Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Windows Verschlüsselungs Trojaner (https://www.trojaner-board.de/116137-windows-verschluesselungs-trojaner.html)

NicoleM 01.06.2012 07:00

Windows Verschlüsselungs Trojaner
 
Hallo Liebes Trojaner-Board Team,

durch das Öffnen einer Email (gefakte Rechnung) wurde mein Laptop mit einem Windowsverschlüsselungstrojaner infiziert. Meine eigenen Dateien sind nun alle verschlüsselt.

In eurem Forum habe ich mich bereits erkundigt wie man vorgeht und habe nun mit Malwarebytes alles abgescannt.
Leider konnte ich bisher mit dem Decrypter nichts entschlüsseln, da ich nur komische Dateinamen, wie AynUsdtjyVUnAtLysE oder DarDXreNsQasvelT auffinde.

Was kann ich tun? Könntet ihr mir bitte weiterhelfen...ich bin wirklich verzweifelt...

cosinus 01.06.2012 14:23

Wer ein schlechtes Backup-Konzept hat, wird irgendwann lernen durch Schmerz :pfeiff:
Beachte obige Hinweise. Es kann dauern bis es ein Tool gibt, was deine Daten wieder entschlüsselt.

Vorher muss dein Rechner sauber sein. Poste erstmal alle Logs von Malwarebytes!

Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

NicoleM 01.06.2012 14:49

Hallo Arne,

Du hast Recht...wer ein schlechtes Backup-Konzept hat, der wird irgendwann bestraft :-/
Deshalb bin ich wirklich froh, dass es so super Leute wie euch gibt! Also, ich bin sehr dankbar für jede Hilfe, da ich leider ahnungslos bin. Danke, danke, danke für die Bemühungen :-)

Hier nun die logs von Malbarebytes:

Code:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.05.31.06

Windows 7 x64 NTFS (Abgesichertenmodus/Netzwerkfähig)
Internet Explorer 8.0.7600.16385
Nicole :: NICOLES_ZWERG [Administrator]

Schutz: Deaktiviert

31.05.2012 21:22:13
mbam-log-2012-05-31 (21-22-13).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 152362
Laufzeit: 31 Minute(n), 15 Sekunde(n) [Abgebrochen]

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|CC794F06 (Packer.ModifiedUPX) -> Daten: D:\Nicole\AppData\Roaming\Mmfwcyypw\DCC74273CC794F061AFB.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 7
D:\Nicole\AppData\Roaming\Mmfwcyypw\DCC74273CC794F061AFB.exe (Packer.ModifiedUPX) -> Erfolgreich gelöscht und in Quarantäne gestellt.
D:\\Nicole\AppData\Roaming\Mmfwcyypw\DCC74273CC794F061AFB.exe (Packer.ModifiedUPX) -> Erfolgreich gelöscht und in Quarantäne gestellt.
D:\\Nicole\AppData\Local\Temp\9nF9asIO.exe.part (Trojan.FakeAlert) -> Erfolgreich gelöscht und in Quarantäne gestellt.
D:\\Nicole\AppData\Local\Temp\cmpmkmkyky.pre (Packer.ModifiedUPX) -> Erfolgreich gelöscht und in Quarantäne gestellt.
D:\\Nicole\AppData\Local\Temp\ffyykmkkfp.pre (Packer.ModifiedUPX) -> Erfolgreich gelöscht und in Quarantäne gestellt.
D:\\Nicole\AppData\Local\Temp\uuvgplppue.pre (Packer.ModifiedUPX) -> Erfolgreich gelöscht und in Quarantäne gestellt.
D:\\Nicole\AppData\Local\Temp\xPg9VjFd.exe.part (Trojan.FakeAlert) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


cosinus 01.06.2012 15:00

Bitte erstmal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

NicoleM 03.06.2012 07:18

Guten Morgen Arne,

Hier ist nun das Ergebnis von ESET Online Scanner:

Code:

all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=376806d1ac52f745b9c25c3e036579c7
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-06-03 02:40:33
# local_time=2012-06-03 04:40:33 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=5893 16776573 100 94 48501878 90315353 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=288199
# found=12
# cleaned=0
# scan_time=5729
C:\Program Files (x86)\PDFCreator\Toolbar\pdfforge Toolbar_setup.exe        Win32/Toolbar.Widgi application (unable to clean)        00000000000000000000000000000000        I
C:\Windows\Installer\2195233a.msi        a variant of Win32/Toolbar.Widgi application (unable to clean)        00000000000000000000000000000000        I
D:\$RECYCLE.BIN\S-1-5-21-3728700144-1891460459-2374237516-1001\$RM0S7RY.exe        a variant of Win32/SoftonicDownloader.A application (unable to clean)        00000000000000000000000000000000        I
D:\Nicole\AppData\Local\Temp\Bescheid-1.zip        Win32/Trustezeb.B trojan (unable to clean)        00000000000000000000000000000000        I
D:\Nicole\AppData\Local\Temp\Bescheid.zip        Win32/Trustezeb.B trojan (unable to clean)        00000000000000000000000000000000        I
D:\Nicole\AppData\Local\Temp\Picture19.JPG-2.zip        a variant of Win32/Injector.IYX trojan (unable to clean)        00000000000000000000000000000000        I
D:\Nicole\AppData\Local\Temp\Picture19.JPG-3.zip        a variant of Win32/Injector.IYX trojan (unable to clean)        00000000000000000000000000000000        I
D:\Nicole\AppData\Local\Temp\Picture19.JPG-4.zip        a variant of Win32/Injector.IYX trojan (unable to clean)        00000000000000000000000000000000        I
D:\Nicole\AppData\Local\Temp\Picture19.JPG.zip        a variant of Win32/Injector.IYX trojan (unable to clean)        00000000000000000000000000000000        I
D:\Nicole\AppData\Local\Temp\SweetIMReinstall\SweetImSetup.exe        a variant of Win32/SweetIM.B application (unable to clean)        00000000000000000000000000000000        I
D:\Nicole\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\88743cf-11842bc1        Java/TrojanDownloader.Agent.ME trojan (unable to clean)        00000000000000000000000000000000        I
D:\Nicole\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\37db3fe2-486b5eec        Java/TrojanDownloader.Agent.ME trojan (unable to clean)        00000000000000000000000000000000        I


cosinus 03.06.2012 13:26

Und was ist mit dem Vollscan mit Malwarebytes? Den solltest du eigentlich vor ESET machen!

NicoleM 03.06.2012 16:22

Hallo Arne,

Dn Vollscan von Malwarebytes habe ich noch vor ESET gemacht und auch zuvor gepostet.

cosinus 03.06.2012 17:35

Ja du hast ein Log von Malwarebytes gepostet, aber das war kein Vollscan

NicoleM 03.06.2012 19:38

Code:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.05.31.06

Windows 7 x64 NTFS (Abgesichertenmodus/Netzwerkfähig)
Internet Explorer 8.0.7600.16385
Nicole :: NICOLES_ZWERG [Administrator]

Schutz: Deaktiviert

31.05.2012 21:54:45
mbam-log-2012-05-31 (21-54-45).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 516099
Laufzeit: 53 Minute(n), 13 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegedit (Hijack.Regedit) -> Daten: 1 -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools (PUM.Hijack.Regedit) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr (PUM.Hijack.TaskManager) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt.

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


Code:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.05.31.07

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Nicole :: NICOLES_ZWERG [Administrator]

Schutz: Aktiviert

01.06.2012 01:20:06
mbam-log-2012-06-01 (01-20-06).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 103054
Laufzeit: 19 Minute(n), 5 Sekunde(n) [Abgebrochen]

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


Code:

2012/06/01 00:52:14 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Executing scheduled update:  Daily
2012/06/01 00:52:22 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting protection
2012/06/01 00:52:27 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Scheduled update executed successfully:  database updated from version v2012.05.31.06 to version v2012.05.31.07
2012/06/01 00:52:27 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Protection started successfully
2012/06/01 00:52:30 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting IP protection
2012/06/01 00:52:33 +0200        NICOLES_ZWERG        Nicole        MESSAGE        IP Protection started successfully
2012/06/01 00:52:33 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting database refresh
2012/06/01 00:52:33 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Stopping IP protection
2012/06/01 00:55:27 +0200        NICOLES_ZWERG        Nicole        MESSAGE        IP Protection stopped
2012/06/01 00:55:31 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Database refreshed successfully
2012/06/01 00:55:31 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting IP protection
2012/06/01 00:55:33 +0200        NICOLES_ZWERG        Nicole        MESSAGE        IP Protection started successfully
2012/06/01 01:20:23 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting protection
2012/06/01 01:20:27 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Protection started successfully
2012/06/01 01:20:30 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting IP protection
2012/06/01 01:20:32 +0200        NICOLES_ZWERG        Nicole        MESSAGE        IP Protection started successfully
2012/06/01 07:27:51 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting protection
2012/06/01 07:27:55 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Protection started successfully
2012/06/01 07:27:58 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting IP protection
2012/06/01 07:28:02 +0200        NICOLES_ZWERG        Nicole        MESSAGE        IP Protection started successfully
2012/06/01 07:28:05 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Executing scheduled update:  Daily
2012/06/01 07:28:16 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Scheduled update executed successfully:  database updated from version v2012.05.31.07 to version v2012.06.01.02
2012/06/01 07:28:16 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting database refresh
2012/06/01 07:28:16 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Stopping IP protection
2012/06/01 07:31:23 +0200        NICOLES_ZWERG        Nicole        MESSAGE        IP Protection stopped
2012/06/01 07:31:28 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Database refreshed successfully
2012/06/01 07:31:28 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting IP protection
2012/06/01 07:31:31 +0200        NICOLES_ZWERG        Nicole        MESSAGE        IP Protection started successfully
2012/06/01 15:37:52 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting protection
2012/06/01 15:37:56 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Protection started successfully
2012/06/01 15:37:59 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting IP protection
2012/06/01 15:38:02 +0200        NICOLES_ZWERG        Nicole        MESSAGE        IP Protection started successfully


Code:

2012/06/03 03:00:13 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting protection
2012/06/03 03:00:17 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Protection started successfully
2012/06/03 03:00:20 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting IP protection
2012/06/03 03:00:22 +0200        NICOLES_ZWERG        Nicole        MESSAGE        IP Protection started successfully
2012/06/03 03:13:36 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Executing scheduled update:  Daily
2012/06/03 03:13:54 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting database refresh
2012/06/03 03:13:54 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Scheduled update executed successfully:  database updated from version v2012.06.01.02 to version v2012.06.02.06
2012/06/03 03:13:54 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Stopping IP protection
2012/06/03 03:17:30 +0200        NICOLES_ZWERG        Nicole        MESSAGE        IP Protection stopped
2012/06/03 03:17:35 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Database refreshed successfully
2012/06/03 03:17:35 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting IP protection
2012/06/03 03:17:37 +0200        NICOLES_ZWERG        Nicole        MESSAGE        IP Protection started successfully
2012/06/03 06:13:44 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Executing scheduled update:  Daily
2012/06/03 06:13:55 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Scheduled update executed successfully:  database updated from version v2012.06.02.06 to version v2012.06.03.01
2012/06/03 06:13:55 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting database refresh
2012/06/03 06:13:55 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Stopping IP protection
2012/06/03 06:17:22 +0200        NICOLES_ZWERG        Nicole        MESSAGE        IP Protection stopped
2012/06/03 06:17:40 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Database refreshed successfully
2012/06/03 06:17:40 +0200        NICOLES_ZWERG        Nicole        MESSAGE        Starting IP protection
2012/06/03 06:17:43 +0200        NICOLES_ZWERG        Nicole        MESSAGE        IP Protection started successfully

Hallole Arne,

Ich hab jetzt mal alles gepostet, was ich so unter den Logdateien finden konnte.
Ist es so richtig? Sorry, ich bin im IT-Bereich leider nicht so die Leuchte :-(

Und nochmal vielen lieben Dank für deine Bemühungen und Geduld! Ich sehe es natürlich nicht als selbstverständlich, dass du dir die Zeit nimmst und mir hilfst.

cosinus 03.06.2012 21:01

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt? (abgesehen von den verschlüsselten Daten)
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

NicoleM 03.06.2012 21:34

Ich konnte Wondows wieder normal starten und es geht soweit alles.
Außer dass eben die Daten verschlüsselt sind und ich sie nicht öffnen kann.

cosinus 03.06.2012 23:01

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


NicoleM 04.06.2012 20:05

OTL Logfile:
Code:

OTL logfile created on: 04.06.2012 20:47:00 - Run 1
OTL by OldTimer - Version 3.2.46.0    Folder = D:\Nicole\Downloads
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,86 Gb Total Physical Memory | 0,84 Gb Available Physical Memory | 45,01% Memory free
3,73 Gb Paging File | 2,40 Gb Available in Paging File | 64,28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 29,32 Gb Total Space | 3,37 Gb Free Space | 11,50% Space Free | Partition Type: NTFS
Drive D: | 257,83 Gb Total Space | 243,07 Gb Free Space | 94,28% Space Free | Partition Type: NTFS
Drive Q: | 9,77 Gb Total Space | 3,35 Gb Free Space | 34,35% Space Free | Partition Type: NTFS
 
Computer Name: NICOLES_ZWERG | User Name: Nicole | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.06.04 20:44:37 | 000,596,480 | ---- | M] (OldTimer Tools) -- D:\Nicole\Downloads\OTL.exe
PRC - [2012.05.25 15:21:44 | 000,992,648 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe
PRC - [2012.05.25 15:12:54 | 000,785,344 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.12.16 13:54:22 | 000,220,744 | ---- | M] (Geek Software GmbH) -- C:\Program Files (x86)\PDF24\pdf24.exe
PRC - [2011.09.01 18:47:26 | 000,090,448 | ---- | M] (Research In Motion Limited) -- C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
PRC - [2011.08.25 15:25:00 | 000,886,760 | ---- | M] (Search-Results) -- C:\Program Files (x86)\Ask.com\Updater\Updater.exe
PRC - [2011.07.20 13:37:54 | 000,206,336 | ---- | M] () -- C:\Program Files (x86)\PC Beschleunigen\PCSUService.exe
PRC - [2010.12.09 21:28:24 | 001,226,608 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.12.08 23:15:44 | 000,063,360 | ---- | M] (DivX, LLC) -- C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe
PRC - [2010.11.09 15:16:38 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
PRC - [2010.08.06 10:59:48 | 000,357,736 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe
PRC - [2010.08.06 10:59:32 | 000,259,432 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
PRC - [2010.08.06 10:59:30 | 000,124,264 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
PRC - [2010.07.06 14:22:22 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Programme\ThinkPad\Bluetooth Software\BluetoothHeadsetProxy.exe
PRC - [2010.05.14 12:44:46 | 000,501,480 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2010.04.20 13:23:32 | 000,074,088 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\Communications Utility\TPKNRSVC.exe
PRC - [2010.04.20 13:23:28 | 000,062,312 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\Communications Utility\TPKNRRES.exe
PRC - [2010.04.20 13:23:18 | 000,050,536 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\Communications Utility\CamMute.exe
PRC - [2010.04.07 07:37:40 | 000,093,032 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\VIRTSCRL\lvvsst.exe
PRC - [2010.04.07 07:37:24 | 000,063,928 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\TPHKSVC.exe
PRC - [2010.04.07 05:02:18 | 000,045,496 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\micmute.exe
PRC - [2010.04.01 07:50:46 | 000,043,960 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\VIRTSCRL\virtscrl.exe
PRC - [2010.02.10 15:40:56 | 000,028,672 | ---- | M] (Lenovo Group Limited) -- c:\Program Files (x86)\Lenovo\System Update\SUService.exe
PRC - [2009.12.21 11:49:46 | 000,069,568 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe
PRC - [2009.11.24 06:51:20 | 000,176,056 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\TPONSCR.exe
PRC - [2009.11.11 10:33:12 | 000,078,272 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\tpnumlkd.exe
PRC - [2009.11.04 06:45:46 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009.11.04 06:45:44 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009.08.28 14:09:58 | 001,019,904 | ---- | M] (Lenovo Group Limited) -- C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
PRC - [2006.10.23 00:24:02 | 000,620,152 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
 
 
========== Modules (No Company Name) ==========

OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 04.06.2012 20:47:00 - Run 1
OTL by OldTimer - Version 3.2.46.0    Folder = D:\Nicole\Downloads
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,86 Gb Total Physical Memory | 0,84 Gb Available Physical Memory | 45,01% Memory free
3,73 Gb Paging File | 2,40 Gb Available in Paging File | 64,28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 29,32 Gb Total Space | 3,37 Gb Free Space | 11,50% Space Free | Partition Type: NTFS
Drive D: | 257,83 Gb Total Space | 243,07 Gb Free Space | 94,28% Space Free | Partition Type: NTFS
Drive Q: | 9,77 Gb Total Space | 3,35 Gb Free Space | 34,35% Space Free | Partition Type: NTFS
 
