (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
22:10:15.0260 3668        NdisWan - ok
22:10:15.0323 3668        NDProxy        (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
22:10:15.0416 3668        NDProxy - ok
22:10:15.0463 3668        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
22:10:15.0572 3668        NetBIOS - ok
22:10:15.0604 3668        NetBT          (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
22:10:15.0713 3668        NetBT - ok
22:10:15.0900 3668        netw5v64        (64428dfdaf6e88366cb51f45a79c5f69) C:\Windows\system32\DRIVERS\netw5v64.sys
22:10:16.0103 3668        netw5v64 - ok
22:10:16.0181 3668        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
22:10:16.0196 3668        nfrd960 - ok
22:10:16.0228 3668        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
22:10:16.0337 3668        Npfs - ok
22:10:16.0368 3668        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
22:10:16.0462 3668        nsiproxy - ok
22:10:16.0524 3668        Ntfs            (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
22:10:16.0618 3668        Ntfs - ok
22:10:16.0680 3668        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
22:10:16.0789 3668        Null - ok
22:10:16.0836 3668        nvraid          (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
22:10:16.0867 3668        nvraid - ok
22:10:16.0883 3668        nvstor          (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
22:10:16.0898 3668        nvstor - ok
22:10:16.0930 3668        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
22:10:16.0945 3668        nv_agp - ok
22:10:16.0976 3668        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
22:10:17.0023 3668        ohci1394 - ok
22:10:17.0054 3668        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
22:10:17.0086 3668        Parport - ok
22:10:17.0148 3668        partmgr        (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
22:10:17.0179 3668        partmgr - ok
22:10:17.0226 3668        pci            (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
22:10:17.0257 3668        pci - ok
22:10:17.0273 3668        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
22:10:17.0288 3668        pciide - ok
22:10:17.0320 3668        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
22:10:17.0351 3668        pcmcia - ok
22:10:17.0382 3668        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
22:10:17.0398 3668        pcw - ok
22:10:17.0429 3668        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
22:10:17.0554 3668        PEAUTH - ok
22:10:17.0725 3668        PptpMiniport    (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
22:10:17.0819 3668        PptpMiniport - ok
22:10:17.0866 3668        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
22:10:17.0897 3668        Processor - ok
22:10:17.0944 3668        Psched          (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
22:10:18.0053 3668        Psched - ok
22:10:18.0146 3668        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
22:10:18.0224 3668        ql2300 - ok
22:10:18.0271 3668        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
22:10:18.0287 3668        ql40xx - ok
22:10:18.0334 3668        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
22:10:18.0380 3668        QWAVEdrv - ok
22:10:18.0427 3668        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
22:10:18.0521 3668        RasAcd - ok
22:10:18.0552 3668        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:10:18.0646 3668        RasAgileVpn - ok
22:10:18.0677 3668        Rasl2tp        (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:10:18.0786 3668        Rasl2tp - ok
22:10:18.0833 3668        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
22:10:18.0926 3668        RasPppoe - ok
22:10:18.0942 3668        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
22:10:19.0036 3668        RasSstp - ok
22:10:19.0067 3668        rdbss          (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
22:10:19.0160 3668        rdbss - ok
22:10:19.0223 3668        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
22:10:19.0254 3668        rdpbus - ok
22:10:19.0285 3668        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:10:19.0394 3668        RDPCDD - ok
22:10:19.0426 3668        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
22:10:19.0519 3668        RDPENCDD - ok
22:10:19.0566 3668        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
22:10:19.0660 3668        RDPREFMP - ok
22:10:19.0691 3668        RDPWD          (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
22:10:19.0800 3668        RDPWD - ok
22:10:19.0862 3668        rdyboost        (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
22:10:19.0894 3668        rdyboost - ok
22:10:19.0972 3668        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
22:10:20.0065 3668        rspndr - ok
22:10:20.0096 3668        RSUSBSTOR      (483df0b58ca532e5240e59dc41f30aa2) C:\Windows\system32\Drivers\RtsUStor.sys
22:10:20.0143 3668        RSUSBSTOR - ok
22:10:20.0190 3668        RTL8167        (ee082e06a82ff630351d1e0ebbd3d8d0) C:\Windows\system32\DRIVERS\Rt64win7.sys
22:10:20.0221 3668        RTL8167 - ok
22:10:20.0284 3668        sbp2port        (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
22:10:20.0299 3668        sbp2port - ok
22:10:20.0362 3668        SBRE            (7e07d2a5b910c71d6474e9aa0eaa1825) C:\Windows\system32\drivers\SBREdrv.sys
22:10:20.0377 3668        SBRE - ok
22:10:20.0408 3668        scfilter        (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
22:10:20.0518 3668        scfilter - ok
22:10:20.0549 3668        sdbus          (111e0ebc0ad79cb0fa014b907b231cf0) C:\Windows\system32\drivers\sdbus.sys
22:10:20.0596 3668        sdbus - ok
22:10:20.0642 3668        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
22:10:20.0736 3668        secdrv - ok
22:10:20.0798 3668        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
22:10:20.0814 3668        Serenum - ok
22:10:20.0861 3668        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
22:10:20.0892 3668        Serial - ok
22:10:20.0939 3668        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
22:10:20.0970 3668        sermouse - ok
22:10:21.0017 3668        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
22:10:21.0064 3668        sffdisk - ok
22:10:21.0095 3668        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
22:10:21.0126 3668        sffp_mmc - ok
22:10:21.0157 3668        sffp_sd        (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
22:10:21.0220 3668        sffp_sd - ok
22:10:21.0266 3668        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
22:10:21.0298 3668        sfloppy - ok
22:10:21.0360 3668        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:10:21.0376 3668        SiSRaid2 - ok
22:10:21.0391 3668        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
22:10:21.0407 3668        SiSRaid4 - ok
22:10:21.0438 3668        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
22:10:21.0547 3668        Smb - ok
22:10:21.0610 3668        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
22:10:21.0625 3668        spldr - ok
22:10:21.0688 3668        srv            (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
22:10:21.0750 3668        srv - ok
22:10:21.0797 3668        srv2            (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
22:10:21.0844 3668        srv2 - ok
22:10:21.0906 3668        SrvHsfHDA      (0c4540311e11664b245a263e1154cef8) C:\Windows\system32\DRIVERS\VSTAZL6.SYS
22:10:21.0968 3668        SrvHsfHDA - ok
22:10:22.0015 3668        SrvHsfV92      (02071d207a9858fbe3a48cbfd59c4a04) C:\Windows\system32\DRIVERS\VSTDPV6.SYS
22:10:22.0093 3668        SrvHsfV92 - ok
22:10:22.0187 3668        SrvHsfWinac    (18e40c245dbfaf36fd0134a7ef2df396) C:\Windows\system32\DRIVERS\VSTCNXT6.SYS
22:10:22.0234 3668        SrvHsfWinac - ok
22:10:22.0265 3668        srvnet          (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
22:10:22.0312 3668        srvnet - ok
22:10:22.0358 3668        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
