Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert (https://www.trojaner-board.de/111463-achtung-sicherheitsgruenden-wurde-windowssystem-blockiert.html)

cosinus 17.03.2012 14:26

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

offliNe. 18.03.2012 14:33

Superantispy log

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 03/18/2012 at 02:20 PM

Application Version : 5.0.1146

Core Rules Database Version : 8347
Trace Rules Database Version: 6159

Scan type      : Complete Scan
Total Scan Time : 01:20:00

Operating System Information
Windows Vista Home Premium 64-bit, Service Pack 2 (Build 6.00.6002)
UAC Off - Administrator

Memory items scanned      : 474
Memory threats detected  : 0
Registry items scanned    : 63319
Registry threats detected : 0
File items scanned        : 272755
File threats detected    : 643

Adware.Tracking Cookie
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@2o7[2].txt [ /2o7 ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@4stats[1].txt [ /4stats ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@a2.adserver01[2].txt [ /a2.adserver01 ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@ad.ad-srv[2].txt [ /ad.ad-srv ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@ad.adnet[2].txt [ /ad.adnet ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@ad.yieldmanager[1].txt [ /ad.yieldmanager ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@ad.yieldmanager[2].txt [ /ad.yieldmanager ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@ad.zanox[2].txt [ /ad.zanox ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@ad3.adfarm1.adition[2].txt [ /ad3.adfarm1.adition ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@adbrite[2].txt [ /adbrite ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@adbrite[3].txt [ /adbrite ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@adfarm1.adition[1].txt [ /adfarm1.adition ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@adform[1].txt [ /adform ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@ads.adshopping[2].txt [ /ads.adshopping ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@ads.jinkads[1].txt [ /ads.jinkads ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@ads.jinkads[2].txt [ /ads.jinkads ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@adserver.71i[1].txt [ /adserver.71i ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@adserver.terahost[2].txt [ /adserver.terahost ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@adsrv.admediate[1].txt [ /adsrv.admediate ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@adsrv.admediate[3].txt [ /adsrv.admediate ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@adtech[1].txt [ /adtech ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@advertising[1].txt [ /advertising ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@advertising[3].txt [ /advertising ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@adx.chip[1].txt [ /adx.chip ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@adxpose[1].txt [ /adxpose ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@apmebf[1].txt [ /apmebf ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@apmebf[2].txt [ /apmebf ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@ar.atwola[2].txt [ /ar.atwola ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@at.atwola[1].txt [ /at.atwola ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@at.atwola[3].txt [ /at.atwola ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@atdmt[1].txt [ /atdmt ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@atwola[1].txt [ /atwola ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@atwola[3].txt [ /atwola ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@bs.serving-sys[2].txt [ /bs.serving-sys ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@casalemedia[1].txt [ /casalemedia ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@cdn.at.atwola[1].txt [ /cdn.at.atwola ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@cgm.adbureau[2].txt [ /cgm.adbureau ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@clicksor[2].txt [ /clicksor ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@collective-media[2].txt [ /collective-media ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@content.yieldmanager[1].txt [ /content.yieldmanager ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@content.yieldmanager[2].txt [ /content.yieldmanager ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@content.yieldmanager[3].txt [ /content.yieldmanager ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@doubleclick[1].txt [ /doubleclick ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@eas.apm.emediate[2].txt [ /eas.apm.emediate ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@eporner[1].txt [ /eporner ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@eporner[2].txt [ /eporner ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@ero-advertising[1].txt [ /ero-advertising ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@ero-advertising[2].txt [ /ero-advertising ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@euros4click[1].txt [ /euros4click ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@explore.trackmania[2].txt [ /explore.trackmania ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@fastclick[1].txt [ /fastclick ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@fl01.ct2.comclick[2].txt [ /fl01.ct2.comclick ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@gamecenter.oberon-media[2].txt [ /gamecenter.oberon-media ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@hdporn[2].txt [ /hdporn ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@himedia.individuad[2].txt [ /himedia.individuad ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@hlstatsx[2].txt [ /hlstatsx ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@im.banner.t-online[2].txt [ /im.banner.t-online ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@imrworldwide[2].txt [ /imrworldwide ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@infectedgaming.de.hlstatsx[1].txt [ /infectedgaming.de.hlstatsx ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@invitemedia[1].txt [ /invitemedia ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@maniahome.trackmania[2].txt [ /maniahome.trackmania ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@maniapub.trackmania[1].txt [ /maniapub.trackmania ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@media.funpic[1].txt [ /media.funpic ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@media6degrees[1].txt [ /media6degrees ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@mediaplex[1].txt [ /mediaplex ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@msnportal.112.2o7[1].txt [ /msnportal.112.2o7 ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@myroitracking[1].txt [ /myroitracking ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@oberon-media[2].txt [ /oberon-media ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@pornvisit[1].txt [ /pornvisit ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@qlocstats[2].txt [ /qlocstats ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@rotator.adjuggler[1].txt [ /rotator.adjuggler ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@rotator.adjuggler[2].txt [ /rotator.adjuggler ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@server.cpmstar[1].txt [ /server.cpmstar ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@serving-sys[1].txt [ /serving-sys ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@serving-sys[2].txt [ /serving-sys ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@sevenoneintermedia.112.2o7[1].txt [ /sevenoneintermedia.112.2o7 ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@sevenoneintermedia.112.2o7[2].txt [ /sevenoneintermedia.112.2o7 ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@slovenia-surf.hlstatsx[1].txt [ /slovenia-surf.hlstatsx ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@specificclick[2].txt [ /specificclick ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@specificclick[3].txt [ /specificclick ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@statcounter[1].txt [ /statcounter ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@statcounter[3].txt [ /statcounter ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@tacoda[2].txt [ /tacoda ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@tacoda[3].txt [ /tacoda ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@toplist[1].txt [ /toplist ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@track.adform[2].txt [ /track.adform ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@tracking.hannoversche[1].txt [ /tracking.hannoversche ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@tracking.mindshare[2].txt [ /tracking.mindshare ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@tracking.quisma[2].txt [ /tracking.quisma ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@tradedoubler[2].txt [ /tradedoubler ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@trafficholder[1].txt [ /trafficholder ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@traffictrack[1].txt [ /traffictrack ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@traffictrack[3].txt [ /traffictrack ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@tribalfusion[1].txt [ /tribalfusion ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@tto2.traffictrack[1].txt [ /tto2.traffictrack ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@unitymedia[1].txt [ /unitymedia ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@webmasterplan[2].txt [ /webmasterplan ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@windowsmedia[2].txt [ /windowsmedia ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@ww251.smartadserver[1].txt [ /ww251.smartadserver ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.eporner[1].txt [ /www.eporner ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.eporner[2].txt [ /www.eporner ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.etracker[2].txt [ /www.etracker ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.googleadservices[1].txt [ /www.googleadservices ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.hdporn[1].txt [ /www.hdporn ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.windowsmedia[2].txt [ /www.windowsmedia ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.zanox-affiliate[2].txt [ /www.zanox-affiliate ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@xiti[1].txt [ /xiti ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@xiti[2].txt [ /xiti ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@yadro[1].txt [ /yadro ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@yieldmanager[1].txt [ /yieldmanager ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@zanox-affiliate[2].txt [ /zanox-affiliate ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@zanox[2].txt [ /zanox ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@zbox.zanox[1].txt [ /zbox.zanox ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\4LPH6GTS.txt [ /dyntracker.com ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\RTJ1N9C2.txt [ /im.banner.t-online.de ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\43KG8DSV.txt [ /adfarm1.adition.com ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\ON22SKCA.txt [ /adviva.net ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\X5XMQI6W.txt [ /atdmt.com ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\QGRNIPG4.txt [ /ad.zanox.com ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\H908OVMV.txt [ /webmasterplan.com ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\MITXU0DU.txt [ /zanox.com ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\JYUZMAMV.txt [ /tracking.quisma.com ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\FXOSH3JC.txt [ /doubleclick.net ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\591DULBS.txt [ /ad.360yield.com ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\GOAMC173.txt [ /smartadserver.com ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\L5VU3S0N.txt [ /ad4.adfarm1.adition.com ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\PSN8BDSA.txt [ /mediaplex.com ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\WHP0VHHJ.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\4ZTUJGNK.txt [ /tradedoubler.com ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\B9NMH548.txt [ /adtech.de ]
        C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\1SYWZ7VV.txt [ /zanox-affiliate.de ]
        C:\USERS\ADMIN\AppData\Roaming\Microsoft\Windows\Cookies\X1DFIQPF.txt [ Cookie:admin@clkads.com/adServe/banners ]
        C:\USERS\ADMIN\Cookies\admin@ad3.adfarm1.adition[2].txt [ Cookie:admin@ad3.adfarm1.adition.com/ ]
        C:\USERS\ADMIN\Cookies\admin@fl01.ct2.comclick[2].txt [ Cookie:admin@fl01.ct2.comclick.com/ ]
        C:\USERS\ADMIN\Cookies\admin@yadro[1].txt [ Cookie:admin@yadro.ru/ ]
        C:\USERS\ADMIN\Cookies\43KG8DSV.txt [ Cookie:admin@adfarm1.adition.com/ ]
        C:\USERS\ADMIN\Cookies\admin@adform[1].txt [ Cookie:admin@adform.net/ ]
        C:\USERS\ADMIN\Cookies\admin@rotator.adjuggler[2].txt [ Cookie:admin@rotator.adjuggler.com/ ]
        C:\USERS\ADMIN\Cookies\admin@advertising[3].txt [ Cookie:admin@advertising.com/ ]
        C:\USERS\ADMIN\Cookies\ON22SKCA.txt [ Cookie:admin@adviva.net/ ]
        C:\USERS\ADMIN\Cookies\admin@maniahome.trackmania[2].txt [ Cookie:admin@maniahome.trackmania.com/ ]
        C:\USERS\ADMIN\Cookies\admin@atwola[3].txt [ Cookie:admin@atwola.com/ ]
        C:\USERS\ADMIN\Cookies\QGRNIPG4.txt [ Cookie:admin@ad.zanox.com/ ]
        C:\USERS\ADMIN\Cookies\MITXU0DU.txt [ Cookie:admin@zanox.com/ ]
        C:\USERS\ADMIN\Cookies\admin@media6degrees[1].txt [ Cookie:admin@media6degrees.com/ ]
        C:\USERS\ADMIN\Cookies\admin@xiti[2].txt [ Cookie:admin@xiti.com/ ]
        C:\USERS\ADMIN\Cookies\JYUZMAMV.txt [ Cookie:admin@tracking.quisma.com/ ]
        C:\USERS\ADMIN\Cookies\admin@adbrite[3].txt [ Cookie:admin@adbrite.com/ ]
        C:\USERS\ADMIN\Cookies\FXOSH3JC.txt [ Cookie:admin@doubleclick.net/ ]
        C:\USERS\ADMIN\Cookies\admin@content.yieldmanager[1].txt [ Cookie:admin@content.yieldmanager.com/ ]
        C:\USERS\ADMIN\Cookies\admin@www.googleadservices[1].txt [ Cookie:admin@www.googleadservices.com/pagead/conversion/1066798348/ ]
        C:\USERS\ADMIN\Cookies\admin@at.atwola[3].txt [ Cookie:admin@at.atwola.com/ ]
        C:\USERS\ADMIN\Cookies\admin@invitemedia[1].txt [ Cookie:admin@invitemedia.com/ ]
        C:\USERS\ADMIN\Cookies\admin@cdn.at.atwola[1].txt [ Cookie:admin@cdn.at.atwola.com/ ]
        C:\USERS\ADMIN\Cookies\admin@explore.trackmania[2].txt [ Cookie:admin@explore.trackmania.com/ ]
        C:\USERS\ADMIN\Cookies\admin@adx.chip[1].txt [ Cookie:admin@adx.chip.de/ ]
        C:\USERS\ADMIN\Cookies\admin@collective-media[2].txt [ Cookie:admin@collective-media.net/ ]
        C:\USERS\ADMIN\Cookies\admin@tracking.hannoversche[1].txt [ Cookie:admin@tracking.hannoversche.de/ ]
        C:\USERS\ADMIN\Cookies\admin@yieldmanager[1].txt [ Cookie:admin@yieldmanager.net/ ]
        C:\USERS\ADMIN\Cookies\admin@serving-sys[1].txt [ Cookie:admin@serving-sys.com/ ]
        C:\USERS\ADMIN\Cookies\admin@www.hdporn[1].txt [ Cookie:admin@www.hdporn.com/ ]
        C:\USERS\ADMIN\Cookies\admin@ero-advertising[1].txt [ Cookie:admin@ero-advertising.com/ ]
        C:\USERS\ADMIN\Cookies\X1DFIQPF.txt [ Cookie:admin@clkads.com/adServe/banners ]
        C:\USERS\ADMIN\Cookies\GOAMC173.txt [ Cookie:admin@smartadserver.com/ ]
        C:\USERS\ADMIN\Cookies\admin@adxpose[1].txt [ Cookie:admin@adxpose.com/ ]
        C:\USERS\ADMIN\Cookies\admin@www.eporner[2].txt [ Cookie:admin@www.eporner.com/ ]
        C:\USERS\ADMIN\Cookies\PSN8BDSA.txt [ Cookie:admin@mediaplex.com/ ]
        C:\USERS\ADMIN\Cookies\admin@eporner[1].txt [ Cookie:admin@eporner.com/ ]
        C:\USERS\ADMIN\Cookies\admin@hdporn[2].txt [ Cookie:admin@hdporn.com/ ]
        C:\USERS\ADMIN\Cookies\admin@track.adform[2].txt [ Cookie:admin@track.adform.net/ ]
        C:\USERS\ADMIN\Cookies\WHP0VHHJ.txt [ Cookie:admin@ad2.adfarm1.adition.com/ ]
        C:\USERS\ADMIN\Cookies\admin@msnportal.112.2o7[1].txt [ Cookie:admin@msnportal.112.2o7.net/ ]
        C:\USERS\ADMIN\Cookies\admin@adsrv.admediate[3].txt [ Cookie:admin@adsrv.admediate.net/ ]
        C:\USERS\ADMIN\Cookies\admin@ad.yieldmanager[2].txt [ Cookie:admin@ad.yieldmanager.com/ ]
        C:\USERS\ADMIN\Cookies\admin@apmebf[1].txt [ Cookie:admin@apmebf.com/ ]
        C:\USERS\ADMIN\Cookies\admin@ad.adnet[2].txt [ Cookie:admin@ad.adnet.de/ ]
        C:\USERS\ADMIN\Cookies\B9NMH548.txt [ Cookie:admin@adtech.de/ ]
