Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Virenbefall: Live Security Platinum Virus (https://www.trojaner-board.de/121546-virenbefall-live-security-platinum-virus.html)

metaldakster 08.08.2012 09:52

Virenbefall: Live Security Platinum Virus
 
Hallo zusammen,

mein Laptop ist leider auch vom Live Security Platinum Virus befallen worden. Jeder Virenscanner sagt mir etwas anders, weshalb ich hoffe, dass Ihr mir weiterhelfen könnt. So sieht meine Malwarebytes-Logdatei aus.

Zitat:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.08.08.02

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
Daniel Kort :: DANIELKORTH-PC [Administrator]

08.08.2012 09:15:05
mbam-log-2012-08-08 (10-49-23).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 352054
Laufzeit: 1 Stunde(n), 33 Minute(n), 55 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 1
HKCU\SOFTWARE\CLASSES\CLSID\{42AEDC87-2188-41FD-B9A3-0C966FEABEC1}\INPROCSERVER32 (Trojan.Zaccess) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce|036DFF85B055CB8D95A3E415F875EF7E (Trojan.LameShield) -> Daten: C:\ProgramData\036DFF85B055CB8D95A3E415F875EF7E\036DFF85B055CB8D95A3E415F875EF7E.exe -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\CLASSES\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32| (Trojan.Zaccess) -> Daten: C:\Users\Daniel Kort\AppData\Local\{7c9c6958-a65d-e6bc-5848-15b770ab5998}\n. -> Keine Aktion durchgeführt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\ProgramData\036DFF85B055CB8D95A3E415F875EF7E\036DFF85B055CB8D95A3E415F875EF7E.exe (Trojan.LameShield) -> Keine Aktion durchgeführt.
C:\Users\Daniel Kort\AppData\Local\{7c9c6958-a65d-e6bc-5848-15b770ab5998}\n (RootKit.0Access) -> Keine Aktion durchgeführt.

(Ende)
Vielen Dank schonmal im Voraus.

Viele Grüße
Daniel

metaldakster 13.08.2012 08:02

Hallo zusammen,

habe ich den Beitrag in ein falsches Forum kopiert? Bisher hat noch keiner darauf geantwortet. Es wäre klasse, wenn Ihr mir helfen könntet.

Vielen Dank!

cosinus 17.08.2012 16:24

Bitte erstmal routinemäßig einen neuen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



Führ danach bitte auch nochmal ESET aus, danach sehen wir weiter.

Hinweis: ESET zeigt durchaus öfter ein paar Fehlalarme. Deswegen soll auch von ESET immer nur erst das Log gepostet und nichts entfernt werden.

ESET Online Scanner

Bitte während der Online-Scans evtl. vorhandene externe Festplatten einschalten! Bitte während der Scans alle Hintergrundwächter (Anti-Virus-Programm, Firewall, Skriptblocking und ähnliches) abstellen und nicht vergessen, alles hinterher wieder einzuschalten.
  • Anmerkung für Vista und Win7 User: Bitte den Browser unbedingt so öffnen: per Rechtsklick => als Administrator ausführen
  • Dein Anti-Virus-Programm während des Scans deaktivieren.

    Button http://img695.imageshack.us/img695/1599/eset1l.jpg (<< klick) drücken.
    • Firefox-User:
      Bitte esetsmartinstaller_enu.exe downloaden.Das Firefox-Addon auf dem Desktop speichern und dann installieren.
    • IE-User:
      müssen das Installieren eines ActiveX Elements erlauben.
  • Setze den einen Haken bei Yes, i accept the Terms of Use.
  • Drücke den http://img707.imageshack.us/img707/687/starteg.jpg Button.
  • Warte bis die Komponenten herunter geladen wurden.
  • Setze einen Haken bei "Scan archives".
  • Gehe sicher das bei Remove Found Threats kein Haken gesetzt ist.
  • http://img707.imageshack.us/img707/687/starteg.jpg drücken.
  • Die Signaturen werden herunter geladen.Der Scan beginnt automatisch.
Wenn der Scan beendet wurde
  • Klicke Finish.
  • Browser schließen.
Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und kopiere folgenden Text in das Ausführen Fenster.
Code:

"%PROGRAMFILES%\Eset\Eset Online Scanner\log.txt"
Hinweis: Falls du ein 64-Bit-Windows einsetzt, lautet der Pfad so:

Code:

"%PROGRAMFILES(X86)%\Eset\Eset Online Scanner\log.txt"
Poste nun den Inhalt der log.txt.



Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

metaldakster 20.08.2012 10:22

Hallo Cosinus,

erstmal vielen Dank für Deine Antwort. Zusätzlich zu dem Scan im anderen Post habe ich nun noch einmal einen Scan über Malwarebytes gemacht. Hier das Log:

Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.08.20.02

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
Daniel Kort :: DANIELKORTH-PC [Administrator]

Schutz: Aktiviert

20.08.2012 09:36:54
mbam-log-2012-08-20 (09-36-54).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 363393
Laufzeit: 1 Stunde(n), 39 Minute(n), 41 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Die fünf Funde aus dem ersten Log sind in Quarantäne.

Das ESET-Log sieht folgendermaßen aus:

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=e0a8a27b9570884081792dfcd076eef1
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-08-14 01:27:17
# local_time=2012-08-14 03:27:17 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 15575013 15575013 0 0
# compatibility_mode=5893 16776573 100 94 20407 96578481 0 0
# compatibility_mode=8192 67108863 100 0 77 77 0 0
# scanned=160685
# found=0
# cleaned=0
# scan_time=3546


cosinus 21.08.2012 11:37

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

metaldakster 22.08.2012 11:06

Hallo Cosinus,

dank Dir für die Antwort. Das Logfile sieht folgendermaßen aus:

Code:

# AdwCleaner v1.801 - Logfile created 08/22/2012 at 12:05:40
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Professional Service Pack 1 (32 bits)
# User : Daniel Kort - DANIELKORTH-PC
# Boot Mode : Normal
# Running from : C:\Users\Daniel Kort\Downloads\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Users\DANIEL~1\AppData\Local\Temp\AskSearch
Folder Found : C:\Users\Daniel Kort\AppData\LocalLow\facemoods.com
Folder Found : C:\Program Files\facemoods.com
File Found : C:\Users\Daniel Kort\AppData\Roaming\Mozilla\Firefox\Profiles\powom3zm.default\searchplugins\Askcom.xml
File Found : C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrch.xml

***** [Registry] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Found : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc
Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1
Key Found : HKLM\SOFTWARE\Classes\facemoods.dskBnd
Key Found : HKLM\SOFTWARE\Classes\facemoods.dskBnd.1
Key Found : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr
Key Found : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr.1
Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl
Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1
Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore
Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1
Key Found : HKLM\SOFTWARE\Description
Key Found : HKLM\SOFTWARE\facemoods.com
Key Found : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\facemoods
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [facemoods]

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Found : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37}
Key Found : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}
Key Found : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883}
Key Found : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7601.17514

[HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://start.facemoods.com/?a=make&f=2
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://start.facemoods.com/?a=make&s={searchTerms}&f=4

-\\ Mozilla Firefox v14.0.1 (de)

Profile name : default
File : C:\Users\Daniel Kort\AppData\Roaming\Mozilla\Firefox\Profiles\powom3zm.default\prefs.js

Found : user_pref("browser.search.defaultengine", "Ask.com");
Found : user_pref("browser.search.order.1", "Ask.com");
Found : user_pref("extensions.facemoods._xpiupdate", true);
Found : user_pref("extensions.facemoods.aflt", "_#wbst");
Found : user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4");
Found : user_pref("extensions.facemoods.first_time", false);
Found : user_pref("extensions.facemoods.id", "_#13a9eef6b57341769e747b0e659befae");
Found : user_pref("extensions.facemoods.instlDay", "_#15348");
Found : user_pref("extensions.facemoods.prtnrId", "_#facemoods.com");
Found : user_pref("extensions.facemoods.sid", "_#13a9eef6b57341769e747b0e659befae");
Found : user_pref("extensions.facemoods.uninst", true);
Found : user_pref("extensions.facemoods.update", "_#v1.4.0");
Found : user_pref("extensions.facemoods.vrsn", "_#1.4.17.5");

-\\ Google Chrome v [Unable to get version]

File : C:\Users\Daniel Kort\AppData\Local\Google\Chrome\User Data\Default\Preferences

Found :                "name" : "facemoods",
Found :                "search_url" : "hxxp://start.facemoods.com/?a=make&s={searchTerms}&f=4",
Found :        "homepage" : "hxxp://start.facemoods.com/?a=make",

*************************

AdwCleaner[R1].txt - [7420 octets] - [22/08/2012 12:05:40]

########## EOF - C:\AdwCleaner[R1].txt - [7548 octets] ##########

:dankeschoen:

cosinus 30.08.2012 12:58

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

metaldakster 04.09.2012 08:58

Hallo Cosinus,

anbei findest Du das Log-file. Facemoods wurde aus der Registry entfernt.:dankeschoen:

Code:

# AdwCleaner v1.801 - Logfile created 09/04/2012 at 09:53:20
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Professional Service Pack 1 (32 bits)
# User : Daniel Kort - DANIELKORTH-PC
# Boot Mode : Normal
# Running from : C:\Users\Daniel Kort\Downloads\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\DANIEL~1\AppData\Local\Temp\AskSearch
Folder Deleted : C:\Users\Daniel Kort\AppData\LocalLow\facemoods.com
Folder Deleted : C:\Program Files\facemoods.com
File Deleted : C:\Users\Daniel Kort\AppData\Roaming\Mozilla\Firefox\Profiles\powom3zm.default\searchplugins\Askcom.xml
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrch.xml

***** [Registry] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.dskBnd
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.dskBnd.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore
Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1
Key Deleted : HKLM\SOFTWARE\Description
Key Deleted : HKLM\SOFTWARE\facemoods.com
Key Deleted : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\facemoods
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [facemoods]

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7601.17514

Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://start.facemoods.com/?a=make&f=2 --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://start.facemoods.com/?a=make&s={searchTerms}&f=4 --> hxxp://www.google.com

-\\ Mozilla Firefox v15.0 (de)

Profile name : default
File : C:\Users\Daniel Kort\AppData\Roaming\Mozilla\Firefox\Profiles\powom3zm.default\prefs.js

C:\Users\Daniel Kort\AppData\Roaming\Mozilla\Firefox\Profiles\powom3zm.default\user.js ... Deleted !

Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Deleted : user_pref("browser.search.order.1", "Ask.com");
Deleted : user_pref("extensions.facemoods._xpiupdate", true);
Deleted : user_pref("extensions.facemoods.aflt", "_#wbst");
Deleted : user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4");
Deleted : user_pref("extensions.facemoods.first_time", false);
Deleted : user_pref("extensions.facemoods.id", "_#13a9eef6b57341769e747b0e659befae");
Deleted : user_pref("extensions.facemoods.instlDay", "_#15348");
Deleted : user_pref("extensions.facemoods.prtnrId", "_#facemoods.com");
Deleted : user_pref("extensions.facemoods.sid", "_#13a9eef6b57341769e747b0e659befae");
Deleted : user_pref("extensions.facemoods.uninst", true);
Deleted : user_pref("extensions.facemoods.update", "_#v1.4.0");
Deleted : user_pref("extensions.facemoods.vrsn", "_#1.4.17.5");

-\\ Google Chrome v [Unable to get version]

File : C:\Users\Daniel Kort\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted :                "name" : "facemoods",
Deleted :                "search_url" : "hxxp://start.facemoods.com/?a=make&s={searchTerms}&f=4",
Deleted :        "homepage" : "hxxp://start.facemoods.com/?a=make",

*************************

AdwCleaner[R1].txt - [7549 octets] - [22/08/2012 12:05:40]
AdwCleaner[S1].txt - [7822 octets] - [04/09/2012 09:53:20]

########## EOF - C:\AdwCleaner[S1].txt - [7950 octets] ##########


cosinus 04.09.2012 15:37

Bitte mal den aktuellen adwCleaner runterladen, also die alte adwcleaner löschen und neu runterladen

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

metaldakster 06.09.2012 10:25

Hallo Cosinus,

die Suche mit dem neuen ADW Cleaner war sauber.

Code:

# AdwCleaner v2.000 - Datei am 09/06/2012 um 11:24:21 erstellt
# Aktualisiert am 30/08/2012 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzer : Daniel Kort - DANIELKORTH-PC
# Normaler Modus : Normal
# Ausgeführt unter : C:\Users\Daniel Kort\Downloads\adwcleaner(1).exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKLM\Software\Description

***** [Internet Browser] *****

-\\ Internet Explorer v8.0.7601.17514

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v15.0 (de)

Profilname : default
Datei : C:\Users\Daniel Kort\AppData\Roaming\Mozilla\Firefox\Profiles\powom3zm.default\prefs.js

[OK] Die Datei ist sauber.

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\Daniel Kort\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [7549 octets] - [22/08/2012 12:05:40]
AdwCleaner[S1].txt - [7951 octets] - [04/09/2012 09:53:20]
AdwCleaner[R2].txt - [1127 octets] - [06/09/2012 11:24:21]

########## EOF - C:\AdwCleaner[R2].txt - [1187 octets] ##########


cosinus 06.09.2012 15:05

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

metaldakster 06.09.2012 16:31

Alles funktioniert und leere Ordner sind auch nicht vorhanden. In den vergangenen Wochen hat mich aber das JAVA-Update ständig genervt und ich vermute, dass hier der Virus auch etwas damit zu tun hatte.:confused: Den habe ich mittlerweile aber gelöscht.

cosinus 06.09.2012 19:58

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


metaldakster 11.09.2012 12:38

Hallo Cosinus,

anbei findest Du das OTL-Log:

OTL Logfile:
Code:

OTL logfile created on: 11.09.2012 13:19:21 - Run 1
OTL by OldTimer - Version 3.2.61.3    Folder = C:\Users\Daniel Kort\Downloads
 Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,22 Gb Available Physical Memory | 40,61% Memory free
5,99 Gb Paging File | 3,85 Gb Available in Paging File | 64,34% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 283,40 Gb Total Space | 227,55 Gb Free Space | 80,29% Space Free | Partition Type: NTFS
 
Computer Name: DANIELKORTH-PC | User Name: Daniel Kort | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.09.11 13:17:51 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Daniel Kort\Downloads\OTL.exe
PRC - [2012.09.07 11:52:02 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012.08.15 09:31:06 | 001,536,712 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe
PRC - [2012.08.10 08:48:16 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.07.03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.05.15 08:44:47 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
PRC - [2012.05.15 08:44:47 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.15 08:44:47 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.05.15 08:44:46 | 000,375,760 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
PRC - [2012.05.15 08:44:46 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.02.17 13:44:10 | 048,060,742 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office.exe
PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.12.30 12:27:34 | 000,074,752 | ---- | M] (Freemake) -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
PRC - [2011.10.13 18:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2011.06.24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.04.08 14:50:02 | 000,542,264 | ---- | M] (Google) -- C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011.02.23 22:19:22 | 000,371,200 | ---- | M] (shbox.de) -- C:\Program Files\FreePDF_XP\fpassist.exe
PRC - [2010.12.06 14:09:22 | 011,229,976 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files\Tracker Software\PDF Viewer\PDFXCview.exe
PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.05.12 17:04:48 | 000,599,480 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\ICA Client\wfcrun32.exe
PRC - [2010.05.12 17:03:22 | 000,300,472 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\ICA Client\concentr.exe
PRC - [2010.01.15 14:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009.11.12 02:55:30 | 000,203,776 | ---- | M] (Microsoft) -- C:\dell\DBRM\Reminder\DbrmTrayicon.exe
PRC - [2009.07.17 06:57:36 | 004,562,944 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
PRC - [2009.07.17 06:57:36 | 000,026,112 | ---- | M] () -- C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
PRC - [2009.07.17 06:57:04 | 003,086,848 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE
PRC - [2009.07.15 20:47:20 | 000,458,844 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
PRC - [2009.07.15 20:47:20 | 000,221,266 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\stacsv.exe
PRC - [2009.06.29 09:59:00 | 000,217,088 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2009.06.29 09:59:00 | 000,054,568 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2009.06.29 09:59:00 | 000,049,250 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2009.06.29 09:59:00 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2009.06.25 04:19:50 | 000,140,520 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2009.06.09 20:33:30 | 000,582,896 | ---- | M] (Dell, Inc.) -- C:\Program Files\Dell\Printer Software\ErrorApp\dkab1err.exe
PRC - [2009.06.09 20:33:28 | 000,603,376 | ---- | M] ( ) -- C:\Windows\System32\dkabcoms.exe
PRC - [2009.02.23 19:48:50 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008.01.07 18:00:00 | 000,036,864 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\OEM13Mon.exe
PRC - [2007.02.12 10:43:44 | 000,065,536 | ---- | M] (O2Micro International) -- C:\Windows\System32\drivers\o2flash.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.09.07 11:52:02 | 002,244,064 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012.08.15 09:31:06 | 009,465,032 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_271.dll
MOD - [2012.06.14 11:17:35 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6c59a14a23f734093e80d6093e25302a\Microsoft.VisualBasic.ni.dll
MOD - [2012.06.14 11:16:10 | 000,391,168 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Iris.Mapi.MessageSt#\67a5a67d1c55617ff8b1e2b71c99f0b9\Iris.Mapi.MessageStore.ni.dll
MOD - [2012.06.14 11:16:09 | 000,462,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.BusinessS#\1b2a08ae2231112bb077a88e5a4737f3\Microsoft.BusinessSolutions.eCRM.DataSync.ni.dll
MOD - [2012.06.14 11:16:04 | 003,826,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\BusinessLayer\2af556542f02c884a5984e3180bf099a\BusinessLayer.ni.dll
MOD - [2012.06.14 11:15:58 | 001,040,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Interop.M#\fbc0feb4b206da7eb439ef53f83d2520\Microsoft.Interop.Mapi.Impl.ni.dll
MOD - [2012.06.14 11:15:57 | 001,526,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\BCMRes\53fd79c2861c4e8a6e25872bea7d9641\BCMRes.ni.dll
MOD - [2012.06.14 08:43:09 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll
MOD - [2012.06.14 08:42:57 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll
MOD - [2012.06.14 08:42:24 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012.06.14 08:42:12 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012.05.14 10:21:39 | 000,220,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\626d0ac2f4ada682d7ca6c4ebf821469\CustomMarshalers.ni.dll
MOD - [2012.05.14 10:20:45 | 002,267,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.In#\581c2fc3b9dffb23020955af33839b2a\Microsoft.Office.Interop.Outlook.ni.dll
MOD - [2012.05.14 10:20:42 | 000,177,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Interop.M#\739c4b6df0732939cef67b3d9964f56a\Microsoft.Interop.Mapi.PropTags.ni.dll
MOD - [2012.05.14 10:20:40 | 000,963,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\office\15c8640cbc8704d22e251f20389fc212\office.ni.dll
MOD - [2012.05.14 10:20:40 | 000,062,976 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Interop.e#\be6b273db7db07786b1776a2dbeaacf9\Microsoft.Interop.eCRM.Ole.ni.dll
MOD - [2012.05.14 10:20:40 | 000,044,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\stdole\d246780b91fd9f6393e85fb13bde94a6\stdole.ni.dll
MOD - [2012.05.14 10:20:39 | 000,152,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Interop.M#\a4bf242f6258d04bd0570c5b7c79f35e\Microsoft.Interop.Mapi.Interfaces.ni.dll
MOD - [2012.05.14 10:20:38 | 000,484,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\BCMCommon\41a94b96546b49a19508e3c1d131bc77\BCMCommon.ni.dll
MOD - [2012.05.14 10:17:33 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012.05.14 10:17:31 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\80fae9f16f80075535e72458ef293f7a\System.Transactions.ni.dll
MOD - [2012.05.14 10:17:30 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll
MOD - [2012.05.14 10:16:34 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012.05.14 10:16:30 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012.05.14 10:16:30 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012.05.14 10:16:21 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2012.02.17 20:55:35 | 000,166,912 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2012.02.17 13:44:10 | 048,060,742 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office.exe
MOD - [2012.02.17 13:44:10 | 001,364,599 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\SSLSocket.dll
MOD - [2012.02.17 13:44:10 | 000,405,504 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\XML.dll
MOD - [2012.02.17 13:44:10 | 000,258,048 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\PostgreSQLPlugin.dll
MOD - [2012.02.17 13:44:10 | 000,223,744 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHPng4101.dll
MOD - [2012.02.17 13:44:10 | 000,151,552 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\RegEx.dll
MOD - [2012.02.17 13:44:10 | 000,139,264 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\Appearance Pak.dll
MOD - [2012.02.17 13:44:10 | 000,120,832 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSPicturePlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,098,304 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\Shell.dll
MOD - [2012.02.17 13:44:10 | 000,098,304 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MD5.dll
MOD - [2012.02.17 13:44:10 | 000,098,304 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\Browser Plugin.dll
MOD - [2012.02.17 13:44:10 | 000,090,112 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHCalCtrl5121.dll
MOD - [2012.02.17 13:44:10 | 000,084,992 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHEffects7511.dll
MOD - [2012.02.17 13:44:10 | 000,073,728 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\Internet Encodings.dll
MOD - [2012.02.17 13:44:10 | 000,069,120 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHZStream10101.dll
MOD - [2012.02.17 13:44:10 | 000,065,536 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSStringPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,065,024 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHEffects37511.dll
MOD - [2012.02.17 13:44:10 | 000,063,488 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHGFShared4101.dll
MOD - [2012.02.17 13:44:10 | 000,059,904 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHTypes6201.dll
MOD - [2012.02.17 13:44:10 | 000,058,880 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSPictureRotatePlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,056,832 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSMainPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,056,832 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHTLStreams6201.dll
MOD - [2012.02.17 13:44:10 | 000,056,320 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHTLEncryption6201.dll
MOD - [2012.02.17 13:44:10 | 000,056,320 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHPEInterfaces7511.dll
MOD - [2012.02.17 13:44:10 | 000,055,808 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSWinPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,055,296 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHZComp10101.dll
MOD - [2012.02.17 13:44:10 | 000,054,784 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCFPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,052,736 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSInternationalWinPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,050,176 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSNotificationPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,048,640 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHAES10101.dll
MOD - [2012.02.17 13:44:10 | 000,047,616 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSSystemInformationPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,046,080 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCGPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,045,056 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSProcessPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,043,520 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSABAddressbookPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,043,008 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHSha210101.dll
MOD - [2012.02.17 13:44:10 | 000,043,008 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHEncrypt10101.dll
MOD - [2012.02.17 13:44:10 | 000,041,984 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSPictureMacPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,040,960 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCallsPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,039,936 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSRegistrationPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,038,400 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSDateDifferencePlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,037,376 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSWinTransPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,035,840 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSScreenshotPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,035,328 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCalendarStorePlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,034,816 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSNSColorPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,033,792 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSMemoryPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,033,792 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSFolderitemsPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,033,792 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCGPDFPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,031,744 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSMacOSXPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,031,744 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCGGeometryPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,031,232 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSNSBasePlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,030,720 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSNSImagePlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,030,720 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSMathPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,030,720 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHBlowf10101.dll
MOD - [2012.02.17 13:44:10 | 000,029,184 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSWindowPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,028,160 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSNSAttributedStringPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,027,648 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCGColorPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,027,136 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCGImagePlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,026,624 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSAppleScriptPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,025,600 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCGDataProviderPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,025,088 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHMacBinary10101.dll
MOD - [2012.02.17 13:44:10 | 000,024,576 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSScreenshotWindowPlugin16724.dll
MOD - [2012.02.17 13:44:10 | 000,024,064 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHBitFuncs6111.dll
MOD - [2012.02.17 13:44:10 | 000,016,384 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHBase6410101.dll
MOD - [2011.10.05 04:52:30 | 000,756,048 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL
MOD - [2011.06.22 12:46:12 | 000,434,016 | ---- | M] () -- C:\Program Files\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll
MOD - [2010.11.13 02:02:22 | 000,434,176 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll
MOD - [2010.11.13 02:02:21 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.11.05 03:58:05 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2010.11.05 03:57:39 | 000,069,120 | ---- | M] () -- C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
MOD - [2010.02.16 15:21:49 | 002,440,144 | ---- | M] () -- C:\Windows\assembly\GAC_32\Microsoft.BusinessSolutions.eCRM.OutlookAddIn.CSUtils\3.0.0.0__31bf3856ad364e35\Microsoft.BusinessSolutions.eCRM.OutlookAddIn.CSUtils.dll
MOD - [2010.02.16 15:21:49 | 000,981,968 | ---- | M] () -- C:\Windows\assembly\GAC_32\Microsoft.BusinessSolutions.eCRM.OutlookAddIn\3.0.0.0__31bf3856ad364e35\Microsoft.BusinessSolutions.eCRM.OutlookAddIn.dll
MOD - [2010.02.16 15:21:49 | 000,591,976 | ---- | M] () -- C:\Windows\assembly\GAC_32\Microsoft.Interop.Mapi.Impl\3.0.0.0__31bf3856ad364e35\Microsoft.Interop.Mapi.Impl.dll
MOD - [2010.02.16 15:21:49 | 000,310,720 | ---- | M] () -- C:\Windows\assembly\GAC_32\BCMCommon\3.0.0.0__31bf3856ad364e35\BCMCommon.dll
MOD - [2010.02.16 15:13:17 | 000,004,608 | ---- | M] () -- C:\Windows\assembly\GAC\Extensibility\7.0.3300.0__b03f5f7f11d50a3a\Extensibility.dll
MOD - [2009.07.17 06:57:02 | 000,055,808 | ---- | M] () -- C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlrmt.dll
MOD - [2009.06.10 23:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009.02.26 14:46:56 | 000,064,344 | ---- | M] () -- C:\Program Files\Microsoft Office\Office12\ADDINS\ColleagueImport.dll
MOD - [2009.02.23 19:51:10 | 000,324,712 | ---- | M] () -- C:\Program Files\Microsoft Small Business\Business Contact Manager\de-DE\BCMRes.resources.dll
MOD - [2008.03.17 17:14:56 | 000,012,112 | ---- | M] () -- C:\Program Files\Microsoft Small Business\Business Contact Manager\de-DE\Microsoft.Interop.Mapi.Interfaces.resources.dll
MOD - [2008.03.17 17:14:38 | 000,068,432 | ---- | M] () -- C:\Program Files\Microsoft Small Business\Business Contact Manager\de-DE\BusinessLayer.resources.dll
 