Computer Name: NICOLES_ZWERG | User Name: Nicole | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{076E70CC-3C7B-445C-99CB-E5986A260A51}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{21A5D449-A363-4221-B5A0-F116908DF2B4}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{21D4639B-9BA3-49F8-AADB-20A45E58466F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{228F5575-88D1-4074-A836-1C23C245C917}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2D74ABCD-86CF-4B27-AF96-D60EA6C2C1E0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{2EB3D7D5-E9A3-4063-A8B7-7BD31099C850}" = lport=138 | protocol=17 | dir=in | app=system |
"{31A681CF-B89A-417B-A51F-2FFDBBA5835B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{46134669-F954-40C0-9DF5-879B739CF353}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{5BD82315-5BC7-4FDA-B776-C077831375A5}" = rport=10243 | protocol=6 | dir=out | app=system |
"{675801E7-A1DF-4D18-B49F-9EB00AAC4124}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7149E7CE-5390-4703-AE69-087462B37A26}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{853137C0-AFDC-445A-82D3-57E2B3D28F03}" = rport=445 | protocol=6 | dir=out | app=system |
"{89655401-5998-410C-BA62-C68E27EFC6A3}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{95D2D221-0E25-41E8-AB13-8094C24D6AC6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{963037DB-4BA2-448E-ACD0-BFA68A66E965}" = lport=139 | protocol=6 | dir=in | app=system |
"{9B8384B4-96D8-465C-9B87-603A44D41014}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{9DAAABC7-67DD-4909-8A6A-94D55F3BFEBC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9EA5B57C-7972-4C0D-AEBF-06E1D3886849}" = lport=445 | protocol=6 | dir=in | app=system |
"{C07B07CC-AB92-4C8E-A898-F8A2963D9B81}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C31D2577-C32A-4F93-9FCE-4267E132FDEE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C9DA2E36-E1DF-446E-A02D-5A737958C44F}" = lport=10243 | protocol=6 | dir=in | app=system |
"{D0148F4E-1B0E-4EAC-82E2-8F6E94FECC23}" = rport=137 | protocol=17 | dir=out | app=system |
"{D8F2DC67-D2D4-4069-96B8-D4131B3624C2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{DC18ABF4-7E35-4BFB-9D3B-703CF7E0E703}" = rport=139 | protocol=6 | dir=out | app=system |
"{DCF95D39-3FB8-4C89-905B-9940915A9955}" = rport=138 | protocol=17 | dir=out | app=system |
"{E56A3CC6-AE16-4927-978D-BE273C588D1A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F0BE8FBE-852A-44AC-B6E2-8DC8D595DF0B}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FB6A22FB-633E-46CA-82D2-1CDFA5FB640D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FCA2F3DE-38DF-4C68-9E19-5BDC7FEEE48B}" = lport=137 | protocol=17 | dir=in | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00A06861-801E-43A7-8411-3AF847744358}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |
"{1452D187-2895-4031-B8CF-712BA7A68B75}" = protocol=6 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{19956F8B-2A09-49C1-B17E-C728838572FD}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{1C9FDBA5-121E-45ED-9C50-7A78B2B1FCDB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2B7BACE3-DA6D-48AB-9775-A958AE38AA25}" = protocol=17 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{31516A40-BCA2-49E2-8424-D282D084E683}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{34F96AFE-9AD0-4C7C-A082-971D5B54FAD0}" = protocol=6 | dir=out | app=system |
"{34FE7541-DFD8-43F5-82F4-F1385B18899E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{3648EBAE-FC05-4929-8B3F-4F5A6C5D7A94}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{36523EBE-8E45-4A06-B731-4D830A2D48FF}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{394F350C-8AAF-4400-B5EC-B839C30DF973}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{40863B5D-5620-4BFC-8684-88A57EEC8B55}" = protocol=17 | dir=in | app=f:\sweetimsetup.exe |
"{4ADE421E-BEAC-41C4-A552-CFF57CADEF51}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4C0D93E5-3B82-4445-9A6B-FEF473D476CA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{56393A72-3CF4-4A67-9AA7-CB0E54577C2A}" = protocol=6 | dir=in | app=f:\sweetimsetup.exe |
"{5A55B255-E2D2-49D8-A111-FDAA08063EA1}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{5C580CF6-9A7B-45F8-A029-2E44F31F5A8F}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{5DD6F943-EF5E-40FA-A3B9-906319858520}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6A362454-D8F3-459A-ACBF-FEA0110C7829}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{6A511C9C-A592-4EBA-8839-081646B5837A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |
"{6A777591-09D6-480C-9076-4193E14BB698}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{6D6685E6-1F73-4FEB-98A4-C6D24F5A1915}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{7114CAD9-CF0D-4F03-A87C-59AFD8B81C2E}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{73F6339D-220B-4D63-AD11-C06A18CC9380}" = protocol=6 | dir=in | app=d:\nicole\appdata\roaming\dropbox\bin\dropbox.exe |
"{8766A6C0-A4D1-490D-9A6B-01C18B2D097F}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{8A6BDC57-1615-40FA-BB87-3740ACB17D06}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{8C34B5CC-E064-4C27-853A-F03F46FBC346}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{92532053-9F18-45B2-874D-C66AC4019AA2}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{94B53AD6-0552-408D-A644-5D93B729F3BD}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{ADECFC19-2B0F-4A23-9F4E-A85E6A75ECE8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AF8BC7FC-5023-4706-9623-BDAF915653D0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B487ACC8-28B4-4ACC-8A76-C2F0418C063C}" = protocol=17 | dir=in | app=d:\nicole\appdata\roaming\dropbox\bin\dropbox.exe |
"{B6CB5992-AD20-4686-A395-E54AD59CE55E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{B6EE06B0-1F50-47D5-BAA5-94D2C31B2514}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{BC8F9327-B09F-48DB-895D-65D6632772EF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BE4EF6B1-8FE0-49EE-B151-9DEDEEFB1364}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |
"{C596270B-2742-47E7-800F-CDA8A3A79C62}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D44D21F5-C6EF-4642-8A9B-3A3F52DA9FF0}" = dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{DAB04C5C-2D0B-4B31-A2B7-16A216EB5888}" = protocol=58 | dir=in | app=system |
"{F5226B10-8014-401E-9731-65F0A73400A6}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{F83A0B2E-9E46-4E97-BD8C-39D5FF361AA7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{7A897E47-53D7-4C7E-B1EE-1AE28C73A1DF}D:\nicole\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=d:\nicole\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{8C3185AA-55FC-4A9D-97F0-BEE19836935C}D:\nicole\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=d:\nicole\appdata\roaming\dropbox\bin\dropbox.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage System für aktiven Festplattenschutz
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4BDE7544-0A08-4AD9-8A8F-4B7944471C36}" = iTunes
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{88C6A6D9-324C-46E8-BA87-563D14021442}_is1" = ThinkVantage Communications Utility
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}" = Apple Mobile Device Support
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"114EB224AD576F278686036AA9E1EFB7847E3935" = Windows-Treiberpaket - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4)
"3BA80AB4C7E9F8497C115C844953A3D4BEB84D21" = Windows Driver Package - Broadcom HIDClass  (07/28/2009 6.2.0.9800)
"9EC603BD25CD27C08F0E5CF7AC8557143E323010" = Windows-Treiberpaket - Intel (iaStor) hdc  (04/13/2010 9.6.2.1001)
"CNXT_AUDIO_HDA" = Conexant CX20582 SmartAudio HD
"DE7217D2A8B057F15EC6E52329FDAB84231521E8" = Windows Driver Package - Broadcom (BTHUSB) Bluetooth  (04/08/2010 6.3.5.430)
"EnablePS" = Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7
"Integrated Camera" = Integrated Camera
"LENOVO.SMIIF" = Lenovo System Interface Driver
"LenovoAutoScrollUtility" = Lenovo Auto Scroll Utility
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"OnScreenDisplay" = Anzeige am Bildschirm
"PC-Doctor for Windows" = Lenovo ThinkVantage Toolbox
"PCSU-SL_is1" = PC Beschleunigen - Vollständige Deinstallation
"Power Management Driver" = ThinkPad Power Management Driver
"SynTPDeinstKey" = ThinkPad UltraNav Driver
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1CA3A991-B03D-4C92-9922-315E5434E87B}" = PS_AIO_05_C4600_Software_Min
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22FC7536-BE5C-4E88-8069-C24689D34EC5}" = Snagit 10.0.1
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{25C64847-B900-48AD-A164-1B4F9B774650}" = System Update
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 22
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{411E0CC3-587A-468C-B461-95FAFD05E4DE}" = Adobe InDesign CS3
"{4330AAE7-1893-42F9-BC38-539A1A60530B}" = Mobile Broadband
"{4393DE35-AD67-4F37-95E4-30F06EA0FDB2}" = Adobe Creative Suite 3 Design Premium
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AA5B8A5-BEEF-4AD8-B11D-4443A042EA4F}" = Adobe Dreamweaver CS3
"{50DC5136-21E8-48BC-97E5-1AD055F6B0B6}" = Create Recovery Media
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5518E08A-2053-4A3E-85B2-F912D4666C9F}" = Adobe Setup
"{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync
"{5B2C4D32-A7CD-44B0-8619-4ADBE301B2D3}" = pdfforge Toolbar v5.8
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
"{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{73B5D990-04EA-4751-B10F-5534770B91F2}" = Adobe Color EU Recommended Settings
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 4.1.2
"{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Search-Results Toolbar
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E537894-A559-4D60-B3CB-F4485E3D24E3}" = ThinkVantage Access Connections
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9D3D2C60-A55F-4fed-B2B9-17311226DF01}" = ThinkPad Wireless LAN Adapter Software
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A7496F46-78AE-4DB2-BCF5-95F210FA6F96}" = Windows Live Movie Maker
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-1033-F400-7760-000000000003}" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch
"{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger
"{B383F243-0ABC-4E56-AA30-923B8D85076E}" = Rescue and Recovery
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B671CBFD-4109-4D35-9252-3062D3CCB7B2}" = Adobe SING CS3
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}" = Adobe BridgeTalk Plugin CS3
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
"{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
"{C6FA39A7-26B1-480A-BC74-6D17531AC222}" = Access Help
"{C8D7A672-F697-4572-AC62-C856053A8DBC}" = Adobe Illustrator CS3
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D3C605D8-3A5E-4BAD-965D-2C61441BF2AC}" = Adobe Photoshop CS3
"{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}" = ThinkPad Energie-Manager
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}" = Adobe InDesign CS3 Icon Handler
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.9
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver
"{F909BB1B-3FC1-4EDA-AF1F-8F1A89163591}" = BlackBerry Desktop Software 6.1
"{FA39B424-C18F-4593-8D84-27C00FED5CCF}" = BlackBerry Device Software v5.0.0 für das BlackBerry 8520-Smartphone
"{FD331A3B-F7A5-4C31-B8D4-DF413C85AF7A}" = Message Center Plus
"{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}" = Lenovo Warranty Information
"{FE7AD27A-62B1-44F6-B69C-25D1ECA94F5D}" = Integrated Camera
"{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}" = Adobe Color NA Extra Settings
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe_061850775b1c6d22bf2a145678e05e0" = Adobe Creative Suite 3 Design Premium hinzufügen oder entfernen
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
"BFGC" = Big Fish Games: Game Manager
"BFG-Farm Frenzy 2" = Farm Frenzy 2
"BFG-Juliette's Fashion Empire" = Juliette's Fashion Empire
"BFG-Miss Management" = Miss Management
"BFG-My Farm Life" = My Farm Life
"BFG-Party Down" = Party Down
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.1
"DivX Setup.divx.com" = DivX-Setup
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"ESET Online Scanner" = ESET Online Scanner v3
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.31
"hotpot_is1" = HotPotatoes v 6.3.0.4
"IrfanView" = IrfanView (remove only)
"Lenovo Welcome_is1" = Lenovo Welcome
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400
"Mozilla Firefox 12.0 (x86 de)" = Mozilla Firefox 12.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Uninstall_is1" = Uninstall 1.0.0.1
"WinLiveSuite_Wave3" = Windows Live Essentials
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"2113656771.www.pcspeedup.com" = PCSpeedUp Application
"Dropbox" = Dropbox
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 31.05.2012 14:29:44 | Computer Name = Nicoles_Zwerg | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 264937
 
Error - 31.05.2012 14:29:44 | Computer Name = Nicoles_Zwerg | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 264937
 
Error - 31.05.2012 14:29:59 | Computer Name = Nicoles_Zwerg | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 31.05.2012 14:29:59 | Computer Name = Nicoles_Zwerg | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 280506
 
Error - 31.05.2012 14:29:59 | Computer Name = Nicoles_Zwerg | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 280506
 
Error - 31.05.2012 14:30:01 | Computer Name = Nicoles_Zwerg | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 31.05.2012 14:30:01 | Computer Name = Nicoles_Zwerg | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 296090
 
Error - 31.05.2012 14:30:01 | Computer Name = Nicoles_Zwerg | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 296090
 
Error - 31.05.2012 14:30:16 | Computer Name = Nicoles_Zwerg | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 31.05.2012 14:30:16 | Computer Name = Nicoles_Zwerg | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 311690
 
[ System Events ]
Error - 29.08.2011 04:36:11 | Computer Name = Nicoles_Zwerg | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
 nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
 
Error - 30.08.2011 12:42:17 | Computer Name = Nicoles_Zwerg | Source = WMPNetworkSvc | ID = 866300
Description =
 
Error - 30.08.2011 16:24:22 | Computer Name = Nicoles_Zwerg | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst SysMain erreicht.
 
Error - 02.09.2011 03:55:20 | Computer Name = Nicoles_Zwerg | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
 nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
 
Error - 03.09.2011 16:02:40 | Computer Name = Nicoles_Zwerg | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst W32Time erreicht.
 
Error - 05.09.2011 03:35:40 | Computer Name = Nicoles_Zwerg | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst AcPrfMgrSvc erreicht.
 
Error - 05.09.2011 15:26:43 | Computer Name = Nicoles_Zwerg | Source = ACPI | ID = 327693
Description = : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen
 Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware
 hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie
den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen
 Situationen zur Folge haben, dass der Computer fehlerhaft läuft.
 
Error - 06.09.2011 04:57:35 | Computer Name = Nicoles_Zwerg | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst Lenovo.VIRTSCRLSVC erreicht.
 
Error - 06.09.2011 04:57:35 | Computer Name = Nicoles_Zwerg | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst lmhosts erreicht.
 
Error - 06.09.2011 11:28:53 | Computer Name = Nicoles_Zwerg | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
 nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
 
 
< End of report >

--- --- ---

--- --- ---

cosinus 04.06.2012 21:26

Das OTL.txt Log ist nicht vollständig

NicoleM 04.06.2012 21:31

Oh, sorry...da hab ich nen Teil übersehen. Danke für den Hinweis :-)

OTL Logfile:
Code:

OTL logfile created on: 04.06.2012 20:47:00 - Run 1
OTL by OldTimer - Version 3.2.46.0    Folder = D:\Nicole\Downloads
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,86 Gb Total Physical Memory | 0,84 Gb Available Physical Memory | 45,01% Memory free
3,73 Gb Paging File | 2,40 Gb Available in Paging File | 64,28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 29,32 Gb Total Space | 3,37 Gb Free Space | 11,50% Space Free | Partition Type: NTFS
Drive D: | 257,83 Gb Total Space | 243,07 Gb Free Space | 94,28% Space Free | Partition Type: NTFS
Drive Q: | 9,77 Gb Total Space | 3,35 Gb Free Space | 34,35% Space Free | Partition Type: NTFS
 
Computer Name: NICOLES_ZWERG | User Name: Nicole | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.06.04 20:44:37 | 000,596,480 | ---- | M] (OldTimer Tools) -- D:\Nicole\Downloads\OTL.exe
PRC - [2012.05.25 15:21:44 | 000,992,648 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe
PRC - [2012.05.25 15:12:54 | 000,785,344 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.12.16 13:54:22 | 000,220,744 | ---- | M] (Geek Software GmbH) -- C:\Program Files (x86)\PDF24\pdf24.exe
PRC - [2011.09.01 18:47:26 | 000,090,448 | ---- | M] (Research In Motion Limited) -- C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
PRC - [2011.08.25 15:25:00 | 000,886,760 | ---- | M] (Search-Results) -- C:\Program Files (x86)\Ask.com\Updater\Updater.exe
PRC - [2011.07.20 13:37:54 | 000,206,336 | ---- | M] () -- C:\Program Files (x86)\PC Beschleunigen\PCSUService.exe
PRC - [2010.12.09 21:28:24 | 001,226,608 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.12.08 23:15:44 | 000,063,360 | ---- | M] (DivX, LLC) -- C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe
PRC - [2010.11.09 15:16:38 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
PRC - [2010.08.06 10:59:48 | 000,357,736 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe
PRC - [2010.08.06 10:59:32 | 000,259,432 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
PRC - [2010.08.06 10:59:30 | 000,124,264 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
PRC - [2010.07.06 14:22:22 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Programme\ThinkPad\Bluetooth Software\BluetoothHeadsetProxy.exe
PRC - [2010.05.14 12:44:46 | 000,501,480 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2010.04.20 13:23:32 | 000,074,088 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\Communications Utility\TPKNRSVC.exe
PRC - [2010.04.20 13:23:28 | 000,062,312 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\Communications Utility\TPKNRRES.exe
PRC - [2010.04.20 13:23:18 | 000,050,536 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\Communications Utility\CamMute.exe
PRC - [2010.04.07 07:37:40 | 000,093,032 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\VIRTSCRL\lvvsst.exe
PRC - [2010.04.07 07:37:24 | 000,063,928 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\TPHKSVC.exe
PRC - [2010.04.07 05:02:18 | 000,045,496 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\micmute.exe
PRC - [2010.04.01 07:50:46 | 000,043,960 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\VIRTSCRL\virtscrl.exe
PRC - [2010.02.10 15:40:56 | 000,028,672 | ---- | M] (Lenovo Group Limited) -- c:\Program Files (x86)\Lenovo\System Update\SUService.exe
PRC - [2009.12.21 11:49:46 | 000,069,568 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe
PRC - [2009.11.24 06:51:20 | 000,176,056 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\TPONSCR.exe
PRC - [2009.11.11 10:33:12 | 000,078,272 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\tpnumlkd.exe
PRC - [2009.11.04 06:45:46 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009.11.04 06:45:44 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009.08.28 14:09:58 | 001,019,904 | ---- | M] (Lenovo Group Limited) -- C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
PRC - [2006.10.23 00:24:02 | 000,620,152 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.11.02 00:26:32 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.11.02 00:26:12 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010.12.09 21:29:16 | 000,096,112 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2010.12.09 21:28:24 | 001,226,608 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2010.06.16 13:44:38 | 000,047,728 | ---- | M] (Lenovo.) [On_Demand | Stopped] -- C:\Windows\SysNative\TPHDEXLG64.exe -- (TPHDEXLGSVC)
SRV:64bit: - [2009.11.18 07:04:24 | 000,045,928 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Windows\SysNative\ibmpmsvc.exe -- (IBMPMSVC)
SRV:64bit: - [2009.07.14 03:41:27 | 000,097,792 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\mprdim.dll -- (RemoteAccess)
SRV:64bit: - [2009.07.14 03:41:21 | 000,084,480 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\Mcx2Svc.dll -- (Mcx2Svc)
SRV:64bit: - [2009.07.14 03:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV - [2012.05.25 15:12:54 | 000,785,344 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2012.05.18 16:26:30 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.05.03 08:31:10 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.07.20 13:37:54 | 000,206,336 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\PC Beschleunigen\PCSUService.exe -- (PCSUService)
SRV - [2010.11.09 15:16:38 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.08.06 10:59:32 | 000,259,432 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe -- (AcSvc)
SRV - [2010.08.06 10:59:30 | 000,124,264 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe -- (AcPrfMgrSvc)
SRV - [2010.07.20 20:27:00 | 000,075,112 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE -- (Power Manager DBC Service)
SRV - [2010.07.06 14:22:22 | 000,915,232 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Programme\ThinkPad\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2010.04.20 13:23:32 | 000,074,088 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\Communications Utility\TPKNRSVC.exe -- (LENOVO.TPKNRSVC)
SRV - [2010.04.20 13:23:18 | 000,050,536 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\Communications Utility\CamMute.exe -- (LENOVO.CAMMUTE)
SRV - [2010.04.07 07:37:40 | 000,093,032 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC)
SRV - [2010.04.07 07:37:24 | 000,063,928 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\HOTKEY\TPHKSVC.exe -- (TPHKSVC)
SRV - [2010.04.07 05:02:18 | 000,045,496 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\HOTKEY\micmute.exe -- (LENOVO.MICMUTE)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.10 15:40:56 | 000,028,672 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- c:\Program Files (x86)\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2009.11.04 06:45:46 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2009.11.04 06:45:44 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2009.08.28 14:09:58 | 001,019,904 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service)
SRV - [2009.07.14 03:15:41 | 000,075,264 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysWOW64\mprdim.dll -- (RemoteAccess)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.06.10 22:39:58 | 000,089,920 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.04.04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.02.15 12:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011.08.02 18:38:44 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:64bit: - [2011.07.25 18:44:46 | 000,074,752 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV:64bit: - [2011.07.20 15:58:22 | 000,044,032 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys -- (RimVSerPort)
DRV:64bit: - [2010.07.30 11:13:04 | 000,947,816 | ---- | M] (Realtek Semiconductor Corporation                          ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192ce.sys -- (RTL8192Ce)
DRV:64bit: - [2010.07.20 20:27:00 | 000,013,104 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\TPPWR64V.SYS -- (TPPWRIF)
DRV:64bit: - [2010.06.23 10:10:56 | 000,344,680 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010.06.22 06:28:06 | 000,729,216 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2010.06.17 10:18:28 | 000,246,376 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010.06.16 13:44:38 | 000,136,816 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsX64.sys -- (Shockprf)
DRV:64bit: - [2010.06.16 13:44:38 | 000,023,664 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsHM64.sys -- (TPDIGIMN)
DRV:64bit: - [2010.06.03 12:18:56 | 001,379,376 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010.04.13 02:44:22 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.04.08 17:11:12 | 000,054,824 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btusbflt.sys -- (btusbflt)
DRV:64bit: - [2010.03.31 08:47:08 | 010,322,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010.02.26 09:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010.02.02 23:38:30 | 000,271,872 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2010.01.15 07:23:20 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2010.01.15 07:23:14 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2010.01.15 07:23:10 | 000,021,288 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2009.11.23 12:06:32 | 000,205,952 | ---- | M] (SMI) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SMIksdrv.sys -- (usbsmi)
DRV:64bit: - [2009.11.18 07:04:04 | 000,032,880 | ---- | M] (Lenovo.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ibmpmdrv.sys -- (IBMPMDRV)
DRV:64bit: - [2009.09.17 05:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
DRV:64bit: - [2009.07.14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 03:47:48 | 000,024,144 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\crcdisk.sys -- (crcdisk)
DRV:64bit: - [2009.07.14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 02:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
DRV:64bit: - [2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\ws2ifsl.sys -- (ws2ifsl)
DRV:64bit: - [2009.07.14 01:31:10 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2009.07.14 01:23:37 | 000,327,168 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\udfs.sys -- (udfs)
DRV:64bit: - [2009.07.14 01:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2009.07.14 01:19:47 | 000,092,160 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\cdfs.sys -- (cdfs)
DRV:64bit: - [2009.07.02 04:16:02 | 000,040,512 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\psadd.sys -- (psadd)
DRV:64bit: - [2009.06.10 23:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009.06.10 23:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009.06.10 23:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009.06.10 22:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel(R)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009.04.07 08:33:08 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2008.05.12 11:04:26 | 000,015,400 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\smiifx64.sys -- (lenovo.smi)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9ADD7D21-A972-496F-B301-2142697D8F22}
IE:64bit: - HKLM\..\SearchScopes\{9ADD7D21-A972-496F-B301-2142697D8F22}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=LEN2&src=IE-SearchBox;
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{56ACE6FD-822B-4B40-A983-6FABA901FE08}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=LEN2&src=IE-SearchBox;
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo.msn.com
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\SearchScopes,DefaultScope = {56ACE6FD-822B-4B40-A983-6FABA901FE08}
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\SearchScopes\{EC9B9EA9-3578-40F5-891B-BEE218CCE491}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=302398&p={searchTerms}
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2010.12.20 16:13:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2010.12.20 16:13:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.05.18 16:26:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.06.01 01:29:27 | 000,000,000 | ---D | M]
 
