Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Erst Fehlermeldungen und nun keine Daten mehr und leerer Desktop. (https://www.trojaner-board.de/112008-erst-fehlermeldungen-keine-daten-mehr-leerer-desktop.html)

cosinus 24.03.2012 18:13

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).


piepmatz 24.03.2012 20:46

ok, hier sind schonmal die gmer und osam log files:

Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-03-24 20:33:55
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 ST9320320AS rev.0303
Running: pj94kw5i.exe; Driver: C:\Users\Nine\AppData\Local\Temp\kwtdqpow.sys


---- Kernel code sections - GMER 1.0.15 ----

.text          C:\Windows\system32\DRIVERS\atikmdag.sys                                                            section is writeable [0x8E608000, 0x23097E, 0xE8000020]
.text          C:\Windows\system32\DRIVERS\atksgt.sys                                                              section is writeable [0x9F406300, 0x3B6D8, 0xE8000020]
.text          C:\Windows\system32\DRIVERS\lirsgt.sys                                                              section is writeable [0x9F449300, 0x1BEE, 0xE8000020]

---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                [740C7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                [7411A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]            [740CBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]      [740BF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                [740C75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]              [740BE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]  [740F8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]    [740CDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]            [740BFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]              [740BFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]              [740B71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]      [7414CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]          [740EC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]            [740BD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                      [740B6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                      [740B687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]        [740C2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\fastfat \Fat                                                                            fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 20:44:39 on 24.03.2012

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 11.0

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys  (File found, but it contains no detailed information)
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"kwtdqpow" (kwtdqpow) - ? - C:\Users\Nine\AppData\Local\Temp\kwtdqpow.sys  (Hidden registry entry, rootkit activity | File not found)
"lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys  (File found, but it contains no detailed information)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{0561EC90-CE54-4f0c-9C55-E226110A740C} "Haali Column Provider" - ? - C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll  (File found, but it contains no detailed information)
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{7D4D6379-F301-4311-BEBA-E26EB0561882} "{7D4D6379-F301-4311-BEBA-E26EB0561882}" - ? -  (File not found | COM-object registry key not found)
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} "Acrobat Elements Context Menu" - "Adobe Systems Inc." - C:\Program Files\Acrobat 8.0\Acrobat Elements\ContextMenu.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{0561EC90-CE54-4f0c-9C55-E226110A740C} "Haali Column Provider" - ? - C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll  (File found, but it contains no detailed information)
{5574006C-28F5-4a65-A28C-74DE6BFBE0BB} "Haali Matroska Shell Property Page" - ? - C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll  (File found, but it contains no detailed information)
{327669A0-59A7-4be9-B99E-1C9F3A57611A} "Haali Matroska Thumbnail Extractor" - ? - C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll  (File found, but it contains no detailed information)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? -  (File not found | COM-object registry key not found)
{B327765E-D724-4347-8B16-78AE18552FC3} "NeroDigitalIconHandler" - ? -  (File not found | COM-object registry key not found)
{7F1CF152-04F8-453A-B34C-E609530A9DC8} "NeroDigitalPropSheetHandler" - ? -  (File not found | COM-object registry key not found)
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\WinRAR\rarext.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_29.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? -  (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "Adobe PDF" - ? - C:\Program Files\Acrobat 8.0\Acrobat\AcroIEFavClient.dll  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{AE7CD045-E861-484f-8273-0445EE161910} "Adobe PDF Conversion Toolbar Helper" - ? - C:\Program Files\Acrobat 8.0\Acrobat\AcroIEFavClient.dll  (File not found)
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Nine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Dropbox.lnk" - "Dropbox, Inc." - C:\Users\Nine\AppData\Roaming\Dropbox\bin\Dropbox.exe  (Shortcut exists | File exists)
"Stardock ObjectDock.lnk" - "Stardock" - C:\Stardock\ObjectDock\ObjectDock.exe  (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"ScottsPaperManager" - ? - "C:\Program Files\SBPaper\paper.exe" -autominimize  (File found, but it contains no detailed information)
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"ATKOSD2" - "ASUS" - C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Adobe PDF Port" - "Adobe Systems Incorporated." - C:\Windows\system32\AdobePDF.dll
"PCL hpz3l5mu" - "Hewlett-Packard Company" - C:\Windows\system32\hpz3l5mu.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%SystemRoot%\System32\TuneUpDefragService.exe,-1" (TuneUp.Defrag) - "TuneUp Software" - C:\Windows\System32\TuneUpDefragService.exe
"@%SystemRoot%\System32\TUProgSt.exe,-1" (TuneUp.ProgramStatisticsSvc) - "TuneUp Software" - C:\Windows\System32\TUProgSt.exe
"@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
"ASLDR Service" (ASLDRService) - ? - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"AVM IGD CTRL Service" (IGDCTRL) - "AVM Berlin" - C:\Program Files\FRITZ!DSL\IGDCTRL.EXE
"Bonjour-Dienst" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Macrovision Europe Ltd." - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Nalpeiron Licensing Service" (ASTSRV) - "Nalpeiron Ltd." - C:\Windows\system32\ASTSRV.EXE
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
"UPnPService" (UPnPService) - "Magix AG" - C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"Sarah NSP" - "AVM Berlin" - C:\Program Files\FRITZ!DSL\sarah.dll
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries )-----
"SARAH LSP" - "AVM Berlin" - C:\Program Files\FRITZ!DSL\sarah.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


