|
Plagegeister aller Art und deren Bekämpfung: TR/crypt.XPACK.gen3 / Zeus BotWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
12.02.2012, 16:53 | #16 |
| TR/crypt.XPACK.gen3 / Zeus Bot Also jetzt mit dem Script sagt er mir das die Avast scanner immernoch Aktiv sind, obwohl ich die Schutzsteuerung ausgeschaltet habe. Das Programm ansich lässt sich nicht beenden, höchstens Deinstallieren. Ohne Script kommt immernoch Avira Desktop |
12.02.2012, 18:07 | #17 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TR/crypt.XPACK.gen3 / Zeus Bot Ignorieren! Ich versuch diese Einträge ja gerade zu entfernen! Denn der AntiVir ist nicht aktiv aber die Einträge sind noch vorhanden, die dafür sorgen, dass Programme glauben Avira sei noch aktiv!
__________________
__________________ |
12.02.2012, 18:23 | #18 |
| TR/crypt.XPACK.gen3 / Zeus Bot So,
__________________Ich habe jetzt den Combofix mit dem Script ausgeführt, diesmal kam aber komischerweise keine Fehlermeldung wegen Avast... hier der Log: Code:
ATTFilter ComboFix 12-02-11.03 - Meik 12.02.2012 18:15:26.2.4 - x64 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.49.1031.18.8138.6579 [GMT 1:00] ausgeführt von:: c:\users\Meik\Desktop\ComboFix.exe Benutzte Befehlsschalter :: c:\users\Meik\Desktop\CFScript.txt AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2012-01-12 bis 2012-02-12 )))))))))))))))))))))))))))))) . . 2012-02-12 17:18 . 2012-02-12 17:18 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-02-11 16:05 . 2012-02-11 16:05 -------- d-----w- C:\_OTL 2012-02-09 16:59 . 2012-02-09 16:59 -------- d-----w- c:\program files (x86)\ESET 2012-02-09 16:13 . 2012-02-09 16:13 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-02-09 16:13 . 2012-02-09 16:13 -------- d-----w- c:\programdata\Malwarebytes 2012-02-09 16:13 . 2011-12-10 14:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-02-09 15:01 . 2012-02-09 15:01 -------- d-----w- c:\program files (x86)\NVIDIA Corporation 2012-02-09 14:54 . 2012-02-09 14:54 -------- d-----w- c:\program files (x86)\Common Files\Steam 2012-02-09 10:27 . 2012-02-09 10:27 -------- d-----w- c:\program files (x86)\7-Zip 2012-02-09 08:24 . 2012-02-09 08:24 -------- d-----w- c:\program files (x86)\Google 2012-02-09 08:24 . 2011-11-28 17:53 304472 ----a-w- c:\windows\system32\drivers\aswSP.sys 2012-02-09 08:24 . 2011-11-28 17:51 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-02-09 08:24 . 2011-11-28 17:52 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2012-02-09 08:24 . 2011-11-28 17:52 58712 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2012-02-09 08:24 . 2011-11-28 18:01 256960 ----a-w- c:\windows\system32\aswBoot.exe 2012-02-09 08:24 . 2011-11-28 17:54 591192 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2012-02-09 08:24 . 2011-11-28 17:52 66904 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-02-09 08:24 . 2011-11-28 18:01 41184 ----a-w- c:\windows\avastSS.scr 2012-02-09 08:24 . 2011-11-28 18:01 199816 ----a-w- c:\windows\SysWow64\aswBoot.exe 2012-02-09 08:24 . 2012-02-09 08:24 -------- d-----w- c:\programdata\AVAST Software 2012-02-09 08:24 . 2012-02-09 08:24 -------- d-----w- c:\program files\AVAST Software 2012-02-09 08:23 . 2012-02-09 08:23 -------- d-----w- c:\windows\system32\appmgmt 2012-02-09 03:33 . 2012-02-09 03:33 -------- d-----w- c:\program files (x86)\Microsoft WSE 2012-02-08 13:55 . 2012-02-08 13:55 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2012-02-08 13:55 . 2012-02-08 13:55 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite 2012-02-08 13:55 . 2012-02-08 13:55 -------- d-----w- c:\programdata\DAEMON Tools Lite 2012-02-07 15:08 . 2012-02-07 15:08 -------- d-----w- c:\program files (x86)\VideoLAN 2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2012-02-07 14:46 . 2012-02-07 14:46 -------- d-----w- c:\program files (x86)\QuickTime 2012-01-25 13:52 . 2012-01-25 13:52 -------- d-----w- c:\windows\Sun 2012-01-22 10:38 . 