 
========== Services (SafeList) ==========
 
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SBSDWSCService)
SRV - [2012.09.07 11:52:02 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.08.15 09:31:09 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.05.15 08:44:47 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService)
SRV - [2012.05.15 08:44:47 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.15 08:44:46 | 000,375,760 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService)
SRV - [2012.05.15 08:44:46 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.12.30 12:27:34 | 000,074,752 | ---- | M] (Freemake) [Auto | Running] -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe -- (Freemake Improver)
SRV - [2011.10.21 16:23:42 | 000,196,176 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011.10.13 18:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (BBUpdate)
SRV - [2010.01.15 14:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009.07.17 06:57:36 | 000,026,112 | ---- | M] () [Auto | Running] -- C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE -- (wltrysvc)
SRV - [2009.07.15 20:47:20 | 000,221,266 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\stacsv.exe -- (STacSV)
SRV - [2009.07.14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.06.09 20:33:28 | 000,603,376 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\dkabcoms.exe -- (dkab_device)
SRV - [2009.02.23 19:48:50 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
SRV - [2007.02.12 10:43:44 | 000,065,536 | ---- | M] (O2Micro International) [Auto | Running] -- C:\Windows\System32\drivers\o2flash.exe -- (O2FLASH)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbdev.sys -- (hwusbdev)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard)
DRV - [2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.05.15 08:44:47 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.05.15 08:44:47 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.12.15 16:00:00 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.11.20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.11.20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.04.16 16:22:04 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2009.07.17 06:56:50 | 000,018,424 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bcm42rly.sys -- (BCM42RLY)
DRV - [2009.07.15 20:47:20 | 000,409,088 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2009.07.14 02:18:07 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2009.07.14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009.06.11 16:39:00 | 009,765,568 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009.05.22 11:17:52 | 000,058,528 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\o2mdg.sys -- (O2MDGRDR)
DRV - [2009.05.07 11:47:12 | 000,041,504 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\o2sdg.sys -- (O2SDGRDR)
DRV - [2009.03.24 17:25:24 | 000,197,680 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2008.05.28 18:01:00 | 000,235,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM13Vid.sys -- (OEM13Vid)
DRV - [2007.03.05 11:45:04 | 000,007,424 | ---- | M] (EyePower Games Pte. Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM13Vfx.sys -- (OEM13Vfx)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0B7E6713-EB47-4ED9-AF4E-5E433AE4A9A7}
IE - HKLM\..\SearchScopes\{0B7E6713-EB47-4ED9-AF4E-5E433AE4A9A7}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLSDF8&pc=MDDS&src=IE-SearchBox
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USSMB/8
IE - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\..\SearchScopes,DefaultScope = {0B7E6713-EB47-4ED9-AF4E-5E433AE4A9A7}
IE - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\..\SearchScopes\{8CF8A38F-F1ED-4060-92CF-5FFBD20BA753}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms}
IE - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/ig"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2
FF - prefs.js..extensions.enabledItems: fmconverter@gmail.com:1.0.0
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\npPDFXCviewNPPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@t-immersion.com/DFusionHomeWebPlugIn: C:\Program Files\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll (Total Immersion)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\npPDFXCviewNPPlugin.dll File not found
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmconverter@gmail.com: C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2012.01.09 16:13:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.07 11:52:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.09.07 11:52:00 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.07 11:52:02 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.09.07 11:52:00 | 000,000,000 | ---D | M]
 
[2010.02.22 12:43:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Daniel Kort\AppData\Roaming\mozilla\Extensions
[2012.08.30 17:56:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Daniel Kort\AppData\Roaming\mozilla\Firefox\Profiles\powom3zm.default\extensions
[2012.08.30 17:56:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Daniel Kort\AppData\Roaming\mozilla\Firefox\Profiles\powom3zm.default\extensions\trash
[2012.08.30 17:56:36 | 000,199,396 | ---- | M] () (No name found) -- C:\Users\Daniel Kort\AppData\Roaming\mozilla\firefox\profiles\powom3zm.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
[2012.07.31 10:03:30 | 000,194,632 | ---- | M] () (No name found) -- C:\Users\Daniel Kort\AppData\Roaming\mozilla\firefox\profiles\powom3zm.default\extensions\trash\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
[2012.09.07 11:51:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.09.07 11:51:57 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.09.07 11:52:02 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010.05.12 16:42:04 | 000,124,344 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\CCMSDK.dll
[2010.05.12 16:43:54 | 000,070,592 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\CgpCore.dll
[2010.05.12 16:42:52 | 000,091,576 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\confmgr.dll
[2010.05.12 16:42:32 | 000,022,464 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\ctxlogging.dll
[2010.05.12 17:22:36 | 000,423,328 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npicaN.dll
[1999.12.31 17:00:00 | 000,166,680 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2010.05.12 16:43:56 | 000,024,000 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\TcpPServ.dll
[2012.02.07 19:07:51 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.30 08:21:04 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.02.07 19:07:51 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.07 19:07:51 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.07 19:07:51 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.07 19:07:51 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider:  ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
 
