|
Log-Analyse und Auswertung: Cyber Crime Investigation Department Österreich - TrojanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
10.09.2012, 16:06 | #16 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Cyber Crime Investigation Department Österreich - Trojaner Wieso von der falschen Seite? Wir verlinken unsere Tools automatisch immer auf die richtige Seite! Wenn du aus anderen Quellen lädst kannst du dir wieder Dreck, Toolbars oder richtig fiese Schädlinge einhandeln!
__________________ Logfiles bitte immer in CODE-Tags posten |
10.09.2012, 16:38 | #17 |
| Cyber Crime Investigation Department Österreich - Trojaner Ja ich weiß, nur habe ich den Link nicht gleich gefunden. Aber den zweiten Scanvorgang habe ich mit dem OTL gemacht, welches ihr bei eurer Anleitung verlinkt hattet. Mein Fehler!
__________________ |
10.09.2012, 20:08 | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Cyber Crime Investigation Department Österreich - Trojaner Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)
__________________Code:
ATTFilter :OTL FF - user.js - File not found IE - HKU\S-1-5-21-2205288494-3300817759-3993977911-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.64.11:8080 O2 - BHO: (GMX Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O3:64bit: - HKLM\..\Toolbar: (GMX Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Programme\GMX Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O3 - HKLM\..\Toolbar: (GMX Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O3:64bit: - HKU\S-1-5-21-2205288494-3300817759-3993977911-1000\..\Toolbar\WebBrowser: (GMX Toolbar) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Programme\GMX Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O3 - HKU\S-1-5-21-2205288494-3300817759-3993977911-1000\..\Toolbar\WebBrowser: (GMX Toolbar) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O2:64bit: - BHO: (GMX Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Programme\GMX Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O4 - HKLM..\Run: [] File not found O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0 O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{2bb5eef1-8255-11e1-b86f-4ceb42085989}\Shell - "" = AutoRun O33 - MountPoints2\{2bb5eef1-8255-11e1-b86f-4ceb42085989}\Shell\AutoRun\command - "" = E:\.\Autorun.exe AUTORUN=1 O33 - MountPoints2\{741fdd7d-8252-11e1-84a7-4ceb42085989}\Shell - "" = AutoRun O33 - MountPoints2\{741fdd7d-8252-11e1-84a7-4ceb42085989}\Shell\AutoRun\command - "" = E:\.\Autorun.exe AUTORUN=1 O33 - MountPoints2\{d0e7913b-b491-11e1-a55b-4ceb42085989}\Shell - "" = AutoRun O33 - MountPoints2\{d0e7913b-b491-11e1-a55b-4ceb42085989}\Shell\AutoRun\command - "" = F:\.\Autorun.exe AUTORUN=1 :Files C:\Users\Christian\AppData\Local\{* C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache ipconfig /flushdns /c :Commands [purity] [emptytemp] [resethosts] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________ |
10.09.2012, 20:50 | #19 |
| Cyber Crime Investigation Department Österreich - Trojaner Hab ich gemacht, hier das Scriptfile: Code:
ATTFilter All processes killed ========== OTL ========== HKU\S-1-5-21-2205288494-3300817759-3993977911-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BF42D4A8-016E-4fcd-B1EB-837659FD77C6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BF42D4A8-016E-4fcd-B1EB-837659FD77C6}\ deleted successfully. C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll moved successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{C424171E-592A-415a-9EB1-DFD6D95D3530} deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415a-9EB1-DFD6D95D3530}\ deleted successfully. C:\Programme\GMX Toolbar\IE\uitb.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{C424171E-592A-415a-9EB1-DFD6D95D3530} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415a-9EB1-DFD6D95D3530}\ deleted successfully. File C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll not found. 64bit-Registry value HKEY_USERS\S-1-5-21-2205288494-3300817759-3993977911-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C424171E-592A-415A-9EB1-DFD6D95D3530} deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415A-9EB1-DFD6D95D3530}\ not found. File C:\Programme\GMX Toolbar\IE\uitb.dll not found. Registry value HKEY_USERS\S-1-5-21-2205288494-3300817759-3993977911-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C424171E-592A-415A-9EB1-DFD6D95D3530} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415A-9EB1-DFD6D95D3530}\ not found. File C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll not found. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BF42D4A8-016E-4fcd-B1EB-837659FD77C6}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BF42D4A8-016E-4fcd-B1EB-837659FD77C6}\ deleted successfully. File C:\Programme\GMX Toolbar\IE\uitb.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoControlPanel deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bb5eef1-8255-11e1-b86f-4ceb42085989}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2bb5eef1-8255-11e1-b86f-4ceb42085989}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bb5eef1-8255-11e1-b86f-4ceb42085989}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2bb5eef1-8255-11e1-b86f-4ceb42085989}\ not found. File E:\.\Autorun.exe AUTORUN=1 not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{741fdd7d-8252-11e1-84a7-4ceb42085989}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{741fdd7d-8252-11e1-84a7-4ceb42085989}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{741fdd7d-8252-11e1-84a7-4ceb42085989}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{741fdd7d-8252-11e1-84a7-4ceb42085989}\ not found. File E:\.\Autorun.exe AUTORUN=1 not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d0e7913b-b491-11e1-a55b-4ceb42085989}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d0e7913b-b491-11e1-a55b-4ceb42085989}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d0e7913b-b491-11e1-a55b-4ceb42085989}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d0e7913b-b491-11e1-a55b-4ceb42085989}\ not found. File F:\.\Autorun.exe AUTORUN=1 not found. ========== FILES ========== C:\Users\Christian\AppData\Local\{00A44926-69AE-429F-85DD-C185C3FEFDF5} folder moved successfully. C:\Users\Christian\AppData\Local\{01AA8E6E-A061-45CF-BF4B-EFB5A9A81FA3} folder moved successfully. C:\Users\Christian\AppData\Local\{028C1121-CDCA-479D-994C-49007FADBC08} folder moved successfully. C:\Users\Christian\AppData\Local\{0293E9A7-7BF6-4899-9B8A-92E304CB837F} folder moved successfully. C:\Users\Christian\AppData\Local\{02A9690E-6D83-4D57-AC69-DE392E6796EC} folder moved successfully. C:\Users\Christian\AppData\Local\{02CB066A-02C8-4D75-9F78-E519A8F58B35} folder moved successfully. C:\Users\Christian\AppData\Local\{032D2104-0342-4238-AB19-CF1306071BCC} folder moved successfully. C:\Users\Christian\AppData\Local\{04D0F3CF-10FD-4950-9F43-FD7562C04339} folder moved successfully. C:\Users\Christian\AppData\Local\{07E3312F-45A3-45B0-86BF-70065B6A687A} folder moved successfully. C:\Users\Christian\AppData\Local\{08834E3D-CF11-4A99-91D9-77662D3394C8} folder moved successfully. C:\Users\Christian\AppData\Local\{09E5DED4-1699-4DE9-9E18-33385CC08410} folder moved successfully. C:\Users\Christian\AppData\Local\{0AB27FDF-F569-467B-96D4-9E272BA66504} folder moved successfully. C:\Users\Christian\AppData\Local\{0BFF7C4E-6105-4051-A8EF-0CB1EC5FE91D} folder moved successfully. C:\Users\Christian\AppData\Local\{0C17A292-9C75-4F07-9B8B-793B2852A0CF} folder moved successfully. C:\Users\Christian\AppData\Local\{0C3008AA-C28C-42AC-8D5B-FDA7A24E2B27} folder moved successfully. C:\Users\Christian\AppData\Local\{0DE9717A-732A-4369-994E-9D7493B90AFD} folder moved successfully. C:\Users\Christian\AppData\Local\{0DF9657F-FCAC-4FDE-B348-73B14E88B4F7} folder moved successfully. C:\Users\Christian\AppData\Local\{0F684264-B6D3-4AF8-B663-B20A14BA8B33} folder moved successfully. C:\Users\Christian\AppData\Local\{1096DD4D-4298-491A-821F-BC995E8B6119} folder moved successfully. C:\Users\Christian\AppData\Local\{10A65D41-CD32-4BBD-AF47-712B505C3F6E} folder moved successfully. C:\Users\Christian\AppData\Local\{10BD7F28-0061-4835-8AAD-45BAFB9BC5EC} folder moved successfully. C:\Users\Christian\AppData\Local\{10DFA9AA-9DD0-4864-BA14-42DCB271811F} folder moved successfully. C:\Users\Christian\AppData\Local\{118B42CF-C9F1-4B81-899C-573B1EDA2652} folder moved successfully. C:\Users\Christian\AppData\Local\{11A23F78-C90B-4829-B3CB-002079658114} folder moved successfully. C:\Users\Christian\AppData\Local\{11E62DB1-6240-4A39-A347-EF2963CE288D} folder moved successfully. C:\Users\Christian\AppData\Local\{12267774-6C1C-4916-99AB-DE0176E26A7B} folder moved successfully. C:\Users\Christian\AppData\Local\{127D1D0C-2FE3-44A0-B734-A38CB3B3838F} folder moved successfully. C:\Users\Christian\AppData\Local\{12F656B5-FCAF-439D-B022-734372DE38DF} folder moved successfully. C:\Users\Christian\AppData\Local\{1308A159-595F-4BF0-9BBE-E3A8C5F7F103} folder moved successfully. C:\Users\Christian\AppData\Local\{1406DB31-90AC-49BB-882B-D7BB34F7D251} folder moved successfully. C:\Users\Christian\AppData\Local\{14EBD7E9-90DE-4A2D-8FCE-30C1CBD52E87} folder moved successfully. C:\Users\Christian\AppData\Local\{1529CBC0-BB73-4E8D-9AD2-3B5B8B3713EF} folder moved successfully. C:\Users\Christian\AppData\Local\{159F64C4-FDC9-40BF-8AAE-F0357861F313} folder moved successfully. C:\Users\Christian\AppData\Local\{15A3C6CC-BB19-4AFF-866D-EF9BFBE97F53} folder moved successfully. C:\Users\Christian\AppData\Local\{1602A8F1-984B-4FAE-8EB6-2B56D4CA297E} folder moved successfully. C:\Users\Christian\AppData\Local\{173441B0-1E62-416F-8B0A-208D967397AF} folder moved successfully. C:\Users\Christian\AppData\Local\{17E21239-7D38-483F-B19C-B7A80C5CA30E} folder moved successfully. C:\Users\Christian\AppData\Local\{180CFE93-AA8C-4F38-A335-0BA1C487AE5D} folder moved successfully. C:\Users\Christian\AppData\Local\{190756E5-051C-4CA6-984B-8886F4174740} folder moved successfully. C:\Users\Christian\AppData\Local\{19AF43B0-CBD6-45D4-A8B7-48F8A3E34C94} folder moved successfully. C:\Users\Christian\AppData\Local\{19EC3999-236B-4BE9-A6B0-36103D6F43DB} folder moved successfully. C:\Users\Christian\AppData\Local\{1AF0FBC9-E476-47EB-88E9-B991AD0D9B18} folder moved successfully. C:\Users\Christian\AppData\Local\{1B01E345-3182-4D93-B123-5A37BFC79335} folder moved successfully. C:\Users\Christian\AppData\Local\{1B8B1F78-35B0-4DBC-91DB-3BC2512B9535} folder moved successfully. C:\Users\Christian\AppData\Local\{1C405DB1-0D96-4301-A3FA-BD870BBC51D7} folder moved successfully. C:\Users\Christian\AppData\Local\{1C472044-6013-4DC7-B157-DEBCB9229F69} folder moved successfully. C:\Users\Christian\AppData\Local\{1C5C44B3-3940-4B70-A6F9-B3272E0D7DF4} folder moved successfully. C:\Users\Christian\AppData\Local\{1DE4B513-811F-4B38-9834-493B9239D48B} folder moved successfully. C:\Users\Christian\AppData\Local\{1E14E81A-F3C6-42FB-9DC2-05327C9557D7} folder moved successfully. C:\Users\Christian\AppData\Local\{1EC1D225-4743-4F88-9F3E-699A1F07F219} folder moved successfully. C:\Users\Christian\AppData\Local\{1EFF66C9-59C0-4428-9B46-91FB0FC95797} folder moved successfully. C:\Users\Christian\AppData\Local\{1F1C765D-EFF2-462B-8CD1-D11F27BE6685} folder moved successfully. C:\Users\Christian\AppData\Local\{1F576B3F-6677-417A-8A3C-0298BD21B6C5} folder moved successfully. C:\Users\Christian\AppData\Local\{201A16B7-4C63-4E8D-8DE6-C15C482EE951} folder moved successfully. C:\Users\Christian\AppData\Local\{2033091E-6159-422C-AE81-997FB1FF9551} folder moved successfully. C:\Users\Christian\AppData\Local\{20627357-8450-470F-9A03-F33397E4CC43} folder moved successfully. C:\Users\Christian\AppData\Local\{208D0712-4CCC-4360-978E-FA42FA8F8194} folder moved successfully. C:\Users\Christian\AppData\Local\{2095252E-13AE-4F98-9CE6-0CBA75F525C9} folder moved successfully. C:\Users\Christian\AppData\Local\{20FF5A40-C397-44FE-8F58-25081CF98DF4} folder moved successfully. C:\Users\Christian\AppData\Local\{21529A7F-125C-4E8A-8887-64A8111973DB} folder moved successfully. C:\Users\Christian\AppData\Local\{22E39B76-D2E5-483B-931F-CC6CB4305177} folder moved successfully. C:\Users\Christian\AppData\Local\{231415C6-7F00-4478-8ABB-EA94FE5C93B3} folder moved successfully. C:\Users\Christian\AppData\Local\{23420D90-BC5E-4381-B4BD-8E3078007E54} folder moved successfully. C:\Users\Christian\AppData\Local\{2385D0E9-CC00-4669-9F6B-8DC9201233B7} folder moved successfully. C:\Users\Christian\AppData\Local\{23ED0FBC-0827-4A22-8D46-CB027C174839} folder moved successfully. C:\Users\Christian\AppData\Local\{24DF72E5-3218-4092-9460-E3AC6449F10E} folder moved successfully. C:\Users\Christian\AppData\Local\{25273AFB-1A36-4198-8E94-1D706C2EA863} folder moved successfully. C:\Users\Christian\AppData\Local\{2540AA2D-DB9B-469B-827C-C600DF0B5378} folder moved successfully. C:\Users\Christian\AppData\Local\{25EE239A-1BAE-476B-B93B-8FE915F44BA0} folder moved successfully. C:\Users\Christian\AppData\Local\{26C293AE-6B2E-40BB-9A52-8677DFF0DA73} folder moved successfully. C:\Users\Christian\AppData\Local\{27476095-1334-48E7-8A05-0AA31198A381} folder moved successfully. C:\Users\Christian\AppData\Local\{27DD53EE-B307-4B27-B4CE-3989DB139C8B} folder moved successfully. C:\Users\Christian\AppData\Local\{28005A83-6BAA-4B14-8DA8-AF3946916CDA} folder moved successfully. C:\Users\Christian\AppData\Local\{2817C09A-263D-4141-8C58-83350BD4A42F} folder moved successfully. C:\Users\Christian\AppData\Local\{2853C147-86BA-4166-A8F2-E92FD7BBF7AE} folder moved successfully. C:\Users\Christian\AppData\Local\{2AE3DE50-5606-4EF5-83DC-BCCBA1F67EFE} folder moved successfully. C:\Users\Christian\AppData\Local\{2B1491DE-8687-4B07-A02B-359AD8D09B26} folder moved successfully. C:\Users\Christian\AppData\Local\{2C54BF74-5BB0-408A-B56E-5285460D797D} folder moved successfully. C:\Users\Christian\AppData\Local\{2C7FE6C3-823A-4698-BDA9-0981A36A3C89} folder moved successfully. C:\Users\Christian\AppData\Local\{2C9B84A9-1A74-4A4F-84A3-6E99B43FB95C} folder moved successfully. C:\Users\Christian\AppData\Local\{2CAE2C9A-CBC7-4BCC-A0DB-37848E9AAA5C} folder moved successfully. C:\Users\Christian\AppData\Local\{2CFA1937-33F8-4580-873C-A114324679F8} folder moved successfully. C:\Users\Christian\AppData\Local\{2D562BE3-CF91-423B-9C8C-37A4B8CA40F1} folder moved successfully. C:\Users\Christian\AppData\Local\{2DB725E3-FE73-44E3-927B-04C2B7A6C07F} folder moved successfully. C:\Users\Christian\AppData\Local\{2E775598-F21D-4069-8992-BFC803F4F89E} folder moved successfully. C:\Users\Christian\AppData\Local\{2EAA65F9-C479-43F1-B5FE-39AF8C2CC94C} folder moved successfully. C:\Users\Christian\AppData\Local\{2EB9266B-60A3-4E27-BABF-159EFC1DA737} folder moved successfully. C:\Users\Christian\AppData\Local\{2F525FF9-3055-4ED0-AC86-E567C99B69AE} folder moved successfully. C:\Users\Christian\AppData\Local\{2F780480-27ED-4D22-B580-D6E4B66B9EF7} folder moved successfully. C:\Users\Christian\AppData\Local\{2FD67F77-A50B-4DB4-88D8-B4EF1D468D98} folder moved successfully. C:\Users\Christian\AppData\Local\{31A0B7CD-C0AC-40E6-9379-2FFB759B43A7} folder moved successfully. C:\Users\Christian\AppData\Local\{3265E914-F729-427B-9003-E0FE4840A29F} folder moved successfully. C:\Users\Christian\AppData\Local\{3422DFB3-7B05-4112-9BA8-8F66BCC5EBD7} folder moved successfully. C:\Users\Christian\AppData\Local\{3492E815-F9C7-4C02-8AAD-9CDA2FDEBB87} folder moved successfully. C:\Users\Christian\AppData\Local\{355DF23E-8983-4264-A0F0-E29128153E65} folder moved successfully. C:\Users\Christian\AppData\Local\{35982AC3-E455-4DCE-9352-D1164F1091E3} folder moved successfully. C:\Users\Christian\AppData\Local\{36669D3D-E6B6-4E3E-9F56-8B0F9521F3F4} folder moved successfully. C:\Users\Christian\AppData\Local\{36AF91DA-D291-4A39-B1A3-3F4892CF167C} folder moved successfully. C:\Users\Christian\AppData\Local\{37106BE5-E780-4FBF-AD32-B7F2F131B660} folder moved successfully. C:\Users\Christian\AppData\Local\{37DE023E-40A5-48A4-8B3C-201848278D62} folder moved successfully. C:\Users\Christian\AppData\Local\{383A4D29-6067-47E9-A85A-11B3190FF062} folder moved successfully. C:\Users\Christian\AppData\Local\{383C525B-8FFE-4136-A511-9B43559EB54A} folder moved successfully. C:\Users\Christian\AppData\Local\{38626F7B-CCE7-43CB-9BCC-CE9A5FDD2031} folder moved successfully. C:\Users\Christian\AppData\Local\{38ED4FF6-ED66-4566-A0AB-1D6806E7D1FC} folder moved successfully. C:\Users\Christian\AppData\Local\{39142782-B914-42F3-AA5E-438BF9F3D02C} folder moved successfully. C:\Users\Christian\AppData\Local\{3928B926-1782-4FAA-99EA-B4068CAB72FB} folder moved successfully. C:\Users\Christian\AppData\Local\{3AB0FC81-114A-4FC2-84ED-E16075CAEF50} folder moved successfully. C:\Users\Christian\AppData\Local\{3C1C870B-DB39-4F12-9434-BD3628C788CD} folder moved successfully. C:\Users\Christian\AppData\Local\{3C602F47-6C98-4708-805B-25083F83DB40} folder moved successfully. C:\Users\Christian\AppData\Local\{3C983C15-D670-49DD-B740-F401C409FFA2} folder moved successfully. C:\Users\Christian\AppData\Local\{3CA81D8D-857C-45AC-85C5-B493471E6368} folder moved successfully. C:\Users\Christian\AppData\Local\{3D2FFEB6-8418-47D1-AE50-41B56C60D539} folder moved successfully. C:\Users\Christian\AppData\Local\{3DA4305B-0ABA-4420-B0A3-4040D5028A73} folder moved successfully. C:\Users\Christian\AppData\Local\{3EAF06AB-B98C-49D3-8C5F-2CCA7061B6C0} folder moved successfully. C:\Users\Christian\AppData\Local\{3EE9F8AE-BEC1-41F0-B8E3-216BF19E6C70} folder moved successfully. C:\Users\Christian\AppData\Local\{3F291BE3-D220-4783-9EF9-68C1DB0C4892} folder moved successfully. C:\Users\Christian\AppData\Local\{3F42549F-6968-4AA1-A113-7FB4825FC43C} folder moved successfully. C:\Users\Christian\AppData\Local\{3FE69590-BE6D-4FC0-BEDC-CA26B5B22FE9} folder moved successfully. C:\Users\Christian\AppData\Local\{3FF17456-15A2-4EEA-91EE-2B4E9DC6C068} folder moved successfully. C:\Users\Christian\AppData\Local\{400A6C73-629B-4AA1-A486-5BE3C5AE6C9E} folder moved successfully. C:\Users\Christian\AppData\Local\{404F46FF-E520-4023-939B-99284723A6EF} folder moved successfully. C:\Users\Christian\AppData\Local\{424B7434-33DE-4182-B9FB-B574637582BD} folder moved successfully. C:\Users\Christian\AppData\Local\{431B45E9-DBEC-4869-ABA8-5251677907F4} folder moved successfully. C:\Users\Christian\AppData\Local\{4370ACD8-4E30-4A47-923A-1ABC2E65AE78} folder moved successfully. C:\Users\Christian\AppData\Local\{43D66EF4-FEF1-4FA7-B2E7-EE9731B6AF86} folder moved successfully. C:\Users\Christian\AppData\Local\{43E15F56-7811-4A0B-A999-B8D75C9957E7} folder moved successfully. C:\Users\Christian\AppData\Local\{44B548CE-54C6-4A49-8C9E-5049CAF10503} folder moved