Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 20.02.2012, 19:09   #16
Franzi87
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



ok das combofix log schaut so aus.

Code:
ATTFilter
ComboFix 12-02-19.02 - Franzi 20.02.2012  18:41:07.1.4 - x64
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.49.1031.18.3956.2471 [GMT 1:00]
ausgeführt von:: c:\users\Franzi\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Common Files\packardbell.ico
c:\programdata\FullRemove.exe
c:\users\Franzi\AppData\Roaming\Local
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-01-20 bis 2012-02-20  ))))))))))))))))))))))))))))))
.
.
2012-02-20 17:50 . 2012-02-20 17:50	--------	d-----w-	c:\users\Default\AppData\Local\temp
2012-02-19 15:55 . 2012-02-20 10:59	--------	d-----r-	c:\users\Franzi\Dropbox
2012-02-19 15:53 . 2012-02-20 10:59	--------	d-----w-	c:\users\Franzi\AppData\Roaming\Dropbox
2012-02-14 20:03 . 2012-01-04 09:58	509952	----a-w-	c:\windows\system32\ntshrui.dll
2012-02-14 20:03 . 2012-01-04 09:03	442880	----a-w-	c:\windows\SysWow64\ntshrui.dll
2012-02-14 20:03 . 2012-01-03 06:24	515584	----a-w-	c:\windows\system32\timedate.cpl
2012-02-14 20:03 . 2012-01-03 05:44	478208	----a-w-	c:\windows\SysWow64\timedate.cpl
2012-02-14 20:03 . 2012-01-14 04:02	3143168	----a-w-	c:\windows\system32\win32k.sys
2012-02-14 20:02 . 2011-12-28 03:59	499200	----a-w-	c:\windows\system32\drivers\afd.sys
2012-02-14 20:02 . 2011-12-16 08:42	634368	----a-w-	c:\windows\system32\msvcrt.dll
2012-02-14 20:02 . 2011-12-16 07:59	690688	----a-w-	c:\windows\SysWow64\msvcrt.dll
2012-02-12 17:16 . 2012-02-12 17:16	--------	d-----w-	c:\program files (x86)\ESET
2012-02-12 15:43 . 2012-02-12 15:43	--------	d-----w-	c:\users\Franzi\AppData\Roaming\Malwarebytes
2012-02-12 15:43 . 2012-02-12 15:43	--------	d-----w-	c:\programdata\Malwarebytes
2012-02-12 15:43 . 2012-02-12 15:43	--------	d-----w-	c:\program files (x86)\Malwarebytes' Anti-Malware
2012-02-12 15:43 . 2011-12-10 14:24	23152	----a-w-	c:\windows\system32\drivers\mbam.sys
2012-02-12 11:16 . 2012-02-12 11:16	--------	d-----w-	C:\_OTL
2012-02-12 07:46 . 2012-02-09 10:59	35648	----a-w-	c:\windows\system32\uxtuneup.dll
2012-02-12 07:46 . 2012-02-09 10:59	28992	----a-w-	c:\windows\SysWow64\uxtuneup.dll
2012-02-09 07:20 . 2012-02-09 10:59	34624	----a-w-	c:\windows\system32\TURegOpt.exe
2012-02-09 07:20 . 2012-02-09 10:59	21312	----a-w-	c:\windows\SysWow64\authuitu.dll
2012-02-09 07:20 . 2012-02-09 10:59	25920	----a-w-	c:\windows\system32\authuitu.dll
2012-02-09 07:19 . 2012-02-12 07:46	--------	d-----w-	c:\program files (x86)\TuneUp Utilities 2012
2012-02-09 07:17 . 2012-02-09 07:17	--------	d-sh--w-	c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2012-02-05 16:09 . 2012-02-08 13:11	--------	d-----w-	c:\users\Franzi\AppData\Roaming\toolplugin
2012-01-31 15:15 . 2012-01-31 15:15	--------	d-----w-	c:\program files (x86)\icq
2012-01-31 15:15 . 2012-01-31 15:15	--------	d-----w-	c:\program files (x86)\Guard-ICQ
2012-01-31 15:12 . 2012-01-31 15:16	--------	d-----w-	c:\program files (x86)\ICQ7.7
2012-01-29 10:23 . 2012-01-29 10:26	--------	d-----w-	c:\users\Franzi\10f5h
2012-01-29 10:23 . 2012-01-29 10:23	--------	d-----w-	c:\program files (x86)\HERDT
2012-01-22 09:43 . 2012-01-22 09:44	--------	d-----w-	c:\program files\iTunes
2012-01-22 09:43 . 2012-01-22 09:44	--------	d-----w-	c:\program files (x86)\iTunes
2012-01-22 09:43 . 2012-01-22 09:43	--------	d-----w-	c:\program files\iPod
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-15 18:45 . 2011-10-23 07:43	132320	----a-w-	c:\windows\system32\drivers\avipbb.sys
2012-01-26 23:52 . 2010-03-14 09:30	279656	------w-	c:\windows\system32\MpSigStub.exe
2012-01-08 08:42 . 2011-05-27 03:59	414368	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-01-06 05:15 . 2012-02-17 17:52	8602168	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{C11B4F42-FE57-4BDD-9927-41D2D68ECA52}\mpengine.dll
2011-12-01 13:57 . 2011-12-01 13:57	163840	----a-w-	c:\windows\LgxSetup.exe
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58	94208	----a-w-	c:\users\Franzi\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58	94208	----a-w-	c:\users\Franzi\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58	94208	----a-w-	c:\users\Franzi\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-05 39408]
"ICQ"="c:\program files (x86)\ICQ7.7\ICQ.exe" [2012-01-31 127040]
"TomTomHOME.exe"="c:\program files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [2011-04-22 247728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2009-11-01 1094736]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"SMART Board Service"="c:\program files (x86)\SMART Technologies\SMART Product Drivers\SMARTBoardService.exe" [2010-07-15 5350288]
"SMART SNMP Agent"="c:\program files (x86)\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe" [2010-07-15 1662352]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-10-11 258512]
"CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"IJNetworkScanUtility"="c:\program files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2010-03-02 140640]
"Guard.Mail.ru.gui"="c:\program files (x86)\Guard-ICQ\GuardICQ.exe" [2012-01-31 1564368]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"Camera Assistant Software"="c:\program files (x86)\Video Web Camera\traybar.exe" [2009-12-03 600688]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
c:\users\Franzi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Franzi\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-15 24246216]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"HP Software Update"=c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"ArcSoft Connection Service"=c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" -h -k
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-15 135664]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-15 135664]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 OberonGameConsoleService;Oberon Media Game Console service;c:\program files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe [2009-08-29 44312]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 vnet;Shrew Soft Virtual Adapter;c:\windows\system32\DRIVERS\virtualnet.sys [x]
R3 WSDPrintDevice;WSD-Druckunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]
R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDScan.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 vflt;Shrew Soft Lightweight Filter;c:\windows\system32\DRIVERS\vfilter.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-08 169312]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-11 86224]
S2 dtpd;ShrewSoft DNS Proxy Daemon;c:\program files\ShrewSoft\VPN Client\dtpd.exe [2009-11-15 50688]
S2 ePowerSvc;Acer ePower Service;c:\program files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [2009-09-30 844320]
S2 Greg_Service;GRegService;c:\program files (x86)\Packard Bell\Registration\GregHSRW.exe [2009-08-28 1150496]
S2 Guard.Mail.ru;Guard.Mail.ru;c:\program files (x86)\Guard-ICQ\GuardICQ.exe [2012-01-31 1564368]
S2 ICQ Service;ICQ Service;c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe [2011-08-17 247872]
S2 iked;ShrewSoft IKE Daemon;c:\program files\ShrewSoft\VPN Client\iked.exe [2009-11-15 948224]
S2 ipsecd;ShrewSoft IPSEC Daemon;c:\program files\ShrewSoft\VPN Client\ipsecd.exe [2009-11-15 690688]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [2009-09-24 62720]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2012-02-09 2143552]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2320920]
S2 Updater Service;Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2009-07-04 240160]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 SMARTMouseFilterx64;HID-compliant mouse;c:\windows\system32\DRIVERS\SMARTMouseFilterx64.sys [x]
S3 SMARTVHidMiniVistaAmd64;SMART HID Device;c:\windows\system32\DRIVERS\SMARTVHidMiniVistaAmd64.sys [x]
S3 SMARTVTabletPCx64;SMART Virtual TabletPC;c:\windows\system32\DRIVERS\SMARTVTabletPCx64.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [2012-02-01 11856]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt	REG_MULTI_SZ   	hpqcxs08
.
Inhalt des "geplante Tasks" Ordners
.
2012-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-15 12:26]
.
2012-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-15 12:26]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58	97792	----a-w-	c:\users\Franzi\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58	97792	----a-w-	c:\users\Franzi\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58	97792	----a-w-	c:\users\Franzi\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58	97792	----a-w-	c:\users\Franzi\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-29 8312352]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-05-22 295936]
"PLFSetI"="c:\windows\PLFSetI.exe" [2009-11-20 200704]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-24 2726728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
UxTuneUp
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = 
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&m=easynote_tj75&r=27360310h9c6l0490z135f4431y248
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files (x86)\ICQ7.7\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Franzi\AppData\Roaming\Mozilla\Firefox\Profiles\9l632w5o.default\
FF - prefs.js: browser.search.defaulturl - 
FF - prefs.js: browser.search.selectedEngine - 
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/webhp?hl=de
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-02-20  19:01:22 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-02-20 18:01
.
Vor Suchlauf: 15 Verzeichnis(se), 385.688.162.304 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 385.170.841.600 Bytes frei
.
- - End Of File - - E8CA49C32A7D7835E7020AFD4D6C2224
         