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [DBRMTray] C:\dell\DBRM\Reminder\DbrmTrayicon.exe (Microsoft)
O4 - HKLM..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW File not found
O4 - HKLM..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OEM13Mon.exe] C:\Windows\OEM13Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKU\S-1-5-21-413260923-1584583347-2878145964-1003..\Run: [DKab1err] C:\Program Files\Dell\Printer Software\ErrorApp\dkab1err.exe (Dell, Inc.)
O4 - HKU\S-1-5-21-413260923-1584583347-2878145964-1003..\Run: [Remote Control Editor] "C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe" File not found
O4 - HKU\S-1-5-21-413260923-1584583347-2878145964-1003..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKU\S-1-5-21-413260923-1584583347-2878145964-1003..\Run: [Unified Remote v2] C:\Program Files\Unified Remote\RemoteServer.exe File not found
O4 - HKLM..\RunOnce: [DBRMTray] C:\dell\DBRM\Reminder\TrayApp.exe (Microsoft)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9DA7C255-C3DF-43F5-8E0B-BC2CBA7F9518}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{e925371b-f804-11df-b546-904ce5e0a042}\Shell - "" = AutoRun
O33 - MountPoints2\{e925371b-f804-11df-b546-904ce5e0a042}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{e925372a-f804-11df-b546-904ce5e0a042}\Shell - "" = AutoRun
O33 - MountPoints2\{e925372a-f804-11df-b546-904ce5e0a042}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.07 11:51:57 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012.08.29 14:31:09 | 000,000,000 | ---D | C] -- C:\Users\Daniel Kort\Desktop\SLS PS
[2012.08.29 09:37:06 | 000,000,000 | ---D | C] -- C:\Users\Daniel Kort\Desktop\Nachhaltigkeit
[2012.08.22 10:47:34 | 000,000,000 | ---D | C] -- C:\Users\Daniel Kort\Desktop\SAP_Ebook Schweiz_online.pdf
[2012.08.14 14:26:53 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2 C:\Users\Daniel Kort\Desktop\*.tmp files -> C:\Users\Daniel Kort\Desktop\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.11 12:31:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.11 11:58:54 | 000,711,370 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.09.11 11:58:54 | 000,662,950 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.09.11 11:58:54 | 000,153,766 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.09.11 11:58:54 | 000,124,144 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.09.11 08:18:12 | 000,014,032 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.11 08:18:12 | 000,014,032 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.11 08:09:58 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2012.09.11 08:09:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.11 08:09:46 | 2411,950,080 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.10 16:33:41 | 000,049,787 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\SAPD-1682 Blogstory Vega.pdf
[2012.09.10 12:49:40 | 000,087,123 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\12244_120904_Schild_SAP.pdf
[2012.09.06 10:34:39 | 000,050,384 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\SAPD-1675 Editing SAP HANA Partner Race (1).pdf
[2012.09.05 16:51:55 | 000,049,082 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\Revolver (2).pdf
[2012.09.05 16:10:15 | 000,050,504 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\Revolver (1).pdf
[2012.09.05 15:43:56 | 000,048,630 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\Revolver.pdf
[2012.09.05 15:37:57 | 000,051,268 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\SAPD-1574 Entwicklung und Programmierung Nachhaltigkeitskampagne.pdf
[2012.08.31 11:30:05 | 001,145,499 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\2012-08-13_10-46-24_578.jpg
[2012.08.24 13:58:52 | 000,688,694 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\952_SAP_E-Book-Mobility_inhalt.pdf
[2012.08.23 09:45:42 | 001,777,486 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\xing_mediadata_20120719_de.pdf
[2012.08.16 08:48:16 | 000,580,104 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2 C:\Users\Daniel Kort\Desktop\*.tmp files -> C:\Users\Daniel Kort\Desktop\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.09.10 16:33:41 | 000,049,787 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\SAPD-1682 Blogstory Vega.pdf
[2012.09.10 12:49:40 | 000,087,123 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\12244_120904_Schild_SAP.pdf
[2012.09.06 10:34:39 | 000,050,384 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\SAPD-1675 Editing SAP HANA Partner Race (1).pdf
[2012.09.05 16:51:54 | 000,049,082 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\Revolver (2).pdf
[2012.09.05 16:10:15 | 000,050,504 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\Revolver (1).pdf
[2012.09.05 15:43:56 | 000,048,630 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\Revolver.pdf
[2012.09.05 15:37:57 | 000,051,268 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\SAPD-1574 Entwicklung und Programmierung Nachhaltigkeitskampagne.pdf
[2012.08.31 11:30:05 | 001,145,499 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\2012-08-13_10-46-24_578.jpg
[2012.08.24 13:58:51 | 000,688,694 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\952_SAP_E-Book-Mobility_inhalt.pdf
[2012.08.23 09:45:42 | 001,777,486 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\xing_mediadata_20120719_de.pdf
[2012.05.07 09:40:00 | 000,116,224 | ---- | C] () -- C:\Windows\System32\redmonnt.dll
[2012.05.07 09:40:00 | 000,045,056 | ---- | C] () -- C:\Windows\System32\unredmon.exe
[2012.01.11 12:17:32 | 000,002,048 | -HS- | C] () -- C:\Users\Daniel Kort\AppData\Local\{7c9c6958-a65d-e6bc-5848-15b770ab5998}\@
[2011.09.08 14:46:59 | 000,072,080 | ---- | C] () -- C:\Users\Daniel Kort\g2mdlhlpx.exe
[2011.07.13 16:00:59 | 000,015,418 | ---- | C] () -- C:\Users\Daniel Kort\.TransferManager.db
[2011.06.22 09:02:50 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2010.11.17 12:22:55 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2010.10.28 10:01:06 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2010.04.01 11:54:19 | 000,006,144 | ---- | C] () -- C:\Users\Daniel Kort\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.02.22 12:52:07 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
 
========== LOP Check ==========
 
[2011.06.10 15:12:58 | 000,000,000 | ---D | M] -- C:\Users\Bewerber\AppData\Roaming\ICAClient
[2012.05.07 09:39:59 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\FreePDF
[2011.06.03 15:56:47 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\ICAClient
[2011.03.10 17:35:41 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\PixelPlanet
[2011.09.01 16:57:24 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Revolver Preferences
[2010.04.14 11:01:08 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\TerraTec
[2011.07.07 15:21:35 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Total Immersion
[2010.05.04 13:15:08 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\TuneUp Software
[2011.10.21 18:49:44 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Unified Remote
[2012.05.10 08:38:17 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.09.27 14:45:35 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Adobe
[2012.06.06 08:39:56 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Apple Computer
[2012.02.16 09:10:48 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Avira
[2010.02.23 09:40:35 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\CyberLink
[2010.07.01 13:20:39 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\DivX
[2010.09.22 08:55:59 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\FastStone
[2012.05.07 09:39:59 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\FreePDF
[2011.06.03 15:56:47 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\ICAClient
[2010.02.22 11:44:24 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Identities
[2012.02.10 18:37:17 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\InstallShield
[2010.02.22 11:58:33 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Macromedia
[2012.07.03 13:45:45 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Malwarebytes
[2009.07.14 10:56:56 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Media Center Programs
[2012.05.18 12:42:28 | 000,000,000 | --SD | M] -- C:\Users\Daniel Kort\AppData\Roaming\Microsoft
[2010.02.22 12:43:16 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Mozilla
[2011.03.10 17:35:41 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\PixelPlanet
[2011.09.01 16:57:24 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Revolver Preferences
[2010.04.01 20:50:12 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Roxio
[2012.09.11 13:20:25 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Skype
[2011.07.11 08:38:59 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\skypePM
[2010.04.14 11:01:08 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\TerraTec
[2011.07.07 15:21:35 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Total Immersion
[2010.05.04 13:15:08 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\TuneUp Software
[2011.10.21 18:49:44 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Unified Remote
[2012.03.07 16:42:11 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\vlc
[2012.06.08 10:21:54 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2011.11.15 15:02:18 | 005,147,880 | ---- | M] (Adobe Systems, Inc.) -- C:\Users\Daniel Kort\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectaddin.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Drivers\storage\R229669\IaStor.sys
[2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\drivers\iaStor.sys
[2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_4f144d6467fc7c22\iaStor.sys
[2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_x86_neutral_10aa509d6843c6fc\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\drivers\iaStorV.sys
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys
[2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys
[2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\drivers\nvstor.sys
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys
[2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\System32\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2012.07.03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

--- --- ---
[/code]
:dankeschoen:

cosinus 11.09.2012 16:58

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
FF - user.js - File not found
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{e925371b-f804-11df-b546-904ce5e0a042}\Shell - "" = AutoRun
O33 - MountPoints2\{e925371b-f804-11df-b546-904ce5e0a042}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{e925372a-f804-11df-b546-904ce5e0a042}\Shell - "" = AutoRun
O33 - MountPoints2\{e925372a-f804-11df-b546-904ce5e0a042}\Shell\AutoRun\command - "" = E:\AutoRun.exe
:Files
C:\Users\Daniel Kort\AppData\Local\{7c9c6958-a65d-e6bc-5848-15b770ab5998}
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

metaldakster 12.09.2012 08:31

Code:

All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-21-413260923-1584583347-2878145964-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e925371b-f804-11df-b546-904ce5e0a042}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e925371b-f804-11df-b546-904ce5e0a042}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e925371b-f804-11df-b546-904ce5e0a042}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e925371b-f804-11df-b546-904ce5e0a042}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e925372a-f804-11df-b546-904ce5e0a042}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e925372a-f804-11df-b546-904ce5e0a042}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e925372a-f804-11df-b546-904ce5e0a042}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e925372a-f804-11df-b546-904ce5e0a042}\ not found.
File E:\AutoRun.exe not found.
========== FILES ==========
C:\Users\Daniel Kort\AppData\Local\{7c9c6958-a65d-e6bc-5848-15b770ab5998}\U folder moved successfully.
C:\Users\Daniel Kort\AppData\Local\{7c9c6958-a65d-e6bc-5848-15b770ab5998}\L folder moved successfully.
C:\Users\Daniel Kort\AppData\Local\{7c9c6958-a65d-e6bc-5848-15b770ab5998} folder moved successfully.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Daniel Kort\Downloads\cmd.bat deleted successfully.
C:\Users\Daniel Kort\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Bewerber
->Temp folder emptied: 45426 bytes
->Temporary Internet Files folder emptied: 2094961 bytes
->Flash cache emptied: 405 bytes
 
User: Daniel Kort
->Temp folder emptied: 79674983 bytes
->Temporary Internet Files folder emptied: 1740404159 bytes
->Java cache emptied: 5531997 bytes
->FireFox cache emptied: 1116988910 bytes
->Google Chrome cache emptied: 5177696 bytes
->Flash cache emptied: 5425486 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2692234 bytes
RecycleBin emptied: 1214826686 bytes
 
Total Files Cleaned = 3.980,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.61.3 log created on 09122012_091307

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Hi Cosinus,

jetzt hat er schon wieder einiges gelöscht. Ich hätte nicht gedacht, dass so viele Dateien betroffen sind. Könnte immer noch was drauf sein?

