Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter.

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 31.07.2012, 20:37   #31
Niels
 
sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter. - Standard

sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter.



sorry
Code:
ATTFilter
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-07-30 20:23:10
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD5000BPVT-00HXZT1 rev.01.01A01
Running: gmer.exe; Driver: C:\Users\JEALOU~1\AppData\Local\Temp\afroykog.sys


---- Kernel code sections - GMER 1.0.15 ----

.text           ntoskrnl.exe!ZwRollbackEnlistment + 1409                                                                                                   83040989 1 Byte  [06]
.text           ntoskrnl.exe!KiDispatchInterrupt + 5A2                                                                                                     830604E2 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}

---- User IAT/EAT - GMER 1.0.15 ----

IAT             C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[6104] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]    [751EFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT             C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[6104] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]     [751EFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT             C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[6104] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]   [751EFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT             C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[6104] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress]  [751EFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT             C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[6104] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress]   [751EFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                                                                     fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                                                                     rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                                                                     fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                                                                     rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device          \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0                                                                                                dvd43llh.sys (dvd43llh.sys/RIF)
Device          \Driver\atapi \Device\Ide\IdePort0                                                                                                         dvd43llh.sys (dvd43llh.sys/RIF)
Device          \Driver\atapi \Device\Ide\IdePort1                                                                                                         dvd43llh.sys (dvd43llh.sys/RIF)
Device          \Driver\atapi \Device\Ide\IdePort2                                                                                                         dvd43llh.sys (dvd43llh.sys/RIF)
Device          \Driver\atapi \Device\Ide\IdePort3                                                                                                         dvd43llh.sys (dvd43llh.sys/RIF)
Device          \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1                                                                                                dvd43llh.sys (dvd43llh.sys/RIF)

AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                                                                     fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                                                                     rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume4                                                                                                     fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume4                                                                                                     rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device          \Driver\ACPI_HAL \Device\0000005d                                                                                                          halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device          \Driver\BTHUSB \Device\0000008a                                                                                                            bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device          \Driver\BTHUSB \Device\0000008c                                                                                                            bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device          \Driver\VClone \Device\Scsi\VClone1                                                                                                        dvd43llh.sys (dvd43llh.sys/RIF)
Device          \Driver\VClone \Device\Scsi\VClone1Port4Path0Target0Lun0                                                                                   dvd43llh.sys (dvd43llh.sys/RIF)

