Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Fehler in C:\Windows\SysWOW64\rundll32.exe. Folgender Eintrag fehlt: FQ10 (https://www.trojaner-board.de/123876-fehler-c-windows-syswow64-rundll32-exe-folgender-eintrag-fehlt-fq10.html)

cosinus 18.09.2012 14:29

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

gabi.flabi 18.09.2012 19:31

Combofix Logfile:
Code:

ComboFix 12-09-18.06 - gabriele 18.09.2012  20:21:39.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3990.2083 [GMT 2:00]
ausgeführt von:: c:\users\gabriele\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\23lldnur.pad
c:\programdata\PCDr\6032\AddOnDownloaded\06004c97-c212-44da-81de-706b46554efe.dll
c:\programdata\PCDr\6032\AddOnDownloaded\07439fd5-7039-4014-b635-5bf088a1465b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\0d461521-7dbf-4cec-a29e-936c88cdf8c9.dll
c:\programdata\PCDr\6032\AddOnDownloaded\0d85b53c-d766-4bf0-8940-17b534910268.dll
c:\programdata\PCDr\6032\AddOnDownloaded\100c3865-0c76-461b-b2fd-042d6d5fa7f6.dll
c:\programdata\PCDr\6032\AddOnDownloaded\140239b3-d59a-46fa-b856-17682a46cb44.dll
c:\programdata\PCDr\6032\AddOnDownloaded\16837627-a839-41c5-a88f-3a0335128383.dll
c:\programdata\PCDr\6032\AddOnDownloaded\16ab6978-b6b5-41fa-81a1-8bffc55a69b9.dll
c:\programdata\PCDr\6032\AddOnDownloaded\173c4dd2-e93c-4725-b006-db1d8f465192.dll
c:\programdata\PCDr\6032\AddOnDownloaded\1e0aaf9a-9947-4a7b-b1ae-8a89919438ed.dll
c:\programdata\PCDr\6032\AddOnDownloaded\263d6ac9-4f87-466c-947c-bd9af71d7035.dll
c:\programdata\PCDr\6032\AddOnDownloaded\2ee79d71-badc-46b4-b731-42b15f3cd1c3.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3410f47b-5e8c-47c6-bf2c-234af4121d4c.dll
c:\programdata\PCDr\6032\AddOnDownloaded\378deb7f-049e-4a5e-83b2-5381dcd9e928.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3972fea3-214c-4935-a7d1-96bf66115683.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3a79f062-8f3e-464f-9815-2c45840494ee.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3b1c7acd-5e3e-4459-ab98-5109117e2341.dll
c:\programdata\PCDr\6032\AddOnDownloaded\3e4c86d5-a5c1-4c3f-8fc7-6258992b16c5.dll
c:\programdata\PCDr\6032\AddOnDownloaded\44ddba62-3b58-480f-a775-ae7e9dd9d5df.dll
c:\programdata\PCDr\6032\AddOnDownloaded\4546f2bc-b9d9-4667-abe7-b0bacc90279e.dll
c:\programdata\PCDr\6032\AddOnDownloaded\4804ced5-915b-48a3-a465-b8a5e02714bf.dll
c:\programdata\PCDr\6032\AddOnDownloaded\4818e109-9489-4cd8-9044-44defd8ec187.dll
c:\programdata\PCDr\6032\AddOnDownloaded\493f295d-1a46-46f6-926c-63b474cedab4.dll
c:\programdata\PCDr\6032\AddOnDownloaded\5e1c102f-bfde-420c-87c0-64fe851888e5.dll
c:\programdata\PCDr\6032\AddOnDownloaded\62d1f0b0-bc9a-4f6c-bad7-93b19a91276a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\67c3d4fe-b638-467a-9fe2-c5813ade3330.dll
c:\programdata\PCDr\6032\AddOnDownloaded\6820b110-e483-4f1e-9b48-438f7916f078.dll
c:\programdata\PCDr\6032\AddOnDownloaded\684a43a7-04d5-4797-bc20-4db8a316286c.dll
c:\programdata\PCDr\6032\AddOnDownloaded\6928cebe-dc61-4564-a488-e19724a8de68.dll
c:\programdata\PCDr\6032\AddOnDownloaded\6b5978fa-48d7-4309-a523-7e157768c0d8.dll
c:\programdata\PCDr\6032\AddOnDownloaded\6f4fb483-ce30-493a-8cb4-3e530ab1be5b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\7014e871-cc3b-4dec-b82b-bc70222b40ed.dll
c:\programdata\PCDr\6032\AddOnDownloaded\739db3eb-d3cd-4c86-a6ea-01a49984fa3b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\7bd83798-7a02-4f50-83a2-b91cabcbd1f9.dll
c:\programdata\PCDr\6032\AddOnDownloaded\7dbfef1a-6148-4748-a1b3-71627763a45a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\813755dc-2229-47a2-b85b-19d0aaa641c9.dll
c:\programdata\PCDr\6032\AddOnDownloaded\872965c7-08b7-47fc-a74c-ff167590b71a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\8a6735b1-c078-4648-9416-b6bb29ec3dc1.dll
c:\programdata\PCDr\6032\AddOnDownloaded\8d357f17-07ad-4392-ba06-fb67564c98cd.dll
c:\programdata\PCDr\6032\AddOnDownloaded\934f6059-2d35-4bd9-a130-a17cb5563507.dll