successfully. C:\Users\Christian\AppData\Local\{452A94FE-B7D8-4DE9-8260-98ADDCA80E78} folder moved successfully. C:\Users\Christian\AppData\Local\{45E89EB7-5C0E-46E1-A413-02C68A2D653C} folder moved successfully. C:\Users\Christian\AppData\Local\{46529E2E-00D1-4443-9B5C-DE6D8B7610F4} folder moved successfully. C:\Users\Christian\AppData\Local\{479F0BA9-7991-46C4-B2CC-EFE8461101B2} folder moved successfully. C:\Users\Christian\AppData\Local\{47C6576C-9A19-4C3C-B28E-5669B9F8D220} folder moved successfully. C:\Users\Christian\AppData\Local\{47CF86C0-156A-43BC-98B0-6B07565154B4} folder moved successfully. C:\Users\Christian\AppData\Local\{48B67BA0-641B-4375-878E-C02CB2067B8F} folder moved successfully. C:\Users\Christian\AppData\Local\{491206A5-AE3A-408A-8BAB-1939A43ED807} folder moved successfully. C:\Users\Christian\AppData\Local\{497F178D-938C-421A-B65F-CA3763F86558} folder moved successfully. C:\Users\Christian\AppData\Local\{4993CF96-2AE3-4A13-BCC7-7BA42794A566} folder moved successfully. C:\Users\Christian\AppData\Local\{4A8D8492-10DE-4194-A14A-DF58AB79E7D4} folder moved successfully. C:\Users\Christian\AppData\Local\{4A90932E-E241-47C8-8F3F-A8A6602FDF23} folder moved successfully. C:\Users\Christian\AppData\Local\{4B0CADFD-0160-4F27-B59B-75D68600F321} folder moved successfully. C:\Users\Christian\AppData\Local\{4BB42B38-FAEB-40E9-ABB6-4BEE6AC0F5D0} folder moved successfully. C:\Users\Christian\AppData\Local\{4CE3D797-5814-4869-B388-20C59EAAD49F} folder moved successfully. C:\Users\Christian\AppData\Local\{4D65322F-1ABA-4F26-8222-C3AB989A7EC5} folder moved successfully. C:\Users\Christian\AppData\Local\{4DD80D53-37B9-4839-835B-03C9385FAB8C} folder moved successfully. C:\Users\Christian\AppData\Local\{4E093603-D170-4A8D-B1FF-BEF408DF4F92} folder moved successfully. C:\Users\Christian\AppData\Local\{4E13E891-0249-4EB1-9892-1B3979514C27} folder moved successfully. C:\Users\Christian\AppData\Local\{4E21E3CC-9B46-43D8-BE4E-6EBDFFEE660A} folder moved successfully. C:\Users\Christian\AppData\Local\{4F46B9E1-2638-4824-B934-C084E1214F5E} folder moved successfully. C:\Users\Christian\AppData\Local\{4FBE4DCC-8DA5-46E0-9E66-D5E0F7753555} folder moved successfully. C:\Users\Christian\AppData\Local\{4FD4E571-C29B-4186-9399-E568F127F8E3} folder moved successfully. C:\Users\Christian\AppData\Local\{50F7A330-E568-46F4-A077-775408B9DD43} folder moved successfully. C:\Users\Christian\AppData\Local\{5179D117-1BCE-4F3A-A2A1-F430F3B48898} folder moved successfully. C:\Users\Christian\AppData\Local\{5215B37B-F575-4777-8707-25237C95116E} folder moved successfully. C:\Users\Christian\AppData\Local\{52513D19-0518-4387-9D2F-6A5A8B444B4C} folder moved successfully. C:\Users\Christian\AppData\Local\{5285938A-1DE5-45F7-AA1D-27BB652D7CA4} folder moved successfully. C:\Users\Christian\AppData\Local\{52DF4FFA-6CDE-4612-865B-60AD2C13225B} folder moved successfully. C:\Users\Christian\AppData\Local\{52E95032-C866-43DB-89B2-DA7D6D4191C8} folder moved successfully. C:\Users\Christian\AppData\Local\{5304CC19-7D73-45F2-8926-5ACA9E8B49DC} folder moved successfully. C:\Users\Christian\AppData\Local\{53B0D2B3-1F37-4340-91A1-991B495D1996} folder moved successfully. C:\Users\Christian\AppData\Local\{53FF9FD8-3DB7-4179-ADA0-9E8F66CC5F21} folder moved successfully. C:\Users\Christian\AppData\Local\{5451155E-4F4F-486D-81F7-664C04E1BD8F} folder moved successfully. C:\Users\Christian\AppData\Local\{54EC0B34-2BE6-49FB-83F0-657D5FAEB3FC} folder moved successfully. C:\Users\Christian\AppData\Local\{55CE4324-C015-4A4E-9B86-8E3C15E736B9} folder moved successfully. C:\Users\Christian\AppData\Local\{55DD86E9-654B-4C81-876A-885C28C59565} folder moved successfully. C:\Users\Christian\AppData\Local\{55F001EF-1AF7-47B0-B5C8-5603E899D347} folder moved successfully. C:\Users\Christian\AppData\Local\{56793849-4B8C-43E8-8464-AD40D8E110A6} folder moved successfully. C:\Users\Christian\AppData\Local\{56994CF6-9449-4D44-BF15-0531EDECD847} folder moved successfully. C:\Users\Christian\AppData\Local\{5747BD3C-2A43-4108-AEB2-67883FABA55C} folder moved successfully. C:\Users\Christian\AppData\Local\{57C5E922-686E-44E9-A0E0-9289460564D3} folder moved successfully. C:\Users\Christian\AppData\Local\{5975BB0B-EC98-4711-81F8-C3CA636CBAEE} folder moved successfully. C:\Users\Christian\AppData\Local\{5AD3DA3E-CFBB-456F-853C-5B7DB0EAB03D} folder moved successfully. C:\Users\Christian\AppData\Local\{5B42770D-121C-41B1-8DB9-51203ECEBDC0} folder moved successfully. C:\Users\Christian\AppData\Local\{5D8C9100-5A17-44BA-9EDA-57C8FB4E6F6F} folder moved successfully. C:\Users\Christian\AppData\Local\{5E77F598-5FB1-466F-BB2F-01128D852099} folder moved successfully. C:\Users\Christian\AppData\Local\{5E8799AF-9C39-41AC-998B-E0B837B32BE1} folder moved successfully. C:\Users\Christian\AppData\Local\{5EBB2684-B4AD-47CE-98E9-EAEE2BF1EE9E} folder moved successfully. C:\Users\Christian\AppData\Local\{5EF77CF4-FA9E-4EB5-AA25-4A8F7A2A77DD} folder moved successfully. C:\Users\Christian\AppData\Local\{5FB246AD-30A1-40AC-AA4E-B38EEBE0604C} folder moved successfully. C:\Users\Christian\AppData\Local\{605F125C-713A-42CC-BEAE-6EF749AE96BE} folder moved successfully. C:\Users\Christian\AppData\Local\{609CAC23-8641-4712-89C9-2A79B716A49C} folder moved successfully. C:\Users\Christian\AppData\Local\{60E00F28-E035-425F-81E6-7E182AD173C2} folder moved successfully. C:\Users\Christian\AppData\Local\{6189E825-EFCB-4D51-A0D6-20FBAE4816AB} folder moved successfully. C:\Users\Christian\AppData\Local\{6191BE32-96D3-4BBD-A32D-AA7414311492} folder moved successfully. C:\Users\Christian\AppData\Local\{61EAF557-B477-478A-A8B1-7799A969D10B} folder moved successfully. C:\Users\Christian\AppData\Local\{61F67918-07D7-40C0-A700-3A58DA45B04E} folder moved successfully. C:\Users\Christian\AppData\Local\{623A2F05-5A04-4A9E-BF7C-D65E93EABB21} folder moved successfully. C:\Users\Christian\AppData\Local\{6252E9A6-7109-4135-8E09-F150CE826BBB} folder moved successfully. C:\Users\Christian\AppData\Local\{62D761BC-12E6-43A6-93CF-58E43A197092} folder moved successfully. C:\Users\Christian\AppData\Local\{635CF4B6-FC87-4DFE-9B4B-6A39B9B160F1} folder moved successfully. C:\Users\Christian\AppData\Local\{63603236-3B7A-43D5-B3F0-CE57CECFCACF} folder moved successfully. C:\Users\Christian\AppData\Local\{6363A9EF-620D-4D6E-81D6-84700453FCE1} folder moved successfully. C:\Users\Christian\AppData\Local\{65A5AC65-9221-4D8D-891A-3265440F5C01} folder moved successfully. C:\Users\Christian\AppData\Local\{66B698B7-CC3C-4AD9-AF3D-72E3636105DB} folder moved successfully. C:\Users\Christian\AppData\Local\{67A67CCF-0D61-4CFC-ACC7-5F4BB8A44E67} folder moved successfully. C:\Users\Christian\AppData\Local\{67DC27A9-7FB3-4039-9C5B-CC0E83D4B281} folder moved successfully. C:\Users\Christian\AppData\Local\{67FEC91D-6207-4F8E-A8F1-34F80B0A505C} folder moved successfully. C:\Users\Christian\AppData\Local\{68B1BC93-94B7-498A-B161-6527E7377783} folder moved successfully. C:\Users\Christian\AppData\Local\{6976EB37-71F6-4165-B704-E020E3244E99} folder moved successfully. C:\Users\Christian\AppData\Local\{69AB1A04-BA6A-4F21-8F10-E1407AAC092A} folder moved successfully. C:\Users\Christian\AppData\Local\{69DA50D6-340A-4BAC-BFA2-FB643BD682BC} folder moved successfully. C:\Users\Christian\AppData\Local\{69F24DDC-1E98-403C-92E9-59C051207593} folder moved successfully. C:\Users\Christian\AppData\Local\{6A2475FD-BF91-4C86-A956-C58211774907} folder moved successfully. C:\Users\Christian\AppData\Local\{6AE2C6B2-CFFB-46D8-AFDC-D63519065346} folder moved successfully. C:\Users\Christian\AppData\Local\{6B0F60C1-80D1-4F4B-8B2B-735203E3C90D} folder moved successfully. C:\Users\Christian\AppData\Local\{6BC7C52B-D6F6-44A8-B3C8-F720DA0C2618} folder moved successfully. C:\Users\Christian\AppData\Local\{6C2E3ED0-B2E8-43D4-83C3-544E2CFADF50} folder moved successfully. C:\Users\Christian\AppData\Local\{6C5560A8-B1EB-40E6-BD56-CBFC53E28AAD} folder moved successfully. C:\Users\Christian\AppData\Local\{6C639A83-9250-483A-BA90-55206250C7AE} folder moved successfully. C:\Users\Christian\AppData\Local\{6CFA5FCD-EBE8-4C71-8235-F91C4125F89C} folder moved successfully. C:\Users\Christian\AppData\Local\{6D16E651-C6ED-4899-924A-CCB2E8E57CF5} folder moved successfully. C:\Users\Christian\AppData\Local\{6E268235-6A0E-4B97-B27D-D03667C94726} folder moved successfully. C:\Users\Christian\AppData\Local\{6F736609-1E89-4781-A028-06C378CC895A} folder moved successfully. C:\Users\Christian\AppData\Local\{6FDAB261-40D1-4D50-95F1-D527855EE980} folder moved successfully. C:\Users\Christian\AppData\Local\{7000DFE7-C664-414F-8A96-2719B1831CC2} folder moved successfully. C:\Users\Christian\AppData\Local\{705E48CD-926A-4A11-AB5E-B3A1398F55A4} folder moved successfully. C:\Users\Christian\AppData\Local\{70843C38-C6A5-4F0D-9E71-F3912EAA11C7} folder moved successfully. C:\Users\Christian\AppData\Local\{70AD62E2-C62E-4B63-83D1-D801A799E64E} folder moved successfully. C:\Users\Christian\AppData\Local\{71716551-583E-4188-9C1E-056A83A905B3} folder moved successfully. C:\Users\Christian\AppData\Local\{71D4F41E-EDB3-440A-96BA-A5881047BC6E} folder moved successfully. C:\Users\Christian\AppData\Local\{727ACD79-606A-4E20-B844-F651528605F6} folder moved successfully. C:\Users\Christian\AppData\Local\{72C128B9-283D-4833-B2A3-737A0C2E724B} folder moved successfully. C:\Users\Christian\AppData\Local\{731AA607-CA4D-4439-91C6-0B6517DB69AD} folder moved successfully. C:\Users\Christian\AppData\Local\{739481A4-2332-4E94-B4EA-6419B00A0933} folder moved successfully. C:\Users\Christian\AppData\Local\{73954663-D5A3-4BAB-BC0F-2D1DBF245228} folder moved successfully. C:\Users\Christian\AppData\Local\{74653C8E-D80C-4DF9-8A28-F024D3604310} folder moved successfully. C:\Users\Christian\AppData\Local\{74B2630E-EE6E-4818-B280-13C8E3D13D00} folder moved successfully. C:\Users\Christian\AppData\Local\{74F794D9-86FA-4692-8DFD-29EC4A9D688E} folder moved successfully. C:\Users\Christian\AppData\Local\{7544A7B0-49A8-4B75-B827-DCB1D819D393} folder moved successfully. C:\Users\Christian\AppData\Local\{75EA96A1-DE0F-4449-92A6-F64398B59A49} folder moved successfully. C:\Users\Christian\AppData\Local\{7609DD1E-6B84-49F7-A22C-DF6FB8972177} folder moved successfully. C:\Users\Christian\AppData\Local\{778D2745-F4BF-4C83-B207-28B26EF9D56C} folder moved successfully. C:\Users\Christian\AppData\Local\{784A58AC-A16A-4B13-812B-AB96C500A127} folder moved successfully. C:\Users\Christian\AppData\Local\{78585DEF-1173-43DC-8EEB-A90195EEEF51} folder moved successfully. C:\Users\Christian\AppData\Local\{78D6031E-6144-45A5-8608-DA2784C256B1} folder moved successfully. C:\Users\Christian\AppData\Local\{7921DD2B-231D-46BA-AA8B-3A93053C7528} folder moved successfully. C:\Users\Christian\AppData\Local\{795C9094-DE2A-46EC-9FC6-046247E2E65E} folder moved successfully. C:\Users\Christian\AppData\Local\{79FC11BD-8CD1-4A8C-8F18-5A9A9B89E760} folder moved successfully. C:\Users\Christian\AppData\Local\{7A3CAC8C-22B7-4C50-90E8-48582CC995F9} folder moved successfully. C:\Users\Christian\AppData\Local\{7A98BD34-A04A-42B4-9B4D-20773B236079} folder moved successfully. C:\Users\Christian\AppData\Local\{7AEDECE0-D4AC-43B8-9634-9EBBE185FF58} folder moved successfully. C:\Users\Christian\AppData\Local\{7B988E60-93ED-4966-8540-4B64D9CCC953} folder moved successfully. C:\Users\Christian\AppData\Local\{7C6179D6-CFBD-4CA5-A3AB-48B6662BE1FB} folder moved successfully. C:\Users\Christian\AppData\Local\{7D14AEEC-3F7E-4F9A-8D32-38FD04F21C1C} folder moved successfully. C:\Users\Christian\AppData\Local\{7DEE4D08-A68D-4998-9BF6-5FF3DDADC03C} folder moved successfully. C:\Users\Christian\AppData\Local\{7ECA1A7A-69D4-460B-BD20-BEC6779FF28F} folder moved successfully. C:\Users\Christian\AppData\Local\{7F7E3A9A-F94C-43F3-BA36-94681191FD81} folder moved successfully. C:\Users\Christian\AppData\Local\{7F858720-0527-49F4-AF4A-69CB58B40229} folder moved successfully. C:\Users\Christian\AppData\Local\{7FCCE8EB-0143-4678-8A68-44D44A754DB6} folder moved successfully. C:\Users\Christian\AppData\Local\{80603FE1-16E1-4F98-AAAB-8576B216A0B1} folder moved successfully. C:\Users\Christian\AppData\Local\{8157E372-6ACA-4A12-9DC6-978ED649FEFA} folder moved successfully. C:\Users\Christian\AppData\Local\{821BE524-45D1-4C00-8D35-F6F6AA8D2D01} folder moved successfully. C:\Users\Christian\AppData\Local\{826FFF15-2636-4853-BEE8-D2E048F17214} folder moved successfully. C:\Users\Christian\AppData\Local\{82A5D821-9DE9-44E6-8C1B-FDCE996BF233} folder moved successfully. C:\Users\Christian\AppData\Local\{843AF0B8-2BC3-4EA4-9E48-0F5515B194CA} folder moved successfully. C:\Users\Christian\AppData\Local\{85BA4183-A65F-460D-9152-9CD8144DD044} folder moved successfully. C:\Users\Christian\AppData\Local\{864FA1F2-2C14-4993-98C3-8322FDF93A12} folder moved successfully. C:\Users\Christian\AppData\Local\{8703D913-A391-4BB8-A1F5-70755D96A3D6} folder moved successfully. C:\Users\Christian\AppData\Local\{87C23FAB-7196-452B-B8A2-84BD2F1F9E09} folder moved successfully. C:\Users\Christian\AppData\Local\{87E43272-841D-480C-999F-261CB79BE236} folder moved successfully. C:\Users\Christian\AppData\Local\{87E60E83-4EF1-4DAF-AA1E-4A09D3066D4F} folder moved successfully. C:\Users\Christian\AppData\Local\{87E66B1F-3D5E-4B27-8092-B0F6BC640CA1} folder moved successfully. C:\Users\Christian\AppData\Local\{892FBE49-C9BF-4341-94FA-60F6678ED68B} folder moved successfully. C:\Users\Christian\AppData\Local\{8957DC13-7FEE-42C3-9A02-5C078F619FD3} folder moved successfully. C:\Users\Christian\AppData\Local\{899DBC9C-234E-4749-A515-24A8283BA730} folder moved successfully. C:\Users\Christian\AppData\Local\{89B6F162-8583-4610-B242-3486DBFED677} folder moved successfully. C:\Users\Christian\AppData\Local\{89C6D2BF-3CEA-4CEB-83EB-881D3900CEDC} folder moved successfully. C:\Users\Christian\AppData\Local\{8A815043-01D8-44E4-9A6E-B6A5AF72724B} folder moved successfully. C:\Users\Christian\AppData\Local\{8AD0EC45-09DA-4F64-A65B-A510BAC85629} folder moved successfully. C:\Users\Christian\AppData\Local\{8B0A64A2-0C34-40BE-94AD-3FFC2608771B} folder moved successfully. C:\Users\Christian\AppData\Local\{8B4617B7-7333-4DF3-BFF6-FDC0BAEC074D} folder moved successfully. C:\Users\Christian\AppData\Local\{8C4F6575-213F-4964-BF5B-7B0BB487C71E} folder moved successfully. C:\Users\Christian\AppData\Local\{8CE94E5F-83E6-4B5A-84F2-546BEFC9F691} folder moved successfully. C:\Users\Christian\AppData\Local\{8D2FBF1E-B916-4091-ACDE-17EA2BE7CAA4} folder moved successfully. C:\Users\Christian\AppData\Local\{8D5552D6-FE47-416D-95E1-EE787427F182} folder moved successfully. C:\Users\Christian\AppData\Local\{8EC00B5B-C2A6-4138-AD03-B688861DE295} folder moved successfully. C:\Users\Christian\AppData\Local\{8F490C40-6793-4657-AF08-AA6200AB3553} folder moved successfully. C:\Users\Christian\AppData\Local\{8F5C276E-4351-45C5-B1B3-721B94F95004} folder moved successfully. C:\Users\Christian\AppData\Local\{8FBC612C-C969-460A-B7A8-579346C2D436} folder moved successfully. C:\Users\Christian\AppData\Local\{9180285F-673D-4022-A0F8-935ECEFAE47E} folder moved successfully. C:\Users\Christian\AppData\Local\{91C26A63-5082-424A-8BA3-FDBCD1BF9C92} folder moved successfully. C:\Users\Christian\AppData\Local\{924B8327-F424-4A3C-B19F-E9D53B308772} folder moved successfully. C:\Users\Christian\AppData\Local\{939D3138-BCE9-4A09-A274-37213455C708} folder moved successfully. C:\Users\Christian\AppData\Local\{93DB8A72-429E-4EBF-AC65-674A7E0AD900} folder moved successfully. C:\Users\Christian\AppData\Local\{955E8EAF-509D-461F-967C-82113C0FFD96} folder moved successfully. C:\Users\Christian\AppData\Local\{95BA3EF9-FA6D-4879-A0ED-5C2F94B1D3DB} folder moved successfully. C:\Users\Christian\AppData\Local\{987AF278-1063-47F0-BB60-9D4D6591A909} folder moved successfully. C:\Users\Christian\AppData\Local\{9A587A8F-DB85-476E-B5E4-7669D6E76F1D} folder moved successfully. C:\Users\Christian\AppData\Local\{9A94926F-EE5B-4C2D-9F76-899302EDC3EF} folder moved successfully. C:\Users\Christian\AppData\Local\{9BA287F6-18EB-43B9-B5ED-C55CC3AA0A45} folder moved successfully. C:\Users\Christian\AppData\Local\{9CD46CAD-128B-4328-A649-8FE2E40F7A75} folder moved successfully. C:\Users\Christian\AppData\Local\{9CFDC041-7A5D-48B0-AD3E-F6B0973CEE5A} folder moved successfully. C:\Users\Christian\AppData\Local\{9D5A472F-E79F-4070-93B4-767B1480EA72} folder moved successfully. C:\Users\Christian\AppData\Local\{9D88E92D-8A95-4DC6-B07C-9B8296B64191} folder moved successfully. C:\Users\Christian\AppData\Local\{9D8A9A35-F460-472D-A5B6-6814139FAE6A} folder moved successfully. C:\Users\Christian\AppData\Local\{9DA4F222-1312-428A-AC46-479BAB552B70} folder moved successfully. C:\Users\Christian\AppData\Local\{9F0AC725-AFBD-40B3-92F4-65185ECDC706} folder moved successfully. C:\Users\Christian\AppData\Local\{9F45DF2D-E976-49CE-B36E-8783D5BAA461} folder moved successfully. C:\Users\Christian\AppData\Local\{9F49CB41-F4FD-4086-819C-6594F8271ADF} folder moved successfully. C:\Users\Christian\AppData\Local\{9F7BED0A-68CD-4E1D-B857-D9B136EA8425} folder moved successfully. C:\Users\Christian\AppData\Local\{A027B344-8BA7-4434-87C6-8EA07BA4166B} folder moved successfully. C:\Users\Christian\AppData\Local\{A030E5DA-27E0-44D3-9E1B-E378B73E05FC} folder moved successfully. C:\Users\Christian\AppData\Local\{A0446503-AC7F-4E60-8DA0-E5AB0C60AF86} folder moved successfully. C:\Users\Christian\AppData\Local\{A075BA28-A738-43CD-B327-04EF2F73B85C} folder moved successfully. C:\Users\Christian\AppData\Local\{A1FEA2AC-81A8-46F9-B7E5-89204FFCE2CD} folder moved successfully. C:\Users\Christian\AppData\Local\{A22AC089-F5E5-4961-AE06-D3D5627214E9} folder moved successfully. C:\Users\Christian\AppData\Local\{A28D8996-1885-4D71-9DE9-7F5B8CCFAED9} folder moved successfully. C:\Users\Christian\AppData\Local\{A338E0DA-1221-4E2D-8D55-4A0D1A7F0AE5} folder moved successfully. C:\Users\Christian\AppData\Local\{A34DF641-86BB-4CDC-A63D-2FC4F7929000} folder moved successfully. C:\Users\Christian\AppData\Local\{A4216F3D-3602-45A5-9F83-34FDFC655145} folder moved successfully. C:\Users\Christian\AppData\Local\{A488A60D-EE1E-432B-A9D6-373B1EBD37A6} folder moved successfully. C:\Users\Christian\AppData\Local\{A4BAF7A1-FF51-409B-B5E9-BE13D216D329} folder moved successfully. C:\Users\Christian\AppData\Local\{A52EE70E-0870-4D99-8626-6E43F5D7530D} folder moved successfully. C:\Users\Christian\AppData\Local\{A5903261-5458-4133-913F-61D6BF89D69A} folder moved successfully. C:\Users\Christian\AppData\Local\{A5B4CE67-947D-4F26-806E-4D9F9CF4A7BE} folder moved successfully. C:\Users\Christian\AppData\Local\{A6041317-CD3F-4794-9334-A566B474E509} folder moved successfully. C:\Users\Christian\AppData\Local\{A68AF949-3C59-4AE5-86E5-B6A76AED14A3} folder moved