Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 18.09.2012, 14:29   #16
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 - Standard

Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10



Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 18.09.2012, 19:31   #17
gabi.flabi
 
Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 - Standard

Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10



Combofix Logfile:
Code:
ATTFilter
ComboFix 12-09-18.06 - gabriele 18.09.2012  20:21:39.1.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.3990.2083 [GMT 2:00]
ausgeführt von:: c:\users\gabriele\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\23lldnur.pad
c:\programdata\PCDr\6032\AddOnDownloaded\06004c97-c212-44da-81de-706b46554efe.dll
c:\programdata\PCDr\6032\AddOnDownloaded\07439fd5-7039-4014-b635-5bf088a1465b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\0d461521-7dbf-4cec-a29e-936c88cdf8c9.dll
c:\programdata\PCDr\6032\AddOnDownloaded\0d85b53c-d766-4bf0-8940-17b534910268.dll
c:\programdata\PCDr\6032\AddOnDownloaded\100c3865-0c76-461b-b2fd-042d6d5fa7f6.dll
c:\programdata\PCDr\6032\AddOnDownloaded\140239b3-d59a-46fa-b856-17682a46cb44.dll
c:\programdata\PCDr\6032\AddOnDownloaded\16837627-a839-41c5-a88f-3a0335128383.dll
c:\programdata\PCDr\6032\AddOnDownloaded\16ab6978-b6b5-41fa-81a1-8bffc55a69b9.dll
c:\programdata\PCDr\6032\AddOnDownloaded\173c4dd2-e93c-4725-b006-db1d8f465192.dll
c:\programdata\PCDr\6032\AddOnDownloaded\1e0aaf9a-9947-4a7b-b1ae-8a89919438ed.dll
c:\programdata\PCDr\6032\AddOnDownloaded\263d6ac9-4f87-466c-947c-bd9af71d7035.dll
c:\programdata\PCDr\6032\AddOnDownloaded\2ee79d71-badc-46b4-b731-42b15f3cd1c3.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3410f47b-5e8c-47c6-bf2c-234af4121d4c.dll
c:\programdata\PCDr\6032\AddOnDownloaded\378deb7f-049e-4a5e-83b2-5381dcd9e928.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3972fea3-214c-4935-a7d1-96bf66115683.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3a79f062-8f3e-464f-9815-2c45840494ee.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3b1c7acd-5e3e-4459-ab98-5109117e2341.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3e4c86d5-a5c1-4c3f-8fc7-6258992b16c5.dll
c:\programdata\PCDr\6032\AddOnDownloaded\44ddba62-3b58-480f-a775-ae7e9dd9d5df.dll
c:\programdata\PCDr\6032\AddOnDownloaded\4546f2bc-b9d9-4667-abe7-b0bacc90279e.dll
c:\programdata\PCDr\6032\AddOnDownloaded\4804ced5-915b-48a3-a465-b8a5e02714bf.dll
c:\programdata\PCDr\6032\AddOnDownloaded\4818e109-9489-4cd8-9044-44defd8ec187.dll
c:\programdata\PCDr\6032\AddOnDownloaded\493f295d-1a46-46f6-926c-63b474cedab4.dll
c:\programdata\PCDr\6032\AddOnDownloaded\5e1c102f-bfde-420c-87c0-64fe851888e5.dll
c:\programdata\PCDr\6032\AddOnDownloaded\62d1f0b0-bc9a-4f6c-bad7-93b19a91276a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\67c3d4fe-b638-467a-9fe2-c5813ade3330.dll
c:\programdata\PCDr\6032\AddOnDownloaded\6820b110-e483-4f1e-9b48-438f7916f078.dll
c:\programdata\PCDr\6032\AddOnDownloaded\684a43a7-04d5-4797-bc20-4db8a316286c.dll
c:\programdata\PCDr\6032\AddOnDownloaded\6928cebe-dc61-4564-a488-e19724a8de68.dll
c:\programdata\PCDr\6032\AddOnDownloaded\6b5978fa-48d7-4309-a523-7e157768c0d8.dll
c:\programdata\PCDr\6032\AddOnDownloaded\6f4fb483-ce30-493a-8cb4-3e530ab1be5b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\7014e871-cc3b-4dec-b82b-bc70222b40ed.dll
c:\programdata\PCDr\6032\AddOnDownloaded\739db3eb-d3cd-4c86-a6ea-01a49984fa3b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\7bd83798-7a02-4f50-83a2-b91cabcbd1f9.dll
c:\programdata\PCDr\6032\AddOnDownloaded\7dbfef1a-6148-4748-a1b3-71627763a45a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\813755dc-2229-47a2-b85b-19d0aaa641c9.dll
c:\programdata\PCDr\6032\AddOnDownloaded\872965c7-08b7-47fc-a74c-ff167590b71a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\8a6735b1-c078-4648-9416-b6bb29ec3dc1.dll
c:\programdata\PCDr\6032\AddOnDownloaded\8d357f17-07ad-4392-ba06-fb67564c98cd.dll
c:\programdata\PCDr\6032\AddOnDownloaded\934f6059-2d35-4bd9-a130-a17cb5563507.dll
c:\programdata\PCDr\6032\AddOnDownloaded\9ad10df8-6662-488d-9a0f-1fab1ee3403d.dll
c:\programdata\PCDr\6032\AddOnDownloaded\9f8591c3-5048-42f7-9553-387b30449f54.dll
c:\programdata\PCDr\6032\AddOnDownloaded\a4930af9-016c-4915-a740-a3364e7618aa.dll
c:\programdata\PCDr\6032\AddOnDownloaded\a61f44a8-21a3-4c4a-a04b-993dfb73bf96.dll
c:\programdata\PCDr\6032\AddOnDownloaded\a9de0c84-9a7c-4638-9653-13aa8cf56e80.dll
c:\programdata\PCDr\6032\AddOnDownloaded\ac96894a-064b-4c44-a457-9d5aaee7032a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\adb45b82-004f-4eed-bd54-d60d7eda1ff5.dll
c:\programdata\PCDr\6032\AddOnDownloaded\ae67b364-b69e-471e-b177-2459120b84d4.dll
c:\programdata\PCDr\6032\AddOnDownloaded\b2152f30-7380-4987-8fcf-e4c06952615d.dll
c:\programdata\PCDr\6032\AddOnDownloaded\b2ed8d53-41ce-48e6-b4ac-8b8e5e1a4fdf.dll
c:\programdata\PCDr\6032\AddOnDownloaded\b4cc2a4a-87f5-49cd-935c-18f1a80e65b7.dll
c:\programdata\PCDr\6032\AddOnDownloaded\b9ce760f-6209-48f2-a4a3-695324591c45.dll
c:\programdata\PCDr\6032\AddOnDownloaded\bbfa36b0-30b0-4e36-8d8c-69df1d87626b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\bc6fc708-5b6b-4a72-b336-09b3089baa7a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\bf647bd7-dfb5-4746-a6b4-b7c2fdbbf3b1.dll