22:10:22.0374 3668        stexstor - ok
22:10:22.0421 3668        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
22:10:22.0436 3668        swenum - ok
22:10:22.0514 3668        SynTP          (3a706a967295e16511e40842b1a2761d) C:\Windows\system32\DRIVERS\SynTP.sys
22:10:22.0546 3668        SynTP - ok
22:10:22.0639 3668        Tcpip          (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
22:10:22.0733 3668        Tcpip - ok
22:10:22.0780 3668        TCPIP6          (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
22:10:22.0858 3668        TCPIP6 - ok
22:10:22.0889 3668        tcpipreg        (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
22:10:22.0982 3668        tcpipreg - ok
22:10:23.0060 3668        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
22:10:23.0154 3668        TDPIPE - ok
22:10:23.0170 3668        TDTCP          (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
22:10:23.0279 3668        TDTCP - ok
22:10:23.0310 3668        tdx            (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
22:10:23.0404 3668        tdx - ok
22:10:23.0435 3668        TermDD          (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
22:10:23.0466 3668        TermDD - ok
22:10:23.0528 3668        tssecsrv        (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:10:23.0606 3668        tssecsrv - ok
22:10:23.0653 3668        TsUsbFlt        (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
22:10:23.0700 3668        TsUsbFlt - ok
22:10:23.0778 3668        tunnel          (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
22:10:23.0872 3668        tunnel - ok
22:10:23.0903 3668        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
22:10:23.0934 3668        uagp35 - ok
22:10:23.0981 3668        udfs            (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
22:10:24.0090 3668        udfs - ok
22:10:24.0137 3668        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
22:10:24.0152 3668        uliagpkx - ok
22:10:24.0199 3668        umbus          (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
22:10:24.0246 3668        umbus - ok
22:10:24.0324 3668        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
22:10:24.0371 3668        UmPass - ok
22:10:24.0402 3668        USBAAPL64      (cd03479f2da26500b203ed075c146a7a) C:\Windows\system32\Drivers\usbaapl64.sys
22:10:24.0402 3668        USBAAPL64 ( UnsignedFile.Multi.Generic ) - warning
22:10:24.0402 3668        USBAAPL64 - detected UnsignedFile.Multi.Generic (1)
22:10:24.0433 3668        usbccgp        (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
22:10:24.0480 3668        usbccgp - ok
22:10:24.0527 3668        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
22:10:24.0574 3668        usbcir - ok
22:10:24.0636 3668        usbehci        (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
22:10:24.0683 3668        usbehci - ok
22:10:24.0714 3668        usbhub          (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
22:10:24.0761 3668        usbhub - ok
22:10:24.0792 3668        usbohci        (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
22:10:24.0839 3668        usbohci - ok
22:10:24.0870 3668        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
22:10:24.0901 3668        usbprint - ok
22:10:24.0917 3668        USBSTOR        (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:10:24.0979 3668        USBSTOR - ok
22:10:25.0010 3668        usbuhci        (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
22:10:25.0042 3668        usbuhci - ok
22:10:25.0120 3668        usbvideo        (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
22:10:25.0151 3668        usbvideo - ok
22:10:25.0182 3668        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
22:10:25.0198 3668        vdrvroot - ok
22:10:25.0244 3668        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
22:10:25.0276 3668        vga - ok
22:10:25.0307 3668        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
22:10:25.0400 3668        VgaSave - ok
22:10:25.0432 3668        vhdmp          (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
22:10:25.0463 3668        vhdmp - ok
22:10:25.0494 3668        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
22:10:25.0510 3668        viaide - ok
22:10:25.0525 3668        volmgr          (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
22:10:25.0541 3668        volmgr - ok
22:10:25.0588 3668        volmgrx        (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
22:10:25.0619 3668        volmgrx - ok
22:10:25.0697 3668        volsnap        (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
22:10:25.0728 3668        volsnap - ok
22:10:25.0759 3668        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
22:10:25.0790 3668        vsmraid - ok
22:10:25.0837 3668        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
22:10:25.0884 3668        vwifibus - ok
22:10:25.0915 3668        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
22:10:25.0978 3668        vwififlt - ok
22:10:26.0009 3668        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
22:10:26.0040 3668        vwifimp - ok
22:10:26.0118 3668        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
22:10:26.0149 3668        WacomPen - ok
22:10:26.0196 3668        WANARP          (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
22:10:26.0290 3668        WANARP - ok
22:10:26.0305 3668        Wanarpv6        (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
22:10:26.0383 3668        Wanarpv6 - ok
22:10:26.0414 3668        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
22:10:26.0446 3668        Wd - ok
22:10:26.0477 3668        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
22:10:26.0524 3668        Wdf01000 - ok
22:10:26.0586 3668        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
22:10:26.0680 3668        WfpLwf - ok
22:10:26.0695 3668        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
22:10:26.0711 3668        WIMMount - ok
22:10:26.0773 3668        WinUsb          (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
22:10:26.0820 3668        WinUsb - ok
22:10:26.0867 3668        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
22:10:26.0914 3668        WmiAcpi - ok
22:10:26.0945 3668        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
22:10:27.0038 3668        ws2ifsl - ok
22:10:27.0148 3668        WudfPf          (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
22:10:27.0226 3668        WudfPf - ok
22:10:27.0257 3668        WUDFRd          (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:10:27.0366 3668        WUDFRd - ok
22:10:27.0397 3668        yukonw7        (b3eeacf62445e24fbb2cd4b0fb4db026) C:\Windows\system32\DRIVERS\yk62x64.sys
22:10:27.0460 3668        yukonw7 - ok
22:10:27.0491 3668        MBR (0x1B8)    (8f84284b2c573e8e1ee0154eacdd9701) \Device\Harddisk0\DR0
22:10:27.0569 3668        \Device\Harddisk0\DR0 - ok
22:10:27.0600 3668        Boot (0x1200)  (f190c2bfc5ca3e250c672d8bfbe22fe4) \Device\Harddisk0\DR0\Partition0
22:10:27.0600 3668        \Device\Harddisk0\DR0\Partition0 - ok
22:10:27.0616 3668        Boot (0x1200)  (410374bc44f434db1c134a8f959aaea6) \Device\Harddisk0\DR0\Partition1
22:10:27.0616 3668        \Device\Harddisk0\DR0\Partition1 - ok
22:10:27.0631 3668        Boot (0x1200)  (8c8b5b4d378d61089f55fad0b8e74c91) \Device\Harddisk0\DR0\Partition2
22:10:27.0631 3668        \Device\Harddisk0\DR0\Partition2 - ok
22:10:27.0662 3668        Boot (0x1200)  (0ddba10283d57d84270920fcde989bd6) \Device\Harddisk0\DR0\Partition3
22:10:27.0662 3668        \Device\Harddisk0\DR0\Partition3 - ok
22:10:27.0662 3668        ============================================================
22:10:27.0662 3668        Scan finished
22:10:27.0662 3668        ============================================================
22:10:27.0678 4284        Detected object count: 1
22:10:27.0678 4284        Actual detected object count: 1
22:11:57.0659 4284        USBAAPL64 ( UnsignedFile.Multi.Generic ) - skipped by user
22:11:57.0659 4284        USBAAPL64 ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 22.02.2012 11:34