c:\programdata\PCDr\6032\AddOnDownloaded\9ad10df8-6662-488d-9a0f-1fab1ee3403d.dll
c:\programdata\PCDr\6032\AddOnDownloaded\9f8591c3-5048-42f7-9553-387b30449f54.dll
c:\programdata\PCDr\6032\AddOnDownloaded\a4930af9-016c-4915-a740-a3364e7618aa.dll
c:\programdata\PCDr\6032\AddOnDownloaded\a61f44a8-21a3-4c4a-a04b-993dfb73bf96.dll
c:\programdata\PCDr\6032\AddOnDownloaded\a9de0c84-9a7c-4638-9653-13aa8cf56e80.dll
c:\programdata\PCDr\6032\AddOnDownloaded\ac96894a-064b-4c44-a457-9d5aaee7032a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\adb45b82-004f-4eed-bd54-d60d7eda1ff5.dll
c:\programdata\PCDr\6032\AddOnDownloaded\ae67b364-b69e-471e-b177-2459120b84d4.dll
c:\programdata\PCDr\6032\AddOnDownloaded\b2152f30-7380-4987-8fcf-e4c06952615d.dll
c:\programdata\PCDr\6032\AddOnDownloaded\b2ed8d53-41ce-48e6-b4ac-8b8e5e1a4fdf.dll
c:\programdata\PCDr\6032\AddOnDownloaded\b4cc2a4a-87f5-49cd-935c-18f1a80e65b7.dll
c:\programdata\PCDr\6032\AddOnDownloaded\b9ce760f-6209-48f2-a4a3-695324591c45.dll
c:\programdata\PCDr\6032\AddOnDownloaded\bbfa36b0-30b0-4e36-8d8c-69df1d87626b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\bc6fc708-5b6b-4a72-b336-09b3089baa7a.dll
c:\programdata\PCDr\6032\AddOnDownloaded\bf647bd7-dfb5-4746-a6b4-b7c2fdbbf3b1.dll
c:\programdata\PCDr\6032\AddOnDownloaded\c2690c4c-81f4-4565-a861-643c7af1fa90.dll
c:\programdata\PCDr\6032\AddOnDownloaded\c4211805-b43b-471d-81af-4e0589f8607b.dll
c:\programdata\PCDr\6032\AddOnDownloaded\cdda52ec-6ccd-425a-8c72-b7bbdc8b3acd.dll
c:\programdata\PCDr\6032\AddOnDownloaded\d1f4dc82-bc4c-4916-b37c-3ab9c30ae468.dll
c:\programdata\PCDr\6032\AddOnDownloaded\d34c0cf7-889f-43dd-9283-b2b6f442aae3.dll
c:\programdata\PCDr\6032\AddOnDownloaded\daf30858-49d8-434b-b4b1-068b5dc9267c.dll
c:\programdata\PCDr\6032\AddOnDownloaded\ddb9fe5d-525c-4d5d-ac37-0bd10f2864f8.dll
c:\programdata\PCDr\6032\AddOnDownloaded\e45cd45a-4d7c-4802-881f-74582b847e5c.dll
c:\programdata\PCDr\6032\AddOnDownloaded\e86f11dd-8b83-43cc-899e-f935ce0a1ea0.dll
c:\programdata\PCDr\6032\AddOnDownloaded\e9bb45d9-5a2b-47e8-9c48-168276d422cc.dll
c:\programdata\PCDr\6032\AddOnDownloaded\ef78c3e8-1d94-4219-8070-7617e119bba4.dll
c:\programdata\PCDr\6032\AddOnDownloaded\f06c5597-1a85-4d1f-ac16-a6fdd2a6bedc.dll
c:\programdata\PCDr\6032\AddOnDownloaded\f80d4ad1-1fad-43b5-b6f3-347848b5ddd5.dll
c:\programdata\PCDr\6032\AddOnDownloaded\f9dc840b-c6f7-42a5-acec-50cc7a2827fd.dll
c:\programdata\Roaming
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-08-18 bis 2012-09-18  ))))))))))))))))))))))))))))))
.
.
2012-09-18 18:26 . 2012-09-18 18:26        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-09-18 17:20 . 2012-09-18 17:20        69000        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{FEF2AC9E-79AC-4156-96C3-C595C8BBA1A0}\offreg.dll
2012-09-17 17:31 . 2012-09-17 17:31        --------        d-----w-        c:\program files (x86)\7-Zip
2012-09-17 12:01 . 2012-09-17 12:01        --------        d-----w-        C:\_OTL
2012-09-15 17:06 . 2012-08-23 08:26        9310152        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{FEF2AC9E-79AC-4156-96C3-C595C8BBA1A0}\mpengine.dll
2012-09-12 21:50 . 2012-09-12 21:50        73696        ----a-w-        c:\program files (x86)\Mozilla Firefox\breakpadinjector.dll
2012-09-12 16:34 . 2012-09-12 16:34        --------        d-----w-        c:\program files (x86)\ESET
2012-09-12 14:45 . 2012-09-12 14:45        --------        d-----w-        c:\users\gabriele\AppData\Roaming\Malwarebytes
2012-09-12 14:44 . 2012-09-12 14:44        --------        d-----w-        c:\programdata\Malwarebytes
2012-09-12 14:44 . 2012-09-12 14:44        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-09-12 14:44 . 2012-09-07 15:04        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-09-12 14:32 . 2012-08-22 18:12        950128        ----a-w-        c:\windows\system32\drivers\ndis.sys
2012-09-12 14:32 . 2012-07-04 20:26        41472        ----a-w-        c:\windows\system32\drivers\RNDISMP.sys