Alt 20.02.2012, 21:19   #17
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehlalarm!
  • Starte die aswMBR.exe Vista und Win7 User aswMBR per Rechtsklick "als Administrator ausführen"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.
__________________

__________________

Alt 24.02.2012, 15:22   #18
Franzi87
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



Habe alles genauso gemacht hier ist das Log:

Code:
ATTFilter
aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-02-24 14:24:45
-----------------------------
14:24:45.309    OS Version: Windows x64 6.1.7600 
14:24:45.309    Number of processors: 4 586 0x2502
14:24:45.309    ComputerName: FRANZI-PC  UserName: Franzi
14:24:46.541    Initialize success
14:25:53.154    AVAST engine defs: 12022400
14:26:03.653    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
14:26:03.653    Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3
14:26:03.669    Disk 0 MBR read successfully
14:26:03.684    Disk 0 MBR scan
14:26:03.684    Disk 0 Windows VISTA default MBR code
14:26:03.700    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS        12000 MB offset 2048
14:26:03.715    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 24578048
14:26:03.731    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       464838 MB offset 24782848
14:26:03.762    Disk 0 scanning C:\Windows\system32\drivers
14:26:14.682    Service scanning
14:26:44.385    Modules scanning
14:26:44.400    Disk 0 trace - called modules:
14:26:44.432    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys spoz.sys hal.dll 
14:26:44.447    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c97060]
14:26:44.463    3 CLASSPNP.SYS[fffff88001b5943f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004963050]
14:26:46.163    AVAST engine scan C:\Windows
14:26:50.718    AVAST engine scan C:\Windows\system32
14:30:19.230    AVAST engine scan C:\Windows\system32\drivers
14:30:31.367    AVAST engine scan C:\Users\Franzi
14:34:59.157    File: C:\Users\Franzi\AppData\Local\Mozilla\Firefox\firefox.exe  **INFECTED** Win32:LockScreen-DG [Trj]
14:43:52.011    AVAST engine scan C:\ProgramData
14:59:54.890    Scan finished successfully
15:20:55.293    Disk 0 MBR has been saved successfully to "C:\Users\Franzi\Desktop\MBR.dat"
15:20:55.308    The log file has been saved successfully to "C:\Users\Franzi\Desktop\aswMBR.txt"
         
__________________

Alt 24.02.2012, 15:58   #19
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



Zitat:
C:\Users\Franzi\AppData\Local\Mozilla\Firefox\firefox.exe
Bitte diesen Schädling, der sich als firefox.exe tarnt löschen. Das kannst du manuell machen
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 24.02.2012, 18:11   #20
Franzi87
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



ok die Anwendung ist gelöscht.