:dankeschoen:

Viele Grüße
Daniel

cosinus 12.09.2012 13:57

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

metaldakster 14.09.2012 08:09

Hallo Cosinus,

zwei Dateien hat er wieder gefunden. Bisher habe ich nur den Scan durchgeführt.

:dankeschoen:

cosinus 14.09.2012 15:06

Irgendwie ist das Log unvollständig - die untere Zusammenfassung was gefunden wurde fehlt, da steht nur dass zwei Elemente gefunden wurden :wtf:

metaldakster 17.09.2012 16:26

Hallo Cosinus,

ich habe die Orginaldatei noch einmal gezippt. Jetzt müsste es passen.

Beste Grüße
Daniel

cosinus 17.09.2012 20:31

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

metaldakster 20.09.2012 17:20

Hallo Cosinus,

anbei findest du das Log.

Code:

ComboFix 12-09-20.01 - Daniel Kort 20.09.2012  18:01:08.1.2 - x86
Microsoft Windows 7 Professional  6.1.7601.1.1252.49.1031.18.3067.1566 [GMT 2:00]
ausgeführt von:: c:\users\Daniel Kort\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum
c:\users\Daniel Kort\g2mdlhlpx.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-08-20 bis 2012-09-20  ))))))))))))))))))))))))))))))
.
.
2012-09-20 16:10 . 2012-09-20 16:10        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-09-20 16:10 . 2012-09-20 16:10        --------        d-----w-        c:\users\Bewerber\AppData\Local\temp
2012-09-20 10:32 . 2012-09-20 10:32        56200        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{906DA589-204C-4F9B-9500-C37432BE97CE}\offreg.dll
2012-09-18 07:02 . 2012-08-23 07:15        7022536        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{906DA589-204C-4F9B-9500-C37432BE97CE}\mpengine.dll
2012-09-12 12:34 . 2012-08-22 17:16        1292144        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-09-12 12:34 . 2012-08-22 17:16        712048        ----a-w-        c:\windows\system32\drivers\ndis.sys
2012-09-12 12:34 . 2012-08-22 17:16        240496        ----a-w-        c:\windows\system32\drivers\netio.sys
2012-09-12 12:34 . 2012-08-22 17:16        187760        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 12:34 . 2012-07-04 19:45        33280        ----a-w-        c:\windows\system32\drivers\RNDISMP.sys
2012-09-12 12:34 . 2012-08-02 16:57        490496        ----a-w-        c:\windows\system32\d3d10level9.dll
2012-09-12 07:13 . 2012-09-12 07:13        --------        d-----w-        C:\_OTL
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-20 06:32 . 2012-03-30 06:14        696240        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-09-20 06:32 . 2011-05-18 06:41        73136        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-18 17:47 . 2012-08-15 06:49        2345984        ----a-w-        c:\windows\system32\win32k.sys
2012-07-06 19:23 . 2012-08-15 16:09        393728        ----a-w-        c:\windows\system32\drivers\bthport.sys
2012-07-04 21:14 . 2012-08-15 06:49        41984        ----a-w-        c:\windows\system32\browcli.dll
2012-07-04 21:14 . 2012-08-15 06:49        102912        ----a-w-        c:\windows\system32\browser.dll
2012-06-27 05:53 . 2012-08-15 06:49        981504        ----a-w-        c:\windows\system32\wininet.dll
2012-06-27 04:10 . 2012-08-15 06:49        1638912        ----a-w-        c:\windows\system32\mshtml.tlb
2010-05-12 14:42 . 2012-09-07 09:51        124344        ----a-w-        c:\program files\mozilla firefox\plugins\CCMSDK.dll
2010-05-12 15:22 . 2012-09-07 09:51        13240        ----a-w-        c:\program files\mozilla firefox\plugins\cgpcfg.dll
2010-05-12 14:43 . 2012-09-07 09:51        70592        ----a-w-        c:\program files\mozilla firefox\plugins\CgpCore.dll
2010-05-12 14:42 . 2012-09-07 09:51        91576        ----a-w-        c:\program files\mozilla firefox\plugins\confmgr.dll
2010-05-12 14:42 . 2012-09-07 09:51        22464        ----a-w-        c:\program files\mozilla firefox\plugins\ctxlogging.dll
2010-05-12 14:41 . 2012-09-07 09:51        255416        ----a-w-        c:\program files\mozilla firefox\plugins\ctxmui.dll
2010-05-12 14:42 . 2012-09-07 09:51        31160        ----a-w-        c:\program files\mozilla firefox\plugins\icafile.dll
2010-05-12 14:42 . 2012-09-07 09:51        40384        ----a-w-        c:\program files\mozilla firefox\plugins\icalogon.dll
2010-04-14 11:55 . 2012-09-07 09:52        652640        ----a-w-        c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2010-05-12 14:43 . 2012-09-07 09:52        24000        ----a-w-        c:\program files\mozilla firefox\plugins\TcpPServ.dll
2012-09-07 09:52 . 2012-09-07 09:51        266720        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DKab1err"="c:\program files\Dell\Printer Software\ErrorApp\DKab1err.exe" [2009-06-09 582896]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-06-29 217088]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-07-15 458844]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-11 13789728]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2009-06-11 92704]
"Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4562944]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]
"OEM13Mon.exe"="c:\windows\OEM13Mon.exe" [2008-01-07 36864]
"DBRMTray"="c:\dell\DBRM\Reminder\DbrmTrayIcon.exe" [2009-11-12 203776]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-05-12 300472]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-08-10 348664]
"FreePDF Assistant"="c:\program files\FreePDF_XP\fpassist.exe" [2011-02-23 371200]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DBRMTray"="c:\dell\DBRM\Reminder\TrayApp.exe" [2009-10-17 7168]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
R2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [x]
R2 Freemake Improver;Freemake Improver;c:\programdata\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.207\McCHSvc.exe [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WSDPrintDevice;WSD-Druckunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AntiVirMailService;Avira Email Schutz;c:\program files\Avira\AntiVir Desktop\avmailc.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
S2 AntiVirWebService;Avira Browser Schutz;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [x]
S2 dkab_device;dkab_device;c:\windows\system32\DKabcoms.exe [x]
S3 O2MDGRDR;O2MDGRDR;c:\windows\system32\DRIVERS\o2mdg.sys [x]
S3 O2SDGRDR;O2SDGRDR;c:\windows\system32\DRIVERS\o2sdg.sys [x]
S3 OEM13Vfx;Creative Camera OEM013 Video VFX Driver;c:\windows\system32\DRIVERS\OEM13Vfx.sys [x]
S3 OEM13Vid;Creative Camera OEM013 Driver;c:\windows\system32\DRIVERS\OEM13Vid.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 06:32]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = about:blank
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Daniel Kort\AppData\Roaming\Mozilla\Firefox\Profiles\powom3zm.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKCU-Run-Remote Control Editor - c:\program files\Common Files\TerraTec\Remote\TTTvRc.exe
HKCU-Run-Unified Remote v2 - c:\program files\Unified Remote\RemoteServer.exe
HKLM-Run-DivXUpdate - c:\program files\DivX\DivX Update\DivXUpdate.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-09-20  18:18:56
ComboFix-quarantined-files.txt  2012-09-20 16:18
.
Vor Suchlauf: 11 Verzeichnis(se), 248.342.691.840 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 248.136.314.880 Bytes frei
.
- - End Of File - - A8144EE2681B99D8793DAD3076D42376


cosinus 20.09.2012 21:39

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

metaldakster 22.10.2012 11:17

Hallo Cosinus,

zwei Logs habe ich Dir angehängt. Bei Osam erhalte ich folgendes Log:

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 12:14:23 on 22.10.2012
OS: Windows 7 Service Pack 1 (Build 7601), 32-bit
Default Browser: Mozilla Corporation Firefox 15.0.1

Scanner Settings
Rootkits detection (hidden registry)
Rootkits detection (hidden files)
Retrieve files information
Check Microsoft signatures

Filters
Trusted entries
Empty entries
Hidden registry entries (rootkit activity)
Exclusively opened files
Not found files
Files without detailed information
Existing files
Non-startable services
Non-startable drivers
Active entries
Disabled entries