---- Registry - GMER 1.0.15 ----

Reg             HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002269e02bd7                                                                
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04                                                           
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                                        C:\Program Files\Alcohol Soft\Alcohol 120\
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                        0
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                     0x21 0xE7 0x0F 0xF4 ...
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001                                                  
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                                               0x20 0x01 0x00 0x00 ...
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                                            0x5A 0x32 0xE2 0xE5 ...
Reg             HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002269e02bd7 (not active ControlSet)                                            
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)                                       
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                                            C:\Program Files\Alcohol Soft\Alcohol 120\
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                            0
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                         0x21 0xE7 0x0F 0xF4 ...
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)                              
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                                                   0x20 0x01 0x00 0x00 ...
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                                                0x5A 0x32 0xE2 0xE5 ...
Reg             HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32                                                          
Reg             HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel                                           Apartment
Reg             HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@                                                         C:\Windows\system32\OLE32.DLL
Reg             HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b                         0xE2 0x63 0x26 0xF1 ...
Reg             HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32                                                          
Reg             HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel                                           Apartment
Reg             HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@                                                         C:\Windows\system32\OLE32.DLL
Reg             HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b                         0x46 0x47 0x15 0xB0 ...
Reg             HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32                                                          
Reg             HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel                                           Apartment
Reg             HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@                                                         C:\Windows\system32\OLE32.DLL
Reg             HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016                         0x25 0xDA 0xEC 0x7E ...
Reg             HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32                                                          
Reg             HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel                                           Apartment
Reg             HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@                                                         C:\Windows\system32\OLE32.DLL
Reg             HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48                         0x3E 0x1E 0x9E 0xE0 ...
Reg             HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32                                                          
Reg             HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel                                           Apartment
Reg             HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@                                                         C:\Windows\system32\OLE32.DLL
Reg             HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472                         0xCD 0x44 0xCD 0xB9 ...
Reg             HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32                                                          
Reg             HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel                                           Apartment
Reg             HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@                                                         C:\Windows\system32\OLE32.DLL
Reg             HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d                         0xB0 0x18 0xED 0xA7 ...
Reg             HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32                                                          
Reg             HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel                                           Apartment
Reg             HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@                                                         C:\Windows\system32\OLE32.DLL
Reg             HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b                         0x97 0x20 0x4E 0x9A ...
Reg             HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32                                                          
Reg             HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel                                           Apartment
Reg             HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@                                                         C:\Windows\system32\OLE32.DLL
Reg             HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d                         0xAA 0x52 0xC6 0x00 ...
Reg             HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32                                                          
Reg             HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel                                           Apartment
Reg             HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@                                                         C:\Windows\system32\OLE32.DLL
Reg             HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3                         0x51 0xFA 0x6E 0x91 ...
Reg             HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32                                                          
Reg             HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel                                           Apartment
Reg             HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@                                                         C:\Windows\system32\OLE32.DLL
Reg             HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b                         0x37 0xA4 0xAA 0xC3 ...
Reg             HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32                                                          
Reg             HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel                                           Apartment
Reg             HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@                                                         C:\Windows\system32\OLE32.DLL
Reg             HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6                         0xF8 0x31 0x0F 0xA9 ...
Reg             HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32                                                          
Reg             HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel                                           Apartment
Reg             HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@                                                         C:\Windows\system32\OLE32.DLL
Reg             HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2                         0x6C 0x43 0x2D 0x1E ...

---- EOF - GMER 1.0.15 ----
         
Code:
ATTFilter
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 10:37:33 on 30.07.2012

OS: Windows 7  Service Pack 1 (Build 7601), 32-bit
Default Browser: Microsoft Corporation Internet Explorer 9.00.8112.16421

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"PCWizard.cpl" - "CPUID" - C:\Windows\system32\PCWizard.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"A2 Direct Disk Access Support Driver" (A2DDA) - "Emsi Software GmbH" - C:\Users\Jealous_Sound\Desktop\emsissoft\Run\a2ddax86.sys
"afroykog" (afroykog) - ? - C:\Users\JEALOU~1\AppData\Local\Temp\afroykog.sys  (Hidden registry entry, rootkit activity | File not found)
"catchme" (catchme) - ? - C:\Users\JEALOU~1\AppData\Local\Temp\catchme.sys  (File not found)
"cpuz135" (cpuz135) - "CPUID" - C:\Windows\system32\drivers\cpuz135_x32.sys
"dvd43llh" (dvd43llh) - "RIF" - C:\Windows\System32\DRIVERS\dvd43llh.sys
"ElbyCDIO Driver" (ElbyCDIO) - "Elaborate Bytes AG" - C:\Windows\System32\Drivers\ElbyCDIO.sys
"epmntdrv" (epmntdrv) - ? - C:\Windows\system32\epmntdrv.sys  (File found, but it contains no detailed information)
"EuGdiDrv" (EuGdiDrv) - ? - C:\Windows\system32\EuGdiDrv.sys  (File found, but it contains no detailed information)
"FssFltr" (fssfltr) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\fssfltr.sys
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"mbr" (mbr) - ? - C:\Users\JEALOU~1\AppData\Local\Temp\mbr.sys  (Hidden registry entry, rootkit activity | File not found)
"SANDRA" (SANDRA) - ? - D:\hardwaretest\SiSoftware Sandra Lite 2011.SP4c\WNt500x86\Sandra.sys  (File not found)
"SASDIFSV" (SASDIFSV) - "SUPERAdBlocker.com and SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
"SASKUTIL" (SASKUTIL) - "SUPERAdBlocker.com and SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
"Sentinel" (Sentinel) - ? - C:\Windows\System32\Drivers\SENTINEL.SYS