c:\programdata\PCDr\6032\AddOnDownloaded\c2690c4c-81f4-4565-a861-643c7af1fa90.dll
c:\programdata\PCDr\6032\AddOnDownloaded\c4211805-b43b-471d-81af-4e0589f8607b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\cdda52ec-6ccd-425a-8c72-b7bbdc8b3acd.dll
c:\programdata\PCDr\6032\AddOnDownloaded\d1f4dc82-bc4c-4916-b37c-3ab9c30ae468.dll
c:\programdata\PCDr\6032\AddOnDownloaded\d34c0cf7-889f-43dd-9283-b2b6f442aae3.dll
c:\programdata\PCDr\6032\AddOnDownloaded\daf30858-49d8-434b-b4b1-068b5dc9267c.dll
c:\programdata\PCDr\6032\AddOnDownloaded\ddb9fe5d-525c-4d5d-ac37-0bd10f2864f8.dll
c:\programdata\PCDr\6032\AddOnDownloaded\e45cd45a-4d7c-4802-881f-74582b847e5c.dll
c:\programdata\PCDr\6032\AddOnDownloaded\e86f11dd-8b83-43cc-899e-f935ce0a1ea0.dll
c:\programdata\PCDr\6032\AddOnDownloaded\e9bb45d9-5a2b-47e8-9c48-168276d422cc.dll
c:\programdata\PCDr\6032\AddOnDownloaded\ef78c3e8-1d94-4219-8070-7617e119bba4.dll
c:\programdata\PCDr\6032\AddOnDownloaded\f06c5597-1a85-4d1f-ac16-a6fdd2a6bedc.dll
c:\programdata\PCDr\6032\AddOnDownloaded\f80d4ad1-1fad-43b5-b6f3-347848b5ddd5.dll
c:\programdata\PCDr\6032\AddOnDownloaded\f9dc840b-c6f7-42a5-acec-50cc7a2827fd.dll
c:\programdata\Roaming
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-08-18 bis 2012-09-18  ))))))))))))))))))))))))))))))
.
.
2012-09-18 18:26 . 2012-09-18 18:26	--------	d-----w-	c:\users\Default\AppData\Local\temp
2012-09-18 17:20 . 2012-09-18 17:20	69000	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{FEF2AC9E-79AC-4156-96C3-C595C8BBA1A0}\offreg.dll
2012-09-17 17:31 . 2012-09-17 17:31	--------	d-----w-	c:\program files (x86)\7-Zip
2012-09-17 12:01 . 2012-09-17 12:01	--------	d-----w-	C:\_OTL
2012-09-15 17:06 . 2012-08-23 08:26	9310152	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{FEF2AC9E-79AC-4156-96C3-C595C8BBA1A0}\mpengine.dll
2012-09-12 21:50 . 2012-09-12 21:50	73696	----a-w-	c:\program files (x86)\Mozilla Firefox\breakpadinjector.dll
2012-09-12 16:34 . 2012-09-12 16:34	--------	d-----w-	c:\program files (x86)\ESET
2012-09-12 14:45 . 2012-09-12 14:45	--------	d-----w-	c:\users\gabriele\AppData\Roaming\Malwarebytes
2012-09-12 14:44 . 2012-09-12 14:44	--------	d-----w-	c:\programdata\Malwarebytes
2012-09-12 14:44 . 2012-09-12 14:44	--------	d-----w-	c:\program files (x86)\Malwarebytes' Anti-Malware
2012-09-12 14:44 . 2012-09-07 15:04	25928	----a-w-	c:\windows\system32\drivers\mbam.sys
2012-09-12 14:32 . 2012-08-22 18:12	950128	----a-w-	c:\windows\system32\drivers\ndis.sys
2012-09-12 14:32 . 2012-07-04 20:26	41472	----a-w-	c:\windows\system32\drivers\RNDISMP.sys
2012-09-12 14:32 . 2012-08-22 18:12	1913200	----a-w-	c:\windows\system32\drivers\tcpip.sys
2012-09-12 14:32 . 2012-08-22 18:12	376688	----a-w-	c:\windows\system32\drivers\netio.sys
2012-09-12 14:32 . 2012-08-22 18:12	288624	----a-w-	c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 14:32 . 2012-08-02 17:58	574464	----a-w-	c:\windows\system32\d3d10level9.dll
2012-09-12 14:32 . 2012-08-02 16:57	490496	----a-w-	c:\windows\SysWow64\d3d10level9.dll
2012-08-23 22:31 . 2012-07-06 20:07	552960	----a-w-	c:\windows\system32\drivers\bthport.sys
2012-08-23 20:43 . 2012-08-23 20:43	--------	d-----w-	c:\programdata\PC-Doctor for Windows
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-13 10:01 . 2012-04-01 16:30	64462936	----a-w-	c:\windows\system32\MRT.exe
2012-08-28 18:24 . 2012-08-10 05:23	477168	----a-w-	c:\windows\SysWow64\npdeployJava1.dll
2012-08-28 18:24 . 2011-11-09 00:42	473072	----a-w-	c:\windows\SysWow64\deployJava1.dll
2012-08-14 23:31 . 2012-03-30 23:11	426184	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-14 23:31 . 2011-11-09 00:26	70344	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19	94208	----a-w-	c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19	94208	----a-w-	c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19	94208	----a-w-	c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-13 138096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2012-07-27 35768]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942]
"Dell Registration"="c:\program files (x86)\System Registration\prodreg.exe" [2011-08-04 4165440]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"NeroLauncher"="c:\program files (x86)\Nero\SyncUP\NeroLauncher.exe" [2012-02-06 66872]
"AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-04-30 885760]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
.
c:\users\gabriele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\gabriele\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-7-3 26868192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-05-19 995392]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 116648]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-07 676936]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-14 250056]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protokoll;c:\windows\system32\DRIVERS\amppal.sys [2011-08-08 299008]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-05-19 1335360]
