Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows Security Center Trojaner eingefangen

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 04.04.2012, 11:23   #16
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Wiederhol den Fix im abgesicherten Modus bitte
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 04.04.2012, 12:59   #17
LaurenLaw
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Code:
ATTFilter
 All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_USERS\S-1-5-21-806744476-1919467886-1915298580-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D7562AE-8EF6-416d-A838-AB665251703A}\ not found.
Registry key HKEY_USERS\S-1-5-21-806744476-1919467886-1915298580-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_USERS\S-1-5-21-806744476-1919467886-1915298580-1000\Software\Microsoft\Internet Explorer\SearchScopes\{97779E92-3072-45F4-AA39-2DCAF9E977FB}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97779E92-3072-45F4-AA39-2DCAF9E977FB}\ not found.
Registry key HKEY_USERS\S-1-5-21-806744476-1919467886-1915298580-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin not found.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin not found.
Folder C:\Users\Ms Lauren Law\AppData\Roaming\UAs\ not found.
Folder C:\Users\Ms Lauren Law\AppData\Roaming\xmldm\ not found.
Folder C:\Users\Ms Lauren Law\AppData\Roaming\kock\ not found.
Folder C:\Users\Ms Lauren Law\AppData\Roaming\Babylon\ not found.
Folder C:\Users\Ms Lauren Law\AppData\Roaming\UAs\ not found.
Folder C:\Users\Ms Lauren Law\AppData\Roaming\xmldm\ not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: AppData
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
         
__________________


Alt 04.04.2012, 13:22   #18
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten, Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