2012-09-12 14:32 . 2012-08-22 18:12        1913200        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-09-12 14:32 . 2012-08-22 18:12        376688        ----a-w-        c:\windows\system32\drivers\netio.sys
2012-09-12 14:32 . 2012-08-22 18:12        288624        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 14:32 . 2012-08-02 17:58        574464        ----a-w-        c:\windows\system32\d3d10level9.dll
2012-09-12 14:32 . 2012-08-02 16:57        490496        ----a-w-        c:\windows\SysWow64\d3d10level9.dll
2012-08-23 22:31 . 2012-07-06 20:07        552960        ----a-w-        c:\windows\system32\drivers\bthport.sys
2012-08-23 20:43 . 2012-08-23 20:43        --------        d-----w-        c:\programdata\PC-Doctor for Windows
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-13 10:01 . 2012-04-01 16:30        64462936        ----a-w-        c:\windows\system32\MRT.exe
2012-08-28 18:24 . 2012-08-10 05:23        477168        ----a-w-        c:\windows\SysWow64\npdeployJava1.dll
2012-08-28 18:24 . 2011-11-09 00:42        473072        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2012-08-14 23:31 . 2012-03-30 23:11        426184        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-14 23:31 . 2011-11-09 00:26        70344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        94208        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        94208        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        94208        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-13 138096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2012-07-27 35768]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942]
"Dell Registration"="c:\program files (x86)\System Registration\prodreg.exe" [2011-08-04 4165440]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"NeroLauncher"="c:\program files (x86)\Nero\SyncUP\NeroLauncher.exe" [2012-02-06 66872]
"AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-04-30 885760]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
.
c:\users\gabriele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\gabriele\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-7-3 26868192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-05-19 995392]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 116648]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-07 676936]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-14 250056]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protokoll;c:\windows\system32\DRIVERS\amppal.sys [2011-08-08 299008]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-05-19 1335360]
R3 DialComService;DIAL Communication Service;c:\program files (x86)\DIAL GmbH\DIAL Communication Framework\DialComService.exe [2011-10-17 1673520]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 116648]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-02-27 158976]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-05-17 34200]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-07 25928]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-12 114144]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-28 340240]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-12-01 250984]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 vnet;Shrew Soft Virtual Adapter;c:\windows\system32\DRIVERS\virtualnet.sys [2010-09-02 17408]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-09-16 27760]
S1 vflt;Shrew Soft Lightweight Filter;c:\windows\system32\DRIVERS\vfilter.sys [2010-09-02 21504]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-08-08 1166848]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-14 86224]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-05-19 921664]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928]
S2 dtpd;ShrewSoft DNS Proxy Daemon;c:\program files\ShrewSoft\VPN Client\dtpd.exe [2010-10-08 56592]
S2 iked;ShrewSoft IKE Daemon;c:\program files\ShrewSoft\VPN Client\iked.exe [2010-10-08 957712]