[2010.11.09 15:48:20 | 000,000,000 | ---D | M] (No name found) -- D:\Nicole\AppData\Roaming\Mozilla\Extensions
[2012.06.03 03:03:06 | 000,000,000 | ---D | M] (No name found) -- D:\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\zni354nt.default\extensions
[2012.04.20 15:47:47 | 000,000,000 | ---D | M] (Search-Results Toolbar) -- D:\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\zni354nt.default\extensions\toolbar@ask.com
[2011.12.20 13:59:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.05.18 16:48:52 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.05.18 16:26:30 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010.11.09 21:30:29 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.02.12 16:30:35 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.02.12 16:30:35 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.02.12 16:30:35 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.12 16:30:35 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.12 16:30:35 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.12 16:30:35 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2 - BHO: (HelperObject Class) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - F:\SnagItBHO.dll File not found
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - F:\SnagItIEAddin.dll File not found
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\Toolbar\WebBrowser: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
O4:64bit: - HKLM..\Run: [AcWin7Hlpr] C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe (Lenovo)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LENOVO.TPKNRRES] C:\Programme\Lenovo\Communications Utility\TPKNRRES.exe (Lenovo Group Limited)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4:64bit: - HKLM..\Run: [TPHOTKEY] C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4:64bit: - HKLM..\Run: [TpShocks] C:\Windows\SysNative\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Search-Results)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor File not found
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11c_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:  =
O8:64bit: - Extra context menu item: An vorhandenes PDF anfügen - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Auswahl in Adobe PDF konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - D:\Nicole\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O8:64bit: - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~4\OFFICE11\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O8:64bit: - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: An vorhandenes PDF anfügen - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - D:\Nicole\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~4\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9:64bit: - Extra Button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Senden an Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Senden an &Bluetooth-Gerät... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.30.3.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A8C423AE-5A29-4B87-841A-AB6DCAAF6BD2}: DhcpNameServer = 172.30.3.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D13A9253-7542-47F9-ADCF-09DE592EC2FA}: DhcpNameServer = 195.234.128.7 195.234.128.16 85.233.58.60
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.06.10 18:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{fb550bba-bf17-11df-ba96-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{fb550bba-bf17-11df-ba96-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {DD677189-CC11-DEAF-7148-7DDD44F82F4E} - .NET Framework
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.06.03 03:02:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.05.31 21:21:18 | 000,000,000 | ---D | C] -- D:\Nicole\AppData\Roaming\Malwarebytes
[2012.05.31 21:20:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.05.31 21:20:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.05.31 21:20:55 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.05.31 21:20:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.05.31 21:19:58 | 010,063,000 | ---- | C] (Malwarebytes Corporation                                    ) -- D:\Nicole\Desktop\malwarebytes_antimalware_1.61.exe
[2012.05.31 15:34:37 | 000,000,000 | ---D | C] -- D:\Nicole\AppData\Roaming\Mmfwcyypw
[2012.05.27 09:01:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Spigot
[2012.05.27 09:01:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\pdfforge Toolbar
[2012.05.27 09:01:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Application Updater
[2012.05.18 16:48:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012.05.18 16:48:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012.05.18 16:26:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.05.18 16:26:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2011.09.12 13:14:27 | 000,250,544 | ---- | C] (KeyWorks Software) -- C:\Program Files (x86)\Common Files\keyhelp.ocx
[2010.12.13 01:48:47 | 023,448,640 | ---- | C] (DVDVideoSoft Limited.                                      ) -- C:\Program Files\FreeYouTubeToMp3Converter31.exe
[2010.12.10 00:59:13 | 011,792,152 | ---- | C] (Geek Software GmbH                                          ) -- C:\Program Files\pdf24-creator.exe
[2010.12.10 00:40:57 | 017,492,496 | ---- | C] (pdfforge GbR) -- C:\Program Files\PDFCreator-1_1_0_setup.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.06.04 20:45:33 | 000,015,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.06.04 20:45:33 | 000,015,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.06.04 20:37:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.04 20:37:41 | 1500,942,336 | -HS- | M] () -- C:\hiberfil.sys
[2012.06.04 07:20:35 | 000,618,912 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.06.04 07:20:35 | 000,107,232 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.06.04 07:20:34 | 001,507,104 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.06.04 07:20:34 | 000,657,666 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.06.04 07:20:34 | 000,131,024 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.06.03 20:33:02 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2012.06.01 01:29:29 | 000,002,459 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat - Schnellstart.lnk
[2012.06.01 01:29:29 | 000,002,097 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
[2012.06.01 00:30:08 | 000,062,065 | ---- | M] () -- D:\Nicole\Desktop\Avira-RansomFileUnlocker-1.0.1.zip
[2012.05.31 23:46:28 | 116,212,736 | ---- | M] () -- D:\Nicole\Desktop\br_free_2012g.msi
[2012.05.31 21:20:57 | 000,001,119 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.05.31 21:20:23 | 010,063,000 | ---- | M] (Malwarebytes Corporation                                    ) -- D:\Nicole\Desktop\malwarebytes_antimalware_1.61.exe
[2012.05.31 20:58:42 | 000,019,458 | ---- | M] () -- D:\Nicole\Desktop\DecryptHelper-0.4.jar
[2012.05.31 15:35:33 | 000,057,220 | ---- | M] () -- D:\Nicole\Desktop\XrXvOpupuleuvTJrpsDX
[2012.05.31 09:12:00 | 000,680,543 | ---- | M] () -- D:\Nicole\Desktop\GAfjEjsxtfAoGs
[2012.05.22 06:31:00 | 000,201,721 | ---- | M] () -- D:\Nicole\Desktop\uplJTOuurDvaOsJX
[2012.05.15 15:57:00 | 000,028,183 | ---- | M] () -- D:\Nicole\Desktop\yjqjoLxqAUjoVGnAsfq
[2012.05.11 21:50:50 | 000,481,078 | ---- | M] () -- C:\Windows\SysWow64\winsh323
[2012.05.11 21:50:40 | 000,481,078 | ---- | M] () -- C:\Windows\SysWow64\winsh322
[2012.05.11 21:50:32 | 000,481,078 | ---- | M] () -- C:\Windows\SysWow64\winsh321
[2012.05.11 21:50:22 | 000,481,078 | ---- | M] () -- C:\Windows\SysWow64\winsh320
[2012.05.10 07:16:40 | 000,000,528 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.06.01 00:30:05 | 000,062,065 | ---- | C] () -- D:\Nicole\Desktop\Avira-RansomFileUnlocker-1.0.1.zip
[2012.05.31 23:46:11 | 116,212,736 | ---- | C] () -- D:\Nicole\Desktop\br_free_2012g.msi
[2012.05.31 21:20:57 | 000,001,119 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.05.31 20:58:36 | 000,019,458 | ---- | C] () -- D:\Nicole\Desktop\DecryptHelper-0.4.jar
[2012.05.31 19:55:08 | 000,481,078 | ---- | C] () -- C:\Windows\SysWow64\winsh325
[2012.05.31 19:55:08 | 000,481,078 | ---- | C] () -- C:\Windows\SysWow64\winsh324
[2012.05.31 19:55:08 | 000,481,078 | ---- | C] () -- C:\Windows\SysWow64\winsh323
[2012.05.31 19:55:08 | 000,481,078 | ---- | C] () -- C:\Windows\SysWow64\winsh322
[2012.05.31 19:55:08 | 000,481,078 | ---- | C] () -- C:\Windows\SysWow64\winsh321
[2012.05.31 19:55:08 | 000,481,078 | ---- | C] () -- C:\Windows\SysWow64\winsh320
[2012.01.26 02:28:59 | 000,000,256 | ---- | C] () -- C:\Windows\SysWow64\pool.bin
[2011.12.28 21:01:57 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2011.01.14 15:27:48 | 095,992,680 | ---- | C] () -- C:\Program Files\col18696.exe
[2011.01.14 15:07:43 | 000,134,784 | ---- | C] () -- C:\Windows\hpoins36.dat.temp
[2011.01.14 15:07:43 | 000,000,578 | ---- | C] () -- C:\Windows\hpomdl36.dat.temp
[2011.01.14 15:01:29 | 039,965,792 | ---- | C] () -- C:\Program Files\PS_AIO_05_C4600_NonNet_Basic_Win_enu_140_047.exe
[2010.12.22 03:12:37 | 033,781,040 | ---- | C] () -- C:\Program Files\snagitde.exe
[2010.12.20 15:56:16 | 000,007,680 | ---- | C] () -- D:\Nicole\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.12.10 01:02:12 | 000,709,944 | ---- | C] () -- C:\Program Files\101209_Dissertation_Proposal.pdf
[2010.11.09 23:08:56 | 001,526,948 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.11.09 23:04:32 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010.11.09 15:48:18 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010.11.09 15:21:48 | 002,463,976 | ---- | C] () -- C:\Windows\SysWow64\NPSWF32.dll
[2010.11.09 15:02:54 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2010.09.13 11:33:35 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2010.09.13 11:33:35 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010.09.13 11:33:35 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2010.09.13 11:33:34 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2010.09.13 11:33:34 | 000,104,636 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
 
========== LOP Check ==========
 
[2012.05.10 07:16:40 | 000,000,528 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2012.06.01 07:25:29 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.06.03 20:33:02 | 000,000,332 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.10.24 13:46:04 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Adobe
[2012.01.02 01:32:19 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\aliasworlds
[2012.01.18 12:36:12 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Apple Computer
[2012.01.26 03:31:28 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Blackberry Desktop
[2010.11.13 15:57:02 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\blg
[2010.11.13 14:40:07 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Boolat Games
[2011.12.28 19:57:05 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\DivoGames
[2011.01.03 01:57:17 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\DivX
[2012.05.31 20:07:14 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Dropbox
[2012.05.31 20:07:14 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.01.03 01:48:10 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\EleFun Games
[2012.01.02 02:55:51 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Gamelab
[2011.12.28 21:01:58 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\GamesCafe
[2010.11.09 13:21:27 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Identities
[2010.11.09 15:56:57 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\IrfanView
[2010.12.20 16:13:34 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Local
[2010.11.09 21:26:44 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Macromedia
[2012.05.31 21:21:18 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Malwarebytes
[2009.07.14 09:44:38 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Media Center Programs
[2011.12.30 16:41:50 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Meridian93
[2012.05.31 20:07:36 | 000,000,000 | --SD | M] -- D:\Nicole\AppData\Roaming\Microsoft
[2012.05.31 21:54:00 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Mmfwcyypw
[2010.11.09 15:48:20 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Mozilla
[2011.10.27 10:59:23 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\OpenCandy
[2011.10.27 10:59:35 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\pdfforge
[2011.12.28 00:42:36 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Ph03nixNewMedia
[2011.12.28 14:31:11 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\PlayFirst
[2012.01.26 03:22:41 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Research In Motion
[2012.05.31 20:07:20 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\Skype
[2012.05.31 20:07:21 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\skypePM
[2012.05.31 20:07:21 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\TFS2
[2011.12.29 01:14:25 | 000,000,000 | ---D | M] -- D:\Nicole\AppData\Roaming\ViquaSoft
 
< %APPDATA%\*.exe /s >
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2010.04.13 02:44:22 | 000,540,696 | ---- | M] (Intel Corporation) MD5=1384872112E8E7FD5786ECEB8BDDF4C9 -- C:\SWTOOLS\DRIVERS\IMSM\iaStor.sys
[2010.04.13 02:44:22 | 000,540,696 | ---- | M] (Intel Corporation) MD5=1384872112E8E7FD5786ECEB8BDDF4C9 -- C:\Windows\SysNative\drivers\iaStor.sys
[2010.04.13 02:44:22 | 000,540,696 | ---- | M] (Intel Corporation) MD5=1384872112E8E7FD5786ECEB8BDDF4C9 -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_d085c8f0cb5c2856\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\SysNative\netlogon.dll
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\drivers\nvstor.sys
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\SysNative\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2010.09.13 21:09:46 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2010.09.13 21:09:46 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2010.09.13 21:09:46 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:908A1B53
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:A26AFC00
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:0988A428
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:56C66609
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:BAC2F271
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:1B3549F2
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:BD8010FE
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:4B244549
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:3B07E6F4
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:C43C957E
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:014BC3B4
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:D8134D8F
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:10D45FC3
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:9B2BD056
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:38D2EA83
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:04ADB7A6
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:8140CB50
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:6FD36C4B
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:3C0887BF
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:CFF6B3FF
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:ED9B661E
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:349E5B74
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:EA701346
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:D7DA89B1
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:67BA17B9

< End of report >

--- --- ---

cosinus 05.06.2012 11:46

Zitat:

O2 - BHO: (DivX Plus Web Player HTML5 <video>)
Sagmal gehörst du auch zur der Fraktion, die sich Serien und Kinofilme über dubiose Portale anschaut?
Wenn ja: in Zukunft Finger weg, diese illegalen Portale verbreiten Malware und wenn du in Zukunft malwarefrei sein wilst, musst du auf legale Alternativen ausweichen und auf solche riskanten Streamingseiten verzichten!
Gerade solche Streamingseiten sind für die aktuelle Welle der Erpresserschädlinge verantwortlich, die Windows blockieren und 50 oder 100 EUR erpressen wollen!!

NicoleM 05.06.2012 19:40

Hab mir mal vor längerem einen Film angeschaut. Bin aber allgemein nicht so der Filme-Gucker.

cosinus 05.06.2012 20:11

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)
Code:

:OTL
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9ADD7D21-A972-496F-B301-2142697D8F22}
IE:64bit: - HKLM\..\SearchScopes\{9ADD7D21-A972-496F-B301-2142697D8F22}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=LEN2&src=IE-SearchBox;
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{56ACE6FD-822B-4B40-A983-6FABA901FE08}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=LEN2&src=IE-SearchBox;
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.msn.com
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2269050
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\SearchScopes,DefaultScope = {56ACE6FD-822B-4B40-A983-6FABA901FE08}
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\SearchScopes\{EC9B9EA9-3578-40F5-891B-BEE218CCE491}: "URL" = http://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=302398&p={searchTerms}
[2012.04.20 15:47:47 | 000,000,000 | ---D | M] (Search-Results Toolbar) -- D:\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\zni354nt.default\extensions\toolbar@ask.com
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\Toolbar\WebBrowser: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Search-Results)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:  =
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.06.10 18:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{fb550bba-bf17-11df-ba96-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{fb550bba-bf17-11df-ba96-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:908A1B53
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:A26AFC00
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:0988A428
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:56C66609
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:BAC2F271
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:1B3549F2
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:BD8010FE
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:4B244549
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:3B07E6F4
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:C43C957E
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:014BC3B4
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:D8134D8F
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:10D45FC3
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:9B2BD056
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:38D2EA83
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:04ADB7A6
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:8140CB50
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:6FD36C4B
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:3C0887BF
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:CFF6B3FF
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:ED9B661E
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:349E5B74
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:EA701346
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:D7DA89B1
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:67BA17B9
:Files
C:\Program Files (x86)\Common Files\Spigot
C:\Program Files (x86)\Application Updater
C:\Program Files (x86)\pdfforge Toolbar
C:\Windows\SysWow64\winsh32?
C:\Program Files\col18696.exe
D:\Nicole\AppData\Roaming\Mmfwcyypw
C:\Program Files (x86)\Ask.com
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

NicoleM 05.06.2012 20:48

Irgendwie funktioniert das nicht und leider bleibt das Programm zwischendrin hängen :(

cosinus 06.06.2012 16:00

Wiederhol den Fix im abgesicherten Modus bitte

NicoleM 08.06.2012 17:10

Ich habe es jetzt noch ein paar Mal versucht.
Leider bleibt das Programm auch im abgesicherten Modus hängen :-/

cosinus 08.06.2012 17:21

Kannst du sehen bei welcher Zeile im Skript OTL hängen bleibt?