__________________
__________________

Alt 04.04.2012, 14:18   #19
LaurenLaw
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Code:
ATTFilter
 15:01:49.0757 4840	TDSS rootkit removing tool 2.7.25.0 Apr  3 2012 13:42:32
15:01:49.0986 4840	============================================================
15:01:49.0986 4840	Current date / time: 2012/04/04 15:01:49.0986
15:01:49.0986 4840	SystemInfo:
15:01:49.0986 4840	
15:01:49.0986 4840	OS Version: 6.1.7600 ServicePack: 0.0
15:01:49.0986 4840	Product type: Workstation
15:01:49.0987 4840	ComputerName: MSLAURENLAW
15:01:49.0987 4840	UserName: Ms Lauren Law
15:01:49.0987 4840	Windows directory: C:\Windows
15:01:49.0987 4840	System windows directory: C:\Windows
15:01:49.0987 4840	Running under WOW64
15:01:49.0987 4840	Processor architecture: Intel x64
15:01:49.0987 4840	Number of processors: 2
15:01:49.0987 4840	Page size: 0x1000
15:01:49.0987 4840	Boot type: Normal boot
15:01:49.0987 4840	============================================================
15:01:50.0365 4840	Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:01:50.0370 4840	\Device\Harddisk0\DR0:
15:01:50.0371 4840	MBR used
15:01:50.0371 4840	\Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0xC8800, BlocksNum 0x12A17000
15:01:50.0371 4840	\Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x12ADF800, BlocksNum 0x1294F000
15:01:50.0445 4840	Initialize success
15:01:50.0445 4840	============================================================
15:03:42.0171 3196	============================================================
15:03:42.0171 3196	Scan started
15:03:42.0171 3196	Mode: Manual; SigCheck; TDLFS; 
15:03:42.0171 3196	============================================================
15:03:42.0532 3196	1394ohci        (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
15:03:42.0664 3196	1394ohci - ok
15:03:42.0789 3196	ACPI            (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
15:03:42.0812 3196	ACPI - ok
15:03:42.0915 3196	AcpiPmi         (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
15:03:43.0003 3196	AcpiPmi - ok
15:03:43.0118 3196	AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
15:03:43.0135 3196	AdobeARMservice - ok
15:03:43.0286 3196	adp94xx         (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
15:03:43.0319 3196	adp94xx - ok
15:03:43.0442 3196	adpahci         (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
15:03:43.0471 3196	adpahci - ok
15:03:43.0591 3196	adpu320         (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
15:03:43.0615 3196	adpu320 - ok
15:03:43.0704 3196	AeLookupSvc     (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
15:03:43.0858 3196	AeLookupSvc - ok
15:03:43.0984 3196	AFD             (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
15:03:44.0048 3196	AFD - ok
15:03:44.0161 3196	agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
15:03:44.0184 3196	agp440 - ok
15:03:44.0271 3196	ALG             (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
15:03:44.0329 3196	ALG - ok
15:03:44.0442 3196	aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
15:03:44.0462 3196	aliide - ok
15:03:44.0579 3196	amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
15:03:44.0598 3196	amdide - ok
15:03:44.0710 3196	AmdK8           (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
15:03:44.0769 3196	AmdK8 - ok
15:03:44.0877 3196	AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
15:03:44.0937 3196	AmdPPM - ok
15:03:45.0061 3196	amdsata         (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
15:03:45.0083 3196	amdsata - ok
15:03:45.0212 3196	amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
15:03:45.0236 3196	amdsbs - ok
15:03:45.0364 3196	amdxata         (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
15:03:45.0383 3196	amdxata - ok
15:03:45.0495 3196	AntiVirSchedulerService (c27d46b06d340293670450fce9dfb166) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
15:03:45.0510 3196	AntiVirSchedulerService - ok
15:03:45.0602 3196	AntiVirService  (72d90e56563165984224493069c69ed4) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
15:03:45.0620 3196	AntiVirService - ok
15:03:45.0746 3196	AppID           (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
15:03:45.0830 3196	AppID - ok
15:03:45.0922 3196	AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
15:03:45.0983 3196	AppIDSvc - ok
15:03:46.0084 3196	Appinfo         (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
15:03:46.0140 3196	Appinfo - ok
15:03:46.0287 3196	Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
15:03:46.0306 3196	Apple Mobile Device - ok
15:03:46.0419 3196	arc             (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
15:03:46.0442 3196	arc - ok
15:03:46.0558 3196	arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
15:03:46.0575 3196	arcsas - ok
15:03:46.0675 3196	AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
15:03:46.0739 3196	AsyncMac - ok
15:03:46.0868 3196	atapi           (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
15:03:46.0886 3196	atapi - ok
15:03:47.0027 3196	athr            (e857eee6b92aaa473ebb3465add8f7e7) C:\Windows\system32\DRIVERS\athrx.sys
15:03:47.0105 3196	athr - ok
15:03:47.0227 3196	AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
15:03:47.0286 3196	AudioEndpointBuilder - ok
15:03:47.0340 3196	AudioSrv        (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
15:03:47.0392 3196	AudioSrv - ok
15:03:47.0516 3196	avgntflt        (b1224e6b086cd6548315b04ab575a23e) C:\Windows\system32\DRIVERS\avgntflt.sys
15:03:47.0551 3196	avgntflt - ok
15:03:47.0683 3196	avipbb          (ed45f12cfa62b83765c9c1496758cc87) C:\Windows\system32\DRIVERS\avipbb.sys
15:03:47.0697 3196	avipbb - ok
15:03:47.0802 3196	AxInstSV        (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
15:03:47.0844 3196	AxInstSV - ok
15:03:47.0970 3196	b06bdrv         (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
15:03:48.0038 3196	b06bdrv - ok
15:03:48.0163 3196	b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
15:03:48.0240 3196	b57nd60a - ok
15:03:48.0353 3196	BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
15:03:48.0383 3196	BDESVC - ok
15:03:48.0492 3196	Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
15:03:48.0573 3196	Beep - ok
15:03:48.0692 3196	BFE             (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
15:03:48.0760 3196	BFE - ok
15:03:48.0871 3196	BITS            (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
15:03:48.0938 3196	BITS - ok
15:03:49.0066 3196	blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
15:03:49.0094 3196	blbdrive - ok
15:03:49.0193 3196	Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
15:03:49.0219 3196	Bonjour Service - ok
15:03:49.0338 3196	bowser          (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
15:03:49.0382 3196	bowser - ok
15:03:49.0505 3196	BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
15:03:49.0553 3196	BrFiltLo - ok
15:03:49.0658 3196	BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
15:03:49.0686 3196	BrFiltUp - ok
15:03:49.0777 3196	Browser         (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
15:03:49.0835 3196	Browser - ok
15:03:49.0956 3196	Brserid         (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\system32\Drivers\Brserid.sys
15:03:50.0015 3196	Brserid - ok
15:03:50.0125 3196	BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
15:03:50.0162 3196	BrSerWdm - ok
15:03:50.0280 3196	BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
15:03:50.0329 3196	BrUsbMdm - ok
15:03:50.0449 3196	BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\Drivers\BrUsbSer.sys
15:03:50.0484 3196	BrUsbSer - ok
15:03:50.0625 3196	BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
15:03:50.0654 3196	BTHMODEM - ok
15:03:50.0753 3196	bthserv         (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
15:03:50.0824 3196	bthserv - ok
15:03:50.0930 3196	cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
15:03:51.0013 3196	cdfs - ok
15:03:51.0136 3196	cdrom           (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
15:03:51.0172 3196	cdrom - ok
15:03:51.0268 3196	CertPropSvc     (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
15:03:51.0352 3196	CertPropSvc - ok
15:03:51.0482 3196	cfWiMAXService  (837ff2d497880198c918e6954dbd170c) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
15:03:51.0502 3196	cfWiMAXService - ok
15:03:51.0618 3196	circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
15:03:51.0647 3196	circlass - ok
15:03:51.0767 3196	CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
15:03:51.0796 3196	CLFS - ok
15:03:51.0887 3196	clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
15:03:51.0913 3196	clr_optimization_v2.0.50727_32 - ok
15:03:51.0994 3196	clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
15:03:52.0013 3196	clr_optimization_v2.0.50727_64 - ok
15:03:52.0150 3196	clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
15:03:52.0169 3196	clr_optimization_v4.0.30319_32 - ok
15:03:52.0296 3196	clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
15:03:52.0314 3196	clr_optimization_v4.0.30319_64 - ok
15:03:52.0431 3196	CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
15:03:52.0473 3196	CmBatt - ok
15:03:52.0576 3196	cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
15:03:52.0592 3196	cmdide - ok
15:03:52.0719 3196	CNG             (937beb186a735aca91d717044a49d17e) C:\Windows\system32\Drivers\cng.sys
15:03:52.0765 3196	CNG - ok
15:03:52.0880 3196	Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
15:03:52.0899 3196	Compbatt - ok
15:03:53.0007 3196	CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
15:03:53.0044 3196	CompositeBus - ok
15:03:53.0087 3196	COMSysApp - ok
15:03:53.0196 3196	ConfigFree Gadget Service (d252c53bcdfc199bba55eeb10cdb266e) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
15:03:53.0213 3196	ConfigFree Gadget Service - ok
15:03:53.0320 3196	ConfigFree Service (cab0eeaf5295fc96ddd3e19dce27e131) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
15:03:53.0334 3196	ConfigFree Service - ok
15:03:53.0434 3196	crcdisk         (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
15:03:53.0453 3196	crcdisk - ok
15:03:53.0551 3196	CryptSvc        (8c57411b66282c01533cb776f98ad384) C:\Windows\system32\cryptsvc.dll
15:03:53.0627 3196	CryptSvc - ok
15:03:53.0737 3196	DcomLaunch      (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
15:03:53.0793 3196	DcomLaunch - ok
15:03:53.0894 3196	defragsvc       (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
15:03:53.0971 3196	defragsvc - ok
15:03:54.0087 3196	DfsC            (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
15:03:54.0138 3196	DfsC - ok
15:03:54.0247 3196	Dhcp            (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
15:03:54.0327 3196	Dhcp - ok
15:03:54.0419 3196	discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
15:03:54.0492 3196	discache - ok
15:03:54.0603 3196	Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
15:03:54.0624 3196	Disk - ok
15:03:54.0727 3196	Dnscache        (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
15:03:54.0767 3196	Dnscache - ok
15:03:54.0851 3196	dot3svc         (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
15:03:54.0912 3196	dot3svc - ok
15:03:55.0006 3196	DPS             (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
15:03:55.0065 3196	DPS - ok
15:03:55.0173 3196	drmkaud         (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
15:03:55.0226 3196	drmkaud - ok
15:03:55.0358 3196	DXGKrnl         (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
15:03:55.0389 3196	DXGKrnl - ok
15:03:55.0484 3196	EapHost         (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
15:03:55.0553 3196	EapHost - ok
15:03:55.0735 3196	ebdrv           (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
15:03:55.0892 3196	ebdrv - ok
15:03:56.0006 3196	EFS             (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
15:03:56.0040 3196	EFS - ok
15:03:56.0147 3196	ehRecvr         (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
15:03:56.0203 3196	ehRecvr - ok
15:03:56.0265 3196	ehSched         (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
15:03:56.0310 3196	ehSched - ok
15:03:56.0448 3196	elxstor         (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
15:03:56.0481 3196	elxstor - ok
15:03:56.0592 3196	ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
15:03:56.0635 3196	ErrDev - ok
15:03:56.0737 3196	EventSystem     (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
15:03:56.0820 3196	EventSystem - ok
15:03:56.0940 3196	exfat           (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
15:03:57.0002 3196	exfat - ok
15:03:57.0107 3196	fastfat         (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
15:03:57.0176 3196	fastfat - ok
15:03:57.0290 3196	Fax             (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
15:03:57.0349 3196	Fax - ok
15:03:57.0453 3196	fdc             (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
15:03:57.0475 3196	fdc - ok
15:03:57.0561 3196	fdPHost         (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
15:03:57.0626 3196	fdPHost - ok
15:03:57.0710 3196	FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
15:03:57.0781 3196	FDResPub - ok
15:03:57.0896 3196	FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
15:03:57.0916 3196	FileInfo - ok
15:03:58.0027 3196	Filetrace       (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
15:03:58.0088 3196	Filetrace - ok
15:03:58.0193 3196	flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
15:03:58.0231 3196	flpydisk - ok
15:03:58.0337 3196	FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
15:03:58.0364 3196	FltMgr - ok
15:03:58.0489 3196	FontCache       (cb5e4b9c319e3c6bb363eb7e58a4a051) C:\Windows\system32\FntCache.dll
15:03:58.0543 3196	FontCache - ok
15:03:58.0644 3196	FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
15:03:58.0659 3196	FontCache3.0.0.0 - ok
15:03:58.0756 3196	FsDepends       (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
15:03:58.0777 3196	FsDepends - ok
15:03:58.0902 3196	fssfltr         (dc0dce4ec2c5d2cf6472f9fd6aa9a7dc) C:\Windows\system32\DRIVERS\fssfltr.sys
15:03:58.0919 3196	fssfltr - ok
15:03:59.0045 3196	fsssvc          (40cdfad174b3d5e80f95dda003c0b97f) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
15:03:59.0098 3196	fsssvc - ok
15:03:59.0197 3196	Fs_Rec          (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
15:03:59.0215 3196	Fs_Rec - ok
15:03:59.0328 3196	fvevol          (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
15:03:59.0356 3196	fvevol - ok
15:03:59.0466 3196	gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
15:03:59.0485 3196	gagp30kx - ok
15:03:59.0622 3196	GameConsoleService (c44d560e441f091ea3b72f778ec60de2) C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
15:03:59.0643 3196	GameConsoleService - ok
15:03:59.0766 3196	GEARAspiWDM     (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
15:03:59.0780 3196	GEARAspiWDM - ok
15:03:59.0885 3196	gpsvc           (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
15:03:59.0926 3196	gpsvc - ok
15:04:00.0014 3196	gupdate         (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:04:00.0028 3196	gupdate - ok
15:04:00.0067 3196	gupdatem        (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:04:00.0076 3196	gupdatem - ok
15:04:00.0155 3196	gusvc           (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
15:04:00.0173 3196	gusvc - ok
15:04:00.0283 3196	hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
15:04:00.0343 3196	hcw85cir - ok
15:04:00.0466 3196	HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
15:04:00.0513 3196	HdAudAddService - ok
15:04:00.0624 3196	HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
15:04:00.0669 3196	HDAudBus - ok
15:04:00.0773 3196	HidBatt         (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
15:04:00.0813 3196	HidBatt - ok
15:04:00.0927 3196	HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
15:04:00.0967 3196	HidBth - ok
15:04:01.0081 3196	HidIr           (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
15:04:01.0124 3196	HidIr - ok
15:04:01.0218 3196	hidserv         (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
15:04:01.0276 3196	hidserv - ok
15:04:01.0402 3196	HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
15:04:01.0440 3196	HidUsb - ok
15:04:01.0529 3196	hkmsvc          (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
15:04:01.0597 3196	hkmsvc - ok
15:04:01.0689 3196	HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
15:04:01.0744 3196	HomeGroupListener - ok
15:04:01.0832 3196	HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
15:04:01.0874 3196	HomeGroupProvider - ok
15:04:02.0006 3196	HpSAMD          (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
15:04:02.0027 3196	HpSAMD - ok
15:04:02.0169 3196	HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
15:04:02.0234 3196	HTTP - ok
15:04:02.0331 3196	hwpolicy        (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
15:04:02.0346 3196	hwpolicy - ok
15:04:02.0456 3196	i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
15:04:02.0475 3196	i8042prt - ok
15:04:02.0594 3196	iaStor          (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys
15:04:02.0617 3196	iaStor - ok
15:04:02.0745 3196	iaStorV         (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
15:04:02.0776 3196	iaStorV - ok
15:04:02.0901 3196	idsvc           (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
15:04:02.0937 3196	idsvc - ok
15:04:03.0217 3196	igfx            (3c3f27002abc69c5afe29cbe6cf7addf) C:\Windows\system32\DRIVERS\igdkmd64.sys
15:04:03.0466 3196	igfx - ok
15:04:03.0590 3196	iirsp           (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
15:04:03.0609 3196	iirsp - ok
15:04:03.0723 3196	IKEEXT          (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
15:04:03.0791 3196	IKEEXT - ok
15:04:03.0964 3196	IntcAzAudAddService (0c3cf4b3bae28e121a1689e3538f8712) C:\Windows\system32\drivers\RTKVHD64.sys
15:04:04.0007 3196	IntcAzAudAddService - ok
15:04:04.0131 3196	IntcHdmiAddService (88a20fa54c73ded4e8dac764e9130ae9) C:\Windows\system32\drivers\IntcHdmi.sys
15:04:04.0180 3196	IntcHdmiAddService - ok
15:04:04.0306 3196	intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
15:04:04.0325 3196	intelide - ok
15:04:04.0438 3196	intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
15:04:04.0470 3196	intelppm - ok
15:04:04.0566 3196	IPBusEnum       (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
15:04:04.0610 3196	IPBusEnum - ok
15:04:04.0717 3196	IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
15:04:04.0781 3196	IpFilterDriver - ok
15:04:04.0887 3196	iphlpsvc        (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
15:04:04.0950 3196	iphlpsvc - ok
15:04:05.0056 3196	IPMIDRV         (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
15:04:05.0090 3196	IPMIDRV - ok
15:04:05.0190 3196	IPNAT           (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
15:04:05.0257 3196	IPNAT - ok
15:04:05.0373 3196	iPod Service    (50d6ccc6ff5561f9f56946b3e6164fb8) C:\Program Files\iPod\bin\iPodService.exe
15:04:05.0402 3196	iPod Service - ok
15:04:05.0516 3196	IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
15:04:05.0546 3196	IRENUM - ok
15:04:05.0659 3196	isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
15:04:05.0678 3196	isapnp - ok
15:04:05.0781 3196	iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
15:04:05.0808 3196	iScsiPrt - ok
15:04:05.0913 3196	kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
15:04:05.0933 3196	kbdclass - ok
15:04:06.0038 3196	kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
15:04:06.0073 3196	kbdhid - ok
15:04:06.0184 3196	KeyIso          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
15:04:06.0206 3196	KeyIso - ok
15:04:06.0319 3196	KSecDD          (16c1b906fc5ead84769f90b736b6bf0e) C:\Windows\system32\Drivers\ksecdd.sys
15:04:06.0336 3196	KSecDD - ok
15:04:06.0444 3196	KSecPkg         (0b711550c56444879d71c7daabda6c83) C:\Windows\system32\Drivers\ksecpkg.sys
15:04:06.0466 3196	KSecPkg - ok
15:04:06.0547 3196	ksthunk         (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
15:04:06.0610 3196	ksthunk - ok
15:04:06.0708 3196	KtmRm           (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
15:04:06.0766 3196	KtmRm - ok
15:04:06.0875 3196	LanmanServer    (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
15:04:06.0940 3196	LanmanServer - ok
15:04:07.0049 3196	LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
15:04:07.0097 3196	LanmanWorkstation - ok
15:04:07.0206 3196	lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
15:04:07.0266 3196	lltdio - ok
15:04:07.0353 3196	lltdsvc         (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
15:04:07.0414 3196	lltdsvc - ok
15:04:07.0501 3196	lmhosts         (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
15:04:07.0547 3196	lmhosts - ok
15:04:07.0659 3196	LPCFilter       (41e122f6d1448c94cc05196bc41d6bfb) C:\Windows\system32\DRIVERS\LPCFilter.sys
15:04:07.0673 3196	LPCFilter - ok
15:04:07.0772 3196	LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
15:04:07.0789 3196	LSI_FC - ok
15:04:07.0898 3196	LSI_SAS         (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
15:04:07.0920 3196	LSI_SAS - ok
15:04:08.0032 3196	LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
15:04:08.0054 3196	LSI_SAS2 - ok
15:04:08.0162 3196	LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
15:04:08.0179 3196	LSI_SCSI - ok
15:04:08.0268 3196	luafv           (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
15:04:08.0320 3196	luafv - ok
15:04:08.0409 3196	Mcx2Svc         (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
15:04:08.0447 3196	Mcx2Svc - ok
15:04:08.0540 3196	megasas         (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
15:04:08.0561 3196	megasas - ok
15:04:08.0663 3196	MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
15:04:08.0690 3196	MegaSR - ok
15:04:08.0795 3196	Microsoft Office Groove Audit Service (123271bd5237ab991dc5c21fdf8835eb) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
15:04:08.0812 3196	Microsoft Office Groove Audit Service - ok
15:04:08.0897 3196	MMCSS           (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
15:04:08.0962 3196	MMCSS - ok
15:04:09.0062 3196	Modem           (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
15:04:09.0120 3196	Modem - ok
15:04:09.0223 3196	monitor         (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
15:04:09.0257 3196	monitor - ok
15:04:09.0365 3196	mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
15:04:09.0384 3196	mouclass - ok
15:04:09.0491 3196	mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
15:04:09.0517 3196	mouhid - ok
15:04:09.0628 3196	mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
15:04:09.0641 3196	mountmgr - ok
15:04:09.0739 3196	mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
15:04:09.0760 3196	mpio - ok
15:04:09.0856 3196	mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
15:04:09.0939 3196	mpsdrv - ok
15:04:10.0050 3196	MpsSvc          (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
15:04:10.0113 3196	MpsSvc - ok
15:04:10.0207 3196	MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
15:04:10.0253 3196	MRxDAV - ok
15:04:10.0377 3196	mrxsmb          (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
15:04:10.0414 3196	mrxsmb - ok
15:04:10.0539 3196	mrxsmb10        (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
15:04:10.0561 3196	mrxsmb10 - ok
15:04:10.0669 3196	mrxsmb20        (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
15:04:10.0706 3196	mrxsmb20 - ok
15:04:10.0805 3196	msahci          (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
15:04:10.0824 3196	msahci - ok
15:04:10.0916 3196	msdsm           (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
15:04:10.0939 3196	msdsm - ok
15:04:11.0036 3196	MSDTC           (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
15:04:11.0066 3196	MSDTC - ok
15:04:11.0162 3196	Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
15:04:11.0207 3196	Msfs - ok
15:04:11.0303 3196	mshidkmdf       (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
15:04:11.0356 3196	mshidkmdf - ok
15:04:11.0446 3196	msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
15:04:11.0464 3196	msisadrv - ok
15:04:11.0563 3196	MSiSCSI         (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
15:04:11.0625 3196	MSiSCSI - ok
15:04:11.0688 3196	msiserver - ok
15:04:11.0791 3196	MSKSSRV         (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
15:04:11.0859 3196	MSKSSRV - ok
15:04:11.0963 3196	MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
15:04:12.0030 3196	MSPCLOCK - ok
15:04:12.0139 3196	MSPQM           (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
15:04:12.0211 3196	MSPQM - ok
15:04:12.0311 3196	MsRPC           (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
15:04:12.0340 3196	MsRPC - ok
15:04:12.0437 3196	mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
15:04:12.0453 3196	mssmbios - ok
15:04:12.0544 3196	MSTEE           (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
15:04:12.0606 3196	MSTEE - ok
15:04:12.0698 3196	MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
15:04:12.0730 3196	MTConfig - ok
15:04:12.0833 3196	Mup             (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
15:04:12.0853 3196	Mup - ok
15:04:12.0949 3196	napagent        (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
15:04:13.0028 3196	napagent - ok
15:04:13.0138 3196	NativeWifiP     (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
15:04:13.0178 3196	NativeWifiP - ok
15:04:13.0301 3196	NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
15:04:13.0345 3196	NDIS - ok
15:04:13.0451 3196	NdisCap         (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
15:04:13.0512 3196	NdisCap - ok
15:04:13.0615 3196	NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
15:04:13.0669 3196	NdisTapi - ok
15:04:13.0745 3196	Ndisuio         (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
15:04:13.0811 3196	Ndisuio - ok
15:04:13.0909 3196	NdisWan         (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
15:04:13.0962 3196	NdisWan - ok
15:04:14.0049 3196	NDProxy         (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
15:04:14.0114 3196	NDProxy - ok
15:04:14.0215 3196	NetBIOS         (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
15:04:14.0275 3196	NetBIOS - ok
15:04:14.0375 3196	NetBT           (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
15:04:14.0435 3196	NetBT - ok
15:04:14.0552 3196	Netlogon        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
15:04:14.0575 3196	Netlogon - ok
15:04:14.0674 3196	Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