S2 ipsecd;ShrewSoft IPSEC Daemon;c:\program files\ShrewSoft\VPN Client\ipsecd.exe [2010-10-08 697616]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-07 399432]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400]
S2 Scia Licence Server;Scia Licence Server;c:\program files (x86)\Common Files\SCIA\Protection\lmgrd.exe [2011-05-26 1408848]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-08-18 1692480]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed - Virtueller Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-08-08 299008]
S3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys [2011-05-19 51712]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2011-05-19 53248]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-07-19 282624]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-01-20 176096]
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-07-20 59904]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-16 317440]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-05-17 25496]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-08-04 8604672]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-02-10 82432]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-02-10 181760]
S3 PCDSRVC{1E208CE0-FB7451FF-06020200}_0;PCDSRVC{1E208CE0-FB7451FF-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2012-08-17 25584]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-11-30 412264]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - PCDSRVC{1E208CE0-FB7451FF-06020200}_0
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 23:31]
.
2012-09-18 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000Core.job
- c:\users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-30 18:18]
.
2012-09-18 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000UA.job
- c:\users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-30 18:18]
.
2012-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 18:24]
.
2012-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 18:24]
.
2012-07-26 c:\windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job
- c:\program files\Dell Support Center\uaclauncher.exe [2012-08-23 05:36]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        97792        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        97792        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        97792        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        97792        ----a-w-        c:\users\gabriele\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-04-14 6629480]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-05 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-05 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-05 416024]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-04-12 609144]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-07-28 1935120]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-05-19 10365952]
"QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2011-03-11 4500640]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"Stage Remote"="c:\program files (x86)\Dell\Stage Remote\StageRemote.exe" [2011-06-28 2022976]
"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-04-30 2055016]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{2541EF2C-0496-4F0B-9962-BD4206C8C433}: NameServer = 193.175.112.3,195.37.168.3
FF - ProfilePath - c:\users\gabriele\AppData\Roaming\Mozilla\Firefox\Profiles\bdxvsrnh.default\
.
.
------- Dateityp-Verknüpfung -------
.
.txt=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-ESET Online Scanner - c:\program files (x86)\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020200}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-09-18  20:29:05
ComboFix-quarantined-files.txt  2012-09-18 18:29
.
Vor Suchlauf: 12 Verzeichnis(se), 422.012.559.360 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 421.861.691.392 Bytes frei
.
- - End Of File - - 5C0ECB1A75CD81B26D8FD3313E243E09