Alt 24.02.2012, 19:10   #21
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



Mach bitte ein neues Log mit aswMBR. Will nur sichergehen, dass es die gefakte firefox.exe nicht mehr sieht
__________________
--> Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung

Alt 24.02.2012, 20:23   #22
Franzi87
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



Hier ist das neue Log:


Code:
ATTFilter
aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-02-24 19:38:34
-----------------------------
19:38:34.073    OS Version: Windows x64 6.1.7600 
19:38:34.073    Number of processors: 4 586 0x2502
19:38:34.073    ComputerName: FRANZI-PC  UserName: Franzi
19:38:35.727    Initialize success
19:38:42.544    AVAST engine defs: 12022400
19:39:07.239    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:39:07.239    Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3
19:39:07.286    Disk 0 MBR read successfully
19:39:07.286    Disk 0 MBR scan
19:39:07.286    Disk 0 Windows VISTA default MBR code
19:39:07.301    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS        12000 MB offset 2048
19:39:07.332    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 24578048
19:39:07.348    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       464838 MB offset 24782848
19:39:07.442    Disk 0 scanning C:\Windows\system32\drivers
19:39:36.801    Service scanning
19:40:05.973    Modules scanning
19:40:05.989    Disk 0 trace - called modules:
19:40:06.067    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys spoz.sys hal.dll 
19:40:06.581    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c97060]
19:40:06.581    3 CLASSPNP.SYS[fffff88001b5943f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004963050]
19:40:08.703    AVAST engine scan C:\Windows
19:40:35.769    AVAST engine scan C:\Windows\system32
19:50:15.125    AVAST engine scan C:\Windows\system32\drivers
19:50:27.730    AVAST engine scan C:\Users\Franzi
20:05:33.096    AVAST engine scan C:\ProgramData
20:17:46.860    Scan finished successfully
20:21:31.812    Disk 0 MBR has been saved successfully to "C:\Users\Franzi\Desktop\MBR.dat"
20:21:31.859    The log file has been saved successfully to "C:\Users\Franzi\Desktop\aswMBR.txt"
20:22:02.747    Disk 0 MBR has been saved successfully to "C:\Users\Franzi\Desktop\MBR.dat"
20:22:02.747    The log file has been saved successfully to "C:\Users\Franzi\Desktop\aswMBR1.txt"
         

Alt 24.02.2012, 20:32   #23
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 25.02.2012, 09:06   #24
Franzi87
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



danke für die schnelle Antwort bin leider erstmal ne Woche im Urlaub und meld mich dann wieder

Alt 05.03.2012, 11:53   #25
Franzi87
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



So bin jetzt wieder da hier die Logdatei von Malwarebytes.

Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.05.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Franzi :: FRANZI-PC [Administrator]

Schutz: Aktiviert

05.03.2012 09:54:40
mbam-log-2012-03-05 (11-51-49).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 488708
Laufzeit: 1 Stunde(n), 13 Minute(n), 9 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\Franzi\Downloads\FLVPlayerSetup.exe (Adware.Agent) -> Keine Aktion durchgeführt.

(Ende)
         

Alt 05.03.2012, 14:17   #26
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



Aus welcher Quelle hast du diese Datei => C:\Users\Franzi\Downloads\FLVPlayerSetup.exe

Und das Log von SUPERAntiSpyware fehlt noch
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 05.03.2012, 15:17   #27
Franzi87
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



Und hier noch das Log von SuperAntiSpyware:

Code:
ATTFilter
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 03/05/2012 at 02:41 PM

Application Version : 5.0.1144

Core Rules Database Version : 8302
Trace Rules Database Version: 6114

Scan type       : Complete Scan
Total Scan Time : 02:41:35

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Administrator

Memory items scanned      : 665
Memory threats detected   : 0
Registry items scanned    : 66435
Registry threats detected : 0
File items scanned        : 287598
File threats detected     : 438