successfully. C:\Users\Christian\AppData\Local\{A7615695-BC51-4168-8637-DDE54938AE32} folder moved successfully. C:\Users\Christian\AppData\Local\{A784577F-AC5A-4CC7-9ABA-FC131EC63897} folder moved successfully. C:\Users\Christian\AppData\Local\{A7B291F6-5BD4-400A-88D5-A41D80722156} folder moved successfully. C:\Users\Christian\AppData\Local\{A8D34D08-1032-466D-9E63-9AF92F86C096} folder moved successfully. C:\Users\Christian\AppData\Local\{ABA3555C-5E72-4ABA-B850-2477CA13A568} folder moved successfully. C:\Users\Christian\AppData\Local\{AC9EE3FF-C099-4AB1-B65B-FC0E66D3587D} folder moved successfully. C:\Users\Christian\AppData\Local\{AE7E3699-471B-47B7-B8F2-41018E334861} folder moved successfully. C:\Users\Christian\AppData\Local\{AEB7DBEF-D1C4-4F93-A789-0C4063532FFA} folder moved successfully. C:\Users\Christian\AppData\Local\{AF18D99F-2049-4996-834E-3CE252216295} folder moved successfully. C:\Users\Christian\AppData\Local\{AF64B89C-0014-4037-88B2-C995B41918D3} folder moved successfully. C:\Users\Christian\AppData\Local\{B08925F2-C000-46B5-A521-51A2A66553A2} folder moved successfully. C:\Users\Christian\AppData\Local\{B0C144B4-8EB0-4F6B-9032-3563A137D62D} folder moved successfully. C:\Users\Christian\AppData\Local\{B189967C-344B-4500-A359-998B5C4E815F} folder moved successfully. C:\Users\Christian\AppData\Local\{B26F7D92-1332-4242-B8AC-1686DC49023D} folder moved successfully. C:\Users\Christian\AppData\Local\{B33B433A-C4A8-4CBE-9CCA-FBC1FC8D7182} folder moved successfully. C:\Users\Christian\AppData\Local\{B3803599-D42E-47BD-A70B-8D5C608E1ADB} folder moved successfully. C:\Users\Christian\AppData\Local\{B3942FD2-4E72-4C75-B90B-563CA7C2902D} folder moved successfully. C:\Users\Christian\AppData\Local\{B3DAE13F-1481-43DD-AE04-9D3F907C7696} folder moved successfully. C:\Users\Christian\AppData\Local\{B51A90B3-4453-435F-BA43-A832482116D0} folder moved successfully. C:\Users\Christian\AppData\Local\{B559A07C-593D-40AF-B8AF-CB63318EF7B6} folder moved successfully. C:\Users\Christian\AppData\Local\{B58A63B1-9ED8-47E7-AB52-4EA713A4F7CE} folder moved successfully. C:\Users\Christian\AppData\Local\{B5A5B607-497F-4A5A-98EA-CAD64F7CA391} folder moved successfully. C:\Users\Christian\AppData\Local\{B5B96551-514A-452F-8154-48D63F274130} folder moved successfully. C:\Users\Christian\AppData\Local\{B5CA66DD-3177-460D-9ACB-2D21A25380E8} folder moved successfully. C:\Users\Christian\AppData\Local\{B5F017E4-244F-4F88-82F7-394C3AF01647} folder moved successfully. C:\Users\Christian\AppData\Local\{B6448FA4-2DAD-47AD-A47E-A3D22D1C6CB6} folder moved successfully. C:\Users\Christian\AppData\Local\{B6ACE21E-C62E-4A8B-865C-E75005417074} folder moved successfully. C:\Users\Christian\AppData\Local\{B7341C8D-5277-4ECD-8061-CC86A0507D69} folder moved successfully. C:\Users\Christian\AppData\Local\{B82AE506-21FF-42C0-97BB-3BC965D9C399} folder moved successfully. C:\Users\Christian\AppData\Local\{B837D1F5-B1AE-45FE-A800-14536021E072} folder moved successfully. C:\Users\Christian\AppData\Local\{B86B1F68-3CB5-47A6-B1ED-CB75AE056A03} folder moved successfully. C:\Users\Christian\AppData\Local\{B8BE0A8E-A379-4115-8B1F-A772AAF2AB48} folder moved successfully. C:\Users\Christian\AppData\Local\{B926DAFE-EC82-4351-9C3F-3CCB45611858} folder moved successfully. C:\Users\Christian\AppData\Local\{B9CC6527-06BC-42A5-9788-9247273E5803} folder moved successfully. C:\Users\Christian\AppData\Local\{B9EF8720-CB1C-496A-A93E-F03193E088BE} folder moved successfully. C:\Users\Christian\AppData\Local\{BA90F085-59D1-4C0F-B4FE-0CEB50392492} folder moved successfully. C:\Users\Christian\AppData\Local\{BA9103A0-9833-4002-BFFE-4418245412FF} folder moved successfully. C:\Users\Christian\AppData\Local\{BC12877A-2C1B-4C00-9182-634E05E31688} folder moved successfully. C:\Users\Christian\AppData\Local\{BD513A21-2A09-4D58-BE88-F3406FB80734} folder moved successfully. C:\Users\Christian\AppData\Local\{BE054F1F-0AC9-42F3-B34E-99D726BBC938} folder moved successfully. C:\Users\Christian\AppData\Local\{BE983905-E248-4022-B86D-3D629D4CF13F} folder moved successfully. C:\Users\Christian\AppData\Local\{BED3D764-C0AC-4B48-9232-E04A111B2AD6} folder moved successfully. C:\Users\Christian\AppData\Local\{BF1E253E-41BA-4A49-B851-C9B887355612} folder moved successfully. C:\Users\Christian\AppData\Local\{BF716A51-4A8B-4A8C-A830-D1BEDD235ED2} folder moved successfully. C:\Users\Christian\AppData\Local\{BF882416-3C44-4FB1-9932-91FDCC302568} folder moved successfully. C:\Users\Christian\AppData\Local\{BFBB3EA2-5693-465B-A295-D58CDFE5E511} folder moved successfully. C:\Users\Christian\AppData\Local\{C025FD74-6225-4830-B742-3CFAA6EB361C} folder moved successfully. C:\Users\Christian\AppData\Local\{C13F1101-DAE0-4F61-8403-0313796F74FB} folder moved successfully. C:\Users\Christian\AppData\Local\{C1587E16-1AB8-4034-A5A4-1BC558DEF612} folder moved successfully. C:\Users\Christian\AppData\Local\{C190F3E7-C3DC-4937-867B-DE91B1A95DAD} folder moved successfully. C:\Users\Christian\AppData\Local\{C1A7B417-CBA1-468F-A81B-A73D79A26E4B} folder moved successfully. C:\Users\Christian\AppData\Local\{C246FFFB-9C76-4F7E-8AEE-B420CA6C94C7} folder moved successfully. C:\Users\Christian\AppData\Local\{C2828847-142F-4631-9868-56618AD39B0F} folder moved successfully. C:\Users\Christian\AppData\Local\{C2B8E1FF-A6E9-49AA-93BA-31826A58D51F} folder moved successfully. C:\Users\Christian\AppData\Local\{C2BB8914-2992-4337-9D12-0B9568F63136} folder moved successfully. C:\Users\Christian\AppData\Local\{C3838E36-A33B-4D17-BC0B-B874B275518D} folder moved successfully. C:\Users\Christian\AppData\Local\{C3A58C96-C7BB-469A-9691-42DD63AAA9A9} folder moved successfully. C:\Users\Christian\AppData\Local\{C3D7CF15-F070-404B-B223-C2639DFF3934} folder moved successfully. C:\Users\Christian\AppData\Local\{C4FF3CFD-CBCB-4DDF-A552-8A22F3E4B5B8} folder moved successfully. C:\Users\Christian\AppData\Local\{C63601A6-D7C1-4372-B9B6-91EA36B9B197} folder moved successfully. C:\Users\Christian\AppData\Local\{C717AE84-CF02-4129-963E-89B8AC45C590} folder moved successfully. C:\Users\Christian\AppData\Local\{C73ED8A0-2C6E-48BB-8929-8BCC030F7920} folder moved successfully. C:\Users\Christian\AppData\Local\{C828485D-EAC3-417F-A0B0-FBDF02D11641} folder moved successfully. C:\Users\Christian\AppData\Local\{C832D298-B460-435D-BFB9-0F34888DE884} folder moved successfully. C:\Users\Christian\AppData\Local\{C853C760-11B7-440A-B89F-47A18B22A8E9} folder moved successfully. C:\Users\Christian\AppData\Local\{C87F46E0-B1E7-4C90-B7F9-F4E49F8346B1} folder moved successfully. C:\Users\Christian\AppData\Local\{C8CC4423-F8DE-44E8-9EA7-29EAD0D39F31} folder moved successfully. C:\Users\Christian\AppData\Local\{C8E2190D-F5A3-478C-8D56-4E17E2521218} folder moved successfully. C:\Users\Christian\AppData\Local\{C8EEED1A-5524-4C21-9187-70E4AFD56674} folder moved successfully. C:\Users\Christian\AppData\Local\{C9E20A22-AB5B-4FF3-81DE-47CAD5F19127} folder moved successfully. C:\Users\Christian\AppData\Local\{CCF6C34B-9BA0-410E-91B1-8981AAF9F743} folder moved successfully. C:\Users\Christian\AppData\Local\{CD4C5DF1-88B2-4D3D-8092-205E63A0C12B} folder moved successfully. C:\Users\Christian\AppData\Local\{CD56B37A-B051-43F4-BA15-E19AC53A6A0C} folder moved successfully. C:\Users\Christian\AppData\Local\{CDBA5185-E0D7-45E9-BCF5-E5A15F503954} folder moved successfully. C:\Users\Christian\AppData\Local\{CE2DA560-A606-4379-83A2-88BDAB574AE9} folder moved successfully. C:\Users\Christian\AppData\Local\{CF7951FC-B386-48BF-AF7D-8EFA00848A8F} folder moved successfully. C:\Users\Christian\AppData\Local\{CFCBC6FD-872C-4EEC-9BC4-2BA07CC69853} folder moved successfully. C:\Users\Christian\AppData\Local\{CFD38B6F-FE17-43C9-A7CF-C9949D7B5740} folder moved successfully. C:\Users\Christian\AppData\Local\{D0F12E09-4958-492D-844F-27C59F1CFD97} folder moved successfully. C:\Users\Christian\AppData\Local\{D1CEED03-1D73-4860-B87E-A56F3EB51FAF} folder moved successfully. C:\Users\Christian\AppData\Local\{D2F949EB-15BC-46AE-8FDA-2394542FBC80} folder moved successfully. C:\Users\Christian\AppData\Local\{D32AE833-5B33-43FA-9BFF-F9F39EF1ACAD} folder moved successfully. C:\Users\Christian\AppData\Local\{D351AACF-B814-46FF-858A-E359AE37A544} folder moved successfully. C:\Users\Christian\AppData\Local\{D392A9AC-BB2F-44B3-8F9E-DCC42D729B42} folder moved successfully. C:\Users\Christian\AppData\Local\{D3F346B3-852B-4EB3-8776-F2A175D35771} folder moved successfully. C:\Users\Christian\AppData\Local\{D4C99F68-34B3-4B0B-85A1-D737DC265BD0} folder moved successfully. C:\Users\Christian\AppData\Local\{D4D33A6B-8F79-45B0-9752-71BD0BE427C1} folder moved successfully. C:\Users\Christian\AppData\Local\{D5289D44-BC3F-487A-B50E-70B19B9142C7} folder moved successfully. C:\Users\Christian\AppData\Local\{D58B6324-612C-48C3-ADF1-2EA1DB96E5E3} folder moved successfully. C:\Users\Christian\AppData\Local\{D5950A37-89A5-43A3-B1CF-095119F0C6D1} folder moved successfully. C:\Users\Christian\AppData\Local\{D5FEFCD8-39B2-4E03-B47F-2A521F8D0C8A} folder moved successfully. C:\Users\Christian\AppData\Local\{D67B3056-742C-4F50-860D-F685A4CAC712} folder moved successfully. C:\Users\Christian\AppData\Local\{D77C9A5B-8337-482B-96E8-F7F19B011302} folder moved successfully. C:\Users\Christian\AppData\Local\{D7E0A694-0EE3-43F8-9270-2EDFC65A4AE7} folder moved successfully. C:\Users\Christian\AppData\Local\{D8611D9B-C433-4288-BF21-8F9E15FB9453} folder moved successfully. C:\Users\Christian\AppData\Local\{D8660A8E-0BCF-463C-867E-63A512E47EA1} folder moved successfully. C:\Users\Christian\AppData\Local\{D8D4157A-61E6-4065-9203-31E9B9F8A53C} folder moved successfully. C:\Users\Christian\AppData\Local\{D8F48545-4544-4794-A5A6-63B839BA2723} folder moved successfully. C:\Users\Christian\AppData\Local\{D9628E2E-C9D8-48EA-A719-C8D6909A51E6} folder moved successfully. C:\Users\Christian\AppData\Local\{D9B811D4-A54E-404E-B34D-E8EF13E9566B} folder moved successfully. C:\Users\Christian\AppData\Local\{D9EA72E1-2B25-4597-880D-F071191F97BB} folder moved successfully. C:\Users\Christian\AppData\Local\{DA9130EA-B013-4E6B-BCE9-BAFA2BC7B0AF} folder moved successfully. C:\Users\Christian\AppData\Local\{DB26D550-FDD3-4F99-AD74-EFA985B32130} folder moved successfully. C:\Users\Christian\AppData\Local\{DBC9DD2F-AE6A-4BBF-871F-B7D8A3FBBCC6} folder moved successfully. C:\Users\Christian\AppData\Local\{DC784CEA-C5F7-4DD5-98C5-752053972509} folder moved successfully. C:\Users\Christian\AppData\Local\{DCD13A33-E3DA-400C-A5DB-B7A008C494EE} folder moved successfully. C:\Users\Christian\AppData\Local\{DD6360BC-EA82-4FDC-86C7-5C29A2F56DD7} folder moved successfully. C:\Users\Christian\AppData\Local\{DE3FF879-671B-4710-A319-0E9E26633801} folder moved successfully. C:\Users\Christian\AppData\Local\{DE930E47-2241-4D3A-A43E-873471536B6D} folder moved successfully. C:\Users\Christian\AppData\Local\{DEF44407-D912-4FDF-8C88-B9FF2F56293C} folder moved successfully. C:\Users\Christian\AppData\Local\{DFDE7001-1F6A-4DBC-84EA-77C4D85719A4} folder moved successfully. C:\Users\Christian\AppData\Local\{E0870B80-D3F0-4D8D-8DFB-1BD1B8FEF59A} folder moved successfully. C:\Users\Christian\AppData\Local\{E1403B31-7636-44F8-9DD9-FD6B1020E45B} folder moved successfully. C:\Users\Christian\AppData\Local\{E150C20B-9AC0-4695-9C9B-3026A65AD33F} folder moved successfully. C:\Users\Christian\AppData\Local\{E17A4A4C-A6D4-4000-BEDA-08DB1EB5F44E} folder moved successfully. C:\Users\Christian\AppData\Local\{E1ED2B89-ACEE-498E-9488-20A91DF817D3} folder moved successfully. C:\Users\Christian\AppData\Local\{E254D801-A31E-4F3D-8A5C-438CB482B23D} folder moved successfully. C:\Users\Christian\AppData\Local\{E2793FF7-A854-4E82-B1F8-42D201C018AD} folder moved successfully. C:\Users\Christian\AppData\Local\{E2ABB98F-B765-40FA-8C4D-1B991D07A49A} folder moved successfully. C:\Users\Christian\AppData\Local\{E2F8AC9C-1A82-4625-8F2B-059EA3ED4CF2} folder moved successfully. C:\Users\Christian\AppData\Local\{E3EB01A8-6DF9-4F88-97E5-F99AE2299D22} folder moved successfully. C:\Users\Christian\AppData\Local\{E43DFFC2-C4A6-4144-9354-085AE754B059} folder moved successfully. C:\Users\Christian\AppData\Local\{E46D71AD-4419-4415-BD65-4A85F24DA720} folder moved successfully. C:\Users\Christian\AppData\Local\{E56A46FC-EB33-45B1-A710-7B6718C15B4F} folder moved successfully. C:\Users\Christian\AppData\Local\{E6226C86-27FB-4C70-9331-986FADFB4265} folder moved successfully. C:\Users\Christian\AppData\Local\{E6281AE8-3D13-40A8-BECE-F0204F21BAC1} folder moved successfully. C:\Users\Christian\AppData\Local\{E655C10F-69C6-4C95-9B0E-BDD5F4E55468} folder moved successfully. C:\Users\Christian\AppData\Local\{E76B8994-DEE4-4A76-B08E-5C8160303876} folder moved successfully. C:\Users\Christian\AppData\Local\{E7952C05-24E1-46FB-8365-912E89DCEF18} folder moved successfully. C:\Users\Christian\AppData\Local\{E88AC612-3CC1-43F7-99BF-B9BC96ACB376} folder moved successfully. C:\Users\Christian\AppData\Local\{E88DBC9B-5A31-4FC2-AD32-4D80DF611D44} folder moved successfully. C:\Users\Christian\AppData\Local\{E8C6269F-C2D9-4AF3-9195-BE58A50C8547} folder moved successfully. C:\Users\Christian\AppData\Local\{EAC78821-5968-4C99-98ED-FC01580AF51F} folder moved successfully. C:\Users\Christian\AppData\Local\{EBB3F83F-BB55-4068-A830-812AB19BF35C} folder moved successfully. C:\Users\Christian\AppData\Local\{EC022B39-1792-41ED-99A9-A87BAC8E4FF1} folder moved successfully. C:\Users\Christian\AppData\Local\{EC6C3211-6CDE-4A45-A1F9-97F90AF9D2DB} folder moved successfully. C:\Users\Christian\AppData\Local\{ED28FC12-76E3-4D67-804E-BB1C27D47C46} folder moved successfully. C:\Users\Christian\AppData\Local\{ED2A820D-617F-4864-B412-E621A5B6528C} folder moved successfully. C:\Users\Christian\AppData\Local\{ED98DA83-2D83-4C73-A3FC-4C69EE1CE526} folder moved successfully. C:\Users\Christian\AppData\Local\{EE13D55D-1511-46B2-8CA3-465FC087813B} folder moved successfully. C:\Users\Christian\AppData\Local\{EE16D0A0-BD66-4586-8819-37075E358308} folder moved successfully. C:\Users\Christian\AppData\Local\{EECB199F-ABA8-4B06-9B11-44303A64B2DE} folder moved successfully. C:\Users\Christian\AppData\Local\{EF869C9B-0272-484F-8FBE-28AB64E68AB8} folder moved successfully. C:\Users\Christian\AppData\Local\{F0327F5A-D5A7-4192-B9B5-BFA02460D1C4} folder moved successfully. C:\Users\Christian\AppData\Local\{F0B1D3EB-8EC7-4A48-A131-8724090F910E} folder moved successfully. C:\Users\Christian\AppData\Local\{F0BCB514-0B42-482D-A95A-E918981DD76F} folder moved successfully. C:\Users\Christian\AppData\Local\{F22AF967-EA74-42CC-A786-14CE0045C694} folder moved successfully. C:\Users\Christian\AppData\Local\{F262040E-09F2-45DC-A36A-922B779D92EE} folder moved successfully. C:\Users\Christian\AppData\Local\{F2CEA5DA-83A3-455B-ADC5-B6C4BD962128} folder moved successfully. C:\Users\Christian\AppData\Local\{F37475E6-8CF8-41A6-92BC-8F26C45FCA74} folder moved successfully. C:\Users\Christian\AppData\Local\{F3A565B1-A132-461F-B84A-C56F5BCBCC08} folder moved successfully. C:\Users\Christian\AppData\Local\{F3AE7132-A49C-4698-9E9F-028D75AF0E53} folder moved successfully. C:\Users\Christian\AppData\Local\{F4447EAA-24AC-454F-A201-25070B392EB8} folder moved successfully. C:\Users\Christian\AppData\Local\{F4457611-2266-49A2-BED4-0553E0332B42} folder moved successfully. C:\Users\Christian\AppData\Local\{F490A84D-1B9B-463D-92F3-84298C50167F} folder moved successfully. C:\Users\Christian\AppData\Local\{F545AA3D-56D2-4CA1-86C5-E972202D5FF8} folder moved successfully. C:\Users\Christian\AppData\Local\{F647B220-8327-4A63-AB04-8273533E1BBD} folder moved successfully. C:\Users\Christian\AppData\Local\{F66DA19E-4010-4D56-8199-104AB7104EBD} folder moved successfully. C:\Users\Christian\AppData\Local\{F6E2CCD9-CC9E-4597-83E2-08C8F0D25635} folder moved successfully. C:\Users\Christian\AppData\Local\{F7025C39-DD92-4BC2-A47C-575AC97752DA} folder moved successfully. C:\Users\Christian\AppData\Local\{F72D20EF-1C59-457A-9FB1-62C3606F1B8B} folder moved successfully. C:\Users\Christian\AppData\Local\{F73191AF-D0A8-45B1-BD09-325D71D6688A} folder moved successfully. C:\Users\Christian\AppData\Local\{F8243C51-1A9B-454A-8B60-05B3378E3380} folder moved successfully. C:\Users\Christian\AppData\Local\{F8865FF6-A34E-46D1-A8EE-F35475CDB4C7} folder moved successfully. C:\Users\Christian\AppData\Local\{FA1C1ADF-2D12-43CE-8DE3-EF06F0131E43} folder moved successfully. C:\Users\Christian\AppData\Local\{FA3EF43D-FF38-4911-8305-F19A552BA2B1} folder moved successfully. C:\Users\Christian\AppData\Local\{FB2EF0A0-F027-4FEC-8DCD-73AEDBC89829} folder moved successfully. C:\Users\Christian\AppData\Local\{FBFA1D70-6352-4ED7-897C-485CEAB65606} folder moved successfully. C:\Users\Christian\AppData\Local\{FC0BD9BE-59BA-4932-B9E9-8E743F72A1A3} folder moved successfully. C:\Users\Christian\AppData\Local\{FCD81F10-C237-485F-82A4-22A80F531523} folder moved successfully. C:\Users\Christian\AppData\Local\{FCF292AC-9AC8-4B2F-B571-A0EB945000A7} folder moved successfully. C:\Users\Christian\AppData\Local\{FEA4B26B-F362-4F18-9472-482DA393A5D8} folder moved successfully. C:\Users\Christian\AppData\Local\{FF6A934D-0DA3-435E-8ED4-2C94818133FA} folder moved successfully. C:\Users\Christian\AppData\Local\{FF6B2C73-B698-4167-886E-C8B6DDFE0682} folder moved successfully. C:\Users\Christian\AppData\Local\{FFD2C7BC-4A60-4412-A95B-A61F426FD048} folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\splash folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully. C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Christian\Desktop\cmd.bat deleted successfully. C:\Users\Christian\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Christian ->Temp folder emptied: 1464766596 bytes ->Temporary Internet Files folder emptied: 2120910516 bytes ->FireFox cache emptied: 633733936 bytes ->Flash cache emptied: 50011 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: UpdatusUser User: UpdatusUser.Christian-PC ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 389691976 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes RecycleBin emptied: 110177128 bytes Total Files Cleaned = 4.501,00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.61.3 log created on 09102012_214105 Files\Folders moved on Reboot... C:\Users\Christian\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Windows\temp\mcafee_yRlx5QOmKorl9gU not found! PendingFileRenameOperations files... Registry entries deleted on Reboot... |
10.09.2012, 22:03 | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Cyber Crime Investigation Department Österreich - Trojaner Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm! Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet, Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs. Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!