          Risk        Name        Publisher        Full Path        Status
Common
%SystemRoot%\Tasks
        ||||||        "Adobe Flash Player Updater.job"        "Adobe Systems Incorporated"        C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe        File exists
Control Panel Objects
%SystemRoot%\system32
        ||||||        "BCMWLCPL.CPL"        "Dell Inc."        C:\Windows\system32\BCMWLCPL.CPL        File exists
        ||||||        "DivXControlPanelApplet.cpl"        "DivX, Inc."        C:\Windows\system32\DivXControlPanelApplet.cpl        File exists
                      "FlashPlayerCPLApp.cpl"        "Adobe Systems Incorporated"        C:\Windows\system32\FlashPlayerCPLApp.cpl        File exists
        ||||||        "nvcpl.cpl"        "NVIDIA Corporation"        C:\Windows\system32\nvcpl.cpl        File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls
        ||||||        "bcmwlcpl.cpl"        "Dell Inc."        C:\Windows\System32\bcmwlcpl.cpl        File exists
        ||||||        "mlcfg32.cpl"        "Microsoft Corporation"        C:\PROGRA~1\MICROS~1\Office12\MLCFG32.CPL        File exists
                      "QuickTime"        "Apple Inc."        C:\Program Files\QuickTime\QTSystem\QuickTime.cpl        File exists
Drivers
HKLM\SYSTEM\CurrentControlSet\Services
                      "aswMBR" (aswMBR)                C:\Users\DANIEL~1\AppData\Local\Temp\aswMBR.sys        Hidden registry entry, rootkit activity | File not found
                      "avgntflt" (avgntflt)        "Avira GmbH"        C:\Windows\System32\DRIVERS\avgntflt.sys        File exists
                      "avipbb" (avipbb)        "Avira GmbH"        C:\Windows\System32\DRIVERS\avipbb.sys        File exists
        ||||||        "avkmgr" (avkmgr)        "Avira GmbH"        C:\Windows\System32\DRIVERS\avkmgr.sys        File exists
        ||||||        "BCM42RLY" (BCM42RLY)        "Broadcom Corporation"        C:\Windows\System32\drivers\BCM42RLY.sys        File exists
                      "catchme" (catchme)                C:\Users\DANIEL~1\AppData\Local\Temp\catchme.sys        File not found
        ||||||        "Citrix USB Monitor Driver" (ctxusbm)        "Citrix Systems, Inc."        C:\Windows\System32\DRIVERS\ctxusbm.sys        File exists
                      "Huawei DataCard USB Modem and USB Serial" (hwdatacard)                C:\Windows\System32\DRIVERS\ewusbmdm.sys        File not found
                      "Huawei DataCard USB PNP Device" (hwusbdev)                C:\Windows\System32\DRIVERS\ewusbdev.sys        File not found
                      "kgddypoc" (kgddypoc)        "GMER"        C:\kgddypoc.sys        Hidden registry entry, rootkit activity
        ||||||        "PxHelp20" (PxHelp20)        "Sonic Solutions"        C:\Windows\System32\Drivers\PxHelp20.sys        File exists
        ||||||        "ssmdrv" (ssmdrv)        "Avira GmbH"        C:\Windows\System32\DRIVERS\ssmdrv.sys        File exists
Explorer
HKLM\Software\Classes\Folder\shellex\ColumnHandlers
        ||||||        {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension"        "Adobe Systems, Inc."        C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll        File exists
HKLM\Software\Classes\Protocols\Filter
        ||||||        {CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class"        "Citrix Systems, Inc."        C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll        File exists
        ||||||        {CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class"        "Citrix Systems, Inc."        C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll        File exists
        ||||||        {807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter"        "Microsoft Corporation"        C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL        File exists
HKLM\Software\Classes\Protocols\Handler
        ||||||        {32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler"        "Microsoft Corporation"        C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL        File exists
        ||||||        {314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class"        "Microsoft Corporation"        C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll        File exists
        ||||||        {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class"        "Skype Technologies"        C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL        File exists
        ||||          {91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol"        "Skype Technologies S.A."        C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll        File exists
        ||||||        {03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler"        "Microsoft Corporation"        C:\Program Files\Windows Live\Mail\mailcomm.dll        File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
        ||||||        {0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter"        "Microsoft Corporation"        C:\Program Files\Windows Live\Mail\mailcomm.dll        File exists
        ||||||        {A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class"        "NVIDIA Corporation"        C:\Windows\system32\nvcpl.dll        File exists
        ||            {D8D1CE8C-B1EB-4E95-B63B-1531BA60E992} "DivX Property Handler"        "DivX, Inc."        C:\Program Files\DivX\DivX Plus Media Foundation Components\DivXPropertyHandler.dll        File exists
        ||            {83238FAE-D346-4E12-8734-D42F7554B3E6} "DivX Thumbnail Provider"        "DivX, Inc."        C:\Program Files\DivX\DivX Plus Media Foundation Components\DivXThumbnailProvider.dll        File exists
        ||||||        {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler"        "Microsoft Corporation"        C:\Program Files\Microsoft Office\Office12\msohevi.dll        File exists
        ||||||        {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler"        "Microsoft Corporation"        C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll        File exists
        ||||||        {00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook"        "Microsoft Corporation"        C:\PROGRA~1\MICROS~1\Office12\MLSHEXT.DLL        File exists
        ||||||        {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler"        "Microsoft Corporation"        C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll        File exists
        ||||||        {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension"        "NVIDIA Corporation"        C:\Windows\system32\nvshext.dll        File exists
        ||||||        {FFB699E0-306A-11d3-8BD1-00104B6F7516} "NVIDIA CPL Extension"        "NVIDIA Corporation"        C:\Windows\system32\nvcpl.dll        File exists
                      {0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension"        "Microsoft Corporation"        C:\PROGRA~1\MICROS~1\Office12\OLKFSTUB.DLL        File exists
                      {1AC06E4B-5A0A-4B62-B24A-F48389402CCE} "PowerLame"                        File not found | COM-object registry key not found
                      {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning"        "Avira Operations GmbH & Co. KG"        C:\Program Files\Avira\AntiVir Desktop\shlext.dll        File exists
        ||||||        {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target"        "Microsoft Corporation"        C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe        File exists
        ||||||        {00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target"        "Microsoft Corporation"        C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe        File exists
        ||||||        {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim"        "Microsoft Corporation"        C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll        File exists
        ||||||        {00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim"        "Microsoft Corporation"        C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll        File exists
        ||||||        {00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim"        "Microsoft Corporation"        C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll        File exists
        ||||||        {00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target"        "Microsoft Corporation"        C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe        File exists
        ||||||        {00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim"        "Microsoft Corporation"        C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll        File exists
                      {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR"        "Alexander Roshal"        C:\Program Files\WinRAR\rarext.dll        File exists
        ||||||        {06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}"        "Microsoft Corporation"        C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe        File exists
Internet Explorer
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
                      ITBar7Height "ITBar7Height"                        File not found | COM-object registry key not found
                      "ITBar7Layout"                        File not found | COM-object registry key not found
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
        ||||          {5F7B1267-94A9-47F5-98DB-E99415F33AEC} "In Blog veröffentlichen"        "Microsoft Corporation"        C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll        File exists
        ||            {FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research"        "Microsoft Corporation"        C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL        File exists
        ||||          {898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call"        "Skype Technologies S.A."        C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll        File exists
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
        ||||          {8dcb7100-df86-4384-8842-8fa844297b3f} "Bing Bar"        "Microsoft Corporation."        C:\Program Files\Microsoft\BingBar\BingExt.dll        File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
        ||||||        {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper"        "Adobe Systems Incorporated"        C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll        File exists
        ||||          {d2ce3e00-f94a-4740-988e-03dc2f38c34f} "Bing Bar Helper"        "Microsoft Corporation."        C:\Program Files\Microsoft\BingBar\BingExt.dll        File exists
                      {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper"                C:\Program Files\Java\jre6\bin\jp2ssv.dll        File not found
        ||||          {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper"        "Skype Technologies S.A."        C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll        File exists
                      {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"                        File not found | COM-object registry key not found
Logon
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
        ||||||        "desktop.ini"                C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini        File exists
%AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup
        ||||||        "desktop.ini"                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini        File exists
        ||||          "Google Calendar Sync.lnk"        "Google"        C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe        Shortcut exists | File exists
                      "McAfee Security Scan Plus.lnk"        "McAfee, Inc."        C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe        Shortcut exists | File exists
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
                      "DKab1err"        "Dell, Inc."        C:\Program Files\Dell\Printer Software\ErrorApp\DKab1err.exe        File exists
        ||||          "Skype"        "Skype Technologies S.A."        "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun        File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
        ||||          "Adobe ARM"        "Adobe Systems Incorporated"        "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"        File exists
                      "APSDaemon"        "Apple Inc."        "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"        File exists
                      "avgnt"        "Avira Operations GmbH & Co. KG"        "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min        File exists
        ||||          "Broadcom Wireless Manager UI"        "Dell Inc."        C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe        File exists
        ||||          "ConnectionCenter"        "Citrix Systems, Inc."        "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup        File exists
                      "DBRMTray"        "Microsoft"        C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe        File exists
                      "FreePDF Assistant"        "shbox.de"        "C:\Program Files\FreePDF_XP\fpassist.exe"        File exists
        ||||||        "NvCplDaemon"        "NVIDIA Corporation"        RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup        File exists
                      "NVHotkey"        "NVIDIA Corporation"        rundll32.exe C:\Windows\system32\nvHotkey.dll,Start        File exists
        ||||          "PDVDDXSrv"        "CyberLink Corp."        "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"        File exists
                      "QuickTime Task"        "Apple Inc."        "C:\Program Files\QuickTime\QTTask.exe" -atboottime        File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
                      "DBRMTray"        "Microsoft"        C:\Dell\DBRM\Reminder\TrayApp.exe        File exists
Network Providers
HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
        ||||||        "Dell Wireless WLAN Card Logon Provider"        "Dell Inc."        C:\Windows\System32\BCMLogon.dll        File exists
Print Monitors
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
                      "Dell Enhanced TCP/IP Port"        " "        C:\Windows\system32\dkablmpm.dll        File exists
        ||||||        "Redirected Port"                C:\Windows\system32\redmonnt.dll        File found, but it contains no detailed information
Services
HKLM\SYSTEM\CurrentControlSet\Services
        ||            "Adobe Acrobat Update Service" (AdobeARMservice)        "Adobe Systems Incorporated"        C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe        File exists
        ||||||        "Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc)        "Adobe Systems Incorporated"        C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe        File exists
                      "Avira Browser Schutz" (AntiVirWebService)        "Avira Operations GmbH & Co. KG"        C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE        File exists
                      "Avira Echtzeit Scanner" (AntiVirService)        "Avira Operations GmbH & Co. KG"        C:\Program Files\Avira\AntiVir Desktop\avguard.exe        File exists
                      "Avira Email Schutz" (AntiVirMailService)        "Avira Operations GmbH & Co. KG"        C:\Program Files\Avira\AntiVir Desktop\avmailc.exe        File exists
                      "Avira Planer" (AntiVirSchedulerService)        "Avira Operations GmbH & Co. KG"        C:\Program Files\Avira\AntiVir Desktop\sched.exe        File exists
        ||||||        "BBUpdate" (BBUpdate)        "Microsoft Corporation"        C:\Program Files\Microsoft\BingBar\SeaPort.EXE        File exists
        ||||          "Bing Bar Update Service" (BBSvc)        "Microsoft Corporation."        C:\Program Files\Microsoft\BingBar\BBSvc.EXE        File exists
        ||||||        "Dell Wireless WLAN Tray Service" (wltrysvc)                C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE        File found, but it contains no detailed information
                      "dkab_device" (dkab_device)        " "        C:\Windows\system32\DKabcoms.exe        File exists
                      "Freemake Improver" (Freemake Improver)        "Freemake"        C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe        File exists
        ||||||        "McAfee Security Scan Component Host Service" (McComponentHostService)        "McAfee, Inc."        C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe        File exists
        ||||||        "Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32)        "Microsoft Corporation"        C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe        File exists
        ||||||        "Microsoft Office Diagnostics Service" (odserv)        "Microsoft Corporation"        C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE        File exists
                      "Mozilla Maintenance Service" (MozillaMaintenance)        "Mozilla Foundation"        C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe        File exists
        ||||||        "NVIDIA Display Driver Service" (nvsvc)        "NVIDIA Corporation"        C:\Windows\system32\nvvsvc.exe        File exists
        ||||||        "Office Source Engine" (ose)        "Microsoft Corporation"        C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE        File exists
        ||||||        "Skype Updater" (SkypeUpdate)        "Skype Technologies"        C:\Program Files\Skype\Updater\Updater.exe        File exists
        ||||||        "SQL Server (MSSMLBIZ)" (MSSQL$MSSMLBIZ)        "Microsoft Corporation"        c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe        File exists
        ||||||        "SQL Server VSS Writer" (SQLWriter)        "Microsoft Corporation"        c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe        File exists
        ||||||        "SQL Server-Browser" (SQLBrowser)        "Microsoft Corporation"        c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe        File exists
        ||||||        "SQL Server-Startdienst für Business Contact Manager" (BcmSqlStartupSvc)        "Microsoft Corporation"        C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe        File exists
        ||||||        "stllssvr" (stllssvr)        "MicroVision Development, Inc."        C:\Program Files\Common Files\SureThing Shared\stllssvr.exe        File exists
Winsock Providers
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries
                      "AVSDA"        "Avira Operations GmbH & Co. KG"        C:\Program Files\Avira\AntiVir Desktop\avsda.dll        File exists