        C:\USERS\ADMIN\Cookies\1SYWZ7VV.txt [ Cookie:admin@zanox-affiliate.de/ ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .msnportal.112.2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.sexkino.to [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.sexkino.to [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .elitepornos.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        elitepornos.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        elitepornos.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        elitepornos.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        elitepornos.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        elitepornos.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        elitepornos.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        elitepornos.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        elitepornos.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        in.getclicky.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .trafficrevenue.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornkino.to [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .trekmedia.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .microsoftwlsearchcrm.112.2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.vagosex.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornturbo.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornturbo.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornturbo.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornturbo.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .gostats.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.cheapfinders.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .naked.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .autoscout24.112.2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.pornturbo.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        vagosex.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .playporn.to [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .playporn.to [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .mediafire.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        s06.flagcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        xxxpornpasswods.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        api.skyscanner.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        api.skyscanner.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .account.live.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .account.live.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.cheapfinders.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .4fuckr.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornprosnetwork.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornproslive.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.elitepvpers.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.elitepvpers.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.elitepvpers.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .elitepvpers.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .elitepvpers.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornoobs.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornoobs.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.supersexywallpapers.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.supersexywallpapers.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.supersexywallpapers.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.supersexywallpapers.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.supersexywallpapers.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.supersexywallpapers.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.supersexywallpapers.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.supersexywallpapers.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .naked.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .naked.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornmegapass.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornmegapass.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornmegapass.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        members.veronicaraynexxx.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.mesohorny.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .nieuwsexcontact.nl [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .nieuwsexcontact.nl [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .sexyandfunny.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .sexyandfunny.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        elitepornos.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornkino.eu [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornkino.eu [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornkino.eu [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.freerunescapeaccounts.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.freerunescapeaccounts.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .account.frogster-online.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .cz8.clickzs.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .cz8.clickzs.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .freesexdoor.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .freesexdoor.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .freesexdoor.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .ich-steh-auf-sex.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .ich-steh-auf-sex.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.vagosex.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .sixapart.112.2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .count.xhit.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .gostats.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .counter-strike.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .counter-strike.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .cmp.112.2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornturbo.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornturbo.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornturbo.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornoteufel.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornoteufel.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        hodenmedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.sexynudegirlfriends.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .toplist.cz [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        members.hornyboy.tv [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        members.hornyboy.tv [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .fucktube.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .fucktube.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .fucktube.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .tripod.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .gotgayporn.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .gotgayporn.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .sexhoundlinks.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .sexhoundlinks.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .fucktube.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .fucktube.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .gayfinder.tv [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .gayfinder.tv [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.gayfinder.tv [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        hoteuroteens.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adult-empire.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adult-empire.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .advertstream.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.biz [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        trackstatsnow.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        baresexymoms.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .sexshop-dildo-king.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .sexshop-dildo-king.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.cheap-traffic.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.cheap-traffic.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.cheap-traffic.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.cheap-traffic.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.cheap-traffic.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.cheap-traffic.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.cheap-traffic.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.cheap-traffic.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        p386t1s4921729.kronos.bravenetmedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .mediatraffic.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .clicksor.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .dealtime.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        stat.dealtime.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        stat.onestat.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        stat.onestat.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.naughtyfuckerz.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www8.addfreestats.