2012-01-22 10:38 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies 2012-01-22 10:36 . 2012-01-22 10:36 -------- d-----w- c:\program files (x86)\AMD APP 2012-01-22 10:35 . 2012-01-22 10:35 -------- d-----w- C:\ATI 2012-01-21 13:25 . 2012-01-21 13:25 -------- d-----w- c:\program files (x86)\Adobe Story 2012-01-21 13:24 . 2012-01-21 13:26 -------- d-----w- c:\program files\Common Files\Adobe 2012-01-21 13:23 . 2012-01-21 13:23 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR 2012-01-21 13:21 . 2012-01-21 13:25 -------- d-----w- c:\program files (x86)\Common Files\Adobe 2012-01-20 18:54 . 2012-01-20 18:54 -------- d-----w- c:\programdata\CanonBJ 2012-01-20 18:54 . 2009-07-14 01:40 84992 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNBPP4.DLL 2012-01-20 18:15 . 2012-01-20 18:15 -------- d-----w- c:\programdata\Sony 2012-01-20 18:15 . 2012-01-20 18:15 -------- d-----w- c:\program files (x86)\Sony 2012-01-20 18:15 . 2012-01-20 18:15 -------- d-----w- c:\program files\Sony 2012-01-19 22:12 . 2012-01-19 22:12 -------- d-----w- c:\programdata\ASUS OC Profiles 2012-01-19 21:52 . 2012-01-19 21:52 16896 ----a-w- c:\windows\AsTaskSched.dll 2012-01-19 21:50 . 2010-11-08 13:57 14464 ----a-w- c:\windows\system32\drivers\AiChargerPlus.sys 2012-01-19 21:50 . 2008-12-02 19:05 184320 ----a-w- c:\windows\SysWow64\drivers\UpdateHelper.dll 2012-01-19 21:49 . 2012-01-19 21:49 -------- d-----w- c:\programdata\ASUS 2012-01-19 21:49 . 2012-01-19 21:49 -------- d-----w- c:\program files (x86)\ASUS 2012-01-19 21:49 . 2010-08-24 07:16 13440 ----a-r- c:\windows\SysWow64\drivers\AsIO.sys 2012-01-19 21:49 . 2010-06-29 07:41 28672 ----a-r- c:\windows\SysWow64\AsIO.dll 2012-01-19 21:49 . 2008-01-04 05:34 11832 ------w- c:\windows\SysWow64\drivers\AsInsHelp64.sys 2012-01-19 21:47 . 2012-02-09 01:46 -------- d-----w- c:\program files (x86)\JDownloader 2012-01-19 21:37 . 2012-01-21 20:02 -------- d-----w- C:\Fraps 2012-01-19 21:15 . 2012-01-19 21:15 -------- d-sh--w- c:\programdata\SecuROM 2012-01-19 21:15 . 2012-01-19 21:15 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll 2012-01-19 21:14 . 2012-01-19 21:15 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE 2012-01-19 21:14 . 2012-01-19 21:14 -------- d-----w- c:\windows\SysWow64\xlive 2012-01-19 20:53 . 2011-11-30 01:21 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DF8A2FC3-958E-4F10-86EE-9B79155C66AB}\mpengine.dll 2012-01-19 20:53 . 2011-11-15 13:29 270720 ------w- c:\windows\system32\MpSigStub.exe 2012-01-19 20:33 . 2012-01-19 20:33 -------- d-----w- c:\programdata\ATI 2012-01-19 20:32 . 2012-01-19 20:32 0 ----a-w- c:\windows\ativpsrm.bin 2012-01-19 20:28 . 2012-01-19 20:28 -------- d-----w- c:\program files (x86)\My Company Name 2012-01-19 20:26 . 2012-01-19 20:26 -------- d-----w- c:\program files (x86)\ATI Technologies 2012-01-19 20:26 . 2012-01-19 20:26 -------- d-----w- c:\program files\Common Files\ATI Technologies 2012-01-19 20:26 . 2010-11-16 23:04 115216 ----a-w- c:\windows\system32\drivers\AtihdW76.sys 2012-01-19 20:26 . 2011-11-10 02:18 58880 ----a-w- c:\windows\system32\coinst.dll 2012-01-19 20:23 . 2012-01-19 20:23 -------- d-----w- c:\program files (x86)\ASM104xUSB3 2012-01-19 20:22 . 2011-04-21 18:17 74272 ----a-w- c:\windows\system32\RtNicProp64.dll 2012-01-19 20:22 . 2011-04-21 18:17 471144 ----a-w- c:\windows\system32\drivers\Rt64win7.sys 2012-01-19 20:22 . 2011-04-21 18:17 107552 ----a-w- c:\windows\system32\RTNUninst64.dll 2012-01-19 20:19 . 2012-01-20 17:40 -------- dc----w- c:\windows\system32\DRVSTORE 2012-01-19 20:19 . 2010-12-16 04:06 47232 ----a-r- c:\windows\system32\drivers\usbfilter.sys 2012-01-19 20:19 . 2012-01-19 20:19 -------- d-----w- c:\program files\ATI 2012-01-19 20:12 . 2012-02-09 15:01 -------- d-----w- c:\users\Meik 2012-01-19 20:12 . 2012-01-19 20:12 -------- d-----w- c:\windows\SysWow64\Adobe 2012-01-19 20:11 . 2012-01-19 20:11 455680 ----a-w- c:\windows\system32\deploytk.dll 2012-01-19 20:11 . 