R3 DialComService;DIAL Communication Service;c:\program files (x86)\DIAL GmbH\DIAL Communication Framework\DialComService.exe [2011-10-17 1673520]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 116648]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-02-27 158976]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-05-17 34200]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-07 25928]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-12 114144]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-28 340240]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-12-01 250984]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 vnet;Shrew Soft Virtual Adapter;c:\windows\system32\DRIVERS\virtualnet.sys [2010-09-02 17408]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-09-16 27760]
S1 vflt;Shrew Soft Lightweight Filter;c:\windows\system32\DRIVERS\vfilter.sys [2010-09-02 21504]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-08-08 1166848]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-14 86224]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-05-19 921664]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928]
S2 dtpd;ShrewSoft DNS Proxy Daemon;c:\program files\ShrewSoft\VPN Client\dtpd.exe [2010-10-08 56592]
S2 iked;ShrewSoft IKE Daemon;c:\program files\ShrewSoft\VPN Client\iked.exe [2010-10-08 957712]
S2 ipsecd;ShrewSoft IPSEC Daemon;c:\program files\ShrewSoft\VPN Client\ipsecd.exe [2010-10-08 697616]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-07 399432]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400]
S2 Scia Licence Server;Scia Licence Server;c:\program files (x86)\Common Files\SCIA\Protection\lmgrd.exe [2011-05-26 1408848]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-08-18 1692480]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed - Virtueller Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-08-08 299008]
S3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys [2011-05-19 51712]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2011-05-19 53248]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-07-19 282624]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-01-20 176096]
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-07-20 59904]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-16 317440]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-05-17 25496]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-08-04 8604672]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-02-10 82432]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-02-10 181760]
S3 PCDSRVC{1E208CE0-FB7451FF-06020200}_0;PCDSRVC{1E208CE0-FB7451FF-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2012-08-17 25584]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-11-30 412264]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - PCDSRVC{1E208CE0-FB7451FF-06020200}_0
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 23:31]
.
2012-09-18 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000Core.job
- c:\users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-30 18:18]
.
2012-09-18 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000UA.job
- c:\users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-30 18:18]
.
2012-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 18:24]
.
2012-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 18:24]
.
2012-07-26 c:\windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job
- c:\program files\Dell Support Center\uaclauncher.exe [2012-08-23 05:36]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19	97792	----a-w-	c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19	97792	----a-w-	c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19	97792	----a-w-	c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19	97792	----a-w-	c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-04-14 6629480]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-05 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-05 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-05 416024]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-04-12 609144]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-07-28 1935120]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-05-19 10365952]
"QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2011-03-11 4500640]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"Stage Remote"="c:\program files (x86)\Dell\Stage Remote\StageRemote.exe" [2011-06-28 2022976]
"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-04-30 2055016]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{2541EF2C-0496-4F0B-9962-BD4206C8C433}: NameServer = 193.175.112.3,195.37.168.3
FF - ProfilePath - c:\users\gabriele\AppData\Roaming\Mozilla\Firefox\Profiles\bdxvsrnh.default\
.
.
------- Dateityp-Verknüpfung -------
.
.txt=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-ESET Online Scanner - c:\program files (x86)\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020200}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-09-18  20:29:05
ComboFix-quarantined-files.txt  2012-09-18 18:29
.
Vor Suchlauf: 12 Verzeichnis(se), 422.012.559.360 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 421.861.691.392 Bytes frei
.
- - End Of File - - 5C0ECB1A75CD81B26D8FD3313E243E09
         