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .getclicky.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .static.getclicky.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.cpcadnet.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .4stats.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .4stats.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .4stats.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .4stats.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .toplist.sk [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.pornwarez.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.pornwarez.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.pornwarez.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.pornwarez.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.pornwarez.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.pornwarez.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.pornwarez.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.pornwarez.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .atomicwarez.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .cdn.atomicwarez.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .warez-load.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .warez-load.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        warez-load.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.pornstar.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornstar.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        s04.flagcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornxplorer.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornxplorer.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.eporner.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        click.payserve.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornkino.to [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornkino.eu [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornkino.eu [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornkino.eu [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        trackstatsnow.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.pixeltrack66.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.pixeltrack66.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        xml.trafficengine.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .trafficengine.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornstar.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.pornstar.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .cz6.clickzs.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .cz6.clickzs.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornpros.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wgkignd5ebp.stats.esomniture.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .cdate.122.2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        dc.tremormedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .vagosex.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .vagosex.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .bookofsex.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .bookofsex.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .bookofsex.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .bookofsex.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .bookofsex.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .bookofsex.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .de.partypoker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.warez-bb.org [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .warez-bb.org [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .warez-bb.org [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.warez.cc [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .warez.cc [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .warez.cc [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        ox-d.yadomedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .ddl-warez.in [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .ddl-warez.in [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        adserver.adreactor.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .fuckfiesta.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.biz [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.biz [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.visit-tracker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .eporner.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .eporner.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .gametracker.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        adultxxxpornstars.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultrental.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultrental.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultrental.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .gay.adultrental.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .gay.adultrental.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultrental.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultrental.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.adultrental.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultrental.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adultrental.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .members.pornpros.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .members.pornpros.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .mediafire.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .mediafire.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .cz5.clickzs.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .cz5.clickzs.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornrush.org [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornrush.org [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornrush.org [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornrush.org [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        xxxpornpasswods.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adscendmedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .adscendmedia.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .toplist.eu [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .warezun.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .warezun.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .warezun.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .warezun.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .crackingforum.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .crackingforum.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .crackingforum.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .crackingforum.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .crackingforum.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        trackstatsnow.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .myroitracking.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .clickbank.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .clickbank.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.freerunescapeaccounts.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.freerunescapeaccounts.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.freerunescapeaccounts.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.freerunescapeaccounts.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.freerunescapeaccounts.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.freerunescapeaccounts.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .userporn.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .userporn.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornkino.eu [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornkino.eu [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornkino.eu [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornkino.eu [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        pornkino.eu [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .4fuckr.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .4fuckr.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .sexkino.to [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .sexkino.to [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .vodafonegroup.122.2o7.net [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornpros.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .pornpros.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]
        .gostats.de [ C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-Malintent
        C:\PROGRAM FILES (X86)\WINRAR\DEFAULT.SFX