--- --- ---

cosinus 19.09.2012 15:00

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

gabi.flabi 20.09.2012 16:54

GMER
GMER Logfile:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-09-20 17:06:04
Windows 6.1.7601 Service Pack 1
Running: 4qx7ui69.exe


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4c80930c6ce5                     
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4c80930c6ce5@9c4a7bf9e3ad        0x9E 0x67 0x88 0xDF ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4c80930c6ce5 (not active ControlSet) 
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4c80930c6ce5@9c4a7bf9e3ad            0x9E 0x67 0x88 0xDF ...

---- EOF - GMER 1.0.15 ----

--- --- ---


OSAM
OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 18:07:41 on 20.09.2012

OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 64-bit
Default Browser: Mozilla Corporation Firefox 15.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000Core.job" - "Facebook Inc." - C:\Users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe
"FacebookUpdateTaskUserS-1-5-21-1531662492-2859076138-1287364489-1000UA.job" - "Facebook Inc." - C:\Users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"adfs" (adfs) - "Adobe Systems, Inc." - C:\Windows\system32\drivers\adfs.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"PCDSRVC{1E208CE0-FB7451FF-06020200}_0 - PCDR Kernel Mode Service Helper Driver" (PCDSRVC{1E208CE0-FB7451FF-06020200}_0) - "PC-Doctor, Inc." - c:\program files\dell support center\pcdsrvc_x64.pkms
"WimFltr" (WimFltr) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\wimfltr.sys