2012-01-19 20:11 -------- d-----w- c:\program files\Java 2012-01-19 20:11 . 2012-01-19 20:11 411368 ----a-w- c:\windows\SysWow64\deploytk.dll 2012-01-19 20:11 . 2012-01-19 20:11 -------- d-----w- c:\program files (x86)\Java 2012-01-19 20:10 . 2012-01-19 20:10 -------- d-----w- c:\program files (x86)\Microsoft Silverlight . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((( SnapShot@2012-02-12_15.28.36 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-14 04:54 . 2012-02-12 17:19 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2012-02-12 15:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2012-02-12 17:19 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-02-12 15:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-02-12 17:19 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2012-02-12 15:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2012-01-19 20:36 . 2012-02-12 15:51 26456 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-02-12 15:51 31008 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2012-01-19 20:24 . 2012-02-12 15:49 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2012-01-19 20:24 . 2012-02-12 15:28 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2012-01-19 20:24 . 2012-02-12 15:49 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2012-01-19 20:24 . 2012-02-12 15:28 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2012-01-19 20:24 . 2012-02-12 15:28 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2012-01-19 20:24 . 2012-02-12 15:49 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2012-01-19 20:24 . 2012-02-12 15:49 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2012-01-19 20:24 . 2012-02-12 15:28 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2012-01-19 20:24 . 2012-02-12 15:28 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2012-01-19 20:24 . 2012-02-12 15:49 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2012-01-19 20:16 . 2012-02-12 15:51 6720 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1943331422-757434833-6866547-1000_UserData.bin - 2012-02-12 15:27 . 2012-02-12 15:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-02-12 17:19 . 2012-02-12 17:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-07-14 02:36 . 2012-02-12 15:54 607530 c:\windows\system32\perfh009.dat - 2009-07-14 02:36 . 2012-02-12 14:05 607530 c:\windows\system32\perfh009.dat + 2009-07-14 17:58 . 2012-02-12 15:54 645502 c:\windows\system32\perfh007.dat - 2009-07-14 17:58 . 2012-02-12 14:05 645502 c:\windows\system32\perfh007.dat + 2009-07-14 02:36 . 2012-02-12 15:54 103908 c:\windows\system32\perfc009.dat - 2009-07-14 02:36 . 2012-02-12 14:05 103908 c:\windows\system32\perfc009.dat - 2009-07-14 17:58 . 2012-02-12 14:05 126822 c:\windows\system32\perfc007.dat + 2009-07-14 17:58 . 2012-02-12 15:54 126822 c:\windows\system32\perfc007.dat - 2009-07-14 05:01 . 2012-02-12 15:26 322272 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2012-02-12 17:18 322272 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 02:34 . 2012-02-11 15:57 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT + 2009-07-14 02:34 . 2012-02-12 16:43 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT + 2012-02-09 08:26 . 2012-02-12 17:18 5073553 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1943331422-757434833-6866547-1000-8192.dat . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-01-24 3478336] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-11-25 98304] "ASUS AiChargerPlus Execute"="c:\program files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe" [2010-11-08 465536] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-09 136176] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360] R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-09 136176] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys [x] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [x] S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144] S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584] S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [x] S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [x] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2012-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-09 08:24] . 