--- --- ---
__________________


Alt 19.09.2012, 15:00   #18
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 - Standard

Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10



Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.
__________________
__________________

Alt 20.09.2012, 16:54   #19
gabi.flabi
 
Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 - Standard

Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10



GMER
GMER Logfile:
Code:
ATTFilter
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-09-20 17:06:04
Windows 6.1.7601 Service Pack 1 
Running: 4qx7ui69.exe


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4c80930c6ce5                      
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4c80930c6ce5@9c4a7bf9e3ad         0x9E 0x67 0x88 0xDF ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4c80930c6ce5 (not active ControlSet)  
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4c80930c6ce5@9c4a7bf9e3ad             0x9E 0x67 0x88 0xDF ...

---- EOF - GMER 1.0.15 ----
         
--- --- ---


OSAM
OSAM Logfile:
Code:
ATTFilter
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 18:07:41 on 20.09.2012

OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 64-bit
Default Browser: Mozilla Corporation Firefox 15.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000Core.job" - "Facebook Inc." - C:\Users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe
"FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000UA.job" - "Facebook Inc." - C:\Users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"adfs" (adfs) - "Adobe Systems, Inc." - C:\Windows\system32\drivers\adfs.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"PCDSRVC{1E208CE0-FB7451FF-06020200}_0 - PCDR Kernel Mode Service Helper Driver" (PCDSRVC{1E208CE0-FB7451FF-06020200}_0) - "PC-Doctor, Inc." - c:\program files\dell support center\pcdsrvc_x64.pkms
"WimFltr" (WimFltr) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\wimfltr.sys