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{8352FA4C-39C6-11D3-ADBA-00A0244FB1A2} "DIALux 2.0 ArchivProtocol Class" - "DIAL GmbH, Germany" - C:\Program Files (x86)\DIALux\DLXToolBox.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
{314111c7-a502-11d2-bbca-00c04f8ec294} "ms-help" - ? -  (File not found | COM-object registry key not found)
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files (x86)\7-Zip\7-zip.dll
{3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D} "Arbeitsbereiche" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{7CCA70DB-DE7A-4FB7-9B2B-52E2335A3B5A} "Enterprise-Projekte" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\NAMEEXT.DLL
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{0006F045-0000-0000-C000-000000000046} "Microsoft Outlook Custom Icon Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\OLKFSTUB.DLL
DIALux Doc ShellExtension "{7889C2D5-D128-43e2-A8D8-A7590A12C8B3}" - ? -  (File not found | COM-object registry key not found)
DIALux LumFile ShellExtension "{7EFFF3DD-71B3-11D4-A25E-005056DCFB89}" - ? -  (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_35" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} "Java Plug-in 1.6.0_35" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_35" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\npjpi160_35.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{69AB812A-8CE4-4BF3-B49B-3B60A9F31FB2} "DIALux 3.1 ULDBrowserHelper Class" - "DIAL GmbH, Germany" - C:\Program Files (x86)\DIALux\DLXShellExtension.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
{B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Dropbox.lnk" - "Dropbox, Inc." - C:\Users\gabriele\AppData\Roaming\Dropbox\bin\Dropbox.exe  (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Facebook Update" - "Facebook Inc." - "C:\Users\gabriele\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"AccuWeatherWidget" - ? - "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"Dell Registration" - "Dell, Inc." - C:\Program Files (x86)\System Registration\prodreg.exe /boot
"Dell Webcam Central" - "Creative Technology Ltd" - "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
"Desktop Disc Tool" - ? - "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
"NeroLauncher" - ? - C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe 900  (File found, but it contains no detailed information)
"QuickTime Task" - "Apple Inc." - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
"RoxWatchTray" - "Sonic Solutions" - "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Bullzip PDF Print Monitor" - "Bullzip" - C:\Windows\system32\bzpdf.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll  (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe"  (File not found)
"@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200" (NAUpdate) - "Nero AG" - C:\Program Files (x86)\Nero\Update\NASvc.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
"ASP.NET State Service" (aspnet_state) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
"Bluetooth Device Monitor" (Bluetooth Device Monitor) - "Intel Corporation" - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
"Bluetooth Media Service" (Bluetooth Media Service) - "Intel Corporation" - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
"Bluetooth OBEX Service" (Bluetooth OBEX Service) - "Intel Corporation" - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
"DIAL Communication Service" (DialComService) - ? - C:\Program Files (x86)\DIAL GmbH\DIAL Communication Framework\DialComService.exe
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Flexera Software, Inc." - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
"Google Update-Dienst (gupdate)" (gupdate) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service" (BTHSSecurityMgr) - "Intel(R) Corporation" - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
"Intel(R) Management and Security Application Local Management Service" (LMS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
"Intel(R) Management and Security Application User Notification Service" (UNS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
"Intel(R) PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
"Intel(R) PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
"Intel(R) Turbo Boost Technology Monitor 2.0" (TurboBoost) - "Intel(R) Corporation" - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
"Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service" (AMPPALR3) - "Intel Corporation" - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
"MBAMScheduler" (MBAMScheduler) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft SharePoint Workspace Audit Service" (Microsoft SharePoint Workspace Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
"Office 64 Source Engine" (ose64) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"Roxio Hard Drive Watcher 12" (RoxWatch12) - "Sonic Solutions" - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
"RoxMediaDB12OEM" (RoxMediaDB12OEM) - "Sonic Solutions" - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
"Scia Licence Server" (Scia Licence Server) - "Flexera Software, Inc." - C:\Program Files (x86)\Common Files\SCIA\Protection\lmgrd.exe
"ShrewSoft DNS Proxy Daemon" (dtpd) - ? - C:\Program Files\ShrewSoft\VPN Client\dtpd.exe  (File found, but it contains no detailed information)
"ShrewSoft IKE Daemon" (iked) - ? - C:\Program Files\ShrewSoft\VPN Client\iked.exe  (File found, but it contains no detailed information)
"ShrewSoft IPSEC Daemon" (ipsecd) - ? - C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe  (File found, but it contains no detailed information)
"Skype C2C Service" (Skype C2C Service) - "Skype Technologies S.A." - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files (x86)\Skype\Updater\Updater.exe
"SoftThinks Agent Service" (SftService) - "SoftThinks SAS" - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
"stllssvr" (stllssvr) - "MicroVision Development, Inc." - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
"Wireless PAN DHCP Server" (MyWiFiDHCPDNS) - ? - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
[/code]

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-20 18:56:12
-----------------------------
18:56:12.722    OS Version: Windows x64 6.1.7601 Service Pack 1
18:56:12.722    Number of processors: 4 586 0x2A07
18:56:12.722    ComputerName: DELLICIOUS  UserName: gabriele
18:56:15.352    Initialize success
18:56:23.182    AVAST engine defs: 12092000
18:56:29.662    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:56:29.672    Disk 0 Vendor: ST950032 D005 Size: 476940MB BusType: 3
18:56:29.702    Disk 0 MBR read successfully
18:56:29.702    Disk 0 MBR scan
18:56:29.712    Disk 0 Windows VISTA default MBR code
18:56:29.722    Disk 0 Partition 1 00    DE Dell Utility Dell 8.0      101 MB offset 63
18:56:29.742    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        20000 MB offset 212992
18:56:29.772    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      456835 MB offset 41172992
18:56:29.812    Disk 0 scanning C:\Windows\system32\drivers
18:56:48.472    Service scanning
18:57:28.812    Modules scanning
18:57:28.822    Disk 0 trace - called modules:
18:57:28.852    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
18:57:28.862    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80065b1060]
18:57:28.872    3 CLASSPNP.SYS[fffff88000cc143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8005356050]
18:57:28.892    Scan finished successfully
18:57:41.141    Disk 0 MBR has been saved successfully to "C:\Users\gabriele\Desktop\Neuer Ordner\MBR.dat"
18:57:41.141    The log file has been saved successfully to "C:\Users\gabriele\Desktop\Neuer Ordner\aswMBR.txt"

