Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Bundespolizei Virus/Trojaner

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 21.11.2011, 18:36   #16
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Bundespolizei Virus/Trojaner - Standard

Bundespolizei Virus/Trojaner



Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.

Code:
ATTFilter
Driver::
YJEHRBYH
RSND

File::
c:\users\Boss\AppData\Local\Temp\YJEHRBYH.exe
c:\users\Boss\AppData\Local\Temp\RSND.exe
         
3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.



6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 21.11.2011, 19:21   #17
Islandis
 
Bundespolizei Virus/Trojaner - Standard

Bundespolizei Virus/Trojaner



Hallo Arne,

hier das Combofix Log:

Code:
ATTFilter
Combofix Logfile:
Code:
ATTFilter
ComboFix 11-11-21.01 - Boss 21.11.2011  18:56:08.3.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.49.1031.18.3066.1777 [GMT 1:00]
ausgeführt von:: c:\users\Boss\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Boss\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\Boss\AppData\Local\Temp\RSND.exe"
"c:\users\Boss\AppData\Local\Temp\YJEHRBYH.exe"
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
(((((((((((((((((((((((((((((((((((((((   Treiber/Dienste   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_RSND
-------\Service_YJEHRBYH
.
.
(((((((((((((((((((((((   Dateien erstellt von 2011-10-21 bis 2011-11-21  ))))))))))))))))))))))))))))))
.
.
2011-11-21 18:03 . 2011-11-21 18:06	--------	d-----w-	c:\users\Boss\AppData\Local\temp
2011-11-21 18:03 . 2011-11-21 18:03	--------	d-----w-	c:\users\Hel\AppData\Local\temp
2011-11-21 18:03 . 2011-11-21 18:03	--------	d-----w-	c:\users\Default\AppData\Local\temp
2011-11-20 15:52 . 2011-11-20 15:52	--------	d-----w-	C:\_OTL
2011-11-19 15:53 . 2011-11-19 15:53	--------	d-----w-	c:\program files\7-Zip
2011-11-18 04:22 . 2011-11-18 04:22	--------	d-----w-	c:\users\Hel\AppData\Roaming\SUPERAntiSpyware.com
2011-11-18 04:21 . 2011-11-18 04:22	--------	d-----w-	c:\program files\SUPERAntiSpyware
2011-11-18 04:21 . 2011-11-18 04:21	--------	d-----w-	c:\programdata\SUPERAntiSpyware.com
2011-11-17 22:10 . 2011-11-17 22:10	--------	d-----w-	c:\program files\ESET
2011-11-16 16:56 . 2011-11-16 16:56	--------	d-----w-	c:\users\Gast
2011-11-16 16:08 . 2011-11-16 16:08	--------	d-----w-	c:\programdata\VirtualWifiRouter
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-15 08:03 . 2011-05-19 07:05	414368	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-07 03:48 . 2011-11-18 18:47	6668624	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{67517676-631F-4A02-9DB2-76013C059DB6}\mpengine.dll
2011-09-14 06:33 . 2009-10-31 13:22	29712	----a-w-	c:\windows\system32\drivers\avgmfx86.sys
2011-09-06 13:30 . 2011-10-12 09:22	2043392	----a-w-	c:\windows\system32\win32k.sys
2011-09-02 13:22 . 2011-09-02 13:22	0	---ha-w-	c:\users\Hel\AppData\Local\BIT3246.tmp
2011-09-01 02:35 . 2011-10-12 09:27	1798144	----a-w-	c:\windows\system32\jscript9.dll
2011-09-01 02:28 . 2011-10-12 09:27	1126912	----a-w-	c:\windows\system32\wininet.dll
2011-09-01 02:22 . 2011-10-12 09:27	2382848	----a-w-	c:\windows\system32\mshtml.tlb
2011-08-31 16:00 . 2009-10-27 10:19	22216	----a-w-	c:\windows\system32\drivers\mbam.sys
2011-08-25 16:15 . 2011-10-12 09:22	555520	----a-w-	c:\windows\system32\UIAutomationCore.dll
2011-08-25 16:14 . 2011-10-12 09:22	563712	----a-w-	c:\windows\system32\oleaut32.dll
2011-08-25 16:14 . 2011-10-12 09:22	238080	----a-w-	c:\windows\system32\oleacc.dll
2011-08-25 13:31 . 2011-10-12 09:22	4096	----a-w-	c:\windows\system32\oleaccrc.dll
2011-09-03 06:18 . 2011-09-14 08:55	134104	----a-w-	c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-11 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"BatteryCare"="c:\program files\BatteryCare\BatteryCare.exe" [2009-11-20 520192]
"Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2009-08-22 5148672]
"ANT Agent"="c:\program files\Garmin\ANT Agent\ANT Agent.exe" [2011-04-14 12036968]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-02-11 186904]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-08 13605408]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-05-08 92704]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2008-10-31 6609440]
"tsnp2uvc"="c:\windows\tsnp2uvc.exe" [2008-08-28 233472]
"MDS_Menu"="c:\program files\HomeCinema\MediaShow4\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"PDVD8LanguageShortcut"="c:\program files\HomeCinema\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"UCam_Menu"="c:\program files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"fspuip"="c:\program files\FSP\fspuip.exe" [2009-06-19 765952]
"CX Print Msgsrv"="c:\program files\silex technology\CX Print\Msgsrv.exe" [2008-08-21 61440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2011-10-24 2078048]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"Eraser"="c:\progra~1\Eraser\Eraser.exe" [2010-11-04 980368]
"PDFPrint"="c:\program files\pdf24\pdf24.exe" [2011-04-28 220552]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Viren\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-04-11 136176]
R2 Internet Manager. RunOuc;Internet Manager. OUC;c:\program files\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [2011-07-30 224096]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2011-07-26 1025352]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [2011-07-30 102784]
R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys [2011-07-30 11136]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2011-07-30 235392]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-04-11 136176]
R3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys [2011-07-30 90112]
R3 huawei_cdcecm;huawei_cdcecm;c:\windows\system32\DRIVERS\ew_jucdcecm.sys [2011-07-30 64384]
R3 huawei_ext_ctrl;huawei_ext_ctrl;c:\windows\system32\DRIVERS\ew_juextctrl.sys [2011-07-30 26624]
R3 RIYSCJEUOHWHV;RIYSCJEUOHWHV;c:\users\Boss\AppData\Local\Temp\RIYSCJEUOHWHV.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files\BatteryCare\WinRing0.sys [2008-07-26 14416]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 BMLoad;Bytemobile Boot Time Load Driver;c:\windows\system32\drivers\BMLoad.sys [2011-07-30 13184]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-07-16 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2011-05-06 243152]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-11 116608]
S2 AAV UpdateService;AAV UpdateService;c:\program files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [2008-10-24 128296]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-07-16 308136]
S2 HWDeviceService.exe;HWDeviceService.exe;c:\programdata\DatacardService\HWDeviceService.exe [2011-01-28 270176]
S2 resetWinService;Reset Reader;c:\program files\Realtek Semiconductor Corp\Realtek USB 2.0 Card Reader\reset.exe [2008-10-29 70656]
S3 fspad_wlh32;Finger-sensing Pad Driver for Windows 2000/XP/Vista/Win7_wlh32;c:\windows\system32\DRIVERS\fspad_wlh32.sys [2009-06-17 41984]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [2011-07-30 73216]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-06-26 66080]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [2010-02-24 522784]
S3 sxuptp;SXUPTP Driver;c:\windows\system32\DRIVERS\sxuptp.sys [2008-12-19 246808]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation	REG_MULTI_SZ   	FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2011-11-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-11 07:04]
.
2011-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-11 10:22]
.
2011-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-11 10:22]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = 
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\wpclsp.dll
TCP: DhcpNameServer = 192.168.2.1
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - 
FF - ProfilePath - c:\users\Boss\AppData\Roaming\Mozilla\Firefox\Profiles\eakt02rm.default\
FF - prefs.js: network.proxy.type - 2
.
.
**************************************************************************
Scanne versteckte Prozesse... 
.
Scanne versteckte Autostarteinträge... 
.
Scanne versteckte Dateien... 
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\windows\system32\rundll32.exe
c:\programdata\Internet Manager\OnlineUpdate\ouc.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\PSIService.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Cyberlink\Shared files\RichVideo.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\conime.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-11-21  19:12:23 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2011-11-21 18:12
ComboFix2.txt  2011-11-21 16:37
ComboFix3.txt  2011-11-21 12:16
.
Vor Suchlauf: 15 Verzeichnis(se), 188.610.695.168 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 188.479.307.776 Bytes frei
.
- - End Of File - - F1D301488BE2A98C53DF75538A5E83C2
         
