Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   funmoods & DR/FakePic.Gen tmp.edb (https://www.trojaner-board.de/111117-funmoods-dr-fakepic-gen-tmp-edb.html)

disteffensso 08.03.2012 09:24

funmoods & DR/FakePic.Gen tmp.edb
 
Hallo,
habe Avira, Bezahlversion.
Vista 32 bit
vorhin den OTL scan gemacht, poste im Anschluß.
Defogger hat keine Meldung gebracht, habe ungeschickter Weise 2 x laufen lassen.
Die Windows- Firewall ist nach jedem Hochfahren/ Bereitschaftsstart seit einiger Zeit ausgeschaltet.
Der tmp.edb wurde schon 6 x in Quarantäne verschoben, wird jedesmal wieder gefunden.

PS: Schönen Gruß an ARNE, der mir das letzte Mal sehr geholfen hat.
Donation hatte ich nicht vergessen, auch diesmal gerne wieder.
Ihr seid jeden Cent wert!!

von Stefan

OTL Extras logfile created on: 08.03.2012 07:56:21 - Run 4
OTL by OldTimer - Version 3.2.35.1 Folder = C:\Users\stefan\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

1,87 Gb Total Physical Memory | 0,79 Gb Available Physical Memory | 42,22% Memory free
3,98 Gb Paging File | 2,57 Gb Available in Paging File | 64,57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116,21 Gb Total Space | 30,20 Gb Free Space | 25,98% Space Free | Partition Type: NTFS
Drive E: | 115,21 Gb Total Space | 55,74 Gb Free Space | 48,39% Space Free | Partition Type: NTFS

Computer Name: STEFANS-PC | User Name: stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0C8D1522-7E32-4BC0-BE14-D90FB4825D3C}" = rport=139 | protocol=6 | dir=out | app=system |
"{144A587B-9B81-410D-8273-00DBD342F077}" = lport=139 | protocol=6 | dir=in | app=system |
"{15E8C7F0-1F48-4F97-94A4-5D1AFA70070A}" = rport=445 | protocol=6 | dir=out | app=system |
"{1932CA5D-3CA1-4DB4-B302-A6EEF8554BEC}" = rport=137 | protocol=17 | dir=out | app=system |
"{2C88C1E2-BC5D-47B2-9F47-1A946A8E38F5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2F928AA8-8801-42A7-AA89-28B122243FFA}" = lport=138 | protocol=17 | dir=in | app=system |
"{4001BB15-D4FD-4FD8-A357-0F3B7106D3E1}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{580834CE-2A4F-4316-A2CA-A3C095E416DF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{65D5C019-7B04-49AA-B130-EDCA2C0EEE5C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{6B6A5499-D5A3-48F4-9126-9715B34DD59C}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{8A90567F-4AE3-42FE-B5AE-89F912CCC731}" = lport=445 | protocol=6 | dir=in | app=system |
"{8DD54E4E-767F-47B8-A79A-AA0C8EBD83C1}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{905A52E1-2634-4A7B-9A83-8119D3B2B28B}" = rport=138 | protocol=17 | dir=out | app=system |
"{9975C84E-BCB3-4EC0-B2EF-AD4E3A6AE4AA}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9B867489-881B-433B-95DA-1B94D2E11C36}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A10545C0-5E04-4098-84C2-3677BDD2D91B}" = lport=137 | protocol=17 | dir=in | app=system |
"{D1C5570F-FFAD-41BB-918F-32153DCE5FDA}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{D3B68AC1-F456-46C6-91CA-328C53962859}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01E5080F-98CB-430A-A700-4866A7116DB1}" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"{13DD5DD0-242D-4BD0-AD59-EB167D755AB0}" = protocol=6 | dir=in | app=c:\program files\common files\aol\1249422293\ee\aolsoftware.exe |
"{3ABB71A2-B77E-4862-BD45-6CBDF152890E}" = protocol=17 | dir=in | app=c:\program files\common files\aol\system information\sinf.exe |
"{3B4D169D-816A-4853-9AEA-E87082F3E7F6}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{3D253078-0B37-493F-B867-E84686DDB605}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{4FD33549-8904-4FEB-B1AC-0E898D60945D}" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"{57CAB3DC-7D38-480F-8185-99F6D1BAC92B}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5E0AAAA4-47E7-4B69-97CE-ECEB650BB37E}" = protocol=17 | dir=in | app=c:\program files\aol 9.0 vr\waol.exe |
"{614C1272-D968-4E00-9A09-1ADA4EDCD6E8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{6577F43D-5FAF-498F-9B1B-6E103D88CBD4}" = protocol=6 | dir=in | app=c:\program files\common files\aol\acs\aoldial.exe |
"{6A5FF6A2-3CB1-4508-8407-1BD472886E93}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{6EE9B36D-A153-411F-A127-454CA12D5EB1}" = protocol=6 | dir=in | app=c:\program files\common files\aol\system information\sinf.exe |
"{946B46CB-D380-4AD6-BA51-8AB8E5286164}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{95620E1D-8F8E-40B7-B156-0324ECBC5C16}" = protocol=6 | dir=in | app=c:\program files\common files\aol\acs\aolacsd.exe |
"{97D38C72-E4C0-4CE3-A241-676749934343}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AAC9DA1C-CDC9-4444-83A0-30A736C2A00D}" = protocol=6 | dir=in | app=c:\program files\common files\aol\topspeed\3.0\aoltpsd3.exe |
"{B6368EF1-F57A-412F-B0CB-70951CBF0685}" = protocol=17 | dir=in | app=c:\program files\common files\aol\acs\aolacsd.exe |
"{BFBA3987-05FD-4532-8978-5C2160C4F028}" = protocol=17 | dir=in | app=c:\program files\common files\aol\topspeed\3.0\aoltpsd3.exe |
"{C58721FE-FB8D-486D-AB3A-C835BA267A93}" = protocol=6 | dir=in | app=c:\program files\aol 9.0 vr\waol.exe |
"{C638E927-AD9D-4C8B-8407-DD3384F539F9}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{CDCCC0EA-DF3A-4935-8610-D870BE4F20F0}" = protocol=17 | dir=in | app=c:\program files\common files\aol\acs\aoldial.exe |
"{D243E28D-554C-41DF-8F51-950416EDBF04}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{DB2C8F83-719E-4246-B239-E199E638F5B6}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{DB88F476-CEC9-4DCC-9ADA-F721C0E8A02D}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{E50FBE1F-CEFA-4DF3-A152-63A4EA064B56}" = protocol=17 | dir=in | app=c:\program files\common files\aol\1249422293\ee\aolsoftware.exe |
"{ECC293F9-732B-4CBF-80E3-D6599AC591AE}" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"{F42E7EF1-35A8-4EEE-9760-64EAC5232840}" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010407-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Professional
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{02CA24DD-C8B0-4280-BE53-7862869C2EB1}" = Realtek WiFi Protected Setup Library
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{0D5D0BEE-FBA9-4928-A50D-6CDFAB827755}" = TOSHIBA ConfigFree
"{0D8E81A5-B61C-4360-910C-A738FD1B220A}" = Toshiba TEMPRO
"{0FB630AB-7BD8-40AE-B223-60397D57C3C9}" = Realtek WLAN Driver
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}" = Primo
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1C971EE3-B4C4-4367-9676-57549919C6CE}" = TOSHIBA Benutzerhandbücher
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2290A680-4083-410A-ADCC-7092C67FC052}" = Toshiba Online Product Information
"{22DD005D-0EF1-4E3E-92F8-49D89E31479A}" = 1400
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java(TM) 6 Update 29
"{2883F6F5-0509-43F3-868C-D50330DD9DD3}" = TOSHIBA Hardware Setup
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{39CB30DB-27F8-4dd4-A294-CB4AE3B584FD}" = Copy
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{44CDBD1B-89FB-4E02-8319-2A4C550F664A}" = RTC Client API v1.2
"{46C4591A-C135-482B-B653-06D67A94DA8B}_is1" = Videograbber5.3
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B1E87C3-00DE-4898-8E39-E390AAEF2391}" = TOSHIBA Supervisor Password
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A3C2391-BCE2-4D28-A336-73B953B4502F}" = 1400Trb
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6FBE200D-1F00-40B7-BF48-FEB265AADE94}" = 1400_Help
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TRDCReminder
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{895722FE-25FE-4854-95AC-B0C42F9DBEDA}" = REALTEK RTL8187B Wireless LAN Driver
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{926BD0E8-24A3-41D2-AF9B-340F1A37ED12}" = MobileMe Control Panel
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95140000-00AF-0407-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.0) - Deutsch
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C656142F-EFE1-44CD-BFAD-6CBC6DCB9860}" = Vodafone Mobile Connect Lite
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CE2121C6-C94D-4A73-8EA4-6943F33EE335}" = Music Transfer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E3723A04-A894-4036-A78E-282E18F43C0A}_is1" = Tinypic 3.14
"{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORDCLauncher
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}" = Safari
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F6D6B258-E3CA-4AAC-965A-68D3E3140A8C}" = iTunes
"{FDB5E0F3-86EA-4379-8A2F-1BC2436543E9}" = iCloud
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AOL Toolbar 4.0" =
"Avira AntiVir Desktop" = Avira Internet Security 2012
"Browser Defender_is1" = Browser Defender 3.0
"DivX Setup.divx.com" = DivX-Setup
"Freemake Video Converter_is1" = Freemake Video Converter Version 3.0.1
"GOM Player" = GOM Player
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TRDCReminder
"InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORDCLauncher
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 10.0.2 (x86 de)" = Mozilla Firefox 10.0.2 (x86 de)
"o2DE" = Mobile Connection Manager
"Picasa 3" = Picasa 3
"RealPlayer 12.0" = RealPlayer
"softonic-de3 Toolbar" = softonic-de3 Toolbar
"SumatraPDF" = SumatraPDF
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"TUGZip_is1" = TUGZip 3.5
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.1.10
"ZTE USB Driver" = ZTE USB Driver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 23.02.2012 03:50:12 | Computer Name = stefans-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4805

Error - 23.02.2012 03:50:12 | Computer Name = stefans-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4805

Error - 24.02.2012 13:56:56 | Computer Name = stefans-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 24.02.2012 13:56:57 | Computer Name = stefans-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 766121

Error - 24.02.2012 13:56:57 | Computer Name = stefans-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 766121

Error - 24.02.2012 22:23:49 | Computer Name = stefans-PC | Source = WinMgmt | ID = 10
Description =

Error - 25.02.2012 06:12:17 | Computer Name = stefans-PC | Source = WinMgmt | ID = 10
Description =

Error - 27.02.2012 09:18:22 | Computer Name = stefans-PC | Source = WinMgmt | ID = 10
Description =

Error - 27.02.2012 13:03:50 | Computer Name = stefans-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung avcenter.exe, Version 12.1.0.18, Zeitstempel
0x4e7bab7a, fehlerhaftes Modul ntdll.dll, Version 6.0.6002.18541, Zeitstempel 0x4ec3e3d5,
Ausnahmecode 0xc0150014, Fehleroffset 0x00075e2f, Prozess-ID 0xc6c, Anwendungsstartzeit
01ccf566b34bd18a.

Error - 27.02.2012 14:03:31 | Computer Name = stefans-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung avcenter.exe, Version 12.1.0.18, Zeitstempel
0x4e7bab7a, fehlerhaftes Modul ntdll.dll, Version 6.0.6002.18541, Zeitstempel 0x4ec3e3d5,
Ausnahmecode 0xc0150014, Fehleroffset 0x00075e2f, Prozess-ID 0x16fc, Anwendungsstartzeit
01ccf57500561b3a.

[ System Events ]
Error - 06.03.2012 07:16:44 | Computer Name = stefans-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 06.03.2012 07:18:00 | Computer Name = stefans-PC | Source = Service Control Manager | ID = 7034
Description =

Error - 07.03.2012 07:10:24 | Computer Name = stefans-PC | Source = Dhcp | ID = 1002
Description = Die IP-Adresslease 192.168.1.31 für die Netzwerkkarte mit der Netzwerkadresse
001A7342FFF6 wurde durch den DHCP-Server 192.168.1.1 abgelehnt (der DHCP-Server
hat eine DHCPNACK-Meldung gesendet).

Error - 07.03.2012 08:44:31 | Computer Name = stefans-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 07.03.2012 08:46:01 | Computer Name = stefans-PC | Source = Service Control Manager | ID = 7034
Description =

Error - 07.03.2012 08:50:15 | Computer Name = stefans-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 07.03.2012 08:51:25 | Computer Name = stefans-PC | Source = Service Control Manager | ID = 7034
Description =

Error - 07.03.2012 23:51:59 | Computer Name = stefans-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 08.03.2012 02:37:31 | Computer Name = stefans-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 08.03.2012 02:38:55 | Computer Name = stefans-PC | Source = Service Control Manager | ID = 7034
Description =


< End of report >


OTL logfile created on: 08.03.2012 07:56:21 - Run 4
OTL by OldTimer - Version 3.2.35.1 Folder = C:\Users\stefan\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

1,87 Gb Total Physical Memory | 0,79 Gb Available Physical Memory | 42,22% Memory free
3,98 Gb Paging File | 2,57 Gb Available in Paging File | 64,57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116,21 Gb Total Space | 30,20 Gb Free Space | 25,98% Space Free | Partition Type: NTFS
Drive E: | 115,21 Gb Total Space | 55,74 Gb Free Space | 48,39% Space Free | Partition Type: NTFS

Computer Name: STEFANS-PC | User Name: stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Users\stefan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Freemake)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)A
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
PRC - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\o2\Mobile Connection Manager\ImpWiFiSvc.exe (Telefónica I+D)
PRC - C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe (Toshiba)
PRC - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
PRC - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)


========== Modules (No Company Name) ==========

MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6310a2050033b0b567428ca55bda4a1b\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d0cf808e33a5123b33010b933d3b1597\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5c3bfd69e0c268baff0d169e11a6a784\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7fd6c62196829d1e2dce5a253145d51a\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d9f0f1dc8cbdb81f1ba122d77a6ab710\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\65450889f3742aada2a6c0cf8e6173e3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\137696d0416b65dbc1561152971488b4\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\3951e0a359c004cd6ba268ff78ac62aa\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1e258a951222c818540b33880ca45f2e\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c50133cb67d7c013fa31e1ffb942060b\System.ni.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
MOD - C:\Program Files\TUGZip\Plugins\TzArchive10.tgp ()
MOD - C:\Windows\System32\ztvunrar36.dll ()
MOD - C:\Program Files\TUGZip\TzShell.dll ()
MOD - C:\Program Files\TUGZip\Plugins\TzImage10.tgp ()


========== Win32 Services (SafeList) ==========

SRV - (Freemake Improver) -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Freemake)
SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (AntiVirMailService) -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (AntiVirFirewallService) -- C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Browser Defender Update Service) -- C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (TGCM_ImportWiFiSvc) -- C:\Program Files\o2\Mobile Connection Manager\ImpWiFiSvc.exe (Telefónica I+D)
SRV - (TemproMonitoringService) Notebook Performance Tuning Service (TEMPRO) -- C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (Toshiba Europe GmbH)
SRV - (SmartFaceVWatchSrv) -- C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe (Toshiba)
SRV - (TNaviSrv) -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (VMCService) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (ConfigFree Service) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (TOSHIBA SMART Log Service) -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (TosCoSrv) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) -- C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) -- File not found
DRV - (NwlnkFlt) -- File not found
DRV - (IpInIp) -- File not found
DRV - (esgiguard) -- File not found
DRV - (catchme) -- File not found
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (avfwot) -- C:\Windows\System32\drivers\avfwot.sys (Avira GmbH)
DRV - (avfwim) -- C:\Windows\System32\drivers\avfwim.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (ZTEusbser6k) -- C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) -- C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) -- C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (winusb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (massfilter_hs) -- C:\Windows\System32\drivers\massfilter_hs.sys (ZTE Incorporated)
DRV - (RTL8187B) -- C:\Windows\System32\drivers\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV - (tos_sps32) -- C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (UVCFTR) -- C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (TVALZ) -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (RtlProt) -- C:\Windows\System32\drivers\RtlProt.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (wanatw) WAN Miniport (ATW) -- C:\Windows\System32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (FwLnk) -- C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) -- C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (FWLANUSB) -- C:\Windows\System32\drivers\fwlanusb.sys (AVM GmbH)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
IE - HKLM\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{9A284460-6B83-4FC5-9B1D-B3C625C48887}: "URL" = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA;
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA;
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {BA778FA4-2DDB-4814-9662-D91BA0D516E1}
IE - HKCU\..\SearchScopes\{9A284460-6B83-4FC5-9B1D-B3C625C48887}: "URL" = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7GPEA_de
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245
IE - HKCU\..\SearchScopes\{BA778FA4-2DDB-4814-9662-D91BA0D516E1}: "URL" = hxxp://start.funmoods.com/results.php?f=4&a=make&q={searchTerms}
IE - HKCU\..\SearchScopes\{C64A81FB-0C89-4787-BA3B-CF8909B4FAF7}: "URL" = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "softonic-de3 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2431245&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://start.funmoods.com"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.2
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.11.2
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.2b
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?q="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\stefan\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.04.30 23:40:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2011.07.08 23:14:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012.02.05 07:42:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.11.14 22:58:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmconverter@gmail.com: C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2012.02.02 17:23:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.02.17 17:52:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.07 19:35:48 | 000,000,000 | ---D | M]

[2009.08.04 20:29:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\stefan\AppData\Roaming\mozilla\Extensions
[2012.03.06 15:50:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions
[2012.02.11 19:04:02 | 000,000,000 | ---D | M] ("Winamp Toolbar") -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2012.02.14 11:59:13 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2011.04.30 23:40:44 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.06.08 10:29:10 | 000,000,927 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\conduit.xml
[2012.02.02 17:24:05 | 000,001,798 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\funmoods.xml
[2010.09.16 14:21:14 | 000,002,689 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\search-defender.xml
[2009.12.14 05:19:41 | 000,001,246 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\winamp-search.xml
[2012.01.25 18:17:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.02.02 17:23:38 | 000,000,000 | ---D | M] (Freemake Video Converter Plugin) -- C:\PROGRAM FILES\FREEMAKE\FREEMAKE VIDEO CONVERTER\BROWSERPLUGIN\FIREFOX
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\{EF4E370E-D9F0-4E00-B93E-A4F274CFDD5A}.XPI
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\CANITBECHEAPER@TRAFFICBROKER.CO.UK.XPI
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\ISREADITLATER@IDEASHOWER.COM.XPI
[2012.02.17 17:52:40 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.19 19:03:23 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.19 19:03:23 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.10.19 19:03:23 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.19 19:03:23 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.27 19:40:39 | 000,002,027 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2011.10.19 19:03:23 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.19 19:03:23 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml

========== Chrome ==========

CHR - default_search_provider: Search (Enabled)
CHR - default_search_provider: search_url = hxxp://start.funmoods.com/results.php?f=4&a=make&q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\pdf.dll
CHR - plugin: Chrome NaCl (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\ppGoogleNaClPluginChrome.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\gears.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.53\npGoogleUpdate3.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Picasa2\npPicasa3.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\stefan\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: YouTube = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Google-Suche = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: SiteAdvisor = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.122.1_0\
CHR - Extension: Freemake Video Converter = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.1_0\
CHR - Extension: Mehr Leistung und Videoformate fr dein HTML5 video = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Google Mail = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
CHR - Extension: Google Mail = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (softonic-de3 Toolbar) - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [cfFncEnabler.exe] cfFncEnabler.exe File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (TOSHIBA)
O4 - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O9 - Extra Button: eBay - Der weltweite Online Marktplatz - {76577871-04EC-495E-A12B-91F7C3600AFA} - hxxp://rover.ebay.com/rover/1/707-44556-9400-3/4 File not found
O9 - Extra Button: Amazon.de - {8A918C1D-E123-4E36-B562-5C1519E434CE} - hxxp://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 110.164.252.222 110.164.252.223
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{162DD6C4-76E2-4D27-BAE8-43FB03178D96}: DhcpNameServer = 110.164.252.222 110.164.252.223
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2D479C68-92B0-4157-B684-8C5176B9A625}: DhcpNameServer = 192.168.8.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2FC486A3-58D8-41E1-AD9B-EBBD52601BB9}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9432ACA8-31E7-41F3-A91F-B334FC66FF5C}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 60 Days ==========