Adware.Tracking Cookie
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\GHASRWYJ.txt [ /mediaplex.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\0DLR9MIX.txt [ /smartadserver.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\BLOREWNB.txt [ /specificclick.net ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\EC98W23M.txt [ /doubleclick.net ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\712ATI99.txt [ /ad2.adfarm1.adition.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\X1UO8I8T.txt [ /ad.yieldmanager.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\HTG7MZ95.txt [ /zanox.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\2ZX0G9Q0.txt [ /serving-sys.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\DW5TSV44.txt [ /adtech.de ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\4NSPKYXS.txt [ /ad.adserver01.de ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\KNVA9Q33.txt [ /adserv.kwick.de ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\LFXMD63P.txt [ /tradedoubler.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\Y8D6MQQY.txt [ /yieldmanager.net ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\TDZV2MFE.txt [ /ad1.adfarm1.adition.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\RIRELRU4.txt [ /eyewonder.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\03NI33E0.txt [ /adform.net ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\O7UNWP90.txt [ /fastclick.net ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\9EO7SDDF.txt [ /atdmt.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\8G44829P.txt [ /track.adform.net ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\GTFIOO8V.txt [ /webmasterplan.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\D2T4CICU.txt [ /ad.360yield.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\6NO8DEKY.txt [ /tracking.quisma.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\UFGXY80S.txt [ /ad.zanox.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\SROQQ11L.txt [ /imrworldwide.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\9ZPDE6A2.txt [ /ad.ad-srv.net ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\DHN6IXLI.txt [ /ad4.adfarm1.adition.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\TW1CB4BH.txt [ /unitymedia.de ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\HARUDS6N.txt [ /adbrite.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\IC2TNIV3.txt [ /apmebf.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\X69KCHBG.txt [ /ad.adc-serv.net ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\AF3RASJX.txt [ /ads.creative-serving.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\5EW0TTZX.txt [ /adfarm1.adition.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\4DPTD3GF.txt [ /invitemedia.com ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\TL4F63O1.txt [ /revsci.net ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\L68Y87GL.txt [ /ads.spinsoft.de ]
	C:\Users\Franzi\AppData\Roaming\Microsoft\Windows\Cookies\N9551VHY.txt [ /ad3.adfarm1.adition.com ]
	C:\USERS\FRANZI\Cookies\GHASRWYJ.txt [ Cookie:franzi@mediaplex.com/ ]
	C:\USERS\FRANZI\Cookies\BLOREWNB.txt [ Cookie:franzi@specificclick.net/ ]
	C:\USERS\FRANZI\Cookies\EC98W23M.txt [ Cookie:franzi@doubleclick.net/ ]
	C:\USERS\FRANZI\Cookies\HTG7MZ95.txt [ Cookie:franzi@zanox.com/ ]
	C:\USERS\FRANZI\Cookies\DW5TSV44.txt [ Cookie:franzi@adtech.de/ ]
	C:\USERS\FRANZI\Cookies\4NSPKYXS.txt [ Cookie:franzi@ad.adserver01.de/ ]
	C:\USERS\FRANZI\Cookies\KNVA9Q33.txt [ Cookie:franzi@adserv.kwick.de/ ]
	C:\USERS\FRANZI\Cookies\LFXMD63P.txt [ Cookie:franzi@tradedoubler.com/ ]
	C:\USERS\FRANZI\Cookies\Y8D6MQQY.txt [ Cookie:franzi@yieldmanager.net/ ]
	C:\USERS\FRANZI\Cookies\TDZV2MFE.txt [ Cookie:franzi@ad1.adfarm1.adition.com/ ]
	C:\USERS\FRANZI\Cookies\RIRELRU4.txt [ Cookie:franzi@eyewonder.com/ ]
	C:\USERS\FRANZI\Cookies\03NI33E0.txt [ Cookie:franzi@adform.net/ ]
	C:\USERS\FRANZI\Cookies\O7UNWP90.txt [ Cookie:franzi@fastclick.net/ ]
	C:\USERS\FRANZI\Cookies\9EO7SDDF.txt [ Cookie:franzi@atdmt.com/ ]
	C:\USERS\FRANZI\Cookies\8G44829P.txt [ Cookie:franzi@track.adform.net/ ]
	C:\USERS\FRANZI\Cookies\6NO8DEKY.txt [ Cookie:franzi@tracking.quisma.com/ ]
	C:\USERS\FRANZI\Cookies\SROQQ11L.txt [ Cookie:franzi@imrworldwide.com/cgi-bin ]
	C:\USERS\FRANZI\Cookies\TW1CB4BH.txt [ Cookie:franzi@unitymedia.de/ ]
	C:\USERS\FRANZI\Cookies\HARUDS6N.txt [ Cookie:franzi@adbrite.com/ ]
	C:\USERS\FRANZI\Cookies\IC2TNIV3.txt [ Cookie:franzi@apmebf.com/ ]
	C:\USERS\FRANZI\Cookies\5EW0TTZX.txt [ Cookie:franzi@adfarm1.adition.com/ ]
	C:\USERS\FRANZI\Cookies\4DPTD3GF.txt [ Cookie:franzi@invitemedia.com/ ]
	C:\USERS\FRANZI\Cookies\N9551VHY.txt [ Cookie:franzi@ad3.adfarm1.adition.com/ ]
	.apmebf.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	track.effiliation.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	fl01.ct2.comclick.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ads20.wwe-media.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.kontera.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.shopping.112.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	tracking.tchibo.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adserver.adtechus.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adtechus.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.server.cpmstar.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	wstat.wibiya.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	user.lucidmedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.interclick.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.interclick.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.liveperson.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	nedstat.hostelbookers.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	nedstat.hostelbookers.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.opodo.122.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.canadiantourismcommission.112.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.ad-track.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	stat.onestat.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	stat.onestat.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	sperrmuell-online.awista-duesseldorf.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.awista-duesseldorf.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adxpose.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	audit.median.hu [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.partypoker.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	de.partypoker.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.educationcom.112.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ru4.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.trafficmaxx.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.microsoftsto.112.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.guj.122.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	adserver.wolterskluwer.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	fl01.ct2.comclick.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	fl01.ct2.comclick.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.realmedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.realmedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.legolas-media.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.fastclick.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.viewablemedia.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.liveperson.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.weborama.fr [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adviva.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	fr.sitestat.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	fr.sitestat.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.yieldmanager.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.nextag.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.nextag.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.eyewonder.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.werbeartikel-discount.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tsleducation.112.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tedi-discount.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.dmtracker.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	tracking.sim-technik.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.sevenoneintermedia.112.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.produkt-pfadfinder.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.produkt-pfadfinder.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.cunda.122.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.a.revenuemax.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	furrycritters-und-co.blogspot.