__________________ Logfiles bitte immer in CODE-Tags posten |
11.09.2012, 14:23 | #21 |
| Cyber Crime Investigation Department Österreich - Trojaner Hier das Log vom TDSS-Killer: Code:
ATTFilter 15:20:16.0946 5156 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48 15:20:17.0121 5156 ============================================================ 15:20:17.0121 5156 Current date / time: 2012/09/11 15:20:17.0121 15:20:17.0121 5156 SystemInfo: 15:20:17.0121 5156 15:20:17.0121 5156 OS Version: 6.1.7601 ServicePack: 1.0 15:20:17.0121 5156 Product type: Workstation 15:20:17.0121 5156 ComputerName: CHRISTIAN-PC 15:20:17.0121 5156 UserName: Christian 15:20:17.0121 5156 Windows directory: C:\Windows 15:20:17.0121 5156 System windows directory: C:\Windows 15:20:17.0121 5156 Running under WOW64 15:20:17.0121 5156 Processor architecture: Intel x64 15:20:17.0121 5156 Number of processors: 8 15:20:17.0121 5156 Page size: 0x1000 15:20:17.0121 5156 Boot type: Normal boot 15:20:17.0121 5156 ============================================================ 15:20:17.0677 5156 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 15:20:17.0697 5156 ============================================================ 15:20:17.0697 5156 \Device\Harddisk0\DR0: 15:20:17.0697 5156 MBR partitions: 15:20:17.0697 5156 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x34000, BlocksNum 0x2710000 15:20:17.0697 5156 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x2744000, BlocksNum 0x54E01EF0 15:20:17.0697 5156 ============================================================ 15:20:17.0729 5156 C: <-> \Device\Harddisk0\DR0\Partition2 15:20:17.0730 5156 ============================================================ 15:20:17.0730 5156 Initialize success 15:20:17.0730 5156 ============================================================ 15:20:57.0149 7604 ============================================================ 15:20:57.0149 7604 Scan started 15:20:57.0149 7604 Mode: Manual; SigCheck; TDLFS; 15:20:57.0149 7604 ============================================================ 15:21:00.0470 7604 ================ Scan system memory ======================== 15:21:00.0470 7604 System memory - ok 15:21:00.0471 7604 ================ Scan services ============================= 15:21:02.0207 7604 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 15:21:02.0290 7604 1394ohci - ok 15:21:02.0372 7604 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 15:21:02.0409 7604 ACPI - ok 15:21:02.0569 7604 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 15:21:02.0889 7604 AcpiPmi - ok 15:21:03.0393 7604 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 15:21:03.0408 7604 AdobeARMservice - ok 15:21:03.0531 7604 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 15:21:03.0549 7604 adp94xx - ok 15:21:03.0648 7604 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys 15:21:03.0664 7604 adpahci - ok 15:21:03.0749 7604 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 15:21:03.0765 7604 adpu320 - ok 15:21:03.0886 7604 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 15:21:05.0526 7604 AeLookupSvc - ok 15:21:05.0868 7604 [ D1E343BC00136CE03C4D403194D06A80 ] AERTFilters C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe 15:21:05.0879 7604 AERTFilters - ok 15:21:05.0963 7604 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 15:21:06.0075 7604 AFD - ok 15:21:06.0313 7604 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 15:21:06.0325 7604 agp440 - ok 15:21:06.0373 7604 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 15:21:06.0492 7604 ALG - ok 15:21:06.0568 7604 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 15:21:06.0583 7604 aliide - ok 15:21:06.0609 7604 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 15:21:06.0626 7604 amdide - ok 15:21:06.0864 7604 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 15:21:06.0969 7604 AmdK8 - ok 15:21:06.0988 7604 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 15:21:07.0020 7604 AmdPPM - ok 15:21:07.0090 7604 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 15:21:07.0101 7604 amdsata - ok 15:21:07.0151 7604 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 15:21:07.0164 7604 amdsbs - ok 15:21:07.0183 7604 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 15:21:07.0192 7604 amdxata - ok 15:21:07.0321 7604 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 15:21:09.0244 7604 AppID - ok 15:21:09.0335 7604 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 15:21:09.0385 7604 AppIDSvc - ok 15:21:09.0455 7604 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 15:21:09.0515 7604 Appinfo - ok 15:21:09.0603 7604 [ F401929EE0CC92BFE7F15161CA535383 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 15:21:09.0654 7604 Apple Mobile Device - ok 15:21:09.0770 7604 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll 15:21:09.0819 7604 AppMgmt - ok 15:21:09.0883 7604 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys 15:21:09.0894 7604 arc - ok 15:21:09.0931 7604 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys 15:21:09.0942 7604 arcsas - ok 15:21:10.0032 7604 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 15:21:10.0170 7604 aspnet_state - ok 15:21:10.0189 7604 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 15:21:10.0234 7604 AsyncMac - ok 15:21:10.0276 7604 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 15:21:10.0285 7604 atapi - ok 15:21:10.0519 7604 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 15:21:10.0584 7604 AudioEndpointBuilder - ok 15:21:10.0602 7604 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 15:21:10.0635 7604 AudioSrv - ok 15:21:10.0650 7604 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 15:21:10.0717 7604 AxInstSV - ok 15:21:10.0747 7604 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 15:21:10.0783 7604 b06bdrv - ok 15:21:10.0889 7604 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 15:21:10.0947 7604 b57nd60a - ok 15:21:11.0021 7604 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 15:21:11.0100 7604 BDESVC - ok 15:21:11.0148 7604 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 15:21:11.0196 7604 Beep - ok 15:21:11.0231 7604 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 15:21:11.0283 7604 BFE - ok 15:21:11.0312 7604 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 15:21:11.0369 7604 BITS - ok 15:21:11.0391 7604 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 15:21:11.0414 7604 blbdrive - ok 15:21:11.0612 7604 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 15:21:11.0624 7604 Bonjour Service - ok 15:21:11.0722 7604 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 15:21:11.0745 7604 bowser - ok 15:21:11.0778 7604 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 15:21:11.0798 7604 BrFiltLo - ok 15:21:11.0812 7604 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 15:21:11.0825 7604 BrFiltUp - ok 15:21:11.0865 7604 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 15:21:11.0898 7604 Browser - ok 15:21:11.0911 7604 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 15:21:11.0964 7604 Brserid - ok 15:21:11.0978 7604 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 15:21:12.0005 7604 BrSerWdm - ok 15:21:12.0035 7604 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 15:21:12.0084 7604 BrUsbMdm - ok 15:21:12.0102 7604 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 15:21:12.0145 7604 BrUsbSer - ok 15:21:12.0287 7604 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys 15:21:12.0332 7604 BthEnum - ok 15:21:12.0344 7604 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 15:21:12.0367 7604 BTHMODEM - ok 15:21:12.0383 7604 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 15:21:12.0405 7604 BthPan - ok 15:21:12.0461 7604 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys 15:21:12.0494 7604 BTHPORT - ok 15:21:12.0528 7604 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 15:21:12.0558 7604 bthserv - ok 15:21:12.0595 7604 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys 15:21:12.0637 7604 BTHUSB - ok 15:21:12.0779 7604 [ 40C6FEC49D1CC4D112368A2BCD2BCBB7 ] btmhsf C:\Windows\system32\DRIVERS\btmhsf.sys 15:21:12.0813 7604 btmhsf - ok 15:21:12.0845 7604 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 15:21:12.0905 7604 cdfs - ok 15:21:12.0934 7604 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 15:21:12.0948 7604 cdrom - ok 15:21:12.0977 7604 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 15:21:13.0023 7604 CertPropSvc - ok 15:21:13.0038 7604 [ 274CE03459896006F7A5069266E0469E ] cfwids C:\Windows\system32\drivers\cfwids.sys 15:21:13.0100 7604 cfwids - ok 15:21:13.0118 7604 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys 15:21:13.0139 7604 circlass - ok 15:21:13.0159 7604 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 15:21:13.0175 7604 CLFS - ok 15:21:13.0384 7604 [ BB86F147B2A7152E4B4D71A2F0A87D41 ] CLKMSVC10_9EC60124 C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe 15:21:13.0397 7604 CLKMSVC10_9EC60124 - ok 15:21:13.0581 7604 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 15:21:13.0592 7604 clr_optimization_v2.0.50727_32 - ok 15:21:13.0616 7604 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 15:21:13.0628 7604 clr_optimization_v2.0.50727_64 - ok 15:21:13.0684 7604 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 15:21:13.0978 7604 clr_optimization_v4.0.30319_32 - ok 15:21:14.0061 7604 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 15:21:14.0088 7604 clr_optimization_v4.0.30319_64 - ok 15:21:14.0139 7604 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 15:21:14.0160 7604 CmBatt - ok 15:21:14.0169 7604 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 15:21:14.0180 7604 cmdide - ok 15:21:14.0209 7604 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 15:21:14.0237 7604 CNG - ok 15:21:14.0259 7604 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 15:21:14.0268 7604 Compbatt - ok 15:21:14.0279 7604 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys 15:21:14.0304 7604 CompositeBus - ok 15:21:14.0316 7604 COMSysApp - ok 15:21:14.0333 7604 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 15:21:14.0343 7604 crcdisk - ok 15:21:14.0380 7604 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\Windows\system32\cryptsvc.dll 15:21:14.0402 7604 CryptSvc - ok 15:21:14.0506 7604 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys 15:21:14.0583 7604 CSC - ok 15:21:14.0745 7604 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll 15:21:14.0778 7604 CscService - ok 15:21:14.0810 7604 [ BC3D4F90978CD7C8EABD1BAF3BF7873A ] CtClsFlt C:\Windows\system32\DRIVERS\CtClsFlt.sys 15:21:14.0835 7604 CtClsFlt - ok 15:21:14.0877 7604 [ 7AF9DAC504FBD047CBC3E64AE52C92BF ] dc3d C:\Windows\system32\DRIVERS\dc3d.sys 15:21:14.0906 7604 dc3d - ok 15:21:14.0946 7604 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 15:21:14.0990 7604 DcomLaunch - ok 15:21:15.0077 7604 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 15:21:15.0125 7604 defragsvc - ok 15:21:15.0152 7604 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 15:21:15.0209 7604 DfsC - ok 15:21:15.0292 7604 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 15:21:15.0345 7604 Dhcp - ok 15:21:15.0361 7604 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 15:21:15.0396 7604 discache - ok 15:21:15.0427 7604 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys 15:21:15.0438 7604 Disk - ok 15:21:15.0469 7604 [ 5DB085A8A6600BE6401F2B24EECB5415 ] dmvsc C:\Windows\system32\drivers\dmvsc.sys 15:21:15.0495 7604 dmvsc - ok 15:21:15.0515 7604 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 15:21:15.0547 7604 Dnscache - ok 15:21:15.0575 7604 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 15:21:15.0615 7604 dot3svc - ok 15:21:15.0668 7604 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 15:21:15.0725 7604 DPS - ok 15:21:15.0788 7604 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 15:21:15.0829 7604 drmkaud - ok 15:21:15.0946 7604 [ 46571ED73AE84469DCA53081D33CF3C8 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys 15:21:15.0958 7604 dtsoftbus01 - ok 15:21:15.0992 7604 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 15:21:16.0012 7604 DXGKrnl - ok 15:21:16.0047 7604 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 15:21:16.0085 7604 EapHost - ok 15:21:17.0184 7604 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys 15:21:17.0388 7604 ebdrv - ok 15:21:17.0412 7604 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 15:21:17.0466 7604 EFS - ok 15:21:17.0608 7604 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 15:21:17.0699 7604 ehRecvr - ok 15:21:17.0720 7604 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 15:21:17.0738 7604 ehSched - ok 15:21:17.0772 7604 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys 15:21:17.0791 7604 elxstor - ok 15:21:17.0812 7604 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 15:21:17.0845 7604 ErrDev - ok 15:21:17.0903 7604 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 15:21:17.0960 7604 EventSystem - ok 15:21:18.0305 7604 [ 8B6C9924B0D333DBF76086B8258A0891 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe 15:21:18.0356 7604 EvtEng - ok 15:21:18.0407 7604 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 15:21:18.0439 7604 exfat - ok 15:21:18.0498 7604 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 15:21:18.0543 7604 fastfat - ok 15:21:18.0602 7604 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 15:21:18.0694 7604 Fax - ok 15:21:18.0738 7604 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys 15:21:18.0760 7604 fdc - ok 15:21:18.0786 7604 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 15:21:18.0832 7604 fdPHost - ok 15:21:18.0859 7604 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 15:21:18.0905 7604 FDResPub - ok 15:21:18.0982 7604 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 15:21:18.0995 7604 FileInfo - ok 15:21:19.0006 7604 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 15:21:19.0050 7604 Filetrace - ok 15:21:19.0076 7604 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 15:21:19.0092 7604 flpydisk - ok 15:21:19.0122 7604 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 15:21:19.0135 7604 FltMgr - ok 15:21:19.0286 7604 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 15:21:19.0377 7604 FontCache - ok 15:21:19.0463 7604 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 15:21:19.0474 7604 FontCache3.0.0.0 - ok 15:21:19.0544 7604 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 15:21:19.0560 7604 FsDepends - ok 15:21:19.0635 7604 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 15:21:19.0644 7604 Fs_Rec - ok 15:21:19.0713 7604 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 15:21:19.0750 7604 fvevol - ok 15:21:19.0788 7604 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 15:21:19.0805 7604 gagp30kx - ok 15:21:19.0867 7604 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 15:21:19.0875 7604 GEARAspiWDM - ok 15:21:20.0076 7604 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 15:21:20.0131 7604 gpsvc - ok 15:21:20.0192 7604 [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys 15:21:20.0209 7604 hamachi - ok 15:21:20.0257 7604 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 15:21:20.0314 7604 hcw85cir - ok 15:21:20.0403 7604 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 15:21:20.0430 7604 HdAudAddService - ok 15:21:20.0490 7604 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 15:21:20.0522 7604 HDAudBus - ok 15:21:20.0559 7604 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 15:21:20.0590 7604 HidBatt - ok 15:21:20.0603 7604 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys 15:21:20.0633 7604 HidBth - ok 15:21:20.0684 7604 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys 15:21:20.0702 7604 HidIr - ok 15:21:20.0754 7604 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll 15:21:20.0782 7604 hidserv - ok 15:21:20.0851 7604 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 15:21:20.0864 7604 HidUsb - ok 15:21:20.0882 7604 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 15:21:20.0938 7604 hkmsvc - ok 15:21:20.0970 7604 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 15:21:21.0021 7604 HomeGroupListener - ok 15:21:21.0098 7604 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 15:21:21.0118 7604 HomeGroupProvider - ok 15:21:21.0164 7604 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 15:21:21.0176 7604 HpSAMD - ok 15:21:21.0319 7604 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 15:21:21.0407 7604 HTTP - ok 15:21:21.0543 7604 [ 8F9B0FC4EC3A8194BD4CBC5ED3E7ABEB ] hwdatacard C:\Windows\system32\DRIVERS\ewusbmdm.sys 15:21:21.0573 7604 hwdatacard - ok 15:21:21.0598 7604 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 15:21:21.0607 7604 hwpolicy - ok 15:21:21.0752 7604 [ 230C041AF8DF1D2308C3AC5146E3FF4F ] hwusbdev C:\Windows\system32\DRIVERS\ewusbdev.sys 15:21:21.0813 7604 hwusbdev - ok 15:21:21.0864 7604 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 15:21:21.0876 7604 i8042prt - ok 15:21:21.0990 7604 [ D469B77687E12FE43E344806740B624D ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys 15:21:22.0003 7604 iaStor - ok 15:21:22.0087 7604 [ 983FC69644DDF0486C8DFEA262948D1A ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe 15:21:22.0096 7604 IAStorDataMgrSvc - ok 15:21:22.0187 7604 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 15:21:22.0212 7604 iaStorV - ok 15:21:22.0247 7604 [ FC47F5CF561BF0FD897EFD1A9604DCCF ] iBtFltCoex C:\Windows\system32\DRIVERS\iBtFltCoex.sys 15:21:22.0300 7604 iBtFltCoex - ok 15:21:22.0480 7604 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe 15:21:22.0489 7604 IDriverT ( UnsignedFile.Multi.Generic ) - warning 15:21:22.0490 7604 IDriverT - detected UnsignedFile.Multi.Generic (1) 15:21:22.0652 7604 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 15:21:22.0701 7604 idsvc - ok 15:21:24.0159 7604 [ 0AC9E321D604BE48A0D72B69BA484BDC ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 15:21:24.0558 7604 igfx - ok 15:21:24.0606 7604 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys 15:21:24.0618 7604 iirsp - ok 15:21:24.0742 7604 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 15:21:24.0811 7604 IKEEXT - ok 15:21:25.0382 7604 [ A9853214CC97796579D75B1F59C51DCD ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 15:21:25.0422 7604 IntcAzAudAddService - ok 15:21:25.0537 7604 [ FC727061C0F47C8059E88E05D5C8E381 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys 15:21:25.0590 7604 IntcDAud - ok 15:21:25.0638 7604 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 15:21:25.0651 7604 intelide - ok 15:21:25.0685 7604 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 15:21:25.0714 7604 intelppm - ok 15:21:25.0767 7604 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 15:21:25.0819 7604 IPBusEnum - ok 15:21:25.0845 7604 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 15:21:25.0874 7604 IpFilterDriver - ok 15:21:26.0052 7604 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 15:21:26.0144 7604 iphlpsvc - ok 15:21:26.0217 7604 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 15:21:26.0253 7604 IPMIDRV - ok 15:21:26.0270 7604 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 15:21:26.0325 7604 IPNAT - ok 15:21:26.0587 7604 [ A9AB99EE7D39725EAFEC82732D2B3271 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 15:21:26.0605 7604 iPod Service - ok 15:21:26.0667 7604 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 15:21:26.0727 7604 IRENUM - ok 15:21:26.0746 7604 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 15:21:26.0760 7604 isapnp - ok 15:21:26.0817 7604 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 15:21:26.0858 7604 iScsiPrt - ok 15:21:26.0881 7604 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 15:21:26.0891 7604 kbdclass - ok 15:21:26.0938 7604 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 15:21:26.0990 7604 kbdhid - ok 15:21:27.0063 7604 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 15:21:27.0074 7604 KeyIso - ok 15:21:27.0131 7604 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 15:21:27.0143 7604 KSecDD - ok 15:21:27.0171 7604 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 15:21:27.0183 7604 KSecPkg - ok 15:21:27.0242 7604 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 15:21:27.0312 7604 ksthunk - ok 15:21:27.0422 7604 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 15:21:27.0471 7604 KtmRm - ok 15:21:27.0554 7604 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll 15:21:27.0600 7604 LanmanServer - ok 15:21:27.0645 7604 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 15:21:27.0694 7604 LanmanWorkstation - ok 15:21:29.0225 7604 [ 20CDB07017497C94A0BAD253C4BAFCBC ] LkCitadelServer C:\Windows\SysWOW64\lkcitdl.exe 15:21:29.0242 7604 LkCitadelServer - ok 15:21:29.0337 7604 [ 99121FD465F7A65AC15EEC3B4034C1E4 ] lkClassAds C:\Windows\SysWOW64\lkads.exe 15:21:29.0347 7604 lkClassAds - ok 15:21:29.0380 7604 [ 19C8D1B03A5229CBBE1037425701F55F ] lkTimeSync C:\Windows\SysWOW64\lktsrv.exe 15:21:29.0389 7604 lkTimeSync - ok 15:21:29.0432 7604 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 15:21:29.0485 7604 lltdio - ok 15:21:29.0561 7604 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 15:21:29.0593 7604 lltdsvc - ok 15:21:29.0633 7604 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 15:21:29.0680 7604 lmhosts - ok 15:21:29.0887 7604 [ 7F32D4C47A50E7223491E8FB9359907D ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 15:21:29.0989 7604 LMS - ok 15:21:30.0059 7604 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 15:21:30.0071 7604 LSI_FC - ok 15:21:30.0175 7604 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 15:21:30.0186 7604 LSI_SAS - ok 15:21:30.0255 7604 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 15:21:30.0268 7604 LSI_SAS2 - ok 15:21:30.0291 7604 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 15:21:30.0303 7604 LSI_SCSI - ok 15:21:30.0415 7604 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 15:21:30.0451 7604 luafv - ok 15:21:30.0722 7604 [ F48571922079BBAB289C57BAFEFE88F3 ] McAWFwk c:\PROGRA~1\mcafee\msc\mcawfwk.exe 15:21:30.0735 7604 McAWFwk - ok 15:21:30.0825 7604 [ ACB01BF1A905356AB7F978C7FE852209 ] McMPFSvc C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 15:21:30.0837 7604 McMPFSvc - ok 15:21:30.0841 7604 [ ACB01BF1A905356AB7F978C7FE852209 ] mcmscsvc C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 15:21:30.0853 7604 mcmscsvc - ok 15:21:30.0862 7604 [ ACB01BF1A905356AB7F978C7FE852209 ] McNaiAnn C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 15:21:30.0873 7604 McNaiAnn - ok 15:21:30.0896 7604 [ ACB01BF1A905356AB7F978C7FE852209 ] McNASvc C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 15:21:30.0907 7604 McNASvc - ok 15:21:31.0126 7604 [ 44D0DA102FA7A1BE22FD7499E80DCF9B ] McODS C:\Program Files\McAfee\VirusScan\mcods.exe 15:21:31.0153 7604 McODS - ok 15:21:31.0182 7604 [ ACB01BF1A905356AB7F978C7FE852209 ] McOobeSv C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 15:21:31.0194 7604 McOobeSv - ok 15:21:31.0199 7604 [ ACB01BF1A905356AB7F978C7FE852209 ] McProxy C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 15:21:31.0210 7604 McProxy - ok 15:21:31.0265 7604 [ E998E3B12101288D716558466CBF6AE1 ] McShield C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe 15:21:31.0277 7604 McShield - ok 15:21:31.0298 7604 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 15:21:31.0321 7604 Mcx2Svc - ok 15:21:31.0350 7604 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys 15:21:31.0361 7604 megasas - ok 15:21:31.0428 