piepmatz 24.03.2012 21:50

und hier nun das aswMBR logfile:

cosinus 25.03.2012 14:30

Wieso wird das jetzt NICHT in CODE-Tags gepostet :confused:
Mach doch nicht so einen Mischmasch :wtf:

piepmatz 25.03.2012 14:34

tut mir leid :( meinst das aswMBR.txt? die anderen sind doch richtig so, oder nicht? anbei nochmal in code-tag:


Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-03-24 21:11:46
-----------------------------
21:11:46.960    OS Version: Windows 6.0.6002 Service Pack 2
21:11:46.961    Number of processors: 2 586 0x170A
21:11:46.962    ComputerName: NINE-PC  UserName: Nine
21:11:48.573    Initialize success
21:11:53.178    AVAST engine defs: 12032400
21:11:55.148    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
21:11:55.151    Disk 0 Vendor: ST9320320AS 0303 Size: 305245MB BusType: 3
21:11:55.197    Disk 0 MBR read successfully
21:11:55.200    Disk 0 MBR scan
21:11:55.208    Disk 0 unknown MBR code
21:11:55.212    Disk 0 Partition 1 00    1C Hidd FAT32 LBA MSDOS5.0    12001 MB offset 63
21:11:55.249    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS      152617 MB offset 24579450
21:11:55.258    Disk 0 Partition - 00    0F Extended LBA            140623 MB offset 337140090
21:11:55.312    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      140623 MB offset 337140153
21:11:55.350    Disk 0 scanning sectors +625137345
21:11:55.555    Disk 0 scanning C:\Windows\system32\drivers
21:12:30.711    Service scanning
21:13:01.378    Modules scanning
21:13:15.959    Disk 0 trace - called modules:
21:13:16.011    ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys
21:13:16.019    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85e21390]
21:13:16.026    3 CLASSPNP.SYS[8a9a18b3] -> nt!IofCallDriver -> [0x85743918]
21:13:16.034    5 acpi.sys[8069b6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0x856f6030]
21:13:17.344    AVAST engine scan C:\Windows
21:13:26.506    AVAST engine scan C:\Windows\system32
21:19:28.689    AVAST engine scan C:\Windows\system32\drivers
21:19:46.549    AVAST engine scan C:\Users\Nine
21:29:59.626    AVAST engine scan C:\ProgramData
21:38:14.334    Scan finished successfully
21:47:51.880    Disk 0 MBR has been saved successfully to "C:\Users\Nine\Desktop\MBR.dat"
21:47:51.888    The log file has been saved successfully to "C:\Users\Nine\Desktop\aswMBR.txt"


cosinus 25.03.2012 15:43

Geht doch http://cheesebuerger.de/images/midi/froehlich/a048.gif

Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.

Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.
Mach den Fix auch dann nicht, wenn du zB mit TrueCrypt oder anderen Verschlüsselungsprogrammen eine Vollverschlüsselung der Windowspartition bzw. gesamten Festplatte hast


Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!

Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

piepmatz 25.03.2012 16:25

hmmm, das ging ja so schnell, ich hoffe ich hab es richtig gemacht..
Hab jetzt die Log Datei nach dem fixen und vor dem Neustart gespeichert, ist das die richtige? Oder muss ich nach dem Neustart noch was anderes machen?

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-03-25 17:15:41
-----------------------------
17:15:41.192    OS Version: Windows 6.0.6002 Service Pack 2
17:15:41.192    Number of processors: 2 586 0x170A
17:15:41.195    ComputerName: NINE-PC  UserName: Nine
17:15:43.307    Initialize success
17:15:53.920    AVAST engine defs: 12032400
17:16:37.793    Verifying
17:16:47.855    Disk 0 Windows 600 MBR fixed successfully
17:17:27.260    Disk 0 MBR has been saved successfully to "C:\Users\Nine\Desktop\MBR.dat"
17:17:27.260    The log file has been saved successfully to "C:\Users\Nine\Desktop\aswMBR.txt"


cosinus 25.03.2012 17:46

Nein du hast kein neues Log gemacht! Das ist nur das Fixlog!

piepmatz 25.03.2012 17:50

ok..scheiße..tut mir leid
und wie mach ich ein neues logfile? Muss ich einfach aswMBR starten und save log klicken oder einmal neu scannen?

falls ein Neuscan gemeint ist, hier vorsichtshalber das Ergebnis:

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-03-25 18:47:38
-----------------------------
18:47:38.416    OS Version: Windows 6.0.6002 Service Pack 2
18:47:38.416    Number of processors: 2 586 0x170A
18:47:38.417    ComputerName: NINE-PC  UserName: Nine
18:47:39.386    Initialize success
18:47:45.174    AVAST engine defs: 12032400
18:47:52.575    The log file has been saved successfully to "C:\Users\Nine\Desktop\aswMBR.txt"
18:51:59.512    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
18:51:59.515    Disk 0 Vendor: ST9320320AS 0303 Size: 305245MB BusType: 3
18:51:59.763    Disk 0 MBR read successfully
18:51:59.767    Disk 0 MBR scan
18:51:59.775    Disk 0 Windows VISTA default MBR code
18:51:59.780    Disk 0 Partition 1 00    1C Hidd FAT32 LBA MSDOS5.0    12001 MB offset 63
18:51:59.797    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS      152617 MB offset 24579450
18:51:59.806    Disk 0 Partition - 00    0F Extended LBA            140623 MB offset 337140090
18:51:59.841    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      140623 MB offset 337140153
18:51:59.855    Disk 0 scanning sectors +625137345
18:51:59.968    Disk 0 scanning C:\Windows\system32\drivers
18:52:17.148    Service scanning
18:52:43.540    Modules scanning
18:52:52.927    Disk 0 trace - called modules:
18:52:52.953    ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
18:52:52.958    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8591e238]
18:52:52.963    3 CLASSPNP.SYS[8a9a08b3] -> nt!IofCallDriver -> [0x8570ef08]
18:52:52.968    5 acpi.sys[8069f6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0x8570e030]
18:52:54.554    AVAST engine scan C:\Windows
18:52:59.271    AVAST engine scan C:\Windows\system32
18:57:53.120    AVAST engine scan C:\Windows\system32\drivers
18:58:10.517    AVAST engine scan C:\Users\Nine
19:18:27.617    AVAST engine scan C:\ProgramData
19:27:46.632    Scan finished successfully
19:29:32.686    Disk 0 MBR has been saved successfully to "C:\Users\Nine\Desktop\MBR.dat"
19:29:32.694    The log file has been saved successfully to "C:\Users\Nine\Desktop\aswMBR ..txt"


cosinus 25.03.2012 19:24

So war das ok

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

piepmatz 26.03.2012 07:34

er hat doch noch was gefunden :( hier das Ergebnis von SuperAntiSpyware:

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 03/26/2012 at 01:23 AM

Application Version : 5.0.1146

Core Rules Database Version : 8377
Trace Rules Database Version: 6189

Scan type      : Complete Scan
Total Scan Time : 02:56:09

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Administrator

Memory items scanned      : 650
Memory threats detected  : 0
Registry items scanned    : 35030
Registry threats detected : 69
File items scanned        : 323415
File threats detected    : 452

PUP.MyWebSearch/FunWebProducts
        HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
        HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\ProxyStubClsid
        HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\ProxyStubClsid32
        HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}
        HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\ProxyStubClsid
        HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\ProxyStubClsid32
        HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}
        HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\ProxyStubClsid
        HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\ProxyStubClsid32
        HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
        HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\ProxyStubClsid
        HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\ProxyStubClsid32
        HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
        HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid
        HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32
        HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
        HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\ProxyStubClsid
        HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\ProxyStubClsid32
        HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
        HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\ProxyStubClsid
        HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\ProxyStubClsid32
        HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
        HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\ProxyStubClsid
        HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\ProxyStubClsid32
        HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
        HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid
        HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32
        HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
        HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid
        HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
        HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
        HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid
        HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
        HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
        HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid
        HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
        HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}
        HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\ProxyStubClsid
        HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\ProxyStubClsid32
        HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}
        HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\ProxyStubClsid
        HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\ProxyStubClsid32
        HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}
        HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\ProxyStubClsid
        HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\ProxyStubClsid32
        HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
        HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\ProxyStubClsid
        HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\ProxyStubClsid32
        HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}
        HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\ProxyStubClsid
        HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\ProxyStubClsid32
        HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}
        HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\ProxyStubClsid
        HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\ProxyStubClsid32
        HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
        HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\ProxyStubClsid
        HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\ProxyStubClsid32
        HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}
        HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid
        HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid32
        HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
        HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid
        HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid32
        HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
        HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\ProxyStubClsid
        HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\ProxyStubClsid32
        HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}
        HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\ProxyStubClsid
        HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\ProxyStubClsid32