2012-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-09 08:24] . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-11-28 18:01 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-19 11613288] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 192.168.2.1 192.168.2.1 FF - ProfilePath - c:\users\Meik\AppData\Roaming\Mozilla\Firefox\Profiles\ba7vtxnj.default\ . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-1943331422-757434833-6866547-1000\Software\SecuROM\License information*] "datasecu"=hex:e5,6d,90,d2,fa,1a,ef,a9,fe,48,98,56,e4,e6,48,24,f8,9e,62,29,05, e2,31,4b,44,4e,ac,cb,3c,d3,89,cf,fe,74,d1,63,85,25,6c,18,36,6b,bd,a2,5d,43,\ "rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}] @Denied: (A 2) (Everyone) @="IFlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib] @="{6EF568F4-D437-4466-AA63-A3645136D93E}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\windows\DAODx.exe c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe c:\program files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe c:\program files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe c:\program files (x86)\ASUS\AI Suite II\AI Suite II.exe . ************************************************************************** . Zeit der Fertigstellung: 2012-02-12 18:22:03 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2012-02-12 17:22 ComboFix2.txt 2012-02-12 15:30 . Vor Suchlauf: 11 Verzeichnis(se), 34.436.530.176 Bytes frei Nach Suchlauf: 12 Verzeichnis(se), 34.217.402.368 Bytes frei . - - End Of File - - BBB9DCB2456827930AB33933ADDA4FCD |
12.02.2012, 18:47 | #19 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TR/crypt.XPACK.gen3 / Zeus Bot Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
12.02.2012, 19:03 | #20 |
| TR/crypt.XPACK.gen3 / Zeus Bot aswMBR Log: Code:
ATTFilter aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software Run date: 2012-02-12 18:52:15 ----------------------------- 18:52:15.831 OS Version: Windows x64 6.1.7600 18:52:15.831 Number of processors: 4 586 0x102 18:52:15.832 ComputerName: xxx-PC UserName: xxx 18:52:16.233 Initialize success 18:52:16.442 AVAST engine defs: 12021200 18:52:25.508 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000066 18:52:25.510 Disk 0 Vendor: ST336032 3.AA Size: 343399MB BusType: 11 18:52:25.520 Disk 0 MBR read successfully 18:52:25.523 Disk 0 MBR scan 18:52:25.525 Disk 0 Windows 7 default MBR code 18:52:25.532 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 81920 MB offset 2048 18:52:25.546 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 261477 MB offset 167774208 18:52:25.549 Service scanning 18:52:26.581 Modules scanning 18:52:26.584 Disk 0 trace - called modules: 18:52:26.595 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys 18:52:26.598 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007d8a060] 18:52:26.602 3 CLASSPNP.SYS[fffff8800192843f] -> nt!IofCallDriver -> [0xfffffa8007ade8e0] 18:52:26.607 5 amd_xata.sys[fffff880011178f7] -> nt!IofCallDriver -> \Device\00000066[0xfffffa8007adc880] 18:52:26.975 AVAST engine scan C:\Windows 18:52:30.434 AVAST engine scan C:\Windows\system32 18:53:46.834 AVAST engine scan C:\Windows\system32\drivers 18:53:53.668 AVAST engine scan C:\Users\xxx 18:54:23.801 AVAST engine scan C:\ProgramData 18:54:45.517 Scan finished successfully 19:02:07.517 Disk 0 MBR has been saved successfully to "C:\Users\xxx\Downloads\MBR.dat" 19:02:07.524 The log file has been saved successfully to "C:\Users\xxx\Downloads\aswMBR.txt" |
12.02.2012, 19:36 | #21 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TR/crypt.XPACK.gen3 / Zeus Bot Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!!