15:04:14.0739 3196	Netman - ok
15:04:14.0839 3196	netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
15:04:14.0916 3196	netprofm - ok
15:04:15.0060 3196	netr28ux        (ba90f3931815703924bfe4d29d27a06c) C:\Windows\system32\DRIVERS\netr28ux.sys
15:04:15.0113 3196	netr28ux - ok
15:04:15.0218 3196	NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
15:04:15.0236 3196	NetTcpPortSharing - ok
15:04:15.0351 3196	nfrd960         (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
15:04:15.0371 3196	nfrd960 - ok
15:04:15.0478 3196	NlaSvc          (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
15:04:15.0539 3196	NlaSvc - ok
15:04:15.0644 3196	Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
15:04:15.0705 3196	Npfs - ok
15:04:15.0797 3196	nsi             (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
15:04:15.0871 3196	nsi - ok
15:04:15.0956 3196	nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
15:04:16.0001 3196	nsiproxy - ok
15:04:16.0139 3196	Ntfs            (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
15:04:16.0184 3196	Ntfs - ok
15:04:16.0276 3196	Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
15:04:16.0328 3196	Null - ok
15:04:16.0449 3196	nvraid          (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
15:04:16.0467 3196	nvraid - ok
15:04:16.0576 3196	nvstor          (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
15:04:16.0597 3196	nvstor - ok
15:04:16.0714 3196	nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
15:04:16.0735 3196	nv_agp - ok
15:04:16.0821 3196	odserv          (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
15:04:16.0847 3196	odserv - ok
15:04:16.0949 3196	ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
15:04:16.0983 3196	ohci1394 - ok
15:04:17.0061 3196	ose             (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:04:17.0080 3196	ose - ok
15:04:17.0180 3196	p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
15:04:17.0228 3196	p2pimsvc - ok
15:04:17.0338 3196	p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
15:04:17.0368 3196	p2psvc - ok
15:04:17.0466 3196	Parport         (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
15:04:17.0491 3196	Parport - ok
15:04:17.0585 3196	partmgr         (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
15:04:17.0605 3196	partmgr - ok
15:04:17.0701 3196	PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
15:04:17.0747 3196	PcaSvc - ok
15:04:17.0841 3196	pci             (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
15:04:17.0860 3196	pci - ok
15:04:17.0948 3196	pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
15:04:17.0965 3196	pciide - ok
15:04:18.0065 3196	pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
15:04:18.0090 3196	pcmcia - ok
15:04:18.0206 3196	PCSUService     (7eb95aa73d657a2da9d8cfc336f4f48f) C:\Program Files (x86)\PC Beschleunigen\PCSUService.exe
15:04:18.0223 3196	PCSUService ( UnsignedFile.Multi.Generic ) - warning
15:04:18.0223 3196	PCSUService - detected UnsignedFile.Multi.Generic (1)
15:04:18.0313 3196	pcw             (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
15:04:18.0334 3196	pcw - ok
15:04:18.0447 3196	PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
15:04:18.0522 3196	PEAUTH - ok
15:04:18.0603 3196	PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
15:04:18.0637 3196	PerfHost - ok
15:04:18.0802 3196	PGEffect        (663962900e7fea522126ba287715bb4a) C:\Windows\system32\DRIVERS\pgeffect.sys
15:04:18.0815 3196	PGEffect - ok
15:04:18.0935 3196	pla             (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
15:04:19.0015 3196	pla - ok
15:04:19.0139 3196	PlugPlay        (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
15:04:19.0195 3196	PlugPlay - ok
15:04:19.0293 3196	PNRPAutoReg     (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
15:04:19.0330 3196	PNRPAutoReg - ok
15:04:19.0436 3196	PNRPsvc         (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
15:04:19.0465 3196	PNRPsvc - ok
15:04:19.0572 3196	PolicyAgent     (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
15:04:19.0637 3196	PolicyAgent - ok
15:04:19.0739 3196	Power           (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
15:04:19.0808 3196	Power - ok
15:04:19.0920 3196	PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
15:04:19.0985 3196	PptpMiniport - ok
15:04:20.0086 3196	Processor       (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
15:04:20.0122 3196	Processor - ok
15:04:20.0212 3196	ProfSvc         (f381975e1f4346de875cb07339ce8d3a) C:\Windows\system32\profsvc.dll
15:04:20.0278 3196	ProfSvc - ok
15:04:20.0385 3196	ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
15:04:20.0408 3196	ProtectedStorage - ok
15:04:20.0519 3196	Psched          (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
15:04:20.0587 3196	Psched - ok
15:04:20.0722 3196	ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
15:04:20.0770 3196	ql2300 - ok
15:04:20.0862 3196	ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
15:04:20.0885 3196	ql40xx - ok
15:04:20.0978 3196	QWAVE           (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
15:04:21.0015 3196	QWAVE - ok
15:04:21.0106 3196	QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
15:04:21.0157 3196	QWAVEdrv - ok
15:04:21.0254 3196	RalinkRegistryWriter (432f5b15e21a54b48072593f03570326) C:\Program Files (x86)\Sitecom\Common\RegistryWriter.exe
15:04:21.0281 3196	RalinkRegistryWriter ( UnsignedFile.Multi.Generic ) - warning
15:04:21.0281 3196	RalinkRegistryWriter - detected UnsignedFile.Multi.Generic (1)
15:04:21.0378 3196	RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
15:04:21.0454 3196	RasAcd - ok
15:04:21.0562 3196	RasAgileVpn     (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
15:04:21.0611 3196	RasAgileVpn - ok
15:04:21.0693 3196	RasAuto         (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
15:04:21.0739 3196	RasAuto - ok
15:04:21.0837 3196	Rasl2tp         (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
15:04:21.0898 3196	Rasl2tp - ok
15:04:21.0999 3196	RasMan          (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
15:04:22.0082 3196	RasMan - ok
15:04:22.0201 3196	RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
15:04:22.0266 3196	RasPppoe - ok
15:04:22.0369 3196	RasSstp         (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
15:04:22.0435 3196	RasSstp - ok
15:04:22.0541 3196	rdbss           (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
15:04:22.0602 3196	rdbss - ok
15:04:22.0695 3196	rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
15:04:22.0737 3196	rdpbus - ok
15:04:22.0837 3196	RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
15:04:22.0887 3196	RDPCDD - ok
15:04:22.0995 3196	RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
15:04:23.0055 3196	RDPENCDD - ok
15:04:23.0165 3196	RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
15:04:23.0221 3196	RDPREFMP - ok
15:04:23.0335 3196	RDPWD           (074ac702d8b8b660b0e1371555995386) C:\Windows\system32\drivers\RDPWD.sys
15:04:23.0395 3196	RDPWD - ok
15:04:23.0503 3196	rdyboost        (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
15:04:23.0529 3196	rdyboost - ok
15:04:23.0619 3196	RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
15:04:23.0674 3196	RemoteAccess - ok
15:04:23.0763 3196	RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
15:04:23.0831 3196	RemoteRegistry - ok
15:04:23.0922 3196	RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
15:04:23.0999 3196	RpcEptMapper - ok
15:04:24.0081 3196	RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
15:04:24.0114 3196	RpcLocator - ok
15:04:24.0207 3196	RpcSs           (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
15:04:24.0260 3196	RpcSs - ok
15:04:24.0359 3196	rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
15:04:24.0406 3196	rspndr - ok
15:04:24.0549 3196	RSUSBSTOR       (8c22f21c924413d4e109995f748e18bb) C:\Windows\system32\Drivers\RtsUStor.sys
15:04:24.0602 3196	RSUSBSTOR - ok
15:04:24.0734 3196	RTL8167         (b49dc435ae3695bac5623dd94b05732d) C:\Windows\system32\DRIVERS\Rt64win7.sys
15:04:24.0786 3196	RTL8167 - ok
15:04:24.0925 3196	rtl8192se       (a9ede191b5478d18f0a1bff3b822f7a5) C:\Windows\system32\DRIVERS\rtl8192se.sys
15:04:24.0983 3196	rtl8192se - ok
15:04:25.0053 3196	RtsUIR - ok
15:04:25.0174 3196	s217bus         (b49951a2c8fd81307707443d01936e37) C:\Windows\system32\DRIVERS\s217bus.sys
15:04:25.0191 3196	s217bus - ok
15:04:25.0311 3196	s217mdfl        (58204ec551d1a94d60cac130440f0feb) C:\Windows\system32\DRIVERS\s217mdfl.sys
15:04:25.0324 3196	s217mdfl - ok
15:04:25.0429 3196	s217mdm         (e2b3de89339a7a807520c6063cd146d3) C:\Windows\system32\DRIVERS\s217mdm.sys
15:04:25.0447 3196	s217mdm - ok
15:04:25.0577 3196	s217nd5         (7bc7d18351b846f4544b54db38fb4208) C:\Windows\system32\DRIVERS\s217nd5.sys
15:04:25.0589 3196	s217nd5 - ok
15:04:25.0707 3196	s217obex        (d498b2082f51858f121d4584a7787cd5) C:\Windows\system32\DRIVERS\s217obex.sys
15:04:25.0723 3196	s217obex - ok
15:04:25.0846 3196	s217unic        (43512d0c3a59eb20fda06ce4265a1549) C:\Windows\system32\DRIVERS\s217unic.sys
15:04:25.0863 3196	s217unic - ok
15:04:25.0974 3196	SamSs           (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
15:04:25.0997 3196	SamSs - ok
15:04:26.0100 3196	sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
15:04:26.0121 3196	sbp2port - ok
15:04:26.0214 3196	SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
15:04:26.0287 3196	SCardSvr - ok
15:04:26.0381 3196	scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
15:04:26.0430 3196	scfilter - ok
15:04:26.0563 3196	Schedule        (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
15:04:26.0614 3196	Schedule - ok
15:04:26.0704 3196	SCPolicySvc     (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
15:04:26.0745 3196	SCPolicySvc - ok
15:04:26.0836 3196	SDRSVC          (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
15:04:26.0891 3196	SDRSVC - ok
15:04:26.0999 3196	secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
15:04:27.0046 3196	secdrv - ok
15:04:27.0129 3196	seclogon        (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
15:04:27.0191 3196	seclogon - ok
15:04:27.0279 3196	SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
15:04:27.0341 3196	SENS - ok
15:04:27.0436 3196	SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
15:04:27.0484 3196	SensrSvc - ok
15:04:27.0571 3196	Serenum         (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
15:04:27.0594 3196	Serenum - ok
15:04:27.0709 3196	Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
15:04:27.0745 3196	Serial - ok
15:04:27.0846 3196	sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
15:04:27.0867 3196	sermouse - ok
15:04:27.0969 3196	SessionEnv      (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
15:04:28.0026 3196	SessionEnv - ok
15:04:28.0117 3196	sffdisk         (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
15:04:28.0156 3196	sffdisk - ok
15:04:28.0252 3196	sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
15:04:28.0288 3196	sffp_mmc - ok
15:04:28.0389 3196	sffp_sd         (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
15:04:28.0430 3196	sffp_sd - ok
15:04:28.0534 3196	sfloppy         (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
15:04:28.0564 3196	sfloppy - ok
15:04:28.0682 3196	SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
15:04:28.0752 3196	SharedAccess - ok
15:04:28.0841 3196	ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
15:04:28.0885 3196	ShellHWDetection - ok
15:04:28.0995 3196	SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
15:04:29.0012 3196	SiSRaid2 - ok
15:04:29.0116 3196	SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
15:04:29.0134 3196	SiSRaid4 - ok
15:04:29.0243 3196	Smb             (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
15:04:29.0309 3196	Smb - ok
15:04:29.0421 3196	SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
15:04:29.0457 3196	SNMPTRAP - ok
15:04:29.0553 3196	spldr           (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
15:04:29.0571 3196	spldr - ok
15:04:29.0680 3196	Spooler         (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
15:04:29.0719 3196	Spooler - ok
15:04:29.0898 3196	sppsvc          (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
15:04:30.0011 3196	sppsvc - ok
15:04:30.0104 3196	sppuinotify     (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
15:04:30.0163 3196	sppuinotify - ok
15:04:30.0274 3196	srv             (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
15:04:30.0323 3196	srv - ok
15:04:30.0446 3196	srv2            (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
15:04:30.0489 3196	srv2 - ok
15:04:30.0609 3196	srvnet          (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
15:04:30.0646 3196	srvnet - ok
15:04:30.0755 3196	SSDPSRV         (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
15:04:30.0822 3196	SSDPSRV - ok
15:04:30.0918 3196	SstpSvc         (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
15:04:30.0966 3196	SstpSvc - ok
15:04:31.0064 3196	stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
15:04:31.0083 3196	stexstor - ok
15:04:31.0189 3196	stisvc          (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
15:04:31.0229 3196	stisvc - ok
15:04:31.0319 3196	swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
15:04:31.0337 3196	swenum - ok
15:04:31.0437 3196	swprv           (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
15:04:31.0492 3196	swprv - ok
15:04:31.0624 3196	SynTP           (be7311da9d6833fa69ed04b744a1c8f8) C:\Windows\system32\DRIVERS\SynTP.sys
15:04:31.0644 3196	SynTP - ok
15:04:31.0772 3196	SysMain         (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
15:04:31.0833 3196	SysMain - ok
15:04:31.0931 3196	TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
15:04:31.0966 3196	TabletInputService - ok
15:04:32.0063 3196	TapiSrv         (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
15:04:32.0133 3196	TapiSrv - ok
15:04:32.0225 3196	TBS             (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
15:04:32.0290 3196	TBS - ok
15:04:32.0456 3196	Tcpip           (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\drivers\tcpip.sys
15:04:32.0505 3196	Tcpip - ok
15:04:32.0677 3196	TCPIP6          (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\DRIVERS\tcpip.sys
15:04:32.0724 3196	TCPIP6 - ok
15:04:32.0813 3196	tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
15:04:32.0862 3196	tcpipreg - ok
15:04:32.0973 3196	tdcmdpst        (fd542b661bd22fa69ca789ad0ac58c29) C:\Windows\system32\DRIVERS\tdcmdpst.sys
15:04:32.0986 3196	tdcmdpst - ok
15:04:33.0088 3196	TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
15:04:33.0119 3196	TDPIPE - ok
15:04:33.0238 3196	TDTCP           (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
15:04:33.0277 3196	TDTCP - ok
15:04:33.0380 3196	tdx             (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
15:04:33.0447 3196	tdx - ok
15:04:33.0519 3196	TemproMonitoringService (63b4f544664dc5154fda4213e2af09d0) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
15:04:33.0534 3196	TemproMonitoringService - ok
15:04:33.0630 3196	TermDD          (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
15:04:33.0650 3196	TermDD - ok
15:04:33.0748 3196	TermService     (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
15:04:33.0817 3196	TermService - ok
15:04:33.0904 3196	Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
15:04:33.0947 3196	Themes - ok
15:04:34.0032 3196	THREADORDER     (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
15:04:34.0082 3196	THREADORDER - ok
15:04:34.0175 3196	TMachInfo       (32577b987ae5401038451bb392cb8d89) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
15:04:34.0188 3196	TMachInfo - ok
15:04:34.0274 3196	TODDSrv         (ed32035bdfeced1ad66d459fd9cc1140) C:\Windows\system32\TODDSrv.exe
15:04:34.0292 3196	TODDSrv - ok
15:04:34.0384 3196	TosCoSrv        (4db8c79bcea76063b83b13410366a1f7) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
15:04:34.0406 3196	TosCoSrv - ok
15:04:34.0518 3196	TOSHIBA eco Utility Service (707800855afbd7648375efb1519b8d6d) C:\Program Files\TOSHIBA\TECO\TecoService.exe
15:04:34.0535 3196	TOSHIBA eco Utility Service - ok
15:04:34.0609 3196	TOSHIBA HDD SSD Alert Service (dd58e1250f604cbbadda04575e5e2376) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
15:04:34.0624 3196	TOSHIBA HDD SSD Alert Service - ok
15:04:34.0754 3196	tos_sps64       (09ff7b0b1b5c3d225495cb6f5a9b39f8) C:\Windows\system32\DRIVERS\tos_sps64.sys
15:04:34.0781 3196	tos_sps64 - ok
15:04:34.0858 3196	TPCHSrv         (de64c52bd0671165cf2eebf2a728a3e2) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
15:04:34.0888 3196	TPCHSrv - ok
15:04:34.0979 3196	TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
15:04:35.0047 3196	TrkWks - ok
15:04:35.0137 3196	TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
15:04:35.0173 3196	TrustedInstaller - ok
15:04:35.0272 3196	tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
15:04:35.0338 3196	tssecsrv - ok
15:04:35.0443 3196	tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
15:04:35.0516 3196	tunnel - ok
15:04:35.0643 3196	TVALZ           (550b567f9364d8f7684c3fb3ea665a72) C:\Windows\system32\DRIVERS\TVALZ_O.SYS
15:04:35.0656 3196	TVALZ - ok
15:04:35.0772 3196	TVALZFL         (9c7191f4b2e49bff47a6c1144b5923fa) C:\Windows\system32\DRIVERS\TVALZFL.sys
15:04:35.0784 3196	TVALZFL - ok
15:04:35.0886 3196	uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
15:04:35.0905 3196	uagp35 - ok
15:04:36.0008 3196	udfs            (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
15:04:36.0072 3196	udfs - ok
15:04:36.0168 3196	UI0Detect       (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
15:04:36.0206 3196	UI0Detect - ok
15:04:36.0310 3196	uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
15:04:36.0329 3196	uliagpkx - ok
15:04:36.0436 3196	umbus           (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
15:04:36.0470 3196	umbus - ok
15:04:36.0557 3196	UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
15:04:36.0576 3196	UmPass - ok
15:04:36.0676 3196	upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
15:04:36.0757 3196	upnphost - ok
15:04:36.0889 3196	USBAAPL64       (fb251567f41bc61988b26731dec19e4b) C:\Windows\system32\Drivers\usbaapl64.sys
15:04:36.0933 3196	USBAAPL64 - ok
15:04:37.0039 3196	usbccgp         (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
15:04:37.0083 3196	usbccgp - ok
15:04:37.0155 3196	USBCCID - ok
15:04:37.0280 3196	usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
15:04:37.0327 3196	usbcir - ok
15:04:37.0421 3196	usbehci         (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
15:04:37.0445 3196	usbehci - ok
15:04:37.0571 3196	usbhub          (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
15:04:37.0612 3196	usbhub - ok
15:04:37.0716 3196	usbohci         (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
15:04:37.0754 3196	usbohci - ok
15:04:37.0867 3196	usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
15:04:37.0912 3196	usbprint - ok
15:04:38.0016 3196	usbscan         (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
15:04:38.0044 3196	usbscan - ok
15:04:38.0158 3196	USBSTOR         (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
15:04:38.0216 3196	USBSTOR - ok
15:04:38.0320 3196	usbuhci         (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys
15:04:38.0358 3196	usbuhci - ok
15:04:38.0492 3196	usbvideo        (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys
15:04:38.0548 3196	usbvideo - ok
15:04:38.0642 3196	UxSms           (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
15:04:38.0689 3196	UxSms - ok
15:04:38.0797 3196	VaultSvc        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
15:04:38.0815 3196	VaultSvc - ok
15:04:38.0930 3196	vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
15:04:38.0946 3196	vdrvroot - ok
15:04:39.0028 3196	vds             (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
15:04:39.0082 3196	vds - ok
15:04:39.0197 3196	vga             (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
15:04:39.0225 3196	vga - ok
15:04:39.0323 3196	VgaSave         (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
15:04:39.0390 3196	VgaSave - ok
15:04:39.0492 3196	vhdmp           (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
15:04:39.0513 3196	vhdmp - ok
15:04:39.0605 3196	viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
15:04:39.0618 3196	viaide - ok
15:04:39.0713 3196	volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
15:04:39.0725 3196	volmgr - ok
15:04:39.0822 3196	volmgrx         (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
15:04:39.0850 3196	volmgrx - ok
15:04:39.0962 3196	volsnap         (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
15:04:39.0986 3196	volsnap - ok
15:04:40.0107 3196	vsmraid         (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
15:04:40.0130 3196	vsmraid - ok
15:04:40.0261 3196	VSS             (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
15:04:40.0317 3196	VSS - ok
15:04:40.0406 3196	vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
15:04:40.0433 3196	vwifibus - ok
15:04:40.0539 3196	vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
15:04:40.0583 3196	vwififlt - ok
15:04:40.0708 3196	vwifimp         (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
15:04:40.0736 3196	vwifimp - ok
15:04:40.0859 3196	W32Time         (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
15:04:40.0910 3196	W32Time - ok
15:04:41.0005 3196	WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
15:04:41.0041 3196	WacomPen - ok
15:04:41.0154 3196	WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
15:04:41.0222 3196	WANARP - ok
15:04:41.0265 3196	Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
15:04:41.0311 3196	Wanarpv6 - ok
15:04:41.0457 3196	WatAdminSvc     (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
15:04:41.0513 3196	WatAdminSvc - ok
15:04:41.0637 3196	wbengine        (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
15:04:41.0698 3196	wbengine - ok
15:04:41.0793 3196	WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
15:04:41.0819 3196	WbioSrvc - ok
15:04:41.0920 3196	wcncsvc         (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
15:04:41.0959 3196	wcncsvc - ok
15:04:42.0050 3196	WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
15:04:42.0084 3196	WcsPlugInService - ok
15:04:42.0194 3196	Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
15:04:42.0214 3196	Wd - ok
15:04:42.0328 3196	Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
15:04:42.0360 3196	Wdf01000 - ok
15:04:42.0451 3196	WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
15:04:42.0497 3196	WdiServiceHost - ok
15:04:42.0503 3196	WdiSystemHost   (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
15:04:42.0524 3196	WdiSystemHost - ok
15:04:42.0628 3196	WebClient       (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
15:04:42.0685 3196	WebClient - ok
15:04:42.0786 3196	Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
15:04:42.0840 3196	Wecsvc - ok
15:04:42.0933 3196	wercplsupport   (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
15:04:42.0989 3196	wercplsupport - ok
15:04:43.0092 3196	WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
15:04:43.0145 3196	WerSvc - ok
15:04:43.0257 3196	WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
15:04:43.0296 3196	WfpLwf - ok
15:04:43.0394 3196	WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
15:04:43.0407 3196	WIMMount - ok
15:04:43.0445 3196	WinDefend - ok
15:04:43.0455 3196	WinHttpAutoProxySvc - ok
15:04:43.0560 3196	Winmgmt         (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
15:04:43.0599 3196	Winmgmt - ok
15:04:43.0737 3196	WinRM           (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
15:04:43.0824 3196	WinRM - ok
15:04:43.0957 3196	WinUsb          (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
15:04:43.0998 3196	WinUsb - ok
15:04:44.0111 3196	Wlansvc         (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
15:04:44.0172 3196	Wlansvc - ok
15:04:44.0294 3196	wlcrasvc        (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
15:04:44.0310 3196	wlcrasvc - ok
15:04:44.0464 3196	wlidsvc         (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
15:04:44.0519 3196	wlidsvc - ok
15:04:44.0623 3196	WmiAcpi         (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
15:04:44.0650 3196	WmiAcpi - ok
15:04:44.0761 3196	wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
15:04:44.0801 3196	wmiApSrv - ok
15:04:44.0861 3196	WMPNetworkSvc - ok
15:04:44.0961 3196	WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
15:04:45.0000 3196	WPCSvc - ok
15:04:45.0096 3196	WPDBusEnum      (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
15:04:45.0136 3196	WPDBusEnum - ok
15:04:45.0231 3196	ws2ifsl         (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
15:04:45.0298 3196	ws2ifsl - ok
15:04:45.0411 3196	wscsvc          (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
15:04:45.0465 3196	wscsvc - ok
15:04:45.0535 3196	WSearch - ok
15:04:45.0626 3196	wuauserv        (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll
15:04:45.0706 3196	wuauserv - ok
15:04:45.0798 3196	WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
15:04:45.0865 3196	WudfPf - ok
15:04:45.0995 3196	WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
15:04:46.0054 3196	WUDFRd - ok
15:04:46.0151 3196	wudfsvc         (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
15:04:46.0212 3196	wudfsvc - ok
15:04:46.0308 3196	WwanSvc         (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
15:04:46.0343 3196	WwanSvc - ok
15:04:46.0399 3196	MBR (0x1B8)     (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
15:04:47.0294 3196	\Device\Harddisk0\DR0 - ok
15:04:47.0322 3196	Boot (0x1200)   (ce11b9c7e374e2bedac58b5561339d08) \Device\Harddisk0\DR0\Partition0
15:04:47.0324 3196	\Device\Harddisk0\DR0\Partition0 - ok
15:04:47.0344 3196	Boot (0x1200)   (8a294704b3c981353aabc814361bd7b8) \Device\Harddisk0\DR0\Partition1
15:04:47.0345 3196	\Device\Harddisk0\DR0\Partition1 - ok
15:04:47.0346 3196	============================================================
15:04:47.0346 3196	Scan finished
15:04:47.0346 3196	============================================================
15:04:47.0426 2832	Detected object count: 2
15:04:47.0426 2832	Actual detected object count: 2
15:16:05.0779 2832	PCSUService ( UnsignedFile.Multi.Generic ) - skipped by user
15:16:05.0779 2832	PCSUService ( UnsignedFile.Multi.Generic ) - User select action: Skip 
15:16:05.0782 2832	RalinkRegistryWriter ( UnsignedFile.Multi.Generic ) - skipped by user
15:16:05.0782 2832	RalinkRegistryWriter ( UnsignedFile.Multi.Generic ) - User select action: Skip
         

