Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Trojaner "System Check" - letzte Schritte?

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 05.03.2012, 20:32   #16
wrimpus
 
Trojaner "System Check" - letzte Schritte? - Standard

Trojaner "System Check" - letzte Schritte?



Hier der Log von GMER - OSAM folgt in Kürze ...

GMER Logfile:
Code:
ATTFilter
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-03-05 20:29:15
Windows 6.0.6001 Service Pack 1 Harddisk0\DR0 -> \Device\00000054 WDC_WD64 rev.05.0
Running: 8mnxkcc7.exe; Driver: C:\Users\mn\AppData\Local\Temp\pgldypoc.sys


---- System - GMER 1.0.15 ----

SSDT            8D3E96BC                                                                                             ZwCreateThread
SSDT            8D3E96A8                                                                                             ZwOpenProcess
SSDT            8D3E96AD                                                                                             ZwOpenThread
SSDT            8D3E96B7                                                                                             ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text           ntkrnlpa.exe!KeSetTimerEx + 454                                                                      824CBA78 4 Bytes  [BC, 96, 3E, 8D]
.text           ntkrnlpa.exe!KeSetTimerEx + 624                                                                      824CBC48 4 Bytes  [A8, 96, 3E, 8D]
.text           ntkrnlpa.exe!KeSetTimerEx + 640                                                                      824CBC64 4 Bytes  [AD, 96, 3E, 8D]
.text           ntkrnlpa.exe!KeSetTimerEx + 854                                                                      824CBE78 4 Bytes  [B7, 96, 3E, 8D]
.text           C:\Windows\system32\DRIVERS\atikmdag.sys                                                             section is writeable [0x90C06000, 0x23097E, 0xE8000020]
?               C:\Windows\system32\Drivers\PROCEXP113.SYS                                                           Das System kann die angegebene Datei nicht finden. !
?               C:\Users\mn\AppData\Local\Temp\catchme.sys                                                           Das System kann die angegebene Datei nicht finden. !

---- User IAT/EAT - GMER 1.0.15 ----

IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdiplusShutdown]                [74D08864] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCloneImage]                 [74D49855] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDrawImageRectI]             [74D0B984] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipSetInterpolationMode]       [74CFFB47] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdiplusStartup]                 [74D07A29] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateFromHDC]              [74CFEA65] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateBitmapFromStreamICM]  [74D3B12D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateBitmapFromStream]     [74D0BC4A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipGetImageHeight]             [74D00756] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipGetImageWidth]              [74D006BD] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDisposeImage]               [74CF71B3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipLoadImageFromFileICM]       [74D8D9E0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipLoadImageFromFile]          [74D27329] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDeleteGraphics]             [74CFE109] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipFree]                       [74CF697E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipAlloc]                      [74CF69A9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[1168] @ C:\Windows\explorer.exe [gdiplus.dll!GdipSetCompositingMode]         [74D02475] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\fastfat \Fat                                                                             fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----
         
--- --- ---

So, und hier der von OSAM

OSAM Logfile:
Code:
ATTFilter
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 20:41:04 on 05.03.2012

OS: Windows Vista Home Premium Edition Service Pack 1 (Build 6001), 32-bit
Default Browser: Mozilla Corporation Firefox 9.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"MT66 Software Update.job" - "MedienTeam66" - C:\Program Files\Common Files\MT66 Software Update\UpdateClient.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"ISUSPM.cpl" - "Macrovision Corporation" - C:\Windows\system32\ISUSPM.cpl
"odbccp32.cpl" - "Microsoft Corporation" - C:\Windows\system32\odbccp32.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"adfs" (adfs) - "Adobe Systems, Inc." - C:\Windows\system32\drivers\adfs.sys
"avgio" (avgio) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avgio.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\Users\mn\AppData\Local\Temp\catchme.sys  (File not found)
"Dynamically loaded UxdDrv" (uxddrv) - ? - I:\DIAGNOSE\WSTGER32\2PART\uxddrv86.sys  (File not found)
"HPFXBULK" (HPFXBULK) - "Hewlett Packard" - C:\Windows\System32\drivers\hpfxbulk.sys
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\Windows\System32\Drivers\PxHelp20.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{63560240-BB5D-4F81-B0B9-AEBEA2FE3DD5} "Shell Extension for High-Logic FontCreator" - "High-Logic" - C:\PROGRA~1\HIGH-L~1\FONTCR~1\FONTCR~1.DLL
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -   (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -   (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -   (File not found | COM-object registry key not found)
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? -   (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\ONFILTER.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2} "NeroCoverEdLiveIcons Class" - "Nero AG" - C:\Program Files\Nero\Nero8\Nero CoverDesigner\CoverEdExtension.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{52B87208-9CCF-42C9-B88E-069281105805} "Trojan Remover Shell Extension" - ? -   (File not found | COM-object registry key not found)
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -   (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Program Files\WinRAR\rarext.dll