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} "Album Download IE Asynchronous Pluggable Protocol Interface" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
{3D9F03FA-7A94-11D3-BE81-0050048385D1} "Data Page Pluggable Protocol mso-offdap Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\Program Files\Windows Live\Messenger\msgrapp.dll
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Messenger\msgrapp.dll
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\Program Files\NVIDIA Corporation\Display\nvui.dll
{09A47860-11B0-4DA5-AFA5-26D86198A780} "EPP" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~1\shellext.dll
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - D:\iTunes\iTunesMiniPlayer.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office10\msohev.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL
{B7056B8E-4F99-44f8-8CBD-282390FE5428} "VirtualCloneDrive Shell Extension" - "Elaborate Bytes AG" - E:\7 Tools\VirtualCloneDrive\ElbyVCDShell.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{0563DB41-F538-4B37-A92D-4659049B7766} "WLMD Message Handler" - ? -   (File not found | COM-object registry key not found)
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{7530BFB8-7293-4D34-9923-61A11451AFC5} "OnlineScanner Control" - "ESET" - C:\PROGRA~1\ESET\ESETON~1\ONLINE~1.OCX / hxxp://download.eset.com/special/eos/OnlineScanner.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} "@C:\Program Files\Windows Live\Companion\companionlang.dll,-600" - "Microsoft Corporation" - C:\Program Files\Windows Live\Companion\companioncore.dll
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "@C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004" - "Microsoft Corporation" - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{8dcb7100-df86-4384-8842-8fa844297b3f} "Bing Bar" - "Microsoft Corporation." - C:\Program Files\Microsoft\BingBar\BingExt.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{d2ce3e00-f94a-4740-988e-03dc2f38c34f} "Bing Bar Helper" - "Microsoft Corporation." - C:\Program Files\Microsoft\BingBar\BingExt.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\ssv.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID Sign-in Helper" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{9FDDE16B-836F-4806-AB1F-1455CBEFF289} "Windows Live Messenger Companion Helper" - "Microsoft Corporation" - C:\Program Files\Windows Live\Companion\companioncore.dll

[LSA Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )-----
"Security Packages" - "Microsoft Corp." - C:\Windows\system32\livessp.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Dropbox.lnk" - "Dropbox, Inc." - C:\Users\Jealous_Sound\AppData\Roaming\Dropbox\bin\Dropbox.exe  (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Microsoft Office.lnk" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office10\OSA.EXE  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"AlcoholAutomount" - "Alcohol Soft Development Team" - "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
"AVMUSBFernanschluss" - "AVM Berlin" - "C:\Users\Jealous_Sound\AppData\Local\Apps\2.0\QWT9J1XB.8ME\Q9GDTMMP.7G0\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\AVMAutoStart.exe"
"ManyCam" - "ManyCam LLC" - "C:\Program Files\ManyCam\Bin\ManyCam.exe" /silent
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"dvd43" - ? - C:\Program Files\dvd43\dvd43_tray.exe
"iTunesHelper" - "Apple Inc." - "D:\iTunes\iTunesHelper.exe"
"MSC" - "Microsoft Corporation" - "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"PDFPrint" - "Geek Software GmbH" - C:\Program Files\PDF24\pdf24.exe
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"VirtualCloneDrive" - "Elaborate Bytes AG" - "E:\7 Tools\VirtualCloneDrive\VCDDaemon.exe" /s