hab mal eine frage..muss ich noch viele scans machen ? :)

cosinus 20.09.2012 20:20

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

gabi.flabi 23.09.2012 22:46

Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.23.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
gabriele :: DELLICIOUS [Administrator]

Schutz: Deaktiviert

23.09.2012 22:16:54
mbam-log-2012-09-23 (22-16-54).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 335424
Laufzeit: 1 Stunde(n), 16 Minute(n),

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/24/2012 at 09:55 AM

Application Version : 5.5.1016

Core Rules Database Version : 9197
Trace Rules Database Version: 7009

Scan type      : Complete Scan
Total Scan Time : 01:55:47

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 653
Memory threats detected  : 0
Registry items scanned    : 68685
Registry threats detected : 0
File items scanned        : 142546
File threats detected    : 383

Adware.Tracking Cookie
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\PHB1CE34.txt [ /media6degrees.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\8KUDFLTB.txt [ /serving-sys.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\Q6SIGC1Q.txt [ /ad1.adfarm1.adition.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\E0Q6ELOW.txt [ /invitemedia.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\RWUUKCKX.txt [ /ad.zanox.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\L7T2W09S.txt [ /imrworldwide.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\E2KH3VCA.txt [ /tracking.quisma.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\N2Q4M2DR.txt [ /apmebf.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\G505DBC0.txt [ /fastclick.net ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\WECVINYQ.txt [ /lucidmedia.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\MJABQUIB.txt [ /c.atdmt.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\F7HEJTIQ.txt [ /mediaplex.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\UKTZCDXV.txt [ /zanox.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\A52YNKJ0.txt [ /track.adform.net ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\9GT86HKS.txt [ /2o7.net ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\141QOIB4.txt [ /adfarm1.adition.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\CCWITI3L.txt [ /adform.net ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\73VWJVQ3.txt [ /doubleclick.net ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\B53N0SIG.txt [ /smartadserver.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\E5BPPIJN.txt [ /atdmt.com ]
        C:\Users\gabriele\AppData\Roaming\Microsoft\Windows\Cookies\ZZ13WNI5.txt [ /dyntracker.com ]
        C:\USERS\GABRIELE\AppData\Roaming\Microsoft\Windows\Cookies\Low\T2UY4KAD.txt [ Cookie:gabriele@serving-sys.com/ ]
        C:\USERS\GABRIELE\AppData\Roaming\Microsoft\Windows\Cookies\Low\G6MXUMQX.txt [ Cookie:gabriele@statse.webtrendslive.com/ ]
        C:\USERS\GABRIELE\AppData\Roaming\Microsoft\Windows\Cookies\Low\JCR4YC1Q.txt [ Cookie:gabriele@bs.serving-sys.com/ ]
        C:\USERS\GABRIELE\Cookies\PHB1CE34.txt [ Cookie:gabriele@media6degrees.com/ ]
        C:\USERS\GABRIELE\Cookies\8KUDFLTB.txt [ Cookie:gabriele@serving-sys.com/ ]
        C:\USERS\GABRIELE\Cookies\Q6SIGC1Q.txt [ Cookie:gabriele@ad1.adfarm1.adition.com/ ]
        C:\USERS\GABRIELE\Cookies\RWUUKCKX.txt [ Cookie:gabriele@ad.zanox.com/ ]
        C:\USERS\GABRIELE\Cookies\L7T2W09S.txt [ Cookie:gabriele@imrworldwide.com/cgi-bin ]
        C:\USERS\GABRIELE\Cookies\E2KH3VCA.txt [ Cookie:gabriele@tracking.quisma.com/ ]
        C:\USERS\GABRIELE\Cookies\N2Q4M2DR.txt [ Cookie:gabriele@apmebf.com/ ]
        C:\USERS\GABRIELE\Cookies\G505DBC0.txt [ Cookie:gabriele@fastclick.net/ ]
        C:\USERS\GABRIELE\Cookies\WECVINYQ.txt [ Cookie:gabriele@lucidmedia.com/ ]
        C:\USERS\GABRIELE\Cookies\F7HEJTIQ.txt [ Cookie:gabriele@mediaplex.com/ ]
        C:\USERS\GABRIELE\Cookies\UKTZCDXV.txt [ Cookie:gabriele@zanox.com/ ]
        C:\USERS\GABRIELE\Cookies\A52YNKJ0.txt [ Cookie:gabriele@track.adform.net/ ]
        C:\USERS\GABRIELE\Cookies\CCWITI3L.txt [ Cookie:gabriele@adform.net/ ]
        C:\USERS\GABRIELE\Cookies\B53N0SIG.txt [ Cookie:gabriele@smartadserver.com/ ]
        C:\USERS\GABRIELE\Cookies\E5BPPIJN.txt [ Cookie:gabriele@atdmt.com/ ]
        C:\USERS\GABRIELE\Cookies\ZZ13WNI5.txt [ Cookie:gabriele@dyntracker.com/ ]