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	furrycritters-und-co.blogspot.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.xiti.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	openx.microsites.transcontinentalmedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.creativdiscount.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	in.getclicky.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ads.247activemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	af.2.cqcounter.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.fastclick.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	zbox.zanox.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.lfstmedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.insightexpressai.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	admediaserver.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	tracking.9flats.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tto2.traffictrack.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	s05.flagcounter.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	counters.gigya.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	statse.webtrendslive.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.azjmp.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.trafficmp.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tracking.3gnet.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.bs.serving-sys.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	stat.aldi.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.libri.112.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.histats.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.histats.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	track.webtrekk.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	studivz.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	studivz.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.mm.chitika.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.e-2dj6wfliwnazaco.stats.esomniture.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.adserver01.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.4stats.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.4stats.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.partypoker.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.partypoker.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.de.partypoker.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.de.partypoker.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.de.partypoker.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.burstnet.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.at.atwola.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.at.atwola.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tacoda.at.atwola.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tacoda.at.atwola.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.at.atwola.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ar.atwola.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.legolas-media.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.blogads.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	stat.dealtime.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.adserver01.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.yieldmanager.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	partners.webmasterplan.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.eyewonder.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ads20.wwe-media.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.getclicky.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.static.getclicky.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tribalfusion.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.interclick.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.trafficmp.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.trafficmp.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.overture.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adxvalue.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tracking.hermesworld.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.lfstmedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.lfstmedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	adsrv1.admediate.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.technoratimedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.harrenmedianetwork.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	e2.emediate.se [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.velmedia.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.pro-market.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	track.effiliation.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.unister-adservices.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad1.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.mmotraffic.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.account.frogster-online.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	tracking.gameforge.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.herdt.112.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.deutschepostag.112.2o7.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.burstnet.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	edates.traffective-tracking.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	edates.traffective-tracking.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	edates.traffective-tracking.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.gostats.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.yadro.ru [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.statcounter.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ad.velmedia.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ad.velmedia.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adxvalue.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adxvalue.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.zanox-affiliate.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	pfa.rotator.hadj7.adjuggler.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.mmotraffic.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.pagetrackr.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.pagetrackr.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.seniorsavingsdiscounts.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.seniorsavingsdiscounts.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.lucidmedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ru4.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.adition.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.adition.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	dtp.missioncontrol.global-media.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.ads.quartermedia.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.bs.serving-sys.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	pfa.rotator.hadj7.adjuggler.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.myroitracking.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.clicksor.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.clicksor.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	tracking1.aleadpay.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adviva.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	media.gan-online.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.zanox.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.secmedia.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.hightraffic.hugoboss.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.hightraffic.hugoboss.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.hightraffic.hugoboss.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.zanox-affiliate.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.dyntracker.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	track.webtrekk.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.fastclick.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.unitymedia.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.unitymedia.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.zanox.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad4.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad2.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.zanox.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	server.adform.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	server.adform.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adform.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ww251.smartadserver.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	ad3.adfarm1.adition.com [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\FRANZI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9L632W5O.DEFAULT\COOKIES.SQLITE ]