--- --- ---
Grüße
Islandis
__________________


Alt 21.11.2011, 19:32   #18
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Bundespolizei Virus/Trojaner - Standard

Bundespolizei Virus/Trojaner



Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).

__________________
__________________

Alt 21.11.2011, 19:57   #19
Islandis
 
Bundespolizei Virus/Trojaner - Standard

Bundespolizei Virus/Trojaner



Hallo Arne,

hier die benötigten Logs:

1. Gmer

Code:
ATTFilter
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit quick scan 2011-11-21 19:47:09
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD32 rev.11.0
Running: rmef47id.exe; Driver: C:\Users\Boss\AppData\Local\Temp\pwtdyfoc.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\fastfat \Fat   fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
AttachedDevice  \FileSystem\fastfat \Fat   fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
AttachedDevice  \Driver\tdx \Device\Ip     avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice  \Driver\tdx \Device\Tcp    tcpipBM.sys
AttachedDevice  \Driver\tdx \Device\Tcp    avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice  \Driver\tdx \Device\Udp    avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice  \Driver\tdx \Device\RawIp  avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

---- EOF - GMER 1.0.15 ----
         
und OSAM:

Code:
ATTFilter
OSAM Logfile:
Code:
ATTFilter
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 19:53:01 on 21.11.2011

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 6.0.2

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[AppInit DLLs]
-----( HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows )-----
"AppInit_DLLs" - "AVG Technologies CZ, s.r.o." - C:\Windows\System32\avgrsstx.dll