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{8352FA4C-39C6-11D3-ADBA-00A0244FB1A2} "DIALux 2.0 ArchivProtocol Class" - "DIAL GmbH, Germany" - C:\Program Files (x86)\DIALux\DLXToolBox.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
{314111c7-a502-11d2-bbca-00c04f8ec294} "ms-help" - ? -   (File not found | COM-object registry key not found)
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files (x86)\7-Zip\7-zip.dll
{3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D} "Arbeitsbereiche" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{7CCA70DB-DE7A-4FB7-9B2B-52E2335A3B5A} "Enterprise-Projekte" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\NAMEEXT.DLL
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{0006F045-0000-0000-C000-000000000046} "Microsoft Outlook Custom Icon Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\OLKFSTUB.DLL
DIALux Doc ShellExtension "{7889C2D5-D128-43e2-A8D8-A7590A12C8B3}" - ? -   (File not found | COM-object registry key not found)
DIALux LumFile ShellExtension "{7EFFF3DD-71B3-11D4-A25E-005056DCFB89}" - ? -   (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_35" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} "Java Plug-in 1.6.0_35" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_35" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\npjpi160_35.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{69AB812A-8CE4-4BF3-B49B-3B60A9F31FB2} "DIALux 3.1 ULDBrowserHelper Class" - "DIAL GmbH, Germany" - C:\Program Files (x86)\DIALux\DLXShellExtension.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
{B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Dropbox.lnk" - "Dropbox, Inc." - C:\Users\gabriele\AppData\Roaming\Dropbox\bin\Dropbox.exe  (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Facebook Update" - "Facebook Inc." - "C:\Users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"AccuWeatherWidget" - ? - "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"Dell Registration" - "Dell, Inc." - C:\Program Files (x86)\System Registration\prodreg.exe /boot
"Dell Webcam Central" - "Creative Technology Ltd" - "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
"Desktop Disc Tool" - ? - "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
"NeroLauncher" - ? - C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe 900  (File found, but it contains no detailed information)
"QuickTime Task" - "Apple Inc." - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
"RoxWatchTray" - "Sonic Solutions" - "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Bullzip PDF Print Monitor" - "Bullzip" - C:\Windows\system32\bzpdf.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll  (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe"  (File not found)
"@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200" (NAUpdate) - "Nero AG" - C:\Program Files (x86)\Nero\Update\NASvc.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
"ASP.NET State Service" (aspnet_state) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
"Bluetooth Device Monitor" (Bluetooth Device Monitor) - "Intel Corporation" - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
"Bluetooth Media Service" (Bluetooth Media Service) - "Intel Corporation" - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
"Bluetooth OBEX Service" (Bluetooth OBEX Service) - "Intel Corporation" - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
"DIAL Communication Service" (DialComService) - ? - C:\Program Files (x86)\DIAL GmbH\DIAL Communication Framework\DialComService.exe
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Flexera Software, Inc." - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
"Google Update-Dienst (gupdate)" (gupdate) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service" (BTHSSecurityMgr) - "Intel(R) Corporation" - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
"Intel(R) Management and Security Application Local Management Service" (LMS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
"Intel(R) Management and Security Application User Notification Service" (UNS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
"Intel(R) PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
"Intel(R) PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
"Intel(R) Turbo Boost Technology Monitor 2.0" (TurboBoost) - "Intel(R) Corporation" - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
"Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service" (AMPPALR3) - "Intel Corporation" - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
"MBAMScheduler" (MBAMScheduler) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft SharePoint Workspace Audit Service" (Microsoft SharePoint Workspace Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
"Office 64 Source Engine" (ose64) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"Roxio Hard Drive Watcher 12" (RoxWatch12) - "Sonic Solutions" - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
"RoxMediaDB12OEM" (RoxMediaDB12OEM) - "Sonic Solutions" - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
"Scia Licence Server" (Scia Licence Server) - "Flexera Software, Inc." - C:\Program Files (x86)\Common Files\SCIA\Protection\lmgrd.exe
"ShrewSoft DNS Proxy Daemon" (dtpd) - ? - C:\Program Files\ShrewSoft\VPN Client\dtpd.exe  (File found, but it contains no detailed information)
"ShrewSoft IKE Daemon" (iked) - ? - C:\Program Files\ShrewSoft\VPN Client\iked.exe  (File found, but it contains no detailed information)
"ShrewSoft IPSEC Daemon" (ipsecd) - ? - C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe  (File found, but it contains no detailed information)
"Skype C2C Service" (Skype C2C Service) - "Skype Technologies S.A." - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files (x86)\Skype\Updater\Updater.exe
"SoftThinks Agent Service" (SftService) - "SoftThinks SAS" - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
"stllssvr" (stllssvr) - "MicroVision Development, Inc." - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
"Wireless PAN DHCP Server" (MyWiFiDHCPDNS) - ? - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe

===[ Logfile end ]=========================================[ Logfile end ]===
         
--- --- ---
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
[/code]

Code:
ATTFilter
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-20 18:56:12
-----------------------------
18:56:12.722    OS Version: Windows x64 6.1.7601 Service Pack 1
18:56:12.722    Number of processors: 4 586 0x2A07
18:56:12.722    ComputerName: DELLICIOUS  UserName: gabriele
18:56:15.352    Initialize success
18:56:23.182    AVAST engine defs: 12092000
18:56:29.662    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:56:29.672    Disk 0 Vendor: ST950032 D005 Size: 476940MB BusType: 3
18:56:29.702    Disk 0 MBR read successfully
18:56:29.702    Disk 0 MBR scan
18:56:29.712    Disk 0 Windows VISTA default MBR code
18:56:29.722    Disk 0 Partition 1 00     DE Dell Utility Dell 8.0      101 MB offset 63
18:56:29.742    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        20000 MB offset 212992
18:56:29.772    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       456835 MB offset 41172992
18:56:29.812    Disk 0 scanning C:\Windows\system32\drivers
18:56:48.472    Service scanning
18:57:28.812    Modules scanning
18:57:28.822    Disk 0 trace - called modules:
18:57:28.852    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 
18:57:28.862    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80065b1060]
18:57:28.872    3 CLASSPNP.SYS[fffff88000cc143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8005356050]
18:57:28.892    Scan finished successfully
18:57:41.141    Disk 0 MBR has been saved successfully to "C:\Users\gabriele\Desktop\Neuer Ordner\MBR.dat"
18:57:41.141    The log file has been saved successfully to "C:\Users\gabriele\Desktop\Neuer Ordner\aswMBR.txt"
         
hab mal eine frage..muss ich noch viele scans machen ?

Alt 20.09.2012, 20:20   #20
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 - Standard

Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10



Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 23.09.2012, 22:46   #21
gabi.flabi
 
Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 - Standard

Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10



Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.23.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
gabriele :: DELLICIOUS [Administrator]

Schutz: Deaktiviert

23.09.2012 22:16:54
mbam-log-2012-09-23 (22-16-54).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 335424
Laufzeit: 1 Stunde(n), 16 Minute(n), 

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         
Code:
ATTFilter
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/24/2012 at 09:55 AM

Application Version : 5.5.1016

Core Rules Database Version : 9197
Trace Rules Database Version: 7009

Scan type       : Complete Scan
Total Scan Time : 01:55:47

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 653
Memory threats detected   : 0
Registry items scanned    : 68685
Registry threats detected : 0
File items scanned        : 142546
File threats detected     : 383