__________________ --> TR/crypt.XPACK.gen3 / Zeus Bot |
14.02.2012, 06:28 | #22 |
| TR/crypt.XPACK.gen3 / Zeus Bot mbam log: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.60.1.1000 www.malwarebytes.org Datenbank Version: v2012.02.12.02 Windows 7 x64 NTFS Internet Explorer 8.0.7600.16385 xxx :: xxx-PC [Administrator] Schutz: Aktiviert 13.02.2012 12:50:59 mbam-log-2012-02-13 (12-50-59).txt Art des Suchlaufs: Vollständiger Suchlauf Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 272712 Laufzeit: 21 Minute(n), 52 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter SUPERAntiSpyware Scan Log hxxp://www.superantispyware.com Generated 02/14/2012 at 03:53 AM Application Version : 5.0.1144 Core Rules Database Version : 8235 Trace Rules Database Version: 6047 Scan type : Complete Scan Total Scan Time : 00:35:43 Operating System Information Windows 7 Ultimate 64-bit (Build 6.01.7600) UAC On - Limited User Memory items scanned : 663 Memory threats detected : 0 Registry items scanned : 64723 Registry threats detected : 0 File items scanned : 107450 File threats detected : 288 Adware.Tracking Cookie C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@ad2.adfarm1.adition[1].txt [ /ad2.adfarm1.adition ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@ad3.adfarm1.adition[1].txt [ /ad3.adfarm1.adition ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@adfarm1.adition[1].txt [ /adfarm1.adition ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@adx.chip[2].txt [ /adx.chip ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@apmebf[2].txt [ /apmebf ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@atdmt[2].txt [ /atdmt ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@bs.serving-sys[2].txt [ /bs.serving-sys ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@c.atdmt[2].txt [ /c.atdmt ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@doubleclick[2].txt [ /doubleclick ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@imrworldwide[2].txt [ /imrworldwide ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@invitemedia[1].txt [ /invitemedia ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@revsci[1].txt [ /revsci ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@serving-sys[1].txt [ /serving-sys ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@specificclick[1].txt [ /specificclick ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@xiti[1].txt [ /xiti ] C:\Users\***\AppData\Roaming\Microsoft\Windows\Cookies\***@openstat[1].txt [ /openstat.net ] C:\USERS\***\AppData\Roaming\Microsoft\Windows\Cookies\Low\***@serving-sys[2].txt [ Cookie:***@serving-sys.com/ ] C:\USERS\***\AppData\Roaming\Microsoft\Windows\Cookies\Low\***@overture[1].txt [ Cookie:***@overture.com/ ] C:\USERS\***\AppData\Roaming\Microsoft\Windows\Cookies\Low\***@ad.yieldmanager[1].txt [ Cookie:***@ad.yieldmanager.com/ ] C:\USERS\***\AppData\Roaming\Microsoft\Windows\Cookies\Low\***@c.atdmt[2].txt [ Cookie:***@c.atdmt.com/ ] C:\USERS\***\AppData\Roaming\Microsoft\Windows\Cookies\Low\***@2o7[2].txt [ Cookie:***@2o7.net/ ] C:\USERS\***\Cookies\***@adx.chip[2].txt [ Cookie:***@adx.chip.de/ ] C:\USERS\***\Cookies\***@adfarm1.adition[1].txt [ Cookie:***@adfarm1.adition.com/ ] C:\USERS\***\Cookies\***@serving-sys[1].txt [ Cookie:***@serving-sys.com/ ] C:\USERS\***\Cookies\***@ad3.adfarm1.adition[1].txt [ Cookie:***@ad3.adfarm1.adition.com/ ] C:\USERS\***\Cookies\***@apmebf[2].txt [ Cookie:***@apmebf.com/ ] C:\USERS\***\Cookies\***@bs.serving-sys[2].txt [ Cookie:***@bs.serving-sys.com/ ] C:\USERS\***\Cookies\***@c.atdmt[2].txt [ Cookie:***@c.atdmt.com/ ] C:\USERS\***\Cookies\***@revsci[1].txt [ Cookie:***@revsci.net/ ] C:\USERS\***\Cookies\***@openstat[1].txt [ Cookie:***@openstat.net/ ] C:\USERS\***\Cookies\***@invitemedia[1].txt [ Cookie:***@invitemedia.com/ ] C:\USERS\***\Cookies\***@specificclick[1].txt [ Cookie:***@specificclick.net/ ] C:\USERS\***\Cookies\***@imrworldwide[2].txt [ Cookie:***@imrworldwide.com/cgi-bin ] C:\USERS\***\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\***@ATDMT[2].TXT [ /ATDMT ] C:\USERS\***\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\***@DOUBLECLICK[1].TXT [ /DOUBLECLICK ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .doubleclick.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adxvalue.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .eyewonder.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .apmebf.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .mediaplex.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adxvalue.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adxvalue.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adxvalue.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adxvalue.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .specificclick.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .imrworldwide.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .imrworldwide.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .counter.sexsuche.tv [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] counter2.sexmoney.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .questionmarket.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .questionmarket.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .amazon-adsystem.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .amazon-adsystem.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .webmasterplan.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adserver.adtechus.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .xiti.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .kontera.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .legolas-media.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .legolas-media.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .legolas-media.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .server.cpmstar.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] eas.apm.emediate.eu [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] tracking.mlsat02.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .at.atwola.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .interclick.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .collective-media.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .interclick.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .atdmt.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .atdmt.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .harrenmedianetwork.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] track.adform.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] statse.webtrendslive.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .lucidmedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adxpose.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .ru4.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .ru4.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .mediaplex.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .smartadserver.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .smartadserver.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .smartadserver.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .smartadserver.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .conrad.122.2o7.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .fastclick.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] partners.webmasterplan.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] stats.computecmedia.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .a.revenuemax.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .p6.mediamolecule.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .p6.mediamolecule.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .p6.mediamolecule.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .p6.mediamolecule.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .p6.mediamolecule.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .eaeacom.112.2o7.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] eas.apm.emediate.eu [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .server.cpmstar.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .server.cpmstar.