[Common]
-----( %SystemRoot%\Tasks )-----
"Google Software Updater.job" - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MI1933~1\Office12\MLCFG32.CPL
"Nero BurnRights" - "Nero AG" - C:\Program Files\Nero\Nero8\Nero Toolkit\NeroBurnRights.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"AVG Free AVI Loader Driver x86" (AvgLdx86) - "AVG Technologies CZ, s.r.o." - C:\Windows\System32\Drivers\avgldx86.sys
"AVG Free Network Redirector" (AvgTdiX) - "AVG Technologies CZ, s.r.o." - C:\Windows\System32\Drivers\avgtdix.sys
"AVG Free On-access Scanner Minifilter Driver x86" (AvgMfx86) - "AVG Technologies CZ, s.r.o." - C:\Windows\System32\Drivers\avgmfx86.sys
"Bytemobile Boot Time Load Driver" (BMLoad) - "Bytemobile, Inc." - C:\Windows\System32\drivers\BMLoad.sys
"Bytemobile Kernel Network Provider" (tcpipBM) - "Bytemobile, Inc." - C:\Windows\system32\drivers\tcpipBM.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"Profos" (Profos) - ? - C:\Program Files\BullGuard Ltd\BullGuard\antirootkit\profos.sys  (File not found)
"pwtdyfoc" (pwtdyfoc) - ? - C:\Users\Boss\AppData\Local\Temp\pwtdyfoc.sys  (Hidden registry entry, rootkit activity | File not found)
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\Windows\System32\Drivers\PxHelp20.sys
"SASDIFSV" (SASDIFSV) - "SUPERAdBlocker.com and SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
"SASKUTIL" (SASKUTIL) - "SUPERAdBlocker.com and SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
"Trufos" (Trufos) - ? - C:\Program Files\BullGuard Ltd\BullGuard\antirootkit\trufos.sys  (File not found)
"WinRing0_1_2_0" (WinRing0_1_2_0) - "OpenLibSys.org" - C:\Program Files\BatteryCare\WinRing0.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{7D4D6379-F301-4311-BEBA-E26EB0561882} "NeroDigitalColumnHandler Class" - "Nero AG" - C:\Program Files\Common Files\Nero\Lib\NeroDigitalExt.dll
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{F2DDE6B2-9684-4A55-86D4-E255E237B77C} "avgsecuritytoolbar" - ? - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll  (File not found)
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
{88FED34C-F0CA-4636-A375-3CB6248B04CD} "Local Groove Web Services Protocol" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} "XPLPPFilter Class" - "AVG Technologies CZ, s.r.o." - C:\Program Files\AVG\AVG9\avgpp.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -   (File not found | COM-object registry key not found)
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} "AVG Find Extension" - ? -   (File not found | COM-object registry key not found)
{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} "AVG Shell Extension Class" - "AVG Technologies CZ, s.r.o." - C:\Program Files\AVG\AVG9\avgse.dll
{DE902992-61FC-4A01-8091-53E1895C9775} "CDR Icon Handler" - "Corel Corporation" - c:\Program Files\Common Files\Corel\Shared\Shell Extension\ShellXP.dll
{7AD101F2-0B93-4D66-A1CA-DF73F3C4377B} "CDR preview provider" - "Corel Corporation" - c:\Program Files\Common Files\Corel\Shared\Shell Extension\ShellVista.dll
{7FA63AC0-F5BC-4F3B-A9CF-94328D812B62} "CDR Property Handler" - "Corel Corporation" - c:\Program Files\Common Files\Corel\Shared\Shell Extension\ShellVista.dll
{1462EBAA-96E7-4D93-9A66-0E4068DE4FCF} "CDR Thumbnail provider" - "Corel Corporation" - c:\Program Files\Common Files\Corel\Shared\Shell Extension\ShellXP.dll
{0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
{DE902994-61FC-4A01-8091-53E1895C9775} "CMX Icon Handler" - "Corel Corporation" - c:\Program Files\Common Files\Corel\Shared\Shell Extension\ShellXP.dll
{1462EBAC-96E7-4D93-9A66-0E4068DE4FCF} "CMX Thumbnail provider" - "Corel Corporation" - c:\Program Files\Common Files\Corel\Shared\Shell Extension\ShellXP.dll
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -   (File not found | COM-object registry key not found)
{DE902993-61FC-4A01-8091-53E1895C9775} "CPT Icon Handler" - "Corel Corporation" - c:\Program Files\Common Files\Corel\Shared\Shell Extension\ShellXP.dll
{7FA63AC1-F5BC-4F3B-A9CF-94328D812B62} "CPT Property Handler" - "Corel Corporation" - c:\Program Files\Common Files\Corel\Shared\Shell Extension\ShellVista.dll
{1462EBAB-96E7-4D93-9A66-0E4068DE4FCF} "CPT Thumbnail provider" - "Corel Corporation" - c:\Program Files\Common Files\Corel\Shared\Shell Extension\ShellXP.dll
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -   (File not found | COM-object registry key not found)
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -   (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MI1933~1\Office12\ONFILTER.DLL
{00020d75-0000-0000-c000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MI1933~1\Office12\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2} "NeroCoverEdLiveIcons Class" - "Nero AG" - C:\Program Files\Nero\Nero8\Nero CoverDesigner\CoverEdExtension.dll
{B327765E-D724-4347-8B16-78AE18552FC3} "NeroDigitalIconHandler Class" - "Nero AG" - C:\Program Files\Common Files\Nero\Lib\NeroDigitalExt.dll
{7F1CF152-04F8-453A-B34C-E609530A9DC8} "NeroDigitalPropSheetHandler Class" - "Nero AG" - C:\Program Files\Common Files\Nero\Lib\NeroDigitalExt.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MI1933~1\Office12\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -   (File not found | COM-object registry key not found)
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe
Eraser Shell Extension "{BC9B776A-90D7-4476-A791-79D835F30650}" - ? -   (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"eBay - Der weltweite Online-Marktplatz" - ? - hxxp://rover.ebay.com/rover/1/707-37276-17534-15/4  (HTTP value)
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "In Blog veröffentlichen" - "Microsoft Corporation" - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Plug-In" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} "AVG Safe Search" - "AVG Technologies CZ, s.r.o." - C:\Program Files\AVG\AVG9\avgssie.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" - "Google Inc." - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID-Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"ANT Agent" - "GARMIN Corp." - C:\Program Files\Garmin\ANT Agent\ANT Agent.exe
"BatteryCare" - "Filipe Lourenço" - "C:\Program Files\BatteryCare\BatteryCare.exe"
"Rainlendar2" - ? - C:\Program Files\Rainlendar2\Rainlendar2.exe
"swg" - "Google Inc." - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"AVG9_TRAY" - "AVG Technologies CZ, s.r.o." - C:\PROGRA~1\AVG\AVG9\avgtray.exe
"CX Print Msgsrv" - ? - "C:\Program Files\silex technology\CX Print\Msgsrv.exe" /NCX Print /S  (File found, but it contains no detailed information)
"Eraser" - "The Eraser Project" - "C:\PROGRA~1\Eraser\Eraser.exe" --atRestart
"GrooveMonitor" - "Microsoft Corporation" - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
"IAAnotif" - "Intel Corporation" - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
"Malwarebytes' Anti-Malware (reboot)" - "Malwarebytes Corporation" - "C:\Program Files\Viren\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
"MDS_Menu" - "CyberLink Corp." - "C:\Program Files\HomeCinema\MediaShow4\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\MediaShow4" UpdateWithCreateOnce "Software\CyberLink\MediaShow\4.1"
"PDFPrint" - "Geek Software GmbH" - C:\Program Files\pdf24\pdf24.exe
"PDVD8LanguageShortcut" - ? - "C:\Program Files\HomeCinema\PowerDVD8\Language\Language.exe"
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"tsnp2uvc" - ? - C:\Windows\tsnp2uvc.exe
"UCam_Menu" - "CyberLink Corp." - "C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\Windows\system32\mdimon.dll
"PRICOM-Print CX Port" - "silex technology, Inc." - C:\Windows\system32\Jcnetmon.dll
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"AAV UpdateService" (AAV UpdateService) - ? - C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"AVG Free WatchDog" (avg9wd) - "AVG Technologies CZ, s.r.o." - C:\Program Files\AVG\AVG9\avgwdsvc.exe
"AVG Security Toolbar Service" (AVG Security Toolbar Service) - ? - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
"C-DillaCdaC11BA" (C-DillaCdaC11BA) - "C-Dilla Ltd" - C:\Windows\system32\drivers\CDAC11BA.EXE
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"HWDeviceService.exe" (HWDeviceService.exe) - ? - C:\ProgramData\DatacardService\HWDeviceService.exe
"Intel(R) Matrix Storage Event Monitor" (IAANTMON) - "Intel Corporation" - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
"Internet Manager. OUC" (Internet Manager. RunOuc) - ? - C:\Program Files\T-Mobile\InternetManager_H\UpdateDog\ouc.exe  (File found, but it contains no detailed information)
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Microsoft Office Groove Audit Service" (Microsoft Office Groove Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
"Nero BackItUp Scheduler 3" (Nero BackItUp Scheduler 3) - "Nero AG" - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
"NMIndexingService" (NMIndexingService) - "Nero AG" - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"PLFlash DeviceIoControl Service" (PLFlash DeviceIoControl Service) - "Prolific Technology Inc." - C:\Windows\system32\IoctlSvc.exe
"Protexis Licensing V2" (PSI_SVC_2) - "Protexis Inc." - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
"ProtexisLicensing" (ProtexisLicensing) - ? - C:\Windows\system32\PSIService.exe
"Reset Reader" (resetWinService) - ? - C:\Program Files\Realtek Semiconductor Corp\Realtek USB 2.0 Card Reader\reset.exe  (File found, but it contains no detailed information)
"RIYSCJEUOHWHV" (RIYSCJEUOHWHV) - ? - C:\Users\Boss\AppData\Local\Temp\RIYSCJEUOHWHV.exe  (File not found)
"SAS Core Service" (!SASCORE) - "SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

[Winlogon]
-----( HKCU\Control Panel\Desktop )-----
"SCRNSAVE.EXE" - "ScreenTime Media" - C:\Windows\System32\Angebo~1.scr

===[ Logfile end ]=========================================[ Logfile end ]===
         
--- --- --- If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
Ich mach jetzt weiter mit aswmbr und poste dann das log

Gruß
Islandis


Und jetzt noch das aswmbr.log:

Code:
ATTFilter
aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-11-21 19:58:19
-----------------------------
19:58:19.459    OS Version: Windows 6.0.6002 Service Pack 2
19:58:19.459    Number of processors: 2 586 0x170A
19:58:19.459    ComputerName: LAPPI-BOSS  UserName: Boss
19:58:20.811    Initialize success
19:59:51.171    AVAST engine defs: 11112100
20:00:06.012    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
20:00:06.014    Disk 0 Vendor: WDC_WD32 11.0 Size: 305245MB BusType: 3
20:00:06.026    Disk 0 MBR read successfully
20:00:06.028    Disk 0 MBR scan
20:00:06.045    Disk 0 Windows VISTA default MBR code
20:00:06.048    Disk 0 scanning sectors +625139712
20:00:06.119    Disk 0 scanning C:\Windows\system32\drivers
20:00:14.442    Service scanning
20:00:15.565    Modules scanning
20:00:19.961    Disk 0 trace - called modules:
20:00:19.978    ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 
20:00:19.981    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x866b1ac8]
20:00:19.984    3 CLASSPNP.SYS[8a9ac8b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8552b028]
20:00:21.572    AVAST engine scan C:\Windows
20:00:25.118    AVAST engine scan C:\Windows\system32
20:02:02.421    AVAST engine scan C:\Windows\system32\drivers
20:02:11.137    AVAST engine scan C:\Users\Boss
20:03:11.762    AVAST engine scan C:\ProgramData
20:05:48.037    Scan finished successfully
20:06:12.643    Disk 0 MBR has been saved successfully to "C:\Users\Boss\Desktop\MBR.dat"
20:06:12.648    The log file has been saved successfully to "C:\Users\Boss\Desktop\aswMBR20111121_2006.txt"
         

Grüße
Islandis

Geändert von Islandis (21.11.2011 um 20:08 Uhr)

Alt 21.11.2011, 21:02   #20
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Bundespolizei Virus/Trojaner - Standard

Bundespolizei Virus/Trojaner



Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!


Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


__________________
Logfiles bitte immer in CODE-Tags posten

Alt 22.11.2011, 03:52   #21
Islandis
 
Bundespolizei Virus/Trojaner - Standard

Bundespolizei Virus/Trojaner



Guten Morgen Arne,

die Scans haben etwas länger gedauert:

Malwarebyte konnte ich leider nicht aktualisieren. Kann das sein, dass das an der freeware liegt und die nur alle x Tage eine Aktualisierung zulassen?

Code:
ATTFilter
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8192

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

22.11.2011 03:32:12
mbam-log-2011-11-22 (03-32-11).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|G:\|)
Durchsuchte Objekte: 338934
Laufzeit: 48 Minute(n), 29 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)
         
hier das esetlog (das neue log wurde vom Programm in ein vorhergehendes log eingefügt und ist im unteren Teil des logs zu finden)

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=799766a7d0ac63459c1dc8fdaa98fad8
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-11-18 12:52:50
# local_time=2011-11-18 01:52:50 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 64940469 64940469 0 0
# compatibility_mode=1024 16777215 100 0 64576381 64576381 0 0
# compatibility_mode=5892 16776574 100 100 3144464 159100810 0 0
# compatibility_mode=8192 67108863 100 0 3861 3861 0 0
# scanned=333702
# found=17
# cleaned=17
# scan_time=9487
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.url	Win32/Adware.ADON application (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Boss\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eBay.url	Win32/Adware.ADON application (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Boss\Desktop\Browser_Reader\eBay.url	Win32/Adware.ADON application (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\AppData\Local\Mozilla\Firefox\Profiles\c64csabm.default\Cache\0\24\D80FAd01	JS/Redirector.NAU trojan (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\AppData\Local\Mozilla\Firefox\Profiles\c64csabm.default\Cache\0\B1\52F45d01	JS/Redirector.NAU trojan (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\AppData\Local\Mozilla\Firefox\Profiles\c64csabm.default\Cache\3\61\6EB1Dd01	JS/Redirector.NAU trojan (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\AppData\Local\Mozilla\Firefox\Profiles\c64csabm.default\Cache\3\F5\89CBCd01	JS/Redirector.NAU trojan (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\AppData\Local\Mozilla\Firefox\Profiles\c64csabm.default\Cache\4\10\86111d01	JS/Redirector.NAU trojan (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\AppData\Local\Mozilla\Firefox\Profiles\c64csabm.default\Cache\5\2C\EA028d01	JS/Redirector.NAU trojan (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\AppData\Local\Mozilla\Firefox\Profiles\c64csabm.default\Cache\7\48\3D64Ed01	JS/Redirector.NAU trojan (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\AppData\Local\Mozilla\Firefox\Profiles\c64csabm.default\Cache\7\4E\5AA0Cd01	JS/Redirector.NAU trojan (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\AppData\Local\Mozilla\Firefox\Profiles\c64csabm.default\Cache\7\69\1BFF5d01	JS/Redirector.NAU trojan (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\AppData\Local\Mozilla\Firefox\Profiles\c64csabm.default\Cache\8\86\CC6EDd01	JS/Redirector.NAU trojan (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\AppData\Local\Mozilla\Firefox\Profiles\c64csabm.default\Cache\9\1B\4797Ad01	JS/Redirector.NAU trojan (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\AppData\Local\Mozilla\Firefox\Profiles\c64csabm.default\Cache\9\F9\668F6d01	JS/Redirector.NAU trojan (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe	a variant of Win32/SoftonicDownloader.A application (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
C:\Users\Hel\Downloads\SoftonicDownloader_fuer_sweet-home-3d.exe	a variant of Win32/SoftonicDownloader.A application (cleaned by deleting - quarantined)	00000000000000000000000000000000	C
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=799766a7d0ac63459c1dc8fdaa98fad8
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-11-22 12:04:07
# local_time=2011-11-22 01:04:07 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 65285308 65285308 0 0
# compatibility_mode=1024 16777215 100 0 64921220 64921220 0 0
# compatibility_mode=5892 16776574 100 100 114236 159445649 0 0
# compatibility_mode=8192 67108863 100 0 348700 348700 0 0
# scanned=201400
# found=0
# cleaned=0
# scan_time=7326
         
und zu guter Letzt noch das SASW_Log:

Code:
ATTFilter
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 11/21/2011 at 10:48 PM

Application Version : 5.0.1136

Core Rules Database Version : 7968
Trace Rules Database Version: 5780

Scan type       : Complete Scan
Total Scan Time : 00:55:49

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC Off - Administrator (Limited User)

Memory items scanned      : 636
Memory threats detected   : 0
Registry items scanned    : 42361
Registry threats detected : 0
File items scanned        : 56787
File threats detected     : 748