MBAm Log

Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.17.06

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 8.0.6001.19190
Admin :: ADMIN-PC [Administrator]

18.03.2012 11:20:27
mbam-log-2012-03-18 (11-20-27).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 389646
Laufzeit: 39 Minute(n), 59 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 19.03.2012 16:32

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

offliNe. 19.03.2012 17:46

Nee is alles in bester Ordnung..läuft super.
Vielen dank für die ganze Hilfe. Find ich top das es so ein Board wie dieses gibt :daumenhoc

Kann ich diese ganzen Programme jetz deinsatllieren?
Und welches Anti-Virenprogramm (kostenlos) würdes du mir empfehlen?

Ich hatte Avira drauf aber das find ich nich so dolle.

cosinus 19.03.2012 18:11

Die Frage - welcher Virenscanner oder ob der installierte reicht - taucht ständig auf.
Der Virenscanner - egal welcher - kann und wird niemals 100% Schutz bieten können. Neue/unbekannte Schädlinge können immer durch die Lappen gehen. Geld ausgeben muss man nicht für einen Scanner, sowas wie Avast oder Microsoft Security Essentials sind für die privaten Gebrauch völlig ausreichend.
Abgesehen davon nutzen verschiedene Virenscanner unterschiedliche Signaturen und Techniken, das führt dazu, dass zB Scanner1 Schädling X entdeckt, aber Schädling Y übersieht. Scanner2 erkennt Schädling Y, dafür aber Schädling X nicht...
Wichtiger ist, dass du dich an Regeln hälst. Der beste Virenscanner bringt nichts, wenn du dich falsch verhälst und fahrlässig/unvorsichtig bist. Airbag und Sicherheitsgurt im Auto sind ja auch keine Gründe dafür auf die Verkehrsregeln zu pfeifen.

Halte Dich am besten grob an diese Regeln:
  1. Sei misstrauisch im Internet und v.a. bei unbekannten E-Mails, sei vorsichtig bei der Herausgabe persönlicher Daten!!
  2. Halte Windows und alle verwendeten Programme immer aktuell - unterstützen kann dich dabei Secunia PSI
  3. Führe regelmäßig Backups auf externe Medien durch
  4. Arbeite mit eingeschränkten Rechten
  5. Nutze sicherere Programme wie zB Opera oder Firefox zum Surfen statt den IE, zum Mailen Thunderbird statt Outlook Express - E-Mails nur als reinen text anzeigen lassen
  6. automatische Wiedergabe von allen Laufwerken komplett deaktivieren, denn das ist ein unnötiges Sicherheitsrisiko
  7. Bei der Installation von Software möglichst darauf achten, dass die Setups aus offiziellen Quellen stammen und du bei der Installation nach Möglichkeit die benutzerdefinierte Methode wählst - dann hast du die Möglichkeit etwaigen Schrott (wie Toolbars oder sowas wie RegistryBooster) abzuwählen, welcher sonst einfach mitinstalliert wird.
  8. Bösartige bzw. ungewollte Sites von vornherein blockieren lassen mit Hilfe der MVPS Hosts File => Blocking Unwanted Parasites with a Hosts File
  9. Finger weg von: TuneUp, Registry-Cleanern aller Art, Softonic sowie illegalen Cracks/Keygens oder anderen "Tools" um ein kommerzielles Programm ohne Lizenz nutzen zu können
  10. dubiose Seiten bzw. Kinofilm-Streaming-Portale ebenfalls sein lassen, erstens handelt man sich dort schnell Malware ein oder kann in Abofallen geraten und zweitens bewegen sich diese Seiten in einer rechtlichen Grauzone.


Alles noch genauer erklärt steht hier => Kompromittierung unvermeidbar?


Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

offliNe. 23.03.2012 13:33

Danke dafür.

Jetz noch ne Frage unzwar wie deinstalliere ich otl, tdsskiller und aswMBR
geht das auch über ausführen wie bei combofix?

Finde auf meinem Pc nämlich keine Dateien ausser die .exe dateine von diesen programmen.

cosinus 23.03.2012 21:30

Nein, diese Programme enfach löschen, die müssen nicht deinstalliert werden

offliNe. 26.03.2012 15:31

Moin

aus welchen Gründen auch immer kam bei mir beim Besuch einer Internetseite wieder der gleiche Kack. :headbang:

Aus Sicherheitsgründen usw. wie beim letzten mal.

Bin nun ersma im abgesicherten Modus. Habe versucht mir Malewarebytes runterzuladen aber ohne Erfolg. Genauso mit dem Eset scanner. Ich klicke auf Dload aber zeigt nichmal an wo ers hingespeichert haben will.

Ich speichere meine Sachen eigentlich immer erst auf dem Desktop aber da befindet sich keines der beide o.g. Programme.

Mit IE konnte ich jetz Malwarebytes laden.

hier schonmal die Logfile falls gewünscht..komischerweise kein Fund.

Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.26.04

Windows Vista Service Pack 2 x64 NTFS (Abgesichertenmodus/Netzwerkfähig)
Internet Explorer 8.0.6001.19190
Admin :: ADMIN-PC [Administrator]

26.03.2012 17:53:27
mbam-log-2012-03-26 (17-53-27).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 391873
Laufzeit: 41 Minute(n), 44 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 26.03.2012 18:26

Zitat:

aus welchen Gründen auch immer kam bei mir beim Besuch einer Internetseite wieder der gleiche Kack.
Dann hast du wohl nicht alle Programme und Plugins aktualisiert...

offliNe. 26.03.2012 19:05

Da hast du Recht. :headbang:

Weißt du was ich da machen kann? Im normalen Modus kann ich den PC nicht hochfahren.
Oder soll ich alles aktualisieren? Was aber jetz im abgesicherten nicht geht oder?

cosinus 26.03.2012 20:09

Dann muss ein neues OTL-Log aus dem abgesicherten Modus her. Warum hast du nicht gleich alle Sachen aktualisiert, das war nicht nur zur Deko da sondern das wichtigste was man direkt nach der Bereinigung eigentlich macht! :balla:

CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


offliNe. 26.03.2012 20:34

Weiss auch nich hab das iwie verplant. Wusste auch nich dass es so wichtig is aber hab wieder dazugelernt.