7604 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 15:21:31.0446 7604 MegaSR - ok 15:21:31.0474 7604 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 15:21:31.0483 7604 MEIx64 - ok 15:21:31.0515 7604 [ 01884CB7655C8908B43FF5E364FE6FD2 ] mfeapfk C:\Windows\system32\drivers\mfeapfk.sys 15:21:31.0524 7604 mfeapfk - ok 15:21:31.0581 7604 [ DAB9A9CDFB04E4D68924492AA043019D ] mfeavfk C:\Windows\system32\drivers\mfeavfk.sys 15:21:31.0594 7604 mfeavfk - ok 15:21:31.0614 7604 mfeavfk01 - ok 15:21:31.0631 7604 [ B26782C3D6045B4464017D7926877560 ] mfefire C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe 15:21:31.0641 7604 mfefire - ok 15:21:31.0677 7604 [ CE9A3680675C0907ADE16404CA967B49 ] mfefirek C:\Windows\system32\drivers\mfefirek.sys 15:21:31.0692 7604 mfefirek - ok 15:21:31.0708 7604 [ 60CF67458DD29CD17E77F2327B1A9A54 ] mfehidk C:\Windows\system32\drivers\mfehidk.sys 15:21:31.0729 7604 mfehidk - ok 15:21:31.0739 7604 [ A8129CFB919347F8533C934B365E9202 ] mfenlfk C:\Windows\system32\DRIVERS\mfenlfk.sys 15:21:31.0748 7604 mfenlfk - ok 15:21:31.0771 7604 [ 5041FA2BD2B3A2693B015771BFBF6DCA ] mferkdet C:\Windows\system32\drivers\mferkdet.sys 15:21:31.0781 7604 mferkdet - ok 15:21:31.0813 7604 [ 723A5EB6CEF7F408C3D0F15A82A6BFF8 ] mfevtp C:\Windows\system32\mfevtps.exe 15:21:31.0827 7604 mfevtp - ok 15:21:31.0843 7604 [ 919C56DB14A0E1E2AB6DA5D2821DC26E ] mfewfpk C:\Windows\system32\drivers\mfewfpk.sys 15:21:31.0857 7604 mfewfpk - ok 15:21:31.0993 7604 Microsoft SharePoint Workspace Audit Service - ok 15:21:32.0024 7604 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 15:21:32.0054 7604 MMCSS - ok 15:21:32.0071 7604 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 15:21:32.0112 7604 Modem - ok 15:21:32.0138 7604 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 15:21:32.0159 7604 monitor - ok 15:21:32.0188 7604 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 15:21:32.0198 7604 mouclass - ok 15:21:32.0208 7604 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 15:21:32.0226 7604 mouhid - ok 15:21:32.0265 7604 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 15:21:32.0276 7604 mountmgr - ok 15:21:32.0303 7604 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 15:21:32.0316 7604 mpio - ok 15:21:32.0340 7604 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 15:21:32.0373 7604 mpsdrv - ok 15:21:32.0477 7604 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 15:21:32.0524 7604 MpsSvc - ok 15:21:32.0554 7604 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 15:21:32.0599 7604 MRxDAV - ok 15:21:32.0627 7604 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 15:21:32.0663 7604 mrxsmb - ok 15:21:32.0704 7604 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 15:21:32.0721 7604 mrxsmb10 - ok 15:21:32.0750 7604 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 15:21:32.0762 7604 mrxsmb20 - ok 15:21:32.0790 7604 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 15:21:32.0799 7604 msahci - ok 15:21:32.0829 7604 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 15:21:32.0843 7604 msdsm - ok 15:21:32.0856 7604 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 15:21:32.0884 7604 MSDTC - ok 15:21:32.0911 7604 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 15:21:32.0940 7604 Msfs - ok 15:21:32.0960 7604 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 15:21:32.0998 7604 mshidkmdf - ok 15:21:33.0010 7604 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 15:21:33.0020 7604 msisadrv - ok 15:21:33.0044 7604 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 15:21:33.0085 7604 MSiSCSI - ok 15:21:33.0087 7604 msiserver - ok 15:21:33.0109 7604 [ ACB01BF1A905356AB7F978C7FE852209 ] MSK80Service C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 15:21:33.0120 7604 MSK80Service - ok 15:21:33.0142 7604 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 15:21:33.0189 7604 MSKSSRV - ok 15:21:33.0212 7604 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 15:21:33.0252 7604 MSPCLOCK - ok 15:21:33.0264 7604 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 15:21:33.0303 7604 MSPQM - ok 15:21:33.0338 7604 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 15:21:33.0365 7604 MsRPC - ok 15:21:33.0379 7604 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 15:21:33.0389 7604 mssmbios - ok 15:21:33.0453 7604 MSSQL$SQLEXPRESS - ok 15:21:33.0538 7604 [ 7A2A8C975356858EB38466A6B1592E8D ] MSSQLServerADHelper100 c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE 15:21:33.0548 7604 MSSQLServerADHelper100 - ok 15:21:33.0576 7604 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 15:21:33.0612 7604 MSTEE - ok 15:21:33.0625 7604 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 15:21:33.0636 7604 MTConfig - ok 15:21:33.0649 7604 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 15:21:33.0658 7604 Mup - ok 15:21:33.0716 7604 [ 6ED8935257672F4CD04A88A0F3DE093D ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe 15:21:33.0730 7604 MyWiFiDHCPDNS - ok 15:21:33.0754 7604 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 15:21:33.0794 7604 napagent - ok 15:21:33.0834 7604 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 15:21:33.0863 7604 NativeWifiP - ok 15:21:33.0894 7604 [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS C:\Windows\system32\drivers\ndis.sys 15:21:33.0919 7604 NDIS - ok 15:21:33.0947 7604 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 15:21:33.0986 7604 NdisCap - ok 15:21:34.0011 7604 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 15:21:34.0039 7604 NdisTapi - ok 15:21:34.0055 7604 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 15:21:34.0085 7604 Ndisuio - ok 15:21:34.0099 7604 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 15:21:34.0137 7604 NdisWan - ok 15:21:34.0146 7604 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 15:21:34.0175 7604 NDProxy - ok 15:21:34.0221 7604 [ 6F4607E2333FE21E9E3FF8133A88B35B ] Netaapl C:\Windows\system32\DRIVERS\netaapl64.sys 15:21:34.0251 7604 Netaapl - ok 15:21:34.0269 7604 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 15:21:34.0303 7604 NetBIOS - ok 15:21:34.0314 7604 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 15:21:34.0345 7604 NetBT - ok 15:21:34.0354 7604 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 15:21:34.0365 7604 Netlogon - ok 15:21:34.0386 7604 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 15:21:34.0426 7604 Netman - ok 15:21:34.0481 7604 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 15:21:34.0503 7604 NetMsmqActivator - ok 15:21:34.0529 7604 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 15:21:34.0538 7604 NetPipeActivator - ok 15:21:34.0568 7604 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 15:21:34.0609 7604 netprofm - ok 15:21:34.0614 7604 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 15:21:34.0623 7604 NetTcpActivator - ok 15:21:34.0626 7604 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 15:21:34.0635 7604 NetTcpPortSharing - ok 15:21:34.0803 7604 [ 5D262402B0634C998F8CBCEAD7DD8676 ] NETwNs64 C:\Windows\system32\DRIVERS\NETwNs64.sys 15:21:34.0994 7604 NETwNs64 - ok 15:21:35.0018 7604 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 15:21:35.0029 7604 nfrd960 - ok 15:21:35.0124 7604 [ CEEFDE8FACE887D6DDA664940404EA58 ] NIDomainService C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe 15:21:35.0136 7604 NIDomainService - ok 15:21:35.0198 7604 [ B17093B9A2C5F874975C732C1A8BA771 ] NILM License Manager C:\Program Files (x86)\National Instruments\Shared\License Manager\Bin\lmgrd.exe 15:21:35.0232 7604 NILM License Manager ( UnsignedFile.Multi.Generic ) - warning 15:21:35.0232 7604 NILM License Manager - detected UnsignedFile.Multi.Generic (1) 15:21:35.0277 7604 niSvcLoc - ok 15:21:35.0310 7604 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll 15:21:35.0349 7604 NlaSvc - ok 15:21:35.0363 7604 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 15:21:35.0393 7604 Npfs - ok 15:21:35.0407 7604 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 15:21:35.0447 7604 nsi - ok 15:21:35.0454 7604 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 15:21:35.0484 7604 nsiproxy - ok 15:21:35.0528 7604 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 15:21:35.0580 7604 Ntfs - ok 15:21:35.0598 7604 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 15:21:35.0638 7604 Null - ok 15:21:35.0663 7604 [ A7127E86F9FFE2A53E271B56B2C4CEDF ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys 15:21:35.0679 7604 nusb3hub - ok 15:21:35.0704 7604 [ 49BBEC6F48D5F9284B03ABF3A959B19B ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys 15:21:35.0738 7604 nusb3xhc - ok 15:21:35.0793 7604 [ 8D4AAC74B571FC356560E5B308955E93 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys 15:21:35.0806 7604 NVHDA - ok 15:21:35.0937 7604 [ 555DDBAF3D306154C553ACBD6780FD1E ] nvkflt C:\Windows\system32\DRIVERS\nvkflt.sys 15:21:35.0949 7604 nvkflt - ok 15:21:36.0196 7604 [ 0EB204639119370F5F8F2871FBF4E14B ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 15:21:36.0357 7604 nvlddmkm - ok 15:21:36.0386 7604 [ 3629B8C7257C6231A3CFB44359C68B1D ] nvpciflt C:\Windows\system32\DRIVERS\nvpciflt.sys 15:21:36.0395 7604 nvpciflt - ok 15:21:36.0426 7604 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 15:21:36.0439 7604 nvraid - ok 15:21:36.0454 7604 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 15:21:36.0467 7604 nvstor - ok 15:21:36.0494 7604 [ 32FF8EE6DCEE5C0CB91FF892FB1CA364 ] NVSvc C:\Windows\system32\nvvsvc.exe 15:21:36.0519 7604 NVSvc - ok 15:21:36.0600 7604 [ BD012DC22C78BE1071BC21EB125D782F ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 15:21:36.0667 7604 nvUpdatusService - ok 15:21:36.0704 7604 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 15:21:36.0717 7604 nv_agp - ok 15:21:36.0735 7604 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 15:21:36.0747 7604 ohci1394 - ok 15:21:36.0796 7604 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 15:21:36.0807 7604 ose - ok 15:21:36.0929 7604 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 15:21:37.0072 7604 osppsvc - ok 15:21:37.0119 7604 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 15:21:37.0146 7604 p2pimsvc - ok 15:21:37.0173 7604 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 15:21:37.0187 7604 p2psvc - ok 15:21:37.0208 7604 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys 15:21:37.0226 7604 Parport - ok 15:21:37.0264 7604 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 15:21:37.0275 7604 partmgr - ok 15:21:37.0286 7604 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 15:21:37.0316 7604 PcaSvc - ok 15:21:37.0331 7604 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 15:21:37.0344 7604 pci - ok 15:21:37.0367 7604 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 15:21:37.0382 7604 pciide - ok 15:21:37.0400 7604 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 15:21:37.0415 7604 pcmcia - ok 15:21:37.0431 7604 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 15:21:37.0440 7604 pcw - ok 15:21:37.0456 7604 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 15:21:37.0501 7604 PEAUTH - ok 15:21:37.0546 7604 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 15:21:37.0612 7604 PeerDistSvc - ok 15:21:37.0649 7604 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 15:21:37.0668 7604 PerfHost - ok 15:21:37.0759 7604 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 15:21:37.0827 7604 pla - ok 15:21:37.0853 7604 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 15:21:37.0883 7604 PlugPlay - ok 15:21:37.0930 7604 [ F485770EEC8959684CC4C4786B63C06C ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 15:21:37.0964 7604 Pml Driver HPZ12 - ok 15:21:37.0982 7604 PnkBstrA - ok 15:21:38.0012 7604 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 15:21:38.0023 7604 PNRPAutoReg - ok 15:21:38.0046 7604 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 15:21:38.0059 7604 PNRPsvc - ok 15:21:38.0132 7604 [ 4F0878FD62D5F7444C5F1C4C66D9D293 ] Point64 C:\Windows\system32\DRIVERS\point64.sys 15:21:38.0140 7604 Point64 - ok 15:21:38.0194 7604 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 15:21:38.0234 7604 PolicyAgent - ok 15:21:38.0294 7604 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 15:21:38.0349 7604 Power - ok 15:21:38.0402 7604 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 15:21:38.0444 7604 PptpMiniport - ok 15:21:38.0461 7604 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys 15:21:38.0484 7604 Processor - ok 15:21:38.0548 7604 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 15:21:38.0577 7604 ProfSvc - ok 15:21:38.0593 7604 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 15:21:38.0604 7604 ProtectedStorage - ok 15:21:38.0649 7604 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 15:21:38.0696 7604 Psched - ok 15:21:38.0774 7604 [ 0928BD20273625622722FE1DE5BBDE57 ] qicflt C:\Windows\system32\DRIVERS\qicflt.sys 15:21:38.0783 7604 qicflt - ok 15:21:38.0843 7604 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 15:21:38.0887 7604 ql2300 - ok 15:21:38.0899 7604 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 15:21:38.0910 7604 ql40xx - ok 15:21:38.0950 7604 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 15:21:38.0968 7604 QWAVE - ok 15:21:38.0987 7604 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 15:21:39.0012 7604 QWAVEdrv - ok 15:21:39.0026 7604 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 15:21:39.0054 7604 RasAcd - ok 15:21:39.0079 7604 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 15:21:39.0107 7604 RasAgileVpn - ok 15:21:39.0135 7604 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 15:21:39.0176 7604 RasAuto - ok 15:21:39.0189 7604 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 15:21:39.0224 7604 Rasl2tp - ok 15:21:39.0245 7604 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 15:21:39.0275 7604 RasMan - ok 15:21:39.0287 7604 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 15:21:39.0325 7604 RasPppoe - ok 15:21:39.0334 7604 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 15:21:39.0374 7604 RasSstp - ok 15:21:39.0390 7604 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 15:21:39.0429 7604 rdbss - ok 15:21:39.0446 7604 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 15:21:39.0461 7604 rdpbus - ok 15:21:39.0479 7604 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 15:21:39.0506 7604 RDPCDD - ok 15:21:39.0531 7604 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 15:21:39.0555 7604 RDPDR - ok 15:21:39.0570 7604 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 15:21:39.0605 7604 RDPENCDD - ok 15:21:39.0623 7604 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 15:21:39.0660 7604 RDPREFMP - ok 15:21:39.0696 7604 [ 70CBA1A0C98600A2AA1863479B35CB90 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 15:21:39.0724 7604 RdpVideoMiniport - ok 15:21:39.0759 7604 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 15:21:39.0807 7604 RDPWD - ok 15:21:39.0825 7604 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 15:21:39.0838 7604 rdyboost - ok 15:21:39.0910 7604 [ 189C5A8D2098E0AA14FD157A954B34FC ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 15:21:39.0927 7604 RegSrvc - ok 15:21:39.0945 7604 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 15:21:39.0982 7604 RemoteAccess - ok 15:21:40.0005 7604 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 15:21:40.0043 7604 RemoteRegistry - ok 15:21:40.0074 7604 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 15:21:40.0096 7604 RFCOMM - ok 15:21:40.0119 7604 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 15:21:40.0184 7604 RpcEptMapper - ok 15:21:40.0199 7604 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 15:21:40.0218 7604 RpcLocator - ok 15:21:40.0236 7604 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 15:21:40.0268 7604 RpcSs - ok 15:21:40.0308 7604 [ CD553B8633466A6D1C115812F2619F1F ] RsFx0103 C:\Windows\system32\DRIVERS\RsFx0103.sys 15:21:40.0322 7604 RsFx0103 - ok 15:21:40.0348 7604 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 15:21:40.0387 7604 rspndr - ok 15:21:40.0511 7604 [ EE082E06A82FF630351D1E0EBBD3D8D0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 15:21:40.0525 7604 RTL8167 - ok 15:21:40.0559 7604 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys 15:21:40.0597 7604 s3cap - ok 15:21:40.0610 7604 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 15:21:40.0621 7604 SamSs - ok 15:21:40.0637 7604 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 15:21:40.0648 7604 sbp2port - ok 15:21:40.0668 7604 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 15:21:40.0699 7604 SCardSvr - ok 15:21:40.0720 7604 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 15:21:40.0759 7604 scfilter - ok 15:21:40.0786 7604 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 15:21:40.0839 7604 Schedule - ok 15:21:40.0853 7604 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 15:21:40.0880 7604 SCPolicySvc - ok 15:21:40.0948 7604 [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys 15:21:40.0970 7604 sdbus - ok 15:21:40.0991 7604 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 15:21:41.0013 7604 SDRSVC - ok 15:21:41.0067 7604 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 15:21:41.0120 7604 secdrv - ok 15:21:41.0129 7604 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 15:21:41.0162 7604 seclogon - ok 15:21:41.0198 7604 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 15:21:41.0236 7604 SENS - ok 15:21:41.0246 7604 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 15:21:41.0273 7604 SensrSvc - ok 15:21:41.0293 7604 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys 15:21:41.0311 7604 Serenum - ok 15:21:41.0334 7604 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys 15:21:41.0361 7604 Serial - ok 15:21:41.0386 7604 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys 15:21:41.0399 7604 sermouse - ok 15:21:41.0417 7604 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 15:21:41.0445 7604 SessionEnv - ok 15:21:41.0448 7604 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys 15:21:41.0471 7604 sffdisk - ok 15:21:41.0474 7604 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 15:21:41.0488 7604 sffp_mmc - ok 15:21:41.0490 7604 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys 15:21:41.0512 7604 sffp_sd - ok 15:21:41.0526 7604 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 15:21:41.0540 7604 sfloppy - ok 15:21:41.0560 7604 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 15:21:41.0606 7604 SharedAccess - ok 15:21:41.0627 7604 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 15:21:41.0671 7604 ShellHWDetection - ok 15:21:41.0703 7604 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 15:21:41.0715 7604 SiSRaid2 - ok 15:21:41.0727 7604 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 15:21:41.0739 7604 SiSRaid4 - ok 15:21:41.0858 7604 [ 753D254205E0A62100A050BD8B458D06 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe 15:21:41.0937 7604 Skype C2C Service - ok 15:21:41.0975 7604 [ DDAA5F4A6B958FC313EBD02DD925752F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 15:21:41.0983 7604 SkypeUpdate - ok 15:21:42.0008 7604 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 15:21:42.0051 7604 Smb - ok 15:21:42.0094 7604 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 15:21:42.0107 7604 SNMPTRAP - ok 15:21:42.0119 7604 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 15:21:42.0128 7604 spldr - ok 15:21:42.0183 7604 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 15:21:42.0212 7604 Spooler - ok 15:21:42.0268 7604 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 15:21:42.0625 7604 sppsvc - ok 15:21:42.0637 7604 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 15:21:42.0667 7604 sppuinotify - ok 15:21:42.0743 7604 [ 12E6D95CDE974B131DEFAA44BAB8B056 ] SQLAgent$SQLEXPRESS c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE 15:21:42.0760 7604 SQLAgent$SQLEXPRESS - ok 15:21:42.0808 7604 [ B54B48F6D92423440C264E91225C5FF1 ] SQLBrowser c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe 15:21:42.0823 7604 SQLBrowser - ok 15:21:42.0839 7604 [ 6D65985945B03CA59B67D0B73702FC7B ] SQLWriter c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe 15:21:42.0850 7604 SQLWriter - ok 15:21:42.0876 7604 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 15:21:42.0906 7604 srv - ok 15:21:42.0922 7604 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 15:21:42.0948 7604 srv2 - ok 15:21:42.0964 7604 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 15:21:42.0977 7604 srvnet - ok 15:21:42.0993 7604 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 15:21:43.0023 7604 SSDPSRV - ok 15:21:43.0034 7604 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 15:21:43.0064 7604 SstpSvc - ok 15:21:43.0088 7604 Steam Client Service - ok 15:21:43.0180 7604 [ FC0A58529A02B1EED55DDC58696B7908 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 15:21:43.0196 7604 Stereo Service - ok 15:21:43.0211 7604 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys 15:21:43.0223 7604 stexstor - ok 15:21:43.0273 7604 [ DECACB6921DED1A38642642685D77DAC ] StillCam C:\Windows\system32\DRIVERS\serscan.sys 15:21:43.0297 7604 StillCam - ok 15:21:43.0329 7604 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 15:21:43.0361 7604 stisvc - ok 15:21:43.0380 7604 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys 15:21:43.0390 7604 storflt - ok 15:21:43.0415 7604 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys 15:21:43.0427 7604 storvsc - ok 15:21:43.0444 7604 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 15:21:43.0454 7604 swenum - ok 15:21:43.0476 7604 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 15:21:43.0524 7604 swprv - ok 15:21:43.0532 7604 [ C3A39C4079305480972D29C44B868C78 ] Synth3dVsc C:\Windows\system32\drivers\synth3dvsc.sys 15:21:43.0544 7604 Synth3dVsc - ok 15:21:43.0573 7604 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 15:21:43.0636 7604 SysMain - ok 15:21:43.0652 7604 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 15:21:43.0670 7604 TabletInputService - ok 15:21:43.0677 7604 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 15:21:43.0718 7604 TapiSrv - ok 15:21:43.0732 7604 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 15:21:43.0761 7604 TBS - ok 15:21:43.0823 7604 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 15:21:43.0877 7604 Tcpip - ok 15:21:43.0922 7604 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 15:21:43.0952 7604 TCPIP6 - ok 15:21:43.0976 7604 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 15:21:44.0017 7604 tcpipreg - ok 15:21:44.0034 7604 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 15:21:44.0072 7604 TDPIPE - ok 15:21:44.0100 7604 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 15:21:44.0127 7604 TDTCP - ok 15:21:44.0143 7604 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 15:21:44.0172 7604 tdx - ok 15:21:44.0199 7604 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 15:21:44.0208 7604 TermDD - ok 15:21:44.0241 7604 [ 2B5BDFF688EC9871D7EC5837833374E9 ] terminpt C:\Windows\system32\drivers\terminpt.sys 15:21:44.0274 7604 terminpt - ok 15:21:44.0368 7604 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 15:21:44.0424 7604 TermService - ok 15:21:44.0461 7604 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 15:21:44.0477 7604 Themes - ok 15:21:44.0510 7604 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 15:21:44.0539 7604 THREADORDER - ok 15:21:44.0561 7604 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 15:21:44.0610 