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

vivastern 22.02.2012 13:30

Zitat:

Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter
Lieber Arne, wie schon zweimal von mir gefragt:

?Wie deaktiviere ich den AVG richtig? Denn ich scheine es nur zu schaffen, die Benutzeroberfläche zu beenden und ComboFix hat nochmal extra gewarnt, dass AVG aktiv ist. Bitte gib mir doch nen Tipp. Danke!

cosinus 22.02.2012 15:12

Das Nutzen einer Suchmaschine ist nicht verboten! => AVG - Temporäres Deaktivieren von AVG | Häufig gestellte Fragen

vivastern 22.02.2012 16:40

Er scheint durch zu sein. Nur zeigt er seit mind. 30 Minuten an:
Zitat:

Fast fertig..dieses Fenster wird sich in Kürze schließen. Bitte warte ein paar Sekunden, damit das log geöffnet werden kann.
Das mit den Anwendungen und der Fehlermeldung ist eingetroffen. Soll ich also nun lieber warten oder neu starten?

vivastern 22.02.2012 17:57

Danke!
Habs geschafft...
Code:

ComboFix 12-02-22.01 - Verena 22.02.2012  15:19:28.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3958.2596 [GMT 1:00]
ausgeführt von:: C:\Users\Verena\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))


C:\Install.exe
C:\Users\Verena\AppData\Roaming\AcroIEHelpe.txt
C:\Users\Verena\AppData\Roaming\srvblck2.tmp


(((((((((((((((((((((((  Dateien erstellt von 2012-01-22 bis 2012-02-22  ))))))))))))))))))))))))))))))


2012-02-22 14:31:13 . 2012-02-22 14:31:13        --------        d-----w-        C:\Users\Default\AppData\Local\temp
2012-02-21 20:17:28 . 2012-02-21 20:17:28        --------        d-----w-        C:\_OTL
2012-02-20 14:00:37 . 2012-02-20 14:00:37        --------        d-----w-        C:\Program Files (x86)\ESET
2012-02-18 13:15:30 . 2012-02-18 13:15:30        --------        d-----w-        C:\$AVG
2012-02-17 17:37:25 . 2012-02-17 17:37:25        --------        d-----w-        C:\Users\Verena\AppData\Roaming\AVG2012
2012-02-17 17:36:30 . 2012-02-17 17:36:36        --------        d-----w-        C:\ProgramData\AVG Secure Search
2012-02-17 17:36:30 . 2012-02-17 17:36:30        --------        d-----w-        C:\Program Files (x86)\Common Files\AVG Secure Search
2012-02-17 17:36:29 . 2012-02-17 17:36:35        --------        d-----w-        C:\Program Files (x86)\AVG Secure Search
2012-02-17 17:35:56 . 2012-02-22 09:58:49        --------        d-----w-        C:\Windows\system32\drivers\AVG
2012-02-17 17:35:56 . 2012-02-17 17:38:00        --------        d-----w-        C:\ProgramData\AVG2012
2012-02-17 17:34:08 . 2012-02-22 09:58:54        --------        d-----w-        C:\ProgramData\MFAData
2012-02-17 17:13:47 . 2012-01-17 03:39:42        8602168        ----a-w-        C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FD8C83BD-DC18-48B5-843B-C42DBBAFD1E7}\mpengine.dll
2012-02-17 11:45:15 . 2012-02-17 11:45:15        --------        d-----w-        C:\Users\Verena\AppData\Roaming\Malwarebytes
2012-02-17 11:44:57 . 2012-02-17 11:44:57        --------        d-----w-        C:\ProgramData\Malwarebytes
2012-02-17 11:44:56 . 2012-02-17 11:45:00        --------        d-----w-        C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-02-17 11:44:56 . 2011-12-10 14:24:08        23152        ----a-w-        C:\Windows\system32\drivers\mbam.sys
2012-02-16 09:16:54 . 2011-12-28 03:59:24        498688        ----a-w-        C:\Windows\system32\drivers\afd.sys
2012-02-16 09:16:54 . 2011-12-16 08:46:06        634880        ----a-w-        C:\Windows\system32\msvcrt.dll
2012-02-16 09:16:53 . 2011-12-16 07:52:58        690688        ----a-w-        C:\Windows\SysWow64\msvcrt.dll
2012-02-16 09:15:02 . 2012-01-14 04:06:27        3145728        ----a-w-        C:\Windows\system32\win32k.sys
2012-02-01 12:24:39 . 2012-02-01 12:24:39        --------        d-----w-        C:\Program Files (x86)\Audiograbber
.


((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))

2012-01-29 04:10:42 . 2010-07-01 12:03:58        279656        ------w-        C:\Windows\system32\MpSigStub.exe
2012-01-10 22:21:10 . 2011-05-13 07:53:17        414368        ----a-w-        C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-01-04 00:48:42 . 2012-01-04 00:48:42        354176        ----a-w-        C:\Windows\SysWow64\DivXControlPanelApplet.cpl
2011-11-30 12:50:41 . 2009-07-14 02:36:51        175616        ----a-w-        C:\Windows\system32\msclmd.dll
2011-11-30 12:50:41 . 2009-07-14 02:36:51        152576        ----a-w-        C:\Windows\SysWow64\msclmd.dll


((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))


*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4

[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-02-17 17:36:29        1811296        ----a-w-        C:\Program Files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "C:\Program Files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll" [2012-02-17 17:36:29 1811296]

[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20        94208        ----a-w-        C:\Users\Verena\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20        94208        ----a-w-        C:\Users\Verena\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20        94208        ----a-w-        C:\Users\Verena\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2011-03-04 10:45:28 2741616]
"HPADVISOR"="C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-09-29 14:26:44 1685048]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-11-24 19:24:38 98304]
"Easybits Recovery"="C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe" [2009-09-02 10:00:00 60464]
"QlbCtrl.exe"="C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 13:19:48 323640]
"WirelessAssistant"="C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2010-05-20 07:04:24 500792]
"PCMAgent"="C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe" [2009-09-16 09:34:02 148776]
"CLMLServer"="C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe" [2009-09-16 09:34:20 202024]
"PlayMovie"="C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe" [2009-09-08 16:07:24 177384]
"TVEService"="C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe" [2009-09-29 15:56:04 226536]
"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 07:37:53 843712]
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 12:06:06 254696]
"HP Software Update"="C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-05-10 01:41:12 49208]
"AVG_TRAY"="C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" [2012-01-24 16:24:26 2416480]
"vProt"="C:\Program Files (x86)\AVG Secure Search\vprot.exe" [2012-02-17 17:36:30 939872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start hxxp://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYAMgBHADMASwAtADgANwBXAFUAVQAtADIAVABWAEgAQQAtAFgANgBEAEYAOAAtAEwANgBQAEEATgA&inst=NwA3AC0AMwA1ADgAOQA1ADgAMAAzADkALQBGAEwAKwA5AC0ARgA5AE0ANgArADEALQBYAE8AMwA2ACsAMQAtAEYAOQBNADcAQwArADUALQBYAE8AOQArADEALQBGADkATQAzACsAMQAtAEQARABUACsAMgA4ADEANgA1AC0ARABEADkAMABGACsAMQAtAFMAVAA5ADAARgBBAFAAUAArADEALQBGAFUASQArADIA&prod=90&ver=9.0.894" [?]