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Nitro PDF Port Monitor" - "Nitro PDF Software" - C:\Windows\system32\nitrolocalmon2.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243" (NisSrv) - "Microsoft Corporation" - C:\Program Files\Microsoft Security Client\NisSrv.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Bing Bar Update Service" (BBSvc) - "Microsoft Corporation." - C:\Program Files\Microsoft\BingBar\BBSvc.EXE
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"Machine Debug Manager" (MDM) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Antimalware Service" (MsMpSvc) - "Microsoft Corporation" - C:\Program Files\Microsoft Security Client\MsMpEng.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
"NitroPDFReaderDriverCreatorReadSpool2" (NitroReaderDriverReadSpool2) - "Nitro PDF Software" - C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe
"NVIDIA Display Driver Service" (nvsvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe
"NVIDIA Update Service Daemon" (nvUpdatusService) - "NVIDIA Corporation" - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
"SAS Core Service" (!SASCORE) - "SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
"SeaPort" (SeaPort) - "Microsoft Corporation" - C:\Program Files\Microsoft\BingBar\SeaPort.EXE
"SiSoftware Deployment Agent Service" (SandraAgentSrv) - ? - D:\hardwaretest\SiSoftware Sandra Lite 2011.SP4c\RpcAgentSrv.exe  (File not found)
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files\Skype\Updater\Updater.exe
"StarWind AE Service" (StarWindServiceAE) - "Rocket Division Software" - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files\Common Files\Steam\SteamService.exe
"Windows Live Family Safety Service" (fsssvc) - "Microsoft Corporation" - C:\Program Files\Windows Live\Family Safety\fsssvc.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
"WindowsLive Local NSP" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
"WindowsLive NSP" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
         

Code:
ATTFilter
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-31 17:47:17
-----------------------------
17:47:17.476    OS Version: Windows 6.1.7601 Service Pack 1
17:47:17.476    Number of processors: 2 586 0x1706
17:47:17.476    ComputerName: SAMSUNG_MADRIL  UserName: Jealous_Sound
17:47:17.897    Initialize success
17:47:22.608    AVAST engine defs: 12073000
17:47:25.525    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
17:47:25.525    Disk 0 Vendor: WDC_WD5000BPVT-00HXZT1 01.01A01 Size: 476940MB BusType: 11
17:47:25.572    Disk 0 MBR read successfully
17:47:25.572    Disk 0 MBR scan
17:47:25.572    Disk 0 Windows 7 default MBR code
17:47:25.603    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
17:47:25.619    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       195000 MB offset 206848
17:47:25.650    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       205000 MB offset 399566848
17:47:25.681    Disk 0 Partition 4 00     07    HPFS/NTFS NTFS        76838 MB offset 819406848
17:47:25.728    Disk 0 scanning sectors +976771072
17:47:25.806    Disk 0 scanning C:\Windows\system32\drivers
17:47:42.654    Service scanning
17:48:06.522    Modules scanning
17:48:25.102    Disk 0 trace - called modules:
17:48:25.148    ntoskrnl.exe CLASSPNP.SYS disk.sys dvd43llh.sys ataport.SYS halmacpi.dll PCIIDEX.SYS msahci.sys 
17:48:25.148    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85e86ac8]
17:48:25.164    3 CLASSPNP.SYS[89e9159e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85da7908]
17:48:25.180    \Driver\atapi[0x85d72650] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> dvd43llh.sys[0x93f28b20]
17:48:25.195    Scan finished successfully
17:48:40.390    Disk 0 MBR has been saved successfully to "C:\Users\Jealous_Sound\Desktop\MBR.dat"
17:48:40.405    The log file has been saved successfully to "C:\Users\Jealous_Sound\Desktop\aswMBR.txt"
         

Alt 01.08.2012, 19:28   #32
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter. - Standard

sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter.



Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!
__________________

__________________

Alt 02.08.2012, 13:01   #33
Niels
 
sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter. - Standard

sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter.



alles klar!
Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.08.02.02

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Jealous_Sound :: SAMSUNG_MADRIL [Administrator]

Schutz: Deaktiviert

02.08.2012 09:03:39
mbam-log-2012-08-02 (09-03-39).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 622422
Laufzeit: 2 Stunde(n), 28 Minute(n), 57 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         
Code:
ATTFilter
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 08/02/2012 at 01:21 PM

Application Version : 5.0.1150

Core Rules Database Version : 8995
Trace Rules Database Version: 6807

Scan type       : Complete Scan
Total Scan Time : 01:44:33

Operating System Information
Windows 7 Professional 32-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 777
Memory threats detected   : 0
Registry items scanned    : 37750
Registry threats detected : 0
File items scanned        : 111475
File threats detected     : 224

Adware.Tracking Cookie
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\CCOYMSVT.txt [ /apmebf.com ]
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\CX7Q2TAV.txt [ /ad3.adfarm1.adition.com ]
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\I7OC6LB3.txt [ /invitemedia.com ]
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\J1M9YF26.txt [ /serving-sys.com ]
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\E56F9C6P.txt [ /ads.creative-serving.com ]
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\R4DUPPR3.txt [ /doubleclick.net ]
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\ODYJKCHJ.txt [ /adfarm1.adition.com ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\Q4YPZ9AS.txt [ Cookie:jealous_sound@webmasterplan.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\RL3JBIGV.txt [ Cookie:jealous_sound@track.effiliation.com/servlet/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\YIM26CS6.txt [ Cookie:jealous_sound@c.atdmt.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\GKXMKXI4.txt [ Cookie:jealous_sound@zanox-affiliate.de/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\W99DCPDC.txt [ Cookie:jealous_sound@ad2.adfarm1.adition.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\A1UKGF0M.txt [ Cookie:jealous_sound@atdmt.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\03OL5J0S.txt [ Cookie:jealous_sound@apmebf.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\AXPOZ0IW.txt [ Cookie:jealous_sound@ad3.adfarm1.adition.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\EGAMEKRI.txt [ Cookie:jealous_sound@ad.zanox.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\JMGZY9EW.txt [ Cookie:jealous_sound@invitemedia.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\HG5ILLUY.txt [ Cookie:jealous_sound@serving-sys.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\K3J9KQE7.txt [ Cookie:jealous_sound@smartadserver.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\7ZIH1ZVG.txt [ Cookie:jealous_sound@tracking.quisma.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\83BF7TN9.txt [ Cookie:jealous_sound@bs.serving-sys.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\QTW613ZT.txt [ Cookie:jealous_sound@tomtailor.dyntracker.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\MM928XIT.txt [ Cookie:jealous_sound@doubleclick.net/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\5YGRTXSD.txt [ Cookie:jealous_sound@zanox.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\0BGOP1CY.txt [ Cookie:jealous_sound@adfarm1.adition.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\JJQAC1L7.txt [ Cookie:jealous_sound@amazon-adsystem.com/ ]
	C:\USERS\JEALOUS_SOUND\Cookies\CCOYMSVT.txt [ Cookie:jealous_sound@apmebf.com/ ]
	C:\USERS\JEALOUS_SOUND\Cookies\CX7Q2TAV.txt [ Cookie:jealous_sound@ad3.adfarm1.adition.com/ ]
	C:\USERS\JEALOUS_SOUND\Cookies\I7OC6LB3.txt [ Cookie:jealous_sound@invitemedia.com/ ]
	C:\USERS\JEALOUS_SOUND\Cookies\J1M9YF26.txt [ Cookie:jealous_sound@serving-sys.com/ ]
	C:\USERS\JEALOUS_SOUND\Cookies\R4DUPPR3.txt [ Cookie:jealous_sound@doubleclick.net/ ]
	C:\USERS\JEALOUS_SOUND\Cookies\ODYJKCHJ.txt [ Cookie:jealous_sound@adfarm1.adition.com/ ]
	core.saymedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9JES5EXY ]
	media.mtvnservices.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9JES5EXY ]
	secure-us.imrworldwide.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9JES5EXY ]
	track.webgains.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9JES5EXY ]
	.adbrite.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	wstat.wibiya.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.questionablecontent.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adserver.twitpic.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.ru4.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.conrad.122.2o7.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	partners.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adserver1.mokono.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	mediathek.daserste.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.statcounter.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.xiti.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.nakedsecurity.sophos.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.c1.atdmt.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.kontera.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.statcounter.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adserver.bremen.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adform.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tracker.vinsight.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	www.mediamarkt.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adserver.adtechus.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.saymedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	stats.computecmedia.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.dyntracker.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad4.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad3.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adserver.doccheck.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.dyntracker.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	www.zanox-affiliate.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.clickfuse.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	accounts.google.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	tomtailor.dyntracker.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.klima-media.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.zanox-affiliate.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.flagcounter.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.dealtime.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	stat.dealtime.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tribalfusion.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.zanox.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adviva.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.zanox.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	teufel-media.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.fastclick.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ww251.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad2.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
         