Adware.Tracking Cookie
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\PHB1CE34.txt [ /media6degrees.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\8KUDFLTB.txt [ /serving-sys.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\Q6SIGC1Q.txt [ /ad1.adfarm1.adition.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\E0Q6ELOW.txt [ /invitemedia.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\RWUUKCKX.txt [ /ad.zanox.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\L7T2W09S.txt [ /imrworldwide.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\E2KH3VCA.txt [ /tracking.quisma.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\N2Q4M2DR.txt [ /apmebf.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\G505DBC0.txt [ /fastclick.net ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\WECVINYQ.txt [ /lucidmedia.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\MJABQUIB.txt [ /c.atdmt.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\F7HEJTIQ.txt [ /mediaplex.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\UKTZCDXV.txt [ /zanox.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\A52YNKJ0.txt [ /track.adform.net ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\9GT86HKS.txt [ /2o7.net ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\141QOIB4.txt [ /adfarm1.adition.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\CCWITI3L.txt [ /adform.net ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\73VWJVQ3.txt [ /doubleclick.net ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\B53N0SIG.txt [ /smartadserver.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\E5BPPIJN.txt [ /atdmt.com ]
	C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\ZZ13WNI5.txt [ /dyntracker.com ]
	C:\USERS\GABRIELE\AppData\Roaming\Microsoft\Windows\Cookies\Low\T2UY4KAD.txt [ Cookie:gabriele@serving-sys.com/ ]
	C:\USERS\GABRIELE\AppData\Roaming\Microsoft\Windows\Cookies\Low\G6MXUMQX.txt [ Cookie:gabriele@statse.webtrendslive.com/ ]
	C:\USERS\GABRIELE\AppData\Roaming\Microsoft\Windows\Cookies\Low\JCR4YC1Q.txt [ Cookie:gabriele@bs.serving-sys.com/ ]
	C:\USERS\GABRIELE\Cookies\PHB1CE34.txt [ Cookie:gabriele@media6degrees.com/ ]
	C:\USERS\GABRIELE\Cookies\8KUDFLTB.txt [ Cookie:gabriele@serving-sys.com/ ]
	C:\USERS\GABRIELE\Cookies\Q6SIGC1Q.txt [ Cookie:gabriele@ad1.adfarm1.adition.com/ ]
	C:\USERS\GABRIELE\Cookies\RWUUKCKX.txt [ Cookie:gabriele@ad.zanox.com/ ]
	C:\USERS\GABRIELE\Cookies\L7T2W09S.txt [ Cookie:gabriele@imrworldwide.com/cgi-bin ]
	C:\USERS\GABRIELE\Cookies\E2KH3VCA.txt [ Cookie:gabriele@tracking.quisma.com/ ]
	C:\USERS\GABRIELE\Cookies\N2Q4M2DR.txt [ Cookie:gabriele@apmebf.com/ ]
	C:\USERS\GABRIELE\Cookies\G505DBC0.txt [ Cookie:gabriele@fastclick.net/ ]
	C:\USERS\GABRIELE\Cookies\WECVINYQ.txt [ Cookie:gabriele@lucidmedia.com/ ]
	C:\USERS\GABRIELE\Cookies\F7HEJTIQ.txt [ Cookie:gabriele@mediaplex.com/ ]
	C:\USERS\GABRIELE\Cookies\UKTZCDXV.txt [ Cookie:gabriele@zanox.com/ ]
	C:\USERS\GABRIELE\Cookies\A52YNKJ0.txt [ Cookie:gabriele@track.adform.net/ ]
	C:\USERS\GABRIELE\Cookies\CCWITI3L.txt [ Cookie:gabriele@adform.net/ ]
	C:\USERS\GABRIELE\Cookies\B53N0SIG.txt [ Cookie:gabriele@smartadserver.com/ ]
	C:\USERS\GABRIELE\Cookies\E5BPPIJN.txt [ Cookie:gabriele@atdmt.com/ ]
	C:\USERS\GABRIELE\Cookies\ZZ13WNI5.txt [ Cookie:gabriele@dyntracker.com/ ]
	.adbrite.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	adserver.adreactor.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.imrworldwide.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adinterax.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adinterax.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.ad-emea.doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.ad-emea.doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.quartermedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.ikea.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.histats.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.histats.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.specificclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.zanox-affiliate.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.realmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.harrenmedianetwork.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.ru4.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.euros4click.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.unitymedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	tracking.dc-storm.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.unitymedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	edu-stats.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.secmedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.dealtime.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.mm.chitika.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	affiliate.mediatemple.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	optimize.indieclick.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	optimize.indieclick.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adserver.adtechus.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	track.zalando.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	studivz.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	studivz.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.guj.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.loyaltypartner.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	adx.kat.ph [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	securetrafficserver5.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	stats.vertriebsassistent.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.xiti.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adviva.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	7.rotator.wigetmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.bwincom.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.gostats.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	media.gan-online.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.traveladvertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.traveladvertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.hawaiianairlines.112.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.interclick.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.interclick.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.pro-market.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.pro-market.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.pro-market.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.pro-market.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.collective-media.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.ar.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.pointroll.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.hotwire.db.advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.networldmedia.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.trafficmp.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tribalfusion.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	clicks.stylefruits.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tracking.3gnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.burstnet.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.casalemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.www.burstnet.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	7.rotator.wigetmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	rotator.hadj7.adjuggler.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.partypoker.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.liveperson.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.partypoker.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.partypoker.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.112.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.lucidmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adbrite.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.ru4.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.usenext.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.a.revenuemax.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	stat.dealtime.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.active-tracking.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	server.adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	server.adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	accounts.google.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad.zanox.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.realmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	network.realmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.opodo.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.unister-adservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.clickfuse.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.clickfuse.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www2.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www2.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.lfstmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.ad.adnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.etracker.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	partners.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.fastclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.clickfuse.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.revenuemax.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.zanox-affiliate.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad1.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.zanox-affiliate.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	adt.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	adt.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	adt.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	adt.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tto2.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad.zanox.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	statse.webtrendslive.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	eas.apm.emediate.eu [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.kontera.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.unitymedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.unitymedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.rambler.ru [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.yadro.ru [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.rambler.ru [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ww251.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adnetwork.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad.zanox.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.zanox.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.zanox-affiliate.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.content.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.content.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.xm.xtendmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.statcounter.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.statcounter.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad2.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad4.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	ad3.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	track.adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
	www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-Falprod[i]
	C:\PROGRAM FILES (X86)\SCIA\ENGINEER2011.0\NESSIE.DLL
         

Alt 24.09.2012, 14:27   #22
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 - Standard

Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10



Code:
ATTFilter
UAC On - Limited User
         
Wie hast du SUPERAntiSpyware gestartet? Einfach per Doppelklick?
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 25.09.2012, 08:59   #23
gabi.flabi
 
Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 - Standard

Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10



rechtsklick..als administrator ausführen

soll ichs wiederholen ?