[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"eBay - Der weltweite Online-Marktplatz" - ? - hxxp://rover.ebay.com/rover/1/707-37276-17534-15/4  (HTTP value)
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_27" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} "Java Plug-in 1.6.0_27" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_27" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_27.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
{233C1507-6A77-46A4-9443-F871F945D258} "Shockwave ActiveX Control" - "Adobe Systems, Inc." - C:\Windows\System32\Adobe\Director\SwDir.dll / hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} "{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}" - ? -   (File not found | COM-object registry key not found) / hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
"eBay - Der weltweite Online-Marktplatz" - ? - hxxp://rover.ebay.com/rover/1/707-37276-17534-25/4  (HTTP value)
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\mn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"AdobeCS4ServiceManager" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

[Network Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order )-----
"Adobe Drive CS4 Network" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"HP Standard TCP/IP Port" - "Hewlett Packard" - C:\Windows\system32\HpTcpMon.dll
"PDFCreator" - ? - C:\Windows\system32\pdfcmnnt.dll  (File found, but it contains no detailed information)
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Acresso Software Inc." - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"HP CUE DeviceDiscovery Service" (hpqddsvc) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
"hpqcxs08" (hpqcxs08) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Nero BackItUp Scheduler 3" (Nero BackItUp Scheduler 3) - "Nero AG" - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"NMIndexingService" (NMIndexingService) - "Nero AG" - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"PLFlash DeviceIoControl Service" (PLFlash DeviceIoControl Service) - "Prolific Technology Inc." - C:\Windows\system32\IoctlSvc.exe
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll

===[ Logfile end ]=========================================[ Logfile end ]===
         
--- --- ---
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
[/code]

Geändert von wrimpus (05.03.2012 um 20:42 Uhr)

Alt 05.03.2012, 21:42   #17
wrimpus
 
Trojaner "System Check" - letzte Schritte? - Standard

Trojaner "System Check" - letzte Schritte?