Adware.Tracking Cookie
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@2o7[10].txt [ /2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@2o7[11].txt [ /2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@2o7[1].txt [ /2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@2o7[2].txt [ /2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@2o7[3].txt [ /2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@2o7[4].txt [ /2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@2o7[5].txt [ /2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@2o7[6].txt [ /2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@2o7[7].txt [ /2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@2o7[8].txt [ /2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@2o7[9].txt [ /2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad-indicator[1].txt [ /ad-indicator ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad.yieldmanager[1].txt [ /ad.yieldmanager ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad.yieldmanager[2].txt [ /ad.yieldmanager ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad.yieldmanager[3].txt [ /ad.yieldmanager ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad.yieldmanager[4].txt [ /ad.yieldmanager ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad.zanox[1].txt [ /ad.zanox ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad1.adfarm1.adition[2].txt [ /ad1.adfarm1.adition ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad1.emediate[1].txt [ /ad1.emediate ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad1.emediate[2].txt [ /ad1.emediate ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad1.emediate[3].txt [ /ad1.emediate ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad1.emediate[4].txt [ /ad1.emediate ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad2.adfarm1.adition[2].txt [ /ad2.adfarm1.adition ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad3.adfarm1.adition[1].txt [ /ad3.adfarm1.adition ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad4.adfarm1.adition[1].txt [ /ad4.adfarm1.adition ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ad4.adfarm1.adition[2].txt [ /ad4.adfarm1.adition ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@adfarm1.adition[1].txt [ /adfarm1.adition ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@adfarm1.adition[2].txt [ /adfarm1.adition ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@adfarm1.adition[4].txt [ /adfarm1.adition ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@adinterax[2].txt [ /adinterax ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@adinterax[3].txt [ /adinterax ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ads.creative-serving[2].txt [ /ads.creative-serving ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ads.immobilienscout24[1].txt [ /ads.immobilienscout24 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@ads.medienhaus[1].txt [ /ads.medienhaus ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@adserv.quality-channel[1].txt [ /adserv.quality-channel ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@adtech[1].txt [ /adtech ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@adtech[2].txt [ /adtech ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@adtech[3].txt [ /adtech ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@adtech[4].txt [ /adtech ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@adviva[1].txt [ /adviva ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@adviva[2].txt [ /adviva ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@apmebf[1].txt [ /apmebf ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@apmebf[2].txt [ /apmebf ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@apmebf[3].txt [ /apmebf ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@apmebf[4].txt [ /apmebf ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@atdmt[1].txt [ /atdmt ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@atdmt[2].txt [ /atdmt ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@atdmt[3].txt [ /atdmt ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@atdmt[5].txt [ /atdmt ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@avgtechnologies.112.2o7[1].txt [ /avgtechnologies.112.2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@avgtechnologies.112.2o7[2].txt [ /avgtechnologies.112.2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@bs.serving-sys[1].txt [ /bs.serving-sys ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@bs.serving-sys[2].txt [ /bs.serving-sys ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@bs.serving-sys[4].txt [ /bs.serving-sys ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@cdn5.specificclick[1].txt [ /cdn5.specificclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@content.yieldmanager[1].txt [ /content.yieldmanager ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@content.yieldmanager[2].txt [ /content.yieldmanager ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@content.yieldmanager[3].txt [ /content.yieldmanager ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@content.yieldmanager[5].txt [ /content.yieldmanager ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@content.yieldmanager[6].txt [ /content.yieldmanager ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@content.yieldmanager[7].txt [ /content.yieldmanager ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@content.yieldmanager[8].txt [ /content.yieldmanager ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@count.spring[2].txt [ /count.spring ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@doubleclick[10].txt [ /doubleclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@doubleclick[11].txt [ /doubleclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@doubleclick[1].txt [ /doubleclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@doubleclick[2].txt [ /doubleclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@doubleclick[3].txt [ /doubleclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@doubleclick[4].txt [ /doubleclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@doubleclick[5].txt [ /doubleclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@doubleclick[6].txt [ /doubleclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@doubleclick[7].txt [ /doubleclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@doubleclick[8].txt [ /doubleclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@doubleclick[9].txt [ /doubleclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@fastclick[1].txt [ /fastclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@guj.122.2o7[1].txt [ /guj.122.2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@guj.122.2o7[2].txt [ /guj.122.2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@guj.122.2o7[3].txt [ /guj.122.2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@guj.122.2o7[4].txt [ /guj.122.2o7 ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@imrworldwide[2].txt [ /imrworldwide ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@invitemedia[1].txt [ /invitemedia ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@mediaplex[1].txt [ /mediaplex ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@mediaplex[2].txt [ /mediaplex ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@mediaplex[3].txt [ /mediaplex ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@overture[1].txt [ /overture ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@questionmarket[1].txt [ /questionmarket ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@questionmarket[3].txt [ /questionmarket ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@revsci[2].txt [ /revsci ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@secmedia[1].txt [ /secmedia ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@serving-sys[1].txt [ /serving-sys ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@serving-sys[3].txt [ /serving-sys ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@serving-sys[4].txt [ /serving-sys ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@smartadserver[2].txt [ /smartadserver ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@specificclick[1].txt [ /specificclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@specificclick[2].txt [ /specificclick ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@stat.aldi[10].txt [ /stat.aldi ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@stat.aldi[11].txt [ /stat.aldi ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@stat.aldi[1].txt [ /stat.aldi ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@stat.aldi[2].txt [ /stat.aldi ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@stat.aldi[3].txt [ /stat.aldi ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@stat.aldi[4].txt [ /stat.aldi ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@stat.aldi[5].txt [ /stat.aldi ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@stat.aldi[6].txt [ /stat.aldi ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@stat.aldi[7].txt [ /stat.aldi ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@stat.aldi[8].txt [ /stat.aldi ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@stat.aldi[9].txt [ /stat.aldi ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@statse.webtrendslive[2].txt [ /statse.webtrendslive ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@track.effiliation[1].txt [ /track.effiliation ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@track.effiliation[3].txt [ /track.effiliation ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@tracking.hannoversche[1].txt [ /tracking.hannoversche ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@tracking.hannoversche[3].txt [ /tracking.hannoversche ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@tracking.mindshare[1].txt [ /tracking.mindshare ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@tracking.mindshare[2].txt [ /tracking.mindshare ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@tracking.quisma[2].txt [ /tracking.quisma ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@tracking.quisma[3].txt [ /tracking.quisma ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@tradedoubler[1].txt [ /tradedoubler ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@tradedoubler[2].txt [ /tradedoubler ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@tradedoubler[3].txt [ /tradedoubler ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@tradedoubler[5].txt [ /tradedoubler ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@traffictrack[1].txt [ /traffictrack ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@traffictrack[2].txt [ /traffictrack ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@traffictrack[3].txt [ /traffictrack ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@unitymedia[2].txt [ /unitymedia ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@webmasterplan[2].txt [ /webmasterplan ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@www.etracker[1].txt [ /www.etracker ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@www.googleadservices[1].txt [ /www.googleadservices ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@www.zanox-affiliate[1].txt [ /www.zanox-affiliate ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@xiti[1].txt [ /xiti ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@yieldmanager[1].txt [ /yieldmanager ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@zanox-affiliate[1].txt [ /zanox-affiliate ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@zanox-affiliate[2].txt [ /zanox-affiliate ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@zanox-affiliate[3].txt [ /zanox-affiliate ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@zanox[1].txt [ /zanox ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@zanox[3].txt [ /zanox ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@CAW071MP.txt [ /de.sitestat.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\NS3OUN3P.txt [ /imrworldwide.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@de.sitestat[11].txt [ /de.sitestat.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\C8NZZHSN.txt [ /www.googleadservices.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\Z461JBSB.txt [ /adform.net ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\YQPHLVCS.txt [ /webmasterplan.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@de.sitestat[9].txt [ /de.sitestat.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\ORRH4ROI.txt [ /track.adform.net ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\FD19G0V0.txt [ /doubleclick.net ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\8TQJGKM5.txt [ /adx.chip.de ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@de.sitestat[10].txt [ /de.sitestat.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\OEEW37W8.txt [ /www.googleadservices.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\WX8H4NY4.txt [ /adfarm1.adition.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\EUCB02X1.txt [ /questionmarket.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\ESFAVB0G.txt [ /smartadserver.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\19ICS1Q0.txt [ /2o7.net ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\hel@CAB01DX1.txt [ /stat.aldi.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\L9ZI9IE7.txt [ /ad3.adfarm1.adition.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\GBKWA39K.txt [ /ad2.adfarm1.adition.com ]
	C:\Users\Hel\AppData\Roaming\Microsoft\Windows\Cookies\COVOE7GN.txt [ /mediaplex.com ]
	C:\USERS\BOSS\AppData\Roaming\Microsoft\Windows\Cookies\boss@stat.aldi[2].txt [ Cookie:boss@stat.aldi.com/ ]
	C:\USERS\BOSS\AppData\Roaming\Microsoft\Windows\Cookies\Low\boss@msnportal.112.2o7[1].txt [ Cookie:boss@msnportal.112.2o7.net/ ]
	C:\USERS\BOSS\AppData\Roaming\Microsoft\Windows\Cookies\Low\boss@counter.hitslink[1].txt [ Cookie:boss@counter.hitslink.com/ ]
	C:\USERS\BOSS\AppData\Roaming\Microsoft\Windows\Cookies\Low\boss@ad.zanox[1].txt [ Cookie:boss@ad.zanox.com/ ]
	C:\USERS\BOSS\AppData\Roaming\Microsoft\Windows\Cookies\Low\boss@skype.122.2o7[1].txt [ Cookie:boss@skype.122.2o7.net/ ]
	C:\USERS\BOSS\AppData\Roaming\Microsoft\Windows\Cookies\Low\boss@atdmt[2].txt [ Cookie:boss@atdmt.com/ ]
	C:\USERS\BOSS\AppData\Roaming\Microsoft\Windows\Cookies\Low\boss@doubleclick[2].txt [ Cookie:boss@doubleclick.net/ ]