Alt 04.04.2012, 14:56   #20
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 04.04.2012, 22:40   #21
LaurenLaw
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Nachdem wieder irgendwann nichts mehr passierte und die Meldung wie aus dem Zitat von alleine auftauchte, habe ich den PC neu gestartet.

Das einzige was ich nun unter C:/Combofix finde ist das:

Code:
ATTFilter
 ComboFix 12-04-04.02 - Ms Lauren Law 04.04.2012  16:32:01.2.2 - x64
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.49.1031.18.3933.2596 [GMT 2:00]
ausgeführt von:: C:\Users\Ms Lauren Law\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))


C:\ProgramData\xp
C:\ProgramData\xp\EBLib.dll
C:\ProgramData\xp\TPwSav.sys
C:\Users\Ms Lauren Law\Documents\~WRD0000.tmp


(((((((((((((((((((((((   Dateien erstellt von 2012-03-04 bis 2012-04-04  ))))))))))))))))))))))))))))))
         

Alt 04.04.2012, 23:24   #22
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Starte Windows neu, lösch die alte combofix.exe, lade CF neu runter und probier es bitte nochmal.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 05.04.2012, 11:49   #23
LaurenLaw
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Super, nun hats geklappt:

Combofix Logfile:
Code:
ATTFilter
ComboFix 12-04-05.04 - Ms Lauren Law 05.04.2012  12:02:09.4.2 - x64
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.49.1031.18.3933.2664 [GMT 2:00]
ausgeführt von:: c:\users\Ms Lauren Law\Downloads\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-03-05 bis 2012-04-05  ))))))))))))))))))))))))))))))
.
.
2012-04-05 10:13 . 2012-04-05 10:13	--------	d-----w-	c:\users\Default\AppData\Local\temp
2012-04-03 23:15 . 2012-04-03 23:15	--------	d-----w-	c:\program files\iPod
2012-04-03 23:15 . 2012-04-03 23:16	--------	d-----w-	c:\program files\iTunes
2012-04-03 18:56 . 2012-04-03 18:56	--------	d-----w-	C:\_OTL
2012-04-03 17:31 . 2012-04-03 17:31	--------	d-----w-	c:\windows\system32\Macromed
2012-04-03 16:27 . 2012-03-14 03:27	8669240	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{037364A3-09BD-471B-8997-50310039AA89}\mpengine.dll
2012-04-02 14:56 . 2012-04-02 14:56	--------	d-----w-	c:\program files (x86)\ESET
2012-03-31 09:38 . 2012-03-31 09:38	--------	d-----w-	c:\users\Ms Lauren Law\AppData\Roaming\Malwarebytes
2012-03-31 09:38 . 2012-03-31 09:38	--------	d-----w-	c:\programdata\Malwarebytes
2012-03-31 09:38 . 2012-03-31 09:38	--------	d-----w-	c:\program files (x86)\Malwarebytes' Anti-Malware
2012-03-31 09:38 . 2011-12-10 13:24	23152	----a-w-	c:\windows\system32\drivers\mbam.sys
2012-03-15 02:02 . 2011-11-19 18:30	5504880	----a-w-	c:\windows\system32\ntoskrnl.exe
2012-03-15 02:02 . 2011-11-19 14:25	3957616	----a-w-	c:\windows\SysWow64\ntkrnlpa.exe
2012-03-15 02:02 . 2011-11-19 14:25	3902320	----a-w-	c:\windows\SysWow64\ntoskrnl.exe
2012-03-14 17:36 . 2012-02-03 04:16	3143168	----a-w-	c:\windows\system32\win32k.sys
2012-03-14 17:36 . 2012-02-10 06:18	1541120	----a-w-	c:\windows\system32\DWrite.dll
2012-03-14 17:36 . 2012-02-10 06:17	1837568	----a-w-	c:\windows\system32\d3d10warp.dll
2012-03-14 17:36 . 2012-02-10 06:17	320512	----a-w-	c:\windows\system32\d3d10_1core.dll
2012-03-14 17:36 . 2012-02-10 05:41	1074176	----a-w-	c:\windows\SysWow64\DWrite.dll
2012-03-14 17:36 . 2012-02-10 05:41	218624	----a-w-	c:\windows\SysWow64\d3d10_1core.dll
2012-03-14 17:36 . 2012-02-10 06:17	902656	----a-w-	c:\windows\system32\d2d1.dll
2012-03-14 17:36 . 2012-02-10 06:17	197120	----a-w-	c:\windows\system32\d3d10_1.dll
2012-03-14 17:36 . 2012-02-10 05:41	161792	----a-w-	c:\windows\SysWow64\d3d10_1.dll
2012-03-14 17:36 . 2012-02-10 05:41	1170944	----a-w-	c:\windows\SysWow64\d3d10warp.dll
2012-03-14 17:36 . 2012-02-10 05:41	739840	----a-w-	c:\windows\SysWow64\d2d1.dll
2012-03-14 15:40 . 2012-01-25 06:20	9216	----a-w-	c:\windows\system32\rdrmemptylst.exe
2012-03-14 15:40 . 2012-01-25 06:27	76288	----a-w-	c:\windows\system32\rdpwsx.dll
2012-03-14 15:40 . 2012-01-25 06:27	149504	----a-w-	c:\windows\system32\rdpcorekmts.dll
2012-03-14 15:40 . 2012-02-15 06:27	1031680	----a-w-	c:\windows\system32\rdpcore.dll
2012-03-14 15:40 . 2012-02-15 05:44	826368	----a-w-	c:\windows\SysWow64\rdpcore.dll
2012-03-14 15:40 . 2012-02-15 04:47	204800	----a-w-	c:\windows\system32\drivers\rdpwd.sys
2012-03-14 15:40 . 2012-02-15 04:46	23552	----a-w-	c:\windows\system32\drivers\tdtcp.sys
2012-03-10 17:37 . 2012-04-03 23:16	--------	d-----w-	c:\program files (x86)\iTunes
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-23 18:53 . 2012-02-23 18:53	86528	----a-w-	c:\windows\SysWow64\iesysprep.dll
2012-02-23 18:53 . 2012-02-23 18:53	76800	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe
2012-02-23 18:53 . 2012-02-23 18:53	74752	----a-w-	c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-02-23 18:53 . 2012-02-23 18:53	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll
2012-02-23 18:53 . 2012-02-23 18:53	161792	----a-w-	c:\windows\SysWow64\msls31.dll
2012-02-23 18:53 . 2012-02-23 18:53	110592	----a-w-	c:\windows\SysWow64\IEAdvpack.dll
2012-02-23 18:53 . 2012-02-23 18:53	91648	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2012-02-23 18:53 . 2012-02-23 18:53	89088	----a-w-	c:\windows\system32\RegisterIEPKEYs.exe
2012-02-23 18:53 . 2012-02-23 18:53	76800	----a-w-	c:\windows\system32\tdc.ocx
2012-02-23 18:53 . 2012-02-23 18:53	74752	----a-w-	c:\windows\SysWow64\iesetup.dll
2012-02-23 18:53 . 2012-02-23 18:53	63488	----a-w-	c:\windows\SysWow64\tdc.ocx
2012-02-23 18:53 . 2012-02-23 18:53	49664	----a-w-	c:\windows\system32\imgutil.dll
2012-02-23 18:53 . 2012-02-23 18:53	48640	----a-w-	c:\windows\system32\mshtmler.dll
2012-02-23 18:53 . 2012-02-23 18:53	448512	----a-w-	c:\windows\system32\html.iec
2012-02-23 18:53 . 2012-02-23 18:53	420864	----a-w-	c:\windows\SysWow64\vbscript.dll
2012-02-23 18:53 . 2012-02-23 18:53	367104	----a-w-	c:\windows\SysWow64\html.iec
2012-02-23 18:53 . 2012-02-23 18:53	35840	----a-w-	c:\windows\SysWow64\imgutil.dll
2012-02-23 18:53 . 2012-02-23 18:53	23552	----a-w-	c:\windows\SysWow64\licmgr10.dll
2012-02-23 18:53 . 2012-02-23 18:53	222208	----a-w-	c:\windows\system32\msls31.dll
2012-02-23 18:53 . 2012-02-23 18:53	173056	----a-w-	c:\windows\system32\ieUnatt.exe
2012-02-23 18:53 . 2012-02-23 18:53	152064	----a-w-	c:\windows\SysWow64\wextract.exe
2012-02-23 18:53 . 2012-02-23 18:53	150528	----a-w-	c:\windows\SysWow64\iexpress.exe
2012-02-23 18:53 . 2012-02-23 18:53	142848	----a-w-	c:\windows\SysWow64\ieUnatt.exe
2012-02-23 18:53 . 2012-02-23 18:53	135168	----a-w-	c:\windows\system32\IEAdvpack.dll
2012-02-23 18:53 . 2012-02-23 18:53	12288	----a-w-	c:\windows\system32\mshta.exe
2012-02-23 18:53 . 2012-02-23 18:53	11776	----a-w-	c:\windows\SysWow64\mshta.exe
2012-02-23 18:53 . 2012-02-23 18:53	114176	----a-w-	c:\windows\system32\admparse.dll
2012-02-23 18:53 . 2012-02-23 18:53	111616	----a-w-	c:\windows\system32\iesysprep.dll
2012-02-23 18:53 . 2012-02-23 18:53	101888	----a-w-	c:\windows\SysWow64\admparse.dll
2012-02-23 18:53 . 2012-02-23 18:53	85504	----a-w-	c:\windows\system32\iesetup.dll
2012-02-23 18:53 . 2012-02-23 18:53	603648	----a-w-	c:\windows\system32\vbscript.dll
2012-02-23 18:53 . 2012-02-23 18:53	30720	----a-w-	c:\windows\system32\licmgr10.dll
2012-02-23 18:53 . 2012-02-23 18:53	165888	----a-w-	c:\windows\system32\iexpress.exe
2012-02-23 18:53 . 2012-02-23 18:53	160256	----a-w-	c:\windows\system32\wextract.exe
2012-02-23 08:18 . 2011-02-24 18:12	279656	------w-	c:\windows\system32\MpSigStub.exe
2012-02-15 10:01 . 2012-02-15 10:01	52736	----a-w-	c:\windows\system32\drivers\usbaapl64.sys
2012-02-15 10:01 . 2012-02-15 10:01	4547944	----a-w-	c:\windows\system32\usbaaplrc.dll
2012-01-23 10:43 . 2012-01-30 14:58	56928	----a-w-	c:\windows\system32\pxc40pm.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-08 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2009-08-12 352256]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 423936]
"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-01-13 34088]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-08-17 1294136]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-11-05 281768]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-09-27 59240]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe" [2009-08-12 6203296]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Sitecom Wireless Utility.lnk - c:\program files (x86)\Sitecom\Common\RaUI.exe [2010-6-12 1773568]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages	REG_MULTI_SZ   	kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
R3 netr28ux;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28ux.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-27 136360]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2009-08-10 248688]
S2 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2009-07-14 42368]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
S2 PCSUService;PC Speed Up Service;c:\program files (x86)\PC Beschleunigen\PCSUService.exe [2011-07-20 206336]
S2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2009-08-06 116104]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-08-27 251760]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-03 137560]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-04 826224]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2012-04-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 23:26]
.
2012-04-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 23:26]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-03 709976]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2009-08-06 1050000]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-02 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-02 387608]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-02 365592]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-28 7982112]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2009-07-30 134032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEH&bmod=TSEH
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube to iPod Converter - c:\users\Ms Lauren Law\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 213.191.74.18 62.109.123.196
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
AddRemove-Uninstall_is1 - c:\program files (x86)\Common Files\DVDVideoSoft\unins000.exe
AddRemove-3988386017.www.pcspeedup.com - c:\program files (x86)\Microsoft Silverlight\4.0.60531.0\Silverlight.Configuration.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-806744476-1919467886-1915298580-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-806744476-1919467886-1915298580-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Sitecom\Common\RegistryWriter.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-04-05  12:42:20 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-04-05 10:42
.
Vor Suchlauf: 15 Verzeichnis(se), 87.391.416.320 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 87.008.587.776 Bytes frei
.
- - End Of File - - 0352AD34C668AFD0B07EB3AB1702136B
         