und hier Nr. 3
Code:
ATTFilter
aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-03-05 20:43:23
-----------------------------
20:43:23.727    OS Version: Windows 6.0.6001 Service Pack 1
20:43:23.727    Number of processors: 2 586 0x203
20:43:23.727    ComputerName: MN-PC  UserName: mn
20:43:50.466    Initialize success
20:45:05.647    AVAST engine defs: 12030501
20:45:58.313    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000055
20:45:58.313    Disk 0 Vendor: WDC_WD64 05.0 Size: 610480MB BusType: 8
20:45:58.328    Disk 0 MBR read successfully
20:45:58.328    Disk 0 MBR scan
20:45:58.328    Disk 0 Windows VISTA default MBR code
20:45:58.344    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS       589993 MB offset 2048
20:45:58.344    Disk 0 Partition - 00     0F Extended LBA             20483 MB offset 1208307712
20:45:58.375    Disk 0 Partition 2 00     0B        FAT32 MSDOS5.0    20483 MB offset 1208307775
20:45:58.375    Disk 0 scanning sectors +1250258625
20:45:58.453    Disk 0 scanning C:\Windows\system32\drivers
20:46:06.674    Service scanning
20:46:22.976    Modules scanning
20:46:26.252    Disk 0 trace - called modules:
20:46:26.908    ntkrnlpa.exe CLASSPNP.SYS disk.sys storport.sys hal.dll ahcix86s.sys USBPORT.SYS usbehci.sys PxHelp20.sys dxgkrnl.sys atikmdag.sys USBSTOR.SYS acpi.sys usbhub.sys tcpip.sys NETIO.SYS watchdog.sys HDAudBus.sys processr.sys rassstp.sys usbo
20:46:26.908    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86e52ac8]
20:46:26.908    3 CLASSPNP.SYS[8b3aa745] -> nt!IofCallDriver -> \Device\00000055[0x85d998f0]
20:46:26.923    5 CLASSPNP.SYS[8b3a925e] -> nt!IofCallDriver -> [0x87a1c018]
20:46:26.923    7 PxHelp20.sys[82b7e773] -> nt!IofCallDriver -> \Device\00000054[0x85d99c90]
20:46:26.939    9 USBSTOR.SYS[918e5dd6] -> nt!IofCallDriver -> [0x88333198]
20:46:26.939    11 acpi.sys[82a116a0] -> nt!IofCallDriver -> \Device\USBPDO-7[0x88290030]
20:46:26.954    13 usbhub.sys[9180de67] -> nt!IofCallDriver -> [0x87dd9c10]
20:46:26.954    15 acpi.sys[82a116a0] -> nt!IofCallDriver -> \Device\USBPDO-2[0x87438028]
20:46:26.970    17 USBSTOR.SYS[918e5dd6] -> nt!IofCallDriver -> [0x88333198]
20:46:26.970    19 acpi.sys[82a116a0] -> nt!IofCallDriver -> \Device\USBPDO-7[0x88290030]
20:46:26.970    21 usbhub.sys[9180de67] -> nt!IofCallDriver -> [0x87dd9c10]
20:46:26.986    23 acpi.sys[82a116a0] -> nt!IofCallDriver -> \Device\USBPDO-2[0x87438028]
20:46:26.986    25 USBSTOR.SYS[918e5dd6] -> nt!IofCallDriver -> [0x88333198]
20:46:26.986    27 acpi.sys[82a116a0] -> nt!IofCallDriver -> \Device\USBPDO-7[0x88290030]
20:46:27.001    29 usbhub.sys[9180de67] -> nt!IofCallDriver -> [0x87dd9c10]
20:46:27.001    31 acpi.sys[82a116a0] -> nt!IofCallDriver -> \Device\USBPDO-2[0x87438028]
20:46:27.017    33 USBSTOR.SYS[918e5dd6] -> nt!IofCallDriver -> [0x88333198]
20:46:27.017    35 acpi.sys[82a116a0] -> nt!IofCallDriver -> \Device\USBPDO-7[0x88290030]
20:46:27.017    37 usbhub.sys[9180de67] -> nt!IofCallDriver -> [0x87dd9c10]
20:46:27.032    39 acpi.sys[82a116a0] -> nt!IofCallDriver -> \Device\USBPDO-2[0x87438028]
20:46:27.032    41 USBSTOR.SYS[918e5dd6] -> nt!IofCallDriver -> [0x88333198]
20:46:27.032    43 acpi.sys[82a116a0] -> nt!IofCallDriver -> \Device\USBPDO-7[0x88290030]
20:46:27.048    45 usbhub.sys[9180de67] -> nt!IofCallDriver -> [0x87dd9c10]
20:46:27.048    47 acpi.sys[82a116a0] -> nt!IofCallDriver -> \Device\USBPDO-2[0x87438028]
20:46:27.048    49 USBSTOR.SYS[918e5dd6] -> nt!IofCallDriver -> [0x88333198]
20:46:27.048    51 acpi.sys[82a116a0] -> nt!IofCallDriver -> \Device\USBPDO-7[0x88290030]
20:46:27.064    53 usbhub.sys[9180de67] -> nt!IofCallDriver -> [0x87dd9c10]
20:46:27.064    55 acpi.sys[82a116a0] -> nt!IofCallDriver -> \Device\USBPDO-2[0x87438028]
20:46:29.014    AVAST engine scan C:\Windows
20:46:33.506    AVAST engine scan C:\Windows\system32
20:49:31.503    AVAST engine scan C:\Windows\system32\drivers
20:49:47.291    AVAST engine scan C:\Users\mn
21:32:07.532    AVAST engine scan C:\ProgramData
21:38:12.198    Scan finished successfully
21:39:39.417    Disk 0 MBR has been saved successfully to "C:\Users\mn\Desktop\MBR.dat"
21:39:39.433    The log file has been saved successfully to "C:\Users\mn\Desktop\aswMBR.txt"
         