[2012.03.08 07:52:05 | 000,584,704 | ---- | C] (OldTimer Tools) -- C:\Users\stefan\Desktop\OTL.exe
[2012.03.08 07:45:55 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012.03.07 17:48:28 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\VIDEO_TS
[2012.03.07 15:24:10 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\iTunes Freemake redsn0w
[2012.03.07 15:11:16 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\salt
[2012.03.07 15:10:57 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\outländer
[2012.03.07 15:10:31 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\knight and day
[2012.03.07 12:31:39 | 000,000,000 | ---D | C] -- C:\sh4ldr
[2012.03.07 12:31:39 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2012.02.18 15:26:57 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\spongebob
[2012.02.18 03:06:55 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.02.18 03:06:52 | 001,798,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012.02.18 03:06:51 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.02.18 03:06:51 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.02.18 03:06:51 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.02.18 03:06:46 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012.02.16 07:32:53 | 002,044,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012.02.15 17:33:34 | 000,000,000 | ---D | C] -- C:\Users\stefan\AppData\Roaming\redsn0w
[2012.02.06 15:38:56 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\Techno - House - Trance - Elektro mp4 & wma
[2012.02.02 17:23:41 | 000,000,000 | ---D | C] -- C:\Users\stefan\Documents\Documents\Freemake
[2012.02.02 17:23:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Freemake
[2012.02.02 17:23:09 | 000,000,000 | ---D | C] -- C:\Users\stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
[2012.02.02 17:23:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
[2012.02.02 17:23:08 | 000,000,000 | ---D | C] -- C:\Program Files\Freemake
[2012.02.02 16:26:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012.02.02 16:25:18 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012.02.02 16:25:14 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012.01.26 11:18:56 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\i- cloud
[2012.01.14 12:44:49 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciseq.dll
[2012.01.14 12:44:36 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
[2012.01.14 12:44:32 | 000,376,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2012.01.14 12:44:18 | 001,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2012.01.14 12:44:18 | 000,497,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 60 Days ==========

[2012.03.08 07:52:20 | 000,584,704 | ---- | M] (OldTimer Tools) -- C:\Users\stefan\Desktop\OTL.exe
[2012.03.08 07:52:09 | 000,073,728 | ---- | M] () -- C:\Users\stefan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.03.08 07:49:04 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.03.08 07:43:25 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.03.08 07:43:24 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.03.08 07:43:24 | 000,126,454 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.03.08 07:43:24 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.03.08 07:37:39 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.03.08 07:36:06 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.08 07:36:06 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.08 07:35:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.03.07 15:27:37 | 000,001,194 | ---- | M] () -- C:\Users\stefan\Desktop\stefan - Verknüpfung.lnk
[2012.03.07 13:46:05 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.03.07 12:10:27 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2012.02.24 18:58:09 | 000,000,680 | ---- | M] () -- C:\Users\stefan\AppData\Local\d3d9caps.dat
[2012.02.23 09:18:36 | 000,237,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2012.02.18 03:31:26 | 000,371,368 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.02.17 03:01:33 | 000,137,416 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2012.02.14 13:59:07 | 000,002,565 | ---- | M] () -- C:\Users\stefan\Desktop\Microsoft Word.lnk
[2012.02.14 12:23:53 | 002,988,767 | ---- | M] () -- C:\Users\stefan\Muddy2.mp3
[2012.02.14 12:19:17 | 003,367,403 | ---- | M] () -- C:\Users\stefan\Muddy1.mp3
[2012.02.02 17:24:29 | 000,000,050 | ---- | M] () -- C:\user.js
[2012.01.17 18:30:43 | 216,364,819 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.01.12 20:52:56 | 002,044,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012.01.08 21:03:37 | 000,000,379 | ---- | M] () -- C:\Users\stefan\Desktop\Fotoos.lnk
[2012.01.08 08:20:04 | 000,000,406 | ---- | M] () -- C:\Users\stefan\Desktop\i 1raffetti - Verknüpfung.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012.02.14 12:23:52 | 002,988,767 | ---- | C] () -- C:\Users\stefan\Muddy2.mp3
[2012.02.14 12:19:13 | 003,367,403 | ---- | C] () -- C:\Users\stefan\Muddy1.mp3
[2012.02.02 18:37:10 | 000,001,194 | ---- | C] () -- C:\Users\stefan\Desktop\stefan - Verknüpfung.lnk
[2012.02.02 17:24:29 | 000,000,050 | ---- | C] () -- C:\user.js
[2012.01.16 20:04:18 | 216,364,819 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012.01.08 21:03:44 | 000,000,379 | ---- | C] () -- C:\Users\stefan\Desktop\Fotoos.lnk
[2012.01.08 08:20:11 | 000,000,406 | ---- | C] () -- C:\Users\stefan\Desktop\i 1raffetti - Verknüpfung.lnk
[2011.07.08 23:14:21 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2011.06.26 21:29:43 | 000,000,002 | ---- | C] () -- C:\Windows\msoffice.ini
[2011.05.08 00:51:39 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011.05.08 00:51:39 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.05.08 00:51:39 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011.05.08 00:51:39 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.05.08 00:51:39 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010.11.01 12:26:47 | 000,000,680 | ---- | C] () -- C:\Users\stefan\AppData\Local\d3d9caps.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >

cosinus 08.03.2012 12:19

Bitte nun routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

disteffensso 09.03.2012 08:36

Hallo Arne,

schön von Dir zu hören.
Leider kriege ich die Protokolle von Malwarebytes und ESET nicht kopiert und eingefügt.
Und das mit CODE- Tags schnall´ ich nicht. Drag & drop geht auch nicht.

Schönen Gruß

vonStefan

cosinus 09.03.2012 09:52

Zitat:

Leider kriege ich die Protokolle von Malwarebytes und ESET nicht kopiert und eingefügt.
Ja und wie soll ich da was zu schreiben? "Bekomms nicht kopiert" ist keine hilfreiche Aussage, was bekommt man da nicht kopiert? Alles markieren, kopieren und hier einfügen, das sind doch die geläufigsten Alltagsaufgaben in Windows überhaupt

Zitat:

Und das mit CODE- Tags schnall´ ich nicht.
Einfach kann man es nun wirklich nicht erklären :balla:
CODE-Tags wurde übrigens extra verlinkt

disteffensso 09.03.2012 13:53

Hallo Arne,
das ging vorhin nicht! Erst nach Neustart. Der Text hatte sich nicht markieren lassen, mir drag/ drop ging es auch nicht. Ich dachte schon, der Virus ist so schlau, daß er das verhindert.

Bei Malwarebytes sind 24 Logdateien aus 2011 und 1 aus 2012.
Soll ich diese öffnen, kopieren und posten?


Hier das ESET- Protokoll.

Code:

C:\Program Files\Videograbber\eBay_shortcuts_1024_Videograbber.exe        Win32/Adware.ADON application
C:\Program Files\Videograbber\Videograbber.EXE        Win32/Adware.ADON application
C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000015        Win32/RegistryBooster application
C:\Users\stefan\Desktop\EBAY 02.05.2010\download\registrybooster.exe        Win32/RegistryBooster application
C:\Users\stefan\Desktop\EBAY 02.05.2010\download\SoftonicDownloader_fuer_tuneup-utilities-2011(1).exe        a variant of Win32/SoftonicDownloader.A application
C:\Users\stefan\Desktop\EBAY 02.05.2010\download\SoftonicDownloader_fuer_tuneup-utilities-2011.exe        a variant of Win32/SoftonicDownloader.A application
C:\Users\stefan\Desktop\EBAY 02.05.2010\download\Downloads\registrybooster.exe        Win32/RegistryBooster application
C:\Users\stefan\Desktop\EBAY 02.05.2010\download\Downloads\SoftonicDownloader_fuer_tuneup-utilities-2011(1).exe        a variant of Win32/SoftonicDownloader.A application
C:\Users\stefan\Desktop\EBAY 02.05.2010\download\Downloads\SoftonicDownloader_fuer_tuneup-utilities-2011.exe        a variant of Win32/SoftonicDownloader.A application
G:\Vista\Program Files\Videograbber\eBay_shortcuts_1024_Videograbber.exe        Win32/Adware.ADON application
G:\Vista\Program Files\Videograbber\Videograbber.EXE        Win32/Adware.ADON application
G:\Vista\Users\stefan\AppData\Local\Temp\MyBabylonTB.exe        a variant of Win32/Toolbar.Babylon application
G:\Vista\Users\stefan\Desktop\EBAY 02.05.2010\download\Downloads\SoftonicDownloader_fuer_tuneup-utilities-2011(1).exe        a variant of Win32/SoftonicDownloader.A application
G:\Vista\Users\stefan\Desktop\EBAY 02.05.2010\download\Downloads\SoftonicDownloader_fuer_tuneup-utilities-2011.exe        a variant of Win32/SoftonicDownloader.A application

vonStefan

cosinus 09.03.2012 13:59

Bitte in CODE-Tags! Das kann doch nicht so schwierig sein! CODE in eckigen Klammern posten, dann das Log und abgeschlossen wird es mit /CODE in eckigen Klammern!!

Die 24-Log von MBAM alle zusammen in EINE ZIP packen und hier anhängen. Falls zu groß da abladen => File-Upload.net - Ihr kostenloser File Hoster!

disteffensso 09.03.2012 14:57

<CODE>
ein kurzer hinweis: nachlesen bei wiki
hätts auch getan.
ich dachte, in tag posten heißt, auf die site "tag" posten.
ich denke manchmal kompliziert.
so soll das aussehen, oder?
<CODE/>

cosinus 09.03.2012 16:06

ECKIGE und keine SPITZEN Klammer!

Das sind eckige Klammer => [ ]
Das sind spotze Klammern => < >

Zitat:

<CODE/>
Das ist schonmal ganz falsch - ich hab es doch oben haarklein erklärt :balla:

disteffensso 09.03.2012 16:10

Hallo Arne,
ich bekomme den Ordner nicht hochgeladen. Auch nicht mit dem upload- tool. Ich hoffe, ich darf das hier posten, soviel ist´s nicht.
In der Quarantäne habe ich 6 Eintragungen. copy/ paste geht nicht.
Dann schreibe ich sie am Besten ab?

<CODE>
Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: 6502

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

04.05.2011 01:07:57
mbam-log-2011-05-04 (01-07-57).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 179130
Laufzeit: 4 Minute(n), 18 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 1
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
c:\program files\free registry cleaner for vista (Rogue.FreeRegistryCleanerForVista) -> Quarantined and deleted successfully.

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)



Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: 6502

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

06.05.2011 08:31:11
mbam-log-2011-05-06 (08-31-11).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|)
Durchsuchte Objekte: 341072
Laufzeit: 1 Stunde(n), 18 Minute(n), 21 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\Users\stefan\AppData\Roaming\desktopicon\ebayshortcuts.exe (Adware.ADON) -> Quarantined and deleted successfully.


Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: 6502

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

08.05.2011 08:42:19
mbam-log-2011-05-08 (08-42-19).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 0
Laufzeit: 30 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)



Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: 6502

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

10.05.2011 15:45:46
mbam-log-2011-05-10 (15-45-46).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 179697
Laufzeit: 4 Minute(n), 47 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: 6548

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

11.05.2011 00:21:22
mbam-log-2011-05-11 (00-21-22).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|)
Durchsuchte Objekte: 312882
Laufzeit: 1 Stunde(n), 0 Minute(n), 48 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)



01:16:15 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 53955, Process: avwebgrd.exe)
01:16:15 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 53973, Process: avwebgrd.exe)
01:16:15 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 53997, Process: avwebgrd.exe)
01:16:15 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 54003, Process: avwebgrd.exe)
01:16:15 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 54009, Process: avwebgrd.exe)
01:16:15 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 54011, Process: avwebgrd.exe)
01:16:15 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 54014, Process: avwebgrd.exe)
01:16:15 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 54015, Process: avwebgrd.exe)
01:16:15 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 54018, Process: avwebgrd.exe)
01:16:15 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 54021, Process: avwebgrd.exe)
01:16:15 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 54029, Process: avwebgrd.exe)
01:16:15 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 54036, Process: avwebgrd.exe)
01:16:15 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 54039, Process: avwebgrd.exe)
02:22:58 stefan MESSAGE Scheduled update executed successfully
02:23:00 stefan MESSAGE IP Protection stopped
02:23:09 stefan MESSAGE Database updated successfully
02:23:11 stefan MESSAGE IP Protection started successfully
21:36:05 stefan MESSAGE Protection started successfully
21:36:11 stefan MESSAGE IP Protection started successfully



Malwarebytes' Anti-Malware 1.51.0.1200
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: 6940

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

25.06.2011 01:04:48
mbam-log-2011-06-25 (01-04-48).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|)
Durchsuchte Objekte: 333464
Laufzeit: 1 Stunde(n), 35 Minute(n), 47 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\Toshiba\Webshops\addamazontoolbarbutton.exe (Rogue.SystemSmartSecurity) -> Quarantined and deleted successfully.


Malwarebytes' Anti-Malware 1.51.0.1200
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: 7006

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

04.07.2011 03:06:52
mbam-log-2011-07-04 (03-06-52).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|)
Durchsuchte Objekte: 332761
Laufzeit: 1 Stunde(n), 34 Minute(n), 25 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)



Malwarebytes' Anti-Malware 1.51.0.1200
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: 7014

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

06.07.2011 13:58:47
mbam-log-2011-07-06 (13-58-47).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|)
Durchsuchte Objekte: 312010
Laufzeit: 1 Stunde(n), 12 Minute(n), 32 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


Malwarebytes Anti-Malware 1.60.1.1000
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: v2012.03.08.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
stefan :: STEFANS-PC [Administrator]

08.03.2012 15:11:22
mbam-log-2012-03-08 (15-11-22).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 465051
Laufzeit: 3 Stunde(n), 51 Minute(n), 12 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 4
G:\Vista\Users\stefan\AppData\Roaming\Desktopicon\eBayShortcuts.exe (Adware.ADON) -> Erfolgreich gelöscht und in Quarantäne gestellt.
G:\vonGG Rafet\Rafet\_office\MS Office 2003 Word-Excel\Thinstall\Office 2003\10000001a00002i\OfficeLiveSignIn.exe (Trojan.IRCBot) -> Erfolgreich gelöscht und in Quarantäne gestellt.
G:\vonGG Rafet\Rafet\_office\MS Office 2003 Word-Excel\Thinstall\Office 2003\1000000b00002i\rundll32.exe (Trojan.IRCBot) -> Erfolgreich gelöscht und in Quarantäne gestellt.
G:\vonGG Rafet\Rafet\_office\MS Office 2003 Word-Excel\Thinstall\Office 2003\4000003900002i\MultiKill.exe (Trojan.IRCBot) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


11:46:00 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55110, Process: avwebgrd.exe)
11:46:00 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55112, Process: avwebgrd.exe)
11:46:00 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55114, Process: avwebgrd.exe)
11:46:00 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55124, Process: avwebgrd.exe)
11:46:00 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55133, Process: avwebgrd.exe)
11:46:00 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55137, Process: avwebgrd.exe)
11:46:00 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55140, Process: avwebgrd.exe)
11:46:00 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55158, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55161, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55165, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55168, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55173, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55174, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55176, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55185, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55186, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55188, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55191, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55195, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55196, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55198, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55200, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55204, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55205, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55206, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55209, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55210, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55213, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55214, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55217, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55218, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55221, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55222, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55228, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55230, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55237, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55243, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55244, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55249, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55250, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55252, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55254, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55256, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55268, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55269, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55270, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55273, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55274, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55276, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55279, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 55280, Process: avwebgrd.exe)
11:46:17 stefan IP-BLOCK 94.198.240.136 (Type: outgoing, Port: 55282, Process: avwebgrd.exe)
11:49:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55497, Process: avwebgrd.exe)
11:49:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55498, Process: avwebgrd.exe)
11:49:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55499, Process: avwebgrd.exe)
11:49:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55501, Process: avwebgrd.exe)
11:49:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55504, Process: avwebgrd.exe)
11:49:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55505, Process: avwebgrd.exe)
11:49:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55508, Process: avwebgrd.exe)
11:49:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55509, Process: avwebgrd.exe)
11:49:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55518, Process: avwebgrd.exe)
11:49:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55521, Process: avwebgrd.exe)
11:49:53 stefan IP-BLOCK 78.108.179.67 (Type: outgoing, Port: 55529, Process: avwebgrd.exe)
11:49:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55533, Process: avwebgrd.exe)
11:50:41 stefan IP-BLOCK 94.198.240.235 (Type: outgoing, Port: 55541, Process: avwebgrd.exe)
11:50:58 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55545, Process: avwebgrd.exe)
11:50:58 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55549, Process: avwebgrd.exe)
11:50:58 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55550, Process: avwebgrd.exe)
11:50:58 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55551, Process: avwebgrd.exe)
11:50:58 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55554, Process: avwebgrd.exe)
11:50:58 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55555, Process: avwebgrd.exe)
11:50:58 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55566, Process: avwebgrd.exe)
11:50:58 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55568, Process: avwebgrd.exe)
11:50:58 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55573, Process: avwebgrd.exe)
11:50:58 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 55578, Process: avwebgrd.exe)
11:50:58 stefan IP-BLOCK 78.108.179.67 (Type: outgoing, Port: 55583, Process: avwebgrd.exe)
20:10:58 stefan MESSAGE Protection started successfully
20:11:05 stefan MESSAGE IP Protection started successfully



10:06:09 stefan IP-BLOCK 78.108.183.130 (Type: outgoing, Port: 50827, Process: avwebgrd.exe)
15:32:39 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 51161, Process: avwebgrd.exe)
15:32:39 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 51163, Process: avwebgrd.exe)
15:32:39 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 51175, Process: avwebgrd.exe)
15:32:39 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 51180, Process: avwebgrd.exe)
15:32:39 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 51182, Process: avwebgrd.exe)
15:32:39 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 51196, Process: avwebgrd.exe)
15:32:39 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 51200, Process: avwebgrd.exe)
15:32:39 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 51213, Process: avwebgrd.exe)
15:32:39 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 51216, Process: avwebgrd.exe)
15:32:39 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 51220, Process: avwebgrd.exe)
15:32:39 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 51221, Process: avwebgrd.exe)
15:32:39 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 51235, Process: avwebgrd.exe)


23:32:44 stefan MESSAGE Protection started successfully
23:32:51 stefan MESSAGE IP Protection started successfully


23:29:17 stefan MESSAGE Protection started successfully
23:29:23 stefan MESSAGE IP Protection started successfully


01:27:45 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49698, Process: avwebgrd.exe)
01:27:45 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49700, Process: avwebgrd.exe)
01:27:45 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49714, Process: avwebgrd.exe)
01:27:45 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49720, Process: avwebgrd.exe)
01:27:45 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49721, Process: avwebgrd.exe)
01:27:45 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49724, Process: avwebgrd.exe)
01:27:45 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49739, Process: avwebgrd.exe)
01:27:45 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49740, Process: avwebgrd.exe)
01:27:45 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49745, Process: avwebgrd.exe)
01:27:45 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49748, Process: avwebgrd.exe)
01:27:45 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49750, Process: avwebgrd.exe)
01:27:45 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49758, Process: avwebgrd.exe)
01:27:45 stefan IP-BLOCK 78.108.179.67 (Type: outgoing, Port: 49765, Process: avwebgrd.exe)
01:27:45 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49767, Process: avwebgrd.exe)
01:27:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49775, Process: avwebgrd.exe)
01:27:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49777, Process: avwebgrd.exe)
01:27:53 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 49779, Process: avwebgrd.exe)
01:28:09 stefan IP-BLOCK 78.108.182.90 (Type: outgoing, Port: 49781, Process: avwebgrd.exe)
01:52:53 stefan IP-BLOCK 78.108.183.130 (Type: outgoing, Port: 51767, Process: avwebgrd.exe)
02:22:57 stefan MESSAGE Scheduled update executed successfully
02:22:59 stefan MESSAGE IP Protection stopped
02:23:08 stefan MESSAGE Database updated successfully
02:23:11 stefan MESSAGE IP Protection started successfully



02:22:58 stefan MESSAGE Scheduled update executed successfully
02:23:01 stefan MESSAGE IP Protection stopped
02:23:12 stefan MESSAGE Database updated successfully
02:23:15 stefan MESSAGE IP Protection started successfully


00:55:50 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57083, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57084, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57086, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57091, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57094, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57096, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57100, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57101, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57104, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57112, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57113, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57114, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57116, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57117, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57118, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57119, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57124, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57125, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57128, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57130, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57136, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57148, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57149, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57154, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57159, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57161, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57163, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57167, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57170, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57172, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57190, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57192, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57193, Process: avwebgrd.exe)
00:55:51 stefan IP-BLOCK 78.108.179.67 (Type: outgoing, Port: 57197, Process: avwebgrd.exe)
00:55:59 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57229, Process: avwebgrd.exe)
00:55:59 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57240, Process: avwebgrd.exe)
00:55:59 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57244, Process: avwebgrd.exe)
00:55:59 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57246, Process: avwebgrd.exe)
00:55:59 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57251, Process: avwebgrd.exe)
00:55:59 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57253, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57329, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57330, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57337, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57338, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57340, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57341, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57343, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57344, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57347, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57349, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57350, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57354, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57355, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57356, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57357, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57359, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57367, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57369, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57375, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57376, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57380, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57382, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57383, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57389, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57390, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57391, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57392, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57396, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57398, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57399, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57400, Process: avwebgrd.exe)
00:57:28 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57408, Process: avwebgrd.exe)
00:57:36 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57419, Process: avwebgrd.exe)
00:57:36 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 57421, Process: avwebgrd.exe)
00:57:36 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57423, Process: avwebgrd.exe)
01:09:30 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57896, Process: avwebgrd.exe)
01:09:30 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57897, Process: avwebgrd.exe)
01:09:30 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57899, Process: avwebgrd.exe)
01:09:30 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57900, Process: avwebgrd.exe)
01:09:30 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57902, Process: avwebgrd.exe)
01:09:30 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57904, Process: avwebgrd.exe)
01:09:30 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57906, Process: avwebgrd.exe)
01:09:30 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57912, Process: avwebgrd.exe)
01:09:30 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57914, Process: avwebgrd.exe)
01:09:30 stefan IP-BLOCK 78.108.183.129 (Type: outgoing, Port: 57916, Process: avwebgrd.exe)
01:09:30 stefan IP-BLOCK 78.108.179.67 (Type: outgoing, Port: 57927, Process: avwebgrd.exe)
01:23:32 stefan IP-BLOCK 92.241.168.67 (Type: outgoing, Port: 58953, Process: avwebgrd.exe)
02:23:00 stefan MESSAGE Scheduled update executed successfully
02:23:01 stefan MESSAGE IP Protection stopped
02:23:19 stefan MESSAGE Database updated successfully
02:23:23 stefan MESSAGE IP Protection started successfully
22:23:55 stefan MESSAGE Protection started successfully
22:24:02 stefan MESSAGE IP Protection started successfully
22:37:47 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 49538, Process: avwebgrd.exe)
22:37:47 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 49550, Process: avwebgrd.exe)
22:37:47 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 49551, Process: avwebgrd.exe)
22:37:47 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 49558, Process: avwebgrd.exe)
22:37:47 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 49565, Process: avwebgrd.exe)
22:37:47 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 49566, Process: avwebgrd.exe)
22:37:55 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 49583, Process: avwebgrd.exe)
22:38:04 stefan IP-BLOCK 94.198.240.62 (Type: outgoing, Port: 49585, Process: avwebgrd.exe)