OTL-Log

Code:

OTL logfile created on: 26.03.2012 21:23:27 - Run 1
OTL by OldTimer - Version 3.2.39.2    Folder = C:\Users\Admin\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19190)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,75 Gb Available Physical Memory | 68,66% Memory free
8,19 Gb Paging File | 7,14 Gb Available in Paging File | 87,15% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 500,00 Gb Total Space | 443,69 Gb Free Space | 88,74% Space Free | Partition Type: NTFS
Drive D: | 331,50 Gb Total Space | 314,94 Gb Free Space | 95,00% Space Free | Partition Type: NTFS
Drive E: | 100,01 Gb Total Space | 97,68 Gb Free Space | 97,67% Space Free | Partition Type: NTFS
 
Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.03.26 21:20:44 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe
 
 
========== Modules (No Company Name) ==========
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2009.04.29 04:07:44 | 000,203,264 | ---- | M] (AMD) [Auto | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2011.11.17 18:39:02 | 003,993,576 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2011.04.01 10:31:38 | 002,271,608 | ---- | M] (TeamViewer GmbH) [Auto | Stopped] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2010.11.17 19:16:10 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.08.18 12:30:10 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009.03.29 21:42:16 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2011.12.08 06:22:38 | 000,203,320 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\ssudmdm.sys -- (ssudmdm) SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.)
DRV:64bit: - [2011.12.08 06:22:38 | 000,098,616 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\ssudbus.sys -- (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.)
DRV:64bit: - [2011.03.29 15:31:38 | 000,025,528 | ---- | M] (Turtle Entertainment GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\ESLvnic.sys -- (ESLvnic1)
DRV:64bit: - [2009.10.01 02:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:64bit: - [2009.04.29 05:32:10 | 005,357,056 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009.04.24 07:43:18 | 000,110,904 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2008.09.23 18:15:00 | 000,056,832 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\L1E60x64.sys -- (L1E)
DRV:64bit: - [2008.07.22 10:02:26 | 000,175,656 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\mv61xx.sys -- (mv61xx)
DRV:64bit: - [2008.04.22 08:53:36 | 000,012,744 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\ENTECH64.sys -- (ENTECH64)
DRV:64bit: - [2008.01.21 04:51:07 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2006.11.01 01:23:42 | 000,015,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\ASACPI.sys -- (MTsensor)
DRV - [2004.12.31 08:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKLM\..\SearchScopes,DefaultScope =
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-428930013-155050764-3272862090-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-428930013-155050764-3272862090-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-428930013-155050764-3272862090-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 33 B4 B6 84 9C DF C9 01  [binary data]
IE - HKU\S-1-5-21-428930013-155050764-3272862090-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-428930013-155050764-3272862090-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-428930013-155050764-3272862090-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "t-online.de"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.5
FF - prefs.js..extensions.enabledItems: {D9A7CBEC-DE1A-444f-A092-844461596C4D}:4.5
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.03.18 19:14:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.03.16 12:27:11 | 000,000,000 | ---D | M]
 
[2012.03.14 22:38:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Extensions
[2012.03.14 22:38:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\5idar8fo.default\extensions
[2011.10.16 15:38:26 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\5idar8fo.default\extensions\firefox@tvunetworks.com
[2012.03.14 22:38:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
() (No name found) -- C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5IDAR8FO.DEFAULT\EXTENSIONS\NOSQUINT@URANDOM.CA.XPI
[2012.03.18 19:14:13 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.02.04 20:32:26 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.02.04 20:32:26 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.02.04 20:32:26 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.04 20:32:26 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.04 20:32:26 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
 
O1 HOSTS File: ([2012.03.16 12:20:35 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [PDFPrint] E:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKU\S-1-5-21-428930013-155050764-3272862090-1000..\Run: [RocketDock] E:\RocketDock\RocketDock.exe ()
O4 - HKU\S-1-5-21-428930013-155050764-3272862090-1000..\Run: [SkypePM] C:\Users\Admin\AppData\Local\Skype\SkypePM.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-428930013-155050764-3272862090-1000..\Run: [Steam] D:\Steam\steam.exe (Valve Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-428930013-155050764-3272862090-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-428930013-155050764-3272862090-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{170BB71F-CEF1-4473-ABE6-8EDB5165DEBB}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
 
 
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: WudfPf - Driver
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {0776E06D-C7B6-8A2E-8DDB-49C83B5BCA01} - Themes Setup
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\Windows\SysWow64\alf2cd.acm (NCT Company)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\SysWow64\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.scg726 - C:\Windows\SysWow64\Scg726.acm (SHARP Corporation)
Drivers32: msacm.voxacm160 - C:\Windows\SysWow64\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.dvsd - C:\Windows\SysWow64\mcdvd_32.dll (MainConcept)
Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.mp42 - C:\Windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.mp43 - C:\Windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.mpg4 - C:\Windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.xvid - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
 
CREATERESTOREPOINT
Error creating restore point.
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.03.26 21:20:42 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe
[2012.03.26 17:52:59 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.03.26 17:52:15 | 009,502,424 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\Admin\Desktop\mbam-setup-1.60.1.1000.exe
[2012.03.26 15:15:05 | 000,428,544 | ---- | C] (Anny Studio) -- C:\Users\Admin\jcpicker.exe
[2012.03.16 12:27:02 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012.03.16 12:25:17 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.03.16 12:21:23 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.03.16 12:18:32 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\temp
[2012.03.16 12:13:48 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012.03.15 00:21:53 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.03.14 18:32:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.03.11 19:41:20 | 000,000,000 | ---D | C] -- C:\Users\Admin\.tfo4
 