--- --- ---

Alt 05.04.2012, 13:41   #24
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!
  • Starte die aswMBR.exe Vista und Win7 User aswMBR per Rechtsklick "als Administrator ausführen"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr", dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 05.04.2012, 15:37   #25
LaurenLaw
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Code:
ATTFilter
 aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-04-05 16:31:43
-----------------------------
16:31:43.963    OS Version: Windows x64 6.1.7600 
16:31:43.963    Number of processors: 2 586 0x170A
16:31:43.965    ComputerName: MSLAURENLAW  UserName: 
16:31:44.592    Initialize success
16:32:10.231    AVAST engine download error: 0
16:32:29.876    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
16:32:29.880    Disk 0 Vendor: TOSHIBA_ GC00 Size: 305245MB BusType: 3
16:32:29.924    Disk 0 MBR read successfully
16:32:29.929    Disk 0 MBR scan
16:32:29.934    Disk 0 Windows 7 default MBR code
16:32:29.949    Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS          400 MB offset 2048
16:32:29.959    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       152622 MB offset 821248
16:32:29.980    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       152222 MB offset 313391104
16:32:30.018    Disk 0 scanning C:\Windows\system32\drivers
16:32:37.123    Service scanning
16:33:14.141    Modules scanning
16:33:14.155    Disk 0 trace - called modules:
16:33:14.163    
16:33:14.504    Scan finished successfully
16:34:14.744    Disk 0 MBR has been saved successfully to "C:\Users\Ms Lauren Law\Desktop\MBR.dat"
16:34:14.750    The log file has been saved successfully to "C:\Users\Ms Lauren Law\Desktop\aswMBR.txt"
         

Alt 05.04.2012, 16:57   #26
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 06.04.2012, 19:18   #27
LaurenLaw
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Code:
ATTFilter
 SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 04/06/2012 at 08:11 PM

Application Version : 5.0.1146

Core Rules Database Version : 8424
Trace Rules Database Version: 6236

Scan type       : Complete Scan
Total Scan Time : 02:08:48

Operating System Information
Windows 7 Home Premium 64-bit (Build 6.01.7600)
UAC On - Administrator

Memory items scanned      : 707
Memory threats detected   : 0
Registry items scanned    : 66352
Registry threats detected : 0
File items scanned        : 179944
File threats detected     : 642