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .server.cpmstar.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .server.cpmstar.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .server.cpmstar.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .statcounter.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] track.effiliation.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] track.effiliation.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] track.effiliation.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] track.effiliation.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] track.effiliation.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] track.effiliation.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .webmasterplan.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .webmasterplan.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .paypal.112.2o7.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .mediaplex.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .de.partypoker.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .partypoker.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .zedo.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] sega.missioncontrol.global-media.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .tribalfusion.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .histats.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .histats.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .fastclick.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ww251.smartadserver.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .tracking.quisma.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .oserverstats.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .oserverstats.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .oserverstats.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .oserverstats.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .apmebf.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad.dyntracker.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .overture.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .overture.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .overture.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .collective-media.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .collective-media.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .collective-media.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .collective-media.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .collective-media.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] adx.chip.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] adx.chip.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] adx.chip.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] adx.chip.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] adx.chip.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] dtp.missioncontrol.global-media.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] adx.chip.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .100sexlinks.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] 100sexlinks.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] 100sexlinks.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] 100sexlinks.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .myroitracking.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .clicksor.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .clicksor.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .clicksor.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .clicksor.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .clicksor.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad3.adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .tracking.quisma.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad4.adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .smartadserver.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .smartadserver.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .smartadserver.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .unitymedia.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .tracking.quisma.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] www.toplistenservice.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] www.toplistenservice.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] www.toplistenservice.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] eas.apm.emediate.eu [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .tradedoubler.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .dyntracker.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .zanox.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .zanox-affiliate.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad1.adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad.zanox.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .bs.serving-sys.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .webmasterplan.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .unister-adservices.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .unister-adservices.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad.adserver01.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .tradedoubler.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .webmasterplan.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .webmasterplan.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .webmasterplan.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .tracking.quisma.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .tracking.quisma.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] tracking.quisma.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] tracking.quisma.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .tradedoubler.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .unitymedia.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .unitymedia.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .traffictrack.de [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] track.adform.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adform.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad2.adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .yieldmanager.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] accounts.google.com [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] .doubleclick.net [ C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BA7VTXNJ.DEFAULT\COOKIES.SQLITE ] |
14.02.2012, 10:40 | #23 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TR/crypt.XPACK.gen3 / Zeus Bot Sieht ok aus, da wurden nur Cookies gefunden. Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie ) Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________ Logfiles bitte immer in CODE-Tags posten |
14.02.2012, 13:18 | #24 |
| TR/crypt.XPACK.gen3 / Zeus Bot Ne, jetzt ist alles in Ordung. Vielen Vielen Dank für die Hilfe. |
14.02.2012, 15:06 | #25 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TR/crypt.XPACK.gen3 / Zeus Bot Dann wären wir durch! Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt. Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken. Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden. Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern. Microsoftupdate Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren. Windows Vista/7: Anleitung Windows-Update PDF-Reader aktualisieren Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast) Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader. Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers: Adobe - Andere Version des Adobe Flash Player installieren Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind. Java-Update Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu TR/crypt.XPACK.gen3 / Zeus Bot |
64-bit, 7-zip, adobe, adobe after effects, antivir, antivirus, asus, autorun, avira, bho, bonjour, bot, call of duty, explorer, firefox, focus, format, helper, installation, langs, microsoft, pixel, plug-in, programme, realtek, registry, software, tr/crypt.xpack.ge, tr/crypt.xpack.gen, trojaner, version=1.0, viren, webcheck, windows, windows xp |