NicoleM 08.06.2012 20:53

O3 - HKLM\ Toolbar: (Search Results Toolbar) - {D4027C7F-154A-4066-A1AD-42430817440} - C:Program Files (x86)\Ask.

Mehr kann ich leider nicht lesen, da das Programm dann hängt und ich nichts anklicken kann...

cosinus 08.06.2012 21:21

Probier es bitte mal mit dem hier als Fixscript:

Code:

:OTL
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9ADD7D21-A972-496F-B301-2142697D8F22}
IE:64bit: - HKLM\..\SearchScopes\{9ADD7D21-A972-496F-B301-2142697D8F22}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=LEN2&src=IE-SearchBox;
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{56ACE6FD-822B-4B40-A983-6FABA901FE08}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=LEN2&src=IE-SearchBox;
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.msn.com
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2269050
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\SearchScopes,DefaultScope = {56ACE6FD-822B-4B40-A983-6FABA901FE08}
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\SearchScopes\{EC9B9EA9-3578-40F5-891B-BEE218CCE491}: "URL" = http://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=302398&p={searchTerms}
[2012.04.20 15:47:47 | 000,000,000 | ---D | M] (Search-Results Toolbar) -- D:\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\zni354nt.default\extensions\toolbar@ask.com
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\Toolbar\WebBrowser: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Search-Results)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:  =
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.06.10 18:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{fb550bba-bf17-11df-ba96-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{fb550bba-bf17-11df-ba96-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:908A1B53
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:A26AFC00
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:0988A428
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:56C66609
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:BAC2F271
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:1B3549F2
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:BD8010FE
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:4B244549
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:3B07E6F4
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:C43C957E
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:014BC3B4
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:D8134D8F
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:10D45FC3
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:9B2BD056
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:38D2EA83
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:04ADB7A6
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:8140CB50
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:6FD36C4B
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:3C0887BF
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:CFF6B3FF
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:ED9B661E
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:349E5B74
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:EA701346
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:D7DA89B1
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:67BA17B9
:Files
C:\Program Files (x86)\Common Files\Spigot
C:\Program Files (x86)\Application Updater
C:\Program Files (x86)\pdfforge Toolbar
C:\Windows\SysWow64\winsh32?
C:\Program Files\col18696.exe
D:\Nicole\AppData\Roaming\Mmfwcyypw
C:\Program Files (x86)\Ask.com
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]


NicoleM 08.06.2012 21:34

Jetzt hängt wieder:

O3 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\...\Toolbar\WebBrowser: (Search Results Toolbar)

Weiter kann ich wieder net, weil es hängt...

cosinus 08.06.2012 21:58

Dann probier es damit (alle O3-Zeilen weg, die sind eh nur nice2have zu löschen aber nicht wirklich schlimm oder wichtig)

Code:

:OTL
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9ADD7D21-A972-496F-B301-2142697D8F22}
IE:64bit: - HKLM\..\SearchScopes\{9ADD7D21-A972-496F-B301-2142697D8F22}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=LEN2&src=IE-SearchBox;
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{56ACE6FD-822B-4B40-A983-6FABA901FE08}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=LEN2&src=IE-SearchBox;
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.msn.com
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2269050
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\SearchScopes,DefaultScope = {56ACE6FD-822B-4B40-A983-6FABA901FE08}
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
IE - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\..\SearchScopes\{EC9B9EA9-3578-40F5-891B-BEE218CCE491}: "URL" = http://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=302398&p={searchTerms}
[2012.04.20 15:47:47 | 000,000,000 | ---D | M] (Search-Results Toolbar) -- D:\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\zni354nt.default\extensions\toolbar@ask.com
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Search-Results)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:  =
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.06.10 18:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{fb550bba-bf17-11df-ba96-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{fb550bba-bf17-11df-ba96-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:908A1B53
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:A26AFC00
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:0988A428
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:56C66609
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:BAC2F271
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:1B3549F2
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:BD8010FE
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:4B244549
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:3B07E6F4
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:C43C957E
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:014BC3B4
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:D8134D8F
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:10D45FC3
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:9B2BD056
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:38D2EA83
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:04ADB7A6
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:8140CB50
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:6FD36C4B
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:3C0887BF
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:CFF6B3FF
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:ED9B661E
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:349E5B74
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:EA701346
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:D7DA89B1
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:67BA17B9
:Files
C:\Program Files (x86)\Common Files\Spigot
C:\Program Files (x86)\Application Updater
C:\Program Files (x86)\pdfforge Toolbar
C:\Windows\SysWow64\winsh32?
C:\Program Files\col18696.exe
D:\Nicole\AppData\Roaming\Mmfwcyypw
C:\Program Files (x86)\Ask.com
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]


NicoleM 09.06.2012 09:53

Code:

All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9ADD7D21-A972-496F-B301-2142697D8F22}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9ADD7D21-A972-496F-B301-2142697D8F22}\ not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found.
File C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56ACE6FD-822B-4B40-A983-6FABA901FE08}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56ACE6FD-822B-4B40-A983-6FABA901FE08}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Secondary_Page_URL| /E : value set successfully!
HKU\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-3728700144-1891460459-2374237516-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found.
File C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll not found.
Registry value HKEY_USERS\S-1-5-21-3728700144-1891460459-2374237516-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{B922D405-6D13-4A2B-AE89-08A030DA4402} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ not found.
File C:\Program Files (x86)\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll not found.
HKEY_USERS\S-1-5-21-3728700144-1891460459-2374237516-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3728700144-1891460459-2374237516-1001\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_USERS\S-1-5-21-3728700144-1891460459-2374237516-1001\Software\Microsoft\Internet Explorer\SearchScopes\{EC9B9EA9-3578-40F5-891B-BEE218CCE491}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC9B9EA9-3578-40F5-891B-BEE218CCE491}\ not found.
Folder D:\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\zni354nt.default\extensions\toolbar@ask.com\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{326E768D-4182-46FD-9C16-1449A49795F4}\ not found.
File C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}\ not found.
File C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found.
File C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ not found.
File C:\Program Files (x86)\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater deleted successfully.
C:\Program Files (x86)\Ask.com\Updater\Updater.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DivX Download Manager deleted successfully.
C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate deleted successfully.
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings deleted successfully.
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe moved successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLUA deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\PromptOnSecureDesktop deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3728700144-1891460459-2374237516-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Q:\AUTORUN.INF moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fb550bba-bf17-11df-ba96-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fb550bba-bf17-11df-ba96-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fb550bba-bf17-11df-ba96-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fb550bba-bf17-11df-ba96-806e6f6e6963}\ not found.
File Q:\LenovoQDrive.exe not found.
ADS C:\ProgramData\TEMP:908A1B53 deleted successfully.
ADS C:\ProgramData\TEMP:A26AFC00 deleted successfully.
ADS C:\ProgramData\TEMP:0988A428 deleted successfully.
ADS C:\ProgramData\TEMP:56C66609 deleted successfully.
ADS C:\ProgramData\TEMP:BAC2F271 deleted successfully.
ADS C:\ProgramData\TEMP:1B3549F2 deleted successfully.
ADS C:\ProgramData\TEMP:BD8010FE deleted successfully.
ADS C:\ProgramData\TEMP:4B244549 deleted successfully.
ADS C:\ProgramData\TEMP:3B07E6F4 deleted successfully.
ADS C:\ProgramData\TEMP:C43C957E deleted successfully.
ADS C:\ProgramData\TEMP:014BC3B4 deleted successfully.
ADS C:\ProgramData\TEMP:D8134D8F deleted successfully.
ADS C:\ProgramData\TEMP:10D45FC3 deleted successfully.
ADS C:\ProgramData\TEMP:9B2BD056 deleted successfully.
ADS C:\ProgramData\TEMP:38D2EA83 deleted successfully.
ADS C:\ProgramData\TEMP:04ADB7A6 deleted successfully.
ADS C:\ProgramData\TEMP:8140CB50 deleted successfully.
ADS C:\ProgramData\TEMP:6FD36C4B deleted successfully.
ADS C:\ProgramData\TEMP:3C0887BF deleted successfully.
ADS C:\ProgramData\TEMP:CFF6B3FF deleted successfully.
ADS C:\ProgramData\TEMP:ED9B661E deleted successfully.
ADS C:\ProgramData\TEMP:349E5B74 deleted successfully.
ADS C:\ProgramData\TEMP:EA701346 deleted successfully.
ADS C:\ProgramData\TEMP:D7DA89B1 deleted successfully.
ADS C:\ProgramData\TEMP:67BA17B9 deleted successfully.
========== FILES ==========
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot\wtxpcom folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot\Search Settings\Res folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot\Search Settings\Lang folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot\Search Settings folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot folder moved successfully.
C:\Program Files (x86)\Application Updater folder moved successfully.
C:\Program Files (x86)\pdfforge Toolbar\Res\Lang folder moved successfully.
C:\Program Files (x86)\pdfforge Toolbar\Res folder moved successfully.
C:\Program Files (x86)\pdfforge Toolbar\IE\5.8 folder moved successfully.
C:\Program Files (x86)\pdfforge Toolbar\IE folder moved successfully.
C:\Program Files (x86)\pdfforge Toolbar\FF\chrome folder moved successfully.
C:\Program Files (x86)\pdfforge Toolbar\FF folder moved successfully.
C:\Program Files (x86)\pdfforge Toolbar folder moved successfully.
C:\Windows\SysWow64\winsh320 moved successfully.
C:\Windows\SysWow64\winsh321 moved successfully.
C:\Windows\SysWow64\winsh322 moved successfully.
C:\Windows\SysWow64\winsh323 moved successfully.
C:\Windows\SysWow64\winsh324 moved successfully.
C:\Windows\SysWow64\winsh325 moved successfully.
C:\Program Files\col18696.exe moved successfully.
D:\Nicole\AppData\Roaming\Mmfwcyypw folder moved successfully.
C:\Program Files (x86)\Ask.com\Updater folder moved successfully.
C:\Program Files (x86)\Ask.com\assets\oobe folder moved successfully.
C:\Program Files (x86)\Ask.com\assets folder moved successfully.
C:\Program Files (x86)\Ask.com folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: $RECYCLE.BIN
 
User: AppData
 
User: MSOCache
 
User: Nicole
->Temp folder emptied: 4783220124 bytes
->Temporary Internet Files folder emptied: 86717351 bytes
->Java cache emptied: 3886116 bytes
->FireFox cache emptied: 99204150 bytes
->Flash cache emptied: 195471 bytes
 
User: Program Files
 
User: System Volume Information
 
User: _OTL
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 841270 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 60299877 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 102494 bytes
RecycleBin emptied: 597436185 bytes
 
Total Files Cleaned = 5.371,00 mb
 
 
[EMPTYFLASH]
 
User: $RECYCLE.BIN
 
User: AppData
 
User: MSOCache
 
User: Nicole
->Flash cache emptied: 0 bytes
 
User: Program Files
 
User: System Volume Information
 
User: _OTL
 
Total Flash Files Cleaned = 0,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.46.0 log created on 06092012_103150

Files\Folders moved on Reboot...
File move failed. D:\Nicole\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...


cosinus 09.06.2012 23:57

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

NicoleM 10.06.2012 08:42

Code:

09:35:29.0892 5396        TDSS rootkit removing tool 2.7.36.0 May 21 2012 16:40:16
09:35:29.0980 5396        ============================================================
09:35:29.0980 5396        Current date / time: 2012/06/10 09:35:29.0980
09:35:29.0980 5396        SystemInfo:
09:35:29.0980 5396       
09:35:29.0980 5396        OS Version: 6.1.7600 ServicePack: 0.0
09:35:29.0980 5396        Product type: Workstation
09:35:29.0981 5396        ComputerName: NICOLES_ZWERG
09:35:29.0981 5396        UserName: Nicole
09:35:29.0981 5396        Windows directory: C:\Windows
09:35:29.0981 5396        System windows directory: C:\Windows
09:35:29.0981 5396        Running under WOW64
09:35:29.0981 5396        Processor architecture: Intel x64
09:35:29.0981 5396        Number of processors: 4
09:35:29.0981 5396        Page size: 0x1000
09:35:29.0981 5396        Boot type: Normal boot
09:35:29.0981 5396        ============================================================
09:35:31.0164 5396        Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
09:35:31.0174 5396        ============================================================
09:35:31.0174 5396        \Device\Harddisk0\DR0:
09:35:31.0174 5396        MBR partitions:
09:35:31.0174 5396        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x258000
09:35:31.0174 5396        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x258800, BlocksNum 0x3AA3800
09:35:31.0189 5396        \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x3CFC800, BlocksNum 0x203A9000
09:35:31.0189 5396        \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x240A6000, BlocksNum 0x1388000
09:35:31.0189 5396        ============================================================
09:35:31.0230 5396        C: <-> \Device\Harddisk0\DR0\Partition1
09:35:31.0274 5396        Q: <-> \Device\Harddisk0\DR0\Partition3
09:35:31.0327 5396        D: <-> \Device\Harddisk0\DR0\Partition2
09:35:31.0368 5396        ============================================================
09:35:31.0368 5396        Initialize success
09:35:31.0368 5396        ============================================================
09:38:35.0573 2728        ============================================================
09:38:35.0573 2728        Scan started
09:38:35.0573 2728        Mode: Manual; SigCheck; TDLFS;
09:38:35.0573 2728        ============================================================
09:38:37.0141 2728        1394ohci        (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
09:38:38.0437 2728        1394ohci - ok
09:38:39.0533 2728        ACPI            (794ff35015209b9d44f1360c42c9776d) C:\Windows\system32\DRIVERS\ACPI.sys
09:38:39.0578 2728        ACPI - ok
09:38:39.0697 2728        AcpiPmi        (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
09:38:39.0862 2728        AcpiPmi - ok
09:38:40.0039 2728        AcPrfMgrSvc    (1f8b13196f7a45019d9dec9fdd473c71) C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
09:38:40.0053 2728        AcPrfMgrSvc - ok
09:38:40.0161 2728        AcSvc          (f541512b2bba14aaab8140021d75a83c) C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
09:38:40.0177 2728        AcSvc - ok
09:38:40.0457 2728        AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
09:38:40.0488 2728        AdobeARMservice - ok
09:38:41.0018 2728        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
09:38:41.0081 2728        adp94xx - ok
09:38:41.0128 2728        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
09:38:41.0159 2728        adpahci - ok
09:38:41.0206 2728        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
09:38:41.0221 2728        adpu320 - ok
09:38:41.0268 2728        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
09:38:41.0440 2728        AeLookupSvc - ok
09:38:41.0533 2728        AFD            (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
09:38:41.0642 2728        AFD - ok
09:38:41.0705 2728        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
09:38:41.0720 2728        agp440 - ok
09:38:41.0767 2728        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
09:38:41.0830 2728        ALG - ok
09:38:41.0861 2728        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
09:38:41.0876 2728        aliide - ok
09:38:41.0892 2728        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
09:38:41.0892 2728        amdide - ok
09:38:41.0923 2728        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
09:38:41.0970 2728        AmdK8 - ok
09:38:41.0970 2728        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
09:38:42.0001 2728        AmdPPM - ok
09:38:42.0032 2728        amdsata        (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
09:38:42.0048 2728        amdsata - ok
09:38:42.0079 2728        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
09:38:42.0095 2728        amdsbs - ok
09:38:42.0110 2728        amdxata        (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
09:38:42.0126 2728        amdxata - ok
09:38:42.0142 2728        AppID          (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
09:38:42.0235 2728        AppID - ok
09:38:42.0251 2728        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
09:38:42.0329 2728        AppIDSvc - ok
09:38:42.0376 2728        Appinfo        (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
09:38:42.0454 2728        Appinfo - ok
09:38:42.0563 2728        Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
09:38:42.0578 2728        Apple Mobile Device - ok
09:38:42.0610 2728        Application Updater - ok
09:38:42.0656 2728        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
09:38:42.0672 2728        arc - ok
09:38:42.0688 2728        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
09:38:42.0703 2728        arcsas - ok
09:38:42.0719 2728        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
09:38:42.0797 2728        AsyncMac - ok
09:38:42.0812 2728        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
09:38:42.0828 2728        atapi - ok
09:38:42.0922 2728        AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
09:38:43.0015 2728        AudioEndpointBuilder - ok
09:38:43.0031 2728        AudioSrv        (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
09:38:43.0093 2728        AudioSrv - ok
09:38:43.0140 2728        AxInstSV        (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
09:38:43.0171 2728        AxInstSV - ok
09:38:43.0249 2728        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
09:38:43.0280 2728        b06bdrv - ok
09:38:43.0343 2728        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
09:38:43.0390 2728        b57nd60a - ok
09:38:43.0421 2728        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
09:38:43.0468 2728        BDESVC - ok
09:38:43.0483 2728        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
09:38:43.0577 2728        Beep - ok
09:38:43.0655 2728        BFE            (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
09:38:43.0748 2728        BFE - ok
09:38:43.0842 2728        BITS            (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
09:38:43.0967 2728        BITS - ok
09:38:44.0045 2728        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
09:38:44.0076 2728        blbdrive - ok
09:38:44.0154 2728        Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
09:38:44.0170 2728        Bonjour Service - ok
09:38:44.0216 2728        bowser          (91ce0d3dc57dd377e690a2d324022b08) C:\Windows\system32\DRIVERS\bowser.sys
09:38:44.0294 2728        bowser - ok
09:38:44.0326 2728        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
09:38:44.0357 2728        BrFiltLo - ok
09:38:44.0357 2728        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
09:38:44.0388 2728        BrFiltUp - ok
09:38:44.0435 2728        Browser        (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
09:38:44.0528 2728        Browser - ok
09:38:44.0544 2728        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
09:38:44.0575 2728        Brserid - ok
09:38:44.0591 2728        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
09:38:44.0622 2728        BrSerWdm - ok
09:38:44.0638 2728        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
09:38:44.0669 2728        BrUsbMdm - ok
09:38:44.0684 2728        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
09:38:44.0716 2728        BrUsbSer - ok
09:38:44.0747 2728        BthEnum        (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\DRIVERS\BthEnum.sys
09:38:44.0794 2728        BthEnum - ok
09:38:44.0825 2728        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
09:38:44.0856 2728        BTHMODEM - ok
09:38:44.0872 2728        BthPan          (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
09:38:44.0918 2728        BthPan - ok
09:38:44.0981 2728        BTHPORT        (a51fa9d0e85d5adabef72e67f386309c) C:\Windows\system32\Drivers\BTHport.sys
09:38:45.0028 2728        BTHPORT - ok
09:38:45.0090 2728        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
09:38:45.0152 2728        bthserv - ok
09:38:45.0168 2728        BTHUSB          (f740b9a16b2c06700f2130e19986bf3b) C:\Windows\system32\Drivers\BTHUSB.sys
09:38:45.0199 2728        BTHUSB - ok
09:38:45.0230 2728        btusbflt        (2641a3fe3d7b0646308f33b67f3b5300) C:\Windows\system32\drivers\btusbflt.sys
09:38:45.0308 2728        btusbflt - ok
09:38:45.0355 2728        btwaudio        (a72a9101f9730db7332714e566614e4d) C:\Windows\system32\drivers\btwaudio.sys
09:38:45.0371 2728        btwaudio - ok
09:38:45.0418 2728        btwavdt        (5ceec634b617525f2b6ad29f871033f7) C:\Windows\system32\DRIVERS\btwavdt.sys
09:38:45.0418 2728        btwavdt - ok
09:38:45.0574 2728        btwdins        (1d2a95842f8dddedd9b600a9cc7936b5) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
09:38:45.0620 2728        btwdins - ok
09:38:45.0667 2728        btwl2cap        (6149301dc3f81d6f9667a3fbac410975) C:\Windows\system32\DRIVERS\btwl2cap.sys
09:38:45.0667 2728        btwl2cap - ok
09:38:45.0698 2728        btwrchid        (2af5604d28bef77b7cf4b9d232fe7cd3) C:\Windows\system32\DRIVERS\btwrchid.sys
09:38:45.0698 2728        btwrchid - ok
09:38:45.0745 2728        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
09:38:45.0823 2728        cdfs - ok
09:38:45.0854 2728        cdrom          (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
09:38:45.0886 2728        cdrom - ok
09:38:45.0917 2728        CertPropSvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
09:38:45.0995 2728        CertPropSvc - ok
09:38:46.0042 2728        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
09:38:46.0073 2728        circlass - ok
09:38:46.0120 2728        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
09:38:46.0151 2728        CLFS - ok
09:38:46.0213 2728        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
09:38:46.0229 2728        clr_optimization_v2.0.50727_32 - ok
09:38:46.0276 2728        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
09:38:46.0291 2728        clr_optimization_v2.0.50727_64 - ok
09:38:46.0385 2728        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
09:38:46.0400 2728        clr_optimization_v4.0.30319_32 - ok
09:38:46.0432 2728        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
09:38:46.0447 2728        clr_optimization_v4.0.30319_64 - ok
09:38:46.0478 2728        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
09:38:46.0510 2728        CmBatt - ok
09:38:46.0525 2728        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
09:38:46.0541 2728        cmdide - ok
09:38:46.0588 2728        CNG            (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
09:38:46.0666 2728        CNG - ok
09:38:46.0759 2728        CnxtHdAudService (a7d943bcfb70f1f053c274b348267b55) C:\Windows\system32\drivers\CHDRT64.sys
09:38:46.0806 2728        CnxtHdAudService - ok
09:38:46.0853 2728        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
09:38:46.0868 2728        Compbatt - ok
09:38:46.0915 2728        CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
09:38:46.0962 2728        CompositeBus - ok
09:38:46.0978 2728        COMSysApp - ok
09:38:46.0993 2728        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
09:38:47.0009 2728        crcdisk - ok
09:38:47.0056 2728        CryptSvc        (8c57411b66282c01533cb776f98ad384) C:\Windows\system32\cryptsvc.dll
09:38:47.0134 2728        CryptSvc - ok
09:38:47.0196 2728        DcomLaunch      (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
09:38:47.0290 2728        DcomLaunch - ok
09:38:47.0352 2728        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
09:38:47.0446 2728        defragsvc - ok
09:38:47.0492 2728        DfsC            (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
09:38:47.0570 2728        DfsC - ok
09:38:47.0633 2728        Dhcp            (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
09:38:47.0726 2728        Dhcp - ok
09:38:47.0773 2728        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
09:38:47.0836 2728        discache - ok
09:38:47.0898 2728        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
09:38:47.0898 2728        Disk - ok
09:38:47.0945 2728        Dnscache        (676108c4e3aa6f6b34633748bd0bebd9) C:\Windows\System32\dnsrslvr.dll
09:38:48.0054 2728        Dnscache - ok
09:38:48.0101 2728        dot3svc        (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
09:38:48.0179 2728        dot3svc - ok
09:38:48.0257 2728        Dot4            (b42ed0320c6e41102fde0005154849bb) C:\Windows\system32\DRIVERS\Dot4.sys
09:38:48.0288 2728        Dot4 - ok
09:38:48.0319 2728        Dot4Print      (85135ad27e79b689335c08167d917cde) C:\Windows\system32\DRIVERS\Dot4Prt.sys
09:38:48.0350 2728        Dot4Print - ok
09:38:48.0366 2728        dot4usb        (fd05a02b0370bc3000f402e543ca5814) C:\Windows\system32\DRIVERS\dot4usb.sys
09:38:48.0382 2728        dot4usb - ok
09:38:48.0413 2728        DPS            (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
09:38:48.0475 2728        DPS - ok
09:38:48.0522 2728        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
09:38:48.0553 2728        drmkaud - ok
09:38:48.0647 2728        DXGKrnl        (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys
09:38:48.0694 2728        DXGKrnl - ok
09:38:48.0756 2728        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
09:38:48.0834 2728        EapHost - ok
09:38:49.0130 2728        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
09:38:49.0240 2728        ebdrv - ok
09:38:49.0349 2728        EFS            (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\System32\lsass.exe
09:38:49.0380 2728        EFS - ok
09:38:49.0474 2728        ehRecvr        (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
09:38:49.0536 2728        ehRecvr - ok
09:38:49.0567 2728        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
09:38:49.0614 2728        ehSched - ok
09:38:49.0739 2728        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
09:38:49.0770 2728        elxstor - ok
09:38:49.0770 2728        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
09:38:49.0817 2728        ErrDev - ok
09:38:49.0879 2728        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
09:38:49.0957 2728        EventSystem - ok
09:38:49.0988 2728        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
09:38:50.0066 2728        exfat - ok
09:38:50.0113 2728        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
09:38:50.0207 2728        fastfat - ok
09:38:50.0285 2728        Fax            (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
09:38:50.0332 2728        Fax - ok
09:38:50.0363 2728        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
09:38:50.0378 2728        fdc - ok
09:38:50.0410 2728        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
09:38:50.0472 2728        fdPHost - ok
09:38:50.0503 2728        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
09:38:50.0566 2728        FDResPub - ok
09:38:50.0581 2728        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
09:38:50.0597 2728        FileInfo - ok
09:38:50.0612 2728        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
09:38:50.0690 2728        Filetrace - ok
09:38:50.0784 2728        FLEXnet Licensing Service (227846995afeefa70d328bf5334a86a5) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
09:38:50.0831 2728        FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - warning
09:38:50.0831 2728        FLEXnet Licensing Service - detected UnsignedFile.Multi.Generic (1)
09:38:50.0862 2728        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
09:38:50.0893 2728        flpydisk - ok
09:38:50.0924 2728        FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
09:38:50.0940 2728        FltMgr - ok
09:38:51.0049 2728        FontCache      (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll
09:38:51.0158 2728        FontCache - ok
09:38:51.0236 2728        FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
09:38:51.0252 2728        FontCache3.0.0.0 - ok
09:38:51.0283 2728        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
09:38:51.0299 2728        FsDepends - ok
09:38:51.0314 2728        Fs_Rec          (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
09:38:51.0330 2728        Fs_Rec - ok
09:38:51.0377 2728        fvevol          (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
09:38:51.0392 2728        fvevol - ok
09:38:51.0424 2728        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
09:38:51.0439 2728        gagp30kx - ok
09:38:51.0486 2728        GEARAspiWDM    (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
09:38:51.0502 2728        GEARAspiWDM - ok
09:38:51.0580 2728        gpsvc          (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
09:38:51.0642 2728        gpsvc - ok
09:38:51.0689 2728        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
09:38:51.0736 2728        hcw85cir - ok
09:38:51.0782 2728        HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
09:38:51.0814 2728        HdAudAddService - ok
09:38:51.0860 2728        HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
09:38:51.0892 2728        HDAudBus - ok
09:38:51.0938 2728        HECIx64        (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
09:38:51.0954 2728        HECIx64 - ok
09:38:51.0970 2728        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
09:38:51.0985 2728        HidBatt - ok
09:38:52.0016 2728        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
09:38:52.0048 2728        HidBth - ok
09:38:52.0048 2728        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
09:38:52.0079 2728        HidIr - ok
09:38:52.0110 2728        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
09:38:52.0172 2728        hidserv - ok
09:38:52.0204 2728        HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
09:38:52.0219 2728        HidUsb - ok
09:38:52.0250 2728        hkmsvc          (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
09:38:52.0313 2728        hkmsvc - ok
09:38:52.0344 2728        HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
09:38:52.0406 2728        HomeGroupListener - ok
09:38:52.0438 2728        HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
09:38:52.0469 2728        HomeGroupProvider - ok
09:38:52.0500 2728        HpSAMD          (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
09:38:52.0516 2728        HpSAMD - ok
09:38:52.0609 2728        HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
09:38:52.0703 2728        HTTP - ok
09:38:52.0718 2728        hwpolicy        (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
09:38:52.0734 2728        hwpolicy - ok
09:38:52.0781 2728        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
09:38:52.0796 2728        i8042prt - ok
09:38:52.0859 2728        iaStor          (1384872112e8e7fd5786eceb8bddf4c9) C:\Windows\system32\DRIVERS\iaStor.sys
09:38:52.0874 2728        iaStor - ok
09:38:52.0937 2728        iaStorV        (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
09:38:52.0952 2728        iaStorV - ok
09:38:52.0984 2728        IBMPMDRV        (3761fab385f1c2f51b2fad48cfabbe9d) C:\Windows\system32\DRIVERS\ibmpmdrv.sys
09:38:52.0984 2728        IBMPMDRV - ok
09:38:52.0999 2728        IBMPMSVC        (fc22310f3862e2c7c8722ef4778d5cc3) C:\Windows\system32\ibmpmsvc.exe
09:38:53.0015 2728        IBMPMSVC - ok
09:38:53.0155 2728        idsvc          (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
09:38:53.0186 2728        idsvc - ok
09:38:54.0044 2728        igfx            (09ce164afa8483e41808784d7fca154e) C:\Windows\system32\DRIVERS\igdkmd64.sys
09:38:54.0481 2728        igfx - ok
09:38:54.0653 2728        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
09:38:54.0668 2728        iirsp - ok
09:38:54.0762 2728        IKEEXT          (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
09:38:54.0856 2728        IKEEXT - ok
09:38:54.0902 2728        Impcd          (dd587a55390ed2295bce6d36ad567da9) C:\Windows\system32\DRIVERS\Impcd.sys
09:38:54.0934 2728        Impcd - ok
09:38:54.0996 2728        IntcDAud        (58cf58dee26c909bd6f977b61d246295) C:\Windows\system32\DRIVERS\IntcDAud.sys
09:38:55.0043 2728        IntcDAud - ok
09:38:55.0058 2728        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
09:38:55.0074 2728        intelide - ok
09:38:55.0105 2728        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
09:38:55.0136 2728        intelppm - ok
09:38:55.0168 2728        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
09:38:55.0246 2728        IPBusEnum - ok
09:38:55.0246 2728        IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
09:38:55.0308 2728        IpFilterDriver - ok
09:38:55.0355 2728        iphlpsvc        (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
09:38:55.0464 2728        iphlpsvc - ok
09:38:55.0480 2728        IPMIDRV        (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
09:38:55.0495 2728        IPMIDRV - ok
09:38:55.0511 2728        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
09:38:55.0589 2728        IPNAT - ok
09:38:55.0745 2728        iPod Service    (755e4ba6dce627a2683bb7640553c8d6) C:\Program Files\iPod\bin\iPodService.exe
09:38:55.0792 2728        iPod Service - ok
09:38:55.0807 2728        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
09:38:55.0838 2728        IRENUM - ok
09:38:55.0870 2728        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
09:38:55.0870 2728        isapnp - ok
09:38:55.0901 2728        iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
09:38:55.0932 2728        iScsiPrt - ok
09:38:55.0948 2728        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
09:38:55.0963 2728        kbdclass - ok
09:38:55.0979 2728        kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
09:38:56.0010 2728        kbdhid - ok
09:38:56.0041 2728        KeyIso          (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
09:38:56.0072 2728        KeyIso - ok
09:38:56.0072 2728        KSecDD          (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
09:38:56.0088 2728        KSecDD - ok
09:38:56.0119 2728        KSecPkg        (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
09:38:56.0135 2728        KSecPkg - ok
09:38:56.0166 2728        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
09:38:56.0244 2728        ksthunk - ok
09:38:56.0275 2728        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
09:38:56.0353 2728        KtmRm - ok
09:38:56.0384 2728        LanmanServer    (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
09:38:56.0431 2728        LanmanServer - ok
09:38:56.0447 2728        LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
09:38:56.0525 2728        LanmanWorkstation - ok
09:38:56.0587 2728        LENOVO.CAMMUTE  (70481dabd9adab51a6933c5893b82925) C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
09:38:56.0603 2728        LENOVO.CAMMUTE - ok
09:38:56.0650 2728        LENOVO.MICMUTE  (c88eb33793420a79f601fb5e33e2edd9) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
09:38:56.0650 2728        LENOVO.MICMUTE - ok
09:38:56.0712 2728        lenovo.smi      (5acff5823634bc2c4ebf559c3b33e18e) C:\Windows\system32\DRIVERS\smiifx64.sys
09:38:56.0712 2728        lenovo.smi - ok
09:38:56.0743 2728        LENOVO.TPKNRSVC (d0daf6a22037f6dee706a095c647aa41) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
09:38:56.0759 2728        LENOVO.TPKNRSVC - ok
09:38:56.0790 2728        Lenovo.VIRTSCRLSVC (6f2cc57eb5836d2ac9bd37f3554d55f8) C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
09:38:56.0790 2728        Lenovo.VIRTSCRLSVC - ok
09:38:56.0837 2728        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
09:38:56.0915 2728        lltdio - ok
09:38:56.0962 2728        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
09:38:57.0024 2728        lltdsvc - ok
09:38:57.0055 2728        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
09:38:57.0118 2728        lmhosts - ok
09:38:57.0196 2728        LMS            (5460828f8951d310b42b442877603b8d) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
09:38:57.0211 2728        LMS - ok
09:38:57.0242 2728        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
09:38:57.0258 2728        LSI_FC - ok
09:38:57.0274 2728        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
09:38:57.0289 2728        LSI_SAS - ok
09:38:57.0305 2728        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
09:38:57.0320 2728        LSI_SAS2 - ok
09:38:57.0336 2728        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
09:38:57.0352 2728        LSI_SCSI - ok
09:38:57.0383 2728        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
09:38:57.0461 2728        luafv - ok
09:38:57.0539 2728        MBAMProtector  (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
09:38:57.0554 2728        MBAMProtector - ok
09:38:57.0664 2728        MBAMService    (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
09:38:57.0695 2728        MBAMService - ok
09:38:57.0710 2728        Mcx2Svc        (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
09:38:57.0742 2728        Mcx2Svc - ok
09:38:57.0835 2728        MDM            (11f714f85530a2bd134074dc30e99fca) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
09:38:57.0866 2728        MDM - ok
09:38:58.0069 2728        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
09:38:58.0116 2728        megasas - ok
09:38:58.0147 2728        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
09:38:58.0178 2728        MegaSR - ok
09:38:58.0210 2728        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
09:38:58.0288 2728        MMCSS - ok
09:38:58.0303 2728        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
09:38:58.0381 2728        Modem - ok
09:38:58.0412 2728        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
09:38:58.0444 2728        monitor - ok
09:38:58.0475 2728        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
09:38:58.0490 2728        mouclass - ok
09:38:58.0537 2728        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
09:38:58.0553 2728        mouhid - ok
09:38:58.0568 2728        mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
09:38:58.0584 2728        mountmgr - ok
09:38:58.0646 2728        MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
09:38:58.0678 2728        MozillaMaintenance - ok
09:38:58.0693 2728        mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
09:38:58.0709 2728        mpio - ok
09:38:58.0740 2728        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
09:38:58.0802 2728        mpsdrv - ok
09:38:58.0880 2728        MpsSvc          (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
09:38:58.0974 2728        MpsSvc - ok
09:38:59.0005 2728        MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
09:38:59.0036 2728        MRxDAV - ok
09:38:59.0068 2728        mrxsmb          (767a4c3bcf9410c286ced15a2db17108) C:\Windows\system32\DRIVERS\mrxsmb.sys
09:38:59.0114 2728        mrxsmb - ok
09:38:59.0146 2728        mrxsmb10        (920ee0ff995fcfdeb08c41605a959e1c) C:\Windows\system32\DRIVERS\mrxsmb10.sys
09:38:59.0192 2728        mrxsmb10 - ok
09:38:59.0208 2728        mrxsmb20        (740d7ea9d72c981510a5292cf6adc941) C:\Windows\system32\DRIVERS\mrxsmb20.sys
09:38:59.0224 2728        mrxsmb20 - ok
09:38:59.0239 2728        msahci          (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
09:38:59.0255 2728        msahci - ok
09:38:59.0270 2728        msdsm          (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
09:38:59.0286 2728        msdsm - ok
09:38:59.0333 2728        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
09:38:59.0348 2728        MSDTC - ok
09:38:59.0395 2728        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
09:38:59.0458 2728        Msfs - ok
09:38:59.0489 2728        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
09:38:59.0567 2728        mshidkmdf - ok
09:38:59.0582 2728        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
09:38:59.0598 2728        msisadrv - ok
09:38:59.0629 2728        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
09:38:59.0707 2728        MSiSCSI - ok
09:38:59.0723 2728        msiserver - ok
09:38:59.0754 2728        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
09:38:59.0832 2728        MSKSSRV - ok
09:38:59.0848 2728        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
09:38:59.0910 2728        MSPCLOCK - ok
09:38:59.0926 2728        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
09:39:00.0004 2728        MSPQM - ok
09:39:00.0035 2728        MsRPC          (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
09:39:00.0066 2728        MsRPC - ok
09:39:00.0082 2728        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
09:39:00.0097 2728        mssmbios - ok
09:39:00.0128 2728        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
09:39:00.0191 2728        MSTEE - ok
09:39:00.0206 2728        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
09:39:00.0238 2728        MTConfig - ok
09:39:00.0269 2728        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
09:39:00.0284 2728        Mup - ok
09:39:00.0347 2728        napagent        (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
09:39:00.0425 2728        napagent - ok
09:39:00.0472 2728        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
09:39:00.0518 2728        NativeWifiP - ok
09:39:00.0628 2728        NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
09:39:00.0690 2728        NDIS - ok
09:39:00.0721 2728        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
09:39:00.0799 2728        NdisCap - ok
09:39:00.0830 2728        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
09:39:00.0908 2728        NdisTapi - ok
09:39:00.0924 2728        Ndisuio        (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
09:39:01.0002 2728        Ndisuio - ok
09:39:01.0033 2728        NdisWan        (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
09:39:01.0111 2728        NdisWan - ok
09:39:01.0127 2728        NDProxy        (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
09:39:01.0189 2728        NDProxy - ok
09:39:01.0252 2728        Net Driver HPZ12 (d5ac41ae382738483faffbd7e373d49a) C:\Windows\system32\HPZinw12.dll