__________________


Alt 06.03.2012, 11:44   #18
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Trojaner "System Check" - letzte Schritte? - Standard

Trojaner "System Check" - letzte Schritte?



Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!
__________________
__________________

Alt 06.03.2012, 14:04   #19
wrimpus
 
Trojaner "System Check" - letzte Schritte? - Standard

Trojaner "System Check" - letzte Schritte?



Hier der Log von Malwarebytes:
Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.06.04

Windows Vista Service Pack 1 x86 NTFS
Internet Explorer 7.0.6001.18000
mn :: MN-PC [Administrator]

Schutz: Aktiviert

06.03.2012 13:04:15
mbam-log-2012-03-06 (13-04-15).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 377985
Laufzeit: 56 Minute(n), 45 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         

Alt 06.03.2012, 16:25   #20
wrimpus
 
Trojaner "System Check" - letzte Schritte? - Standard

Trojaner "System Check" - letzte Schritte?



Und hier der von SuperAntiSpyware:

Code:
ATTFilter
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 03/06/2012 at 04:02 PM

Application Version : 5.0.1144

Core Rules Database Version : 8306
Trace Rules Database Version: 6118

Scan type       : Complete Scan
Total Scan Time : 01:52:25

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 1 (Build 6.00.6001)
UAC On - Administrator

Memory items scanned      : 632
Memory threats detected   : 0
Registry items scanned    : 35576
Registry threats detected : 0
File items scanned        : 233410
File threats detected     : 472