__________________

Alt 03.08.2012, 12:59   #34
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter. - Standard

sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter.



Code:
ATTFilter
UAC On - Limited User
         
Wie hast du SUPERAntiSpyware gestartet? Einfach per Doppelklick?
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 05.08.2012, 17:13   #35
Niels
 
sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter. - Standard

sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter.



Eigentlich hab ich immer drauf geachtet als Administrator auszuführen. Ich habe es Sicherheitshalber nochmal durchlaufen lassen (als administrator) und im logfile steht dasselbe wieder:

Code:
ATTFilter
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 08/05/2012 at 02:35 PM

Application Version : 5.0.1150

Core Rules Database Version : 8995
Trace Rules Database Version: 6807

Scan type       : Complete Scan
Total Scan Time : 01:44:39

Operating System Information
Windows 7 Professional 32-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 781
Memory threats detected   : 0
Registry items scanned    : 37756
Registry threats detected : 0
File items scanned        : 111840
File threats detected     : 257

Adware.Tracking Cookie
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\CCOYMSVT.txt [ /apmebf.com ]
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\UF28AD1E.txt [ /ad3.adfarm1.adition.com ]
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\I7OC6LB3.txt [ /invitemedia.com ]
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\J1M9YF26.txt [ /serving-sys.com ]
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\E56F9C6P.txt [ /ads.creative-serving.com ]
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\ZRJP5D5O.txt [ /doubleclick.net ]
	C:\Users\Jealous_Sound\AppData\Roaming\Microsoft\Windows\Cookies\4E1NP0PO.txt [ /adfarm1.adition.com ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\Q4YPZ9AS.txt [ Cookie:jealous_sound@webmasterplan.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\RL3JBIGV.txt [ Cookie:jealous_sound@track.effiliation.com/servlet/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\YIM26CS6.txt [ Cookie:jealous_sound@c.atdmt.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\GKXMKXI4.txt [ Cookie:jealous_sound@zanox-affiliate.de/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\W99DCPDC.txt [ Cookie:jealous_sound@ad2.adfarm1.adition.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\A1UKGF0M.txt [ Cookie:jealous_sound@atdmt.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\03OL5J0S.txt [ Cookie:jealous_sound@apmebf.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\AXPOZ0IW.txt [ Cookie:jealous_sound@ad3.adfarm1.adition.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\EGAMEKRI.txt [ Cookie:jealous_sound@ad.zanox.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\JMGZY9EW.txt [ Cookie:jealous_sound@invitemedia.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\HG5ILLUY.txt [ Cookie:jealous_sound@serving-sys.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\K3J9KQE7.txt [ Cookie:jealous_sound@smartadserver.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\7ZIH1ZVG.txt [ Cookie:jealous_sound@tracking.quisma.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\83BF7TN9.txt [ Cookie:jealous_sound@bs.serving-sys.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\QTW613ZT.txt [ Cookie:jealous_sound@tomtailor.dyntracker.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\MM928XIT.txt [ Cookie:jealous_sound@doubleclick.net/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\5YGRTXSD.txt [ Cookie:jealous_sound@zanox.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\0BGOP1CY.txt [ Cookie:jealous_sound@adfarm1.adition.com/ ]
	C:\USERS\JEALOUS_SOUND\AppData\Roaming\Microsoft\Windows\Cookies\Low\JJQAC1L7.txt [ Cookie:jealous_sound@amazon-adsystem.com/ ]
	C:\USERS\JEALOUS_SOUND\Cookies\CCOYMSVT.txt [ Cookie:jealous_sound@apmebf.com/ ]
	C:\USERS\JEALOUS_SOUND\Cookies\UF28AD1E.txt [ Cookie:jealous_sound@ad3.adfarm1.adition.com/ ]
	C:\USERS\JEALOUS_SOUND\Cookies\I7OC6LB3.txt [ Cookie:jealous_sound@invitemedia.com/ ]
	C:\USERS\JEALOUS_SOUND\Cookies\J1M9YF26.txt [ Cookie:jealous_sound@serving-sys.com/ ]
	C:\USERS\JEALOUS_SOUND\Cookies\ZRJP5D5O.txt [ Cookie:jealous_sound@doubleclick.net/ ]
	C:\USERS\JEALOUS_SOUND\Cookies\4E1NP0PO.txt [ Cookie:jealous_sound@adfarm1.adition.com/ ]
	core.saymedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9JES5EXY ]
	media.mtvnservices.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9JES5EXY ]
	secure-us.imrworldwide.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9JES5EXY ]
	track.webgains.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9JES5EXY ]