02:22:58 stefan MESSAGE Scheduled update executed successfully
02:23:04 stefan MESSAGE IP Protection stopped
02:23:27 stefan MESSAGE Database updated successfully
02:23:31 stefan MESSAGE IP Protection started successfully
16:03:22 stefan IP-BLOCK 208.91.207.65 (Type: outgoing, Port: 51206, Process: avwebgrd.exe)



12:44:20 stefan IP-BLOCK 78.108.183.130 (Type: outgoing, Port: 54591, Process: avwebgrd.exe)
13:12:48 stefan IP-BLOCK 78.108.183.130 (Type: outgoing, Port: 56044, Process: avwebgrd.exe)



20:44:30 stefan IP-BLOCK 78.108.183.130 (Type: outgoing, Port: 62636, Process: avwebgrd.exe)
20:51:51 stefan IP-BLOCK 78.108.183.130 (Type: outgoing, Port: 63216, Process: avwebgrd.exe)
20:52:16 stefan IP-BLOCK 208.91.207.65 (Type: outgoing, Port: 63328, Process: avwebgrd.exe)
20:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 63872, Process: avwebgrd.exe)
20:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 63874, Process: avwebgrd.exe)
20:57:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 63880, Process: avwebgrd.exe)
20:57:36 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 63891, Process: avwebgrd.exe)
20:57:36 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 63899, Process: avwebgrd.exe)
20:57:36 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 63900, Process: avwebgrd.exe)
20:57:36 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 63902, Process: avwebgrd.exe)
21:02:01 stefan IP-BLOCK 208.91.207.65 (Type: outgoing, Port: 64244, Process: avwebgrd.exe)
21:04:01 stefan IP-BLOCK 78.108.181.20 (Type: outgoing, Port: 64317, Process: avwebgrd.exe)
21:04:01 stefan IP-BLOCK 78.108.181.20 (Type: outgoing, Port: 64319, Process: avwebgrd.exe)



12:58:03 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 52023, Process: avwebgrd.exe)
12:58:03 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 52040, Process: avwebgrd.exe)
12:58:03 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 52041, Process: avwebgrd.exe)
12:58:03 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 52042, Process: avwebgrd.exe)
12:58:03 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 52056, Process: avwebgrd.exe)
12:58:03 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 52057, Process: avwebgrd.exe)
12:58:03 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 52061, Process: avwebgrd.exe)
12:58:03 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 52062, Process: avwebgrd.exe)
12:58:03 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 52063, Process: avwebgrd.exe)
12:58:03 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 52073, Process: avwebgrd.exe)
12:58:03 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 52076, Process: avwebgrd.exe)
12:58:03 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 52092, Process: avwebgrd.exe)
12:58:11 stefan IP-BLOCK 94.198.240.202 (Type: outgoing, Port: 52097, Process: avwebgrd.exe)
12:58:19 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 52099, Process: avwebgrd.exe)
13:19:20 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 53023, Process: avwebgrd.exe)
13:19:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 53056, Process: avwebgrd.exe)
13:19:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 53062, Process: avwebgrd.exe)
13:19:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 53075, Process: avwebgrd.exe)
13:19:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 53077, Process: avwebgrd.exe)
13:19:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 53097, Process: avwebgrd.exe)
13:19:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 53098, Process: avwebgrd.exe)
13:19:28 stefan IP-BLOCK 78.108.179.68 (Type: outgoing, Port: 53099, Process: avwebgrd.exe)
13:54:05 stefan IP-BLOCK 208.91.207.65 (Type: outgoing, Port: 55249, Process: avwebgrd.exe)


00:23:41 stefan MESSAGE IP Protection stopped
21:19:16 stefan MESSAGE Protection started successfully
21:19:30 stefan MESSAGE IP Protection started successfully
21:19:34 stefan MESSAGE IP Protection stopped
21:46:47 stefan MESSAGE Protection started successfully
21:46:54 stefan MESSAGE IP Protection started successfully
21:46:57 stefan MESSAGE IP Protection stopped
<CODE/>

Hoffentlich ist das ok so. Fürchte fast, daß nicht. Hätte nach jedem Absatz ein </> Endezeichen gehört?

Grüße
vonStefan

disteffensso 09.03.2012 16:35

Hi Arna (hatten wir vor 1 Jahr schonmal :)
Hier die abgetippte Liste der Quarantäne vom Malwarebytes.
G ist die externe Festplatte.
Jetzt ist mir die CODE/ Tag Bedeutung auch klar geworden. Legt Anfang und Ende fest.
Hätt´ ich auch selber.. bin ich aber nicht. Bin über 55, das merkt man bei sowas.
Gruß
vonStefan

<CODE>
Adware.ADON 08.03.2012, 14:14 File G:\Vista\User\stefan\AppData\Roaming\Desktopicon\eB...
Trojan.IRCBot 08.03.2012, 14:11 File G:\vonGG Rafet\Rafet\_office\MS Office 2003 Word-Exce...
Trojan.IRCBot 08.03.2012, 14:11 File G:\vonGG Rafet\Rafet\_office\MS Office 2003 Word-Exce...
Trojan.IRCBot 08.03.2012, 14:11 File G:\vonGG Rafet\Rafet\_office\MS Office 2003 Word-Exce...
Rogue.SystemS... File c:\Toshiba\Webshops\addamazontoolbarbutton.exe
Aadware.ADON File c:\User\stefan\AppData\Roaming\desktopicon\ebayshor...
<CODE/>

disteffensso 09.03.2012 16:38

Habe das mit den eckigen Klammern zu spät gelesen. Tut mir echt leid.

cosinus 10.03.2012 16:08

Zitat:

G:\vonGG Rafet\Rafet\_office\MS Office 2003 Word-Excel\Thinstall\Office 2003
Wo hast du dieses Zeugs her?

disteffensso 10.03.2012 16:23

Urlaubsbekanntschaft. Dem hats ein Arbeitskollege auf die mobile Festplatte gespielt. Die habe ich auf G kopiert und immer wieder einen Film zum Anschauen auf meinen PC gezogen.
Großartige Idee, wie mir scheint..
Gruß
Stefan

cosinus 10.03.2012 16:46

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


disteffensso 10.03.2012 17:49

Hallo Arne,
ich hatte den Firefox offen. Soll ich nochmal?

OTL Logfile:
Code:

OTL logfile created on: 10.03.2012 17:11:38 - Run 5
OTL by OldTimer - Version 3.2.35.1    Folder = C:\Users\stefan\Desktop\Trojanerjäger
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,87 Gb Total Physical Memory | 0,93 Gb Available Physical Memory | 49,49% Memory free
3,98 Gb Paging File | 2,68 Gb Available in Paging File | 67,30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116,21 Gb Total Space | 19,38 Gb Free Space | 16,67% Space Free | Partition Type: NTFS
Drive E: | 115,21 Gb Total Space | 55,26 Gb Free Space | 47,96% Space Free | Partition Type: NTFS
Drive G: | 465,65 Gb Total Space | 179,61 Gb Free Space | 38,57% Space Free | Partition Type: FAT32
 
Computer Name: STEFANS-PC | User Name: stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\stefan\Desktop\Trojanerjäger\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Freemake)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
PRC - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\o2\Mobile Connection Manager\ImpWiFiSvc.exe (Telefónica I+D)
PRC - C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe (Toshiba)
PRC - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
PRC - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6310a2050033b0b567428ca55bda4a1b\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d0cf808e33a5123b33010b933d3b1597\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5c3bfd69e0c268baff0d169e11a6a784\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7fd6c62196829d1e2dce5a253145d51a\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d9f0f1dc8cbdb81f1ba122d77a6ab710\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\65450889f3742aada2a6c0cf8e6173e3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\137696d0416b65dbc1561152971488b4\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\3951e0a359c004cd6ba268ff78ac62aa\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1e258a951222c818540b33880ca45f2e\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c50133cb67d7c013fa31e1ffb942060b\System.ni.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
MOD - C:\Program Files\TUGZip\Plugins\TzArchive10.tgp ()
MOD - C:\Windows\System32\ztvunrar36.dll ()
MOD - C:\Program Files\TUGZip\TzShell.dll ()
MOD - C:\Program Files\TUGZip\Plugins\TzImage10.tgp ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Freemake Improver) -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Freemake)
SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (AntiVirMailService) -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (AntiVirFirewallService) -- C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Browser Defender Update Service) -- C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (TGCM_ImportWiFiSvc) -- C:\Program Files\o2\Mobile Connection Manager\ImpWiFiSvc.exe (Telefónica I+D)
SRV - (TemproMonitoringService) Notebook Performance Tuning Service (TEMPRO) -- C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (Toshiba Europe GmbH)
SRV - (SmartFaceVWatchSrv) -- C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe (Toshiba)
SRV - (TNaviSrv) -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (VMCService) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (ConfigFree Service) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (TOSHIBA SMART Log Service) -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (TosCoSrv) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) -- C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (NwlnkFwd) --  File not found
DRV - (NwlnkFlt) --  File not found
DRV - (IpInIp) --  File not found
DRV - (esgiguard) --  File not found
DRV - (catchme) --  File not found
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (avfwot) -- C:\Windows\System32\drivers\avfwot.sys (Avira GmbH)
DRV - (avfwim) -- C:\Windows\System32\drivers\avfwim.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (ZTEusbser6k) -- C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) -- C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) -- C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (winusb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (massfilter_hs) -- C:\Windows\System32\drivers\massfilter_hs.sys (ZTE Incorporated)
DRV - (RTL8187B) -- C:\Windows\System32\drivers\RTL8187B.sys (Realtek Semiconductor Corporation                          )
DRV - (tos_sps32) -- C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (UVCFTR) -- C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (TVALZ) -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (RtlProt) -- C:\Windows\System32\drivers\RtlProt.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (wanatw) WAN Miniport (ATW) -- C:\Windows\System32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (FwLnk) -- C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) -- C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (FWLANUSB) -- C:\Windows\System32\drivers\fwlanusb.sys (AVM GmbH)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
IE - HKLM\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{9A284460-6B83-4FC5-9B1D-B3C625C48887}: "URL" = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA;
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA;
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {BA778FA4-2DDB-4814-9662-D91BA0D516E1}
IE - HKCU\..\SearchScopes\{9A284460-6B83-4FC5-9B1D-B3C625C48887}: "URL" = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7GPEA_de
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245
IE - HKCU\..\SearchScopes\{BA778FA4-2DDB-4814-9662-D91BA0D516E1}: "URL" = hxxp://start.funmoods.com/results.php?f=4&a=make&q={searchTerms}
IE - HKCU\..\SearchScopes\{C64A81FB-0C89-4787-BA3B-CF8909B4FAF7}: "URL" = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultthis.engineName: "softonic-de3 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2431245&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://start.funmoods.com"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.2
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.11.2
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.2b
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\stefan\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.04.30 23:40:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2011.07.08 23:14:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012.03.09 12:46:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.11.14 22:58:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmconverter@gmail.com: C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2012.02.02 17:23:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.02.17 17:52:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.07 19:35:48 | 000,000,000 | ---D | M]
 
[2009.08.04 20:29:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\stefan\AppData\Roaming\mozilla\Extensions
[2012.03.06 15:50:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions
[2012.02.11 19:04:02 | 000,000,000 | ---D | M] ("Winamp Toolbar") -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2012.02.14 11:59:13 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2011.04.30 23:40:44 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.06.08 10:29:10 | 000,000,927 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\conduit.xml
[2012.02.02 17:24:05 | 000,001,798 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\funmoods.xml
[2010.09.16 14:21:14 | 000,002,689 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\search-defender.xml
[2009.12.14 05:19:41 | 000,001,246 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\winamp-search.xml
[2012.01.25 18:17:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.02.02 17:23:38 | 000,000,000 | ---D | M] (Freemake Video Converter Plugin) -- C:\PROGRAM FILES\FREEMAKE\FREEMAKE VIDEO CONVERTER\BROWSERPLUGIN\FIREFOX
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\{EF4E370E-D9F0-4E00-B93E-A4F274CFDD5A}.XPI
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\CANITBECHEAPER@TRAFFICBROKER.CO.UK.XPI
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\ISREADITLATER@IDEASHOWER.COM.XPI
[2012.02.17 17:52:40 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.19 19:03:23 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.19 19:03:23 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.10.19 19:03:23 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.19 19:03:23 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.27 19:40:39 | 000,002,027 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2011.10.19 19:03:23 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.19 19:03:23 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Search (Enabled)
CHR - default_search_provider: search_url = hxxp://start.funmoods.com/results.php?f=4&a=make&q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit)  (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\pdf.dll
CHR - plugin: Chrome NaCl (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\ppGoogleNaClPluginChrome.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\gears.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.53\npGoogleUpdate3.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Picasa2\npPicasa3.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\stefan\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: SiteAdvisor = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.122.1_0\
CHR - Extension: Freemake Video Converter = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.1_0\
CHR - Extension: Mehr Leistung und Videoformate fr dein HTML5 video = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Google Mail = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (softonic-de3 Toolbar) - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [cfFncEnabler.exe] cfFncEnabler.exe File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (TOSHIBA)
O4 - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O9 - Extra Button: eBay - Der weltweite Online Marktplatz - {76577871-04EC-495E-A12B-91F7C3600AFA} - hxxp://rover.ebay.com/rover/1/707-44556-9400-3/4 File not found
O9 - Extra Button: Amazon.de - {8A918C1D-E123-4E36-B562-5C1519E434CE} - hxxp://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range -  5)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 110.164.252.222 110.164.252.223
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{162DD6C4-76E2-4D27-BAE8-43FB03178D96}: DhcpNameServer = 110.164.252.222 110.164.252.223
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2D479C68-92B0-4157-B684-8C5176B9A625}: DhcpNameServer = 192.168.8.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2FC486A3-58D8-41E1-AD9B-EBBD52601BB9}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9432ACA8-31E7-41F3-A91F-B334FC66FF5C}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe - (Hewlett-Packard Co.)
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE - (Microsoft Corporation)
MsConfig - StartUpFolder: C:^Users^stefan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PMB Medien-Prüfung.lnk - C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe - (Sony Corporation)
MsConfig - StartUpReg: 00TCrdMain - hkey= - key= -  File not found
MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= -  File not found
MsConfig - StartUpReg: Google EULA Launcher - hkey= - key= - c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe ( )
MsConfig - StartUpReg: HP Software Update - hkey= - key= - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
MsConfig - StartUpReg: HSON - hkey= - key= -  File not found
MsConfig - StartUpReg: RtHDVCpl - hkey= - key= - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
MsConfig - StartUpReg: Skytel - hkey= - key= - C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
MsConfig - StartUpReg: SmoothView - hkey= - key= -  File not found
MsConfig - StartUpReg: swg - hkey= - key= - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
MsConfig - StartUpReg: TkBellExe - hkey= - key= - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
MsConfig - StartUpReg: Toshiba Registration - hkey= - key= - C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe (Toshiba)
MsConfig - StartUpReg: TPwrMain - hkey= - key= -  File not found
MsConfig - StartUpReg: WinampAgent - hkey= - key= -  File not found
MsConfig - State: "services" - 2
MsConfig - State: "startup" - 2
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PEVSystemStart - Service
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Driver
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger -  File not found
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PEVSystemStart - Service
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: procexp90.Sys - Driver
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.divxa32 - C:\Windows\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.03.09 17:00:03 | 000,000,000 | R--D | C] -- C:\Users\stefan\Desktop\Trojanerjäger
[2012.03.09 15:43:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File-Upload.net
[2012.03.09 15:43:36 | 000,000,000 | ---D | C] -- C:\Users\stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File-Upload.net
[2012.03.09 15:43:36 | 000,000,000 | ---D | C] -- C:\Program Files\File-Upload.net
[2012.03.09 04:04:47 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.03.08 15:07:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.03.08 15:07:07 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.03.08 15:07:07 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.03.08 14:34:11 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\Filmää
[2012.03.08 13:43:30 | 000,000,000 | ---D | C] -- C:\Users\stefan\AppData\Roaming\dvdcss
[2012.03.08 08:29:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012.03.08 08:29:56 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2012.03.08 07:45:55 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012.03.07 15:24:10 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\iTunes Freemake redsn0w
[2012.03.07 12:31:39 | 000,000,000 | ---D | C] -- C:\sh4ldr
[2012.03.07 12:31:39 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2012.02.15 17:33:34 | 000,000,000 | ---D | C] -- C:\Users\stefan\AppData\Roaming\redsn0w
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.03.10 17:10:41 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.03.10 17:10:41 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.03.10 17:10:41 | 000,126,454 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.03.10 17:10:41 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.03.10 16:49:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.03.10 16:01:03 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.03.10 15:59:05 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.10 15:59:05 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.10 15:58:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.03.10 12:18:54 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2012.03.09 16:13:24 | 000,002,565 | ---- | M] () -- C:\Users\stefan\Desktop\Microsoft Word.lnk
[2012.03.08 13:42:20 | 000,076,288 | ---- | M] () -- C:\Users\stefan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.03.08 08:17:54 | 000,000,000 | ---- | M] () -- C:\Users\stefan\defogger_reenable
[2012.03.07 15:27:37 | 000,001,194 | ---- | M] () -- C:\Users\stefan\Desktop\stefan - Verknüpfung.lnk
[2012.02.24 18:58:09 | 000,000,680 | ---- | M] () -- C:\Users\stefan\AppData\Local\d3d9caps.dat
[2012.02.18 03:31:26 | 000,371,368 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.02.17 03:01:33 | 000,137,416 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2012.02.14 12:23:53 | 002,988,767 | ---- | M] () -- C:\Users\stefan\Muddy2.mp3
[2012.02.14 12:19:17 | 003,367,403 | ---- | M] () -- C:\Users\stefan\Muddy1.mp3
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.03.08 08:17:54 | 000,000,000 | ---- | C] () -- C:\Users\stefan\defogger_reenable
[2012.02.14 12:23:52 | 002,988,767 | ---- | C] () -- C:\Users\stefan\Muddy2.mp3
[2012.02.14 12:19:13 | 003,367,403 | ---- | C] () -- C:\Users\stefan\Muddy1.mp3
[2011.07.08 23:14:21 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2011.06.26 21:29:43 | 000,000,002 | ---- | C] () -- C:\Windows\msoffice.ini
[2011.05.08 00:51:39 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011.05.08 00:51:39 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.05.08 00:51:39 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011.05.08 00:51:39 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.05.08 00:51:39 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010.11.01 12:26:47 | 000,000,680 | ---- | C] () -- C:\Users\stefan\AppData\Local\d3d9caps.dat
 