C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - C:\Users\Verena\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-1-18 24246216]
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute        REG_MULTI_SZ          autocheck autochk *\0C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 11:16:28 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 12:27:14 138576]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-02-25 13:21:32 227896]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys [2009-09-23 01:39:00 225280]
R3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys [x]
S0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys [x]
S1 SBRE;SBRE;C:\Windows\system32\drivers\SBREdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 13:10:42 63928]
S2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 02:14:26 98208]
S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe [x]
S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 05:25:22 4433248]
S2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-02 05:09:08 192776]
S2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\system32\svchost.exe [2009-07-14 01:39:46 27136]
S2 TVECapSvc;TVEnhance Background Capture Service (TBCS);C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe [2009-09-29 15:56:26 464224]
S2 TVESched;TVEnhance Task Scheduler (TTS));C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe [2009-09-29 15:56:26 189792]
S2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 04:01:32 2320920]
S2 vToolbarUpdater;vToolbarUpdater;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe [2012-02-17 17:36:30 909152]
S3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
S3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys [x]


--- Andere Dienste/Treiber im Speicher ---

*NewlyCreated* - WS2IFSL

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
ezSharedSvc

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-03-04 10:29:54        451872        ----a-w-        C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe

Inhalt des "geplante Tasks" Ordners

2012-02-18 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2604564059-764910878-3552578447-1001Core.job
- C:\Users\Verena\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-09 09:28:35 . 2010-09-09 09:28:32]

2012-02-22 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2604564059-764910878-3552578447-1001UA.job
- C:\Users\Verena\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-09 09:28:35 . 2010-09-09 09:28:32]

2012-02-17 C:\Windows\Tasks\HPCeeScheduleForVerena.job
- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-07 03:22:28 . 2009-10-07 03:22:28]


--------- x86-64 -----------


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20        97792        ----a-w-        C:\Users\Verena\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20        97792        ----a-w-        C:\Users\Verena\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20        97792        ----a-w-        C:\Users\Verena\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" [2009-12-22 19:32:18 5977600]
"RtkOSD"="C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe" [2009-10-13 18:33:00 995840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1

------- Zusätzlicher Suchlauf -------

uLocal Page = C:\Windows\system32\blank.htm
mLocal Page = C:\Windows\SysWOW64\blank.htm
IE: Free YouTube to Mp3 Converter - C:\Users\Verena\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll
FF - ProfilePath - C:\Users\Verena\AppData\Roaming\Mozilla\Firefox\Profiles\lheuqom4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B9403eeb4-0520-49ea-b0c1-62b1eb9e3793%7D&mid=5b0d75e38c0da276cb56abf84b374079-831f635ca31915cbf27df9f3e079de75575703db&ds=AVG&v=10.0.0.7&lang=de&pr=fr&d=2012-02-17%2018%3A36%3A31&sap=ku&q=

- - - - Entfernte verwaiste Registrierungseinträge - - - -

HKLM-Run-SynTPEnh - C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-EasyBits Magic Desktop - C:\Windows\system32\ezMDUninstall.exe


cosinus 22.02.2012 19:51

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehlalarm!
  • Starte die aswMBR.exe Vista und Win7 User aswMBR per Rechtsklick "als Administrator ausführen"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

vivastern 23.02.2012 09:55

Sorry, hab beim ersten Scan nicht auf die success-Nachricht gewartet....also hier dann beide logs:

Code:

aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-02-23 09:22:46
-----------------------------
09:22:46.312    OS Version: Windows x64 6.1.7601 Service Pack 1
09:22:46.312    Number of processors: 4 586 0x2502
09:22:46.312    ComputerName: VERENAS-PC  UserName: Verena
09:22:47.794    Initialize success
09:23:42.733    AVAST engine defs: 12022201
09:24:47.333    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
09:24:47.349    Disk 0 Vendor: Hitachi_ PC4O Size: 476940MB BusType: 3
09:24:47.364    Disk 0 MBR read successfully
09:24:47.364    Disk 0 MBR scan
09:24:47.364    Disk 0 unknown MBR code
09:24:47.380    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          199 MB offset 2048
09:24:47.396    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      463423 MB offset 409600
09:24:47.427    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        13213 MB offset 949499904
09:24:47.458    Disk 0 Partition 4 00    0C    FAT32 LBA MSDOS5.0      103 MB offset 976560128
09:24:47.505    Disk 0 scanning C:\Windows\system32\drivers
09:24:58.628    Service scanning
09:25:38.704    Modules scanning
09:25:38.720    Disk 0 trace - called modules:
09:25:39.234    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
09:25:39.250    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c02060]
09:25:39.250    3 CLASSPNP.SYS[fffff8800110b43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800494c050]
09:25:40.451    AVAST engine scan C:\Windows
09:25:44.226    AVAST engine scan C:\Windows\system32
09:29:26.995    AVAST engine scan C:\Windows\system32\drivers
09:29:45.450    AVAST engine scan C:\Users\Verena
09:33:31.447    Disk 0 MBR has been saved successfully to "C:\Users\Verena\Desktop\MBR.dat"
09:33:31.463    The log file has been saved successfully to "C:\Users\Verena\Desktop\aswMBR.txt"

Code:

aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-02-23 09:36:17
-----------------------------
09:36:17.373    OS Version: Windows x64 6.1.7601 Service Pack 1
09:36:17.373    Number of processors: 4 586 0x2502
09:36:17.373    ComputerName: VERENAS-PC  UserName: Verena
09:36:18.917    Initialize success
09:36:26.608    AVAST engine defs: 12022201
09:36:33.971    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
09:36:33.971    Disk 0 Vendor: Hitachi_ PC4O Size: 476940MB BusType: 3
09:36:34.002    Disk 0 MBR read successfully
09:36:34.002    Disk 0 MBR scan
09:36:34.018    Disk 0 unknown MBR code
09:36:34.018    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          199 MB offset 2048
09:36:34.049    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      463423 MB offset 409600
09:36:34.080    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        13213 MB offset 949499904
09:36:34.096    Disk 0 Partition 4 00    0C    FAT32 LBA MSDOS5.0      103 MB offset 976560128
09:36:34.143    Disk 0 scanning C:\Windows\system32\drivers
09:36:49.056    Service scanning
09:37:16.185    Modules scanning
09:37:16.200    Disk 0 trace - called modules:
09:37:16.731    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
09:37:16.731    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c02060]
09:37:16.746    3 CLASSPNP.SYS[fffff8800110b43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800494c050]
09:37:18.197    AVAST engine scan C:\Windows
09:37:23.111    AVAST engine scan C:\Windows\system32
09:40:41.840    AVAST engine scan C:\Windows\system32\drivers
09:40:56.972    AVAST engine scan C:\Users\Verena
09:46:29.238    AVAST engine scan C:\ProgramData
09:47:16.521    Scan finished successfully
09:48:17.580    Disk 0 MBR has been saved successfully to "C:\Users\Verena\Desktop\MBR.dat"
09:48:17.595    The log file has been saved successfully to "C:\Users\Verena\Desktop\aswMBR2.txt"