	.adbrite.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	wstat.wibiya.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.questionablecontent.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adserver.twitpic.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.ru4.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.conrad.122.2o7.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	partners.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adserver1.mokono.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	mediathek.daserste.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.statcounter.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.xiti.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.nakedsecurity.sophos.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.c1.atdmt.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.kontera.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adserver.bremen.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adform.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tracker.vinsight.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	www.mediamarkt.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adserver.adtechus.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.saymedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	stats.computecmedia.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.dyntracker.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad4.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adserver.doccheck.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	tomtailor.dyntracker.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.klima-media.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.flagcounter.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.dealtime.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	stat.dealtime.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adviva.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	teufel-media.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.fastclick.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	stats.computecmedia.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	accounts.youtube.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	accounts.youtube.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	accounts.youtube.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad3.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ww251.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	accounts.youtube.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	accounts.youtube.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	accounts.youtube.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	accounts.youtube.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	accounts.youtube.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	accounts.google.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad1.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	insight.torbit.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.unitymedia.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.unitymedia.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tribalfusion.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.zanox.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.zanox.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.yieldmanager.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.statcounter.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.zanox-affiliate.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad.dyntracker.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	www.zanox-affiliate.de [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	ad2.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.mmstat.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\JEALOUS_SOUND\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3ZNYJC2Z.DEFAULT\COOKIES.SQLITE ]
         


Alt 05.08.2012, 17:36   #36
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter. - Standard

sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter.



Ja, dann ist das ein Bug in SUPERAntiSpyware aber halb so wild

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________
--> sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter.

Alt 06.08.2012, 16:06   #37
Niels
 
sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter. - Standard

sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter.



Hi!
Zunächst mal: Ein riesengroßes Dankeschön für deine unermüdliche, immer freundliche und sachliche Hilfe bei meinem Problem!
Dadurch, dass ich den Rechner nicht neu aufsetzen musst hast du mir wirklich einen großen Gefallen getan!

Mein Notebook verhält sich jetzt wieder normal.

Danke auch für die Tipps zu den Cookies. Ich werde mir das mit den Host-Files mal anschauen. Bzw. erstmal zwei Browser verwenden.

Alt 06.08.2012, 20:55   #38
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter. - Standard

sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter.



Dann wären wir durch!

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => http://www.adobe.com/software/flash/about/
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.
__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter.
automatisch, automatische, autostart, browser, commandozeile, down, e-mail, internetbrowser, kritischer fehler, langsamer, lizenz, logfiles, microsoft, min, notebook, rechner, rum, runterfahren, scan, security, shutdown, sich automatisch, sirefef.ah, sirefef.r, software, system, tan, virenscanner, win, win7, windows 7 32bit




Ähnliche Themen: sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter.