	C:\USERS\BOSS\Cookies\boss@stat.aldi[2].txt [ Cookie:boss@stat.aldi.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@traffictrack[2].txt [ Cookie:hel@traffictrack.de/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@www.googleadservices[2].txt [ Cookie:hel@www.googleadservices.com/pagead/conversion/1036273579/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\6VR6O96C.txt [ Cookie:hel@imrworldwide.com/cgi-bin ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@bs.serving-sys[2].txt [ Cookie:hel@bs.serving-sys.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@nl.sitestat[3].txt [ Cookie:hel@nl.sitestat.com/ibg/ibg/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\RC8MPTNW.txt [ Cookie:hel@www.googleadservices.com/pagead/conversion/1070390966/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@avgtechnologies.112.2o7[1].txt [ Cookie:hel@avgtechnologies.112.2o7.net/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\D6NMNCNH.txt [ Cookie:hel@paypal.112.2o7.net/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@overture[1].txt [ Cookie:hel@overture.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@a7.adserver01[1].txt [ Cookie:hel@a7.adserver01.de/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@de.sitestat[1].txt [ Cookie:hel@de.sitestat.com/is24/is24/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@adserver.budgetmedia[2].txt [ Cookie:hel@adserver.budgetmedia.de/bm/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@myaccount.1601telecom[1].txt [ Cookie:hel@myaccount.1601telecom.nl/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@im.banner.t-online[1].txt [ Cookie:hel@im.banner.t-online.de/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@adviva[1].txt [ Cookie:hel@adviva.net/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@trvlnet.adbureau[1].txt [ Cookie:hel@trvlnet.adbureau.net/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@tradefx.advertserve[1].txt [ Cookie:hel@tradefx.advertserve.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@nl.sitestat[1].txt [ Cookie:hel@nl.sitestat.com/ibg/particulier/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@tto2.traffictrack[2].txt [ Cookie:hel@tto2.traffictrack.de/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@traveladvertising[1].txt [ Cookie:hel@traveladvertising.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\NOH8QHMI.txt [ Cookie:hel@stats.paypal.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@advertising[2].txt [ Cookie:hel@advertising.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@ad.yieldmanager[2].txt [ Cookie:hel@ad.yieldmanager.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@interclick[2].txt [ Cookie:hel@interclick.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@microsoftmachinetranslation.112.2o7[1].txt [ Cookie:hel@microsoftmachinetranslation.112.2o7.net/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@content.yieldmanager[3].txt [ Cookie:hel@content.yieldmanager.com/ak/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@nl.sitestat[5].txt [ Cookie:hel@nl.sitestat.com/ziggo/ziggo/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\706LMZ3N.txt [ Cookie:hel@adfarm1.adition.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@de.at.atwola[1].txt [ Cookie:hel@de.at.atwola.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@traffictrack.3gnet[1].txt [ Cookie:hel@traffictrack.3gnet.de/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZAWYUR1H.txt [ Cookie:hel@specificclick.net/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@cdn5.specificclick[2].txt [ Cookie:hel@cdn5.specificclick.net/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@2o7[1].txt [ Cookie:hel@2o7.net/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@tradedoubler[1].txt [ Cookie:hel@tradedoubler.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@zanox[1].txt [ Cookie:hel@zanox.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@iacas.adbureau[1].txt [ Cookie:hel@iacas.adbureau.net/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\W0WNP7FQ.txt [ Cookie:hel@mediaplex.com/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@microsoftsto.112.2o7[1].txt [ Cookie:hel@microsoftsto.112.2o7.net/ ]
	C:\USERS\HEL\AppData\Roaming\Microsoft\Windows\Cookies\Low\hel@apmebf[1].txt [ Cookie:hel@apmebf.com/ ]
	C:\USERS\HEL\Cookies\hel@traffictrack[3].txt [ Cookie:hel@traffictrack.de/ ]
	C:\USERS\HEL\Cookies\hel@CAW071MP.txt [ Cookie:hel@de.sitestat.com/ndr/ ]
	C:\USERS\HEL\Cookies\hel@www.googleadservices[1].txt [ Cookie:hel@www.googleadservices.com/pagead/conversion/1036273579/ ]
	C:\USERS\HEL\Cookies\NS3OUN3P.txt [ Cookie:hel@imrworldwide.com/cgi-bin ]
	C:\USERS\HEL\Cookies\hel@bs.serving-sys[4].txt [ Cookie:hel@bs.serving-sys.com/ ]
	C:\USERS\HEL\Cookies\hel@tracking.hannoversche[3].txt [ Cookie:hel@tracking.hannoversche.de/ ]
	C:\USERS\HEL\Cookies\hel@de.sitestat[11].txt [ Cookie:hel@de.sitestat.com/ndr/ts/ ]
	C:\USERS\HEL\Cookies\C8NZZHSN.txt [ Cookie:hel@www.googleadservices.com/pagead/conversion/1070390966/ ]
	C:\USERS\HEL\Cookies\hel@avgtechnologies.112.2o7[2].txt [ Cookie:hel@avgtechnologies.112.2o7.net/ ]
	C:\USERS\HEL\Cookies\hel@ad4.adfarm1.adition[2].txt [ Cookie:hel@ad4.adfarm1.adition.com/ ]
	C:\USERS\HEL\Cookies\hel@yieldmanager[1].txt [ Cookie:hel@yieldmanager.net/ ]
	C:\USERS\HEL\Cookies\Z461JBSB.txt [ Cookie:hel@adform.net/ ]
	C:\USERS\HEL\Cookies\hel@overture[1].txt [ Cookie:hel@overture.com/ ]
	C:\USERS\HEL\Cookies\hel@de.sitestat[9].txt [ Cookie:hel@de.sitestat.com/is24-mail/is24-mail/ ]
	C:\USERS\HEL\Cookies\hel@adviva[2].txt [ Cookie:hel@adviva.net/ ]
	C:\USERS\HEL\Cookies\ORRH4ROI.txt [ Cookie:hel@track.adform.net/ ]
	C:\USERS\HEL\Cookies\hel@xiti[1].txt [ Cookie:hel@xiti.com/ ]
	C:\USERS\HEL\Cookies\8TQJGKM5.txt [ Cookie:hel@adx.chip.de/ ]
	C:\USERS\HEL\Cookies\hel@de.sitestat[10].txt [ Cookie:hel@de.sitestat.com/sueddeutsche/sueddeutsche/ ]
	C:\USERS\HEL\Cookies\hel@ad.yieldmanager[4].txt [ Cookie:hel@ad.yieldmanager.com/ ]
	C:\USERS\HEL\Cookies\hel@content.yieldmanager[8].txt [ Cookie:hel@content.yieldmanager.com/ak/ ]
	C:\USERS\HEL\Cookies\WX8H4NY4.txt [ Cookie:hel@adfarm1.adition.com/ ]
	C:\USERS\HEL\Cookies\EUCB02X1.txt [ Cookie:hel@questionmarket.com/ ]
	C:\USERS\HEL\Cookies\hel@invitemedia[1].txt [ Cookie:hel@invitemedia.com/ ]
	C:\USERS\HEL\Cookies\hel@ad1.adfarm1.adition[2].txt [ Cookie:hel@ad1.adfarm1.adition.com/ ]
	C:\USERS\HEL\Cookies\hel@specificclick[1].txt [ Cookie:hel@specificclick.net/ ]
	C:\USERS\HEL\Cookies\ESFAVB0G.txt [ Cookie:hel@smartadserver.com/ ]
	C:\USERS\HEL\Cookies\hel@adinterax[3].txt [ Cookie:hel@adinterax.com/ ]
	C:\USERS\HEL\Cookies\19ICS1Q0.txt [ Cookie:hel@2o7.net/ ]
	C:\USERS\HEL\Cookies\L9ZI9IE7.txt [ Cookie:hel@ad3.adfarm1.adition.com/ ]
	C:\USERS\HEL\Cookies\hel@tradedoubler[5].txt [ Cookie:hel@tradedoubler.com/ ]
	C:\USERS\HEL\Cookies\COVOE7GN.txt [ Cookie:hel@mediaplex.com/ ]
	C:\USERS\HEL\Cookies\hel@tracking.quisma[3].txt [ Cookie:hel@tracking.quisma.com/ ]
	C:\USERS\HEL\Cookies\hel@apmebf[3].txt [ Cookie:hel@apmebf.com/ ]
	C:\USERS\BOSS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\BOSS@STAT.ALDI[1].TXT [ /STAT.ALDI ]
	C:\USERS\HEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HEL@AD.BOREUS[1].TXT [ /AD.BOREUS ]
	C:\USERS\HEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HEL@ADS.PARTNERBRIDGE[2].TXT [ /ADS.PARTNERBRIDGE ]
	C:\USERS\HEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HEL@ATDMT[2].TXT [ /ATDMT ]
	C:\USERS\HEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HEL@CONTENT.YIELDMANAGER[2].TXT [ /CONTENT.YIELDMANAGER ]
	C:\USERS\HEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HEL@COUNT.SPRING[1].TXT [ /COUNT.SPRING ]
	C:\USERS\HEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HEL@GUJ.122.2O7[1].TXT [ /GUJ.122.2O7 ]
	C:\USERS\HEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HEL@MSNPORTAL.112.2O7[1].TXT [ /MSNPORTAL.112.2O7 ]
	C:\USERS\HEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HEL@REVSCI[2].TXT [ /REVSCI ]
	C:\USERS\HEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HEL@SERVING-SYS[2].TXT [ /SERVING-SYS ]
	C:\USERS\HEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HEL@STAT.ALDI[1].TXT [ /STAT.ALDI ]
	C:\USERS\HEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HEL@USAIRWAYS.112.2O7[1].TXT [ /USAIRWAYS.112.2O7 ]
	C:\USERS\HEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HEL@ZANOX-AFFILIATE[1].TXT [ /ZANOX-AFFILIATE ]
	nl.sitestat.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad1.emediate.dk [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.eurostar.122.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.count.spring.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.creativdiscount.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.creativdiscount.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.creativdiscount.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	tracking.mlsat02.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.guj.122.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.gostats.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	nl.sitestat.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.unitymedia.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.daimlerag.122.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adxpose.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.a.revenuemax.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	track.effiliation.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.e-2dj6wdlyooajmhp.stats.esomniture.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.paypal.112.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	nl.sitestat.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	nl.sitestat.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	nl.sitestat.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.getclicky.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.static.getclicky.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	in.getclicky.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.c.atdmt.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.c.atdmt.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.trafficmp.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.trafficmp.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.trafficmp.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	banners.sys-con.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	banners.sys-con.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.weborama.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.gsmweb.solution.weborama.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.gsmweb.solution.weborama.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.gsmweb.solution.weborama.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.gsmweb.solution.weborama.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	beacons.hottraffic.nl [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	tracking.tchibo.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	go.dynamic-tracking.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.accounts.google.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.accounts.google.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.accounts.google.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.accounts.google.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	teufel-media.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.blau.122.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad1.dyntracker.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.horyzon-media.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.horyzon-media.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.horyzon-media.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.horyzon-media.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.horyzon-media.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.euros4click.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.liveperson.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.overture.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad.zanox.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	urbia.wwe-media.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	media.laredoute.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.deutschepostag.112.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.e-2dj6wjlyujajgco.stats.esomniture.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.ru4.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ads.247activemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	adsrv1.admediate.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.yieldmanager.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.lucidmedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.ru4.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ox-d.coedmediagroup.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.xm.xtendmedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tribalfusion.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ads.adxvalue.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ads.adxvalue.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ads.adxvalue.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ads.adxvalue.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	s0.2mdn.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ohra.adservinginternational.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.s0.2mdn.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	s0.2mdn.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	s0.2mdn.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tracking.mindshare.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.skydeutschland.122.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adviva.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.liveperson.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	s0.2mdn.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.xiti.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adxvalue.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.bluemango.solution.weborama.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.bluemango.solution.weborama.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.bluemango.solution.weborama.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.bluemango.solution.weborama.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.hottraffic.nl [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	xml.hottraffic.nl [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.vodafonebranding.solution.weborama.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.vodafonebranding.solution.weborama.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.vodafonebranding.solution.weborama.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.vodafonebranding.solution.weborama.fr [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.bt.ilsemedia.nl [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.bt.ilsemedia.nl [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.dyntracker.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.conrad.122.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	banner.testberichte.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.usenext.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.bs.serving-sys.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.bs.serving-sys.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.msnportal.112.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.microsoftsto.112.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.pro-market.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	partners.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.liveperson.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	server.lon.liveperson.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.zanox-affiliate.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad.dyntracker.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	accounts.youtube.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad4.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad1.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adform.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.avgtechnologies.112.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	accounts.google.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.hightraffic.hugoboss.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.hightraffic.hugoboss.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.hightraffic.hugoboss.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad.adserver01.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.histats.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.histats.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.zanox-affiliate.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.hitbox.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.hitbox.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.ehg-adversitement.hitbox.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad1.emediate.dk [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.unitymedia.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.unitymedia.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ww251.smartadserver.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad3.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad.zanox.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.zanox.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad1.emediate.dk [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad2.adfarm1.adition.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.clickfuse.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.fastclick.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	track.effiliation.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	track.effiliation.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	track.effiliation.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	track.effiliation.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	track.effiliation.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.gostats.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.statcounter.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	www.etracker.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\HEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C64CSABM.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-Bancos
	C:\_OTL\MOVEDFILES\11202011_165244\C_PROGRAM FILES\PREISPIRATEN6\IEBUTTONEBAYINTERFACE.DLL
         