7604 TrkWks - ok 15:21:44.0682 7604 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 15:21:44.0731 7604 TrustedInstaller - ok 15:21:44.0769 7604 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 15:21:44.0818 7604 tssecsrv - ok 15:21:44.0845 7604 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 15:21:44.0883 7604 TsUsbFlt - ok 15:21:44.0886 7604 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys 15:21:44.0906 7604 TsUsbGD - ok 15:21:44.0923 7604 [ E1748D04AE40118B62BC18AC86032192 ] tsusbhub C:\Windows\system32\drivers\tsusbhub.sys 15:21:44.0951 7604 tsusbhub - ok 15:21:45.0009 7604 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 15:21:45.0061 7604 tunnel - ok 15:21:45.0121 7604 [ FD24F98D2898BE093FE926604BE7DB99 ] TurboB C:\Windows\system32\DRIVERS\TurboB.sys 15:21:45.0131 7604 TurboB - ok 15:21:45.0196 7604 [ 600B406A04D90F577FEA8A88D7379F08 ] TurboBoost C:\Program Files\Intel\TurboBoost\TurboBoost.exe 15:21:45.0207 7604 TurboBoost - ok 15:21:45.0235 7604 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 15:21:45.0253 7604 uagp35 - ok 15:21:45.0311 7604 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 15:21:45.0363 7604 udfs - ok 15:21:45.0405 7604 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 15:21:45.0427 7604 UI0Detect - ok 15:21:45.0490 7604 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 15:21:45.0500 7604 uliagpkx - ok 15:21:45.0532 7604 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 15:21:45.0557 7604 umbus - ok 15:21:45.0606 7604 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys 15:21:45.0623 7604 UmPass - ok 15:21:45.0700 7604 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll 15:21:45.0734 7604 UmRdpService - ok 15:21:46.0021 7604 [ 2C16648A12999AE69A9EBF41974B0BA2 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe 15:21:46.0112 7604 UNS - ok 15:21:46.0140 7604 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 15:21:46.0178 7604 upnphost - ok 15:21:46.0261 7604 [ FB251567F41BC61988B26731DEC19E4B ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 15:21:46.0291 7604 USBAAPL64 - ok 15:21:46.0355 7604 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 15:21:46.0390 7604 usbccgp - ok 15:21:46.0468 7604 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 15:21:46.0482 7604 usbcir - ok 15:21:46.0509 7604 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys 15:21:46.0526 7604 usbehci - ok 15:21:46.0611 7604 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 15:21:46.0637 7604 usbhub - ok 15:21:46.0652 7604 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 15:21:46.0690 7604 usbohci - ok 15:21:46.0706 7604 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\drivers\usbprint.sys 15:21:46.0739 7604 usbprint - ok 15:21:46.0783 7604 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 15:21:46.0850 7604 USBSTOR - ok 15:21:46.0909 7604 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 15:21:46.0949 7604 usbuhci - ok 15:21:47.0013 7604 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 15:21:47.0071 7604 usbvideo - ok 15:21:47.0113 7604 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 15:21:47.0161 7604 UxSms - ok 15:21:47.0173 7604 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 15:21:47.0184 7604 VaultSvc - ok 15:21:47.0317 7604 [ 87947A6F7DD5183AABA2CB45CFF0BF26 ] VBoxDrv C:\Windows\system32\DRIVERS\VBoxDrv.sys 15:21:47.0329 7604 VBoxDrv - ok 15:21:47.0438 7604 [ A502011EB830AD5BF4D30A940614CF4E ] VBoxNetAdp C:\Windows\system32\DRIVERS\VBoxNetAdp.sys 15:21:47.0472 7604 VBoxNetAdp - ok 15:21:47.0486 7604 [ 9E86BB348A82EC3047D7CC75868B28AA ] VBoxNetFlt C:\Windows\system32\DRIVERS\VBoxNetFlt.sys 15:21:47.0496 7604 VBoxNetFlt - ok 15:21:47.0518 7604 [ 5E9F3633DDDAF2F1070017DC07044C97 ] VBoxUSBMon C:\Windows\system32\DRIVERS\VBoxUSBMon.sys 15:21:47.0529 7604 VBoxUSBMon - ok 15:21:47.0580 7604 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 15:21:47.0589 7604 vdrvroot - ok 15:21:47.0740 7604 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 15:21:47.0806 7604 vds - ok 15:21:47.0831 7604 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 15:21:47.0862 7604 vga - ok 15:21:47.0883 7604 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 15:21:47.0942 7604 VgaSave - ok 15:21:47.0945 7604 VGPU - ok 15:21:47.0961 7604 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 15:21:47.0974 7604 vhdmp - ok 15:21:48.0002 7604 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 15:21:48.0013 7604 viaide - ok 15:21:48.0055 7604 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys 15:21:48.0068 7604 vmbus - ok 15:21:48.0092 7604 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 15:21:48.0134 7604 VMBusHID - ok 15:21:48.0165 7604 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 15:21:48.0177 7604 volmgr - ok 15:21:48.0201 7604 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 15:21:48.0216 7604 volmgrx - ok 15:21:48.0253 7604 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 15:21:48.0267 7604 volsnap - ok 15:21:48.0344 7604 [ ABD9B4A7E2D0AE51A3B8DF1AF3152D61 ] vpcbus C:\Windows\system32\DRIVERS\vpchbus.sys 15:21:48.0371 7604 vpcbus - ok 15:21:48.0393 7604 [ 8ACDA395841538CE9713A67FE8B2A3EB ] vpcnfltr C:\Windows\system32\DRIVERS\vpcnfltr.sys 15:21:48.0403 7604 vpcnfltr - ok 15:21:48.0433 7604 [ 31924E31BC315773E6D149B157DB46D5 ] vpcusb C:\Windows\system32\DRIVERS\vpcusb.sys 15:21:48.0455 7604 vpcusb - ok 15:21:48.0513 7604 [ C5B651E52540E6F46DA66574C74B4898 ] vpcvmm C:\Windows\system32\drivers\vpcvmm.sys 15:21:48.0526 7604 vpcvmm - ok 15:21:48.0602 7604 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 15:21:48.0617 7604 vsmraid - ok 15:21:48.0832 7604 [ 1928B9CA20F51BFBBAD54D2C2C447B13 ] VSPerfDrv100 C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys 15:21:48.0865 7604 VSPerfDrv100 - ok 15:21:49.0163 7604 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 15:21:49.0234 7604 VSS - ok 15:21:49.0255 7604 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 15:21:49.0292 7604 vwifibus - ok 15:21:49.0312 7604 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 15:21:49.0372 7604 vwififlt - ok 15:21:49.0389 7604 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 15:21:49.0409 7604 vwifimp - ok 15:21:49.0537 7604 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 15:21:49.0572 7604 W32Time - ok 15:21:49.0608 7604 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys 15:21:49.0631 7604 WacomPen - ok 15:21:49.0680 7604 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 15:21:49.0722 7604 WANARP - ok 15:21:49.0746 7604 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 15:21:49.0775 7604 Wanarpv6 - ok 15:21:49.0946 7604 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 15:21:49.0998 7604 WatAdminSvc - ok 15:21:50.0097 7604 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 15:21:50.0172 7604 wbengine - ok 15:21:50.0186 7604 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 15:21:50.0205 7604 WbioSrvc - ok 15:21:50.0224 7604 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 15:21:50.0253 7604 wcncsvc - ok 15:21:50.0267 7604 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 15:21:50.0294 7604 WcsPlugInService - ok 15:21:50.0318 7604 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys 15:21:50.0328 7604 Wd - ok 15:21:50.0359 7604 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 15:21:50.0380 7604 Wdf01000 - ok 15:21:50.0391 7604 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 15:21:50.0461 7604 WdiServiceHost - ok 15:21:50.0464 7604 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 15:21:50.0480 7604 WdiSystemHost - ok 15:21:50.0514 7604 [ 94DC2BF6CBAAA95E369C3756D3115A76 ] wdkmd C:\Windows\system32\DRIVERS\WDKMD.sys 15:21:50.0523 7604 wdkmd - ok 15:21:50.0539 7604 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 15:21:50.0568 7604 WebClient - ok 15:21:50.0581 7604 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 15:21:50.0621 7604 Wecsvc - ok 15:21:50.0633 7604 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 15:21:50.0663 7604 wercplsupport - ok 15:21:50.0685 7604 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 15:21:50.0714 7604 WerSvc - ok 15:21:50.0740 7604 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 15:21:50.0768 7604 WfpLwf - ok 15:21:50.0779 7604 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 15:21:50.0790 7604 WIMMount - ok 15:21:50.0811 7604 WinDefend - ok 15:21:50.0827 7604 WinHttpAutoProxySvc - ok 15:21:50.0866 7604 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 15:21:50.0899 7604 Winmgmt - ok 15:21:50.0949 7604 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 15:21:51.0024 7604 WinRM - ok 15:21:51.0101 7604 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 15:21:51.0127 7604 WinUsb - ok 15:21:51.0150 7604 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 15:21:51.0183 7604 Wlansvc - ok 15:21:51.0261 7604 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 15:21:51.0293 7604 wlidsvc - ok 15:21:51.0314 7604 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys 15:21:51.0333 7604 WmiAcpi - ok 15:21:51.0362 7604 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 15:21:51.0386 7604 wmiApSrv - ok 15:21:51.0412 7604 WMPNetworkSvc - ok 15:21:51.0446 7604 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 15:21:51.0468 7604 WPCSvc - ok 15:21:51.0480 7604 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 15:21:51.0494 7604 WPDBusEnum - ok 15:21:51.0514 7604 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 15:21:51.0543 7604 ws2ifsl - ok 15:21:51.0553 7604 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll 15:21:51.0577 7604 wscsvc - ok 15:21:51.0579 7604 WSearch - ok 15:21:51.0654 7604 [ 1D448834EBAEB2D99AE7C6634B8D17BE ] WTGService C:\Program Files (x86)\3DataManager\WTGService.exe 15:21:51.0668 7604 WTGService - ok 15:21:51.0730 7604 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 15:21:51.0798 7604 wuauserv - ok 15:21:51.0813 7604 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 15:21:51.0853 7604 WudfPf - ok 15:21:51.0880 7604 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 15:21:51.0920 7604 WUDFRd - ok 15:21:51.0940 7604 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 15:21:51.0969 7604 wudfsvc - ok 15:21:51.0987 7604 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 15:21:52.0017 7604 WwanSvc - ok 15:21:52.0069 7604 [ 2EE48CFCE7CA8E0DB4C44C7476C0943B ] xusb21 C:\Windows\system32\DRIVERS\xusb21.sys 15:21:52.0091 7604 xusb21 - ok 15:21:52.0107 7604 ================ Scan global =============================== 15:21:52.0128 7604 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 15:21:52.0151 7604 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 15:21:52.0158 7604 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 15:21:52.0180 7604 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 15:21:52.0199 7604 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 15:21:52.0202 7604 [Global] - ok 15:21:52.0202 7604 ================ Scan MBR ================================== 15:21:52.0217 7604 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 15:21:52.0554 7604 \Device\Harddisk0\DR0 - ok 15:21:52.0554 7604 ================ Scan VBR ================================== 15:21:52.0556 7604 [ 6A04F76CB68F5227E246BFDC390B6533 ] \Device\Harddisk0\DR0\Partition1 15:21:52.0557 7604 \Device\Harddisk0\DR0\Partition1 - ok 15:21:52.0594 7604 [ 9268F4807D984E0850A43089F572BF04 ] \Device\Harddisk0\DR0\Partition2 15:21:52.0596 7604 \Device\Harddisk0\DR0\Partition2 - ok 15:21:52.0596 7604 ============================================================ 15:21:52.0596 7604 Scan finished 15:21:52.0596 7604 ============================================================ 15:21:52.0603 7580 Detected object count: 2 15:21:52.0603 7580 Actual detected object count: 2 15:22:07.0263 7580 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user 15:22:07.0263 7580 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip 15:22:07.0264 7580 NILM License Manager ( UnsignedFile.Multi.Generic ) - skipped by user 15:22:07.0264 7580 NILM License Manager ( UnsignedFile.Multi.Generic ) - User select action: Skip |
11.09.2012, 20:52 | #22 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Cyber Crime Investigation Department Österreich - Trojaner Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat! Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
11.09.2012, 21:32 | #23 |
| Cyber Crime Investigation Department Österreich - Trojaner Fertig. Hier das Log-File von ComboFix: Code:
ATTFilter ComboFix 12-09-11.02 - Christian 11.09.2012 22:19:45.1.8 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.43.1031.18.8086.6194 [GMT 2:00] ausgeführt von:: c:\users\Christian\Desktop\ComboFix.exe AV: McAfee Anti-Virus und Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} SP: McAfee Anti-Virus und Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\nud0repor.pad c:\programdata\Roaming c:\users\Christian\AppData\Local\assembly\tmp c:\users\Christian\GoToAssistDownloadHelper.exe c:\windows\SysWow64\FlashPlayerInstaller.exe . . ((((((((((((((((((((((( Dateien erstellt von 2012-08-11 bis 2012-09-11 )))))))))))))))))))))))))))))) . . 2012-09-11 20:26 . 2012-09-11 20:26 -------- d-----w- c:\users\UpdatusUser.Christian-PC\AppData\Local\temp 2012-09-11 20:26 . 2012-09-11 20:26 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-09-10 19:41 . 2012-09-10 19:41 -------- d-----w- C:\_OTL 2012-09-06 08:19 . 2012-09-06 08:19 -------- d-----w- c:\program files (x86)\ESET 2012-09-05 07:31 . 2012-09-05 07:31 -------- d-----w- c:\users\Christian\AppData\Roaming\Malwarebytes 2012-09-05 07:30 . 2012-09-05 07:30 -------- d-----w- c:\programdata\Malwarebytes 2012-09-05 07:30 . 2012-07-03 11:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-09-05 07:30 . 2012-09-05 07:31 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-08-16 07:01 . 2012-07-06 20:07 552960 ----a-w- c:\windows\system32\drivers\bthport.sys 2012-08-15 18:20 . 2012-05-05 08:36 503808 ----a-w- c:\windows\system32\srcore.dll 2012-08-15 18:20 . 2012-05-05 07:46 43008 ----a-w- c:\windows\SysWow64\srclient.dll 2012-08-15 18:19 . 2012-02-11 06:43 751104 ----a-w- c:\windows\system32\win32spl.dll 2012-08-15 18:19 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe 2012-08-15 18:19 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe 2012-08-15 18:19 . 2012-02-11 05:43 492032 ----a-w- c:\windows\SysWow64\win32spl.dll 2012-08-15 18:19 . 2012-07-04 22:16 73216 ----a-w- c:\windows\system32\netapi32.dll 2012-08-15 18:19 . 2012-07-04 22:13 59392 ----a-w- c:\windows\system32\browcli.dll 2012-08-15 18:19 . 2012-07-04 22:13 136704 ----a-w- c:\windows\system32\browser.dll 2012-08-15 18:19 . 2012-07-04 21:14 41984 ----a-w- c:\windows\SysWow64\browcli.dll 2012-08-15 18:18 . 2012-07-18 18:15 3148800 ----a-w- c:\windows\system32\win32k.sys 2012-08-15 18:18 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll 2012-08-13 11:35 . 2012-08-13 11:35 5115584 ----a-w- c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-08-20 09:10 . 2012-04-04 10:51 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-08-20 09:10 . 2012-02-20 21:27 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-15 22:37 . 2012-02-20 20:54 62134624 ----a-w- c:\windows\system32\MRT.exe 2012-07-12 15:13 . 2012-05-08 20:19 405144 ----a-w- c:\windows\SysWow64\Newtonsoft.Json.Net20.dll 2012-07-05 16:32 . 2012-07-05 16:32 268720 ----a-w- c:\windows\system32\javaws.exe 2012-07-05 16:32 . 2012-07-05 16:32 189360 ----a-w- c:\windows\system32\javaw.exe 2012-07-05 16:32 . 2012-07-05 16:32 188840 ----a-w- c:\windows\system32\java.exe 2012-07-05 16:32 . 2012-04-25 17:20 955840 ----a-w- c:\windows\system32\npdeployJava1.dll 2012-07-05 16:32 . 2012-02-20 18:39 839096 ----a-w- c:\windows\system32\deployJava1.dll 2012-06-29 06:27 . 2012-04-02 19:58 43520 ----a-w- c:\windows\SysWow64\CmdLineExt03.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Facebook Update"="c:\users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-12 138096] "Steam"="c:\program files (x86)\Steam\steam.exe" [2012-08-04 1353080] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-07-13 17418928] "MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-01-12 283160] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-21 1675160] "RemoteControl9"="c:\program files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [2010-10-01 87336] "PDVD9LanguageShortcut"="c:\program files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [2010-09-17 50472] "BDRegion"="c:\program files (x86)\Cyberlink\Shared Files\brs.exe" [2011-08-11 75048] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942] "AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-05-30 885760] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-10-01 640376] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280] "NI Background Service"="c:\program files (x86)\National Instruments\Shared\Update Service\niupdate.exe" [2010-08-10 77824] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-18 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-07 421776] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Windchill ProductPoint Client Manager.lnk - c:\windows\Installer\{371E8B48-2AF1-491B-8F35-BD60D18CB927}\PPS.ico [2012-4-12 7782] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 CLKMSVC10_9EC60124;CyberLink Product - 2012/02/20 20:27;c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2011-08-11 248304] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-01 2348352] R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168] R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-07-24 114560] R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2011-01-28 225216] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-02-22 100912] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240] R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2011-08-02 22528] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2012-01-17 188224] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248] R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736] R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2012-04-02 147248] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-03-17 68440] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2012-02-20 1255736] R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936] R4 MSSQLServerADHelper100;SQL Server Hilfsdienst für Active Directory;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-21 61976] R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656] R4 SQLAgent$SQLEXPRESS;SQL Server-Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-02-22 289664] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2012-03-01 28992] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 75936] S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys [2012-03-01 249152] S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2012-04-02 224048] S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2012-04-02 130864] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-12 13336] S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936] S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-03-20 210584] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-03-20 162192] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-29 382272] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280] S2 WTGService;WTGService;c:\program files (x86)\3DataManager\WTGService.exe [2009-10-12 312784] S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-11-15 327168] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-02-22 65264] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-01-20 176096] S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2011-05-18 47616] S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-06-08 283200] S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-12-09 60416] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440] S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-02-22 487296] S3 NETwNs64;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2010-12-21 8505856] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-11-19 80384] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-11-19 181248] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416] S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [2010-07-02 29288] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240] S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2012-04-02 166192] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [2010-12-01 42392] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - 31128341 *Deregistered* - 31128341 *Deregistered* - CLKMDRV10_9EC60124 *Deregistered* - mfeavfk01 . Inhalt des "geplante Tasks" Ordners . 2012-09-05 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2205288494-3300817759-3993977911-1000Core.job - c:\users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-29 07:25] . 2012-09-11 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2205288494-3300817759-3993977911-1000UA.job - c:\users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-29 07:25] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-01-18 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-01-18 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-01-18 417304] "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-17 1933584] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2010-12-14 6561384] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-12-10 2186856] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] "QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2011-01-25 4479648] "Stage Remote"="c:\program files (x86)\Dell\Stage Remote\StageRemote.exe" [2011-08-08 2034752] "DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-05-30 2055816] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.at/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = <local>;*.local IE: An OneNote s&enden - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105 IE: Free YouTube Download - c:\users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm IE: Free YouTube to MP3 Converter - c:\users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000 Trusted Zone: oracle.com\ilearning TCP: DhcpNameServer = 192.168.1.1 Handler: gmx - {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - FF - ProfilePath - c:\users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\bzpwl7d1.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.at/ FF - prefs.js: network.proxy.type - 0 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-BattlEye - c:\program files (x86)\Bohemia Interactive\ArmA 2 Operation ArrowheadExpansion\BattlEye\UnInstallBE.exe AddRemove-BattlEye A2 Free - c:\program files (x86)\Bohemia Interactive\ArmA 2 FreeBattlEye\UnInstallBE.exe AddRemove-Call of Duty Modern Warfare 2_is1 - c:\program files (x86)\Activision\Modern Warfare 2\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2012-09-11 22:28:51 ComboFix-quarantined-files.txt 2012-09-11 20:28 . Vor Suchlauf: 14 Verzeichnis(se), 244.549.480.448 Bytes frei Nach Suchlauf: 18 Verzeichnis(se), 244.182.171.648 Bytes frei . - - End Of File - - F1820A63C14FFDE75B04740AA0584239 |
11.09.2012, 23:57 | #24 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Cyber Crime Investigation Department Österreich - Trojaner Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen. Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst. Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM! Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes: Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.