cosinus 23.02.2012 12:54

MBR ist immer noch unbekannt. Bitte wiederholen

vivastern 23.02.2012 19:42

Soweit ich das sehen kann, hat sich leider nichts verändert....außer, dass es einen Absturz gab, als ich das Programm hab laufen lassen...
Code:

aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-02-23 18:50:40
-----------------------------
18:50:40.400    OS Version: Windows x64 6.1.7601 Service Pack 1
18:50:40.400    Number of processors: 4 586 0x2502
18:50:40.400    ComputerName: VERENAS-PC  UserName: Verena
18:50:41.663    Initialize success
18:50:53.082    AVAST engine defs: 12022201
18:51:01.850    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:51:01.850    Disk 0 Vendor: Hitachi_ PC4O Size: 476940MB BusType: 3
18:51:01.865    Disk 0 MBR read successfully
18:51:01.881    Disk 0 MBR scan
18:51:01.881    Disk 0 unknown MBR code
18:51:01.896    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          199 MB offset 2048
18:51:01.943    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      463423 MB offset 409600
18:51:01.990    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        13213 MB offset 949499904
18:51:02.006    Disk 0 Partition 4 00    0C    FAT32 LBA MSDOS5.0      103 MB offset 976560128
18:51:02.052    Disk 0 scanning C:\Windows\system32\drivers
18:51:13.924    Service scanning
18:51:47.620    Modules scanning
18:51:47.636    Disk 0 trace - called modules:
18:51:48.166    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
18:51:48.166    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004bf9060]
18:51:48.182    3 CLASSPNP.SYS[fffff8800115243f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004978050]
18:51:49.289    AVAST engine scan C:\Windows
18:51:52.612    AVAST engine scan C:\Windows\system32
19:07:13.419    AVAST engine scan C:\Windows\system32\drivers
19:08:42.948    AVAST engine scan C:\Users\Verena
19:18:11.569    AVAST engine scan C:\ProgramData
19:19:33.126    Scan finished successfully
19:39:16.341    Disk 0 MBR has been saved successfully to "C:\Users\Verena\Desktop\MBR.dat"
19:39:16.341    The log file has been saved successfully to "C:\Users\Verena\Desktop\aswMBR3.txt"


cosinus 23.02.2012 21:09

Du klickst auch schon auf FixMBR?! :wtf:

vivastern 23.02.2012 21:57

Du liest auch schon deine Anweisungen???
Zitat:

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung
Also doch fix klicken?

cosinus 23.02.2012 22:01

Ja ich lese schon, hab dich in diesem Fall aber mit jmd anderes verwechselt :lach:
Wäre nicht passiert, wenn ich dochnochmal nach oben gescrollt und mal nachgesehen hätte, ob ich die MBR-Fix-Anweisung gepostet hab :o dann hätte ich mir diese meine Ausrede jetzt sparen können :D :zunge:

Also dann jetzt:

Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.



Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.
Mach den Fix auch dann nicht, wenn du zB mit TrueCrypt oder anderen Verschlüsselungsprogrammen eine Vollverschlüsselung der Windowspartition bzw. gesamten Festplatte hast


Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehlalarm!

Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

vivastern 23.02.2012 23:16

Kann ja mal passieren... stell mich zwar schon mal blöd an, aber da war ich mir doch sicher :heilig:

Alles getan, dann schauen sie mal nach Hr. Doktor :dankeschoen:

Code:

aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-02-23 22:57:38
-----------------------------
22:57:38.110    OS Version: Windows x64 6.1.7601 Service Pack 1
22:57:38.110    Number of processors: 4 586 0x2502
22:57:38.110    ComputerName: VERENAS-PC  UserName: Verena
22:57:39.592    Initialize success
22:57:47.205    AVAST engine defs: 12022201
22:57:55.286    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:57:55.301    Disk 0 Vendor: Hitachi_ PC4O Size: 476940MB BusType: 3
22:57:55.317    Disk 0 MBR read successfully
22:57:55.317    Disk 0 MBR scan
22:57:55.317    Disk 0 Windows 7 default MBR code
22:57:55.333    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          199 MB offset 2048
22:57:55.348    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      463423 MB offset 409600
22:57:55.379    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        13213 MB offset 949499904
22:57:55.411    Disk 0 Partition 4 00    0C    FAT32 LBA MSDOS5.0      103 MB offset 976560128
22:57:55.473    Disk 0 scanning C:\Windows\system32\drivers
22:58:10.496    Service scanning
22:58:43.116    Modules scanning
22:58:43.131    Disk 0 trace - called modules:
22:58:43.662    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
22:58:43.662    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004bfb060]
22:58:43.677    3 CLASSPNP.SYS[fffff880010b943f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800495b050]
22:58:45.112    AVAST engine scan C:\Windows
22:58:50.728    AVAST engine scan C:\Windows\system32
23:02:32.046    AVAST engine scan C:\Windows\system32\drivers
23:03:03.823    AVAST engine scan C:\Users\Verena
23:08:51.938    AVAST engine scan C:\ProgramData
23:09:40.532    Scan finished successfully
23:10:36.286    Disk 0 MBR has been saved successfully to "C:\Users\Verena\Desktop\MBR.dat"
23:10:36.286    The log file has been saved successfully to "C:\Users\Verena\Desktop\aswMBR4.txt"


cosinus 24.02.2012 10:57

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

vivastern 24.02.2012 15:52

Seltsam, die email und dein Post stimmen nicht überein...ich hab mich mal an den Post gehalten...
Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.02.23.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Verena :: VERENAS-PC [Administrator]

24.02.2012 11:02:11
mbam-log-2012-02-24 (11-02-11).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 379857
Laufzeit: 54 Minute(n), 23 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 02/24/2012 at 03:34 PM

Application Version : 5.0.1144

Core Rules Database Version : 8273
Trace Rules Database Version: 6085

Scan type      : Complete Scan
Total Scan Time : 03:25:20

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Administrator

Memory items scanned      : 752
Memory threats detected  : 0
Registry items scanned    : 65772
Registry threats detected : 0
File items scanned        : 230887
File threats detected    : 627