Zum SUPERAntiSpyware Log hätte ich noch zwei Fragen:
1. kann ich die in C:\_OTL gespeicherte Datei löschen
2. Was kann ich gegen die ganzen Tracking Cookies tun?

Auf jeden Fall bin ich sehr erleichtert, dass der PC jetzt wieder OK aussieht. . Ich bin sehr beeindruckt, wie souverän Du das Problem gelöst hast . Vielen, vielen Dank!
Jetzt würde mich nur noch interessieren, wie ich in Zukunft solche Infektionen vermeiden kann. Ich denke ich muss mich mal tiefer in die Materie einlesen. Für eine <unterstützung dabei wäre ich natürlich dankbar.

Herzliche Grüße
Islandis

Alt 22.11.2011, 09:18   #22
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Bundespolizei Virus/Trojaner - Standard

Bundespolizei Virus/Trojaner



Zitat:
Malwarebyte konnte ich leider nicht aktualisieren. Kann das sein, dass das an der freeware liegt und die nur alle x Tage eine Aktualisierung zulassen?
Nein. Bitte beachten => http://www.trojaner-board.de/94344-p...n-pruefen.html

Zitat:
1. kann ich die in C:\_OTL gespeicherte Datei löschen
2. Was kann ich gegen die ganzen Tracking Cookies tun?
löschen
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 22.11.2011, 10:57   #23
Islandis
 
Bundespolizei Virus/Trojaner - Standard

Bundespolizei Virus/Trojaner



Hallo Arne,

wenn ich malwarebyte offne und auf aktualisieren gehe, dann ist das Feld Suche nach Aktualisierungen "greyed out" und ohne Funktion (siehe Anlage).