========== Files - Modified Within 30 Days ==========
 
[2012.03.26 21:20:44 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe
[2012.03.26 17:53:00 | 000,000,740 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.03.26 17:52:29 | 009,502,424 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\Admin\Desktop\mbam-setup-1.60.1.1000.exe
[2012.03.26 16:32:19 | 000,007,728 | ---- | M] () -- C:\Users\Admin\AppData\Local\d3d9caps.dat
[2012.03.26 16:26:40 | 001,445,546 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.03.26 16:26:40 | 000,627,978 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.03.26 16:26:40 | 000,595,608 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.03.26 16:26:40 | 000,126,092 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.03.26 16:26:40 | 000,103,682 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.03.26 16:21:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.03.26 16:18:31 | 000,004,112 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.26 16:18:31 | 000,004,112 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.26 16:06:22 | 000,076,575 | ---- | M] () -- C:\Users\Admin\Desktop\forever-alone-face-i9.png
[2012.03.26 16:05:59 | 000,050,423 | ---- | M] () -- C:\Users\Admin\Desktop\create+folder+on+desktop+lable+quot+Fap+folder+quot+inside+make+a+_c3d1490daf245dd15f021b58131b65f4.png
[2012.03.26 16:05:07 | 000,072,028 | ---- | M] () -- C:\Users\Admin\Desktop\618px-Trollface_HD.png
[2012.03.26 15:11:30 | 000,428,544 | ---- | M] (Anny Studio) -- C:\Users\Admin\jcpicker.exe
[2012.03.16 12:20:35 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.03.14 23:40:00 | 002,308,112 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.03.04 16:32:55 | 000,018,646 | ---- | M] () -- C:\Users\Admin\englisch1.odt
 
========== Files Created - No Company Name ==========
 
[2012.03.26 17:53:00 | 000,000,740 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.03.26 16:06:22 | 000,076,575 | ---- | C] () -- C:\Users\Admin\Desktop\forever-alone-face-i9.png
[2012.03.26 16:05:59 | 000,050,423 | ---- | C] () -- C:\Users\Admin\Desktop\create+folder+on+desktop+lable+quot+Fap+folder+quot+inside+make+a+_c3d1490daf245dd15f021b58131b65f4.png
[2012.03.26 16:05:07 | 000,072,028 | ---- | C] () -- C:\Users\Admin\Desktop\618px-Trollface_HD.png
[2012.03.16 12:27:11 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012.03.04 16:32:55 | 000,018,646 | ---- | C] () -- C:\Users\Admin\englisch1.odt
[2011.12.23 21:58:24 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2011.12.23 21:58:24 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2011.12.23 21:58:24 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2011.12.23 21:58:24 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2011.09.23 18:42:31 | 000,140,448 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011.09.18 18:21:46 | 000,484,352 | ---- | C] () -- C:\Windows\SysWow64\lame_enc.dll
[2010.09.17 14:32:06 | 000,007,728 | ---- | C] () -- C:\Users\Admin\AppData\Local\d3d9caps.dat
 
========== LOP Check ==========
 
[2010.09.11 20:52:10 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Ableton
[2009.05.28 15:37:19 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Ashampoo
[2009.05.30 13:35:20 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Fisher-Price
[2011.09.18 18:21:52 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FreeAudioPack
[2011.09.18 18:22:16 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FreeCDRipper
[2009.08.14 18:33:22 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\gtk-2.0
[2009.12.10 20:11:50 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Mumble
[2009.08.07 19:35:36 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Octoshape
[2009.05.28 15:59:15 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\OpenOffice.org
[2012.01.11 12:05:13 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Samsung
[2009.05.29 17:30:31 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ScanSoft
[2011.04.08 13:30:29 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\TeamViewer
[2011.09.14 16:26:15 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Teeworlds
[2012.01.07 18:05:17 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\TS3Client
[2011.08.01 23:49:15 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Windows Sidebar Styler
[2012.03.26 16:19:08 | 000,032,530 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.09.11 20:52:10 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Ableton
[2012.03.26 15:56:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Adobe
[2011.09.23 18:22:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Apple Computer
[2009.05.28 15:37:19 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Ashampoo
[2009.05.28 15:42:50 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ATI
[2009.06.08 20:34:57 | 000,000,000 | R--D | M] -- C:\Users\Admin\AppData\Roaming\Brother
[2010.07.19 20:14:34 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DivX
[2009.05.30 13:35:20 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Fisher-Price
[2011.09.18 18:21:52 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FreeAudioPack
[2011.09.18 18:22:16 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FreeCDRipper
[2009.08.14 18:33:22 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\gtk-2.0
[2009.05.28 14:09:06 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Identities
[2009.05.29 09:30:03 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\InstallShield
[2009.05.28 15:32:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Macromedia
[2011.05.25 18:04:14 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Malwarebytes
[2006.11.02 17:07:25 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Media Center Programs
[2012.01.11 12:13:15 | 000,000,000 | --SD | M] -- C:\Users\Admin\AppData\Roaming\Microsoft
[2009.08.07 19:35:37 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Mozilla
[2009.12.10 20:11:50 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Mumble
[2009.08.07 19:35:36 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Octoshape
[2009.05.28 15:59:15 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\OpenOffice.org
[2012.01.11 12:05:13 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Samsung
[2009.05.29 17:30:31 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ScanSoft
[2010.05.30 15:37:57 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\teamspeak2
[2011.04.08 13:30:29 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\TeamViewer
[2011.09.14 16:26:15 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Teeworlds
[2012.01.07 18:05:17 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\TS3Client
[2011.12.27 19:05:15 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\vlc
[2011.08.01 23:49:15 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Windows Sidebar Styler
[2009.05.29 17:49:53 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2009.05.28 15:20:41 | 000,010,134 | R--- | M] () -- C:\Users\Admin\AppData\Roaming\Microsoft\Installer\{4411E4C3-C60F-B094-0E1F-C6E73311A9EA}\ARPPRODUCTICON.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2008.01.21 04:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\SysNative\drivers\AGP440.sys
[2008.01.21 04:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008.01.21 04:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.01.21 04:46:50 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2009.04.11 00:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\ERDNT\cache64\atapi.sys
[2009.04.11 00:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\SysNative\drivers\atapi.sys
[2009.04.11 00:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\ERDNT\cache64\cngaudit.dll
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\SysNative\cngaudit.dll
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\ERDNT\cache86\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 04:46:59 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2008.01.21 04:46:59 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2008.01.21 04:51:03 | 000,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\ERDNT\cache86\netlogon.dll
[2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SysWOW64\netlogon.dll
[2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009.04.11 00:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\ERDNT\cache64\netlogon.dll
[2009.04.11 00:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\SysNative\netlogon.dll
[2009.04.11 00:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008.01.21 04:48:28 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2008.01.21 04:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\SysNative\drivers\nvstor.sys
[2008.01.21 04:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 04:50:28 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008.01.21 04:49:49 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\ERDNT\cache86\scecli.dll
[2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009.04.11 00:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\ERDNT\cache64\scecli.dll
[2009.04.11 00:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\SysNative\scecli.dll
[2009.04.11 00:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
 