Adware.Tracking Cookie
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@a3.adserver01[1].txt [ /a3.adserver01 ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@ad.71i[1].txt [ /ad.71i ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@ad.adition[1].txt [ /ad.adition ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@ad.adnet[1].txt [ /ad.adnet ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@ad.yieldmanager[2].txt [ /ad.yieldmanager ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@ad.zanox[2].txt [ /ad.zanox ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@adfarm1.adition[1].txt [ /adfarm1.adition ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@adredirect.zattoo[2].txt [ /adredirect.zattoo ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@ads.heias[1].txt [ /ads.heias ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@adtech[2].txt [ /adtech ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@advertising[2].txt [ /advertising ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@adx.chip[2].txt [ /adx.chip ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@apmebf[1].txt [ /apmebf ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@atdmt[2].txt [ /atdmt ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@atwola[1].txt [ /atwola ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@bluestreak[2].txt [ /bluestreak ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@bs.serving-sys[2].txt [ /bs.serving-sys ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@collective-media[1].txt [ /collective-media ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@doubleclick[1].txt [ /doubleclick ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@fastclick[1].txt [ /fastclick ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@mediaplex[2].txt [ /mediaplex ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@questionmarket[2].txt [ /questionmarket ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@roiservice[1].txt [ /roiservice ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@serving-sys[1].txt [ /serving-sys ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@smartadserver[2].txt [ /smartadserver ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@track.webtrekk[1].txt [ /track.webtrekk ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@tracking.quisma[1].txt [ /tracking.quisma ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@tradedoubler[1].txt [ /tradedoubler ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@traffictrack[1].txt [ /traffictrack ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@tto2.traffictrack[1].txt [ /tto2.traffictrack ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@webmasterplan[2].txt [ /webmasterplan ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@www.etracker[1].txt [ /www.etracker ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@www.zanox-affiliate[1].txt [ /www.zanox-affiliate ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@zanox-affiliate[2].txt [ /zanox-affiliate ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@zanox[1].txt [ /zanox ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@de.sitestat[1].txt [ /de.sitestat.com ]
	C:\Users\mn\AppData\Roaming\Microsoft\Windows\Cookies\mn@de.sitestat[2].txt [ /de.sitestat.com ]
	C:\USERS\MN\AppData\Roaming\Microsoft\Windows\Cookies\Low\mn@adfarm1.adition[1].txt [ Cookie:mn@adfarm1.adition.com/ ]
	C:\USERS\MN\AppData\Roaming\Microsoft\Windows\Cookies\Low\mn@tradedoubler[1].txt [ Cookie:mn@tradedoubler.com/ ]
	C:\USERS\MN\Cookies\mn@advertising[2].txt [ Cookie:mn@advertising.com/ ]
	C:\USERS\MN\Cookies\mn@bs.serving-sys[2].txt [ Cookie:mn@bs.serving-sys.com/ ]
	C:\USERS\MN\Cookies\mn@zanox-affiliate[2].txt [ Cookie:mn@zanox-affiliate.de/ ]
	C:\USERS\MN\Cookies\mn@tto2.traffictrack[1].txt [ Cookie:mn@tto2.traffictrack.de/ ]
	C:\USERS\MN\Cookies\mn@zanox[1].txt [ Cookie:mn@zanox.com/ ]
	C:\USERS\MN\Cookies\mn@bluestreak[2].txt [ Cookie:mn@bluestreak.com/ ]
	C:\USERS\MN\Cookies\mn@apmebf[1].txt [ Cookie:mn@apmebf.com/ ]
	C:\USERS\MN\Cookies\mn@mediaplex[2].txt [ Cookie:mn@mediaplex.com/ ]
	C:\USERS\MN\Cookies\mn@ad.adition[1].txt [ Cookie:mn@ad.adition.net/ ]
	C:\USERS\MN\Cookies\mn@atwola[1].txt [ Cookie:mn@atwola.com/ ]
	C:\USERS\MN\Cookies\mn@tracking.quisma[1].txt [ Cookie:mn@tracking.quisma.com/ ]
	C:\USERS\MN\Cookies\mn@serving-sys[1].txt [ Cookie:mn@serving-sys.com/ ]
	C:\USERS\MN\Cookies\mn@adfarm1.adition[1].txt [ Cookie:mn@adfarm1.adition.com/ ]
	C:\USERS\MN\Cookies\mn@traffictrack[1].txt [ Cookie:mn@traffictrack.de/ ]
	C:\USERS\MN\Cookies\mn@de.sitestat[1].txt [ Cookie:mn@de.sitestat.com/tcook/condor/ ]
	C:\USERS\MN\Cookies\mn@ad.yieldmanager[2].txt [ Cookie:mn@ad.yieldmanager.com/ ]
	C:\USERS\MN\Cookies\mn@ad.zanox[2].txt [ Cookie:mn@ad.zanox.com/ ]
	C:\USERS\MN\Cookies\mn@a3.adserver01[1].txt [ Cookie:mn@a3.adserver01.de/ ]
	C:\USERS\MN\Cookies\mn@tradedoubler[1].txt [ Cookie:mn@tradedoubler.com/ ]
	C:\USERS\MN\Cookies\mn@atdmt[2].txt [ Cookie:mn@atdmt.com/ ]
	C:\USERS\MN\Cookies\mn@questionmarket[2].txt [ Cookie:mn@questionmarket.com/ ]
	C:\USERS\MN\Cookies\mn@webmasterplan[2].txt [ Cookie:mn@webmasterplan.com/ ]
	C:\USERS\MN\Cookies\mn@adredirect.zattoo[2].txt [ Cookie:mn@adredirect.zattoo.com/ ]
	C:\USERS\MN\Cookies\mn@de.sitestat[2].txt [ Cookie:mn@de.sitestat.com/tcook/ ]
	C:\USERS\MN\Cookies\mn@fastclick[1].txt [ Cookie:mn@fastclick.net/ ]
	C:\USERS\MN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MN@ADTECH[1].TXT [ /ADTECH ]
	C:\USERS\MN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MN@DOUBLECLICK[1].TXT [ /DOUBLECLICK ]
	C:\USERS\MN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MN@WW251.SMARTADSERVER[1].TXT [ /WW251.SMARTADSERVER ]
	de.sitestat.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.4stats.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.4stats.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	track.webtrekk.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	eas4.emediate.eu [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tracking.umg-cms.eu [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tracking.umg-cms.eu [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	fl01.ct2.comclick.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.viacom.adbureau.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.viacom.adbureau.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	adserv.quality-channel.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.a.revenuemax.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adinterax.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	adserver.yopi.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.getclicky.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.static.getclicky.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	in.getclicky.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.aok.122.2o7.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.unstats.un.org [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.unstats.un.org [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.worldmapfinder.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.worldmapfinder.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	studivz.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	studivz.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.4stats.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.4stats.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.youporn.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.legolas-media.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.legolas-media.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adinterax.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.system.medianac.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.system.medianac.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	track.effiliation.