__________________ Logfiles bitte immer in CODE-Tags posten |
12.09.2012, 15:39 | #25 |
| Cyber Crime Investigation Department Österreich - Trojaner Hat ein bisschen gedauert aber jetzt habe ich alle drei Logs. Hier das GMER-Log: Code:
ATTFilter GMER 1.0.15.15641 - hxxp://www.gmer.net Rootkit scan 2012-09-12 16:16:03 Windows 6.1.7601 Service Pack 1 Running: dz7wfiqe.exe ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4ceb42085989 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4ceb42085989@d82a7e4afc86 0x0F 0x2A 0xDF 0xC1 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4ceb42085989 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4ceb42085989@d82a7e4afc86 0x0F 0x2A 0xDF 0xC1 ... ---- EOF - GMER 1.0.15 ---- Code:
ATTFilter Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 16:21:03 on 12.09.2012 OS: Windows 7 Ultimate Edition Service Pack 1 (Build 7601), 64-bit Default Browser: Microsoft Corporation Internet Explorer 9.00.8112.16421 Scanner Settings [x] Rootkits detection (hidden registry) [x] Rootkits detection (hidden files) [x] Retrieve files information [x] Check Microsoft signatures Filters [ ] Trusted entries [ ] Empty entries [x] Hidden registry entries (rootkit activity) [x] Exclusively opened files [x] Not found files [x] Files without detailed information [x] Existing files [ ] Non-startable services [ ] Non-startable drivers [x] Active entries [x] Disabled entries [Common] -----( %SystemRoot%\Tasks )----- "FacebookUpdateTaskUserS-1-5-21-2205288494-3300817759-3993977911-1000Core.job" - "Facebook Inc." - C:\Users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe "FacebookUpdateTaskUserS-1-5-21-2205288494-3300817759-3993977911-1000UA.job" - "Facebook Inc." - C:\Users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe [Control Panel Objects] -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )----- "mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\MLCFG32.CPL "QuickTime" - "Apple Inc." - C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.cpl [Drivers] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "catchme" (catchme) - ? - C:\ComboFix\catchme.sys (File not found) "Hamachi Network Interface" (hamachi) - "LogMeIn, Inc." - C:\Windows\System32\DRIVERS\hamachi.sys "McAfee Inc." (mfeavfk01) - ? - C:\Windows\system32\drivers\mfeavfk01.sys (File not found) "Performance Tools Driver 10.0" (VSPerfDrv100) - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys "VGPU" (VGPU) - ? - C:\Windows\System32\drivers\rdvgkmd.sys (File not found) [Explorer] -----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )----- {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll -----( HKLM\Software\Classes\Protocols\Filter )----- {3EF5086B-5478-4598-A054-786C45D75692} "McInternetProtocolRoot Class" - "McAfee, Inc." - c:\progra~2\mcafee\msc\mcsniepl.dll {807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL -----( HKLM\Software\Classes\Protocols\Handler )----- {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} "GMX NewTab Protocol" - ? - C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll (File not found) {314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL {828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll {0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL {828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll {91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )----- {B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} "Acrobat Elements Context Menu" - "Adobe Systems Inc." - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat Elements\ContextMenu.dll {3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D} "Arbeitsbereiche" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL {D66DC78C-4F61-447F-942B-3FB6980118CF} "CInfoTipShellExt Class" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\VISSHE.DLL {99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL {920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL {16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL {2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL {72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL {6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL {B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL {A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL {387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL {506F4668-F13E-4AA1-BB04-B43203AB3CC0} "ImageExtractorShellExt Class" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\VISSHE.DLL {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\msohevi.dll {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll {0875DCB6-C686-4243-9432-ADCCF0B9F2D7} "Microsoft OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONFILTER.DLL {00020D75-0000-0000-C000-000000000046} "Microsoft Outlook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\MLSHEXT.DLL {0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\OLKFSTUB.DLL {CB7EB523-76DC-4A1B-81C6-46DAABE5AC31} "PTC Umgebung" - "Parametric Technology Corporation" - C:\Program Files (x86)\PTC\'PTC Places' Namespace Shell Extension\ptcnse.dll [Internet Explorer] -----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )----- ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found) ITBar7Height64 "ITBar7Height64" - ? - (File not found | COM-object registry key not found) <binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found) <binary data> "ITBar7Layout64" - ? - (File not found | COM-object registry key not found) -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )----- {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} "A9Helper.A9" - ? - C:\Windows\Downloaded Program Files\A9.ocx / file:///D:/components/A9.ocx {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} "DellSystemLite.Scanner" - ? - C:\Windows\Downloaded Program Files\DellSystemLite.ocx / hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} "HidInputMonitorX Control" - "TODO: <Company name>" - C:\Windows\DOWNLO~1\HIDINP~1.OCX / file:///D:/components/hidinputmonitorx.ocx {C3F79A2B-B9B4-4A66-B012-3EE46475B072} "MessengerStatsClient Class" - "Microsoft Corporation" - C:\Windows\Downloaded Program Files\MessengerStatsPAClient.dll / hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab {7530BFB8-7293-4D34-9923-61A11451AFC5} "OnlineScanner Control" - "ESET" - C:\PROGRA~2\ESET\ESETON~1\ONLINE~1.OCX / hxxp://download.eset.com/special/eos/OnlineScanner.cab {D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\SysWOW64\Macromed\Flash\Flash32_11_3_300_271.ocx / hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab {E6F480FC-BD44-4CBA-B74A-89AF7842937D} "SysInfo Class" - "Husdawg, LLC" - C:\Program Files (x86)\SystemRequirementsLab\srldetect_cyri_4.5.1.0.dll / hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.5.1.0.cab {1E54D648-B804-468d-BC78-4AFFED8E262F} "System Requirements Lab Class" - "Husdawg, LLC" - C:\Windows\Downloaded Program Files\sysreqlab_nvd.dll / hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} "WMVHDRatingCtrl Class" - ? - C:\Windows\Downloaded Program Files\wmvhdrating.ocx / file:///D:/components/wmvhdrating.ocx -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )----- {48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll {898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll {FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )----- {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll {72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL {DDA57003-0068-4ed2-9D32-4D1EC707D94D} "Microsoft-Webtestaufzeichnung 10.0-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll {B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL {7DB2D5A0-7241-4E79-B68D-6309F01C5231} "scriptproxy" - "McAfee, Inc." - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120630181840.dll {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll {9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID-Anmelde-Hilfsprogramm" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [LSA Providers] -----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )----- "Security Packages" - "Microsoft Corp." - C:\Windows\system32\livessp.dll [Logon] -----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini -----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini "Windchill ProductPoint Client Manager.lnk" - "PTC" - C:\Program Files (x86)\PTC\WindchillSharePointProducts\ClientManager\ProductPointService.exe (Shortcut exists | File exists) -----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )----- "DAEMON Tools Lite" - "DT Soft Ltd" - "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun "Facebook Update" - "Facebook Inc." - "C:\Users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver "MobileDocuments" - "Apple Inc." - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe "Skype" - "Skype Technologies S.A." - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun "Steam" - "Valve Corporation" - "C:\Program Files (x86)\Steam\steam.exe" -silent -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )----- "AccuWeatherWidget" - ? - "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup "Acrobat Assistant 8.0" - "Adobe Systems Inc." - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" "Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "APSDaemon" - "Apple Inc." - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "BCSSync" - "Microsoft Corporation" - "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices "BDRegion" - "cyberlink" - C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe "Dell Webcam Central" - "Creative Technology Ltd" - "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 "HP Software Update" - "Hewlett-Packard" - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe "IAStorIcon" - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe "iTunesHelper" - "Apple Inc." - "C:\Program Files (x86)\iTunes\iTunesHelper.exe" "mcui_exe" - "McAfee, Inc." - "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey "NI Background Service" - "National Instruments" - C:\Program Files (x86)\National Instruments\Shared\Update Service\niupdate.exe "NUSB3MON" - "Renesas Electronics Corporation" - "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" "PDVD9LanguageShortcut" - "CyberLink Corp." - "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe" "QuickTime Task" - "Apple Inc." - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime "RemoteControl9" - "CyberLink Corp." - "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [Print Monitors] -----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )----- "Adobe PDF Port Monitor" - "Adobe Systems Inc" - C:\Windows\system32\AdobePDF.dll "HP Discovery Port Monitor (HP Deskjet 3050 J610 series)" - "Hewlett-Packard Co." - C:\Windows\system32\HPDiscoPM9311.dll [Services] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll (File not found) "@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe" (File not found) "Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe "Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe "ASP.NET-Zustandsdienst" (aspnet_state) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe "CyberLink Product - 2012/02/20 20:27:18" (CLKMSVC10_9EC60124) - "CyberLink" - C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe "Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe "InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe "Intel(R) Management and Security Application Local Management Service" (LMS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe "Intel(R) Management and Security Application User Notification Service" (UNS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe "Intel(R) PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe "Intel(R) PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe "Intel(R) Rapid Storage Technology" (IAStorDataMgrSvc) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe "Intel(R) Turbo Boost Technology Monitor 2.0" (TurboBoost) - "Intel(R) Corporation" - C:\Program Files\Intel\TurboBoost\TurboBoost.exe "iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe "Lookout Citadel Server" (LkCitadelServer) - "National Instruments, Inc." - C:\Windows\SysWOW64\lkcitdl.exe "McAfee Activation Service" (McAWFwk) - "McAfee, Inc." - c:\PROGRA~1\mcafee\msc\mcawfwk.exe "McAfee Anti-Spam Service" (MSK80Service) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe "McAfee Firewall Core Service" (mfefire) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe "McAfee McShield" (McShield) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe "McAfee Network Agent" (McNASvc) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe "McAfee Personal Firewall Service" (McMPFSvc) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe "McAfee Proxy Service" (McProxy) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe "McAfee Scanner" (McODS) - "McAfee, Inc." - C:\Program Files\McAfee\VirusScan\mcods.exe "McAfee Services" (mcmscsvc) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe "McAfee Validation Trust Protection Service" (mfevtp) - "McAfee, Inc." - C:\Windows\system32\mfevtps.exe "McAfee VirusScan Announcer" (McNaiAnn) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe "Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe "Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe "Microsoft SharePoint Workspace Audit Service" (Microsoft SharePoint Workspace Audit Service) - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE "National Instruments Domain Service" (NIDomainService) - "National Instruments Corporation" - C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe "National Instruments PSP Server Locator" (lkClassAds) - "National Instruments Corporation" - C:\Windows\SysWOW64\lkads.exe "National Instruments Time Synchronization" (lkTimeSync) - "National Instruments Corporation" - C:\Windows\SysWOW64\lktsrv.exe "NI Service Locator" (niSvcLoc) - "National Instruments Corporation" - C:\Windows\SysWOW64\nisvcloc.exe "NVIDIA Display Driver Service" (NVSvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe "NVIDIA Stereoscopic 3D Driver Service" (Stereo Service) - "NVIDIA Corporation" - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe "NVIDIA Update Service Daemon" (nvUpdatusService) - "NVIDIA Corporation" - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe "Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE "Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE "PnkBstrA" (PnkBstrA) - ? - C:\Windows\system32\PnkBstrA.exe (File not found) "Skype C2C Service" (Skype C2C Service) - "Skype Technologies S.A." - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe "Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files (x86)\Skype\Updater\Updater.exe "SQL Server (SQLEXPRESS)" (MSSQL$SQLEXPRESS) - "Microsoft Corporation" - c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe "SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe "Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files (x86)\Common Files\Steam\SteamService.exe "Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE "Wireless PAN DHCP Server" (MyWiFiDHCPDNS) - ? - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe "WTGService" (WTGService) - ? - C:\Program Files (x86)\3DataManager\WTGService.exe (File found, but it contains no detailed information) [Winsock Providers] -----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )----- "mdnsNSP" - "Apple Inc." - C:\Program Files (x86)\Bonjour\mdnsNSP.dll "WindowsLive Local NSP" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL "WindowsLive NSP" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL ===[ Logfile end ]=========================================[ Logfile end ]=== If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru Code:
ATTFilter aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software Run date: 2012-09-12 16:33:37 ----------------------------- 16:33:37.380 OS Version: Windows x64 6.1.7601 Service Pack 1 16:33:37.380 Number of processors: 8 586 0x2A07 16:33:37.381 ComputerName: CHRISTIAN-PC UserName: Christian 16:33:48.511 Initialize success 16:33:54.201 AVAST engine defs: 12091200 16:33:58.455 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 16:33:58.457 Disk 0 Vendor: ST975042 0002 Size: 715404MB BusType: 3 16:33:58.518 Disk 0 MBR read successfully 16:33:58.521 Disk 0 MBR scan 16:33:58.527 Disk 0 Windows 7 default MBR code 16:33:58.540 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 101 MB offset 63 16:33:58.550 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 20000 MB offset 212992 16:33:58.565 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 695299 MB offset 41172992 16:33:58.588 Disk 0 scanning C:\Windows\system32\drivers 16:34:18.491 Service scanning 16:34:48.073 Modules scanning 16:34:48.088 Disk 0 trace - called modules: 16:34:48.101 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll 16:34:48.106 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8009711060] 16:34:48.111 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa8007761d10] 16:34:48.115 5 ACPI.sys[fffff88000f3b7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007765050] 16:34:48.119 Scan finished successfully 16:36:18.108 Disk 0 MBR has been saved successfully to "C:\Users\Christian\Desktop\MBR.dat" 16:36:18.115 The log file has been saved successfully to "C:\Users\Christian\Desktop\aswMBR.txt" |
12.09.2012, 18:50 | #26 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Cyber Crime Investigation Department Österreich - Trojaner Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!!
__________________ Logfiles bitte immer in CODE-Tags posten |
13.09.2012, 09:54 | #27 |
| Cyber Crime Investigation Department Österreich - Trojaner Noch eine kurze Frage bevor ich die Scans mache. Seit ich gestern die drei Logs gemacht habe stockt mein Laptop bei Spielen die vorher total flüssig gelaufen sind. Auch die Videoqualität bei meinen Filmen ist jetzt nicht mehr so gut. Kann das mit den Scans zusammenhängen? Denn zuvor hatte ich keinerlei Probleme. |
13.09.2012, 20:08 | #28 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Cyber Crime Investigation Department Österreich - Trojaner Mach bitte erst die Logs. Wenn wir durch sind kümmern wir uns um die anderen Probleme.