09:39:01.0267 2728        Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
09:39:01.0267 2728        Net Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
09:39:01.0314 2728        Netaapl        (6f4607e2333fe21e9e3ff8133a88b35b) C:\Windows\system32\DRIVERS\netaapl64.sys
09:39:01.0345 2728        Netaapl - ok
09:39:01.0376 2728        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
09:39:01.0439 2728        NetBIOS - ok
09:39:01.0486 2728        NetBT          (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
09:39:01.0548 2728        NetBT - ok
09:39:01.0579 2728        Netlogon        (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
09:39:01.0595 2728        Netlogon - ok
09:39:01.0657 2728        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
09:39:01.0735 2728        Netman - ok
09:39:01.0782 2728        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
09:39:01.0860 2728        netprofm - ok
09:39:01.0954 2728        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
09:39:01.0969 2728        NetTcpPortSharing - ok
09:39:02.0453 2728        netw5v64        (64428dfdaf6e88366cb51f45a79c5f69) C:\Windows\system32\DRIVERS\netw5v64.sys
09:39:02.0702 2728        netw5v64 - ok
09:39:02.0843 2728        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
09:39:02.0858 2728        nfrd960 - ok
09:39:02.0952 2728        NlaSvc          (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
09:39:03.0030 2728        NlaSvc - ok
09:39:03.0061 2728        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
09:39:03.0124 2728        Npfs - ok
09:39:03.0124 2728        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
09:39:03.0202 2728        nsi - ok
09:39:03.0217 2728        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
09:39:03.0295 2728        nsiproxy - ok
09:39:03.0467 2728        Ntfs            (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
09:39:03.0529 2728        Ntfs - ok
09:39:03.0654 2728        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
09:39:03.0732 2728        Null - ok
09:39:03.0763 2728        nvraid          (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
09:39:03.0779 2728        nvraid - ok
09:39:03.0794 2728        nvstor          (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
09:39:03.0810 2728        nvstor - ok
09:39:03.0826 2728        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
09:39:03.0841 2728        nv_agp - ok
09:39:03.0857 2728        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
09:39:03.0872 2728        ohci1394 - ok
09:39:03.0950 2728        ose            (7a56cf3e3f12e8af599963b16f50fb6a) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
09:39:03.0966 2728        ose - ok
09:39:04.0013 2728        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
09:39:04.0075 2728        p2pimsvc - ok
09:39:04.0122 2728        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
09:39:04.0153 2728        p2psvc - ok
09:39:04.0184 2728        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
09:39:04.0216 2728        Parport - ok
09:39:04.0231 2728        partmgr        (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
09:39:04.0247 2728        partmgr - ok
09:39:04.0294 2728        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
09:39:04.0325 2728        PcaSvc - ok
09:39:04.0372 2728        pci            (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
09:39:04.0387 2728        pci - ok
09:39:04.0387 2728        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
09:39:04.0403 2728        pciide - ok
09:39:04.0434 2728        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
09:39:04.0450 2728        pcmcia - ok
09:39:04.0559 2728        PCSUService    (7eb95aa73d657a2da9d8cfc336f4f48f) C:\Program Files (x86)\PC Beschleunigen\PCSUService.exe
09:39:04.0574 2728        PCSUService ( UnsignedFile.Multi.Generic ) - warning
09:39:04.0574 2728        PCSUService - detected UnsignedFile.Multi.Generic (1)
09:39:04.0621 2728        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
09:39:04.0637 2728        pcw - ok
09:39:04.0699 2728        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
09:39:04.0777 2728        PEAUTH - ok
09:39:04.0855 2728        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
09:39:04.0886 2728        PerfHost - ok
09:39:05.0027 2728        pla            (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
09:39:05.0136 2728        pla - ok
09:39:05.0198 2728        PlugPlay        (23157d583244400e1d7fbaee2e4b31b7) C:\Windows\system32\umpnpmgr.dll
09:39:05.0292 2728        PlugPlay - ok
09:39:05.0339 2728        Pml Driver HPZ12 (37f6046cdc630442d7dc087501ff6fc6) C:\Windows\system32\HPZipm12.dll
09:39:05.0370 2728        Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
09:39:05.0370 2728        Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
09:39:05.0386 2728        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
09:39:05.0417 2728        PNRPAutoReg - ok
09:39:05.0448 2728        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
09:39:05.0479 2728        PNRPsvc - ok
09:39:05.0526 2728        PolicyAgent    (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
09:39:05.0604 2728        PolicyAgent - ok
09:39:05.0651 2728        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
09:39:05.0729 2728        Power - ok
09:39:05.0791 2728        Power Manager DBC Service (a65a62ee76e94eed6b2dbcfdbd2cae6d) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
09:39:05.0807 2728        Power Manager DBC Service - ok
09:39:05.0885 2728        PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
09:39:05.0947 2728        PptpMiniport - ok
09:39:05.0963 2728        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
09:39:05.0978 2728        Processor - ok
09:39:06.0025 2728        ProfSvc        (f381975e1f4346de875cb07339ce8d3a) C:\Windows\system32\profsvc.dll
09:39:06.0103 2728        ProfSvc - ok
09:39:06.0134 2728        ProtectedStorage (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
09:39:06.0150 2728        ProtectedStorage - ok
09:39:06.0181 2728        psadd          (515a7c5a0886fcc60901916785efd549) C:\Windows\system32\DRIVERS\psadd.sys
09:39:06.0197 2728        psadd - ok
09:39:06.0244 2728        Psched          (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
09:39:06.0306 2728        Psched - ok
09:39:06.0446 2728        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
09:39:06.0509 2728        ql2300 - ok
09:39:06.0634 2728        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
09:39:06.0649 2728        ql40xx - ok
09:39:06.0712 2728        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
09:39:06.0743 2728        QWAVE - ok
09:39:06.0758 2728        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
09:39:06.0805 2728        QWAVEdrv - ok
09:39:06.0821 2728        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
09:39:06.0883 2728        RasAcd - ok
09:39:06.0930 2728        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
09:39:06.0992 2728        RasAgileVpn - ok
09:39:07.0024 2728        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
09:39:07.0102 2728        RasAuto - ok
09:39:07.0133 2728        Rasl2tp        (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
09:39:07.0195 2728        Rasl2tp - ok
09:39:07.0226 2728        RasMan          (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
09:39:07.0304 2728        RasMan - ok
09:39:07.0351 2728        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
09:39:07.0429 2728        RasPppoe - ok
09:39:07.0445 2728        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
09:39:07.0523 2728        RasSstp - ok
09:39:07.0554 2728        rdbss          (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
09:39:07.0632 2728        rdbss - ok
09:39:07.0648 2728        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
09:39:07.0679 2728        rdpbus - ok
09:39:07.0694 2728        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
09:39:07.0757 2728        RDPCDD - ok
09:39:07.0804 2728        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
09:39:07.0882 2728        RDPENCDD - ok
09:39:07.0897 2728        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
09:39:07.0975 2728        RDPREFMP - ok
09:39:08.0006 2728        RDPWD          (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
09:39:08.0069 2728        RDPWD - ok
09:39:08.0116 2728        rdyboost        (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
09:39:08.0131 2728        rdyboost - ok
09:39:08.0162 2728        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
09:39:08.0240 2728        RemoteAccess - ok
09:39:08.0287 2728        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
09:39:08.0365 2728        RemoteRegistry - ok
09:39:08.0412 2728        RFCOMM          (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
09:39:08.0443 2728        RFCOMM - ok
09:39:08.0474 2728        RimUsb          (ad42432d22940b4215177be113e4919c) C:\Windows\system32\Drivers\RimUsb_AMD64.sys
09:39:08.0521 2728        RimUsb - ok
09:39:08.0568 2728        RimVSerPort    (4aafffa67ac4dfa3d9985d78573887e2) C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys
09:39:08.0599 2728        RimVSerPort - ok
09:39:08.0662 2728        ROOTMODEM      (388d3dd1a6457280f3badba9f3acd6b1) C:\Windows\system32\Drivers\RootMdm.sys
09:39:08.0724 2728        ROOTMODEM - ok
09:39:08.0755 2728        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
09:39:08.0818 2728        RpcEptMapper - ok
09:39:08.0864 2728        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
09:39:08.0880 2728        RpcLocator - ok
09:39:08.0927 2728        RpcSs          (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
09:39:08.0989 2728        RpcSs - ok
09:39:09.0020 2728        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
09:39:09.0098 2728        rspndr - ok
09:39:09.0130 2728        RSUSBSTOR      (763ae0c6d9df4c24b7e2c26036a8188a) C:\Windows\system32\Drivers\RtsUStor.sys
09:39:09.0145 2728        RSUSBSTOR - ok
09:39:09.0208 2728        RTL8167        (4b42bc58294e83a6a92ec8b88c14c4a3) C:\Windows\system32\DRIVERS\Rt64win7.sys
09:39:09.0239 2728        RTL8167 - ok
09:39:09.0332 2728        RTL8192Ce      (9a1cea6e20e19afce888d3f3e4358381) C:\Windows\system32\DRIVERS\rtl8192Ce.sys
09:39:09.0379 2728        RTL8192Ce - ok
09:39:09.0410 2728        SamSs          (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
09:39:09.0426 2728        SamSs - ok
09:39:09.0442 2728        sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
09:39:09.0457 2728        sbp2port - ok
09:39:09.0504 2728        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
09:39:09.0582 2728        SCardSvr - ok
09:39:09.0598 2728        scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
09:39:09.0676 2728        scfilter - ok
09:39:09.0754 2728        Schedule        (ec56b171f85c7e855e7b0588ac503eea) C:\Windows\system32\schedsvc.dll
09:39:09.0847 2728        Schedule - ok
09:39:09.0878 2728        SCPolicySvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
09:39:09.0941 2728        SCPolicySvc - ok
09:39:09.0988 2728        sdbus          (54e47ad086782d3ae9417c155cdceb9b) C:\Windows\system32\DRIVERS\sdbus.sys
09:39:10.0019 2728        sdbus - ok
09:39:10.0066 2728        SDRSVC          (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
09:39:10.0081 2728        SDRSVC - ok
09:39:10.0112 2728        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
09:39:10.0190 2728        secdrv - ok
09:39:10.0206 2728        seclogon        (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
09:39:10.0284 2728        seclogon - ok
09:39:10.0300 2728        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
09:39:10.0362 2728        SENS - ok
09:39:10.0393 2728        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
09:39:10.0440 2728        SensrSvc - ok
09:39:10.0471 2728        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
09:39:10.0487 2728        Serenum - ok
09:39:10.0518 2728        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
09:39:10.0549 2728        Serial - ok
09:39:10.0565 2728        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
09:39:10.0596 2728        sermouse - ok
09:39:10.0643 2728        SessionEnv      (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
09:39:10.0721 2728        SessionEnv - ok
09:39:10.0721 2728        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
09:39:10.0752 2728        sffdisk - ok
09:39:10.0783 2728        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
09:39:10.0799 2728        sffp_mmc - ok
09:39:10.0814 2728        sffp_sd        (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
09:39:10.0830 2728        sffp_sd - ok
09:39:10.0846 2728        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
09:39:10.0861 2728        sfloppy - ok
09:39:10.0924 2728        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
09:39:11.0002 2728        SharedAccess - ok
09:39:11.0048 2728        ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
09:39:11.0095 2728        ShellHWDetection - ok
09:39:11.0158 2728        Shockprf        (29e316de2c0261c30c08f872032c53a2) C:\Windows\system32\DRIVERS\Apsx64.sys
09:39:11.0158 2728        Shockprf - ok
09:39:11.0189 2728        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
09:39:11.0204 2728        SiSRaid2 - ok
09:39:11.0220 2728        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
09:39:11.0236 2728        SiSRaid4 - ok
09:39:11.0329 2728        SkypeUpdate    (579ba0a911ff5ea70cb604cd3b744b0a) C:\Program Files (x86)\Skype\Updater\Updater.exe
09:39:11.0329 2728        SkypeUpdate - ok
09:39:11.0360 2728        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
09:39:11.0438 2728        Smb - ok
09:39:11.0470 2728        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
09:39:11.0501 2728        SNMPTRAP - ok
09:39:11.0532 2728        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
09:39:11.0548 2728        spldr - ok
09:39:11.0610 2728        Spooler        (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
09:39:11.0657 2728        Spooler - ok
09:39:11.0969 2728        sppsvc          (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
09:39:12.0078 2728        sppsvc - ok
09:39:12.0203 2728        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
09:39:12.0265 2728        sppuinotify - ok
09:39:12.0359 2728        srv            (de6f5658da951c4bc8e498570b5b0d5f) C:\Windows\system32\DRIVERS\srv.sys
09:39:12.0390 2728        srv - ok
09:39:12.0437 2728        srv2            (4d33d59c0b930c523d29f9bd40cda9d2) C:\Windows\system32\DRIVERS\srv2.sys
09:39:12.0484 2728        srv2 - ok
09:39:12.0530 2728        SrvHsfHDA      (0c4540311e11664b245a263e1154cef8) C:\Windows\system32\DRIVERS\VSTAZL6.SYS
09:39:12.0562 2728        SrvHsfHDA - ok
09:39:12.0686 2728        SrvHsfV92      (02071d207a9858fbe3a48cbfd59c4a04) C:\Windows\system32\DRIVERS\VSTDPV6.SYS
09:39:12.0749 2728        SrvHsfV92 - ok
09:39:12.0936 2728        SrvHsfWinac    (18e40c245dbfaf36fd0134a7ef2df396) C:\Windows\system32\DRIVERS\VSTCNXT6.SYS
09:39:12.0983 2728        SrvHsfWinac - ok
09:39:13.0014 2728        srvnet          (5a663fd67049267bc5c3f3279e631ffb) C:\Windows\system32\DRIVERS\srvnet.sys
09:39:13.0045 2728        srvnet - ok
09:39:13.0092 2728        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
09:39:13.0170 2728        SSDPSRV - ok
09:39:13.0186 2728        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
09:39:13.0264 2728        SstpSvc - ok
09:39:13.0279 2728        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
09:39:13.0295 2728        stexstor - ok
09:39:13.0357 2728        stisvc          (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
09:39:13.0404 2728        stisvc - ok
09:39:13.0513 2728        SUService      (f3c73e650f1cd3289f38e62ccc325a66) c:\Program Files (x86)\Lenovo\System Update\SUService.exe
09:39:13.0529 2728        SUService ( UnsignedFile.Multi.Generic ) - warning
09:39:13.0529 2728        SUService - detected UnsignedFile.Multi.Generic (1)
09:39:13.0560 2728        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
09:39:13.0576 2728        swenum - ok
09:39:13.0622 2728        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
09:39:13.0700 2728        swprv - ok
09:39:13.0856 2728        SynTP          (d268d2a0db2a2bbe963e688d0b039267) C:\Windows\system32\DRIVERS\SynTP.sys
09:39:13.0903 2728        SynTP - ok
09:39:14.0153 2728        SysMain        (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
09:39:14.0231 2728        SysMain - ok
09:39:14.0340 2728        TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
09:39:14.0371 2728        TabletInputService - ok
09:39:14.0418 2728        TapiSrv        (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
09:39:14.0496 2728        TapiSrv - ok
09:39:14.0512 2728        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
09:39:14.0574 2728        TBS - ok
09:39:14.0792 2728        Tcpip          (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys
09:39:14.0870 2728        Tcpip - ok
09:39:15.0182 2728        TCPIP6          (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys
09:39:15.0260 2728        TCPIP6 - ok
09:39:15.0401 2728        tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
09:39:15.0463 2728        tcpipreg - ok
09:39:15.0494 2728        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
09:39:15.0557 2728        TDPIPE - ok
09:39:15.0557 2728        TDTCP          (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
09:39:15.0619 2728        TDTCP - ok
09:39:15.0650 2728        tdx            (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
09:39:15.0713 2728        tdx - ok
09:39:15.0760 2728        TermDD          (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
09:39:15.0775 2728        TermDD - ok
09:39:15.0869 2728        TermService    (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
09:39:15.0978 2728        TermService - ok
09:39:16.0025 2728        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
09:39:16.0056 2728        Themes - ok
09:39:16.0181 2728        ThinkVantage Registry Monitor Service (39ac444e07fdbd8c2e8e291a65d515d3) C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
09:39:16.0228 2728        ThinkVantage Registry Monitor Service ( UnsignedFile.Multi.Generic ) - warning
09:39:16.0228 2728        ThinkVantage Registry Monitor Service - detected UnsignedFile.Multi.Generic (1)
09:39:16.0259 2728        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
09:39:16.0321 2728        THREADORDER - ok
09:39:16.0399 2728        TPDIGIMN        (8b359a7f4c715b84c76de3c5167797c5) C:\Windows\system32\DRIVERS\ApsHM64.sys
09:39:16.0415 2728        TPDIGIMN - ok
09:39:16.0446 2728        TPHDEXLGSVC    (0c1c7753a5539c898adaffde835df7a8) C:\Windows\system32\TPHDEXLG64.exe
09:39:16.0462 2728        TPHDEXLGSVC - ok
09:39:16.0540 2728        TPHKSVC        (2cf225e19490f499528b926263fe4554) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
09:39:16.0555 2728        TPHKSVC - ok
09:39:16.0586 2728        TPM            (dbcc20c02e8a3e43b03c304a4e40a84f) C:\Windows\system32\drivers\tpm.sys
09:39:16.0618 2728        TPM - ok
09:39:16.0680 2728        TPPWRIF        (2c067e01d6bbccc88b233b868e210907) C:\Windows\system32\drivers\Tppwr64v.sys
09:39:16.0680 2728        TPPWRIF - ok
09:39:16.0727 2728        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
09:39:16.0789 2728        TrkWks - ok
09:39:16.0852 2728        TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
09:39:16.0883 2728        TrustedInstaller - ok
09:39:16.0898 2728        tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
09:39:16.0961 2728        tssecsrv - ok
09:39:17.0008 2728        tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
09:39:17.0070 2728        tunnel - ok
09:39:17.0273 2728        TVT Backup Service (003afb1490828615b041849abb40eaa1) C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
09:39:17.0335 2728        TVT Backup Service - ok
09:39:17.0476 2728        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
09:39:17.0491 2728        uagp35 - ok
09:39:17.0538 2728        udfs            (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
09:39:17.0600 2728        udfs - ok
09:39:17.0632 2728        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
09:39:17.0678 2728        UI0Detect - ok
09:39:17.0694 2728        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
09:39:17.0694 2728        uliagpkx - ok
09:39:17.0725 2728        umbus          (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
09:39:17.0756 2728        umbus - ok
09:39:17.0772 2728        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
09:39:17.0803 2728        UmPass - ok
09:39:18.0053 2728        UNS            (9e89c2d6945389270de067ce51ff7425) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
09:39:18.0146 2728        UNS - ok
09:39:18.0271 2728        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
09:39:18.0365 2728        upnphost - ok
09:39:18.0427 2728        USBAAPL64      (fb251567f41bc61988b26731dec19e4b) C:\Windows\system32\Drivers\usbaapl64.sys
09:39:18.0474 2728        USBAAPL64 - ok
09:39:18.0521 2728        usbccgp        (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
09:39:18.0552 2728        usbccgp - ok
09:39:18.0599 2728        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
09:39:18.0630 2728        usbcir - ok
09:39:18.0630 2728        usbehci        (cb490987a7f6928a04bb838e3bd8a936) C:\Windows\system32\DRIVERS\usbehci.sys
09:39:18.0661 2728        usbehci - ok
09:39:18.0724 2728        usbhub          (18124ef0a881a00ee222d02a3ee30270) C:\Windows\system32\DRIVERS\usbhub.sys
09:39:18.0755 2728        usbhub - ok
09:39:18.0770 2728        usbohci        (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
09:39:18.0786 2728        usbohci - ok
09:39:18.0802 2728        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
09:39:18.0833 2728        usbprint - ok
09:39:18.0864 2728        usbscan        (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
09:39:18.0880 2728        usbscan - ok
09:39:18.0926 2728        usbsmi          (63fe600d71d72eb960ff01b0f0e5d837) C:\Windows\system32\DRIVERS\SMIksdrv.sys
09:39:18.0973 2728        usbsmi - ok
09:39:19.0020 2728        USBSTOR        (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
09:39:19.0051 2728        USBSTOR - ok
09:39:19.0067 2728        usbuhci        (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
09:39:19.0082 2728        usbuhci - ok
09:39:19.0145 2728        usbvideo        (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys
09:39:19.0176 2728        usbvideo - ok
09:39:19.0192 2728        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
09:39:19.0270 2728        UxSms - ok
09:39:19.0301 2728        VaultSvc        (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
09:39:19.0316 2728        VaultSvc - ok
09:39:19.0332 2728        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
09:39:19.0348 2728        vdrvroot - ok
09:39:19.0410 2728        vds            (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
09:39:19.0441 2728        vds - ok
09:39:19.0457 2728        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
09:39:19.0488 2728        vga - ok
09:39:19.0504 2728        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
09:39:19.0582 2728        VgaSave - ok
09:39:19.0597 2728        vhdmp          (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
09:39:19.0613 2728        vhdmp - ok
09:39:19.0628 2728        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
09:39:19.0644 2728        viaide - ok
09:39:19.0675 2728        volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
09:39:19.0691 2728        volmgr - ok
09:39:19.0722 2728        volmgrx        (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
09:39:19.0738 2728        volmgrx - ok
09:39:19.0769 2728        volsnap        (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
09:39:19.0784 2728        volsnap - ok
09:39:19.0831 2728        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
09:39:19.0847 2728        vsmraid - ok
09:39:19.0987 2728        VSS            (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
09:39:20.0065 2728        VSS - ok
09:39:20.0206 2728        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
09:39:20.0221 2728        vwifibus - ok
09:39:20.0252 2728        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
09:39:20.0284 2728        vwififlt - ok
09:39:20.0346 2728        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
09:39:20.0424 2728        W32Time - ok
09:39:20.0440 2728        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
09:39:20.0471 2728        WacomPen - ok
09:39:20.0502 2728        WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
09:39:20.0580 2728        WANARP - ok
09:39:20.0596 2728        Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
09:39:20.0658 2728        Wanarpv6 - ok
09:39:20.0783 2728        wbengine        (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
09:39:20.0861 2728        wbengine - ok
09:39:21.0001 2728        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
09:39:21.0032 2728        WbioSrvc - ok
09:39:21.0079 2728        wcncsvc        (8321c2ca3b62b61b293cda3451984468) C:\Windows\System32\wcncsvc.dll
09:39:21.0110 2728        wcncsvc - ok
09:39:21.0126 2728        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
09:39:21.0157 2728        WcsPlugInService - ok
09:39:21.0220 2728        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
09:39:21.0235 2728        Wd - ok
09:39:21.0298 2728        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
09:39:21.0329 2728        Wdf01000 - ok
09:39:21.0344 2728        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
09:39:21.0391 2728        WdiServiceHost - ok
09:39:21.0391 2728        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
09:39:21.0422 2728        WdiSystemHost - ok
09:39:21.0469 2728        WebClient      (8a438cbb8c032a0c798b0c642ffbe572) C:\Windows\System32\webclnt.dll
09:39:21.0500 2728        WebClient - ok
09:39:21.0547 2728        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
09:39:21.0625 2728        Wecsvc - ok
09:39:21.0656 2728        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
09:39:21.0719 2728        wercplsupport - ok
09:39:21.0734 2728        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
09:39:21.0797 2728        WerSvc - ok
09:39:21.0875 2728        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
09:39:21.0937 2728        WfpLwf - ok
09:39:21.0953 2728        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
09:39:21.0968 2728        WIMMount - ok
09:39:22.0000 2728        WinDefend - ok
09:39:22.0015 2728        WinHttpAutoProxySvc - ok
09:39:22.0078 2728        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
09:39:22.0156 2728        Winmgmt - ok
09:39:22.0343 2728        WinRM          (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
09:39:22.0483 2728        WinRM - ok
09:39:22.0655 2728        WinUsb          (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
09:39:22.0670 2728        WinUsb - ok
09:39:22.0764 2728        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
09:39:22.0811 2728        Wlansvc - ok
09:39:22.0858 2728        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
09:39:22.0873 2728        WmiAcpi - ok
09:39:22.0936 2728        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
09:39:22.0967 2728        wmiApSrv - ok
09:39:23.0029 2728        WMPNetworkSvc - ok
09:39:23.0060 2728        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
09:39:23.0092 2728        WPCSvc - ok
09:39:23.0123 2728        WPDBusEnum      (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
09:39:23.0170 2728        WPDBusEnum - ok
09:39:23.0201 2728        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
09:39:23.0263 2728        ws2ifsl - ok
09:39:23.0294 2728        wscsvc          (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\System32\wscsvc.dll
09:39:23.0326 2728        wscsvc - ok
09:39:23.0326 2728        WSearch - ok
09:39:23.0513 2728        wuauserv        (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll
09:39:23.0638 2728        wuauserv - ok
09:39:23.0872 2728        WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
09:39:23.0934 2728        WudfPf - ok
09:39:23.0950 2728        WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
09:39:24.0028 2728        WUDFRd - ok
09:39:24.0074 2728        wudfsvc        (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
09:39:24.0152 2728        wudfsvc - ok
09:39:24.0184 2728        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
09:39:24.0230 2728        WwanSvc - ok
09:39:24.0262 2728        MBR (0x1B8)    (0d8ccfd941fcd953f608374feb7acc05) \Device\Harddisk0\DR0
09:39:24.0761 2728        \Device\Harddisk0\DR0 - ok
09:39:24.0776 2728        Boot (0x1200)  (1704543382a9d1ea50d3144fd18489a9) \Device\Harddisk0\DR0\Partition0
09:39:24.0776 2728        \Device\Harddisk0\DR0\Partition0 - ok
09:39:24.0792 2728        Boot (0x1200)  (debf4b060b55e980f02dd52908062982) \Device\Harddisk0\DR0\Partition1
09:39:24.0808 2728        \Device\Harddisk0\DR0\Partition1 - ok
09:39:24.0823 2728        Boot (0x1200)  (d5f53d16380f5b37c73e7accc8f0889e) \Device\Harddisk0\DR0\Partition2
09:39:24.0823 2728        \Device\Harddisk0\DR0\Partition2 - ok
09:39:24.0854 2728        Boot (0x1200)  (0c98f31d378c627956d69bad8ef30b2f) \Device\Harddisk0\DR0\Partition3
09:39:24.0854 2728        \Device\Harddisk0\DR0\Partition3 - ok
09:39:24.0854 2728        ============================================================
09:39:24.0854 2728        Scan finished
09:39:24.0854 2728        ============================================================
09:39:24.0886 4124        Detected object count: 6
09:39:24.0886 4124        Actual detected object count: 6
09:39:50.0376 4124        FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - skipped by user
09:39:50.0376 4124        FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:39:50.0376 4124        Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
09:39:50.0376 4124        Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:39:50.0376 4124        PCSUService ( UnsignedFile.Multi.Generic ) - skipped by user
09:39:50.0376 4124        PCSUService ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:39:50.0376 4124        Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
09:39:50.0376 4124        Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:39:50.0376 4124        SUService ( UnsignedFile.Multi.Generic ) - skipped by user
09:39:50.0376 4124        SUService ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:39:50.0376 4124        ThinkVantage Registry Monitor Service ( UnsignedFile.Multi.Generic ) - skipped by user
09:39:50.0376 4124        ThinkVantage Registry Monitor Service ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 10.06.2012 15:46