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.guj.122.2o7.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adserver.adtechus.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	wstat.wibiya.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tivoli.112.2o7.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.deutschepostag.112.2o7.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adxpose.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	eas4.emediate.eu [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.yieldmanager.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ads.adxvalue.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	fl01.ct2.comclick.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	fl01.ct2.comclick.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	banner.holidaycheck.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adviva.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.ceramex-media.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.ceramex-media.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	track.webtrekk.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.wissende.122.2o7.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.xiti.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.eyewonder.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.adserver01.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	adserver.icmedienhaus.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	adserver.ep-solutions.org [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.passende-gedichte-finden.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.passende-gedichte-finden.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.pro-market.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	eas4.emediate.eu [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.elitepartner.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.eyewonder.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	accounts.google.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	tracking.sim-technik.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.weborama.fr [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.lanes.solution.weborama.fr [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adxvalue.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adxvalue.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.zanox.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	tradefx.advertserve.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.unrulymedia.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.c.gigcount.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adxvalue.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.eyewonder.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.eyewonder.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.files.bannersnack.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.files.bannersnack.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.overture.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.overture.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.komtrack.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.komtrack.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	track.effiliation.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.paypal.112.2o7.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tto2.traffictrack.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.traffective-tracking.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.traffective-tracking.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tracking.mindshare.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ec-track.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.yadro.ru [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.hightraffic.hugoboss.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	server.adform.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	server.adform.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.at.atwola.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adxvalue.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.zanox-affiliate.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.urbia.wwe-media.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	tracking.tchibo.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tribalfusion.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.c.atdmt.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.c.atdmt.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.clickfuse.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.youporn.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.youporn.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.lfstmedia.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	adserver1.mokono.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	edates.traffective-tracking.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	edates.traffective-tracking.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	edates.traffective-tracking.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	edates.traffective-tracking.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.aerlingus.122.2o7.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	oasc-eu1.247realmedia.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.zanox-affiliate.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.dyntracker.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	stat.dealtime.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.dealtime.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.lokalportal24de.112.2o7.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.nextag.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.nextag.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.nextag.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.nextag.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.nextag.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.nextag.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.mediabistro.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.w3counter.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	s0.2mdn.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.icompetence.122.2o7.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	statse.webtrendslive.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad1.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad4.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.nextag.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.bs.serving-sys.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.bs.serving-sys.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.dyntracker.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.statcounter.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adform.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	adserver.zeichensetzen.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.ads20.wwe-media.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.zanox.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.zanox.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.clickfuse.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ww251.smartadserver.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.fastclick.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad2.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	ad3.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	adfarm1.adition.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.unitymedia.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.unitymedia.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\MN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\43PUV1LI.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-FakeAV
	C:\PROGRAM FILES\WINRAR\DEFAULT.SFX
         