Adware.Tracking Cookie
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\verena@ad.adnet[1].txt [ /ad.adnet ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\verena@ads.medienhaus[1].txt [ /ads.medienhaus ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\verena@adserver.kino-zeit[2].txt [ /adserver.kino-zeit ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\verena@tracking.hannoversche[1].txt [ /tracking.hannoversche ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\verena@traffictrack[1].txt [ /traffictrack ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\verena@unitymedia[1].txt [ /unitymedia ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\verena@webmasterplan[2].txt [ /webmasterplan ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\verena@zanox-affiliate[1].txt [ /zanox-affiliate ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\4NEHARJ2.txt [ /adx.chip.de ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\Z9D2FJJH.txt [ /ad.zanox.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\8JT8JOXG.txt [ /track.adform.net ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\RZWRQMIK.txt [ /apmebf.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\XQ3KQD1F.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\TAV5WJOS.txt [ /adform.net ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\M3LRIQP8.txt [ /statse.webtrendslive.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\9112777S.txt [ /ads.creative-serving.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\ZIZBSMA5.txt [ /xvid-media-codec.softonic.de ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\IQ0A8SFP.txt [ /imrworldwide.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\L1CR3WU2.txt [ /ad.ad-srv.net ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\0RM3VCF7.txt [ /mediaplex.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\HX700QMX.txt [ /ad.yieldmanager.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\WY3M8OP4.txt [ /zanox.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\O590CWJ1.txt [ /invitemedia.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\YW4QBI9O.txt [ /atdmt.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\QUG24RZM.txt [ /serving-sys.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\0HOD2GWD.txt [ /bs.serving-sys.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\N47KQS0L.txt [ /avgtechnologies.112.2o7.net ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\2P4VW0WC.txt [ /tracking.quisma.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\BRWIWTMI.txt [ /tracking.mlsat02.de ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\MAH8ED85.txt [ /server.adform.net ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\QTTSLD8J.txt [ /doubleclick.net ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\PRTKYWWQ.txt [ /revsci.net ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\N6BLG7ML.txt [ /c.atdmt.com ]
        C:\Users\Verena\AppData\Roaming\Microsoft\Windows\Cookies\XDNWK9S0.txt [ /adfarm1.adition.com ]
        C:\USERS\VERENA\AppData\Roaming\Microsoft\Windows\Cookies\ICG4Q917.txt [ Cookie:verena@clkads.com/adServe/banners/ ]
        C:\USERS\VERENA\AppData\Roaming\Microsoft\Windows\Cookies\AMRUKH8L.txt [ Cookie:verena@clkads.com/adServe/banners ]
        C:\USERS\VERENA\AppData\Roaming\Microsoft\Windows\Cookies\Low\verena@ad.adnet[1].txt [ Cookie:verena@ad.adnet.de/ ]
        C:\USERS\VERENA\AppData\Roaming\Microsoft\Windows\Cookies\Low\verena@atdmt[1].txt [ Cookie:verena@atdmt.com/ ]
        C:\USERS\VERENA\AppData\Roaming\Microsoft\Windows\Cookies\Low\verena@zanox-affiliate[1].txt [ Cookie:verena@zanox-affiliate.de/ ]
        C:\USERS\VERENA\AppData\Roaming\Microsoft\Windows\Cookies\Low\verena@adserver.kino-zeit[2].txt [ Cookie:verena@adserver.kino-zeit.de/ ]
        C:\USERS\VERENA\AppData\Roaming\Microsoft\Windows\Cookies\Low\verena@traffictrack[1].txt [ Cookie:verena@traffictrack.de/ ]
        C:\USERS\VERENA\AppData\Roaming\Microsoft\Windows\Cookies\Low\verena@unitymedia[1].txt [ Cookie:verena@unitymedia.de/ ]
        C:\USERS\VERENA\Cookies\Z9D2FJJH.txt [ Cookie:verena@ad.zanox.com/ ]
        C:\USERS\VERENA\Cookies\ICG4Q917.txt [ Cookie:verena@clkads.com/adServe/banners/ ]
        C:\USERS\VERENA\Cookies\AMRUKH8L.txt [ Cookie:verena@clkads.com/adServe/banners ]
        C:\USERS\VERENA\Cookies\RZWRQMIK.txt [ Cookie:verena@apmebf.com/ ]
        C:\USERS\VERENA\Cookies\XQ3KQD1F.txt [ Cookie:verena@ad2.adfarm1.adition.com/ ]
        C:\USERS\VERENA\Cookies\TAV5WJOS.txt [ Cookie:verena@adform.net/ ]
        C:\USERS\VERENA\Cookies\M3LRIQP8.txt [ Cookie:verena@statse.webtrendslive.com/ ]
        C:\USERS\VERENA\Cookies\ZIZBSMA5.txt [ Cookie:verena@xvid-media-codec.softonic.de/ ]
        C:\USERS\VERENA\Cookies\IQ0A8SFP.txt [ Cookie:verena@imrworldwide.com/cgi-bin ]
        C:\USERS\VERENA\Cookies\verena@ad.adnet[1].txt [ Cookie:verena@ad.adnet.de/ ]
        C:\USERS\VERENA\Cookies\HX700QMX.txt [ Cookie:verena@ad.yieldmanager.com/ ]
        C:\USERS\VERENA\Cookies\verena@tracking.hannoversche[1].txt [ Cookie:verena@tracking.hannoversche.de/ ]
        C:\USERS\VERENA\Cookies\O590CWJ1.txt [ Cookie:verena@invitemedia.com/ ]
        C:\USERS\VERENA\Cookies\YW4QBI9O.txt [ Cookie:verena@atdmt.com/ ]
        C:\USERS\VERENA\Cookies\0HOD2GWD.txt [ Cookie:verena@bs.serving-sys.com/ ]
        C:\USERS\VERENA\Cookies\N47KQS0L.txt [ Cookie:verena@avgtechnologies.112.2o7.net/ ]
        C:\USERS\VERENA\Cookies\verena@zanox-affiliate[1].txt [ Cookie:verena@zanox-affiliate.de/ ]
        C:\USERS\VERENA\Cookies\verena@adserver.kino-zeit[2].txt [ Cookie:verena@adserver.kino-zeit.de/ ]
        C:\USERS\VERENA\Cookies\verena@traffictrack[1].txt [ Cookie:verena@traffictrack.de/ ]
        C:\USERS\VERENA\Cookies\MAH8ED85.txt [ Cookie:verena@server.adform.net/ ]
        C:\USERS\VERENA\Cookies\QTTSLD8J.txt [ Cookie:verena@doubleclick.net/ ]
        C:\USERS\VERENA\Cookies\PRTKYWWQ.txt [ Cookie:verena@revsci.net/ ]
        C:\USERS\VERENA\Cookies\N6BLG7ML.txt [ Cookie:verena@c.atdmt.com/ ]
        C:\USERS\VERENA\Cookies\verena@unitymedia[1].txt [ Cookie:verena@unitymedia.de/ ]
        .gostats.de [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .thesexfacebook.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .thesexfacebook.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .thesexfacebook.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .thesexfacebook.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .thesexfacebook.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .thesexfacebook.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .thesexfacebook.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        1.bfugmedia.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        rgadvert.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.myindextracker.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .dmtracker.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.myindextracker.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.myindextracker.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.myindextracker.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .myindextracker.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .myindextracker.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .myindextracker.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .moviepilot.de [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .moviepilot.de [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .moviepilot.de [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.moviepilot.de [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.tldadserv.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .gostats.de [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .de.at.atwola.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad3.adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tacoda.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tacoda.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tacoda.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tacoda.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tacoda.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tacoda.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atwola.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .at.atwola.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .at.atwola.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        studivz.adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .statcounter.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .harrenmedianetwork.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .xm.xtendmedia.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        wmedia.rotator.hadj7.adjuggler.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        wmedia.rotator.hadj7.adjuggler.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .rotator.hadj7.adjuggler.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        wmedia.rotator.hadj7.adjuggler.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pro-market.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pro-market.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .osloadserver.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .media6degrees.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .media6degrees.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .media6degrees.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adxpose.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ru4.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ru4.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yieldmanager.net [ C:\USERS\VERENA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        C:\USERS\VERENA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\VERENA@WEBMASTERPLAN[2].TXT [ /WEBMASTERPLAN ]
        C:\USERS\VERENA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\VERENA@ZANOX[1].TXT [ /ZANOX ]
        C:\USERS\VERENA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\VERENA@ADX.CHIP[2].TXT [ /ADX.CHIP ]
        C:\USERS\VERENA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\VERENA@ADS.MEDIENHAUS[1].TXT [ /ADS.MEDIENHAUS ]
        C:\USERS\VERENA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\VERENA@TRACKING.QUISMA[1].TXT [ /TRACKING.QUISMA ]
        .ad.adnet.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .vodafonegroup.122.2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        fidelity.rotator.hadj7.adjuggler.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adserver.adtechus.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .deutschepostag.112.2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .avgtechnologies.112.2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .msnportal.112.2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        de.partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .game-advertising-online.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        wmedia.rotator.hadj7.adjuggler.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        adsrv1.admediate.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ads.247activemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .velmedia.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .247realmedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .247realmedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .247realmedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .harrenmedianetwork.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.888.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .admediate.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .dbnvb.adserve.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adserve.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .kontera.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .server.cpmstar.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adinterax.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adinterax.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .mediabrandsww.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ad.adserve.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ad.adserve.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .aim4media.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .linksynergy.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .linksynergy.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .linksynergy.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .warnerbros.112.2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adlegend.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .click.right-ads.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .gostats.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .keygenguru.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .keygenguru.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .keygens.nl [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .keygens.nl [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .serialnumber.in [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .serialnumber.in [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .crack.ms [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .crack.ms [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        adservpi.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        xvid-media-codec.softonic.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        xvid-media-codec.softonic.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        xvid-media-codec.softonic.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        webstats.dellmont.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .realmedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .mmotraffic.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        pfatracking.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        tracking.gameforge.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        wstat.wibiya.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .aim4media.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .azjmp.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        tracking.sim-technik.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .h.atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .h.atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .h.atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .h.atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        httptrack.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .cbs.112.2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        httptrack.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .mmotraffic.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .oracle.112.2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        s2.netxmedia.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .aim4media.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        httptrack.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .analytics.rogersmedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .rogersmedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .gostats.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .gutscheine.big-click.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .gutscheine.big-click.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ads.247activemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        httptrack.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .banners.victor.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        tracking1.aleadpay.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        e2.emediate.se [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .paypal.112.2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .247activemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .www.burstnet.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.burstnet.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .burstnet.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        api.zanox.ws [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .burstnet.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .loyaltypartner.122.2o7.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        forexyard.advertserve.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        pfa.rotator.hadj7.adjuggler.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        pfa.rotator.hadj7.adjuggler.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .mmotraffic.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .mmotraffic.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .xm.xtendmedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ad.velmedia.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ad.velmedia.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .www.traffictrack.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .zieltrack.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        teufel-media.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.usenext.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.usenext.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .aim4media.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        affiliate.a4dtracker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        edates.traffective-tracking.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        edates.traffective-tracking.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        edates.traffective-tracking.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        fidelity.rotator.hadj7.adjuggler.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .advertstream.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.track-visits.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        clicks.thespecialsearch.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.easymedia-gmbh.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .server.cpmstar.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .server.cpmstar.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .server.cpmstar.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .server.cpmstar.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .de.partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.usenext.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .cpvadverts.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .cpvadverts.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.tldadserv.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        tracking.hostgator.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.track-visits.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .oserverstats.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .content.yieldmanager.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        trackstatsnow.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        trackstatsnow.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        wmedia.rotator.hadj7.adjuggler.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .businessenhanced.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .businessenhanced.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.biz [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.biz [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.biz [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        tracking.publicidees.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        tracking.publicidees.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .myroitracking.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\VERENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LHEUQOM4.DEFAULT\COOKIES.SQLITE ]