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

NicoleM 10.06.2012 17:01

Combofix Logfile:
Code:

ComboFix 12-06-09.02 - Nicole 10.06.2012  17:43:54.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.49.1031.18.1909.1082 [GMT 2:00]
ausgeführt von:: d:\nicole\Downloads\ComboFix.exe
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
d:\nicole\AppData\Roaming\Local
d:\nicole\AppData\Roaming\Local\Temp\DDM\Settings\.ddr
d:\nicole\AppData\Roaming\Local\Temp\DDM\Settings\0.ddi
d:\nicole\AppData\Roaming\Local\Temp\DDM\Settings\Post_Install_RB_HiQ_de.divx.ddr
d:\nicole\AppData\Roaming\Local\Temp\DDM\Settings\settings.ddi
d:\nicole\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\.ddp
d:\nicole\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\Post_Install_RB_HiQ_de.divx
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-05-10 bis 2012-06-10  ))))))))))))))))))))))))))))))
.
.
2012-06-05 19:17 . 2012-06-05 19:17        --------        d-----w-        d:\\_OTL
2012-06-03 01:02 . 2012-06-03 01:02        --------        d-----w-        c:\program files (x86)\ESET
2012-05-31 19:21 . 2012-05-31 19:21        --------        d-----w-        d:\nicole\AppData\Roaming\Malwarebytes
2012-05-31 19:21 . 2012-05-31 19:21        --------        d-----w-        d:\\Nicole\AppData\Roaming\Malwarebytes
2012-05-31 19:20 . 2012-05-31 19:20        --------        d-----w-        c:\programdata\Malwarebytes
2012-05-31 19:20 . 2012-05-31 19:20        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-05-31 19:20 . 2012-04-04 13:56        24904        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-05-18 14:48 . 2012-05-18 14:48        --------        d-----w-        c:\program files (x86)\Common Files\Skype
2012-05-18 14:26 . 2012-05-18 14:26        --------        d-----w-        c:\program files (x86)\Mozilla Maintenance Service
2012-05-18 14:26 . 2012-05-18 14:26        157352        ----a-w-        c:\program files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
2012-05-18 14:26 . 2012-05-18 14:26        129976        ----a-w-        c:\program files (x86)\Mozilla Firefox\maintenanceservice.exe
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-14 13:02 . 2011-01-14 13:01        39965792        ----a-w-        c:\program files\PS_AIO_05_C4600_NonNet_Basic_Win_enu_140_047.exe
2010-12-22 01:12 . 2010-12-22 01:12        33781040        ----a-w-        c:\program files\snagitde.exe
2010-12-12 23:49 . 2010-12-12 23:48        23448640        ----a-w-        c:\program files\FreeYouTubeToMp3Converter31.exe
2010-12-09 22:59 . 2010-12-09 22:59        11792152        ----a-w-        c:\program files\pdf24-creator.exe
2010-12-09 22:54 . 2010-12-09 22:40        17492496        ----a-w-        c:\program files\PDFCreator-1_1_0_setup.exe
2003-03-21 11:45 . 2011-09-12 11:14        250544        ----a-w-        c:\program files (x86)\Common Files\keyhelp.ocx
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2010-07-20 1129320]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"PDFPrint"="c:\program files (x86)\PDF24\pdf24.exe" [2011-12-16 220744]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"RIMBBLaunchAgent.exe"="c:\program files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-09-01 90448]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-06 421736]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
d:\nicole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - d:\nicole\AppData\Roaming\Dropbox\bin\Dropbox.exe [N/A]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Acrobat - Schnellstart.lnk - c:\windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2010-11-9 295606]
Adobe Reader Synchronizer.lnk - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2010-7-6 1086240]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 Application Updater;Application Updater;c:\program files (x86)\Application Updater\ApplicationUpdater.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-05-03 158856]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-18 129976]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2010-07-20 75112]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys [x]
S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiifx64.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 LENOVO.CAMMUTE;Lenovo Camera Mute;c:\program files\Lenovo\Communications Utility\CAMMUTE.exe [2010-04-20 50536]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2010-04-07 45496]
S2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;c:\program files\Lenovo\Communications Utility\TPKNRSVC.exe [2010-04-20 74088]
S2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;c:\program files\LENOVO\VIRTSCRL\lvvsst.exe [2010-04-07 93032]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 PCSUService;PC Speed Up Service;c:\program files (x86)\PC Beschleunigen\PCSUService.exe [2011-07-20 206336]
S2 TPHKSVC;Anzeige am Bildschirm;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2010-04-07 63928]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys [x]
S3 usbsmi;Integrated Camera;c:\windows\system32\DRIVERS\SMIksdrv.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2012-06-08 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PC-Doctor\uaclauncher.exe [2010-05-07 19:52]
.
2012-06-10 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\PC-Doctor\pcdrcui.exe [2010-05-08 18:09]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-12-21 69568]
"TpShocks"="TpShocks.exe" [2010-07-01 380776]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2010-04-28 307768]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-31 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-31 413720]
"LENOVO.TPKNRRES"="c:\program files\Lenovo\Communications Utility\TPKNRRES.exe" [2010-04-20 62312]
"AcWin7Hlpr"="c:\program files (x86)\Lenovo\Access Connections\AcTBenabler.exe" [2010-08-06 31592]
"combofix"="c:\combofix\CF21592.3XE" [2009-07-14 344576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
mLocal Page =
uInternet Settings,ProxyOverride = *.local
IE: An vorhandenes PDF anfügen - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Auswahl in Adobe PDF konvertieren - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Auswahl in vorhandene PDF-Datei konvertieren - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Free YouTube to MP3 Converter - d:\nicole\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: In Adobe PDF konvertieren - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
IE: Verknüpfungsziel in Adobe PDF konvertieren - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
TCP: DhcpNameServer = 195.234.128.7 195.234.128.16 85.233.58.60
FF - ProfilePath - d:\nicole\AppData\Roaming\Mozilla\Firefox\Profiles\zni354nt.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - d:\nicole\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - d:\nicole\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - d:\nicole\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - d:\nicole\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - d:\nicole\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - d:\nicole\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - d:\nicole\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - d:\nicole\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-DivX Setup.divx.com - c:\programdata\DivX\Setup\DivXSetup.exe
AddRemove-2113656771.www.pcspeedup.com - c:\program files (x86)\Microsoft Silverlight\4.0.60310.0\Silverlight.Configuration.exe
AddRemove-Dropbox - d:\nicole\AppData\Roaming\Dropbox\bin\Uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
c:\progra~1\Lenovo\HOTKEY\tpnumlkd.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\progra~1\LENOVO\VIRTSCRL\virtscrl.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files (x86)\Lenovo\Access Connections\AcSvc.exe
c:\program files\Lenovo\HOTKEY\TPONSCR.exe
c:\windows\SysWOW64\rundll32.exe
c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe
c:\program files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\ThinkPad\Bluetooth Software\BluetoothHeadsetProxy.exe
c:\program files (x86)\Lenovo\System Update\SUService.exe
c:\program files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-06-10  17:57:25 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-06-10 15:57
.
Vor Suchlauf: 3.688.681.472 Bytes frei
Nach Suchlauf: 3.372.978.176 Bytes frei
.
- - End Of File - - 8BD1241FEDC2DC2FD828327CFA0DCC1B

[/CODE]
--- --- ---

cosinus 10.06.2012 17:14

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

NicoleM 10.06.2012 17:39

GMER Logfile:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-06-10 18:34:53
Windows 6.1.7600 
Running: z9z1vyx3.exe


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f3ad3f74a                     
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\78dd08a98abb                     
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f3ad3f74a (not active ControlSet) 
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\78dd08a98abb (not active ControlSet) 

---- EOF - GMER 1.0.15 ----

[/CODE]
--- --- ---


Hallo Arne,
Ich habe soeben OSAM durchgeführt, aber kann da leider nix speichern...Könntest du mir da irgendwie weiterhelfen?