Alt 06.03.2012, 20:02   #21
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Trojaner "System Check" - letzte Schritte? - Standard

Trojaner "System Check" - letzte Schritte?



Sieht ok aus, da wurden nur Cookies gefunden. Die können weg. Und ein Fehlalarm war dabei.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ist das System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________
--> Trojaner "System Check" - letzte Schritte?

Alt 06.03.2012, 22:12   #22
wrimpus
 
Trojaner "System Check" - letzte Schritte? - Standard

Trojaner "System Check" - letzte Schritte?



Alles klar, vielen Dank!

Das System ist sonst wieder wunderbar in Ordnung (mein Desktop-Hintergrund ist weg, aber das ist egal). Empfiehlst du, die ganzen Scan-Programme nun wieder zu deinstallieren und kann ich die Logs etc. löschen?

Alt 07.03.2012, 00:24   #23
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Trojaner "System Check" - letzte Schritte? - Standard

Trojaner "System Check" - letzte Schritte?



Dann wären wir durch!

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 12.03.2012, 13:34   #24
wrimpus
 
Trojaner "System Check" - letzte Schritte? - Standard

Trojaner "System Check" - letzte Schritte?



etwas verspätet, aber nicht minder herzlich: Vielen, vielen Dank für die Hilfe!

Antwort

Themen zu Trojaner "System Check" - letzte Schritte?
check, desktop, entfern, eset-online, funde, hilfe!, laufe, laufen, leer, log, malwarebytes, scan, schritte, schwarz, system, system check, troja, trojaner, was tun, zunächst




Ähnliche Themen: Trojaner "System Check" - letzte Schritte?


  1. Trojaner " win32 skintrim kz" mit ESET Check gefunden
    Log-Analyse und Auswertung - 06.09.2013 (3)
  2. Avira hat Trojaner "TR/Rogue.KD.853855.1" gefunden und in Quarantäne verschoben --> Sind weitere Schritte notwendig?
    Log-Analyse und Auswertung - 25.02.2013 (11)
  3. Trojaner "System Check" deinstalliert - System sauber?
    Log-Analyse und Auswertung - 11.04.2012 (23)
  4. 'System Check' Virus, die nächsten Schritte?
    Plagegeister aller Art und deren Bekämpfung - 05.04.2012 (29)
  5. "System Check" - Virus, wie werde ich ihn wieder los
    Plagegeister aller Art und deren Bekämpfung - 04.04.2012 (23)
  6. "System Check" auch hier
    Plagegeister aller Art und deren Bekämpfung - 02.04.2012 (13)
  7. "System Check" Scareware
    Plagegeister aller Art und deren Bekämpfung - 31.03.2012 (17)
  8. "System-Check Virus" eingefangen, MAM schon durchgführt, wie gehts weiter?
    Log-Analyse und Auswertung - 27.03.2012 (34)
  9. "System Check" eingefangen und lässt sich nicht entfernen
    Plagegeister aller Art und deren Bekämpfung - 27.03.2012 (15)
  10. System Check - "Windows - Delayed Write Failed", schwarzer Bildschirm, Datenverlust?
    Log-Analyse und Auswertung - 26.03.2012 (12)
  11. Befall mit "System Check"
    Plagegeister aller Art und deren Bekämpfung - 21.03.2012 (21)
  12. Problem mit "System Check" Critical error
    Plagegeister aller Art und deren Bekämpfung - 16.03.2012 (9)
  13. ComboFix-Logfile nach "System Check"-Malware
    Log-Analyse und Auswertung - 03.03.2012 (5)
  14. Infiziert mit "System Check" - System wieder in Ordnung?
    Log-Analyse und Auswertung - 01.03.2012 (24)
  15. Virus "System-Check" hat mich erwischt
    Log-Analyse und Auswertung - 06.02.2012 (11)
  16. Onlinebanking-Trojaner: "Bitte Warten, prüfen wir die letzte Sitzung"
    Plagegeister aller Art und deren Bekämpfung - 19.09.2011 (1)
  17. "UFO-Hacker" nutzt letzte Rechtsmittel gegen Auslieferung an die USA
    Nachrichten - 04.12.2009 (0)

Zum Thema Trojaner "System Check" - letzte Schritte? - Hier der Log von GMER - OSAM folgt in Kürze ... GMER Logfile: Code: Alles auswählen Aufklappen ATTFilter GMER 1.0.15.15641 - hxxp://www.gmer.net Rootkit scan 2012-03-05 20:29:15 Windows 6.0.6001 Service Pack - Trojaner "System Check" - letzte Schritte?...
Archiv
Du betrachtest: Trojaner "System Check" - letzte Schritte? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.