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

Dank Dir!

cosinus 22.10.2012 12:21

WArum denn jetzt im Anhang, poste bitte alle Log direkt und in CODE-Tags

metaldakster 22.10.2012 13:40

Kein Problem. Hier kommt GMER:

Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-10-22 11:10:24
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.FC4O
Running: 3xbfbk21.exe; Driver: C:\Users\DANIEL~1\AppData\Local\Temp\kgddypoc.sys


---- System - GMER 1.0.15 ----

SSDT            914E2A26                                                                                                                      ZwCreateSection
SSDT            914E2A30                                                                                                                      ZwRequestWaitReplyPort
SSDT            914E2A2B                                                                                                                      ZwSetContextThread
SSDT            914E2A35                                                                                                                      ZwSetSecurityObject
SSDT            914E2A3A                                                                                                                      ZwSystemDebugControl
SSDT            914E29C7                                                                                                                      ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text          ntkrnlpa.exe!ZwRollbackEnlistment + 140D                                                                                      82E76A49 1 Byte  [06]
.text          ntkrnlpa.exe!KiDispatchInterrupt + 5A2                                                                                        82EB04D2 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text          ntkrnlpa.exe!KeRemoveQueueEx + 11F7                                                                                            82EB762C 4 Bytes  [26, 2A, 4E, 91] {SUB CL, ES:[ESI-0x6f]}
.text          ntkrnlpa.exe!KeRemoveQueueEx + 1553                                                                                            82EB7988 4 Bytes  [30, 2A, 4E, 91] {XOR [EDX], CH; DEC ESI; XCHG ECX, EAX}
.text          ntkrnlpa.exe!KeRemoveQueueEx + 1597                                                                                            82EB79CC 4 Bytes  [2B, 2A, 4E, 91] {SUB EBP, [EDX]; DEC ESI; XCHG ECX, EAX}
.text          ntkrnlpa.exe!KeRemoveQueueEx + 1613                                                                                            82EB7A48 4 Bytes  [35, 2A, 4E, 91]
.text          ntkrnlpa.exe!KeRemoveQueueEx + 1667                                                                                            82EB7A9C 4 Bytes  [3A, 2A, 4E, 91] {CMP CH, [EDX]; DEC ESI; XCHG ECX, EAX}
.text          ...                                                                                                                           
PAGE            spsys.sys!?SPRevision@@3PADA + 4F90                                                                                            A00E5000 290 Bytes  [8B, FF, 55, 8B, EC, 33, C0, ...]
PAGE            spsys.sys!?SPRevision@@3PADA + 50B3                                                                                            A00E5123 629 Bytes  [05, 0E, A0, FE, 05, 34, 05, ...]
PAGE            spsys.sys!?SPRevision@@3PADA + 5329                                                                                            A00E5399 101 Bytes  [6A, 28, 59, A5, 5E, C6, 03, ...]
PAGE            spsys.sys!?SPRevision@@3PADA + 538F                                                                                            A00E53FF 148 Bytes  [18, 5D, C2, 14, 00, 8B, FF, ...]
PAGE            spsys.sys!?SPRevision@@3PADA + 543B                                                                                            A00E54AB 2228 Bytes  [8B, FF, 55, 8B, EC, FF, 75, ...]
PAGE            ...                                                                                                                           

---- User code sections - GMER 1.0.15 ----

.text          C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[2248] kernel32.dll!SetUnhandledExceptionFilter                          7637F4FB 5 Bytes  JMP 5F1450B8 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
.text          C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[2248] ole32.dll!OleLoadFromStream                                      77206143 5 Bytes  JMP 5FC0E11A C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
.text          C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[4432] kernel32.dll!SetUnhandledExceptionFilter                          7637F4FB 5 Bytes  JMP 5F1450B8 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
.text          C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[4432] ole32.dll!OleLoadFromStream                                      77206143 5 Bytes  JMP 5FC0E11A C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)

---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[2248] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress]  [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[2248] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]    [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[2248] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]    [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[2248] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]  [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[2248] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress]  [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                                [746224CB] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                          [7460562E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                          [746056EC] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                                [74622546] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                                      [746185AA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                                        [74614D5E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                                        [74615105] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                                      [746151DA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP]                              [74616707] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                                        [74618301] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                                  [74618850] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                                [746190B1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                                      [7461E254] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                          [74614C90] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\System32\rundll32.exe[4064] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]                          [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Windows\System32\rundll32.exe[4064] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]                          [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Windows\System32\rundll32.exe[4064] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress]                        [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Windows\System32\rundll32.exe[4064] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]                        [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[4432] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress]  [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[4432] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]    [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[4432] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]    [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[4432] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]  [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[4432] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress]  [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[4432] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress]  [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[4432] @ C:\Windows\system32\SECUR32.DLL [KERNEL32.dll!GetProcAddress]  [75B9FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                                                        fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                                                        rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                                                        fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                                                        rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                                                        fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                                                        rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device          \Driver\BTHUSB \Device\00000078                                                                                                bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device          \Driver\ACPI_HAL \Device\0000004d                                                                                              halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device          \Driver\BTHUSB \Device\0000007a                                                                                                bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)

AttachedDevice  \FileSystem\fastfat \Fat                                                                                                      fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
AttachedDevice  \FileSystem\fastfat \Fat                                                                                                      fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)

---- Threads - GMER 1.0.15 ----

Thread          System [4:6084]                                                                                                                A00F2F2E

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\904ce5e0a042                                                   
Reg            HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{E9D31056-D588-4780-9B7E-9F6DC1857DFD}@InterfaceName        isatap.{E5C8C42F-560E-44DC-9ED7-EF3C023EC3F3}
Reg            HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{E9D31056-D588-4780-9B7E-9F6DC1857DFD}@ReusableType          0
Reg            HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\904ce5e0a042 (not active ControlSet)                               

---- Files - GMER 1.0.15 ----

File            C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00F45.log                                                        1048576 bytes
File            C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00F46.log                                                        0 bytes
File            C:\Users\Daniel Kort\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3AA9CA5C.dat                        0 bytes

---- EOF - GMER 1.0.15 ----

Und ASW:

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-10-22 11:38:35
-----------------------------
11:38:35.604    OS Version: Windows 6.1.7601 Service Pack 1
11:38:35.604    Number of processors: 2 586 0x170A
11:38:35.606    ComputerName: DANIELKORTH-PC  UserName: Daniel Kort
11:38:36.931    Initialize success
11:38:51.108    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
11:38:51.111    Disk 0 Vendor: Hitachi_ FC4O Size: 305245MB BusType: 3
11:38:51.199    Disk 0 MBR read successfully
11:38:51.207    Disk 0 MBR scan
11:38:51.214    Disk 0 Windows VISTA default MBR code
11:38:51.309    Disk 0 Partition 1 00    DE Dell Utility Dell 8.0      39 MB offset 63
11:38:51.366    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        15000 MB offset 81920
11:38:51.396    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      290204 MB offset 30801920
11:38:51.435    Disk 0 scanning sectors +625140400
11:38:51.774    Disk 0 scanning C:\Windows\system32\drivers
11:40:09.976    Service scanning
11:40:27.108    Modules scanning
11:42:24.790    Disk 0 trace - called modules:
11:42:24.839    ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys halmacpi.dll
11:42:24.841    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86d03718]
11:42:24.841    3 CLASSPNP.SYS[8b9c159e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x862ba028]
11:42:24.842    Scan finished successfully
11:46:20.905    Disk 0 MBR has been saved successfully to "C:\Users\Daniel Kort\Desktop\MBR.dat"
11:46:20.911    The log file has been saved successfully to "C:\Users\Daniel Kort\Desktop\aswMBR.txt"


cosinus 22.10.2012 14:27

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

metaldakster 05.11.2012 17:52

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 11/05/2012 at 05:38 PM

Application Version : 5.6.1014

Core Rules Database Version : 9529
Trace Rules Database Version: 7341

Scan type      : Quick Scan
Total Scan Time : 00:09:19

Operating System Information
Windows 7 Professional 32-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 935
Memory threats detected  : 0
Registry items scanned    : 30602
Registry threats detected : 0
File items scanned        : 8195
File threats detected    : 604