Adware.Tracking Cookie
        C:\Users\Nine\AppData\Roaming\Microsoft\Windows\Cookies\T8XUJXRF.txt [ /apmebf.com ]
        C:\Users\Nine\AppData\Roaming\Microsoft\Windows\Cookies\9Z3Q4SL2.txt [ /doubleclick.net ]
        C:\Users\Nine\AppData\Roaming\Microsoft\Windows\Cookies\ANHU9UJ8.txt [ /dyntracker.com ]
        C:\Users\Nine\AppData\Roaming\Microsoft\Windows\Cookies\PCV2ICA6.txt [ /atdmt.com ]
        C:\Users\Nine\AppData\Roaming\Microsoft\Windows\Cookies\LCX5TU9S.txt [ /zanox-affiliate.de ]
        C:\Users\Nine\AppData\Roaming\Microsoft\Windows\Cookies\E23WZP41.txt [ /mediaplex.com ]
        C:\Users\Nine\AppData\Roaming\Microsoft\Windows\Cookies\MA7OFNFV.txt [ /www.zanox-affiliate.de ]
        C:\USERS\NINE\Cookies\T8XUJXRF.txt [ Cookie:nine@apmebf.com/ ]
        C:\USERS\NINE\Cookies\9Z3Q4SL2.txt [ Cookie:nine@doubleclick.net/ ]
        C:\USERS\NINE\Cookies\ANHU9UJ8.txt [ Cookie:nine@dyntracker.com/ ]
        C:\USERS\NINE\Cookies\PCV2ICA6.txt [ Cookie:nine@atdmt.com/ ]
        C:\USERS\NINE\Cookies\LCX5TU9S.txt [ Cookie:nine@zanox-affiliate.de/ ]
        C:\USERS\NINE\Cookies\E23WZP41.txt [ Cookie:nine@mediaplex.com/ ]
        C:\USERS\NINE\Cookies\MA7OFNFV.txt [ Cookie:nine@www.zanox-affiliate.de/ ]
        delivery.atkmedia.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.belstat.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .getclicky.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .static.getclicky.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        in.getclicky.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.solocpm.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .stats.ebay.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .de.pornhub.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .de.pornhub.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        eas.almamedia.fi [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        eas.almamedia.fi [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.webtrekk.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.webtrekk.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adserver.mvg-werbung.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .gostats.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .blogads.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .blogads.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tto2.traffictrack.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .lebannerofficial.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .lebannerofficial.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        lpa.trackfox2.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        zbox.zanox.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .enoratraffic.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ads.crakmedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .track.webgains.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adserver.sevenload.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        teufel-media.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        secure.img-cdn.mediaplex.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        cn.clickable.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .googleads.g.doubleclick.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        banner.lv.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.mediamarkt.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ad.yieldmanager.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ad.yieldmanager.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .77tracking.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .77tracking.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        pornografish.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        pornografish.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aemywpdjclp.stats.esomniture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wnkycnajwhp.stats.esomniture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjkokmczgdp.stats.esomniture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aemyeoc5clo.stats.esomniture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aelyskd5elp.stats.esomniture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wdmiqgajcdo.stats.esomniture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wdl4kkazwbq.stats.esomniture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjliskc5aho.stats.esomniture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wmmyend5aco.stats.esomniture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wck4uoc5gcp.stats.esomniture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6aemiolcpeco.stats.esomniture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        tracking.tchibo.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .h.atdmt.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .h.atdmt.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .h.atdmt.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .h.atdmt.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        delivery.way2traffic.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        delivery.way2traffic.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        delivery.way2traffic.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        delivery.way2traffic.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        tracking.sim-technik.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .one-tracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .one-tracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .one-tracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .one-tracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .one-tracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .one-tracker.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adserver.kauperts.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adserver1.mokono.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .toplist.cz [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adserv.chirurgie-portal.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .crackz.me [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .crackz.me [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ads.trafficjunky.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        stat.iltalehti.fi [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .urbia.wwe-media.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .urbia.wwe-media.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .dealtime.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        stat.dealtime.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .elitepartner.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .elitepartner.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .elitepartner.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .elitepartner.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        banner.testberichte.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .sexad.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .zieltrack.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .hightraffic.hugoboss.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .estat.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .122.2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .paypal.112.2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .deutschepostag.112.2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .rcci.122.2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .autoscout24.112.2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .photobox.112.2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .malaysiaairlines.112.2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .monstercom.112.2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .stepstone.112.2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .iscout24.112.2o7.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ads2.zeusclicks.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .pornhubgold.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .pornhubgold.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .dyntracker.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .mediaevent.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .mediaevent.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\NINE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CMSWDCIP.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-SoftonicDownloader
        D:\DOWNLOAD\SOFTONICDOWNLOADER_FUER_SCOTTS-WALLPAPER-SWITCHER.EXE


cosinus 26.03.2012 15:22

Sieht ok aus, da wurden nur Cookies und Überreste gefunden, kann alles weg.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Malwarebytes kommt noch?

piepmatz 26.03.2012 18:24

puuhh, super.
noch ne blöde Frage, muss ich das noch irgendwie löschen oder ist das schon vom programm gelöscht worden?

Malwarebytes lass ich jetzt noch drüberlaufen..kommt also noch.

vielen vielen Dank für deine Hilfe, super das es Euch gibt!!!!

cosinus 26.03.2012 18:43

Die Cookies kannst du mit SASW löschen

piepmatz 26.03.2012 23:46

so, und hier noch das logfile von malwarebytes:

Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.26.07

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 7.0.6002.18005
Nine :: NINE-PC [Administrator]

26.03.2012 21:45:19
mbam-log-2012-03-26 (21-45-19).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM | P2P
Deaktivierte Suchlaufeinstellungen:
Durchsuchte Objekte: 471420
Laufzeit: 2 Stunde(n), 21 Minute(n), 46 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)



Alle Zeitangaben in WEZ +1. Es ist jetzt 01:57 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131