Alt 25.09.2012, 12:55   #24
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 - Standard

Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10



Nein dann ist das ok, das Programm hat da einen Bug und zeigt das nicht immer richtig an

Code:
ATTFilter
C:\PROGRAM FILES (X86)\SCIA\ENGINEER2011.0\NESSIE.DLL
         
Was machst du mit dieser Software, wie kommt die darauf?!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 26.09.2012, 12:20   #25
gabi.flabi
 
Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 - Standard

Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10



ich arbeite ab und an mal mit der software...für die uni...

Alt 26.09.2012, 15:40   #26
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 - Standard

Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10



Gut, Uni also...dann ist das geklärt!

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10
adobe, antivir, autorun, avg, avira, bho, defender, dll, document, explorer, fehler, firefox, flash player, format, google earth, home, limited.com/facebook, logfile, monitor, mozilla, opera, plug-in, realtek, registry, rundll, scan, software, usb, windows, wscript.exe




Ähnliche Themen: Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10


  1. Fehler in C:\Windows\system32\rundll32.exe Folgender Eintrag fehlt: FQ10 !
    Plagegeister aller Art und deren Bekämpfung - 24.02.2013 (8)
  2. Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10, Spyware.Zeus, Trojan.Ransom.Gen
    Log-Analyse und Auswertung - 07.02.2013 (17)
  3. Fehler in C:\Windows\system32\rundll32.exe Folgender Eintrag fehlt: FQ10 !
    Plagegeister aller Art und deren Bekämpfung - 25.11.2012 (6)
  4. C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10
    Plagegeister aller Art und deren Bekämpfung - 05.11.2012 (32)
  5. C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10
    Plagegeister aller Art und deren Bekämpfung - 20.10.2012 (2)
  6. C:\\Windows\SysWOW64\rundl32.exe Folgender Eintrag fehlt: FQ10
    Plagegeister aller Art und deren Bekämpfung - 10.10.2012 (8)
  7. Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10
    Plagegeister aller Art und deren Bekämpfung - 09.10.2012 (5)
  8. Trojaner C:\Windows\system32\rundll32.exe Folgender Eintrag fehlt: FQ10 Fehler in C:\Windows\system32\rundll32.exe Folgender Eintrag fehlt:
    Plagegeister aller Art und deren Bekämpfung - 05.10.2012 (19)
  9. windows\SysWOW64\rundll32.exe - Eintrag FQ10 fehlt
    Log-Analyse und Auswertung - 27.09.2012 (2)
  10. Meldung: C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10
    Plagegeister aller Art und deren Bekämpfung - 26.09.2012 (17)
  11. Fehler in C:\Windows\SysWOW64\rundl32.exe Folrgender Eintrag fehlt: FQ10
    Plagegeister aller Art und deren Bekämpfung - 20.09.2012 (10)
  12. Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10
    Plagegeister aller Art und deren Bekämpfung - 12.09.2012 (13)
  13. Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10
    Alles rund um Windows - 03.09.2012 (1)
  14. windows\SysWOW64\rundll32.exe - Eintrag FQ10 fehlt
    Plagegeister aller Art und deren Bekämpfung - 21.08.2012 (7)
  15. Mein Online-Banking wurde ausspioniert!! / Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 (Beim Windows-Start)
    Plagegeister aller Art und deren Bekämpfung - 19.08.2012 (2)
  16. Fehler in C:\Windows\system32\rundll32.exe Folgender Eintrag fehlt: FQ10
    Plagegeister aller Art und deren Bekämpfung - 19.08.2012 (22)
  17. C:\Windows\system32\rundll32.exe Folgender Eintrag fehlt: FQ10
    Log-Analyse und Auswertung - 19.08.2012 (1)

Zum Thema Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 - Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix Lade dir ComboFix hier herunter auf deinen Desktop . Schliesse alle Programme, vor allem dein Antivirenprogramm - Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10...
Archiv
Du betrachtest: Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.