Adware.Tracking Cookie
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@112.2o7[1].txt [ /112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@2.bfugmedia[1].txt [ /2.bfugmedia ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@247realmedia[2].txt [ /247realmedia ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@a.revenuemax[1].txt [ /a.revenuemax ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@account.live[2].txt [ /account.live ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@aco.solution.weborama[2].txt [ /aco.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.360yield[1].txt [ /ad.360yield ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.adition[1].txt [ /ad.adition ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.adnet[2].txt [ /ad.adnet ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.allvoices[1].txt [ /ad.allvoices ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.beepworld[2].txt [ /ad.beepworld ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.dyntracker[1].txt [ /ad.dyntracker ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.dyntracker[2].txt [ /ad.dyntracker ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.leadbolt[1].txt [ /ad.leadbolt ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.reklamport[2].txt [ /ad.reklamport ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.wsod[2].txt [ /ad.wsod ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.youporn.videobox[1].txt [ /ad.youporn.videobox ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad1.adfarm.adtelligence[2].txt [ /ad1.adfarm.adtelligence ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad2.adfarm1.adition[1].txt [ /ad2.adfarm1.adition ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad5.adfarm1.adition[2].txt [ /ad5.adfarm1.adition ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad6media[1].txt [ /ad6media ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adbrite[1].txt [ /adbrite ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adcentriconline[2].txt [ /adcentriconline ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adinterax[2].txt [ /adinterax ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.ad4game[2].txt [ /ads.ad4game ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.adk2[2].txt [ /ads.adk2 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.carpooling[1].txt [ /ads.carpooling ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.cinemaden[1].txt [ /ads.cinemaden ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.clicmanager[1].txt [ /ads.clicmanager ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.cosmotourist[2].txt [ /ads.cosmotourist ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.cpxadroit[2].txt [ /ads.cpxadroit ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.e-planning[1].txt [ /ads.e-planning ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.fling[1].txt [ /ads.fling ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.horyzon-media[2].txt [ /ads.horyzon-media ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.iadmanager[2].txt [ /ads.iadmanager ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.immobilienscout24[1].txt [ /ads.immobilienscout24 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.lzjl[2].txt [ /ads.lzjl ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.medienhaus[1].txt [ /ads.medienhaus ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.mikinimedia[2].txt [ /ads.mikinimedia ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.mitfahrzentrale[1].txt [ /ads.mitfahrzentrale ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.moveco[1].txt [ /ads.moveco ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.moviease[1].txt [ /ads.moviease ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.pointroll[1].txt [ /ads.pointroll ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.quartermedia[2].txt [ /ads.quartermedia ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.sportwerk[1].txt [ /ads.sportwerk ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.startseiten24[1].txt [ /ads.startseiten24 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.traffikings[1].txt [ /ads.traffikings ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.travel-overland[1].txt [ /ads.travel-overland ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.undertone[2].txt [ /ads.undertone ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.us.e-planning[1].txt [ /ads.us.e-planning ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.youporn[2].txt [ /ads.youporn ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.zeusclicks[1].txt [ /ads.zeusclicks ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads2.zeusclicks[1].txt [ /ads2.zeusclicks ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads20.wwe-media[2].txt [ /ads20.wwe-media ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads5.netpublisher[2].txt [ /ads5.netpublisher ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserv.quality-channel[2].txt [ /adserv.quality-channel ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.adreactor[1].txt [ /adserver.adreactor ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.adtechus[1].txt [ /adserver.adtechus ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.kino-zeit[1].txt [ /adserver.kino-zeit ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.mitfahrzentrale[2].txt [ /adserver.mitfahrzentrale ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.tattooscout[1].txt [ /adserver.tattooscout ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.webmasterbond[1].txt [ /adserver.webmasterbond ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.yopi[1].txt [ /adserver.yopi ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver2.clipkit[1].txt [ /adserver2.clipkit ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver2.traffictrack[2].txt [ /adserver2.traffictrack ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserving.versaneeds[1].txt [ /adserving.versaneeds ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adsrv.admediate[2].txt [ /adsrv.admediate ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adsrv1.admediate[1].txt [ /adsrv1.admediate ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adtech[1].txt [ /adtech ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@advertising[2].txt [ /advertising ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@advertstream[1].txt [ /advertstream ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adx.chip[2].txt [ /adx.chip ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adxpansion[2].txt [ /adxpansion ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adxpose[1].txt [ /adxpose ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@aidacruises.122.2o7[1].txt [ /aidacruises.122.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@aimfar.solution.weborama[1].txt [ /aimfar.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@albumprinter.122.2o7[1].txt [ /albumprinter.122.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@apmebf[1].txt [ /apmebf ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@apodiscounter[1].txt [ /apodiscounter ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@atdmt.combing[1].txt [ /atdmt.combing ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@autoscout24.112.2o7[1].txt [ /autoscout24.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@banner.testberichte[1].txt [ /banner.testberichte ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@banquepopulaire2010.solution.weborama[2].txt [ /banquepopulaire2010.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@baseco.solution.weborama[2].txt [ /baseco.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@bizrate[1].txt [ /bizrate ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@bluestreak[2].txt [ /bluestreak ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@bnpparibasnet.solution.weborama[2].txt [ /bnpparibasnet.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@bs.serving-sys[2].txt [ /bs.serving-sys ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@burstnet[2].txt [ /burstnet ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@cdn5.specificclick[1].txt [ /cdn5.specificclick ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@cheaptickets.122.2o7[1].txt [ /cheaptickets.122.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@clickbank[1].txt [ /clickbank ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@clicks.pangora[1].txt [ /clicks.pangora ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@clicksor[1].txt [ /clicksor ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@cngg-stats.condenastdigital[1].txt [ /cngg-stats.condenastdigital ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@cofidis2.solution.weborama[2].txt [ /cofidis2.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@content.yieldmanager[3].txt [ /content.yieldmanager ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@count.rbc[1].txt [ /count.rbc ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@countomat[1].txt [ /countomat ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@cunda.122.2o7[1].txt [ /cunda.122.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@dealtime[1].txt [ /dealtime ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@deutschepostag.112.2o7[1].txt [ /deutschepostag.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@directtrack[1].txt [ /directtrack ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@discounter-in-deutschland[2].txt [ /discounter-in-deutschland ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@dmtracker[1].txt [ /dmtracker ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ds.clickexperts[1].txt [ /ds.clickexperts ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@dztadserver.dx-work[2].txt [ /dztadserver.dx-work ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6aekiogazmko.stats.esomniture[2].txt [ /e-2dj6aekiogazmko.stats.esomniture ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6aekyghcjsep.stats.esomniture[2].txt [ /e-2dj6aekyghcjsep.stats.esomniture ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6aeliakdjsco.stats.esomniture[2].txt [ /e-2dj6aeliakdjsco.stats.esomniture ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6wbliwgd5olo.stats.esomniture[2].txt [ /e-2dj6wbliwgd5olo.stats.esomniture ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6wcliwoc5chp.stats.esomniture[2].txt [ /e-2dj6wcliwoc5chp.stats.esomniture ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6whkowiczmdp.stats.esomniture[1].txt [ /e-2dj6whkowiczmdp.stats.esomniture ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6wjlyahd5glp.stats.esomniture[2].txt [ /e-2dj6wjlyahd5glp.stats.esomniture ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6wmk4omd5iep.stats.esomniture[2].txt [ /e-2dj6wmk4omd5iep.stats.esomniture ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6wnmyeidzgeo.stats.esomniture[2].txt [ /e-2dj6wnmyeidzgeo.stats.esomniture ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@eaeacom.112.2o7[1].txt [ /eaeacom.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@eas4.emediate[1].txt [ /eas4.emediate ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@elitepartner.tt.omtrdc[2].txt [ /elitepartner.tt.omtrdc ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@elitepartner[1].txt [ /elitepartner ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ero-advertising[2].txt [ /ero-advertising ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@eyewonder[2].txt [ /eyewonder ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@fl01.ct2.comclick[2].txt [ /fl01.ct2.comclick ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@frontlinegmbh.122.2o7[1].txt [ /frontlinegmbh.122.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@gemey2011.solution.weborama[2].txt [ /gemey2011.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@germanwings.112.2o7[1].txt [ /germanwings.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@girlsteachsex[2].txt [ /girlsteachsex ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@gostats[1].txt [ /gostats ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@gotacha.rotator.hadj7.adjuggler[1].txt [ /gotacha.rotator.hadj7.adjuggler ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@gotacha.rotator.hadj7.adjuggler[2].txt [ /gotacha.rotator.hadj7.adjuggler ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@guj.122.2o7[1].txt [ /guj.122.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@hansenet.122.2o7[1].txt [ /hansenet.122.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@harrenmedianetwork[1].txt [ /harrenmedianetwork ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@himedia.individuad[1].txt [ /himedia.individuad ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@horyzon-media[1].txt [ /horyzon-media ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ice.112.2o7[1].txt [ /ice.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@idtgv.solution.weborama[2].txt [ /idtgv.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@imrworldwide[2].txt [ /imrworldwide ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@indigio.122.2o7[1].txt [ /indigio.122.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@interclick[1].txt [ /interclick ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@intersportmontagne.solution.weborama[2].txt [ /intersportmontagne.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@jsfp.coremetrics[2].txt [ /jsfp.coremetrics ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@komtrack[1].txt [ /komtrack ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@komtrack[2].txt [ /komtrack ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@kontera[1].txt [ /kontera ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@legolas-media[1].txt [ /legolas-media ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@lfstmedia[1].txt [ /lfstmedia ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@liveperson[1].txt [ /liveperson ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@liveperson[2].txt [ /liveperson ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@liveperson[3].txt [ /liveperson ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@liveperson[5].txt [ /liveperson ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@loralparis2011.solution.weborama[2].txt [ /loralparis2011.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@lstat.youku[1].txt [ /lstat.youku ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@media.photobucket[1].txt [ /media.photobucket ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@media2.legacy[1].txt [ /media2.legacy ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@media6degrees[2].txt [ /media6degrees ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@mediafire[1].txt [ /mediafire ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@mediaforge[1].txt [ /mediaforge ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@mediastay.directtrack[2].txt [ /mediastay.directtrack ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@metroleap.rotator.hadj7.adjuggler[2].txt [ /metroleap.rotator.hadj7.adjuggler ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@microsoftinternetexplorer.112.2o7[1].txt [ /microsoftinternetexplorer.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@microsoftmachinetranslation.112.2o7[1].txt [ /microsoftmachinetranslation.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@microsoftwlsearchcrm.112.2o7[1].txt [ /microsoftwlsearchcrm.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@mm.chitika[1].txt [ /mm.chitika ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@monoprix.solution.weborama[2].txt [ /monoprix.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@msnportal.112.2o7[1].txt [ /msnportal.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@naked[1].txt [ /naked ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@nedstat.hostelbookers[1].txt [ /nedstat.hostelbookers ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@nedstat.hostelbookers[2].txt [ /nedstat.hostelbookers ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@nedstat.hostelbookers[3].txt [ /nedstat.hostelbookers ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@nextag[1].txt [ /nextag ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@nike.112.2o7[1].txt [ /nike.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@overture[1].txt [ /overture ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@parship.122.2o7[1].txt [ /parship.122.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@partypoker[3].txt [ /partypoker ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@paypal.112.2o7[1].txt [ /paypal.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@pluckit.demandmedia[1].txt [ /pluckit.demandmedia ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@pmu3.solution.weborama[2].txt [ /pmu3.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@pointroll[2].txt [ /pointroll ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@pornhub[2].txt [ /pornhub ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@pornme[2].txt [ /pornme ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@realmedia[2].txt [ /realmedia ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@revenue[2].txt [ /revenue ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@revsci[1].txt [ /revsci ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@rgadvert[2].txt [ /rgadvert ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@roitracking[1].txt [ /roitracking ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@rotator.adjuggler[1].txt [ /rotator.adjuggler ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ru4[1].txt [ /ru4 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@secmedia[2].txt [ /secmedia ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@server.cpmstar[2].txt [ /server.cpmstar ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@server.iad.liveperson[1].txt [ /server.iad.liveperson ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@server.lon.liveperson[1].txt [ /server.lon.liveperson ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@sevenoneintermedia.112.2o7[1].txt [ /sevenoneintermedia.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@sfr.solution.weborama[2].txt [ /sfr.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@snapfish.112.2o7[1].txt [ /snapfish.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@specificclick[1].txt [ /specificclick ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@start.elitepartner[2].txt [ /start.elitepartner ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stat.culturebase[1].txt [ /stat.culturebase ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stat.dealtime[1].txt [ /stat.dealtime ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stat.heimat[2].txt [ /stat.heimat ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stat.onestat[2].txt [ /stat.onestat ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stat.youku[1].txt [ /stat.youku ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@statcounter[1].txt [ /statcounter ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stats.d-p-h[1].txt [ /stats.d-p-h ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stats.paypal[2].txt [ /stats.paypal ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stats.yetanotherblog[1].txt [ /stats.yetanotherblog ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@statsadv.dadapro[1].txt [ /statsadv.dadapro ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@supremeadserver[2].txt [ /supremeadserver ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tacoda.at.atwola[2].txt [ /tacoda.at.atwola ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tele2de.112.2o7[1].txt [ /tele2de.112.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tns-counter[1].txt [ /tns-counter ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@toyota2.solution.weborama[2].txt [ /toyota2.solution.weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@track.effiliation[1].txt [ /track.effiliation ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@track.webtrekk[1].txt [ /track.webtrekk ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@track.webtrekk[2].txt [ /track.webtrekk ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.3gnet[1].txt [ /tracking.3gnet ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.affiliaxe[2].txt [ /tracking.affiliaxe ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.bmbfcluster[1].txt [ /tracking.bmbfcluster ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.dc-storm[1].txt [ /tracking.dc-storm ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.ejoni[1].txt [ /tracking.ejoni ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.hannoversche[1].txt [ /tracking.hannoversche ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.inuvo[2].txt [ /tracking.inuvo ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.publicidees[1].txt [ /tracking.publicidees ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.star-advertising[2].txt [ /tracking.star-advertising ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.tchibo[1].txt [ /tracking.tchibo ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.veille-referencement[2].txt [ /tracking.veille-referencement ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tradedoubler[1].txt [ /tradedoubler ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@trafficmp[1].txt [ /trafficmp ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@traveladvertising[1].txt [ /traveladvertising ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tto2.traffictrack[2].txt [ /tto2.traffictrack ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@uk.at.atwola[1].txt [ /uk.at.atwola ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@usenext.122.2o7[1].txt [ /usenext.122.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@viacom.adbureau[2].txt [ /viacom.adbureau ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@videoegg.adbureau[1].txt [ /videoegg.adbureau ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@vinvest.122.2o7[1].txt [ /vinvest.122.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@vodafonegroup.122.2o7[1].txt [ /vodafonegroup.122.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@weborama[1].txt [ /weborama ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@wissende.122.2o7[1].txt [ /wissende.122.2o7 ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ww381.smartadserver[2].txt [ /ww381.smartadserver ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.active-tracking[2].txt [ /www.active-tracking ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.advertonic[2].txt [ /www.advertonic ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.bigtracker[1].txt [ /www.bigtracker ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.burstnet[2].txt [ /www.burstnet ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.elitepartner[2].txt [ /www.elitepartner ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[10].txt [ /www.googleadservices ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[11].txt [ /www.googleadservices ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[1].txt [ /www.googleadservices ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[3].txt [ /www.googleadservices ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[5].txt [ /www.googleadservices ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[6].txt [ /www.googleadservices ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[7].txt [ /www.googleadservices ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[8].txt [ /www.googleadservices ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[9].txt [ /www.googleadservices ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.messengerdusexe[1].txt [ /www.messengerdusexe ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.pornhub[1].txt [ /www.pornhub ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.traffic2drive[1].txt [ /www.traffic2drive ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.yuoporn[1].txt [ /www.yuoporn ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www3.smartadserver[2].txt [ /www3.smartadserver ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@xiti[1].txt [ /xiti ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@xm.xtendmedia[2].txt [ /xm.xtendmedia ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@yadro[2].txt [ /yadro ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@yieldmanager[1].txt [ /yieldmanager ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@youporn.videobox[1].txt [ /youporn.videobox ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@youporne[1].txt [ /youporne ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@youporn[2].txt [ /youporn ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@zbox.zanox[1].txt [ /zbox.zanox ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\1VL01HFJ.txt [ /tracking.quisma.com ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\Q0H56MWF.txt [ /fastclick.net ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\M7FFZQK4.txt [ /youporn.com ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\T1U0HIZC.txt [ /mediaplex.com ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\JO5SKGAC.txt [ /de.partypoker.com ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\42R09K1H.txt [ /doubleclick.net ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\IV9WQBJM.txt [ /www.youporn.com ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\IBWMCMCU.txt [ /www.usenext.de ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\024Q7JNZ.txt [ /apmebf.com ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\8UC650DI.txt [ /partypoker.com ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\X93X1RIP.txt [ /zanox.com ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ZVPP3UXE.txt [ /forum.usenext.de ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\DJXPEQR3.txt [ /oracle.112.2o7.net ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\GW63R3PI.txt [ /usenext.de ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\NYRKDB5B.txt [ /smartadserver.com ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\B0YAUVSD.txt [ /ad.adc-serv.net ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\QJOIKU4L.txt [ /counter.hitslink.com ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\SUVW7D4B.txt [ /rts.pgmediaserve.com ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\Q7CFTT4D.txt [ /exoclick.com ]
	C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\0OHRAM65.txt [ /www.usenext.com ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@imrworldwide[2].txt [ Cookie:ms lauren law@imrworldwide.com/cgi-bin ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\R85HYIYM.txt [ Cookie:ms lauren law@fastclick.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads.quartermedia[2].txt [ Cookie:ms lauren law@ads.quartermedia.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\BQPTFBRZ.txt [ Cookie:ms lauren law@youporn.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@media6degrees[2].txt [ Cookie:ms lauren law@media6degrees.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@snapfish.112.2o7[1].txt [ Cookie:ms lauren law@snapfish.112.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@msnportal.112.2o7[1].txt [ Cookie:ms lauren law@msnportal.112.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\C0GUQR46.txt [ Cookie:ms lauren law@traffictrack.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\KNL64NFX.txt [ Cookie:ms lauren law@track.effiliation.com/servlet/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@bluestreak[2].txt [ Cookie:ms lauren law@bluestreak.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.pornhub[1].txt [ Cookie:ms lauren law@www.pornhub.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\JQLL3UFZ.txt [ Cookie:ms lauren law@eas.apm.emediate.eu/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\NG3PFQER.txt [ Cookie:ms lauren law@atdmt.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@intersportmontagne.solution.weborama[2].txt [ Cookie:ms lauren law@intersportmontagne.solution.weborama.fr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@countomat[1].txt [ Cookie:ms lauren law@countomat.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\BKYV9O33.txt [ Cookie:ms lauren law@doubleclick.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@eyewonder[2].txt [ Cookie:ms lauren law@eyewonder.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@paypal.112.2o7[1].txt [ Cookie:ms lauren law@paypal.112.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@autoscout24.112.2o7[1].txt [ Cookie:ms lauren law@autoscout24.112.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@eaeacom.112.2o7[1].txt [ Cookie:ms lauren law@eaeacom.112.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@guj.122.2o7[1].txt [ Cookie:ms lauren law@guj.122.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@lfstmedia[1].txt [ Cookie:ms lauren law@lfstmedia.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\VDDK7NVB.txt [ Cookie:ms lauren law@adviva.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\A7A27Y33.txt [ Cookie:ms lauren law@tradedoubler.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@track.effiliation[1].txt [ Cookie:ms lauren law@track.effiliation.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@xiti[1].txt [ Cookie:ms lauren law@xiti.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@apmebf[1].txt [ Cookie:ms lauren law@apmebf.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads.youporn[2].txt [ Cookie:ms lauren law@ads.youporn.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\JACEA0WE.txt [ Cookie:ms lauren law@bs.serving-sys.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\A1JT2B8K.txt [ Cookie:ms lauren law@zanox.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\42H9H0PO.txt [ Cookie:ms lauren law@partypoker.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@xm.xtendmedia[2].txt [ Cookie:ms lauren law@xm.xtendmedia.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@youporn[2].txt [ Cookie:ms lauren law@youporn.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\162AKRQ7.txt [ Cookie:ms lauren law@casalemedia.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\DX9DU1RR.txt [ Cookie:ms lauren law@questionmarket.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adserver.adtechus[1].txt [ Cookie:ms lauren law@adserver.adtechus.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\RA6YD216.txt [ Cookie:ms lauren law@www.zanox-affiliate.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[2].txt [ Cookie:ms lauren law@de.sitestat.com/karstadt-de/karstadt/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@statcounter[1].txt [ Cookie:ms lauren law@statcounter.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZCNFOIJT.txt [ Cookie:ms lauren law@www.etracker.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\IYYHY7PA.txt [ Cookie:ms lauren law@tracking.mindshare.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@traveladvertising[1].txt [ Cookie:ms lauren law@traveladvertising.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@247realmedia[2].txt [ Cookie:ms lauren law@247realmedia.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\R1RTLESE.txt [ Cookie:ms lauren law@smartadserver.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\PWICDX3M.txt [ Cookie:ms lauren law@adtech.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@revenue[2].txt [ Cookie:ms lauren law@revenue.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@2.bfugmedia[1].txt [ Cookie:ms lauren law@2.bfugmedia.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\TDKV0JRL.txt [ Cookie:ms lauren law@adultfriendfinder.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@youporn.videobox[1].txt [ Cookie:ms lauren law@youporn.videobox.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\XZOS6U6N.txt [ Cookie:ms lauren law@2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.elitepartner[2].txt [ Cookie:ms lauren law@www.elitepartner.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ru4[1].txt [ Cookie:ms lauren law@ru4.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@hansenet.122.2o7[1].txt [ Cookie:ms lauren law@hansenet.122.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.burstnet[2].txt [ Cookie:ms lauren law@www.burstnet.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@lstat.youku[1].txt [ Cookie:ms lauren law@lstat.youku.