cosinus 24.02.2012 15:59

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

vivastern 24.02.2012 16:10

Soweit sieht alles prima aus. Dafür erstmal ein riesiges :dankeschoen:

Kann ich nun alle Programme löschen oder empfiehlst du welche/alle zu behalten?

Und: Könntest du mir als Profi denn geeignete Software empfehlen für folgende Bereiche:
1. Anti-Virus
2. Anti- Malware, Adware, etc...
3. ich suche ein Programm, dass meine IP verschlüsselt und es so aussehen lässt, als ob ich in den USA bin. Denn das ist die einzige Möglichkeit, meine geliebten Serien direkt auf den "sicheren" Homepages der TV-Networks zu gucken, ohne "gezwungen" zu sein, die BÖSEN Seiten zu besuchen und damit wieder in die Misere zu geraten. Damit würdest du mein Leben retten!

Ich bin gern bereit, für Software zu bezahlen, wenn ich dadurch einen immer aktuellen Schutz vor allem Bösen des www bekomme.

HIER MUSS NOCHMAL ERWÄHNT WERDEN: ARNE HAT MICH UND MEINEN LAPTOP GERETTET!!! :dankeschoen::dankeschoen::dankeschoen:

cosinus 24.02.2012 16:14

Zitat:

Und: Könntest du mir als Profi denn geeignete Software empfehlen für folgende Bereiche:
1. Anti-Virus
2. Anti- Malware, Adware, etc...
Die Frage - welcher Virenscanner oder ob der installierte reicht - taucht ständig auf.
Der Virenscanner - egal welcher - kann und wird niemals 100% Schutz bieten können. Neue/unbekannte Schädlinge können immer durch die Lappen gehen. Geld ausgeben muss man nicht für einen Scanner, sowas wie Avast oder Microsoft Security Essentials sind für die privaten Gebrauch völlig ausreichend.
Abgesehen davon nutzen verschiedene Virenscanner unterschiedliche Signaturen und Techniken, das führt dazu, dass zB Scanner1 Schädling X entdeckt, aber Schädling Y übersieht. Scanner2 erkennt Schädling Y, dafür aber Schädling X nicht...
Wichtiger ist, dass du dich an Regeln hälst. Der beste Virenscanner bringt nichts, wenn du dich falsch verhälst und fahrlässig/unvorsichtig bist. Airbag und Sicherheitsgurt im Auto sind ja auch keine Gründe dafür auf die Verkehrsregeln zu pfeifen.

Halte Dich am besten grob an diese Regeln:
  1. Sei misstrauisch im Internet und v.a. bei unbekannten E-Mails, sei vorsichtig bei der Herausgabe persönlicher Daten!!
  2. Halte Windows und alle verwendeten Programme immer aktuell - unterstützen kann dich dabei Secunia PSI
  3. Führe regelmäßig Backups auf externe Medien durch
  4. Arbeite mit eingeschränkten Rechten
  5. Nutze sicherere Programme wie zB Opera oder Firefox zum Surfen statt den IE, zum Mailen Thunderbird statt Outlook Express - E-Mails nur als reinen text anzeigen lassen
  6. automatische Wiedergabe von allen Laufwerken komplett deaktivieren, denn das ist ein unnötiges Sicherheitsrisiko
  7. Bei der Installation von Software möglichst darauf achten, dass die Setups aus offiziellen Quellen stammen und du bei der Installation nach Möglichkeit die benutzerdefinierte Methode wählst - dann hast du die Möglichkeit etwaigen Schrott (wie Toolbars oder sowas wie RegistryBooster) abzuwählen, welcher sonst einfach mitinstalliert wird.
  8. Bösartige bzw. ungewollte Sites von vornherein blockieren lassen mit Hilfe der MVPS Hosts File => Blocking Unwanted Parasites with a Hosts File
  9. Finger weg von: TuneUp, Registry-Cleanern aller Art, Softonic sowie illegalen Cracks/Keygens oder anderen "Tools" um ein kommerzielles Programm ohne Lizenz nutzen zu können
  10. dubiose Seiten bzw. Kinofilm-Streaming-Portale ebenfalls sein lassen, erstens handelt man sich dort schnell Malware ein oder kann in Abofallen geraten und zweitens bewegen sich diese Seiten in einer rechtlichen Grauzone.