  1. Rechner fährt alleine hoch und runter & Trojan.Generic & verschiedene HEUR/QVM wurde gefunden
    Plagegeister aller Art und deren Bekämpfung - 31.10.2014 (13)
  2. Trojaner TR/Sirefef.BC.57, TR/Sirefef.AG.9, TR/ATRAPS.Gen2, TR/Necurs.A.71 und SpyHunter 4 auf Rechner
    Log-Analyse und Auswertung - 07.05.2013 (7)
  3. Trojaner Sirefef.AG.9 u. Sirefef.AL.50 in C:\$Recycle.Bin\, Vista-Sicherheitscenter u. Firewall nach anschl. VistaUpdate nicht mehr startbar
    Plagegeister aller Art und deren Bekämpfung - 06.03.2013 (41)
  4. Sirefef-A und Sirefef.mc Virenfund - eigenständiges Öffnen von Internetseiten
    Plagegeister aller Art und deren Bekämpfung - 12.11.2012 (9)
  5. Trojaner eingefangen - Sirefef-A/Sirefef-AHF/BitCoinMiner-U/Malware-gen
    Log-Analyse und Auswertung - 31.08.2012 (27)
  6. Win64/Sirefef.w - Sirefef.ab und Sirefef.M eingefangen
    Plagegeister aller Art und deren Bekämpfung - 14.08.2012 (29)
  7. Virus/Trojaner: Win64/sirefef.A ; Win64/sirefef.AB ; Win64/sirefef.W ; Auto-Neustart nach 1 Minute
    Plagegeister aller Art und deren Bekämpfung - 13.08.2012 (18)
  8. win 32:Sirefef-AO und Malware.gen, win64:Sirefef-A gefunden von avast!
    Log-Analyse und Auswertung - 11.08.2012 (1)
  9. Trojana:Win32/Sirefef.R und Sirefef.AH kann nicht entfernt werden
    Plagegeister aller Art und deren Bekämpfung - 17.07.2012 (13)
  10. Win7/64: Sirefef.b, .w und .y gefunden, Teilerfolg schon erzielt
    Plagegeister aller Art und deren Bekämpfung - 06.07.2012 (21)
  11. Trojaner: Sirefef.X / Sirefef.E / Conedex.A und Exploit: JS/Blacole.FF
    Plagegeister aller Art und deren Bekämpfung - 13.06.2012 (37)
  12. Win64:Sirefef-A (Trj) und Win32:Sirefef-AO (Rtk) eingefangen
    Log-Analyse und Auswertung - 10.06.2012 (14)
  13. Trojan:Win64/Sirefef.K + .../Sirefef.D + .../Sirefef.E
    Log-Analyse und Auswertung - 13.01.2012 (15)
  14. Trojan:Win64/Sirefef.K, Sirefef.E und Sirefef.D kommen immer wieder
    Plagegeister aller Art und deren Bekämpfung - 04.01.2012 (1)
  15. Trojan:Win64/Sirefef.K & Sirefef.D & Sirefef.E
    Log-Analyse und Auswertung - 02.01.2012 (6)
  16. Flacor.dat - Rechner fährt automatisch binnen 30 Sekunden runter
    Antiviren-, Firewall- und andere Schutzprogramme - 03.05.2010 (6)
  17. Rechner fährt automatisch binnen 30 Sekunden runter
    Antiviren-, Firewall- und andere Schutzprogramme - 29.04.2010 (1)

Zum Thema sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter. - sorry Code: Alles auswählen Aufklappen ATTFilter GMER 1.0.15.15641 - hxxp://www.gmer.net Rootkit scan 2012-07-30 20:23:10 Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD5000BPVT-00HXZT1 rev.01.01A01 Running: gmer.exe; Driver: C:\Users\JEALOU~1\AppData\Local\Temp\afroykog.sys ---- Kernel - sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter....
Archiv
Du betrachtest: sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter. auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.