========== LOP Check ==========
 
[2011.05.06 07:31:11 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Desktopicon
[2011.04.30 23:40:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Facebook
[2011.04.30 23:40:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\gtk-2.0
[2011.08.09 22:16:09 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Image Zone Express
[2011.05.09 22:12:03 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Modpad
[2011.04.26 21:38:31 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\PeerNetworking
[2009.08.14 15:47:54 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Printer Info Cache
[2012.02.15 17:53:59 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\redsn0w
[2011.05.12 16:03:26 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\SumatraPDF
[2011.09.01 18:46:14 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Telefónica
[2009.10.01 06:47:06 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Toshiba
[2011.04.26 21:47:03 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\TuneUp Software
[2010.11.14 19:39:02 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Uniblue
[2009.12.08 12:21:46 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Vodafone
[2009.09.02 12:50:46 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\WinBatch
[2012.03.10 12:38:37 | 000,032,626 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.12.21 23:24:22 | 000,000,434 | ---- | M] () -- C:\Windows\Tasks\SLOW-PCfighter.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.06.03 22:18:55 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Adobe
[2011.06.26 21:29:45 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\AOL
[2012.01.26 11:09:36 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Apple Computer
[2011.11.13 20:03:44 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Avira
[2011.05.06 07:31:11 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Desktopicon
[2011.05.04 00:13:36 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\DivX
[2012.03.08 13:43:30 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\dvdcss
[2011.04.30 23:40:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Facebook
[2009.08.04 12:14:21 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Google
[2011.12.29 06:26:29 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\GRETECH
[2011.04.30 23:40:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\gtk-2.0
[2009.08.14 15:31:06 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\HP
[2009.10.13 09:53:09 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\HpUpdate
[2009.08.04 00:35:28 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Identities
[2011.08.09 22:16:09 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Image Zone Express
[2009.08.04 00:33:08 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\InstallShield
[2009.08.04 21:07:07 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Macromedia
[2011.05.04 00:00:21 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Malwarebytes
[2011.06.03 22:18:55 | 000,000,000 | --SD | M] -- C:\Users\stefan\AppData\Roaming\Microsoft
[2009.08.04 01:56:05 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Microsoft Web Folders
[2011.05.09 22:12:03 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Modpad
[2009.08.04 22:44:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Mozilla
[2011.04.26 21:38:31 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\PeerNetworking
[2009.08.14 15:47:54 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Printer Info Cache
[2010.03.12 12:09:31 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Real
[2012.02.15 17:53:59 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\redsn0w
[2010.02.15 11:39:51 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Sony Corporation
[2011.05.12 16:03:26 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\SumatraPDF
[2011.09.01 18:46:14 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Telefónica
[2009.10.01 06:47:06 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Toshiba
[2011.04.26 21:47:03 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\TuneUp Software
[2010.11.14 19:39:02 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Uniblue
[2011.12.26 15:44:59 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\vlc
[2009.12.08 12:21:46 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Vodafone
[2009.09.02 12:50:46 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\WinBatch
[2010.05.01 23:28:14 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2010.06.21 04:38:34 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Users\stefan\AppData\Roaming\Facebook\uninstall.exe
[2007.03.22 11:46:40 | 000,126,976 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\GRETECH\GomPlayer\GrLauncher.exe
[2010.02.15 10:11:04 | 000,010,134 | R--- | M] () -- C:\Users\stefan\AppData\Roaming\Microsoft\Installer\{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}\ARPPRODUCTICON.exe
[2010.03.11 22:44:21 | 000,443,912 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\setup3.10\setup.exe
[2010.03.11 13:12:41 | 000,079,368 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\setup3.10\RUP\vista.exe
[2010.05.25 10:52:20 | 000,443,912 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\setup3.11\setup.exe
[2011.11.14 10:05:27 | 000,317,048 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.00\rnupgagent.exe
[2011.11.14 13:07:54 | 026,533,840 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.00\stub_data\RealPlayer_de.exe
[2011.11.14 13:05:42 | 000,676,624 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.00\stub_exe\RealPlayer_de.exe
[2010.10.21 00:16:36 | 005,401,680 | ---- | M] (Uniblue Systems Ltd                                        ) -- C:\Users\stefan\AppData\Roaming\Uniblue\DriverScanner\_temp\driverscanner.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2008.03.25 04:22:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=2D77788D0B7FE269044F58C86AE099CE -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_3e1ecd89\AGP440.sys
[2008.03.25 04:22:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=2D77788D0B7FE269044F58C86AE099CE -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.22142_none_ba734aead7ed1bb6\AGP440.sys
[2008.03.26 04:38:23 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=ED91751834103DB2A74470CD763A49FE -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_e4087235\AGP440.sys
[2008.03.26 04:38:23 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=ED91751834103DB2A74470CD763A49FE -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20800_none_b8b64d46daa7e57a\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.03.12 07:38:18 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys
[2008.03.12 07:38:18 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.21 03:23:26 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.21 03:23:26 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.03.12 07:24:20 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=96DC4E1A9F90CCD489950A8935425C59 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2008.04.15 16:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2008.04.15 16:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008.04.15 16:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\drivers\iaStor.sys
[2008.04.15 16:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_77c04a30\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 03:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008.01.21 03:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.21 03:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.21 03:24:31 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.21 03:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008.01.21 03:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.21 03:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 03:25:18 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2008.01.21 03:24:47 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 03:25:16 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.21 03:25:16 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 03:24:09 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.21 03:24:09 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.01.13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 03:25:17 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 03:25:11 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.21 03:25:11 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2008.01.21 04:20:25 | 017,223,680 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008.01.21 04:20:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008.01.21 04:20:25 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 11:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 11:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >

--- --- ---
[CustomScan mit OTL]

Gruß
vonStefan

cosinus 12.03.2012 13:11

Zitat:

Scan Mode: Current user
Du hast den Haken bei "Scanne alle Benutzer" auch vergessen :(

disteffensso 12.03.2012 15:14

Entschuldige mich für die Nachlässigkeit. Im Ernst.
Habe den Suchlauf 5 x versucht. Alles richtig eingestellt und eingefügt.
Der Suchlauf bleibt nach ca. 10 sek. bei "scanne Modules" hängen.
Auch nach Neustart.

Gruß

Stefan

cosinus 12.03.2012 15:36

Was heißt das genau? Wenn du alle Benutzer scannen willst hänger OTL sich auf?

disteffensso 12.03.2012 15:50

Nach dem 6. mal ging es. Meine Firewall ist bei jedem Neustart aus. Das macht der Virus, oder? Allerdings ist die Windows- und die Avirafirewall an. War früher kein Problem.
Im Anschluß der Log.

OTL Logfile:
Code:

OTL logfile created on: 12.03.2012 15:15:35 - Run 7
OTL by OldTimer - Version 3.2.35.1    Folder = C:\Users\stefan\Desktop\Trojanerjäger
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,87 Gb Total Physical Memory | 1,01 Gb Available Physical Memory | 54,08% Memory free
3,98 Gb Paging File | 2,86 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116,21 Gb Total Space | 20,20 Gb Free Space | 17,38% Space Free | Partition Type: NTFS
Drive E: | 115,21 Gb Total Space | 55,26 Gb Free Space | 47,96% Space Free | Partition Type: NTFS
Drive G: | 465,65 Gb Total Space | 179,61 Gb Free Space | 38,57% Space Free | Partition Type: FAT32
 
Computer Name: STEFANS-PC | User Name: stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\stefan\Desktop\Trojanerjäger\OTL.exe (OldTimer Tools)
PRC - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Freemake)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
PRC - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\o2\Mobile Connection Manager\ImpWiFiSvc.exe (Telefónica I+D)
PRC - C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe (Toshiba)
PRC - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
PRC - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6310a2050033b0b567428ca55bda4a1b\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d0cf808e33a5123b33010b933d3b1597\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5c3bfd69e0c268baff0d169e11a6a784\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7fd6c62196829d1e2dce5a253145d51a\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d9f0f1dc8cbdb81f1ba122d77a6ab710\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\65450889f3742aada2a6c0cf8e6173e3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\137696d0416b65dbc1561152971488b4\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\3951e0a359c004cd6ba268ff78ac62aa\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1e258a951222c818540b33880ca45f2e\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c50133cb67d7c013fa31e1ffb942060b\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
MOD - C:\Program Files\TUGZip\Plugins\TzArchive10.tgp ()
MOD - C:\Windows\System32\ztvunrar36.dll ()
MOD - C:\Program Files\TUGZip\Plugins\TzImage10.tgp ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Freemake Improver) -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Freemake)
SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (AntiVirMailService) -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (AntiVirFirewallService) -- C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Browser Defender Update Service) -- C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (TGCM_ImportWiFiSvc) -- C:\Program Files\o2\Mobile Connection Manager\ImpWiFiSvc.exe (Telefónica I+D)
SRV - (TemproMonitoringService) Notebook Performance Tuning Service (TEMPRO) -- C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (Toshiba Europe GmbH)
SRV - (SmartFaceVWatchSrv) -- C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe (Toshiba)
SRV - (TNaviSrv) -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (VMCService) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (ConfigFree Service) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (TOSHIBA SMART Log Service) -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (TosCoSrv) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) -- C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (NwlnkFwd) --  File not found
DRV - (NwlnkFlt) --  File not found
DRV - (IpInIp) --  File not found
DRV - (esgiguard) --  File not found
DRV - (catchme) --  File not found
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (avfwot) -- C:\Windows\System32\drivers\avfwot.sys (Avira GmbH)
DRV - (avfwim) -- C:\Windows\System32\drivers\avfwim.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (ZTEusbser6k) -- C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) -- C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) -- C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (winusb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (massfilter_hs) -- C:\Windows\System32\drivers\massfilter_hs.sys (ZTE Incorporated)
DRV - (RTL8187B) -- C:\Windows\System32\drivers\RTL8187B.sys (Realtek Semiconductor Corporation                          )
DRV - (tos_sps32) -- C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (UVCFTR) -- C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (TVALZ) -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (RtlProt) -- C:\Windows\System32\drivers\RtlProt.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (wanatw) WAN Miniport (ATW) -- C:\Windows\System32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (FwLnk) -- C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) -- C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (FWLANUSB) -- C:\Windows\System32\drivers\fwlanusb.sys (AVM GmbH)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
IE - HKLM\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{9A284460-6B83-4FC5-9B1D-B3C625C48887}: "URL" = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA;
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA;
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes,DefaultScope = {BA778FA4-2DDB-4814-9662-D91BA0D516E1}
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{9A284460-6B83-4FC5-9B1D-B3C625C48887}: "URL" = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7GPEA_de
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{BA778FA4-2DDB-4814-9662-D91BA0D516E1}: "URL" = hxxp://start.funmoods.com/results.php?f=4&a=make&q={searchTerms}
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{C64A81FB-0C89-4787-BA3B-CF8909B4FAF7}: "URL" = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={searchTerms}
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultthis.engineName: "softonic-de3 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2431245&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.2
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.11.2
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.2b
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\stefan\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.04.30 23:40:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2011.07.08 23:14:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012.03.09 12:46:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.11.14 22:58:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmconverter@gmail.com: C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2012.02.02 17:23:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.02.17 17:52:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.07 19:35:48 | 000,000,000 | ---D | M]
 
[2009.08.04 20:29:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\stefan\AppData\Roaming\mozilla\Extensions
[2012.03.06 15:50:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions
[2012.02.11 19:04:02 | 000,000,000 | ---D | M] ("Winamp Toolbar") -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2012.02.14 11:59:13 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2011.04.30 23:40:44 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.06.08 10:29:10 | 000,000,927 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\conduit.xml
[2012.02.02 17:24:05 | 000,001,798 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\funmoods.xml
[2010.09.16 14:21:14 | 000,002,689 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\search-defender.xml
[2009.12.14 05:19:41 | 000,001,246 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\winamp-search.xml
[2012.01.25 18:17:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.02.02 17:23:38 | 000,000,000 | ---D | M] (Freemake Video Converter Plugin) -- C:\PROGRAM FILES\FREEMAKE\FREEMAKE VIDEO CONVERTER\BROWSERPLUGIN\FIREFOX
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\{EF4E370E-D9F0-4E00-B93E-A4F274CFDD5A}.XPI
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\CANITBECHEAPER@TRAFFICBROKER.CO.UK.XPI
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\ISREADITLATER@IDEASHOWER.COM.XPI
[2012.02.17 17:52:40 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.19 19:03:23 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.19 19:03:23 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.10.19 19:03:23 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.19 19:03:23 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.27 19:40:39 | 000,002,027 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2011.10.19 19:03:23 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.19 19:03:23 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Search (Enabled)
CHR - default_search_provider: search_url = hxxp://start.funmoods.com/results.php?f=4&a=make&q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.78\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit)  (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.78\pdf.dll
CHR - plugin: Chrome NaCl (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.78\ppGoogleNaClPluginChrome.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.78\gears.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.53\npGoogleUpdate3.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Picasa2\npPicasa3.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\stefan\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: SiteAdvisor = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.122.1_0\
CHR - Extension: SiteAdvisor = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\
CHR - Extension: Freemake Video Converter = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.1_0\
CHR - Extension: Mehr Leistung und Videoformate fr dein HTML5 video = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Google Mail = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O3 - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\Toolbar\WebBrowser: (softonic-de3 Toolbar) - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [cfFncEnabler.exe] cfFncEnabler.exe File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (TOSHIBA)
O4 - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O4 - Startup: C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O9 - Extra Button: eBay - Der weltweite Online Marktplatz - {76577871-04EC-495E-A12B-91F7C3600AFA} - hxxp://rover.ebay.com/rover/1/707-44556-9400-3/4 File not found
O9 - Extra Button: Amazon.de - {8A918C1D-E123-4E36-B562-5C1519E434CE} - hxxp://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..Trusted Domains: aol.com ([objects] * is out of zone range -  5)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 110.164.252.222 110.164.252.223
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{162DD6C4-76E2-4D27-BAE8-43FB03178D96}: DhcpNameServer = 110.164.252.222 110.164.252.223
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2D479C68-92B0-4157-B684-8C5176B9A625}: DhcpNameServer = 192.168.8.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2FC486A3-58D8-41E1-AD9B-EBBD52601BB9}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9432ACA8-31E7-41F3-A91F-B334FC66FF5C}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe - (Hewlett-Packard Co.)
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE - (Microsoft Corporation)
MsConfig - StartUpFolder: C:^Users^stefan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PMB Medien-Prüfung.lnk - C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe - (Sony Corporation)
MsConfig - StartUpReg: 00TCrdMain - hkey= - key= -  File not found
MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= -  File not found
MsConfig - StartUpReg: Google EULA Launcher - hkey= - key= - c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe ( )
MsConfig - StartUpReg: HP Software Update - hkey= - key= - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
MsConfig - StartUpReg: HSON - hkey= - key= -  File not found
MsConfig - StartUpReg: RtHDVCpl - hkey= - key= - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
MsConfig - StartUpReg: Skytel - hkey= - key= - C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
MsConfig - StartUpReg: SmoothView - hkey= - key= -  File not found
MsConfig - StartUpReg: swg - hkey= - key= - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
MsConfig - StartUpReg: TkBellExe - hkey= - key= - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
MsConfig - StartUpReg: Toshiba Registration - hkey= - key= - C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe (Toshiba)
MsConfig - StartUpReg: TPwrMain - hkey= - key= -  File not found
MsConfig - StartUpReg: WinampAgent - hkey= - key= -  File not found
MsConfig - State: "services" - 2
MsConfig - State: "startup" - 2
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PEVSystemStart - Service
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Driver
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger -  File not found
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PEVSystemStart - Service
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: procexp90.Sys - Driver
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.divxa32 - C:\Windows\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.03.09 17:00:03 | 000,000,000 | R--D | C] -- C:\Users\stefan\Desktop\Trojanerjäger
[2012.03.09 15:43:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File-Upload.net
[2012.03.09 15:43:36 | 000,000,000 | ---D | C] -- C:\Users\stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File-Upload.net
[2012.03.09 15:43:36 | 000,000,000 | ---D | C] -- C:\Program Files\File-Upload.net
[2012.03.09 04:04:47 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.03.08 15:07:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.03.08 15:07:07 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.03.08 15:07:07 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.03.08 14:34:11 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\Filmää
[2012.03.08 13:43:30 | 000,000,000 | ---D | C] -- C:\Users\stefan\AppData\Roaming\dvdcss
[2012.03.08 08:29:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012.03.08 08:29:56 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2012.03.08 07:45:55 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012.03.07 15:24:10 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\iTunes Freemake redsn0w
[2012.03.07 12:31:39 | 000,000,000 | ---D | C] -- C:\sh4ldr
[2012.03.07 12:31:39 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2012.02.15 17:33:34 | 000,000,000 | ---D | C] -- C:\Users\stefan\AppData\Roaming\redsn0w
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.03.12 15:05:00 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.03.12 15:05:00 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.03.12 15:05:00 | 000,126,454 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.03.12 15:05:00 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.03.12 15:01:41 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.03.12 14:59:59 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.12 14:59:59 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.12 14:59:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.03.12 14:49:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.03.11 15:40:07 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2012.03.10 19:04:40 | 000,057,866 | ---- | M] () -- C:\Users\stefan\Desktop\1966-pontiac-grand-prix.jpg
[2012.03.10 17:52:50 | 000,002,565 | ---- | M] () -- C:\Users\stefan\Desktop\Microsoft Word.lnk
[2012.03.08 13:42:20 | 000,076,288 | ---- | M] () -- C:\Users\stefan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.03.08 08:17:54 | 000,000,000 | ---- | M] () -- C:\Users\stefan\defogger_reenable
[2012.03.07 15:27:37 | 000,001,194 | ---- | M] () -- C:\Users\stefan\Desktop\stefan - Verknüpfung.lnk
[2012.02.24 18:58:09 | 000,000,680 | ---- | M] () -- C:\Users\stefan\AppData\Local\d3d9caps.dat
[2012.02.18 03:31:26 | 000,371,368 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.02.17 03:01:33 | 000,137,416 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2012.02.14 12:23:53 | 002,988,767 | ---- | M] () -- C:\Users\stefan\Muddy2.mp3
[2012.02.14 12:19:17 | 003,367,403 | ---- | M] () -- C:\Users\stefan\Muddy1.mp3
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.03.10 19:04:36 | 000,057,866 | ---- | C] () -- C:\Users\stefan\Desktop\1966-pontiac-grand-prix.jpg
[2012.03.08 08:17:54 | 000,000,000 | ---- | C] () -- C:\Users\stefan\defogger_reenable
[2012.02.14 12:23:52 | 002,988,767 | ---- | C] () -- C:\Users\stefan\Muddy2.mp3
[2012.02.14 12:19:13 | 003,367,403 | ---- | C] () -- C:\Users\stefan\Muddy1.mp3
[2011.07.08 23:14:21 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2011.06.26 21:29:43 | 000,000,002 | ---- | C] () -- C:\Windows\msoffice.ini
[2011.05.08 00:51:39 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011.05.08 00:51:39 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.05.08 00:51:39 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011.05.08 00:51:39 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.05.08 00:51:39 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010.11.01 12:26:47 | 000,000,680 | ---- | C] () -- C:\Users\stefan\AppData\Local\d3d9caps.dat
 
========== LOP Check ==========
 
[2011.11.13 20:40:57 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\Telefónica
[2010.09.16 09:20:27 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\Vodafone
[2011.05.06 07:31:11 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Desktopicon
[2011.04.30 23:40:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Facebook
[2011.04.30 23:40:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\gtk-2.0
[2011.08.09 22:16:09 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Image Zone Express
[2011.05.09 22:12:03 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Modpad
[2011.04.26 21:38:31 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\PeerNetworking
[2009.08.14 15:47:54 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Printer Info Cache
[2012.02.15 17:53:59 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\redsn0w
[2011.05.12 16:03:26 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\SumatraPDF
[2011.09.01 18:46:14 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Telefónica
[2009.10.01 06:47:06 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Toshiba
[2011.04.26 21:47:03 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\TuneUp Software
[2010.11.14 19:39:02 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Uniblue
[2009.12.08 12:21:46 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Vodafone
[2009.09.02 12:50:46 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\WinBatch
[2012.03.12 14:58:13 | 000,032,626 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.12.21 23:24:22 | 000,000,434 | ---- | M] () -- C:\Windows\Tasks\SLOW-PCfighter.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.06.03 22:18:55 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Adobe
[2011.06.26 21:29:45 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\AOL
[2012.01.26 11:09:36 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Apple Computer
[2011.11.13 20:03:44 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Avira
[2011.05.06 07:31:11 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Desktopicon
[2011.05.04 00:13:36 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\DivX
[2012.03.08 13:43:30 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\dvdcss
[2011.04.30 23:40:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Facebook
[2009.08.04 12:14:21 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Google
[2011.12.29 06:26:29 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\GRETECH
[2011.04.30 23:40:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\gtk-2.0
[2009.08.14 15:31:06 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\HP
[2009.10.13 09:53:09 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\HpUpdate
[2009.08.04 00:35:28 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Identities
[2011.08.09 22:16:09 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Image Zone Express
[2009.08.04 00:33:08 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\InstallShield
[2009.08.04 21:07:07 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Macromedia
[2011.05.04 00:00:21 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Malwarebytes
[2011.06.03 22:18:55 | 000,000,000 | --SD | M] -- C:\Users\stefan\AppData\Roaming\Microsoft
[2009.08.04 01:56:05 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Microsoft Web Folders
[2011.05.09 22:12:03 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Modpad
[2009.08.04 22:44:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Mozilla
[2011.04.26 21:38:31 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\PeerNetworking
[2009.08.14 15:47:54 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Printer Info Cache
[2010.03.12 12:09:31 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Real
[2012.02.15 17:53:59 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\redsn0w
[2010.02.15 11:39:51 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Sony Corporation
[2011.05.12 16:03:26 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\SumatraPDF
[2011.09.01 18:46:14 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Telefónica
[2009.10.01 06:47:06 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Toshiba
[2011.04.26 21:47:03 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\TuneUp Software
[2010.11.14 19:39:02 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Uniblue
[2011.12.26 15:44:59 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\vlc
[2009.12.08 12:21:46 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Vodafone
[2009.09.02 12:50:46 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\WinBatch
[2010.05.01 23:28:14 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2010.06.21 04:38:34 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Users\stefan\AppData\Roaming\Facebook\uninstall.exe
[2007.03.22 11:46:40 | 000,126,976 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\GRETECH\GomPlayer\GrLauncher.exe
[2010.02.15 10:11:04 | 000,010,134 | R--- | M] () -- C:\Users\stefan\AppData\Roaming\Microsoft\Installer\{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}\ARPPRODUCTICON.exe
[2010.03.11 22:44:21 | 000,443,912 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\setup3.10\setup.exe
[2010.03.11 13:12:41 | 000,079,368 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\setup3.10\RUP\vista.exe
[2010.05.25 10:52:20 | 000,443,912 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\setup3.11\setup.exe
[2011.11.14 10:05:27 | 000,317,048 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.00\rnupgagent.exe
[2011.11.14 13:07:54 | 026,533,840 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.00\stub_data\RealPlayer_de.exe
[2011.11.14 13:05:42 | 000,676,624 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.00\stub_exe\RealPlayer_de.exe
[2010.10.21 00:16:36 | 005,401,680 | ---- | M] (Uniblue Systems Ltd                                        ) -- C:\Users\stefan\AppData\Roaming\Uniblue\DriverScanner\_temp\driverscanner.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2008.03.25 04:22:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=2D77788D0B7FE269044F58C86AE099CE -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_3e1ecd89\AGP440.sys
[2008.03.25 04:22:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=2D77788D0B7FE269044F58C86AE099CE -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.22142_none_ba734aead7ed1bb6\AGP440.sys
[2008.03.26 04:38:23 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=ED91751834103DB2A74470CD763A49FE -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_e4087235\AGP440.sys
[2008.03.26 04:38:23 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=ED91751834103DB2A74470CD763A49FE -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20800_none_b8b64d46daa7e57a\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.03.12 07:38:18 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys
[2008.03.12 07:38:18 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.21 03:23:26 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.21 03:23:26 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.03.12 07:24:20 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=96DC4E1A9F90CCD489950A8935425C59 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2008.04.15 16:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2008.04.15 16:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008.04.15 16:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\drivers\iaStor.sys
[2008.04.15 16:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_77c04a30\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 03:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008.01.21 03:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.21 03:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.21 03:24:31 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.21 03:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008.01.21 03:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.21 03:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 03:25:18 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2008.01.21 03:24:47 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 03:25:16 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.21 03:25:16 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 03:24:09 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.21 03:24:09 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.01.13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 03:25:17 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 03:25:11 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.21 03:25:11 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2008.01.21 04:20:25 | 017,223,680 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008.01.21 04:20:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008.01.21 04:20:25 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 11:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 11:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >

--- --- ---
[CustomScan mit OTL]

Gruß
vonStefan.

cosinus 12.03.2012 15:58

Zitat:

Allerdings ist die Windows- und die Avirafirewall an.
Was soll sowas?! Zwei PFWs sind Unsinn hoch drei!
Schmeiß die Avira-Firewall runter!

disteffensso 12.03.2012 16:06

Ist da Microsoft echt besser? Schau an.
Nebenbei: Was für ein Antivirenprogramm hast Du drauf?