Vielen Dank!

cosinus 10.06.2012 18:45

Lass OSAM weg, das funktioniert nicht immer auf 64-Bit-Systemen

NicoleM 10.06.2012 19:20

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-06-10 19:52:38
-----------------------------
19:52:38.820    OS Version: Windows x64 6.1.7600
19:52:38.820    Number of processors: 4 586 0x2505
19:52:38.822    ComputerName: NICOLES_ZWERG  UserName: Nicole
19:52:39.076    Initialize success
19:58:45.995    AVAST engine defs: 12061000
19:59:30.925    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
19:59:30.930    Disk 0 Vendor: HITACHI_ PB3Z Size: 305245MB BusType: 3
19:59:30.941    Disk 0 MBR read successfully
19:59:30.945    Disk 0 MBR scan
19:59:30.952    Disk 0 unknown MBR code
19:59:30.964    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS        1200 MB offset 2048
19:59:30.982    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS        30023 MB offset 2459648
19:59:30.990    Disk 0 Partition - 00    0F Extended LBA            264020 MB offset 63946752
19:59:31.024    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        10000 MB offset 604659712
19:59:31.057    Disk 0 Partition 4 00    07    HPFS/NTFS NTFS      264018 MB offset 63948800
19:59:31.126    Disk 0 scanning C:\Windows\system32\drivers
19:59:40.503    Service scanning
20:00:11.629    Modules scanning
20:00:11.650    Disk 0 trace - called modules:
20:00:11.677    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
20:00:11.686    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80027ec060]
20:00:11.694    3 CLASSPNP.SYS[fffff88001b2243f] -> nt!IofCallDriver -> [0xfffffa80024cf2a0]
20:00:11.704    5 ACPI.sys[fffff88000f5f769] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0xfffffa800250a050]
20:00:11.870    AVAST engine scan C:\Windows
20:00:14.220    AVAST engine scan C:\Windows\system32
20:03:12.300    AVAST engine scan C:\Windows\system32\drivers
20:03:23.831    AVAST engine scan D:\Nicole
20:06:12.084    AVAST engine scan C:\ProgramData
20:06:50.945    Scan finished successfully
20:17:28.722    Disk 0 MBR has been saved successfully to "D:\Nicole\Desktop\MBR.dat"
20:17:28.730    The log file has been saved successfully to "D:\Nicole\Desktop\aswMBR.txt"


cosinus 10.06.2012 20:31

Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.

Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.
Mach den Fix auch dann nicht, wenn du zB mit TrueCrypt oder anderen Verschlüsselungsprogrammen eine Vollverschlüsselung der Windowspartition bzw. gesamten Festplatte hast


Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!

Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

NicoleM 10.06.2012 20:53

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-06-10 21:46:38
-----------------------------
21:46:38.591    OS Version: Windows x64 6.1.7600
21:46:38.591    Number of processors: 4 586 0x2505
21:46:38.592    ComputerName: NICOLES_ZWERG  UserName: Nicole
21:46:38.841    Initialize success
21:46:49.514    AVAST engine defs: 12061000
21:46:58.260    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
21:46:58.267    Disk 0 Vendor: HITACHI_ PB3Z Size: 305245MB BusType: 3
21:46:58.286    Disk 0 MBR read successfully
21:46:58.291    Disk 0 MBR scan
21:46:58.326    Disk 0 Windows 7 default MBR code
21:46:58.343    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS        1200 MB offset 2048
21:46:58.361    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS        30023 MB offset 2459648
21:46:58.369    Disk 0 Partition - 00    0F Extended LBA            264020 MB offset 63946752
21:46:58.403    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        10000 MB offset 604659712
21:46:58.435    Disk 0 Partition 4 00    07    HPFS/NTFS NTFS      264018 MB offset 63948800
21:46:58.493    Disk 0 scanning C:\Windows\system32\drivers
21:47:09.637    Service scanning
21:47:43.139    Modules scanning
21:47:43.509    Disk 0 trace - called modules:
21:47:43.545    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
21:47:43.553    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80027c5060]
21:47:43.562    3 CLASSPNP.SYS[fffff88001bc443f] -> nt!IofCallDriver -> [0xfffffa8002538e40]
21:47:43.569    5 ACPI.sys[fffff88000e0b769] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0xfffffa8002537050]
21:47:44.006    AVAST engine scan C:\Windows
21:47:46.289    AVAST engine scan C:\Windows\system32
21:50:40.721    AVAST engine scan C:\Windows\system32\drivers
21:50:51.836    AVAST engine scan D:\Nicole
21:52:14.207    Disk 0 MBR has been saved successfully to "D:\Nicole\Desktop\MBR.dat"
21:52:14.222    The log file has been saved successfully to "D:\Nicole\Desktop\aswMBR2.txt"


cosinus 11.06.2012 08:40

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

NicoleM 11.06.2012 09:27

Code:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.11.03

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Nicole :: NICOLES_ZWERG [Administrator]

Schutz: Deaktiviert

11.06.2012 09:49:31
mbam-log-2012-06-11 (09-49-31).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 434607
Laufzeit: 35 Minute(n), 7 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 06/11/2012 at 11:29 AM

Application Version : 5.0.1150

Core Rules Database Version : 8710
Trace Rules Database Version: 6522

Scan type      : Complete Scan
Total Scan Time : 00:49:17

Operating System Information
Windows 7 Home Premium 64-bit (Build 6.01.7600)
UAC On - Administrator

Memory items scanned      : 655
Memory threats detected  : 0
Registry items scanned    : 66524
Registry threats detected : 0
File items scanned        : 76778
File threats detected    : 590

Adware.Tracking Cookie
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@2o7[2].txt [ /2o7 ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad.360yield[2].txt [ /ad.360yield ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad.ad-srv[2].txt [ /ad.ad-srv ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad.adnet[1].txt [ /ad.adnet ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad.adnet[2].txt [ /ad.adnet ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad.dyntracker[1].txt [ /ad.dyntracker ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad.porta.eol[1].txt [ /ad.porta.eol ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad.yieldmanager[1].txt [ /ad.yieldmanager ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad.yieldmanager[2].txt [ /ad.yieldmanager ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad.yieldmanager[3].txt [ /ad.yieldmanager ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad.zanox[1].txt [ /ad.zanox ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad.zanox[2].txt [ /ad.zanox ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad.zanox[4].txt [ /ad.zanox ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad1.adfarm1.adition[1].txt [ /ad1.adfarm1.adition ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad2.adfarm1.adition[1].txt [ /ad2.adfarm1.adition ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad2.adfarm1.adition[2].txt [ /ad2.adfarm1.adition ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad2.adfarm1.adition[3].txt [ /ad2.adfarm1.adition ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad2.adfarm1.adition[4].txt [ /ad2.adfarm1.adition ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad3.adfarm1.adition[1].txt [ /ad3.adfarm1.adition ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad3.adfarm1.adition[2].txt [ /ad3.adfarm1.adition ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ad4.adfarm1.adition[1].txt [ /ad4.adfarm1.adition ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@adfarm1.adition[1].txt [ /adfarm1.adition ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@adfarm1.adition[2].txt [ /adfarm1.adition ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@adfarm1.adition[3].txt [ /adfarm1.adition ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@adfarm1.adition[5].txt [ /adfarm1.adition ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ads.creative-serving[1].txt [ /ads.creative-serving ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@adtech[1].txt [ /adtech ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@adtech[2].txt [ /adtech ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@adtech[3].txt [ /adtech ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@adtech[4].txt [ /adtech ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@adviva[1].txt [ /adviva ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@adx.chip[1].txt [ /adx.chip ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@adx.chip[3].txt [ /adx.chip ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@adx.chip[4].txt [ /adx.chip ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@apmebf[1].txt [ /apmebf ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@apmebf[2].txt [ /apmebf ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@apmebf[4].txt [ /apmebf ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@atdmt.combing[1].txt [ /atdmt.combing ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@atdmt.combing[2].txt [ /atdmt.combing ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@atdmt.combing[3].txt [ /atdmt.combing ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@atdmt.combing[4].txt [ /atdmt.combing ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@atdmt[1].txt [ /atdmt ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@atdmt[2].txt [ /atdmt ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@atdmt[3].txt [ /atdmt ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@atdmt[4].txt [ /atdmt ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@atdmt[5].txt [ /atdmt ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@atdmt[6].txt [ /atdmt ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@atdmt[8].txt [ /atdmt ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@bs.serving-sys[1].txt [ /bs.serving-sys ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@bs.serving-sys[2].txt [ /bs.serving-sys ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@bs.serving-sys[3].txt [ /bs.serving-sys ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@bs.serving-sys[5].txt [ /bs.serving-sys ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@c.atdmt[1].txt [ /c.atdmt ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@c.atdmt[3].txt [ /c.atdmt ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@content.yieldmanager[2].txt [ /content.yieldmanager ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@daimlerag.122.2o7[1].txt [ /daimlerag.122.2o7 ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@doubleclick[1].txt [ /doubleclick ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@doubleclick[2].txt [ /doubleclick ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@doubleclick[3].txt [ /doubleclick ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@doubleclick[4].txt [ /doubleclick ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@dyntracker[1].txt [ /dyntracker ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ero-advertising[1].txt [ /ero-advertising ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@ero-advertising[3].txt [ /ero-advertising ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@fastclick[1].txt [ /fastclick ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@gartis-pornos[1].txt [ /gartis-pornos ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@im.banner.t-online[1].txt [ /im.banner.t-online ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@imrworldwide[2].txt [ /imrworldwide ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@invitemedia[1].txt [ /invitemedia ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@invitemedia[2].txt [ /invitemedia ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@mediaplex[1].txt [ /mediaplex ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@mediaplex[3].txt [ /mediaplex ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@mediaplex[4].txt [ /mediaplex ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@mediaplex[5].txt [ /mediaplex ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@mediaplex[6].txt [ /mediaplex ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@microsoftwllivemkt.112.2o7[1].txt [ /microsoftwllivemkt.112.2o7 ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@myhammer.122.2o7[1].txt [ /myhammer.122.2o7 ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@questionmarket[1].txt [ /questionmarket ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@questionmarket[3].txt [ /questionmarket ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@realmedia[1].txt [ /realmedia ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@revsci[2].txt [ /revsci ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@revsci[3].txt [ /revsci ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@revsci[4].txt [ /revsci ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@serving-sys[1].txt [ /serving-sys ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@serving-sys[2].txt [ /serving-sys ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@serving-sys[3].txt [ /serving-sys ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@serving-sys[4].txt [ /serving-sys ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@serving-sys[6].txt [ /serving-sys ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@smartadserver[1].txt [ /smartadserver ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@smartadserver[3].txt [ /smartadserver ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@smartadserver[4].txt [ /smartadserver ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@specificclick[1].txt [ /specificclick ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@specificclick[2].txt [ /specificclick ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@specificclick[3].txt [ /specificclick ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@statse.webtrendslive[1].txt [ /statse.webtrendslive ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@tracking.mlsat02[1].txt [ /tracking.mlsat02 ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@tracking.mlsat02[2].txt [ /tracking.mlsat02 ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@tracking.quisma[1].txt [ /tracking.quisma ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@tracking.quisma[2].txt [ /tracking.quisma ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@tracking.quisma[3].txt [ /tracking.quisma ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@tradedoubler[1].txt [ /tradedoubler ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@tradedoubler[2].txt [ /tradedoubler ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@tradedoubler[3].txt [ /tradedoubler ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@tradedoubler[5].txt [ /tradedoubler ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@traffictrack[1].txt [ /traffictrack ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@traffictrack[2].txt [ /traffictrack ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@traffictrack[3].txt [ /traffictrack ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@unister-adservices[1].txt [ /unister-adservices ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@unitymedia[2].txt [ /unitymedia ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@vdwp.solution.weborama[2].txt [ /vdwp.solution.weborama ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@webmasterplan[2].txt [ /webmasterplan ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@webmasterplan[3].txt [ /webmasterplan ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@webmasterplan[4].txt [ /webmasterplan ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@weborama[1].txt [ /weborama ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@www.active-tracking[2].txt [ /www.active-tracking ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@www.googleadservices[1].txt [ /www.googleadservices ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@www.googleadservices[2].txt [ /www.googleadservices ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@www.youporn-deutsch[1].txt [ /www.youporn-deutsch ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@www.youporn-deutsch[3].txt [ /www.youporn-deutsch ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@www.zanox-affiliate[2].txt [ /www.zanox-affiliate ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@xiti[1].txt [ /xiti ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@yieldmanager[1].txt [ /yieldmanager ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@youporn-deutsch[1].txt [ /youporn-deutsch ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@youporn-deutsch[3].txt [ /youporn-deutsch ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@youporn[1].txt [ /youporn ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@zanox-affiliate[2].txt [ /zanox-affiliate ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@zanox-affiliate[3].txt [ /zanox-affiliate ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@zanox[2].txt [ /zanox ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@zanox[3].txt [ /zanox ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@zanox[4].txt [ /zanox ]
        D:\Nicole\AppData\Roaming\Microsoft\Windows\Cookies\nicole@de.sitestat[1].txt [ /de.sitestat.com ]
        cdn1.static.youporn.phncdn.com [ D:\NICOLE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FG24CJDE ]
        delivery.ibanner.de [ D:\NICOLE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FG24CJDE ]
        .specificclick.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .googleads.g.doubleclick.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .stepstone.112.2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .view.atdmt.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        wstat.wibiya.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ads2.bartime.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        fr.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        fr.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ads1.moonchildmedia.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        tracking.tchibo.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .autoscout24.112.2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ad.yieldmanager.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ad.yieldmanager.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ispo-mediaservices.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ispo-mediaservices.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        tracking.gameforge.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        zbox.zanox.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .search.eclickz.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .search.eclickz.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .eclickz.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        adserver2.eclickz.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .timeinc.122.2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .dsupermarked.112.2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ltur.112.2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.adserv3.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ads2.bartime.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .horyzon-media.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .hertz.122.2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .indigio.122.2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .germanwings.112.2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .nextag.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adserver.adtechus.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        teufel-media.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        delivery.atkmedia.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .traffective-tracking.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        deutsches-youporn.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        webstats.de-cix.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aeloeoc5wbo.stats.esomniture.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .discounto.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .discounto.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .discounto.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .mmotraffic.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .getclicky.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .static.getclicky.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        in.getclicky.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        eas8.emediate.eu [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        eas8.emediate.eu [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        eas8.emediate.eu [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .estat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        fr.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .dealtime.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .nextag.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .nextag.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .nextag.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        media3.tchibo-content.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        media4.tchibo-content.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .revenuemax.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wnmiuhcpsho.stats.esomniture.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aekoeldjgco.stats.esomniture.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .paypal.112.2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        nfm-adserver.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        stat.dealtime.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .jobscanner.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .jobscanner.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        pt.trafficjunky.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        pt.trafficjunky.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .pornme.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .pornme.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.pornme.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.youporn-deutsch.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.youporn-deutsch.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .horyzon-media.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .horyzon-media.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .horyzon-media.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        server.adformdsp.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        youporn-deutsch.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn-deutsch.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn-deutsch.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        youporn-deutsch.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adformdsp.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        server.adformdsp.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adformdsp.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        banner.holidaycheck.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ads1.moonchildmedia.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.youporn.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ads2.zeusclicks.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn.com.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn.com.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn.com.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn.com.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ads.crakmedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        de.youporn.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        de.youporn.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .realmedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .realmedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .movitex.122.2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.de [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.youporn.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .sexad.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ads.trafficjunky.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        www.youporn.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .powerhitz.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .powerhitz.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .powerhitz.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]
        network.realmedia.com [ D:\NICOLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZNI354NT.DEFAULT\COOKIES.SQLITE ]


cosinus 11.06.2012 12:30

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

NicoleM 11.06.2012 12:40

Super, danke für den Tipp! Dann werd ich mich da mal drum kümmern.

Hmm...meine ganzen Daten sind immer noch verschlüsselt und ich kann sie nicht öffnen...

cosinus 11.06.2012 13:04

Hinweise bzgl. der verschlüsselten Dateien:
Wann genau deine Daten entschlüsselt werden können wird dir niemand genau sagen können außer vllt einer :glaskugel: es kann sein, dass du eine neuere Variante hast, deren Verschlüsselungsalgorithmus noch unbekannt ist. Sowas kann man (noch) nicht entschlüsseln und ohne Schlüssel schon garnicht - ist ja auch logisch, sonst wär es ja keine vernünftige Verschlüsselung
Einfach hier nochmal reinsehen in regelmäßigen Abständen, obige Hinweise beachten. 8 Tools mitsamt hunderten Diskussionsbeiträgen stehen da schon

Eine Notlösung für Vista und Win7-User => http://www.trojaner-board.de/115496-...erstellen.html

Entschlüsselungsversuche der verschlüsselten Dateien sind nur auf zusätzliche Kopien der verschlüsselten Dateien anzuwenden, sonst zerhackt man sich die noch weiter ohne die "original" verschlüsselte Datei mehr zu haben. Das willst du sicher nicht!

Man darf sich aber keine falschen Hoffnungen machen. Mittlerweile sieht es finster aus => http://www.delphipraxis.net/1169769-post147.html


Und in Zukunft willst du sicher mal an ein besseres Backupkonzept denken. Hier ein Denkanstoß => http://www.trojaner-board.de/115678-...r-backups.html


Abgesehen davon wären wir aber durch
Entfern bitte noch nichts aus der Quarantäne, die schädlichen Dateien, Ordner etc die wir gelöscht haben, liegen noch als Sicherheitskopie in diversen Ordner wie Qoobox oder _OTL/MovedFiles - die werden evtl. noch für eine Entschlüsselung benötigt


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

NicoleM 11.06.2012 13:40

Alles, klar, ich werde mich auf dem Laufenden halten und vielen lieben Dank für deine Geduld!

Ich hätte noch eine Frage:
Besteht irgendwie die Möglichkeit meine Mails im Outlook wieder herzustellen?

cosinus 11.06.2012 13:54

Zitat:

Besteht irgendwie die Möglichkeit meine Mails im Outlook wieder herzustellen?
Ja ganz schnell wenn du ein Backup hast :rofl:
ansonsten wirst du warten müssen bis die vom Schädling verschlüsselten Dateien entschlüsselt werden können. Die Outlook-PST Datei die zB alle Mails anthält wird sicher auch betroffen sein :pfeiff:

Naja, so ist das leider wenn man keine Backups macht http://cosgan.de/images/midi/boese/a040.gif

NicoleM 11.06.2012 14:01

Naja, dann werde ich die wohl nicht so schnell wiederherstellen können...oh, man! :(

Wie kann ich denn erfahren wann die vom Schädling entschlüsselten Dateien entschlüsselt werden können?

cosinus 11.06.2012 14:08

Zitat:

Wie kann ich denn erfahren wann die vom Schädling entschlüsselten Dateien entschlüsselt werden können?
Indem du einfach hier mal öfter reinschaust, wir können nicht in die Zukunft sehen :glaskugel:
Eine Notfalllösung über den shadowexplorer wurde dir auch genannt

NicoleM 11.06.2012 14:14

Super, dankeschön! Dann werde ich hier regelmäßig reinschauen :-)

Den Shadowexplorer habe ich nicht ganz verstanden - werde mich aber versuchen reinzufuchsen!

Daaaankeschön und einen schönen Tag wünsch ich dir!


Alle Zeitangaben in WEZ +1. Es ist jetzt 14:44 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131