__________________ Logfiles bitte immer in CODE-Tags posten |
13.09.2012, 23:53 | #29 |
| Cyber Crime Investigation Department Österreich - Trojaner Ok, hier die beiden Logs: Malwarebytes Anti-Malware : Code:
ATTFilter Malwarebytes Anti-Malware 1.65.0.1400 www.malwarebytes.org Datenbank Version: v2012.09.13.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Christian :: CHRISTIAN-PC [Administrator] 13.09.2012 18:11:06 mbam-log-2012-09-13 (18-11-06).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 619648 Laufzeit: 3 Stunde(n), 10 Minute(n), 4 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) SUPERAntiSpyware Scan Log: Code:
ATTFilter SUPERAntiSpyware Scan Log hxxp://www.superantispyware.com Generated 09/14/2012 at 00:45 AM Application Version : 5.5.1016 Core Rules Database Version : 9223 Trace Rules Database Version: 7035 Scan type : Complete Scan Total Scan Time : 03:15:58 Operating System Information Windows 7 Ultimate 64-bit, Service Pack 1 (Build 6.01.7601) UAC On - Administrator Memory items scanned : 874 Memory threats detected : 0 Registry items scanned : 69261 Registry threats detected : 0 File items scanned : 375487 File threats detected : 377 Adware.Tracking Cookie C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\PKTK2D0V.txt [ /track.adform.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\MUJ6TNE3.txt [ /accounts.google.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\SM34FID4.txt [ /smartadserver.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\Y98W62WV.txt [ /tradedoubler.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\MAAQ83V7.txt [ /specificclick.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\5YCFISSO.txt [ /questionmarket.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\QPT4F37Y.txt [ /ad2.adfarm1.adition.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\OTNAPD34.txt [ /amazon-adsystem.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\ED55MXLJ.txt [ /ad.zanox.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\I70RFZQW.txt [ /revsci.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\70CG3B0Y.txt [ /ar.atwola.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\LCNWSZJ1.txt [ /msnportal.112.2o7.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\U1V4X8NO.txt [ /ad.adc-serv.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\33JS0SIV.txt [ /casalemedia.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\L3J9JXQO.txt [ /microsoftwllivemkt.112.2o7.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\HJ2DNVL6.txt [ /zanox.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\SOHBTAYQ.txt [ /splash.trackmania.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\LT5WUSHC.txt [ /mediaplex.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\75MTCAJ1.txt [ /advertising.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\A51CO6US.txt [ /ad1.adfarm1.adition.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\0626V712.txt [ /invitemedia.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\0HSPAGQQ.txt [ /eas.apm.emediate.eu ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\TMZSH5LI.txt [ /c.atdmt.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\2RK3JUT2.txt [ /tracker.vinsight.de ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\KO7QF06L.txt [ /tracking.quisma.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\JVSVL6O0.txt [ /maniapub.trackmania.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\QD6W3263.txt [ /apmebf.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\O4X1A6H2.txt [ /estat.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\IB7BZN0I.txt [ /ads.creative-serving.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\PUAAKE99.txt [ /highbeam.122.2o7.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\AWT28XF4.txt [ /tacoda.at.atwola.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\ADSUZ6HJ.txt [ /kontera.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\BY0QWXXJ.txt [ /adbrite.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\GTTWCXI0.txt [ /conrad.122.2o7.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\E2W0THS6.txt [ /adtech.de ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\6BK4W16Q.txt [ /de-fourmedia.videoplaza.tv ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\KG4K84NU.txt [ /webmasterplan.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\GK1P8QKI.txt [ /px.steelhousemedia.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\L7E2ZPUZ.txt [ /ad.yieldmanager.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\T70D1UK7.txt [ /e-2dj6wjmikncpgdq.stats.esomniture.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\E48IYZO1.txt [ /media6degrees.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\7QXG1A4I.txt [ /imrworldwide.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\LK4NCCB4.txt [ /ad4.adfarm1.adition.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\4BA9OZOG.txt [ /ad3.adfarm1.adition.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\L64GFAMH.txt [ /tradetracker.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\BFCNEM8H.txt [ /adfarm1.adition.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\TDQNTMXQ.txt [ /at.atwola.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\XGG12GAP.txt [ /doubleclick.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\TEWF5TN5.txt [ /ad.360yield.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\4L6X5QOU.txt [ /atdmt.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\0L8I96FW.txt [ /bs.serving-sys.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\UUQG7KJS.txt [ /im.banner.t-online.de ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\ZE6SMRE9.txt [ /serving-sys.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\5OSGKT49.txt [ /partners.webmasterplan.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\JD8D55X6.txt [ /2o7.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\6YFE43RP.txt [ /statse.webtrendslive.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\ED6LURD3.txt [ /adform.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\PUJ4Y68E.txt [ /fastclick.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\15UENQ3R.txt [ /collective-media.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\98PWVKBB.txt [ /ww251.smartadserver.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\MXVB93CT.txt [ /www.googleadservices.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\33C3NXDT.txt [ /www.googleadservices.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\C3PO5G5T.txt [ /ad.ad-srv.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\H9M5HZPJ.txt [ /steelhousemedia.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\7QEY8323.txt [ /ad.adnet.de ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\9XX22DWD.txt [ /etargetnet.com ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\IMTFGO1N.txt [ /edsa.122.2o7.net ] C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\2FF49X6Q.txt [ /eaeacom.112.2o7.net ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\5U7BCW4U.txt [ Cookie:christian@clkads.com/adServe ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\BI68553W.txt [ Cookie:christian@clkads.com/adServe/banners ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\15FKWLDM.txt [ Cookie:christian@fastclick.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\KOFUZ4C8.txt [ Cookie:christian@track.adform.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\GEXNXCR0.txt [ Cookie:christian@tradedoubler.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Q01GH0GM.txt [ Cookie:christian@specificclick.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\HFTWN6ZB.txt [ Cookie:christian@liveperson.net/hc/42179880 ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\IH4RZK73.txt [ Cookie:christian@eas4.emediate.eu/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\VRP5PBGN.txt [ Cookie:christian@server.adform.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\P0RB7T4N.txt [ Cookie:christian@ad2.adfarm1.adition.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\X7H2Q5B7.txt [ Cookie:christian@liveperson.net/hc/82753263 ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\XF1JN7PM.txt [ Cookie:christian@collective-media.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\NZRYW2U2.txt [ Cookie:christian@amazon-adsystem.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\FO8BBJLA.txt [ Cookie:christian@ad.zanox.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\6NNFW8ED.txt [ Cookie:christian@clkads.com/adServe ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\SBS6RPXV.txt [ Cookie:christian@zedo.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\OX1DOWDJ.txt [ Cookie:christian@revsci.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\FV7HX27A.txt [ Cookie:christian@fangatemedia.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\7EN5Z5WD.txt [ Cookie:christian@tribalfusion.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\D31EHRFI.txt [ Cookie:christian@ad.dyntracker.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\QZZUKZ9Q.txt [ Cookie:christian@zanox.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\3VKKUMS7.txt [ Cookie:christian@advertising.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\BORCNUVM.txt [ Cookie:christian@yadro.ru/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\1XSUP9YX.txt [ Cookie:christian@invitemedia.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MPUHC13H.txt [ Cookie:christian@c.atdmt.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\4NIB619M.txt [ Cookie:christian@server.lon.liveperson.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\J17K7E29.txt [ Cookie:christian@tracking.quisma.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\SVQDGE57.txt [ Cookie:christian@clkads.com/adServe/banners ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\QS3CI1DR.txt [ Cookie:christian@moviepilot.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Y4IYED06.txt [ Cookie:christian@kontera.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MTUH7HNE.txt [ Cookie:christian@liveperson.net/hc/17387962 ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YP94HWJW.txt [ Cookie:christian@adserver.adreactor.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\5E5SKGI2.txt [ Cookie:christian@tracking.oe24.at// ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZOEKAYK8.txt [ Cookie:christian@lucidmedia.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\94E3B83B.txt [ Cookie:christian@adtech.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\0NSUDCFN.txt [ Cookie:christian@ad.yieldmanager.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\IXT8UT6F.txt [ Cookie:christian@ox-d.sublimemedia.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\LG4P2HL6.txt [ Cookie:christian@clicksor.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\OTMFXQ4C.txt [ Cookie:christian@c1.atdmt.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\PRN2RZM3.txt [ Cookie:christian@media6degrees.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\QZK5CJGP.txt [ Cookie:christian@imrworldwide.com/cgi-bin ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZR1COMNC.txt [ Cookie:christian@myroitracking.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MMGQVVSW.txt [ Cookie:christian@www.etracker.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZKTIQQ2V.txt [ Cookie:christian@ad4.adfarm1.adition.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\PAJG4YE0.txt [ Cookie:christian@adx.chip.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\JX0HPDJJ.txt [ Cookie:christian@ad3.adfarm1.adition.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\1KEQ7V64.txt [ Cookie:christian@at.atwola.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\X9HELXIY.txt [ Cookie:christian@adfarm1.adition.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\QD2RZ8FZ.txt [ Cookie:christian@doubleclick.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\2JE1NZGE.txt [ Cookie:christian@atdmt.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\AS3Z0HQ9.txt [ Cookie:christian@bs.serving-sys.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\5YOZQOP1.txt [ Cookie:christian@statse.webtrendslive.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\SQ7D2HV1.txt [ Cookie:christian@liveperson.net/hc/13554660 ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\X67V9MOX.txt [ Cookie:christian@adform.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\1ITAVZVG.txt [ Cookie:christian@zanox-affiliate.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZH2NAB6L.txt [ Cookie:christian@quartermedia.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\BUUY7ULT.txt [ Cookie:christian@counter.hitslink.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\GUSPYR41.txt [ Cookie:christian@in.getclicky.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Y2J9RW5V.txt [ Cookie:christian@accounts.google.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\FW3PIFMP.txt [ Cookie:christian@adsonar.com/adserving ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\631HTEYG.txt [ Cookie:christian@questionmarket.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\2QD5G717.txt [ Cookie:christian@ww251.smartadserver.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\6H758SM2.txt [ Cookie:christian@ar.atwola.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\TPTO8S86.txt [ Cookie:christian@rambler.ru/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Z1WZLJA5.txt [ Cookie:christian@ad1.adfarm1.adition.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\QUAP7GJO.txt [ Cookie:christian@traffictrack.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\C9Y3VSW7.txt [ Cookie:christian@ru4.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\TN0U7H3W.txt [ Cookie:christian@www.moviepilot.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MS9OSUED.txt [ Cookie:christian@overture.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\KDH1UL9X.txt [ Cookie:christian@uk.sitestat.com/future/techradar/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\OLB1JVSN.txt [ Cookie:christian@adbrite.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\UCVEVWAU.txt [ Cookie:christian@interclick.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\SRJB2JXX.txt [ Cookie:christian@callofduty.4players.de/board1-callofdutyseries-de-news-fragen-und-fehler/board23-news-von-unseren-redakteuren-f%C3%BCr-user/4490-call-of-duty-modern-warfare-2-neuer-multiplayer-crack-im-umlauf/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\IVAAE4TJ.txt [ Cookie:christian@webresint.122.2o7.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\V84I9RYW.txt [ Cookie:christian@mm.chitika.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\6EZ7NB20.txt [ Cookie:christian@edsa.122.2o7.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\6L4GHKGG.txt [ Cookie:christian@de.sitestat.com/idgcom-de/gamestar/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\3AUTCNLP.txt [ Cookie:christian@livestat.derstandard.at/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\UIJEQVEQ.txt [ Cookie:christian@ero-advertising.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\A0IDZCI8.txt [ Cookie:christian@www.mediamarkt.at/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\86P5Y2BQ.txt [ Cookie:christian@www.tunefind.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\PAHLP23X.txt [ Cookie:christian@www.trafficjmp.com/conversion ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\9HLVNVW6.txt [ Cookie:christian@stat.kk-bits.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Q2KQK3IA.txt [ Cookie:christian@ads.pointroll.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\6E6D0O17.txt [ Cookie:christian@adsby.webtraffic.se/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\PAOAL659.txt [ Cookie:christian@2o7.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\W9GPYOVE.txt [ Cookie:christian@content.yieldmanager.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\G5UAL0AJ.txt [ Cookie:christian@guj.122.2o7.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\GGMZQ2F9.txt [ Cookie:christian@www.gotgayporn.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MVVAWR7B.txt [ Cookie:christian@ox.9livesmediainc.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\5UK7AAI5.txt [ Cookie:christian@server.cpmstar.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\310OF6KO.txt [ Cookie:christian@realmedia.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\FFQ0Y4NX.txt [ Cookie:christian@a.revenuemax.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\K0AOD1HL.txt [ Cookie:christian@premiumtv.122.2o7.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Y80DO0LM.txt [ Cookie:christian@eas.apm.emediate.eu/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\6OJ2D9PX.txt [ Cookie:christian@neckermannde.122.2o7.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\GROKWQQU.txt [ Cookie:christian@adserver.hardtecs.org/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Q6OZ10ZO.txt [ Cookie:christian@www.learning-languages-online.net/piwik-stats/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\03O59IUX.txt [ Cookie:christian@hitbox.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\CF6TXK3Y.txt [ Cookie:christian@nfm-adserver.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\JD7KMA26.txt [ Cookie:christian@vogelservices.122.2o7.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\JL9JCFW7.txt [ Cookie:christian@unister-adservices.com/campaign/conversion/36 ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\HMGK55JU.txt [ Cookie:christian@www.sexhoundlinks.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YB4YUXYX.txt [ Cookie:christian@www.swoodoo.com/at/ad/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\TIPLIS5S.txt [ Cookie:christian@blogs.mediamarkt.at/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\7PPOC6WO.txt [ Cookie:christian@unister-adservices.com/campaign/conversion/27 ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\S12I47D0.txt [ Cookie:christian@pro-market.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\OP0BCRAC.txt [ Cookie:christian@mtvn.112.2o7.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\JQDFFD8T.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1058785566/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\DO43NAIJ.txt [ Cookie:christian@adxpansion.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\E10DNMZT.txt [ Cookie:christian@adultfriendfinder.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\2GQ4E9Q0.txt [ Cookie:christian@thomascookag.122.2o7.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\JQHCTS24.txt [ Cookie:christian@tracking.surveycheck.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\FIFBV2SZ.txt [ Cookie:christian@cdnw.trafficjmp.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\20CVE3SI.txt [ Cookie:christian@liveperson.net/hc/7074034 ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\ODCGNPGP.txt [ Cookie:christian@de.sitestat.com/idgcom-de/macwelt/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\3U106KP8.txt [ Cookie:christian@media.neodau.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\S56V2RE7.txt [ Cookie:christian@c.gigcount.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\WX7CY6AQ.txt [ Cookie:christian@unister-adservices.com/campaign/conversion/56 ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YR80XT33.txt [ Cookie:christian@de.sitestat.com/idgcom-de/gamepro/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\KVYNOXUS.txt [ Cookie:christian@openstat.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\37TRWOGJ.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1045321740/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\O13DQA0F.txt [ Cookie:christian@toplist.cz/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\W0SB94BW.txt [ Cookie:christian@tracking.eduscho.at/265328718441342/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MR6N4H6P.txt [ Cookie:christian@track.effiliation.com/servlet/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YQPU2WKD.txt [ Cookie:christian@www.mediafire.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\B0I3BI5B.txt [ Cookie:christian@hot-sex-tube.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\OW40M3DO.txt [ Cookie:christian@trafficholder.com/cgi-bin/traffic/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\WHT7EL29.txt [ Cookie:christian@aimfar.solution.weborama.fr/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\7YY7OS78.txt [ Cookie:christian@m1.webstats.motigo.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\34ELTGXZ.txt [ Cookie:christian@games.mediamarkt.at/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\W1Q3G2MG.txt [ Cookie:christian@tunefind.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\BG4NHJ2P.txt [ Cookie:christian@clickbank.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\HDIAY67R.txt [ Cookie:christian@yieldmanager.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YPANZ0CI.txt [ Cookie:christian@server.adformdsp.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\9AJ1NQ9M.txt [ Cookie:christian@7.rotator.wigetmedia.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\LEZMXCZ5.txt [ Cookie:christian@unister-adservices.com/campaign/conversion/8 ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\0RNHV7CA.txt [ Cookie:christian@insightexpressai.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\F33J3OI7.txt [ Cookie:christian@adverts.timesofmalta.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\4LDWMR54.txt [ Cookie:christian@media.funpic.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\DFE1E0BH.txt [ Cookie:christian@linksynergy.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\EOPI1YS8.txt [ Cookie:christian@www.abendblatt.de/ratgeber/multimedia/article2377714/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\79VZP2YL.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1035377488/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\G89EX00N.txt [ Cookie:christian@counters.gigya.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\5EU011JO.txt [ Cookie:christian@e-2dj6wdl4ulczmbp.stats.esomniture.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\1NAOX0J6.txt [ Cookie:christian@adscendmedia.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\L6XTHX5Y.txt [ Cookie:christian@rubitrack.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\DBBZ9TLS.txt [ Cookie:christian@ads.neudesicmediagroup.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\INTSR7YT.txt [ Cookie:christian@liveperson.net/hc/64975841 ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\P6R8GF20.txt [ Cookie:christian@ads2.zeusclicks.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YII4PJER.txt [ Cookie:christian@clickandbuy.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\8UN8HKZX.txt [ Cookie:christian@e-2dj6whkoqkdjwbp.stats.esomniture.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YWPKKQ74.txt [ Cookie:christian@mediamarkt.at/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\WF3NXHK9.txt [ Cookie:christian@unitymedia.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\NOYQDZT2.txt [ Cookie:christian@track.effiliation.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\DYYBQRZZ.txt [ Cookie:christian@twinkteenboys.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\VTJU3NC3.txt [ Cookie:christian@www.mediashop.tv/DE/waterzoom_1/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\1HMON9TJ.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1070806761/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\W576WQF7.txt [ Cookie:christian@otclick-adv.ru/core ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\XX3HT73U.txt [ Cookie:christian@googleads.g.doubleclick.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\39NT7QAK.txt [ Cookie:christian@legolas-media.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\EK117ZRC.txt [ Cookie:christian@pornhub.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\T0GOS1LD.txt [ Cookie:christian@sub.bubblesmedia.ru/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\VELPP7YI.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1017865890/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\UJAXSZP6.txt [ Cookie:christian@unister-adservices.com/campaign/conversion/22 ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\7D7WE645.txt [ Cookie:christian@histats.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\VED181H4.txt [ Cookie:christian@box1.counter-service.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\U5VRDNMH.txt [ Cookie:christian@track.zalando.at/513072222822788/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\AX2JP301.txt [ Cookie:christian@fl01.ct2.comclick.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\IKKC01R7.txt [ Cookie:christian@exoclick.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\NG2CQGIM.txt [ Cookie:christian@tracker.vinsight.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\E3ZRCAWG.txt [ Cookie:christian@austrianairlines.122.2o7.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\DIV0NF79.txt [ Cookie:christian@spylog.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\VJM63G9J.txt [ Cookie:christian@nikonjp.112.2o7.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\EMB2K6NJ.txt [ Cookie:christian@www.pornhub.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\V17MTVNC.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1071943062/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\E9HCW7TE.txt [ Cookie:christian@www.hxtrack.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MD00Z29P.txt [ Cookie:christian@officemedia.de/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\J1Z3K8I1.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1072260330/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\8B3U7RLG.txt [ Cookie:christian@eas5.emediate.eu/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\4LQWJ28Y.txt [ Cookie:christian@mediashop.tv/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\OJVAW4C8.txt [ Cookie:christian@sexhoundlinks.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\J5BM21LH.txt [ Cookie:christian@ehg-tfl.hitbox.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\N1N7HHBO.txt [ Cookie:christian@zbox.zanox.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\RD9IWAYJ.txt [ Cookie:christian@liveperson.net/hc/55779702 ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\DN8FXYRT.txt [ Cookie:christian@hearstdigital.122.2o7.net/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\2EBK49L8.txt [ Cookie:christian@adxpose.com/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\TFG6TSZU.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1061703000/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\32BP8A4K.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1023629923/ ] C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\WOR3UK2O.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1067799827/ ] C:\USERS\CHRISTIAN\Cookies\PKTK2D0V.txt [ Cookie:christian@track.adform.net/ ] C:\USERS\CHRISTIAN\Cookies\MUJ6TNE3.txt [ Cookie:christian@accounts.google.com/ ] C:\USERS\CHRISTIAN\Cookies\Y98W62WV.txt [ Cookie:christian@tradedoubler.com/ ] C:\USERS\CHRISTIAN\Cookies\MAAQ83V7.txt [ Cookie:christian@specificclick.net/ ] C:\USERS\CHRISTIAN\Cookies\5YCFISSO.txt [ Cookie:christian@questionmarket.com/ ] C:\USERS\CHRISTIAN\Cookies\QPT4F37Y.txt [ Cookie:christian@ad2.adfarm1.adition.com/ ] C:\USERS\CHRISTIAN\Cookies\OTNAPD34.txt [ Cookie:christian@amazon-adsystem.com/ ] C:\USERS\CHRISTIAN\Cookies\ED55MXLJ.txt [ Cookie:christian@ad.zanox.com/ ] C:\USERS\CHRISTIAN\Cookies\5U7BCW4U.txt [ Cookie:christian@clkads.com/adServe ] C:\USERS\CHRISTIAN\Cookies\I70RFZQW.txt [ Cookie:christian@revsci.net/ ] C:\USERS\CHRISTIAN\Cookies\70CG3B0Y.txt [ Cookie:christian@ar.atwola.com/ ] C:\USERS\CHRISTIAN\Cookies\LCNWSZJ1.txt [ Cookie:christian@msnportal.112.2o7.net/ ] C:\USERS\CHRISTIAN\Cookies\HJ2DNVL6.txt [ Cookie:christian@zanox.com/ ] C:\USERS\CHRISTIAN\Cookies\SOHBTAYQ.txt [ Cookie:christian@splash.trackmania.com/display/ ] C:\USERS\CHRISTIAN\Cookies\75MTCAJ1.txt [ Cookie:christian@advertising.com/ ] C:\USERS\CHRISTIAN\Cookies\A51CO6US.txt [ Cookie:christian@ad1.adfarm1.adition.com/ ] C:\USERS\CHRISTIAN\Cookies\0626V712.txt [ Cookie:christian@invitemedia.com/ ] C:\USERS\CHRISTIAN\Cookies\0HSPAGQQ.txt [ Cookie:christian@eas.apm.emediate.eu/ ] C:\USERS\CHRISTIAN\Cookies\TMZSH5LI.txt [ Cookie:christian@c.atdmt.com/ ] C:\USERS\CHRISTIAN\Cookies\2RK3JUT2.txt [ Cookie:christian@tracker.vinsight.de/ ] C:\USERS\CHRISTIAN\Cookies\KO7QF06L.txt [ Cookie:christian@tracking.quisma.com/ ] C:\USERS\CHRISTIAN\Cookies\BI68553W.txt [ Cookie:christian@clkads.com/adServe/banners ] C:\USERS\CHRISTIAN\Cookies\JVSVL6O0.txt [ Cookie:christian@maniapub.trackmania.com/banner/ ] C:\USERS\CHRISTIAN\Cookies\O4X1A6H2.txt [ Cookie:christian@estat.com/ ] C:\USERS\CHRISTIAN\Cookies\PUAAKE99.txt [ Cookie:christian@highbeam.122.2o7.net/ ] C:\USERS\CHRISTIAN\Cookies\ADSUZ6HJ.txt [ Cookie:christian@kontera.com/ ] C:\USERS\CHRISTIAN\Cookies\BY0QWXXJ.txt [ Cookie:christian@adbrite.com/ ] C:\USERS\CHRISTIAN\Cookies\E2W0THS6.txt [ Cookie:christian@adtech.de/ ] C:\USERS\CHRISTIAN\Cookies\L7E2ZPUZ.txt [ Cookie:christian@ad.yieldmanager.com/ ] C:\USERS\CHRISTIAN\Cookies\E48IYZO1.txt [ Cookie:christian@media6degrees.com/ ] C:\USERS\CHRISTIAN\Cookies\7QXG1A4I.txt [ Cookie:christian@imrworldwide.com/cgi-bin ] C:\USERS\CHRISTIAN\Cookies\LK4NCCB4.txt [ Cookie:christian@ad4.adfarm1.adition.com/ ] C:\USERS\CHRISTIAN\Cookies\4BA9OZOG.txt [ Cookie:christian@ad3.adfarm1.adition.com/ ] C:\USERS\CHRISTIAN\Cookies\L64GFAMH.txt [ Cookie:christian@tradetracker.net/ ] C:\USERS\CHRISTIAN\Cookies\BFCNEM8H.txt [ Cookie:christian@adfarm1.adition.com/ ] C:\USERS\CHRISTIAN\Cookies\TDQNTMXQ.txt [ Cookie:christian@at.atwola.com/ ] C:\USERS\CHRISTIAN\Cookies\XGG12GAP.txt [ Cookie:christian@doubleclick.net/ ] C:\USERS\CHRISTIAN\Cookies\4L6X5QOU.txt [ Cookie:christian@atdmt.com/ ] C:\USERS\CHRISTIAN\Cookies\0L8I96FW.txt [ Cookie:christian@bs.serving-sys.com/ ] C:\USERS\CHRISTIAN\Cookies\JD8D55X6.txt [ Cookie:christian@2o7.net/ ] C:\USERS\CHRISTIAN\Cookies\6YFE43RP.txt [ Cookie:christian@statse.webtrendslive.com/ ] C:\USERS\CHRISTIAN\Cookies\ED6LURD3.txt [ Cookie:christian@adform.net/ ] C:\USERS\CHRISTIAN\Cookies\PUJ4Y68E.txt [ Cookie:christian@fastclick.net/ ] C:\USERS\CHRISTIAN\Cookies\15UENQ3R.txt [ Cookie:christian@collective-media.net/ ] C:\USERS\CHRISTIAN\Cookies\98PWVKBB.txt [ Cookie:christian@ww251.smartadserver.com/ ] C:\USERS\CHRISTIAN\Cookies\MXVB93CT.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1023106454/ ] C:\USERS\CHRISTIAN\Cookies\33C3NXDT.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/978602949/ ] C:\USERS\CHRISTIAN\Cookies\IMTFGO1N.txt [ Cookie:christian@edsa.122.2o7.net/ ] C:\USERS\CHRISTIAN\Cookies\2FF49X6Q.txt [ Cookie:christian@eaeacom.112.2o7.net/ ] delivery.ibanner.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9EXBQXJN ] .2o7.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .msnportal.112.2o7.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .amazon-adsystem.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .amazon-adsystem.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .doubleclick.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .atdmt.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] de.sitestat.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .webmasterplan.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .tradedoubler.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .webmasterplan.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .webmasterplan.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .tradedoubler.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .xiti.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .mediaplex.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .tradedoubler.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .tradedoubler.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] adx.chip.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] adx.chip.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] adx.chip.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .questionmarket.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .questionmarket.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] www.netdebit-counter.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .mediaplex.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] ad2.adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .atdmt.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .c1.atdmt.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .apmebf.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .smartadserver.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .mediaplex.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] ww251.smartadserver.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .bs.serving-sys.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .im.banner.t-online.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .im.banner.t-online.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .fastclick.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .im.banner.t-online.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .im.banner.t-online.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .tracking.quisma.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] .doubleclick.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ] |
14.09.2012, 14:35 | #30 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Cyber Crime Investigation Department Österreich - Trojaner Sieht ok aus, da wurden nur Cookies gefunden. Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie ) Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat. Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/ Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird. Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da. Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Cyber Crime Investigation Department Österreich - Trojaner |
administrator, anti-malware, antiviren-programm, appdata, autostart, crime, cyber crime, dateien, ergebnis, explorer, firefox, internet, keine verbindung, laptop, malwarebytes, mcafee, microsoft, mozilla, neustart, probleme, scan, software, super, system, temp, trojaner, verbindung, virus, wlan |