Adware.Tracking Cookie
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\daniel_kort@adx.chip[2].txt [ /adx.chip ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\MXK51CNI.txt [ /questionmarket.com ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\MHWAYLTX.txt [ /atdmt.com ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\87Y02FYX.txt [ /adfarm1.adition.com ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\L2XZU31Y.txt [ /adform.net ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\YXJEIKPR.txt [ /bs.serving-sys.com ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\26L3USJR.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\VMYCPS90.txt [ /ads.creative-serving.com ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\DKVMJ4D3.txt [ /smartadserver.com ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\Z0DM1835.txt [ /ad.zanox.com ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\2JB17Q4E.txt [ /doubleclick.net ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\6ATJO5WC.txt [ /imrworldwide.com ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\GGU3Y3BJ.txt [ /eas.apm.emediate.eu ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\F3IQF87J.txt [ /dyntracker.com ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\V7DH8LWD.txt [ /invitemedia.com ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\OZCY2V3W.txt [ /serving-sys.com ]
        .invitemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\TL3OVYJR.txt [ /track.adform.net ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\IS5M5YU9.txt [ /c.atdmt.com ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\NQSZZI9F.txt [ /zanox.com ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\DJA8SI7F.txt [ /www.etracker.de ]
        C:\Users\Daniel Kort\AppData\Roaming\Microsoft\Windows\Cookies\GQH9JDTI.txt [ /2o7.net ]
        C:\USERS\BEWERBER\AppData\Roaming\Microsoft\Windows\Cookies\Low\bewerber@doubleclick[1].txt [ Cookie:bewerber@doubleclick.net/ ]
        C:\USERS\BEWERBER\AppData\Roaming\Microsoft\Windows\Cookies\Low\bewerber@msnportal.112.2o7[1].txt [ Cookie:bewerber@msnportal.112.2o7.net/ ]
        C:\USERS\BEWERBER\AppData\Roaming\Microsoft\Windows\Cookies\Low\bewerber@atdmt[1].txt [ Cookie:bewerber@atdmt.com/ ]
        de.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.gujmedia.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.gujmedia.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.gujmedia.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\219KE2C8.txt [ Cookie:daniel kort@wm.wiredminds.de/track/ ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        tracking.mlsat02.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\HG0HWJGH.txt [ Cookie:daniel kort@ad.yieldmanager.com/ ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\daniel_kort@apmebf[1].txt [ Cookie:daniel kort@apmebf.com/ ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\YWVJLL0W.txt [ Cookie:daniel kort@clkads.com/adServe/banners ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\YL6LY0PY.txt [ Cookie:daniel kort@atdmt.com/ ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\TE4UXJOC.txt [ Cookie:daniel kort@adfarm1.adition.com/ ]
        .amazon-adsystem.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\daniel_kort@fastclick[1].txt [ Cookie:daniel kort@fastclick.net/ ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\2O5DRGDJ.txt [ Cookie:daniel kort@ad2.adfarm1.adition.com/ ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\daniel_kort@content.yieldmanager[2].txt [ Cookie:daniel kort@content.yieldmanager.com/ ]
        ad.yieldmanager.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\daniel_kort@smartadserver[1].txt [ Cookie:daniel kort@smartadserver.com/ ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\53PBZAID.txt [ Cookie:daniel kort@doubleclick.net/ ]
        .xiti.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\daniel_kort@imrworldwide[2].txt [ Cookie:daniel kort@imrworldwide.com/cgi-bin ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\daniel_kort@mediaplex[2].txt [ Cookie:daniel kort@mediaplex.com/ ]
        .postclicktracking.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\M7XFSKJJ.txt [ Cookie:daniel kort@wm.wiredminds.de/track/ ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\0TYXV83R.txt [ Cookie:daniel kort@stats.zmags.com/StatsCollector/ ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\daniel_kort@msnportal.112.2o7[1].txt [ Cookie:daniel kort@msnportal.112.2o7.net/ ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\daniel_kort@de.sitestat[1].txt [ Cookie:daniel kort@de.sitestat.com/idgcom-de/pcwelt/ ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\HFKQ75JA.txt [ Cookie:daniel kort@ad3.adfarm1.adition.com/ ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\daniel_kort@invitemedia[1].txt [ Cookie:daniel kort@invitemedia.com/ ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\daniel_kort@serving-sys[1].txt [ Cookie:daniel kort@serving-sys.com/ ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\F9WPKBDV.txt [ Cookie:daniel kort@c.atdmt.com/ ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\LOLDP55O.txt [ Cookie:daniel kort@www.etracker.de/ ]
        www.googleadservices.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\AppData\Roaming\Microsoft\Windows\Cookies\Low\daniel_kort@2o7[1].txt [ Cookie:daniel kort@2o7.net/ ]
        de.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\Cookies\daniel_kort@adx.chip[2].txt [ Cookie:daniel kort@adx.chip.de/ ]
        C:\USERS\DANIEL KORT\Cookies\MHWAYLTX.txt [ Cookie:daniel kort@atdmt.com/ ]
        C:\USERS\DANIEL KORT\Cookies\87Y02FYX.txt [ Cookie:daniel kort@adfarm1.adition.com/ ]
        C:\USERS\DANIEL KORT\Cookies\L2XZU31Y.txt [ Cookie:daniel kort@adform.net/ ]
        .advertising.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .de.at.atwola.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\Cookies\26L3USJR.txt [ Cookie:daniel kort@ad2.adfarm1.adition.com/ ]
        .c.atdmt.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\Cookies\DKVMJ4D3.txt [ Cookie:daniel kort@smartadserver.com/ ]
        www.googleadservices.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DANIEL KORT\Cookies\Z0DM1835.txt [ Cookie:daniel kort@ad.zanox.com/ ]
        C:\USERS\DANIEL KORT\Cookies\2JB17Q4E.txt [ Cookie:daniel kort@doubleclick.net/ ]
        C:\USERS\DANIEL KORT\Cookies\6ATJO5WC.txt [ Cookie:daniel kort@imrworldwide.com/cgi-bin ]
        C:\USERS\DANIEL KORT\Cookies\219KE2C8.txt [ Cookie:daniel kort@wm.wiredminds.de/track/ ]
        C:\USERS\DANIEL KORT\Cookies\GGU3Y3BJ.txt [ Cookie:daniel kort@eas.apm.emediate.eu/ ]
        C:\USERS\DANIEL KORT\Cookies\F3IQF87J.txt [ Cookie:daniel kort@dyntracker.com/ ]
        C:\USERS\DANIEL KORT\Cookies\V7DH8LWD.txt [ Cookie:daniel kort@invitemedia.com/ ]
        C:\USERS\DANIEL KORT\Cookies\OZCY2V3W.txt [ Cookie:daniel kort@serving-sys.com/ ]
        C:\USERS\DANIEL KORT\Cookies\TL3OVYJR.txt [ Cookie:daniel kort@track.adform.net/ ]
        C:\USERS\DANIEL KORT\Cookies\IS5M5YU9.txt [ Cookie:daniel kort@c.atdmt.com/ ]
        C:\USERS\DANIEL KORT\Cookies\DJA8SI7F.txt [ Cookie:daniel kort@www.etracker.de/ ]
        C:\USERS\DANIEL KORT\Cookies\GQH9JDTI.txt [ Cookie:daniel kort@2o7.net/ ]
        .adform.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .deutschepostag.112.2o7.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        tomtailor.dyntracker.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        aimfar.solution.weborama.fr [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .weboramapublishertrackinguk2.solution.weborama.fr [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .weboramapublishertrackinguk2.solution.weborama.fr [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        teufel-media.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        int.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        int.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        int.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        server.adformdsp.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adformdsp.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .stepstone.112.2o7.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .steelhousemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .px.steelhousemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        tracking.porsche.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        tracking.porsche.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .trackalyzer.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        t2.trackalyzer.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradetracker.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .eaeacom.112.2o7.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .mmotraffic.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .mmotraffic.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        stats.vertriebsassistent.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        stats.computecmedia.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        banner.lv.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www2.forum-media.eu [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        in.getclicky.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        adserver.mundo-service.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .googleads.g.doubleclick.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradetracker.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradetracker.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        media.neodau.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        media.neodau.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        media.neodau.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradetracker.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradetracker.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        edates.traffective-tracking.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        edates.traffective-tracking.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        edates.traffective-tracking.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        edates.traffective-tracking.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .www.burstnet.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adlegend.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradetracker.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradetracker.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradetracker.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        track.adcocktail.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradetracker.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        viewad.exchangecash.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        oasn04.247realmedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        media.nuclearblast.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .mosaiq-media.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .mosaiq-media.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .mosaiq-media.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .fr.at.atwola.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        sales.liveperson.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        adserver.medialine.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.medialine.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.medialine.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .olympiaverlag.122.2o7.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        adx2.chip.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .tracker.vinsight.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        stats.computecmedia.de [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\DANIEL KORT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\POWOM3ZM.DEFAULT\COOKIES.SQLITE ]

Hallo Cosinus,

anbei findest Du den ersten Scan. Leider hat mir hier das Programm jeden Cookie als Fehler angezeigt. Mein MBAM-Logfile ist leider verschollen. Ich weiß nicht, wo es abgelegt wurde. Hier wurde aber nichts angezeigt.

Vielen Dank schon einmal für alles!!!

Viele Grüße
Daniel

cosinus 06.11.2012 10:30

Zitat:

Ich weiß nicht, wo es abgelegt wurde. Hier wurde aber nichts angezeigt.
Wird doch alles beschrieben! Hier zB => http://www.trojaner-board.de/125889-...tml#post941520

metaldakster 09.11.2012 13:22

Hi Cosinus,

das Log hatte ja keine Funde ;-) Aber ich habe es gefunden. Dank Dir!

Code:

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Datenbank Version: v2012.11.05.04

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
Daniel Kort :: DANIELKORTH-PC [Administrator]

05.11.2012 16:19:05
mbam-log-2012-11-05 (16-19-05).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 367469
Laufzeit: 1 Stunde(n), 7 Minute(n), 2 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 09.11.2012 19:56

Sieht ok aus, da wurden nur Cookies gefunden, die können alle weg.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

metaldakster 15.11.2012 15:25

Hallo Cosinus,

noch einmal vielen herzlichen Dank. Mein System ist jetzt - zum Glück und dank Deiner Hilfe - wieder voll funktionsfähig.

Viele Grüße
Daniel

cosinus 15.11.2012 17:51

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate
Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.
Windows Vista/7: Start, Systemsteuerung, Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks findest du hier => Browsers and Plugins - FilePony.de

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 07:31 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131