Gruß
von Stefan

cosinus 12.03.2012 16:20

Zitat:

Nebenbei: Was für ein Antivirenprogramm hast Du drauf?
Unter Windows zu Hause nutze ich nur Malwarebytes.

Zitat:

O2 - BHO: (DivX Plus Web Player HTML5 <video>)
Gehörst du auch zur der Fraktion, die sich Serien und Kinofilme über dubiose Portale anschaut?
Wenn ja: in Zukunft Finger weg, diese illegalen Portale verbreiten Malware und wenn du in Zukunft malwarefrei sein wilst, musst du auf legale Alternativen ausweichen und auf solche riskanten Streamingseiten verzichten!

disteffensso 12.03.2012 16:31

Hab´ ich einmal versucht. Kino.to. Hat mir die Avira gesperrt. In Deutschland geh´ ich höchstens mal zur Videothek. Bin, wie gesagt, schon wat älter und überwintere in Thailand. Da zwickts nicht ganz so wie in der Kälte daheim. Mein Nachbar hat mir seine Festplatte zum Kopieren gegeben. Bin hier um Ablenkung froh, weil ich mit den Thaifrauen nix anfangen kann. Auf die Idee, daß ich da einen Virus... Sonst paß´ ich auf wie ein Haftlmacher (bin Münchner). Tja und jetzt? Habe ich einen Zombie?

Gruß

von Stefan.

cosinus 12.03.2012 16:36

Wie gesagt: schmeiß die Avira-Firewall runter. Und diesen DivX-Kram am besten auch gleich.
Mach danach wieder ein neues OTL-Log

disteffensso 12.03.2012 17:01

Die Avira FW schaltet sich beim Neustart wieder an, die Windows FW aus. Habe jetzt manuell umgeschaltet. Alle 4 Komponenten von DivX Player deinstalliert. OTL scan mit eingefügtem Text ausführen, also wie vorher?

Gruß
vonStefan

cosinus 12.03.2012 17:16

Ja genauso wie vorher

disteffensso 12.03.2012 17:46

War eine überflüssige Frage.

OTL Logfile:
Code:

OTL logfile created on: 12.03.2012 17:16:28 - Run 8
OTL by OldTimer - Version 3.2.35.1    Folder = C:\Users\stefan\Desktop\Trojanerjäger
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,87 Gb Total Physical Memory | 1,01 Gb Available Physical Memory | 54,04% Memory free
3,98 Gb Paging File | 2,86 Gb Available in Paging File | 71,77% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116,21 Gb Total Space | 20,68 Gb Free Space | 17,79% Space Free | Partition Type: NTFS
Drive E: | 115,21 Gb Total Space | 55,26 Gb Free Space | 47,96% Space Free | Partition Type: NTFS
Drive G: | 465,65 Gb Total Space | 179,61 Gb Free Space | 38,57% Space Free | Partition Type: FAT32
 
Computer Name: STEFANS-PC | User Name: stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\stefan\Desktop\Trojanerjäger\OTL.exe (OldTimer Tools)
PRC - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Freemake)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
PRC - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\o2\Mobile Connection Manager\ImpWiFiSvc.exe (Telefónica I+D)
PRC - C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe (Toshiba)
PRC - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
PRC - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6310a2050033b0b567428ca55bda4a1b\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d0cf808e33a5123b33010b933d3b1597\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5c3bfd69e0c268baff0d169e11a6a784\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7fd6c62196829d1e2dce5a253145d51a\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d9f0f1dc8cbdb81f1ba122d77a6ab710\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\65450889f3742aada2a6c0cf8e6173e3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\137696d0416b65dbc1561152971488b4\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\3951e0a359c004cd6ba268ff78ac62aa\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1e258a951222c818540b33880ca45f2e\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c50133cb67d7c013fa31e1ffb942060b\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
MOD - C:\Program Files\TUGZip\Plugins\TzArchive10.tgp ()
MOD - C:\Windows\System32\ztvunrar36.dll ()
MOD - C:\Program Files\TUGZip\Plugins\TzImage10.tgp ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Freemake Improver) -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Freemake)
SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (AntiVirMailService) -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (AntiVirFirewallService) -- C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Browser Defender Update Service) -- C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (TGCM_ImportWiFiSvc) -- C:\Program Files\o2\Mobile Connection Manager\ImpWiFiSvc.exe (Telefónica I+D)
SRV - (TemproMonitoringService) Notebook Performance Tuning Service (TEMPRO) -- C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (Toshiba Europe GmbH)
SRV - (SmartFaceVWatchSrv) -- C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe (Toshiba)
SRV - (TNaviSrv) -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (VMCService) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (ConfigFree Service) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (TOSHIBA SMART Log Service) -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (TosCoSrv) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) -- C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (NwlnkFwd) --  File not found
DRV - (NwlnkFlt) --  File not found
DRV - (IpInIp) --  File not found
DRV - (esgiguard) --  File not found
DRV - (catchme) --  File not found
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (avfwot) -- C:\Windows\System32\drivers\avfwot.sys (Avira GmbH)
DRV - (avfwim) -- C:\Windows\System32\drivers\avfwim.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (ZTEusbser6k) -- C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) -- C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) -- C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (winusb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (massfilter_hs) -- C:\Windows\System32\drivers\massfilter_hs.sys (ZTE Incorporated)
DRV - (RTL8187B) -- C:\Windows\System32\drivers\RTL8187B.sys (Realtek Semiconductor Corporation                          )
DRV - (tos_sps32) -- C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (UVCFTR) -- C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (TVALZ) -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (RtlProt) -- C:\Windows\System32\drivers\RtlProt.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (wanatw) WAN Miniport (ATW) -- C:\Windows\System32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (FwLnk) -- C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) -- C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (FWLANUSB) -- C:\Windows\System32\drivers\fwlanusb.sys (AVM GmbH)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
IE - HKLM\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{9A284460-6B83-4FC5-9B1D-B3C625C48887}: "URL" = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA;
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA;
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes,DefaultScope = {BA778FA4-2DDB-4814-9662-D91BA0D516E1}
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{9A284460-6B83-4FC5-9B1D-B3C625C48887}: "URL" = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7GPEA_de
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{BA778FA4-2DDB-4814-9662-D91BA0D516E1}: "URL" = hxxp://start.funmoods.com/results.php?f=4&a=make&q={searchTerms}
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{C64A81FB-0C89-4787-BA3B-CF8909B4FAF7}: "URL" = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={searchTerms}
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultthis.engineName: "softonic-de3 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2431245&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.2
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.11.2
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.2b
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\stefan\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.04.30 23:40:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2011.07.08 23:14:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012.03.09 12:46:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmconverter@gmail.com: C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2012.02.02 17:23:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.02.17 17:52:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.07 19:35:48 | 000,000,000 | ---D | M]
 
[2009.08.04 20:29:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\stefan\AppData\Roaming\mozilla\Extensions
[2012.03.06 15:50:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions
[2012.02.11 19:04:02 | 000,000,000 | ---D | M] ("Winamp Toolbar") -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2012.02.14 11:59:13 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2011.04.30 23:40:44 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.06.08 10:29:10 | 000,000,927 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\conduit.xml
[2012.02.02 17:24:05 | 000,001,798 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\funmoods.xml
[2010.09.16 14:21:14 | 000,002,689 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\search-defender.xml
[2009.12.14 05:19:41 | 000,001,246 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\winamp-search.xml
[2012.01.25 18:17:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.02.02 17:23:38 | 000,000,000 | ---D | M] (Freemake Video Converter Plugin) -- C:\PROGRAM FILES\FREEMAKE\FREEMAKE VIDEO CONVERTER\BROWSERPLUGIN\FIREFOX
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\{EF4E370E-D9F0-4E00-B93E-A4F274CFDD5A}.XPI
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\CANITBECHEAPER@TRAFFICBROKER.CO.UK.XPI
() (No name found) -- C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\EXTENSIONS\ISREADITLATER@IDEASHOWER.COM.XPI
[2012.02.17 17:52:40 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.19 19:03:23 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.19 19:03:23 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.10.19 19:03:23 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.19 19:03:23 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.27 19:40:39 | 000,002,027 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2011.10.19 19:03:23 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.19 19:03:23 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Search (Enabled)
CHR - default_search_provider: search_url = hxxp://start.funmoods.com/results.php?f=4&a=make&q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.78\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit)  (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.78\pdf.dll
CHR - plugin: Chrome NaCl (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.78\ppGoogleNaClPluginChrome.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.78\gears.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.53\npGoogleUpdate3.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Picasa2\npPicasa3.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\stefan\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: SiteAdvisor = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\
CHR - Extension: Freemake Video Converter = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.1_0\
CHR - Extension: Google Mail = C:\Users\stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O3 - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\Toolbar\WebBrowser: (softonic-de3 Toolbar) - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [cfFncEnabler.exe] cfFncEnabler.exe File not found
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (TOSHIBA)
O4 - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O4 - Startup: C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O9 - Extra Button: eBay - Der weltweite Online Marktplatz - {76577871-04EC-495E-A12B-91F7C3600AFA} - hxxp://rover.ebay.com/rover/1/707-44556-9400-3/4 File not found
O9 - Extra Button: Amazon.de - {8A918C1D-E123-4E36-B562-5C1519E434CE} - hxxp://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..Trusted Domains: aol.com ([objects] * is out of zone range -  5)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 110.164.252.222 110.164.252.223
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{162DD6C4-76E2-4D27-BAE8-43FB03178D96}: DhcpNameServer = 110.164.252.222 110.164.252.223
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2D479C68-92B0-4157-B684-8C5176B9A625}: DhcpNameServer = 192.168.8.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2FC486A3-58D8-41E1-AD9B-EBBD52601BB9}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9432ACA8-31E7-41F3-A91F-B334FC66FF5C}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe - (Hewlett-Packard Co.)
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE - (Microsoft Corporation)
MsConfig - StartUpFolder: C:^Users^stefan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PMB Medien-Prüfung.lnk - C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe - (Sony Corporation)
MsConfig - StartUpReg: 00TCrdMain - hkey= - key= -  File not found
MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= -  File not found
MsConfig - StartUpReg: Google EULA Launcher - hkey= - key= - c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe ( )
MsConfig - StartUpReg: HP Software Update - hkey= - key= - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
MsConfig - StartUpReg: HSON - hkey= - key= -  File not found
MsConfig - StartUpReg: RtHDVCpl - hkey= - key= - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
MsConfig - StartUpReg: Skytel - hkey= - key= - C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
MsConfig - StartUpReg: SmoothView - hkey= - key= -  File not found
MsConfig - StartUpReg: swg - hkey= - key= - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
MsConfig - StartUpReg: TkBellExe - hkey= - key= - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
MsConfig - StartUpReg: Toshiba Registration - hkey= - key= - C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe (Toshiba)
MsConfig - StartUpReg: TPwrMain - hkey= - key= -  File not found
MsConfig - StartUpReg: WinampAgent - hkey= - key= -  File not found
MsConfig - State: "services" - 2
MsConfig - State: "startup" - 2
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PEVSystemStart - Service
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Driver
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger -  File not found
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PEVSystemStart - Service
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: procexp90.Sys - Driver
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.divxa32 - C:\Windows\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.03.09 17:00:03 | 000,000,000 | R--D | C] -- C:\Users\stefan\Desktop\Trojanerjäger
[2012.03.09 15:43:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File-Upload.net
[2012.03.09 15:43:36 | 000,000,000 | ---D | C] -- C:\Users\stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File-Upload.net
[2012.03.09 15:43:36 | 000,000,000 | ---D | C] -- C:\Program Files\File-Upload.net
[2012.03.09 04:04:47 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.03.08 15:07:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.03.08 15:07:07 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.03.08 15:07:07 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.03.08 14:34:11 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\Filmää
[2012.03.08 13:43:30 | 000,000,000 | ---D | C] -- C:\Users\stefan\AppData\Roaming\dvdcss
[2012.03.08 08:29:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012.03.08 08:29:56 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2012.03.08 07:45:55 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012.03.07 15:24:10 | 000,000,000 | ---D | C] -- C:\Users\stefan\Desktop\iTunes Freemake redsn0w
[2012.03.07 12:31:39 | 000,000,000 | ---D | C] -- C:\sh4ldr
[2012.03.07 12:31:39 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2012.02.15 17:33:34 | 000,000,000 | ---D | C] -- C:\Users\stefan\AppData\Roaming\redsn0w
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.03.12 16:49:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.03.12 16:48:13 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.03.12 16:48:13 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.03.12 16:48:13 | 000,126,454 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.03.12 16:48:13 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.03.12 16:45:33 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.03.12 16:43:52 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.12 16:43:52 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.12 16:43:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.03.12 16:07:16 | 000,479,190 | ---- | M] () -- C:\Users\stefan\Desktop\Foto.JPG
[2012.03.11 15:40:07 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2012.03.10 19:04:40 | 000,057,866 | ---- | M] () -- C:\Users\stefan\Desktop\1966-pontiac-grand-prix.jpg
[2012.03.10 17:52:50 | 000,002,565 | ---- | M] () -- C:\Users\stefan\Desktop\Microsoft Word.lnk
[2012.03.08 13:42:20 | 000,076,288 | ---- | M] () -- C:\Users\stefan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.03.08 08:17:54 | 000,000,000 | ---- | M] () -- C:\Users\stefan\defogger_reenable
[2012.03.07 15:27:37 | 000,001,194 | ---- | M] () -- C:\Users\stefan\Desktop\stefan - Verknüpfung.lnk
[2012.02.24 18:58:09 | 000,000,680 | ---- | M] () -- C:\Users\stefan\AppData\Local\d3d9caps.dat
[2012.02.18 03:31:26 | 000,371,368 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.02.17 03:01:33 | 000,137,416 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2012.02.14 12:23:53 | 002,988,767 | ---- | M] () -- C:\Users\stefan\Muddy2.mp3
[2012.02.14 12:19:17 | 003,367,403 | ---- | M] () -- C:\Users\stefan\Muddy1.mp3
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.03.12 16:07:13 | 000,479,190 | ---- | C] () -- C:\Users\stefan\Desktop\Foto.JPG
[2012.03.10 19:04:36 | 000,057,866 | ---- | C] () -- C:\Users\stefan\Desktop\1966-pontiac-grand-prix.jpg
[2012.03.08 08:17:54 | 000,000,000 | ---- | C] () -- C:\Users\stefan\defogger_reenable
[2012.02.14 12:23:52 | 002,988,767 | ---- | C] () -- C:\Users\stefan\Muddy2.mp3
[2012.02.14 12:19:13 | 003,367,403 | ---- | C] () -- C:\Users\stefan\Muddy1.mp3
[2011.07.08 23:14:21 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2011.06.26 21:29:43 | 000,000,002 | ---- | C] () -- C:\Windows\msoffice.ini
[2011.05.08 00:51:39 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011.05.08 00:51:39 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.05.08 00:51:39 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011.05.08 00:51:39 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.05.08 00:51:39 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010.11.01 12:26:47 | 000,000,680 | ---- | C] () -- C:\Users\stefan\AppData\Local\d3d9caps.dat
 
========== LOP Check ==========
 
[2011.11.13 20:40:57 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\Telefónica
[2010.09.16 09:20:27 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\Vodafone
[2011.05.06 07:31:11 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Desktopicon
[2011.04.30 23:40:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Facebook
[2011.04.30 23:40:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\gtk-2.0
[2011.08.09 22:16:09 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Image Zone Express
[2011.05.09 22:12:03 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Modpad
[2011.04.26 21:38:31 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\PeerNetworking
[2009.08.14 15:47:54 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Printer Info Cache
[2012.02.15 17:53:59 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\redsn0w
[2011.05.12 16:03:26 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\SumatraPDF
[2011.09.01 18:46:14 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Telefónica
[2009.10.01 06:47:06 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Toshiba
[2011.04.26 21:47:03 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\TuneUp Software
[2010.11.14 19:39:02 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Uniblue
[2009.12.08 12:21:46 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Vodafone
[2009.09.02 12:50:46 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\WinBatch
[2012.03.12 16:42:01 | 000,032,626 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.12.21 23:24:22 | 000,000,434 | ---- | M] () -- C:\Windows\Tasks\SLOW-PCfighter.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.06.03 22:18:55 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Adobe
[2011.06.26 21:29:45 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\AOL
[2012.01.26 11:09:36 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Apple Computer
[2011.11.13 20:03:44 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Avira
[2011.05.06 07:31:11 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Desktopicon
[2011.05.04 00:13:36 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\DivX
[2012.03.08 13:43:30 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\dvdcss
[2011.04.30 23:40:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Facebook
[2009.08.04 12:14:21 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Google
[2011.12.29 06:26:29 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\GRETECH
[2011.04.30 23:40:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\gtk-2.0
[2009.08.14 15:31:06 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\HP
[2009.10.13 09:53:09 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\HpUpdate
[2009.08.04 00:35:28 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Identities
[2011.08.09 22:16:09 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Image Zone Express
[2009.08.04 00:33:08 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\InstallShield
[2009.08.04 21:07:07 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Macromedia
[2011.05.04 00:00:21 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Malwarebytes
[2011.06.03 22:18:55 | 000,000,000 | --SD | M] -- C:\Users\stefan\AppData\Roaming\Microsoft
[2009.08.04 01:56:05 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Microsoft Web Folders
[2011.05.09 22:12:03 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Modpad
[2009.08.04 22:44:43 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Mozilla
[2011.04.26 21:38:31 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\PeerNetworking
[2009.08.14 15:47:54 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Printer Info Cache
[2010.03.12 12:09:31 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Real
[2012.02.15 17:53:59 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\redsn0w
[2010.02.15 11:39:51 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Sony Corporation
[2011.05.12 16:03:26 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\SumatraPDF
[2011.09.01 18:46:14 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Telefónica
[2009.10.01 06:47:06 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Toshiba
[2011.04.26 21:47:03 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\TuneUp Software
[2010.11.14 19:39:02 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Uniblue
[2011.12.26 15:44:59 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\vlc
[2009.12.08 12:21:46 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\Vodafone
[2009.09.02 12:50:46 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\WinBatch
[2010.05.01 23:28:14 | 000,000,000 | ---D | M] -- C:\Users\stefan\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2010.06.21 04:38:34 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Users\stefan\AppData\Roaming\Facebook\uninstall.exe
[2007.03.22 11:46:40 | 000,126,976 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\GRETECH\GomPlayer\GrLauncher.exe
[2010.02.15 10:11:04 | 000,010,134 | R--- | M] () -- C:\Users\stefan\AppData\Roaming\Microsoft\Installer\{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}\ARPPRODUCTICON.exe
[2010.03.11 22:44:21 | 000,443,912 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\setup3.10\setup.exe
[2010.03.11 13:12:41 | 000,079,368 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\setup3.10\RUP\vista.exe
[2010.05.25 10:52:20 | 000,443,912 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\setup3.11\setup.exe
[2011.11.14 10:05:27 | 000,317,048 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.00\rnupgagent.exe
[2011.11.14 13:07:54 | 026,533,840 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.00\stub_data\RealPlayer_de.exe
[2011.11.14 13:05:42 | 000,676,624 | ---- | M] (RealNetworks, Inc.) -- C:\Users\stefan\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.00\stub_exe\RealPlayer_de.exe
[2010.10.21 00:16:36 | 005,401,680 | ---- | M] (Uniblue Systems Ltd                                        ) -- C:\Users\stefan\AppData\Roaming\Uniblue\DriverScanner\_temp\driverscanner.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.21 03:23:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2008.03.25 04:22:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=2D77788D0B7FE269044F58C86AE099CE -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_3e1ecd89\AGP440.sys
[2008.03.25 04:22:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=2D77788D0B7FE269044F58C86AE099CE -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.22142_none_ba734aead7ed1bb6\AGP440.sys
[2008.03.26 04:38:23 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=ED91751834103DB2A74470CD763A49FE -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_e4087235\AGP440.sys
[2008.03.26 04:38:23 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=ED91751834103DB2A74470CD763A49FE -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20800_none_b8b64d46daa7e57a\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.03.12 07:38:18 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys
[2008.03.12 07:38:18 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.21 03:23:26 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.21 03:23:26 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.03.12 07:24:20 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=96DC4E1A9F90CCD489950A8935425C59 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2008.04.15 16:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2008.04.15 16:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008.04.15 16:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\drivers\iaStor.sys
[2008.04.15 16:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_77c04a30\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 03:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008.01.21 03:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.21 03:23:47 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.21 03:24:31 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.21 03:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008.01.21 03:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.21 03:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 03:25:18 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2008.01.21 03:24:47 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 03:25:16 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.21 03:25:16 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 03:24:09 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.21 03:24:09 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.01.13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 03:25:17 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 03:25:11 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.21 03:25:11 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2008.01.21 04:20:25 | 017,223,680 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008.01.21 04:20:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008.01.21 04:20:25 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 11:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 11:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >

--- --- ---
[CustomScan mit OTL]

Gruß

vonStefan.

cosinus 12.03.2012 19:08

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
IE - HKLM\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{9A284460-6B83-4FC5-9B1D-B3C625C48887}: "URL" = http://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA;
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA;
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes,DefaultScope = {BA778FA4-2DDB-4814-9662-D91BA0D516E1}
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{9A284460-6B83-4FC5-9B1D-B3C625C48887}: "URL" = http://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7GPEA_de
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{BA778FA4-2DDB-4814-9662-D91BA0D516E1}: "URL" = http://start.funmoods.com/results.php?f=4&a=make&q={searchTerms}
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{C64A81FB-0C89-4787-BA3B-CF8909B4FAF7}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://de.search.yahoo.com/search?fr=mcafee&p={searchTerms}
FF - prefs.js..browser.search.defaultthis.engineName: "softonic-de3 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2431245&SearchSource=3&q={searchTerms}"
[2012.02.11 19:04:02 | 000,000,000 | ---D | M] ("Winamp Toolbar") -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2011.04.30 23:40:44 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.06.08 10:29:10 | 000,000,927 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\conduit.xml
[2012.02.02 17:24:05 | 000,001,798 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\funmoods.xml
[2010.09.16 14:21:14 | 000,002,689 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\search-defender.xml
[2009.12.14 05:19:41 | 000,001,246 | ---- | M] () -- C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\winamp-search.xml
CHR - default_search_provider: search_url = http://start.funmoods.com/results.php?f=4&a=make&q={searchTerms}
[2011.10.19 19:03:23 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.27 19:40:39 | 000,002,027 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O3 - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\Toolbar\WebBrowser: (softonic-de3 Toolbar) - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:DFC5A2B2
:Files
C:\Program Files\softonic*
C:\Program Files\AOL\AOL Toolbar 4.0
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

disteffensso 12.03.2012 19:56

Hatte während der Prozedur die Wlan- Verbindung unterbrochen. G war immer dran.
Nach Windowsmeldung: "OTL funktioniert nicht mehr" das Programm geschlossen. Rechner per Ausschalter `runter gefahren. Nach problemlosem manuellen Neustart erschien dieses Log:

[code]
All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ deleted successfully.
C:\Program Files\softonic-de3\tbsoft.dll moved successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9A284460-6B83-4FC5-9B1D-B3C625C48887}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A284460-6B83-4FC5-9B1D-B3C625C48887}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-21-2415907942-3743196634-3517938245-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\StartPageCache| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{472734EA-242A-422b-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422b-ADF8-83D1E48CC825}\ deleted successfully.
C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll moved successfully.
Registry value HKEY_USERS\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ not found.
File C:\Program Files\softonic-de3\tbsoft.dll not found.
HKEY_USERS\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9A284460-6B83-4FC5-9B1D-B3C625C48887}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A284460-6B83-4FC5-9B1D-B3C625C48887}\ not found.
Registry key HKEY_USERS\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_USERS\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BA778FA4-2DDB-4814-9662-D91BA0D516E1}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA778FA4-2DDB-4814-9662-D91BA0D516E1}\ not found.
Registry key HKEY_USERS\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{C64A81FB-0C89-4787-BA3B-CF8909B4FAF7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C64A81FB-0C89-4787-BA3B-CF8909B4FAF7}\ not found.
Registry key HKEY_USERS\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DECA3892-BA8F-44b8-A993-A466AD694AE4}\ not found.
Prefs.js: "softonic-de3 Customized Web Search" removed from browser.search.defaultthis.engineName
Prefs.js: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2431245&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl
C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\META-INF folder moved successfully.
C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\gecko6 folder moved successfully.
C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components folder moved successfully.
C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\chrome folder moved successfully.
C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} folder moved successfully.
C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults\preferences folder moved successfully.
C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults folder moved successfully.
C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome folder moved successfully.
C:\Users\stefan\AppData\Roaming\mozilla\Firefox\Profiles\afsd7hfq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} folder moved successfully.
C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\conduit.xml moved successfully.
C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\funmoods.xml moved successfully.
C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\search-defender.xml moved successfully.
C:\Users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\searchplugins\winamp-search.xml moved successfully.
Unable to fix default_search_provider items.
C:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\McSiteAdvisor.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}\ deleted successfully.
File C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3049C3E9-B461-4BC5-8870-4C09146192CA}\ deleted successfully.
C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}\ deleted successfully.
C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}\ deleted successfully.
c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ not found.
File C:\Program Files\softonic-de3\tbsoft.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}\ deleted successfully.
File c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{472734EA-242A-422B-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422B-ADF8-83D1E48CC825}\ not found.
File C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ not found.
File de3\tbsoft.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{DE9C389F-3316-41A7-809B-AA305ED9D922} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DE9C389F-3316-41A7-809B-AA305ED9D922}\ deleted successfully.
File C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll not found.
Registry value HKEY_USERS\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}\ not found.
File de3\tbsoft.dll not found.
Registry value HKEY_USERS\S-1-5-21-2415907942-3743196634-3517938245-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{DE9C389F-3316-41A7-809B-AA305ED9D922} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DE9C389F-3316-41A7-809B-AA305ED9D922}\ not found.
File C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll not found.
ADS C:\ProgramData\TEMP:430C6D84 deleted successfully.
ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully.
========== FILES ==========
C:\Program Files\softonic-de3 folder moved successfully.
C:\Program Files\AOL\AOL Toolbar 4.0\resources\de-DE\ui folder moved successfully.
C:\Program Files\AOL\AOL Toolbar 4.0\resources\de-DE\rss folder moved successfully.
C:\Program Files\AOL\AOL Toolbar 4.0\resources\de-DE\local folder moved successfully.
C:\Program Files\AOL\AOL Toolbar 4.0\resources\de-DE\buttons folder moved successfully.
C:\Program Files\AOL\AOL Toolbar 4.0\resources\de-DE\ba folder moved successfully.
C:\Program Files\AOL\AOL Toolbar 4.0\resources\de-DE\aimPages folder moved successfully.
C:\Program Files\AOL\AOL Toolbar 4.0\resources\de-DE folder moved successfully.
C:\Program Files\AOL\AOL Toolbar 4.0\resources folder moved successfully.
C:\Program Files\AOL\AOL Toolbar 4.0 folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users
-> No Temporary Internet Files cache folder defined!

User: Default
->Temp folder emptied: 0 bytes
-> No Temporary Internet Files cache folder defined!

User: Default User
->Temp folder emptied: 0 bytes
-> No Temporary Internet Files cache folder defined!

User: Gast
->Temp folder emptied: 54668 bytes
-> No Temporary Internet Files cache folder defined!
->Java cache emptied: 2002 bytes
->FireFox cache emptied: 26620681 bytes
->Flash cache emptied: 766 bytes

User: Public
-> No Temporary Internet Files cache folder defined!

User: stefan
->Temp folder emptied: 93371558 bytes
-> No Temporary Internet Files cache folder defined!
->Java cache emptied: 17360 bytes
->FireFox cache emptied: 772154833 bytes
->Google Chrome cache emptied: 89317835 bytes
->Apple Safari cache emptied: 101837824 bytes
->Flash cache emptied: 36773 bytes

User: TEMP
-> No Temporary Internet Files cache folder defined!

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1279590 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 312576111 bytes
RecycleBin emptied: 3789267158 bytes

Total Files Cleaned = 4.946,00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.35.1 log created on 03122012_193048

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...
[CustomScan mit OTL]

cosinus 12.03.2012 19:57

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

disteffensso 12.03.2012 20:17

Gibt kein Log. "Scan Results" ist leer.
Klicke ich auf "show information messages" erscheint- vermutlich 265 mal- OK.
Kaspersky TDSSKiller sagt:
No threads found.
Processed: 265 objekts

cosinus 12.03.2012 20:26

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

disteffensso 12.03.2012 21:06

Arne,
hier ist es jetzt 03:00 morgens. 6 Stunden vor. Können wir morgen weiter machen?
Besten Dank derweil.
Stefan

Combofix Logfile:
Code:

ComboFix 12-03-12.03 - stefan 12.03.2012  20:35:26.3.2 - x86
Microsoft® Windows Vista™ Business  6.0.6002.2.1252.49.1031.18.1915.1047 [GMT 1:00]
ausgeführt von:: c:\users\stefan\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\stefan\AppData\Roaming\Desktopicon
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-02-12 bis 2012-03-12  ))))))))))))))))))))))))))))))
.
.
2012-03-12 19:46 . 2012-03-12 19:46        --------        d-----w-        c:\users\Gast\AppData\Local\temp
2012-03-12 19:46 . 2012-03-12 19:46        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-03-10 03:40 . 2012-02-08 06:03        6552120        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{AC21A542-62BD-4899-A57B-8CE324FC2337}\mpengine.dll
2012-03-09 14:43 . 2012-03-09 14:43        --------        d-----w-        c:\program files\File-Upload.net
2012-03-09 03:04 . 2012-03-09 03:04        --------        d-----w-        c:\program files\ESET
2012-03-08 14:07 . 2012-03-08 14:07        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2012-03-08 14:07 . 2011-12-10 14:24        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-03-08 12:43 . 2012-03-08 12:43        --------        d-----w-        c:\users\stefan\AppData\Roaming\dvdcss
2012-03-08 07:29 . 2012-03-08 07:29        --------        d-----w-        c:\program files\7-Zip
2012-03-07 11:31 . 2012-03-08 06:45        --------        d-----w-        C:\sh4ldr
2012-03-07 11:31 . 2012-03-07 11:31        --------        d-----w-        c:\program files\Enigma Software Group
2012-02-16 06:32 . 2011-12-14 16:17        680448        ----a-w-        c:\windows\system32\msvcrt.dll
2012-02-16 06:32 . 2012-01-12 19:52        2044416        ----a-w-        c:\windows\system32\win32k.sys
2012-02-16 06:32 . 2011-12-20 10:56        2409784        ----a-w-        c:\program files\Windows Mail\OESpamFilter.dat
2012-02-15 16:33 . 2012-02-15 16:53        --------        d-----w-        c:\users\stefan\AppData\Roaming\redsn0w
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-07 12:46 . 2011-05-14 07:44        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-23 08:18 . 2009-10-03 08:00        237072        ------w-        c:\windows\system32\MpSigStub.exe
2012-02-17 02:01 . 2011-11-13 19:02        137416        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-02-17 16:52 . 2011-04-20 21:41        134104        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"iCloudServices"="c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe" [2011-11-11 59240]
"ApplePhotoStreams"="c:\program files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2011-11-11 59240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416]
"NDSTray.exe"="NDSTray.exe" [BU]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-25 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-25 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-25 145944]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2008-04-29 417792]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]
"MobileConnect"="c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe" [2008-07-04 2072576]
"Toshiba TEMPRO"="c:\program files\Toshiba TEMPRO\TemproTray.exe" [2010-10-26 1050072]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-06 59240]
"PCTools FGuard"="c:\program files\PC Tools Security\BDT\FGuard.exe" [2011-05-20 247760]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-10-11 258512]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-06-05 202256]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files\TOSHIBA\TRDCReminder\TRDCReminder.exe [2008-3-5 393216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^stefan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PMB Medien-Prüfung.lnk]
path=c:\users\stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PMB Medien-Prüfung.lnk
backup=c:\windows\pss\PMB Medien-Prüfung.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00TCrdMain]
2008-05-09 09:49        716800        ----a-w-        c:\program files\TOSHIBA\FlashCards\TCrdMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 10:55        937920        ----a-w-        c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google EULA Launcher]
2008-05-28 11:40        20480        ----a-w-        c:\program files\Google\Google EULA\GoogleEULALauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-12-10 19:52        49152        ----a-w-        c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HSON]
2007-10-31 20:01        54608        ----a-w-        c:\program files\TOSHIBA\TBS\HSON.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-04-08 13:14        6037504        ----a-w-        c:\windows\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
2007-11-20 16:15        1826816        ----a-w-        c:\windows\SkyTel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
2008-06-24 08:06        509816        ----a-w-        c:\program files\TOSHIBA\SmoothView\SmoothView.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-08-13 16:24        68856        ----a-w-        c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-06-05 22:57        202256        ----a-w-        c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration]
2008-01-11 02:07        574864        ----a-w-        c:\program files\TOSHIBA\Registration\ToshibaRegistration.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPwrMain]
2008-01-17 14:27        431456        ----a-w-        c:\program files\TOSHIBA\Power Saver\TPwrMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 78945024
*Deregistered* - 78945024
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork        REG_MULTI_SZ          PLA DPS BFE mpssvc
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt        REG_MULTI_SZ          hpqcxs08 hpqddsvc
WindowsMobile        REG_MULTI_SZ          wcescomm rapimgr
LocalServiceRestricted        REG_MULTI_SZ          WcesComm RapiMgr
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2012-03-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-13 09:49]
.
2012-03-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 21:02]
.
2012-03-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 21:02]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page =
mStart Page =
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://de.search.yahoo.com/search?fr=mcafee&p=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - c:\users\stefan\AppData\Roaming\Mozilla\Firefox\Profiles\afsd7hfq.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?q=
FF - user.js: yahoo.homepage.dontask - true);user_pref(extensions.funmoods_i.hmpg, true
FF - user.js: extensions.funmoods_i.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=make
FF - user.js: extensions.funmoods_i.dfltSrch - true
FF - user.js: extensions.funmoods_i.srchPrvdr - Search
FF - user.js: extensions.funmoods_i.dnsErr - true
FF - user.js: extensions.funmoods_i.newTab - true
FF - user.js: extensions.funmoods_i.newTabUrl - hxxp://start.funmoods.com/?f=2&a=make
FF - user.js: extensions.funmoods_i.tlbrSrchUrl - hxxp://start.funmoods.com/results.php?f=3&a=make&q=
FF - user.js: extensions.funmoods_i.id - 90911d57000000000000001a7342fff6
FF - user.js: extensions.funmoods_i.instlDay - 15372
FF - user.js: extensions.funmoods_i.vrsn - 1.5.11.16
FF - user.js: extensions.funmoods_i.vrsni - 1.5.11.16
FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.11.1617:24
FF - user.js: extensions.funmoods_i.prtnrId - funmoods
FF - user.js: extensions.funmoods_i.prdct - funmoods
FF - user.js: extensions.funmoods_i.aflt - make
FF - user.js: extensions.funmoods_i.smplGrp - none
FF - user.js: extensions.funmoods_i.tlbrId - base
FF - user.js: extensions.funmoods_i.instlRef -
FF - user.js: extensions.funmoods_i.dfltLng -
FF - user.js: extensions.funmoods_i.excTlbr - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-cfFncEnabler.exe - cfFncEnabler.exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-WinampAgent - c:\program files\Winamp\winampa.exe
AddRemove-AOL Toolbar 4.0 - c:\program files\AOL\AOL Toolbar 4.0\uninstall.exe
AddRemove-DivX Setup.divx.com - c:\programdata\DivX\Setup\DivXSetup.exe
AddRemove-softonic-de3 Toolbar - c:\progra~1\SOFTON~1\UNWISE.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-03-12 20:49
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2012-03-12  20:53:42
ComboFix-quarantined-files.txt  2012-03-12 19:53
.
Vor Suchlauf: 10 Verzeichnis(se), 26.457.956.352 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 26.397.908.992 Bytes frei
.
- - End Of File - - A29FEE5D9FD5254B617CC2A265A6D4B3

--- --- ---
[COMOFIX Scan]

cosinus 12.03.2012 21:13

Ja morgen kanns weiter gehen :pfeiff:

disteffensso 13.03.2012 17:42

Hi Arne,

gehts gut?

Schönen Gruß
vonStefan.

cosinus 13.03.2012 17:44

Danke für den Reminder :D geht sofort weiter! ;)

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).


disteffensso 14.03.2012 09:04

Habe gestern auf eine email gewartet. Daher nicht mehr reagiert. Der Rechner sprang nachts von standby aus alleine an.
GMER ging nicht.