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@nedstat.hostelbookers[3].txt [ Cookie:ms lauren law@nedstat.hostelbookers.com/hb/de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[1].txt [ Cookie:ms lauren law@de.sitestat.com/is24-mail/is24-mail/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\IQZ4P2O5.txt [ Cookie:ms lauren law@ad3.adfarm1.adition.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tns-counter[1].txt [ Cookie:ms lauren law@tns-counter.ru/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.hannoversche[1].txt [ Cookie:ms lauren law@tracking.hannoversche.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@wissende.122.2o7[1].txt [ Cookie:ms lauren law@wissende.122.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\U55NOPYI.txt [ Cookie:ms lauren law@revsci.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[3].txt [ Cookie:ms lauren law@de.sitestat.com/karstadt-de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@rotator.adjuggler[1].txt [ Cookie:ms lauren law@rotator.adjuggler.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@uk.at.atwola[1].txt [ Cookie:ms lauren law@uk.at.atwola.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@himedia.individuad[1].txt [ Cookie:ms lauren law@himedia.individuad.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ad.adition[1].txt [ Cookie:ms lauren law@ad.adition.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@videoegg.adbureau[1].txt [ Cookie:ms lauren law@videoegg.adbureau.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZZVQ1G1I.txt [ Cookie:ms lauren law@ads.crakmedia.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adserver2.traffictrack[2].txt [ Cookie:ms lauren law@adserver2.traffictrack.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@jsfp.coremetrics[2].txt [ Cookie:ms lauren law@jsfp.coremetrics.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\3AGWQY0F.txt [ Cookie:ms lauren law@collective-media.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ad.adnet[2].txt [ Cookie:ms lauren law@ad.adnet.biz/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ero-advertising[2].txt [ Cookie:ms lauren law@ero-advertising.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\G6OWCP1O.txt [ Cookie:ms lauren law@adx.chip.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.yuoporn[1].txt [ Cookie:ms lauren law@www.yuoporn.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@apodiscounter[1].txt [ Cookie:ms lauren law@apodiscounter.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads20.wwe-media[2].txt [ Cookie:ms lauren law@ads20.wwe-media.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ad5.adfarm1.adition[2].txt [ Cookie:ms lauren law@ad5.adfarm1.adition.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@burstnet[2].txt [ Cookie:ms lauren law@burstnet.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adbrite[1].txt [ Cookie:ms lauren law@adbrite.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@cunda.122.2o7[1].txt [ Cookie:ms lauren law@cunda.122.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@fl01.ct2.comclick[2].txt [ Cookie:ms lauren law@fl01.ct2.comclick.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adserver.kino-zeit[1].txt [ Cookie:ms lauren law@adserver.kino-zeit.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\1I86LBXG.txt [ Cookie:ms lauren law@ad2.adfarm1.adition.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\FGS448NP.txt [ Cookie:ms lauren law@statse.webtrendslive.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@microsoftmachinetranslation.112.2o7[1].txt [ Cookie:ms lauren law@microsoftmachinetranslation.112.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.inuvo[2].txt [ Cookie:ms lauren law@tracking.inuvo.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@mediafire[1].txt [ Cookie:ms lauren law@mediafire.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ice.112.2o7[1].txt [ Cookie:ms lauren law@ice.112.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\Z3OHBIDK.txt [ Cookie:ms lauren law@ad.adnet.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\6X0ZG97B.txt [ Cookie:ms lauren law@tribalfusion.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@komtrack[2].txt [ Cookie:ms lauren law@komtrack.com/tr/869350 ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@track.webtrekk[1].txt [ Cookie:ms lauren law@track.webtrekk.de/562243648792138/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@roitracking[1].txt [ Cookie:ms lauren law@roitracking.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@clicksor[1].txt [ Cookie:ms lauren law@clicksor.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\1451A7YO.txt [ Cookie:ms lauren law@unitymedia.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\7TQZMBV7.txt [ Cookie:ms lauren law@im.banner.t-online.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@overture[1].txt [ Cookie:ms lauren law@overture.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@advertising[2].txt [ Cookie:ms lauren law@advertising.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@aidacruises.122.2o7[1].txt [ Cookie:ms lauren law@aidacruises.122.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\8O676AKJ.txt [ Cookie:ms lauren law@adform.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@nike.112.2o7[1].txt [ Cookie:ms lauren law@nike.112.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@statsadv.dadapro[1].txt [ Cookie:ms lauren law@statsadv.dadapro.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@loralparis2011.solution.weborama[2].txt [ Cookie:ms lauren law@loralparis2011.solution.weborama.fr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adserver.tattooscout[1].txt [ Cookie:ms lauren law@adserver.tattooscout.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@count.rbc[1].txt [ Cookie:ms lauren law@count.rbc.ru/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@stat.onestat[2].txt [ Cookie:ms lauren law@stat.onestat.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@sevenoneintermedia.112.2o7[1].txt [ Cookie:ms lauren law@sevenoneintermedia.112.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\OD5A8HT5.txt [ Cookie:ms lauren law@studivz.adfarm1.adition.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\W3VLYTNE.txt [ Cookie:ms lauren law@de.partypoker.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@in.mydirtyhobby[2].txt [ Cookie:ms lauren law@in.mydirtyhobby.com/track/vZIPADkU,33/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@komtrack[1].txt [ Cookie:ms lauren law@komtrack.com/tr ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\JXEGQGL0.txt [ Cookie:ms lauren law@ad4.adfarm1.adition.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@idtgv.solution.weborama[2].txt [ Cookie:ms lauren law@idtgv.solution.weborama.fr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@e-2dj6wnmyeidzgeo.stats.esomniture[2].txt [ Cookie:ms lauren law@e-2dj6wnmyeidzgeo.stats.esomniture.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\4S9ZZME9.txt [ Cookie:ms lauren law@www.google.com/accounts ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adinterax[2].txt [ Cookie:ms lauren law@adinterax.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@e-2dj6aekiogazmko.stats.esomniture[2].txt [ Cookie:ms lauren law@e-2dj6aekiogazmko.stats.esomniture.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@e-2dj6aeliakdjsco.stats.esomniture[2].txt [ Cookie:ms lauren law@e-2dj6aeliakdjsco.stats.esomniture.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@stat.dealtime[1].txt [ Cookie:ms lauren law@stat.dealtime.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.ejoni[1].txt [ Cookie:ms lauren law@tracking.ejoni.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@secmedia[2].txt [ Cookie:ms lauren law@secmedia.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads.pointroll[1].txt [ Cookie:ms lauren law@ads.pointroll.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.bigtracker[1].txt [ Cookie:ms lauren law@www.bigtracker.de/piwik/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\JP7KJ3IW.txt [ Cookie:ms lauren law@www.youporn.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ds.clickexperts[1].txt [ Cookie:ms lauren law@ds.clickexperts.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@yieldmanager[1].txt [ Cookie:ms lauren law@yieldmanager.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adxpose[1].txt [ Cookie:ms lauren law@adxpose.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@vinvest.122.2o7[1].txt [ Cookie:ms lauren law@vinvest.122.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@baseco.solution.weborama[2].txt [ Cookie:ms lauren law@baseco.solution.weborama.fr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@indigio.122.2o7[1].txt [ Cookie:ms lauren law@indigio.122.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@sfr.solution.weborama[2].txt [ Cookie:ms lauren law@sfr.solution.weborama.fr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@stat.youku[1].txt [ Cookie:ms lauren law@stat.youku.com/player/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@kontera[1].txt [ Cookie:ms lauren law@kontera.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@liveperson[1].txt [ Cookie:ms lauren law@liveperson.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@clicks.pangora[1].txt [ Cookie:ms lauren law@clicks.pangora.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@media2.legacy[1].txt [ Cookie:ms lauren law@media2.legacy.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.advertonic[2].txt [ Cookie:ms lauren law@www.advertonic.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@youporne[1].txt [ Cookie:ms lauren law@youporne.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@discounter-in-deutschland[2].txt [ Cookie:ms lauren law@discounter-in-deutschland.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@yadro[2].txt [ Cookie:ms lauren law@yadro.ru/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\SN0IFLZN.txt [ Cookie:ms lauren law@content.yieldmanager.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\K6L4SH87.txt [ Cookie:ms lauren law@rts.pgmediaserve.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.veille-referencement[2].txt [ Cookie:ms lauren law@tracking.veille-referencement.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@aimfar.solution.weborama[1].txt [ Cookie:ms lauren law@aimfar.solution.weborama.fr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@stats.paypal[2].txt [ Cookie:ms lauren law@stats.paypal.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@partypoker[3].txt [ Cookie:ms lauren law@partypoker.fr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@metroleap.rotator.hadj7.adjuggler[2].txt [ Cookie:ms lauren law@metroleap.rotator.hadj7.adjuggler.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[10].txt [ Cookie:ms lauren law@de.sitestat.com/haba/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@a.revenuemax[1].txt [ Cookie:ms lauren law@a.revenuemax.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@pluckit.demandmedia[1].txt [ Cookie:ms lauren law@pluckit.demandmedia.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\3ZL8GT48.txt [ Cookie:ms lauren law@pornografish.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@supremeadserver[2].txt [ Cookie:ms lauren law@supremeadserver.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@dmtracker[1].txt [ Cookie:ms lauren law@dmtracker.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tacoda.at.atwola[2].txt [ Cookie:ms lauren law@tacoda.at.atwola.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@gemey2011.solution.weborama[2].txt [ Cookie:ms lauren law@gemey2011.solution.weborama.fr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@microsoftinternetexplorer.112.2o7[1].txt [ Cookie:ms lauren law@microsoftinternetexplorer.112.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.active-tracking[2].txt [ Cookie:ms lauren law@www.active-tracking.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@pointroll[2].txt [ Cookie:ms lauren law@pointroll.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@e-2dj6aekyghcjsep.stats.esomniture[2].txt [ Cookie:ms lauren law@e-2dj6aekyghcjsep.stats.esomniture.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adxpansion[2].txt [ Cookie:ms lauren law@adxpansion.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@server.lon.liveperson[1].txt [ Cookie:ms lauren law@server.lon.liveperson.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@bizrate[1].txt [ Cookie:ms lauren law@bizrate.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ww381.smartadserver[2].txt [ Cookie:ms lauren law@ww381.smartadserver.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@dztadserver.dx-work[2].txt [ Cookie:ms lauren law@dztadserver.dx-work.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads2.zeusclicks[1].txt [ Cookie:ms lauren law@ads2.zeusclicks.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\4QU9CD6T.txt [ Cookie:ms lauren law@media.gan-online.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[8].txt [ Cookie:ms lauren law@de.sitestat.com/ndr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\QGQK5DW8.txt [ Cookie:ms lauren law@banners.xxxgaymatch.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@liveperson[3].txt [ Cookie:ms lauren law@liveperson.net/hc/67442175 ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@stats.yetanotherblog[1].txt [ Cookie:ms lauren law@stats.yetanotherblog.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@trafficmp[1].txt [ Cookie:ms lauren law@trafficmp.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@directtrack[1].txt [ Cookie:ms lauren law@directtrack.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@account.live[2].txt [ Cookie:ms lauren law@account.live.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@frontlinegmbh.122.2o7[1].txt [ Cookie:ms lauren law@frontlinegmbh.122.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@rgadvert[2].txt [ Cookie:ms lauren law@rgadvert.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\1WUB3NRI.txt [ Cookie:ms lauren law@www.usenext.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[7].txt [ Cookie:ms lauren law@de.sitestat.com/ndr/ts/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@mediaforge[1].txt [ Cookie:ms lauren law@mediaforge.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@e-2dj6whkowiczmdp.stats.esomniture[1].txt [ Cookie:ms lauren law@e-2dj6whkowiczmdp.stats.esomniture.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.3gnet[1].txt [ Cookie:ms lauren law@tracking.3gnet.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@zbox.zanox[1].txt [ Cookie:ms lauren law@zbox.zanox.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@cngg-stats.condenastdigital[1].txt [ Cookie:ms lauren law@cngg-stats.condenastdigital.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.googleadservices[1].txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1066875729/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.googleadservices[9].txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1021415196/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@server.cpmstar[2].txt [ Cookie:ms lauren law@server.cpmstar.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\XSDIGG8H.txt [ Cookie:ms lauren law@www.youporncocks.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@fr.sitestat[1].txt [ Cookie:ms lauren law@fr.sitestat.com/euronews/euronews/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[4].txt [ Cookie:ms lauren law@de.sitestat.com/sueddeutsche/sueddeutsche/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.traffic2drive[1].txt [ Cookie:ms lauren law@www.traffic2drive.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@mm.chitika[1].txt [ Cookie:ms lauren law@mm.chitika.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.affiliaxe[2].txt [ Cookie:ms lauren law@tracking.affiliaxe.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@server.iad.liveperson[1].txt [ Cookie:ms lauren law@server.iad.liveperson.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@gotacha.rotator.hadj7.adjuggler[1].txt [ Cookie:ms lauren law@gotacha.rotator.hadj7.adjuggler.net/servlet/ajrotator/85029/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\L1XSCPA9.txt [ Cookie:ms lauren law@adserver2.exgfnetwork.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.googleadservices[3].txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1051309330/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\HYWRVY4T.txt [ Cookie:ms lauren law@stats.justhost.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\6QUCDKES.txt [ Cookie:ms lauren law@tracking.mlsat02.de/tmobile/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@aco.solution.weborama[2].txt [ Cookie:ms lauren law@aco.solution.weborama.fr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ad6media[1].txt [ Cookie:ms lauren law@ad6media.fr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@germanwings.112.2o7[1].txt [ Cookie:ms lauren law@germanwings.112.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.googleadservices[5].txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1052039368/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.publicidees[1].txt [ Cookie:ms lauren law@tracking.publicidees.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adsonar[3].txt [ Cookie:ms lauren law@adsonar.com/adserving ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@start.elitepartner[2].txt [ Cookie:ms lauren law@start.elitepartner.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\5RWZ47KR.txt [ Cookie:ms lauren law@youporncocks.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@clkads[4].txt [ Cookie:ms lauren law@clkads.com/adServe/static/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\6SQWSL16.txt [ Cookie:ms lauren law@freewebcamsex.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\GUK2O59F.txt [ Cookie:ms lauren law@edates.traffective-tracking.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@realmedia[2].txt [ Cookie:ms lauren law@realmedia.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@banquepopulaire2010.solution.weborama[2].txt [ Cookie:ms lauren law@banquepopulaire2010.solution.weborama.fr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\HTCLUF2S.txt [ Cookie:ms lauren law@youporngay.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\LZ61W26B.txt [ Cookie:ms lauren law@h.atdmt.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\46YUUEJO.txt [ Cookie:ms lauren law@exoclick.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@usenext.122.2o7[1].txt [ Cookie:ms lauren law@usenext.122.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@mediastay.directtrack[2].txt [ Cookie:ms lauren law@mediastay.directtrack.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adserving.versaneeds[1].txt [ Cookie:ms lauren law@adserving.versaneeds.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@pmu3.solution.weborama[2].txt [ Cookie:ms lauren law@pmu3.solution.weborama.fr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@liveperson[2].txt [ Cookie:ms lauren law@liveperson.net/hc/16903755 ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@bnpparibasnet.solution.weborama[2].txt [ Cookie:ms lauren law@bnpparibasnet.solution.weborama.fr/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www3.smartadserver[2].txt [ Cookie:ms lauren law@www3.smartadserver.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@content.yieldmanager[3].txt [ Cookie:ms lauren law@content.yieldmanager.com/ak/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\E0BDL23X.txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1065944648/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tto2.traffictrack[2].txt [ Cookie:ms lauren law@tto2.traffictrack.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\E31BK844.txt [ Cookie:ms lauren law@exoclick.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\H69GKR03.txt [ Cookie:ms lauren law@hightraffic.hugoboss.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\6XEWZXSE.txt [ Cookie:ms lauren law@count.asnetworks.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ad.dyntracker[1].txt [ Cookie:ms lauren law@ad.dyntracker.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.googleadservices[7].txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1067082950/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[9].txt [ Cookie:ms lauren law@de.sitestat.com/haba/jako-o-de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adserver.mitfahrzentrale[2].txt [ Cookie:ms lauren law@adserver.mitfahrzentrale.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\SFWB3Z1A.txt [ Cookie:ms lauren law@affiliates.commissionaccount.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\LILJNSLL.txt [ Cookie:ms lauren law@amazon-adsystem.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\N7IVEH5J.txt [ Cookie:ms lauren law@www.youpporn.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@clkads[2].txt [ Cookie:ms lauren law@clkads.com/adServe/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\U6R6THVD.txt [ Cookie:ms lauren law@openx.sexsearchcom.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@gostats[1].txt [ Cookie:ms lauren law@gostats.de/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads5.netpublisher[2].txt [ Cookie:ms lauren law@ads5.netpublisher.pe/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\XMZDUU71.txt [ Cookie:ms lauren law@google.com/accounts/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\82DW7OGR.txt [ Cookie:ms lauren law@c.atdmt.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@e-2dj6wbliwgd5olo.stats.esomniture[2].txt [ Cookie:ms lauren law@e-2dj6wbliwgd5olo.stats.esomniture.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads.zeusclicks[1].txt [ Cookie:ms lauren law@ads.zeusclicks.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\4QHWQXW4.txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1042917106/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\SL4ZBBM9.txt [ Cookie:ms lauren law@www.google.de/accounts ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\SNEJQ0S9.txt [ Cookie:ms lauren law@pro-market.net/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\RNIS5VJQ.txt [ Cookie:ms lauren law@xxxgaymatch.com/ ]
	C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\9OFZST0M.txt [ Cookie:ms lauren law@stat.ed.cupidplc.com/ ]
	C:\USERS\MS LAUREN LAW\Cookies\Q0H56MWF.txt [ Cookie:ms lauren law@fastclick.net/ ]
	C:\USERS\MS LAUREN LAW\Cookies\M7FFZQK4.txt [ Cookie:ms lauren law@youporn.com/ ]
	C:\USERS\MS LAUREN LAW\Cookies\JO5SKGAC.txt [ Cookie:ms lauren law@de.partypoker.com/ ]
	C:\USERS\MS LAUREN LAW\Cookies\42R09K1H.txt [ Cookie:ms lauren law@doubleclick.net/ ]
	C:\USERS\MS LAUREN LAW\Cookies\IV9WQBJM.txt [ Cookie:ms lauren law@www.youporn.com/ ]
	C:\USERS\MS LAUREN LAW\Cookies\IBWMCMCU.txt [ Cookie:ms lauren law@www.usenext.de/ ]
	C:\USERS\MS LAUREN LAW\Cookies\024Q7JNZ.txt [ Cookie:ms lauren law@apmebf.com/ ]
	C:\USERS\MS LAUREN LAW\Cookies\8UC650DI.txt [ Cookie:ms lauren law@partypoker.com/ ]
	C:\USERS\MS LAUREN LAW\Cookies\X93X1RIP.txt [ Cookie:ms lauren law@zanox.com/ ]
	C:\USERS\MS LAUREN LAW\Cookies\ZVPP3UXE.txt [ Cookie:ms lauren law@forum.usenext.de/ ]
	C:\USERS\MS LAUREN LAW\Cookies\DJXPEQR3.txt [ Cookie:ms lauren law@oracle.112.2o7.net/ ]
	C:\USERS\MS LAUREN LAW\Cookies\NYRKDB5B.txt [ Cookie:ms lauren law@smartadserver.com/ ]
	C:\USERS\MS LAUREN LAW\Cookies\SUVW7D4B.txt [ Cookie:ms lauren law@rts.pgmediaserve.com/ ]
	C:\USERS\MS LAUREN LAW\Cookies\Q7CFTT4D.txt [ Cookie:ms lauren law@exoclick.com/ ]
	C:\USERS\MS LAUREN LAW\Cookies\0OHRAM65.txt [ Cookie:ms lauren law@www.usenext.com/ ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.360YIELD[1].TXT [ /AD.360YIELD ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.SPORTWERK[1].TXT [ /ADS.SPORTWERK ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.MOVECO[1].TXT [ /ADS.MOVECO ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.E-PLANNING[1].TXT [ /ADS.E-PLANNING ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TELE2DE.112.2O7[1].TXT [ /TELE2DE.112.2O7 ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@WEBORAMA[1].TXT [ /WEBORAMA ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.MIKINIMEDIA[2].TXT [ /ADS.MIKINIMEDIA ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSERVER.ADREACTOR[1].TXT [ /ADSERVER.ADREACTOR ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.DYNTRACKER[2].TXT [ /AD.DYNTRACKER ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@STAT.HEIMAT[2].TXT [ /STAT.HEIMAT ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSERVER2.CLIPKIT[1].TXT [ /ADSERVER2.CLIPKIT ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@E-2DJ6WCLIWOC5CHP.STATS.ESOMNITURE[2].TXT [ /E-2DJ6WCLIWOC5CHP.STATS.ESOMNITURE ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@STATS.D-P-H[1].TXT [ /STATS.D-P-H ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@VIACOM.ADBUREAU[2].TXT [ /VIACOM.ADBUREAU ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.TRAFFIKINGS[1].TXT [ /ADS.TRAFFIKINGS ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@GOTACHA.ROTATOR.HADJ7.ADJUGGLER[2].TXT [ /GOTACHA.ROTATOR.HADJ7.ADJUGGLER ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.CLICMANAGER[1].TXT [ /ADS.CLICMANAGER ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.COSMOTOURIST[2].TXT [ /ADS.COSMOTOURIST ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.AD4GAME[2].TXT [ /ADS.AD4GAME ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@NAKED[1].TXT [ /NAKED ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.LEADBOLT[1].TXT [ /AD.LEADBOLT ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.REKLAMPORT[2].TXT [ /AD.REKLAMPORT ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@E-2DJ6WMK4OMD5IEP.STATS.ESOMNITURE[2].TXT [ /E-2DJ6WMK4OMD5IEP.STATS.ESOMNITURE ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@WWW.GOOGLEADSERVICES[6].TXT [ /WWW.GOOGLEADSERVICES ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@VODAFONEGROUP.122.2O7[1].TXT [ /VODAFONEGROUP.122.2O7 ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.CARPOOLING[1].TXT [ /ADS.CARPOOLING ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@DEUTSCHEPOSTAG.112.2O7[1].TXT [ /DEUTSCHEPOSTAG.112.2O7 ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@HARRENMEDIANETWORK[1].TXT [ /HARRENMEDIANETWORK ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ELITEPARTNER.TT.OMTRDC[2].TXT [ /ELITEPARTNER.TT.OMTRDC ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@PARSHIP.122.2O7[1].TXT [ /PARSHIP.122.2O7 ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@MICROSOFTWLSEARCHCRM.112.2O7[1].TXT [ /MICROSOFTWLSEARCHCRM.112.2O7 ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ELITEPARTNER[1].TXT [ /ELITEPARTNER ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.US.E-PLANNING[1].TXT [ /ADS.US.E-PLANNING ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ALBUMPRINTER.122.2O7[1].TXT [ /ALBUMPRINTER.122.2O7 ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.WSOD[2].TXT [ /AD.WSOD ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.MEDIENHAUS[1].TXT [ /ADS.MEDIENHAUS ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.YOUPORN.VIDEOBOX[1].TXT [ /AD.YOUPORN.VIDEOBOX ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@CHEAPTICKETS.122.2O7[1].TXT [ /CHEAPTICKETS.122.2O7 ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TRACKING.DC-STORM[1].TXT [ /TRACKING.DC-STORM ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@NEDSTAT.HOSTELBOOKERS[2].TXT [ /NEDSTAT.HOSTELBOOKERS ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.FLING[1].TXT [ /ADS.FLING ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@STAT.CULTUREBASE[1].TXT [ /STAT.CULTUREBASE ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@NEDSTAT.HOSTELBOOKERS[1].TXT [ /NEDSTAT.HOSTELBOOKERS ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TRACKING.BMBFCLUSTER[1].TXT [ /TRACKING.BMBFCLUSTER ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.IMMOBILIENSCOUT24[1].TXT [ /ADS.IMMOBILIENSCOUT24 ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.MITFAHRZENTRALE[1].TXT [ /ADS.MITFAHRZENTRALE ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@LIVEPERSON[5].TXT [ /LIVEPERSON ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@COFIDIS2.SOLUTION.WEBORAMA[2].TXT [ /COFIDIS2.SOLUTION.WEBORAMA ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.ALLVOICES[1].TXT [ /AD.ALLVOICES ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@LEGOLAS-MEDIA[1].TXT [ /LEGOLAS-MEDIA ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.IADMANAGER[2].TXT [ /ADS.IADMANAGER ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.HORYZON-MEDIA[2].TXT [ /ADS.HORYZON-MEDIA ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@INTERCLICK[1].TXT [ /INTERCLICK ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@MONOPRIX.SOLUTION.WEBORAMA[2].TXT [ /MONOPRIX.SOLUTION.WEBORAMA ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.TRAVEL-OVERLAND[1].TXT [ /ADS.TRAVEL-OVERLAND ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.ADK2[2].TXT [ /ADS.ADK2 ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@MEDIA.PHOTOBUCKET[1].TXT [ /MEDIA.PHOTOBUCKET ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSRV.ADMEDIATE[2].TXT [ /ADSRV.ADMEDIATE ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TOYOTA2.SOLUTION.WEBORAMA[2].TXT [ /TOYOTA2.SOLUTION.WEBORAMA ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@CLICKBANK[1].TXT [ /CLICKBANK ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSERVER.YOPI[1].TXT [ /ADSERVER.YOPI ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@WWW.GOOGLEADSERVICES[10].TXT [ /WWW.GOOGLEADSERVICES ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@WWW.GOOGLEADSERVICES[8].TXT [ /WWW.GOOGLEADSERVICES ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.CPXADROIT[2].TXT [ /ADS.CPXADROIT ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@PORNME[2].TXT [ /PORNME ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TRACK.WEBTREKK[2].TXT [ /TRACK.WEBTREKK ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.UNDERTONE[2].TXT [ /ADS.UNDERTONE ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@DEALTIME[1].TXT [ /DEALTIME ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.STARTSEITEN24[1].TXT [ /ADS.STARTSEITEN24 ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@WWW.MESSENGERDUSEXE[1].TXT [ /WWW.MESSENGERDUSEXE ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@NEXTAG[1].TXT [ /NEXTAG ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.LZJL[2].TXT [ /ADS.LZJL ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@PORNHUB[2].TXT [ /PORNHUB ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@CDN5.SPECIFICCLICK[1].TXT [ /CDN5.SPECIFICCLICK ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSERVER.WEBMASTERBOND[1].TXT [ /ADSERVER.WEBMASTERBOND ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD1.ADFARM.ADTELLIGENCE[2].TXT [ /AD1.ADFARM.ADTELLIGENCE ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.BEEPWORLD[2].TXT [ /AD.BEEPWORLD ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TRACKING.STAR-ADVERTISING[2].TXT [ /TRACKING.STAR-ADVERTISING ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ATDMT.COMBING[1].TXT [ /ATDMT.COMBING ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@HORYZON-MEDIA[1].TXT [ /HORYZON-MEDIA ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSRV1.ADMEDIATE[1].TXT [ /ADSRV1.ADMEDIATE ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@EAS4.EMEDIATE[1].TXT [ /EAS4.EMEDIATE ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@SPECIFICCLICK[1].TXT [ /SPECIFICCLICK ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@E-2DJ6WJLYAHD5GLP.STATS.ESOMNITURE[2].TXT [ /E-2DJ6WJLYAHD5GLP.STATS.ESOMNITURE ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.MOVIEASE[1].TXT [ /ADS.MOVIEASE ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@112.2O7[1].TXT [ /112.2O7 ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@WWW.GOOGLEADSERVICES[11].TXT [ /WWW.GOOGLEADSERVICES ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.CINEMADEN[1].TXT [ /ADS.CINEMADEN ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@BANNER.TESTBERICHTE[1].TXT [ /BANNER.TESTBERICHTE ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADVERTSTREAM[1].TXT [ /ADVERTSTREAM ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@GIRLSTEACHSEX[2].TXT [ /GIRLSTEACHSEX ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TRACKING.TCHIBO[1].TXT [ /TRACKING.TCHIBO ]
	C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSERV.QUALITY-CHANNEL[2].TXT [ /ADSERV.QUALITY-CHANNEL ]
         