        .adbrite.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adserver.adreactor.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adinterax.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adinterax.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .quartermedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ikea.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .realmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .harrenmedianetwork.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .euros4click.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        tracking.dc-storm.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.unitymedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        edu-stats.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .secmedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .dealtime.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .mm.chitika.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        affiliate.mediatemple.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        optimize.indieclick.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        optimize.indieclick.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adserver.adtechus.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        track.zalando.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .loyaltypartner.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adx.kat.ph [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        securetrafficserver5.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        stats.vertriebsassistent.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        7.rotator.wigetmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .bwincom.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .gostats.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .traveladvertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .traveladvertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .hawaiianairlines.112.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .pro-market.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tacoda.at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ar.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .hotwire.db.advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .networldmedia.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .trafficmp.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        clicks.stylefruits.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.3gnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .burstnet.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .www.burstnet.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        7.rotator.wigetmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        rotator.hadj7.adjuggler.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.usenext.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        stat.dealtime.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .realmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        network.realmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .opodo.122.2o7.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www2.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www2.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revenuemax.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adt.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adt.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adt.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        adt.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tto2.traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .kontera.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .rambler.ru [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .rambler.ru [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adnetwork.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.hqfootyads1.altervista.org [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .content.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .content.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .xm.xtendmedia.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GABRIELE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BDXVSRNH.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-Falprod[i]
        C:\PROGRAM FILES (X86)\SCIA\ENGINEER2011.0\NESSIE.DLL


cosinus 24.09.2012 14:27

Code:

UAC On - Limited User
Wie hast du sasw gestartet? Einfach per Doppelklick?

gabi.flabi 25.09.2012 08:59

rechtsklick..als administrator ausführen

soll ichs wiederholen ?

cosinus 25.09.2012 12:55

Nein dann ist das ok, das Programm hat da einen Bug und zeigt das nicht immer richtig an

Code:

C:\PROGRAM FILES (X86)\SCIA\ENGINEER2011.0\NESSIE.DLL
Was machst du mit dieser Software, wie kommt die darauf?! :wtf:

gabi.flabi 26.09.2012 12:20

ich arbeite ab und an mal mit der software...für die uni...

cosinus 26.09.2012 15:40

Gut, Uni also...dann ist das geklärt! :daumenhoc

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?


Alle Zeitangaben in WEZ +1. Es ist jetzt 06:35 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131