Unclassified.Unknown Origin
	C:\PROGRAMDATA\LERNWERKSTATT 8\DATA\GWS\HäUFIGKEIT ALLE\DIE.TXT
	C:\PROGRAMDATA\LERNWERKSTATT 8\DATA\GWS\WöRTER MIT IE\DIE.TXT

Adware.InstallCore
	C:\USERS\FRANZI\DOWNLOADS\FLVPLAYERSETUP.EXE
         

Alt 05.03.2012, 15:21   #28
Franzi87
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



Den FLV player hab ich über die hxxp://www.antenneduesseldorf.de seite.

Alt 05.03.2012, 16:03   #29
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



Dann ist es wohl eher ein Fehlalarm. Die anderen von SUPERAntiSpyware auch und sonst nur Cookies.

Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 20.03.2012, 08:20   #30
Franzi87
 
Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - Standard

Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung



habe noch ein Problem entdeckt.... wenn ich mich anmelde steht unter meinem Anmeldenamen noch immer 'gesperrt', aber sonst geht wieder alles prima

Antwort

Themen zu Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung
adobe, alternate, antivir, autorun, avg, avira, bho, bonjour, canon, error, excel, explorer, firefox, format, home, launch, logfile, mozilla, packard bell, photoshop, plug-in, realtek, registry, scan, search the web, security, security scan, software, temp, version=1.0, virus, windows




Ähnliche Themen: Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung


  1. Neuer Rechner; Neuer Virenschutz & Windows 8 Secure-Einstellungen
    Antiviren-, Firewall- und andere Schutzprogramme - 12.10.2014 (21)
  2. Hunderte E-Mails nach Sperr-Trojaner ?
    Plagegeister aller Art und deren Bekämpfung - 24.10.2012 (7)
  3. Sperr-Trojaner
    Log-Analyse und Auswertung - 05.10.2012 (6)
  4. E-mail sperr trojaner
    Log-Analyse und Auswertung - 16.07.2012 (12)
  5. Sperr-Trojaner eingefangen!
    Plagegeister aller Art und deren Bekämpfung - 04.07.2012 (23)
  6. Windows Sperr Trojaner WinXP
    Log-Analyse und Auswertung - 03.05.2012 (3)
  7. Ein weiterer Fall: 50 € Virus - Windows gesperrt
    Log-Analyse und Auswertung - 11.04.2012 (22)
  8. (2x) Computer-Sperr-Trojaner entfernen
    Mülltonne - 30.03.2012 (3)
  9. Ein neuer Fall von TR\Crypt.XPACK.Gen.3
    Plagegeister aller Art und deren Bekämpfung - 22.03.2012 (43)
  10. Windows Security Center Bezahlaufforderung von 100 €
    Plagegeister aller Art und deren Bekämpfung - 13.03.2012 (1)
  11. XP Bezahlaufforderung Microsoft, Kaspersky... OTL schon laufen lassen...
    Plagegeister aller Art und deren Bekämpfung - 22.12.2011 (3)
  12. Hilfe zwecks Viruses!
    Log-Analyse und Auswertung - 13.11.2010 (22)
  13. Danger! Harmful viruses detected on your computer.
    Plagegeister aller Art und deren Bekämpfung - 13.04.2010 (5)
  14. Warning!!! Your computer contains various signs of viruses and malware..
    Plagegeister aller Art und deren Bekämpfung - 17.08.2009 (70)
  15. Probleme mit mir unbekanntem HDD-Sperr-Virus
    Plagegeister aller Art und deren Bekämpfung - 16.02.2008 (3)
  16. Escan: Total Viruses Found: 4
    Plagegeister aller Art und deren Bekämpfung - 14.09.2005 (2)
  17. e-scan viruses
    Plagegeister aller Art und deren Bekämpfung - 05.01.2005 (19)

Zum Thema Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung - ok das combofix log schaut so aus. Code: Alles auswählen Aufklappen ATTFilter ComboFix 12-02-19.02 - Franzi 20.02.2012 18:41:07.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.49.1031.18.3956.2471 [GMT 1:00] ausgeführt von:: - Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung...
Archiv
Du betrachtest: Neuer Fall des Windows sperr Viruses mit Bezahlaufforderung auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.