Code:
ATTFilter
 Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.04.05.10

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Ms Lauren Law :: MSLAURENLAW [Administrator]

05.04.2012 23:19:22
mbam-log-2012-04-05 (23-19-22).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 384234
Laufzeit: 1 Stunde(n), 24 Minute(n), 45 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         

Alt 06.04.2012, 20:05   #28
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 06.04.2012, 20:15   #29
LaurenLaw
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Nein, Probleme gibt es nicht.
Die Cookies die nun in Quarantäne verschoben wurden kann ich löschen oder?
Gut, ich guck mir das mal an was du vorgeschlagen hast.

Und ich danke dir GANZ HERZLICH für deine Zeit und Hilfe!! Ich finds echt toll, dass es diese Seite gibt und ihr/ du sowas mach(s)t.

Und soll ich all die runtergeladenen Sachen aufm PC lassen, für den Fall, dass nochmal was passiert?

Bei dem Cookie Culler steht nicht, dass es für Windows 7 ist. Kann ich das trotzdem runterladen?

Alt 06.04.2012, 20:52   #30
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Security Center Trojaner eingefangen - Standard

Windows Security Center Trojaner eingefangen



Ja die Cookies können weg.
Dre CookieCuller ist für den Firefox, das ist betriebssystemunabhängig. Nimm die neuere Version falls chip da noch was altes hat => http://filepony.de/download-cookie_culler/

Wichtig ist halt, dass du die Cookies die bleiben sollen über den CookieCuller schützen lässt (Protection On einzustellen bei Extras => CookieCuller), das kannst du zB bei FaceBook, Trojaner-Board oder allen anderen Seiten machen lassen wo es Cookies für das automatische Login erfordert. Ist nur etwas umständlich, denn bisher weiß ich nur, dass man jedes Cookies einzeln manuell schützen muss, ist anfangs etwas viel Klickarbeit je nachdem wie viele Cookies man schützen lassen muss/will
Anschließend muss der CookieCuller so konfiguriert werden, dass er jedes Mal beim FF-Start alle nicht geschützten Cookies löscht (Extras, Addons, CookiesCuller Einstellungen, Haken seiten bei "Delete unprotected Cookies on Startup")

Das im Zusammenspiel mit MVPS Hosts-Datei, die du alle paar Wochen mal aktuell hälst ist schon eine gute Grundkonfig. Viele TrackingCookies kommen duch die Hosts nicht mehr rein und alle ungeschützen Cookies werden beim nächsten FF-Start gelöscht


Dann wären wir durch!

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.
__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu Windows Security Center Trojaner eingefangen
.dll, 80-100, antivir, avg, bildschirm, blöd, computer, desktop, fehler, forum, google, logfiles, löschen, malwarebytes, microsoft, modul, namen, neu, neustart, nicht gefunden, nt.dll, programm, prozesse, quelldatei, security, software, trojaner, verweise, warnung, windows




Ähnliche Themen: Windows Security Center Trojaner eingefangen


  1. Virus/Trojaner, Windows-Security-Center, 100 euro per u-kash oder paysafecard zahlen
    Plagegeister aller Art und deren Bekämpfung - 02.06.2012 (4)
  2. Gema Trojaner & Windows Security Center Trojaner
    Log-Analyse und Auswertung - 25.04.2012 (24)
  3. Windows Security Center,Trojaner, 100Euro Strafe zum Entsperren
    Log-Analyse und Auswertung - 16.04.2012 (6)
  4. Windows Security Center,Trojaner, 100Euro Strafe zum Entsperren
    Plagegeister aller Art und deren Bekämpfung - 11.04.2012 (9)
  5. Windows Security Center Virus eingefangen !
    Log-Analyse und Auswertung - 20.03.2012 (5)
  6. 'Windows Security Center' Trojaner - Windows-Benutzer gesperrt !
    Log-Analyse und Auswertung - 16.03.2012 (5)
  7. windows security center virus/trojaner
    Plagegeister aller Art und deren Bekämpfung - 15.03.2012 (7)
  8. Windows Security Center - 100€ ukash paysafe Trojaner
    Log-Analyse und Auswertung - 14.03.2012 (4)
  9. Windows Security Center Trojaner sperrt PC
    Log-Analyse und Auswertung - 14.03.2012 (24)
  10. GEMA-Trojaner eingefangen - Windows XP Media Center Edition
    Plagegeister aller Art und deren Bekämpfung - 23.02.2012 (9)
  11. 100Euro Trojaner - Windows Security Center
    Plagegeister aller Art und deren Bekämpfung - 16.02.2012 (20)
  12. Trojaner Windows Security Center 100€ bezahlen
    Log-Analyse und Auswertung - 15.02.2012 (1)
  13. Windows Security Center: Computer gesperrt! Virus, Trojaner ?
    Log-Analyse und Auswertung - 13.02.2012 (22)
  14. Windows Security Center Trojaner sperrt Computer
    Log-Analyse und Auswertung - 07.02.2012 (17)
  15. Fehler: windows security center trojaner
    Log-Analyse und Auswertung - 02.02.2012 (1)
  16. Ukash Trojaner Windows Security Center Computer wurde gesperrt
    Log-Analyse und Auswertung - 29.01.2012 (7)
  17. "Windows Security Center Alert", selbst ein Trojaner/Wurm ?
    Plagegeister aller Art und deren Bekämpfung - 29.12.2009 (5)

Zum Thema Windows Security Center Trojaner eingefangen - Wiederhol den Fix im abgesicherten Modus bitte - Windows Security Center Trojaner eingefangen...
Archiv
Du betrachtest: Windows Security Center Trojaner eingefangen auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.