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 08:56:35 on 14.03.2012

OS: Windows Vista Business Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Google Inc. Google Chrome 17.0.963.79

Scanner Settings
Rootkits detection (hidden registry)
Rootkits detection (hidden files)
Retrieve files information
Check Microsoft signatures

Filters
Trusted entries
Empty entries
Hidden registry entries (rootkit activity)
Exclusively opened files
Not found files
Files without detailed information
Existing files
Non-startable services
Non-startable drivers
Active entries
Disabled entries

        Risk        Name        Publisher        Full Path        Status
Common
%SystemRoot%\Tasks
        ||||          "GoogleUpdateTaskMachineCore.job"        "Google Inc."        C:\Program Files\Google\Update\GoogleUpdate.exe        File exists
        ||||          "GoogleUpdateTaskMachineUA.job"        "Google Inc."        C:\Program Files\Google\Update\GoogleUpdate.exe        File exists
        ||||          "Google Software Updater.job"        "Google"        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe        File exists
Control Panel Objects
%SystemRoot%\system32
                      "FlashPlayerCPLApp.cpl"        "Adobe Systems Incorporated"        C:\Windows\system32\FlashPlayerCPLApp.cpl        File exists
        ||||||        "TOSCDSPD.cpl"        "TOSHIBA"        C:\Windows\system32\TOSCDSPD.cpl        File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls
        ||||||        "QuickTime"        "Apple Inc."        C:\Program Files\QuickTime\QTSystem\QuickTime.cpl        File exists
Drivers
HKLM\SYSTEM\CurrentControlSet\Services
        ||||||        "avfwot" (avfwot)        "Avira GmbH"        C:\Windows\System32\DRIVERS\avfwot.sys        File exists
        ||||||        "avgntflt" (avgntflt)        "Avira GmbH"        C:\Windows\System32\DRIVERS\avgntflt.sys        File exists
        ||||||        "avipbb" (avipbb)        "Avira GmbH"        C:\Windows\System32\DRIVERS\avipbb.sys        File exists
        ||||||        "avkmgr" (avkmgr)        "Avira GmbH"        C:\Windows\System32\DRIVERS\avkmgr.sys        File exists
                      "catchme" (catchme)                C:\Users\stefan\AppData\Local\Temp\catchme.sys        File not found
                      "esgiguard" (esgiguard)                C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys        File not found
                      "IP in IP Tunnel Driver" (IpInIp)                C:\Windows\System32\DRIVERS\ipinip.sys        File not found
                      "IPX Traffic Filter Driver" (NwlnkFlt)                C:\Windows\System32\DRIVERS\nwlnkflt.sys        File not found
                      "IPX Traffic Forwarder Driver" (NwlnkFwd)                C:\Windows\System32\DRIVERS\nwlnkfwd.sys        File not found
        ||||||        "PxHelp20" (PxHelp20)        "Sonic Solutions"        C:\Windows\System32\Drivers\PxHelp20.sys        File exists
        ||||||        "ssmdrv" (ssmdrv)        "Avira GmbH"        C:\Windows\System32\DRIVERS\ssmdrv.sys        File exists
Explorer
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
        ||||||        {BDEADF00-C265-11d0-BCED-00A0C90AB50F} "Webordner"        "Microsoft Corporation"        C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL        File exists
HKLM\Software\Classes\Folder\shellex\ColumnHandlers
        ||||||        {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension"        "Adobe Systems, Inc."        C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll        File exists
HKLM\Software\Classes\Protocols\Handler
                      {5513F07E-936B-4E52-9B00-067394E91CC5} "McAfee SACore Protocol Handler"                c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll        File not found
                      {5513F07E-936B-4E52-9B00-067394E91CC5} "McAfee SACore Protocol Handler"                c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll        File not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
                      {911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files"                        File not found | COM-object registry key not found
        ||||||        {23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension"        "Igor Pavlov"        C:\Program Files\7-Zip\7-zip.dll        File exists
                      {1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder"                        File not found | COM-object registry key not found
                      {34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder"                        File not found | COM-object registry key not found
                      {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder"                        File not found | COM-object registry key not found
                      {2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band"                        File not found | COM-object registry key not found
                      {FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist"                        File not found | COM-object registry key not found
                      {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes"        "Apple Inc."        C:\Program Files\iTunes\iTunesMiniPlayer.dll        File exists
        ||||||        {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler"        "Microsoft Corporation"        C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll        File exists
        ||||||        {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler"        "Microsoft Corporation"        C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll        File exists
        ||||||        {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class"        "RealNetworks, Inc."        c:\program files\real\realplayer\rpshell.dll        File exists
                      {C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder"                        File not found | COM-object registry key not found
                      {E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder"                        File not found | COM-object registry key not found
                      {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning"        "Avira Operations GmbH & Co. KG"        C:\Program Files\Avira\AntiVir Desktop\shlext.dll        File exists
                      {da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service"                        File not found | COM-object registry key not found
Internet Explorer
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
                      ITBar7Height "ITBar7Height"                        File not found | COM-object registry key not found
                      "ITBar7Layout"                        File not found | COM-object registry key not found
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units
        ||||          {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29"
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab        "Sun Microsystems, Inc."        C:\Program Files\Java\jre6\bin\npjpi160_29.dll        File exists
                      {E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}"
hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab                        File not found | COM-object registry key not found
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
                      "Amazon.de"                hxxp://www.amazon.de/exec/obidos/redirect-home?tag=Toshibadebholink-21&site=home        HTTP value
                      {DE9C389F-3316-41A7-809B-AA305ED9D922} "AOL Toolbar"                        File not found | COM-object registry key not found
                      "eBay - Der weltweite Online Marktplatz"                hxxp://rover.ebay.com/rover/1/707-44556-9400-3/4        HTTP value
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
        ||||||        {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper"        "Adobe Systems Incorporated"        C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll        File exists
        ||||          {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper"        "Sun Microsystems, Inc."        C:\Program Files\Java\jre6\bin\jp2ssv.dll        File exists
Logon
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
        ||||||        "desktop.ini"                C:\Users\stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini        File exists
%AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup
        ||||||        "desktop.ini"                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini        File exists
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
                      "ApplePhotoStreams"        "Apple Inc."        C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe        File exists
                      "iCloudServices"        "Apple Inc."        C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe        File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
        ||||          "Adobe ARM"        "Adobe Systems Incorporated"        "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"        File exists
                      "AppleSyncNotifier"        "Apple Inc."        C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe        File exists
        ||||          "APSDaemon"        "Apple Inc."        "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"        File exists
                      "avgnt"        "Avira Operations GmbH & Co. KG"        "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min        File exists
        ||||          "Camera Assistant Software"        "Chicony"        "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start        File exists
                      "iTunesHelper"        "Apple Inc."        "C:\Program Files\iTunes\iTunesHelper.exe"        File exists
        ||||          "MobileConnect"        "Vodafone"        %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent        File exists
                      "NDSTray.exe"                NDSTray.exe        File not found
        ||||||        "PCTools FGuard"        "Threat Expert Ltd."        C:\Program Files\PC Tools Security\BDT\FGuard.exe        File exists
        ||||          "QuickTime Task"        "Apple Inc."        "C:\Program Files\QuickTime\QTTask.exe" -atboottime        File exists
        ||||          "SunJavaUpdateSched"        "Sun Microsystems, Inc."        "C:\Program Files\Common Files\Java\Java Update\jusched.exe"        File exists
        ||||          "TkBellExe"        "RealNetworks, Inc."        "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot        File exists
        ||||          "topi"        "TOSHIBA"        C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup        File exists
        ||||          "Toshiba TEMPRO"        "Toshiba Europe GmbH"        C:\Program Files\Toshiba TEMPRO\TemproTray.exe        File exists
Services
HKLM\SYSTEM\CurrentControlSet\Services
        ||||||        "@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400)        "Microsoft Corporation"        C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe        File exists
        ||            "Adobe Acrobat Update Service" (AdobeARMservice)        "Adobe Systems Incorporated"        C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe        File exists
        ||||||        "Apple Mobile Device" (Apple Mobile Device)        "Apple Inc."        C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe        File exists
                      "Avira Browser Schutz" (AntiVirWebService)        "Avira Operations GmbH & Co. KG"        C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE        File exists
                      "Avira Echtzeit Scanner" (AntiVirService)        "Avira Operations GmbH & Co. KG"        C:\Program Files\Avira\AntiVir Desktop\avguard.exe        File exists
                      "Avira Email Schutz" (AntiVirMailService)        "Avira Operations GmbH & Co. KG"        C:\Program Files\Avira\AntiVir Desktop\avmailc.exe        File exists
                      "Avira FireWall" (AntiVirFirewallService)        "Avira Operations GmbH & Co. KG"        C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe        File exists
                      "Avira Planer" (AntiVirSchedulerService)        "Avira Operations GmbH & Co. KG"        C:\Program Files\Avira\AntiVir Desktop\sched.exe        File exists
        ||||||        "Browser Defender Update Service" (Browser Defender Update Service)        "Threat Expert Ltd."        C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe        File exists
        ||||||        "ConfigFree Service" (ConfigFree Service)        "TOSHIBA CORPORATION"        C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe        File exists
        ||||||        "Dienst "Bonjour"" (Bonjour Service)        "Apple Inc."        C:\Program Files\Bonjour\mDNSResponder.exe        File exists
                      "Freemake Improver" (Freemake Improver)        "Freemake"        C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe        File exists
        ||||          "Google Software Updater" (gusvc)        "Google"        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe        File exists
        ||||          "Google Update Service (gupdate)" (gupdate)        "Google Inc."        C:\Program Files\Google\Update\GoogleUpdate.exe        File exists
        ||||          "Google Update-Dienst (gupdatem)" (gupdatem)        "Google Inc."        C:\Program Files\Google\Update\GoogleUpdate.exe        File exists
        ||||||        "HP CUE DeviceDiscovery Service" (hpqddsvc)        "Hewlett-Packard Co."        C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll        File exists
        ||||||        "hpqcxs08" (hpqcxs08)        "Hewlett-Packard Co."        C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll        File exists
        ||||||        "iPod-Dienst" (iPod Service)        "Apple Inc."        C:\Program Files\iPod\bin\iPodService.exe        File exists
                      "McAfee SiteAdvisor Service" (McAfee SiteAdvisor Service)        "McAfee, Inc."        C:\Program Files\McAfee\SiteAdvisor\McSACore.exe        File exists
        ||||||        "Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32)        "Microsoft Corporation"        C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe        File exists
        ||||||        "Net Driver HPZ12" (Net Driver HPZ12)        "Hewlett-Packard"        C:\Windows\system32\HPZinw12.dll        File exists
        ||||||        "Notebook Performance Tuning Service (TEMPRO)" (TemproMonitoringService)        "Toshiba Europe GmbH"        C:\Program Files\Toshiba TEMPRO\TemproSvc.exe        File exists
        ||||||        "Pml Driver HPZ12" (Pml Driver HPZ12)        "Hewlett-Packard"        C:\Windows\system32\HPZipm12.dll        File exists
        ||||||        "SmartFaceVWatchSrv" (SmartFaceVWatchSrv)        "Toshiba"        C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe        File exists
        ||||||        "TGCM_ImportWiFiSvc" (TGCM_ImportWiFiSvc)        "Telefónica I+D"        C:\Program Files\o2\Mobile Connection Manager\ImpWiFiSvc.exe        File exists
Winsock Providers
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries
        ||||||        "mdnsNSP"        "Apple Inc."        C:\Program Files\Bonjour\mdnsNSP.dll        File exists
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries
                      "AVSDA"        "Avira Operations GmbH & Co. KG"        C:\Program Files\Avira\AntiVir Desktop\avsda.dll        File exists
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


disteffensso 14.03.2012 12:16

Hi Arne,

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-03-14 09:07:41
-----------------------------
09:07:41.938    OS Version: Windows 6.0.6002 Service Pack 2
09:07:41.938    Number of processors: 2 586 0xF0D
09:07:41.954    ComputerName: STEFANS-PC  UserName: stefan
09:08:05.434    Initialize success
09:15:36.471    AVAST engine defs: 12031301
09:16:12.524    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
09:16:12.524    Disk 0 Vendor: WDC_WD25 01.0 Size: 238475MB BusType: 3
09:16:12.539    Disk 0 MBR read successfully
09:16:12.555    Disk 0 MBR scan
09:16:12.633    Disk 0 Windows VISTA default MBR code
09:16:12.648    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        1500 MB offset 2048
09:16:12.680    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS      119000 MB offset 3074048
09:16:12.695    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      117973 MB offset 246786048
09:16:12.711    Disk 0 scanning sectors +488394752
09:16:12.789    Disk 0 scanning C:\Windows\system32\drivers
09:16:28.155    Service scanning
09:16:58.186    Modules scanning
09:17:03.583    Disk 0 trace - called modules:
09:17:03.615    ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
09:17:03.630    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86503478]
09:17:03.630    3 CLASSPNP.SYS[883118b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x85536028]
09:17:05.409    AVAST engine scan C:\Windows
09:17:19.964    AVAST engine scan C:\Windows\system32
09:23:54.118    AVAST engine scan C:\Windows\system32\drivers
09:24:19.452    AVAST engine scan C:\Users\stefan
09:45:23.651    AVAST engine scan C:\ProgramData
09:47:03.507    Scan finished successfully
12:10:32.415    Disk 0 MBR has been saved successfully to "C:\Users\stefan\Documents\Documents\MBR.dat"
12:10:32.415    The log file has been saved successfully to "C:\Users\stefan\Documents\Documents\aswMBR.txt"
12:11:42.157    Disk 0 MBR has been saved successfully to "C:\Users\stefan\Documents\Documents\MBR.dat"
12:11:42.173    The log file has been saved successfully to "C:\Users\stefan\Documents\Documents\aswMBR.txt"
12:11:58.599    Disk 0 MBR has been saved successfully to "C:\Users\stefan\Desktop\MBR.dat"
12:11:58.864    The log file has been saved successfully to "C:\Users\stefan\Desktop\aswMBR.txt"

Gruß
vonStefan.

cosinus 14.03.2012 15:27

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

disteffensso 14.03.2012 19:42

Arne,
ich könnt´ Dich abknutschen.
Zumal alle Superschlaumeier genau wußten, daß das nur mit Format C:\ geht. HA! Großartiger Mann, Bastard Operator from Hell!

Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.14.02

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
stefan :: STEFANS-PC [Administrator]

14.03.2012 16:01:16
mbam-log-2012-03-14 (16-01-16).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 468428
Laufzeit: 3 Stunde(n), 31 Minute(n), 13 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Gruß
vonStefan

PS:SaS- Scan folgt.

cosinus 14.03.2012 21:22

Bitte achte auf die CODE-Tags! Ich musste das jetzt schon zum dritten Mal bei dir korrigieren!

disteffensso 15.03.2012 04:59

Ich setze 2 eckige Klammern und schreibe code hinein.
Am Schluß mache ich das Gleiche und schreibe den Scannamen ´rein.
Mir ist der Fehler nicht klar. Oder soll am Schluß nur Klammern/code stehen und das mit dem Text "CustomScan" war eine Ausnahme?

Soll ich "remove Threads" klicken?

Gruß
von Stefan.

cosinus 15.03.2012 05:01

Zitat:

Am Schluß mache ich das Gleiche und schreibe den Scannamen ´rein.
Genau das ist falsch. Wo du das her hast ist für mich nicht zu erklären :balla:

disteffensso 15.03.2012 05:44

SAS- Log, ich habs gezippt, aber es läßt sich nicht hochladen. Entpacken am Rechner geht.

Gruß

vonStefan.

disteffensso 15.03.2012 06:12

Vielleicht darf ichs ausnahmsweise auf 2 x hier posten?

Gruß
vonStefan

disteffensso 15.03.2012 07:25

Wollte WinRAR installieren. Geht nicht, weil SaS noch offen ist. Ich poste jetzt auf 2 x und warte auf den Anschiß...

[code]
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 03/14/2012 at 10:00 PM

Application Version : 5.0.1146

Core Rules Database Version : 8335
Trace Rules Database Version: 6147

Scan type : Complete Scan
Total Scan Time : 02:03:35

Operating System Information
Windows Vista Business 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Administrator

Memory items scanned : 793
Memory threats detected : 0
Registry items scanned : 34362
Registry threats detected : 0
File items scanned : 79531
File threats detected : 1141

Adware.Tracking Cookie
statse.webtrendslive.com [ G:\VISTA\USERS\GAST\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5JSW9IV2.DEFAULT\COOKIES.SQLITE ]
aka-cdn-ns.adtech.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
atdmt.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
bc.youporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
broadcast.piximedia.fr [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
cdn1.eyewonder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
cdn1.image.freeporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
cdn1.pics.mofosex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
cdn4.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
cdn5.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
cloud.video.unrulymedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
de.mediaplanet.streamingbolaget.se [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
googleads.g.doubleclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
ia.media-imdb.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
imagesrv.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
media.ichwillspielen.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
media.scanscout.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
media01.kyte.tv [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
media1.break.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
pornme.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
s0.2mdn.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
secure-us.imrworldwide.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
static.sunporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
vidii.hardsextube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
www.adtracking.org [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
www.alphaporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
www.euros4click.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
www.freeporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
www.gotgayporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
www.mofosex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
www.naiadsystems.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
www.pornerbros.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
www.pornhub.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
www.sexbot.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
www.sexkiste.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\HNWR6CTN ]
.ads.quartermedia.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ads.quartermedia.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ads.quartermedia.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ads.quartermedia.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.bs.serving-sys.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexlist.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.247realmedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.interclick.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.autoscout24.112.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tacoda.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tacoda.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.at.atwola.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fls.doubleclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.112.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adserver.traffictrack.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
rotator.adjuggler.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
rotator.adjuggler.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adsrv.admediate.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adsrv.admediate.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.112.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexlist.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexy.exgfs.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexlist.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xiti.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.bluestreak.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.zanox.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
rts.pgmediaserve.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
cdn5.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
stat.dealtime.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
cdn5.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.at.atwola.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adviva.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.guj.122.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.adserver01.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.questionmarket.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ads.quartermedia.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.im.banner.t-online.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ad.adnet.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ad.adnet.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.adition.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.adition.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
openx.e-mags-media.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.eyewonder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adx.chip.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.klicktel.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.zanox-affiliate.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.traffictrack.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ad.adnet.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.daimlerag.122.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexy-bitches.org [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ads.quartermedia.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.adition.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
fr.sitestat.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.interclick.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.interclick.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.112.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adxpose.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.estat.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adecn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adinterax.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adinterax.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultadworld.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultadworld.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ero-advertising.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.traffictrack.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.deutschepostag.112.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wfkicgazagp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wgmyemcjecq.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.count.spring.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wgmionc5ohp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.cheaptickets.122.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjloskc5shq.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tacoda.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
banner.testberichte.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjlocpazmap.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wclykgc5kbo.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
counter.live4members.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wflisjdzicq.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
dc.tremormedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.crakmedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wbk4wjazgap.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ru4.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ru4.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wgmyshdpiko.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
delivery.atkmedia.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.overture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.h2omedia.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.traffictrack.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wfkikicpweo.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wnkowncpidp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wnkiwkdpoho.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wcmyugcjmbq.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hardsextube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adserver.hardsextube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hardsextube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hardsextube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adnetxchange.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adnetxchange.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.partypoker.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.gotgayporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornhub.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornhub.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tour1.xxxmatch.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
wt.xxxmatch.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ice.112.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornoxo.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornoxo.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.pornoxo.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.br.naked.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.goldporntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.goldporntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wbmyqocpcgp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.crakmedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.wlw.122.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wnlooncjebp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hardsexmate.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.steelhousemedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.steelhousemedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wbk4qhdpmko.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6whl4gjazccp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aekyepd5ecp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wdkoshdpedp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wcmiolczolq.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wgkiwkdjeep.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wclickdpcaq.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
user.lucidmedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porndad.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
porndad.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.static.ads.crakmedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.static.ads.crakmedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wakikgd5odq.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wnloamczoao.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.adxpansion.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adxpansion.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tns-counter.ru [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.yadro.ru [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.opodo.122.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aekiwoc5gko.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.partypoker.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.youporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.youporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.youporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wgl4gjdjsfp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.bannerdesign4u.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.bannerdesign4u.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.trafficrevenue.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
server.lon.liveperson.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
server.lon.liveperson.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hostedbannerads.aebn.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.visit-tracker.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.visit-tracker.biz [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.clicksor.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.clicksor.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.clicksor.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.clicksor.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.realtouchbannerwidget.aebn.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adserver.anschlusstor.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6whkispdzcbp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aekocjdzclp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.visit-tracker.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjlionczkeo.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.questionmarket.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.belstat.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.spylog.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wfkooidjmap.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wclispazkfo.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wfkokhcjkbp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.youporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.server.cpmstar.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornrabbit.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornrabbit.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjmiemd5sao.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tube1sex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.facebookofsex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.facebookofsex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wgmywndzchp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adserver.doccheck.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fameporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fameporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad5.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.cz8.clickzs.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.cz8.clickzs.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.realsexcash.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad3.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.girlsteachsex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.conrad.122.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.girlsteachsex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.dc-storm.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjlougdjelq.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjloehd5cbo.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.visit-tracker.biz [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sex2ube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sex2ube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sex2ube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads1.exgfnetwork.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexbot.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexbot.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexbotlive.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.nextag.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.nextag.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.nextag.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.nextag.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.usenext.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.vinvest.122.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.snapfish.112.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6whlowgc5khq.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.etracker.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adverts.friedrichchiller.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
spenden.wikimedia.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.freepornmate.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.eyewonder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.yieldmanager.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.azjmp.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.azjmp.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.skyscanner.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.skyscanner.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.skyscanner.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.skyscanner.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.skyscanner.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.skyscanner.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ehg-cheaptickets.hitbox.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hitbox.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.liveperson.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.liveperson.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ehg-cheaptickets.hitbox.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adserver.iszene.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wmkoupazsdq.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.etracker.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.etracker.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.content.yieldmanager.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.etracker.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adx.chip.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adx.chip.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adx.chip.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adx.chip.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adx.chip.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adx.chip.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adx.chip.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adx.chip.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.zanox-affiliate.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.etracker.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
statse.webtrendslive.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sunporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ero-advertising.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sunporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sunporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sunporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.alphaporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.alphaporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.alphaporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.alphaporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.alphaporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.alphaporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.alphaporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.alphaporno.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.stats.paypal.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.trafficjunky.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.partypoker.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.partypoker.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.secmedia.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.secmedia.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.secmedia.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.roitracking.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.vodafonegroup.122.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aek4ggcjicp.stats.esomniture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.freeporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.freeporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.freeporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.naked.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
rts.pgmediaserve.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
rts.pgmediaserve.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
rts.pgmediaserve.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zanox-affiliate.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.paypal.112.2o7.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mediabrandsww.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.overture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.overture.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad1.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.mofosex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mofosex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mofosex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mofosex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porntubemate.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.porntube.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
porntubemate.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porntubemate.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.pornerbros.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornerbros.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.pornerbros.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.pornerbros.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornerbros.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornerbros.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.pornerbros.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adxpansion.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xxxkinky.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.xxxkinky.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.toplist.cz [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xxxkinky.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xxxkinky.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.gotgayporn.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad2.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.content.yieldmanager.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.hannoversche.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.im.banner.t-online.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.im.banner.t-online.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.im.banner.t-online.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.im.banner.t-online.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.traffictrack.de [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ww251.smartadserver.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adviva.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.zanox.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad4.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zanox.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]