Die Proxyeinstellungen entsprechen den Empfehlungen (aus OTL-Log):

Code:
ATTFilter
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
         
ansonsten funktioniert Firefox o. Probleme.

Ich werd jetzt mal malwarebyte deinstallieren und neu installieren. Mal sehen was passiert.

Wie kann ich denn die Tracking cookies verhindern?

Grüße
Islandis
Miniaturansicht angehängter Grafiken
Bundespolizei Virus/Trojaner-malware_akltualisierg.jpg  

Alt 22.11.2011, 13:36   #24
Islandis
 
Bundespolizei Virus/Trojaner - Standard

Bundespolizei Virus/Trojaner



Hallo Arne,

deinstallieren und Neuinstallation Malwarebytes hat funktioniert und konnte aktualisiert werden. Allerdings nur einmal. Inzwischen ist der Button wieder greyed out.

Hier das Log:

Code:
ATTFilter
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8213

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

22.11.2011 13:24:36
mbam-log-2011-11-22 (13-24-11).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 336822
Laufzeit: 44 Minute(n), 27 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vasja (Trojan.RansomP.Gen) -> Value: vasja -> No action taken.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)
         
Wahrscheinlich habe ich jetzt auch noch einen Fehler gemacht. Ich habe dummerweise auf Auswahl entfernen gedrückt. MWB hat gemeldet, dass der Regeintrag entfernt wurde. Sorry dafür.

Was lässt sich nun noch tun?

Danke schon mal
Grüße Islandis

P.S. ich lass in der Zwischenzeit nochmal einen Scan laufen

Nachtrag: Der "gelöschte" Eintrag befindet sich in der Qurantäne (siehe Anlage)
Miniaturansicht angehängter Grafiken
Bundespolizei Virus/Trojaner-mwb_q_20111122.jpg  

Alt 22.11.2011, 14:21   #25
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Bundespolizei Virus/Trojaner - Standard

Bundespolizei Virus/Trojaner



Zitat:
Wie kann ich denn die Tracking cookies verhindern?
Indem du den Browser so einstellst, dass er immer nachfragt, ob du Cookies annehmen willst. => dann poppt bei dem Seiten besuch immer eine Cookiesanfrage auf
Oder: Du löscht bei jedem Beenden die Cookies. Dann musst du dich bei jeder Seite aber auch immer wieder manuell neu einloggen (Trojaner-Board, Facebook, usw. usf)

Zitat:
Ich habe dummerweise auf Auswahl entfernen gedrückt. MWB hat gemeldet, dass der Regeintrag entfernt wurde. Sorry dafür.
Anleitung nicht gelesen? Das ist richtig so, die Funde sollen mit Malwarebytes entfernt werden!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 22.11.2011, 16:35   #26
Islandis
 
Bundespolizei Virus/Trojaner - Standard

Bundespolizei Virus/Trojaner



Hallo Arne,

danke für die Antwort. Ich hatte mich nur an den Satz erinnert, dass ohne Anweisung keine Maßnahmen ergriffen werden sollen.

Sind wir dann mit dem Problem durch und das System wider sauber? Auf jeden Fall herzlichen Dank für die hervorragende Betreuung.



Herzliche Grüße
Islandis

Alt 22.11.2011, 17:34   #27
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Bundespolizei Virus/Trojaner - Standard

Bundespolizei Virus/Trojaner



Dann wären wir durch!

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 22.11.2011, 21:11   #28
Islandis
 
Bundespolizei Virus/Trojaner - Daumen hoch

Bundespolizei Virus/Trojaner



Hallo mein lieber Arne,

ich habe Deine Vorschläge nun umgesetzt. Vielen Dank noch mal für die Geduld mit mir.

Nun muss ich nur noch Paragon für ein Backup nutzen und dann müsste alles OK sein.

Also noch mals vielen Dank. Ich hoffe sehr dich nicht mehr bemühen zu müssen.

Herzliche Grüße

Ciao
Islandis

Antwort

Themen zu Bundespolizei Virus/Trojaner
adobe, antivirus, askbar, avg, avg antivirus, avg security toolbar, bho, bundespolizei, bundestrojaner, c:\windows\system32\rundll32.exe, defender, eraser, firefox, format, google earth, home, infizierte, infizierte dateien, installation, logfile, msiexec, nvlddmkm.sys, plug-in, programm, realtek, registry, required, rundll, scan, security, software, studio, superantispyware, t-mobile, udp, upd.exe, updates, usb, usb 2.0, version=1.0, viren, virus/trojaner, vista




Ähnliche Themen: Bundespolizei Virus/Trojaner


  1. Bundespolizei Virus/Trojaner
    Log-Analyse und Auswertung - 05.01.2014 (5)
  2. Umfrage zur Schadsoftware des sog. "BKA-, GVU-, GEMA-, Bundespolizei-Virus/Trojaner"
    Diskussionsforum - 17.11.2013 (4)
  3. Virus Bundespolizei/Trojaner
    Plagegeister aller Art und deren Bekämpfung - 18.08.2013 (15)
  4. Bundespolizei-Virus/Trojaner
    Log-Analyse und Auswertung - 15.12.2012 (13)
  5. Der Bundespolizei-Virus/Trojaner-wie werde ich ihn los?
    Plagegeister aller Art und deren Bekämpfung - 17.10.2012 (9)
  6. Bundespolizei Virus,Ucash Trojaner ?
    Plagegeister aller Art und deren Bekämpfung - 11.09.2012 (1)
  7. Bundespolizei Virus / Trojaner vom 11.8. wirklich durch Systemwiederherstellung entfernt?
    Log-Analyse und Auswertung - 22.08.2012 (19)
  8. Virus/Trojaner von der Bundespolizei
    Log-Analyse und Auswertung - 30.07.2012 (2)
  9. Bundespolizei Virus/trojaner
    Plagegeister aller Art und deren Bekämpfung - 30.07.2012 (6)
  10. Trojaner / Virus - Bundespolizei Einheit 5.2 - 100 Euro...
    Plagegeister aller Art und deren Bekämpfung - 19.07.2012 (10)
  11. Virus/Trojaner Bundespolizei
    Plagegeister aller Art und deren Bekämpfung - 17.07.2012 (1)
  12. Bundespolizei Virus Trojaner
    Plagegeister aller Art und deren Bekämpfung - 19.06.2012 (1)
  13. Trojaner/Virus: Bundespolizei verlangt 100€ via Ukash
    Plagegeister aller Art und deren Bekämpfung - 02.04.2012 (13)
  14. Bundespolizei - Virus, Trojaner: Wie entfernen?
    Plagegeister aller Art und deren Bekämpfung - 13.03.2012 (1)
  15. Trojaner/Virus: Bundespolizei verlangt 100€
    Plagegeister aller Art und deren Bekämpfung - 10.03.2012 (12)
  16. Bundespolizei Virus / Trojaner eingefangen und total hilflos :-( PC immer noch "gefährdet"
    Plagegeister aller Art und deren Bekämpfung - 08.10.2011 (1)
  17. Bundespolizei Virus / Trojaner - Entfernung
    Plagegeister aller Art und deren Bekämpfung - 06.06.2011 (1)

Zum Thema Bundespolizei Virus/Trojaner - Combofix - Scripten 1. Starte das Notepad (Start / Ausführen / notepad[Enter]) 2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein. Code: Alles - Bundespolizei Virus/Trojaner...
Archiv
Du betrachtest: Bundespolizei Virus/Trojaner auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.