Alles noch genauer erklärt steht hier => Kompromittierung unvermeidbar?

Zitat:

wenn ich dadurch einen immer aktuellen Schutz vor allem Bösen des www bekomme.
Man kann Sicherheit nicht allein durch Software in bunten Pappschachteln erkaufen, warum hab ich oben erwähnt


Zitat:

3. ich suche ein Programm, dass meine IP verschlüsselt
Da gibt es ein paar Lösungen, aber die Performance ist sehr besch...eiden. Probier mal TOR aus und/oder die FF-Erweiterung Stealthy




Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

vivastern 24.02.2012 16:48

Arne, du bist ein :heilig:

Vielen Dank für die Tips, werde gleich mal alle durchgehen, beherzigen und dann hoffen, dass wir gesund bleiben.
Habe vor einiger Zeit den WR Cleaner empfohlen bekommen, sehe aber in deiner Antwort, man sollte solche Programme gar nicht benutzen? Darf ich fragen warum?
Hab ihn einmal drüber laufen lassen. Aber werde ihn wohl dann lieber wieder runter schmeißen.

Und:
Zitat:

Arbeite mit eingeschränkten Rechten
Was heißt das?

cosinus 24.02.2012 18:46

Zitat:

Was heißt das?
Dass man nicht ständig mit Adminrechten drin ist! Für den alltäglichen Umgang benutzt man ein Windows-Bentuzerkonto mit normalen Rechten => Benutzerrechten - und geht nur in ein Konto mit Adminrechten wenn man diese Rechte für administrative Tätigkeiten benötigt

Stell dir ein Adminkonto vor wie eine Schusswaffe, die immer geladen und entsichert ist, und mit dieser läufst du ständig herum. Irgendwann schießt du dir damit in den Fuß.
Die Schusswaffe lädst und entsicherst du nur, wenn du sie wirklich brauchst - oder nicht? :pfeiff:

vivastern 25.02.2012 16:58

Hallo Arne,

als ich gerade meinen Laptop mithilfe deiner Tips optimieren wollte, ist eingetreten, was ich befürchtet hatte: Gleicher Fehler wie ganz am Anfang, nur dieses Mal blieb die CPU bei 98-100% und ging nicht nach einer Weile runter.
Außerdem haben sich die sychost.exes auch wieder vermehrt.

Am Ende hab ich mich für eine Systemwiederherstelliung entschieden. Besonders das Secunia hat Probleme gemacht.

Und: ComboFix lässt sich nicht deinstallieren sowie auch SuperAntiSpyware nicht.

Hilfe, Hilfe, Hilfe bitte!

cosinus 26.02.2012 15:30

Zitat:

Außerdem haben sich die sychost.exes auch wieder vermehrt.
Mehrere laufende svchost.exe sind normal. Das ist ein legitimer Systemdienst! Wenn da aber wirklich was von "sychost" steht sind das Schädlinge.

Zitat:

Besonders das Secunia hat Probleme gemacht.
Probleme mit diesem Tool kenn ich nicht. Was für Probleme sollen das sein, wieso beschreibst du das nicht gleich am Anfang genau?

vivastern 26.02.2012 17:54

Ich könnte hier gerade ausrasten, ehrlich....

Also zu deinen Fragen:

Es ist tatsächlich sVchost.exe, aber denkst du, dass es normal ist, dass sich das vermehrt, wenn man den Prozess manuell beendet? Kommt mir jedenfalls komisch vor.

Und mit Secunia habe ich nicht direkt ein Problem, aber mein CPU 100%-Problem hat nach der Installation davon wieder losgelegt.

Außerdem habe ich mein AVG gegen COMODO ausgetauscht, nur komm ich mit dem ersten Scan gerade bis ca. 10% bis dann die CPU wieder bei 100% ist und dementsprechend der Scan langsamer ist, als täte man es per Hand.

Ich bin echt verzweifelt und weiß auch echt nicht, was passiert sein soll, dass das böse Phänomen wieder da ist. Ich habe mich wirklich nur an deine abschließenden Tips gehalten.

Zusammenfassend:

Ich habe alle Programme, die ich während unserer Analyse installiert habe wieder runtergeschmissen. Außer SuperAntispyware und ComboFix, die habe ich heute erst deinstalliert (hat endlich geklappt)

Ich habe neu installiert: Thunderbird, diese hosts-Datei, die du empfohlen hast und dann noch das Secunia. Dann wars wieder da. Ich habe ausschließlich Download-Links genommen, die du empfohlen hast und habe jede Datei nochmal vorm Ausführen mit AVG gescannt.
Außerdem habe ich Java neu installiert sowie die im Updatecenter angegebenen Windows-Updates. Das müsste es gewesen sein.

Ich weiß einfach echt nicht, was passiert sein soll.

Ich hoffe inständig, dass dir noch eine Möglichkeit einfällt, wie wir das Problem lösen könnten!

LG, Verena

P.S.: Ich bemerke auch gerade, dass auf dieser Seite jegliche Benutzersymbole vor unseren Namen fehlen, falls das ein Hinweis sein könnte.

cosinus 26.02.2012 18:31

Zitat:

dass sich das vermehrt, wenn man den Prozess manuell beendet? Kommt mir jedenfalls komisch vor.
Was soll das manuelle Beenden?! :balla:
Weißt du dann was genau sich für Funktionalitäten hinter der svchost Instanz verbergen? Nein, also lass es sein einfach irgendwas abzuwürgen

Zitat:

Außerdem habe ich mein AVG gegen COMODO ausgetauscht,
Genau das hätte ich NICHT rempfohlen wenn du sowas wie Comodo Internet Security meinst! :balla:
Umgehend deinstallieren!

vivastern 26.02.2012 19:58

Da soll noch einer durchblicken...COMODO hatte so gute Meinungen, sah mir aber schon nach ein wenig too much für freeware aus.

Deinstallation ist abgeschlossen, Avast dafür installiert und gleich mal damit einen QuickScan gemacht ohne Befund.

Wollte jetzt nochmal versuchen, das Secunia zu installieren, um zu schauen, ob das tatsächlich der Auslöser war (denn COMODO war da ja noch gar nicht drauf).

Falls du eine bessere Vorgehensweise vorschlägst, sag mir Bescheid :crazy:


Alle Zeitangaben in WEZ +1. Es ist jetzt 03:58 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131