disteffensso 15.03.2012 07:28

.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.exoclick.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.exoclick.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.doubleclick.net [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.divx.112.2o7.net [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.atdmt.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
track.adform.net [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
track.adform.net [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.adform.net [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad1.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
count.asnetworks.de [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.ru4.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.atdmt.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.c1.atdmt.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.imrworldwide.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.autoscout24.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xiti.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
rts.pgmediaserve.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
stat.dealtime.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adviva.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.guj.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ad.adnet.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.eyewonder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ad.adnet.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.daimlerag.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adxpose.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.deutschepostag.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.cheaptickets.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.overture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hardsextube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Porno tube - Adult Streaming Sex Tube Videos at PornoXO - page 1 [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.br.naked.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.static.ads.crakmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adxpansion.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.youporn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.youporn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.conrad.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.snapfish.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.eyewonder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.vodafonegroup.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.paypal.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adviva.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
brutalfistingsex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6waliwjczslq.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornsharia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.count.xhit.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tripod.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wnkyggcjseo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wgmishdpmdp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjloqpcpcho.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjlywldzilp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.thefind.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.thefind.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.thefind.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.thefind.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.thefind.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexctube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.germansexvideo.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.germansexvideo.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.discounter-deutschland.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aekyshcjieo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.4stats.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.4stats.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
static.sunporno.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fuckcams.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjk4wgcziho.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ero-advertising.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.traffichaus.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.zeusclicks.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porntubemate.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adserving.greenadvertizing.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adserving.greenadvertizing.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
pornografish.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adserver.adtechus.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.cdate.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6whkowpc5kfp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wakiqkc5oep.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wnmiuhczokp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
xml.trafficengine.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.trafficengine.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wblowmcjcgp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
hc2.humanclick.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
hc2.humanclick.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjk4umdpcgo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.philips.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adult-empire.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
stat.aldi.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.secmedia.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads2.zeusclicks.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aelisndpibp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mofosex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6whmyohc5chq.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornoxo.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sunporno.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aeloggd5ecp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adserver.gs [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas4.emediate.eu [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ad.adnet.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aeliqjajwko.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.count.spring.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
accounts.youtube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.adition.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.adition.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjmychc5wlo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6whkoomdjsfo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.alotporn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
openx.e-mags-media.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.gay.porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aek4ogcjcdo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aeloakcjolp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.dafuckbook.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.dafuckbook.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
openx.sexsearchcom.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wgkyqlc5cdp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjlyeidjehp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.wlw.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.lokalportal24de.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexlist.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tradefx.advertserve.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.oms.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.gostats.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjk4ondzmlp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.komtrack.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.komtrack.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.markussexblog.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.markussexblog.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ad.adnet.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xhamster.fuckshow.org [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xhamster.fuckshow.org [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adserver2.exgfnetwork.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adserver.tarifecheck.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.opodo.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.de.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.de.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.de.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.stats.tso.co.uk [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.stats.tso.co.uk [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexlist.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hightraffic.hugoboss.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Kostenlose private Sexkontakte - sexkiste.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xxxkinky.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xxxkinky.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Free Sex Videos - Hot Sex Movies - Free Porn Tube [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.amazon-adsystem.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.amazon-adsystem.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wnmiskd5map.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultmoneymakers.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
support.adultmemberservice.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
support.adultmemberservice.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ads.crakmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ads.crakmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.yadro.ru [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.yadro.ru [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
animalporntv.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.animalporntv.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.animalporntv.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
zoosextv.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
freeanimalsextube.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Animal Porn FREE. Extreme collection of free animal porn [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Wild Animal Porn. Collection of free animal porn videos [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
wildanimalporn.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
zoo sex tv - free animal porn, animal sex, zoo porn, dog porn [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Free Sex Videos - Hot Sex Movies - Free Porn Tube [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.pornerbros.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornerbros.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornerbros.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porntube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porntube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aelyomcjmdp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornrabbit.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornrabbit.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.adultrevads.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultadworld.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultadworld.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.im.banner.t-online.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjlougdjelq.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wamyandpkeo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.enoratraffic.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.questionmarket.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads3.bangkokpost.co.th [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.h2porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.h2porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.h2porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.h2porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.h2porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.freeporn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.freeporn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.track.gridlockparadise.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.track.gridlockparadise.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornper.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornper.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornhub.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornhub.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.at.atwola.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mmotraffic.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mmotraffic.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ru4.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornbanana.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornbanana.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.adserver01.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
delivery.trafficbroker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.ventivmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.alphaporno.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.alphaporno.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.girlsteachsex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracker.roitesting.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hardsextube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hardsextube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adserver.hardsextube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6whmysocpkep.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.lfstmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.lfstmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.olympiaverlag.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.crakmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adxpansion.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.traffictrack.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.lfstmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.yieldmanager.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
zbox.zanox.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.zanox-affiliate.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.bs.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas4.emediate.eu [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ru4.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adverts.friedrichchiller.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.dyntracker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.histats.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.histats.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.unister-adservices.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adx.chip.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adx.chip.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.overture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adform.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.stats.paypal.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ehg-cheaptickets.hitbox.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hitbox.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.zanox.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
etracker Home - forget log-file analysis, this is real-time Web Analytics and online market research [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.overture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.im.banner.t-online.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adviva.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.lucidmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.quartermedia.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.affiliaxe.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.affiliaxe.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.eset.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xm.xtendmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adserver.entlastungszug.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.a.revenuemax.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad3.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
etracker Home - forget log-file analysis, this is real-time Web Analytics and online market research [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad4.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.microsoftsto.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zanox.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zanox-affiliate.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.accounts.google.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.accounts.google.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.accounts.google.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
accounts.youtube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aemyglajigq.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
counter13.sextracker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sextracker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tribalfusion.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.kontera.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.unister-adservices.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.unister-adservices.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad1.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
server.iad.liveperson.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adverts.friedrichchiller.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adverts.friedrichchiller.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
accounts.youtube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.zanox.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
clicktrk.news.asiarooms.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
clicktrk.news.asiarooms.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
clicktrk.news.asiarooms.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
clicktrk.news.asiarooms.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
statse.webtrendslive.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad2.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-SoftonicDownloader
G:\VISTA\USERS\STEFAN\DESKTOP\EBAY 02.05.2010\DOWNLOAD\DOWNLOADS\SOFTONICDOWNLOADER_FUER_TUNEUP-UTILITIES-2011(1).EXE
G:\VISTA\USERS\STEFAN\DESKTOP\EBAY 02.05.2010\DOWNLOAD\DOWNLOADS\SOFTONICDOWNLOADER_FUER_TUNEUP-UTILITIES-2011.EXE
C:\USERS\STEFAN\DESKTOP\EBAY 02.05.2010\DOWNLOAD\DOWNLOADS\SOFTONICDOWNLOADER_FUER_TUNEUP-UTILITIES-2011(1).EXE
C:\USERS\STEFAN\DESKTOP\EBAY 02.05.2010\DOWNLOAD\DOWNLOADS\SOFTONICDOWNLOADER_FUER_TUNEUP-UTILITIES-2011.EXE
C:\USERS\STEFAN\DESKTOP\EBAY 02.05.2010\DOWNLOAD\SOFTONICDOWNLOADER_FUER_TUNEUP-UTILITIES-2011(1).EXE
C:\USERS\STEFAN\DESKTOP\EBAY 02.05.2010\DOWNLOAD\SOFTONICDOWNLOADER_FUER_TUNEUP-UTILITIES-2011.EXE
[/code]

Gruß
vonStefan.

disteffensso 15.03.2012 07:31

.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.exoclick.com [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ G:\VISTA\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.exoclick.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.doubleclick.net [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.divx.112.2o7.net [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.atdmt.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
track.adform.net [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
track.adform.net [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.adform.net [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad1.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
count.asnetworks.de [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.ru4.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.atdmt.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.c1.atdmt.com [ C:\USERS\STEFAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.imrworldwide.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.autoscout24.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xiti.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
rts.pgmediaserve.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
stat.dealtime.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adviva.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.guj.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ad.adnet.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.eyewonder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ad.adnet.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.daimlerag.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adxpose.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.deutschepostag.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.cheaptickets.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.overture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hardsextube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Porno tube - Adult Streaming Sex Tube Videos at PornoXO - page 1 [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.br.naked.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.static.ads.crakmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adxpansion.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.youporn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.youporn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.conrad.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.snapfish.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.eyewonder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.vodafonegroup.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.paypal.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adviva.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
brutalfistingsex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6waliwjczslq.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornsharia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.count.xhit.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tripod.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wnkyggcjseo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wgmishdpmdp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjloqpcpcho.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjlywldzilp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.thefind.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.thefind.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.thefind.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.thefind.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.thefind.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexctube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.germansexvideo.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.germansexvideo.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.discounter-deutschland.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aekyshcjieo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.4stats.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.4stats.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
static.sunporno.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fuckcams.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjk4wgcziho.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ero-advertising.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.traffichaus.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.zeusclicks.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porntubemate.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adserving.greenadvertizing.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adserving.greenadvertizing.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
pornografish.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adserver.adtechus.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.cdate.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6whkowpc5kfp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wakiqkc5oep.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wnmiuhczokp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
xml.trafficengine.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.trafficengine.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wblowmcjcgp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.generaltracking.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
hc2.humanclick.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
hc2.humanclick.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjk4umdpcgo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.philips.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adult-empire.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
stat.aldi.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.secmedia.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads2.zeusclicks.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aelisndpibp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mofosex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6whmyohc5chq.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornoxo.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sunporno.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aeloggd5ecp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adserver.gs [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas4.emediate.eu [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ad.adnet.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aeliqjajwko.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.count.spring.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
accounts.youtube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.adition.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.adition.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjmychc5wlo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6whkoomdjsfo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.alotporn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
openx.e-mags-media.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.gay.porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aek4ogcjcdo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aeloakcjolp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.dafuckbook.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.dafuckbook.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
openx.sexsearchcom.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wgkyqlc5cdp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjlyeidjehp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.wlw.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.lokalportal24de.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexlist.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tradefx.advertserve.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.oms.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.gostats.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjk4ondzmlp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.komtrack.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.komtrack.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.markussexblog.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.markussexblog.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ad.adnet.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xhamster.fuckshow.org [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xhamster.fuckshow.org [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adserver2.exgfnetwork.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adserver.tarifecheck.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.opodo.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.de.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.de.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.de.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.partypoker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.stats.tso.co.uk [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.stats.tso.co.uk [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sexlist.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hightraffic.hugoboss.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Kostenlose private Sexkontakte - sexkiste.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xxxkinky.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xxxkinky.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Free Sex Videos - Hot Sex Movies - Free Porn Tube [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.amazon-adsystem.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.amazon-adsystem.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wnmiskd5map.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultmoneymakers.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
support.adultmemberservice.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
support.adultmemberservice.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ads.crakmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ads.crakmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.yadro.ru [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.yadro.ru [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
animalporntv.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.animalporntv.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.animalporntv.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
zoosextv.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
freeanimalsextube.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Animal Porn FREE. Extreme collection of free animal porn [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Wild Animal Porn. Collection of free animal porn videos [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
wildanimalporn.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
zoo sex tv - free animal porn, animal sex, zoo porn, dog porn [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Free Sex Videos - Hot Sex Movies - Free Porn Tube [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.pornerbros.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornerbros.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornerbros.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porntube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porntube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aelyomcjmdp.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornrabbit.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornrabbit.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.adultrevads.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultadworld.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultadworld.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.im.banner.t-online.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wjlougdjelq.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6wamyandpkeo.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.enoratraffic.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.questionmarket.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads3.bangkokpost.co.th [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.h2porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.h2porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.h2porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.h2porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.h2porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.freeporn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.freeporn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.track.gridlockparadise.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.track.gridlockparadise.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornper.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornper.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornhub.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornhub.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.porn.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.at.atwola.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mmotraffic.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mmotraffic.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ru4.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornbanana.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.pornbanana.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.adserver01.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
delivery.trafficbroker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.ventivmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.alphaporno.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.alphaporno.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.girlsteachsex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracker.roitesting.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hardsextube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hardsextube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adserver.hardsextube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6whmysocpkep.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.lfstmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.lfstmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.olympiaverlag.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ads.crakmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adxpansion.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.traffictrack.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.lfstmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.yieldmanager.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
zbox.zanox.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
www.zanox-affiliate.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.bs.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
eas4.emediate.eu [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ru4.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adverts.friedrichchiller.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.dyntracker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.histats.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.histats.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.unister-adservices.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adx.chip.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adx.chip.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adultfriendfinder.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.overture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adform.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.stats.paypal.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.ehg-cheaptickets.hitbox.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.hitbox.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.zanox.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
etracker Home - forget log-file analysis, this is real-time Web Analytics and online market research [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.overture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.im.banner.t-online.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adviva.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.lucidmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.quartermedia.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.affiliaxe.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
tracking.affiliaxe.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.webmasterplan.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.eset.122.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.xm.xtendmedia.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adserver.entlastungszug.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.a.revenuemax.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad3.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
etracker Home - forget log-file analysis, this is real-time Web Analytics and online market research [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad4.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.microsoftsto.112.2o7.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zanox.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.zanox-affiliate.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.accounts.google.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.accounts.google.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.accounts.google.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
accounts.youtube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aemyglajigq.stats.esomniture.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
counter13.sextracker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.sextracker.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tribalfusion.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.kontera.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.unister-adservices.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.unister-adservices.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad1.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
Google [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
server.iad.liveperson.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adverts.friedrichchiller.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
adverts.friedrichchiller.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
accounts.youtube.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad.zanox.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
clicktrk.news.asiarooms.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
clicktrk.news.asiarooms.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
clicktrk.news.asiarooms.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
clicktrk.news.asiarooms.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
statse.webtrendslive.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
ad2.adfarm1.adition.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tracking.quisma.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\STEFAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFSD7HFQ.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-SoftonicDownloader
G:\VISTA\USERS\STEFAN\DESKTOP\EBAY 02.05.2010\DOWNLOAD\DOWNLOADS\SOFTONICDOWNLOADER_FUER_TUNEUP-UTILITIES-2011(1).EXE
G:\VISTA\USERS\STEFAN\DESKTOP\EBAY 02.05.2010\DOWNLOAD\DOWNLOADS\SOFTONICDOWNLOADER_FUER_TUNEUP-UTILITIES-2011.EXE
C:\USERS\STEFAN\DESKTOP\EBAY 02.05.2010\DOWNLOAD\DOWNLOADS\SOFTONICDOWNLOADER_FUER_TUNEUP-UTILITIES-2011(1).EXE
C:\USERS\STEFAN\DESKTOP\EBAY 02.05.2010\DOWNLOAD\DOWNLOADS\SOFTONICDOWNLOADER_FUER_TUNEUP-UTILITIES-2011.EXE
C:\USERS\STEFAN\DESKTOP\EBAY 02.05.2010\DOWNLOAD\SOFTONICDOWNLOADER_FUER_TUNEUP-UTILITIES-2011(1).EXE
C:\USERS\STEFAN\DESKTOP\EBAY 02.05.2010\DOWNLOAD\SOFTONICDOWNLOADER_FUER_TUNEUP-UTILITIES-2011.EXE
[/code]
:pfeiff:


Gruß
vonStefan.

disteffensso 15.03.2012 07:33

Der zweite Beitrag ist doppel. Ging schief. Leider.

Gruß

vonStefan.:balla:

cosinus 15.03.2012 22:14

Müll von Softonic!

Finger weg von Softonic!!

Softonic ist eine Toolbar- und Adwareschleuder! Finger weg! Software lädt man sich mit oberster Priorität direkt vom Hersteller und nicht von solchen Toolbarklitschen wie Softonic! Im Notfall würde natürlich chip.de gehen


Sieht ansosnten aus, da wurden außer dem Softonic-Müll nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

disteffensso 16.03.2012 15:42

Hallo Arne,
das Laptop hat sich mehrfach selbst eingeschaltet, aus dem Energiesparmodus. Allerdings nur unter Netzbetrieb mit angeschaltetem Wlan.
Einmal wurde ich auf ein Firewall- Problem hingewiesen. Anschließend kam die Meldung:
-zitat-
Windows wird nach unerwartetem Herunterfahren wieder ausgeführt.
Windows funktioniert nicht mehr einwandfrei.
Sie erhalten Nachricht, wenn eine Lösung verfügbar ist.
--zitat--
Ich lasse jetzt die Windows- Firewall aus, weil sich die Avira nicht dauerhaft ausschalten läßt. Kam nicht mehr vor. Bisher.
Ansonsten läuft es, wie man es von einem 2- jährigen Rechner erwarten kann:
Zufriedenstellend.
Kann ich die Filme auf -G- noch kucken? War die ganze Zeit angeschlossen und wurde mitbearbeitet.
Wenn mir wieder jemand so was anbietet, reichts da, wenn ich erst ein Virenprogramm drüberlaufen lasse?

Und abschließend:
:dankeschoen:

vonStefan.

PS: Die Überweisung- 29,99 damit mans auch erkennt- führe ich am Wochenende aus.

cosinus 16.03.2012 17:14

Na dann deinstallier Avira doch mal komplett und pack dir nur einen reinen Virenscanner ohne Firewallgedöns drauf.

Zitat:

Kann ich die Filme auf -G- noch kucken?
WO willst du Filme sehen? :balla:

disteffensso 16.03.2012 17:43

--Zitat--
WO willst du Filme sehen?
--Zitatende--
Die Filme von extern -G- am Laptop. :pfeiff:

--Zitat--
Na dann deinstallier Avira doch mal komplett und pack dir nur einen reinen Virenscanner ohne Firewallgedöns drauf.
--Zitatende--
Das wäre: SuperAntiSpyware & Windows Firewall?

Gruß
vonStefan.

cosinus 16.03.2012 18:31

Na, wenn du den Laufwerkssbuchstaben G: meinst finde ich ist "-G-" eine merkwürdige Bezeichnung dafür :D
Aber ja, die Filme darfst du sehen

Zitat:

Das wäre: SuperAntiSpyware & Windows Firewall?
Nein nicht SASW das soll später wieder runter - mit einem reinem Virenscanner meine ich sowas wie Avast (nur die Virenscannerkomponente oder MSE)

disteffensso 16.03.2012 18:41

Ja so a Freud´!:taenzer:
Sagst Du mir noch, was ich wie `runtermachen soll?
G:, ich lerns schon noch!

Gruß
vonStefan.:lach:

cosinus 16.03.2012 19:22

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

disteffensso 16.03.2012 19:32

Ich arbeite das morgen ab. Du erinnerst Dich: Thailand + 6 h.
Amgenehmen Abend noch.

Gruß
vonStefan.

nochmal:dankeschoen:

disteffensso 16.03.2012 19:33

Angenehmen. Pardon.

cosinus 16.03.2012 19:44

Mach das, viel Erfolg bei der Umsetzung. Nicht vergessen: das Prüfen und Einspielen der Updates ist immens wichtig.

disteffensso 17.03.2012 14:02

Leider kein Erfolg. Auf die Eingabe:
"combofix/uninstall" folgt die Mitteilung:
"combofix/uninstall konnte nicht gefunden werden. Stellen Sie sicher usw."

Die folgenden Programme sind nicht in "Programm deinstallieren oder ändern" gelistet:
ESET
OTL
Defogger
Osam
tdsskiller
aswMBR
Combofix (wird ja eh anders entfernt).

Alle Updates von MS sind am neuesten Stand, aber ein Defender- Update ist fehlgeschlagen.

Was nun?

Gruß

vonStefan.

cosinus 17.03.2012 15:25

Zitat:

Leider kein Erfolg. Auf die Eingabe:
"combofix/uninstall" folgt die Mitteilung:
"combofix/uninstall konnte nicht gefunden werden. Stellen Sie sicher usw."
Falsch: "combofix/uninstall"
Richtig: "combofix /uninstall"

Siehst du den Unterschied? :pfeiff:

Zitat:

Die folgenden Programme sind nicht in "Programm deinstallieren oder ändern" gelistet:
Das sind ja auch einfach nur die EXE als Programm einfach löschen

disteffensso 19.03.2012 16:56

-Zitat-
Falsch: "combofix/uninstall"
Richtig: "combofix /uninstall"
--zitat--

..die Gaudiburschen von MS! Damit man wieder recht als Depp dasteht! Echt wahr!
Combifix ging problemlos weg, nur der Löwenkopf ist noch am Desktop. Ich habe einen Riesenrespekt vor dem CF.
Vor Dir übrigens auch. Nochmals besten Dank.
Ich überweise im Anschluß. Ich erwähne das so oft, damit sich vielleicht auch andere ein Beispiel daran nehmen.

Allerbeste Grüße

vonStefan.

disteffensso 19.03.2012 17:03

:bussi:

..hab´ doch gesagt, ich könnt´ Dich abknutschen!

vonStefan.:lach:

cosinus 19.03.2012 17:07

Zitat:

Zitat von disteffensso (Beitrag 795315)
:bussi:

..hab´ doch gesagt, ich könnt´ Dich abknutschen!

vonStefan.:lach:

Das würde meiner Freundin aber garnicht gefallen :D

disteffensso 20.03.2012 09:43

...meiner wohl auch nicht...:applaus:

Gruß
von Stefan


Alle Zeitangaben in WEZ +1. Es ist jetzt 22:52 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58