< MD5 for: USER32.DLL  >
[2008.01.21 04:48:29 | 000,820,224 | ---- | M] (Microsoft Corporation) MD5=32B87D215905F648EBE36A621978442C -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_295707c525b9f068\user32.dll
[2008.01.21 04:49:14 | 000,648,192 | ---- | M] (Microsoft Corporation) MD5=3D691030DBD3BD75DE1501BE54F0D425 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_33abb2175a1ab263\user32.dll
[2009.04.10 23:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\ERDNT\cache86\user32.dll
[2009.04.10 23:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\SysWOW64\user32.dll
[2009.04.10 23:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_35972b23573c7daf\user32.dll
[2009.04.11 00:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) MD5=F3F5549E69AE8509342E67E4F972CA1C -- C:\Windows\ERDNT\cache64\user32.dll
[2009.04.11 00:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) MD5=F3F5549E69AE8509342E67E4F972CA1C -- C:\Windows\SysNative\user32.dll
[2009.04.11 00:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) MD5=F3F5549E69AE8509342E67E4F972CA1C -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_2b4280d122dbbbb4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 04:50:36 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\ERDNT\cache86\userinit.exe
[2008.01.21 04:50:36 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SysWOW64\userinit.exe
[2008.01.21 04:50:36 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2008.01.21 04:49:46 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\ERDNT\cache64\userinit.exe
[2008.01.21 04:49:46 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\SysNative\userinit.exe
[2008.01.21 04:49:46 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 04:48:04 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\ERDNT\cache86\wininit.exe
[2008.01.21 04:48:04 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\SysWOW64\wininit.exe
[2008.01.21 04:48:04 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2008.01.21 04:50:23 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\ERDNT\cache64\wininit.exe
[2008.01.21 04:50:23 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\SysNative\wininit.exe
[2008.01.21 04:50:23 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_8d115452bcae17d8\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\ERDNT\cache64\winlogon.exe
[2009.04.11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\SysNative\winlogon.exe
[2009.04.11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008.01.21 04:49:47 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009.04.10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SysWOW64\winlogon.exe
[2009.04.10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 04:50:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 04:49:42 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2008.01.21 04:49:42 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_aba53c58802b1777\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >

< End of report >


cosinus 27.03.2012 10:05

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
O4 - HKU\S-1-5-21-428930013-155050764-3272862090-1000..\Run: [SkypePM] C:\Users\Admin\AppData\Local\Skype\SkypePM.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
:Files
C:\Users\Admin\AppData\Local\Skype
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

offliNe. 27.03.2012 12:25

hier nach dem Fix

Code:

All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-428930013-155050764-3272862090-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SkypePM deleted successfully.
C:\Users\Admin\AppData\Local\Skype\SkypePM.exe moved successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
========== FILES ==========
C:\Users\Admin\AppData\Local\Skype folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Admin
->Temp folder emptied: 58484032 bytes
->Temporary Internet Files folder emptied: 608938 bytes
->Java cache emptied: 1951710 bytes
->FireFox cache emptied: 49338180 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 897 bytes
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 819456 bytes
 
Total Files Cleaned = 106,00 mb
 
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.39.2 log created on 03272012_131819

Files\Folders moved on Reboot...
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.

Registry entries deleted on Reboot...


cosinus 27.03.2012 13:41

Geht der normale Modus wieder?
Wenn ja kümmer dich jetzt SOFORT um die Updates!!


Alle Zeitangaben in WEZ +1. Es ist jetzt 01:29 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19