|
Plagegeister aller Art und deren Bekämpfung: Hesperbot nach TelebankingWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
05.04.2014, 10:55 | #16 |
| Hesperbot nach Telebanking Hallo Sandra! Keine Probleme mit dem Rechner. Hatte ich aber vorher auch nicht. Wenn Security Essentials nicht gemeldet hätte, dass es einen Trojaner gefunden hat, wäre es mir nicht aufgefallen. Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014 Ran by landumhollabrunn at 2014-04-05 09:31:06 Run:1 Running from C:\Users\landumhollabrunn\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** 2014-04-03 15:27 - 2014-04-03 15:25 - 00000000 ____D () C:\ProgramData\icuf 2014-04-03 15:25 - 2014-04-03 15:25 - 00000000 ____D () C:\ProgramData\usjk 2014-04-03 15:25 - 2014-04-03 15:24 - 00000000 ____D () C:\ProgramData\kghd 2014-04-03 15:25 - 2014-04-03 15:19 - 00000000 ____D () C:\ProgramData\okew 2014-04-03 15:25 - 2014-04-03 15:08 - 00000000 ____D () C:\ProgramData\ozet 2014-04-03 15:25 - 2014-04-03 14:19 - 00000000 ____D () C:\ProgramData\yjil 2014-04-03 15:24 - 2014-04-03 15:24 - 00000000 ____D () C:\ProgramData\ynyp 2014-04-03 15:24 - 2014-04-03 15:24 - 00000000 ____D () C:\ProgramData\oqup 2014-04-03 15:24 - 2014-04-03 15:24 - 00000000 ____D () C:\ProgramData\objm 2014-04-03 15:24 - 2014-04-03 15:24 - 00000000 ____D () C:\ProgramData\jjun 2014-04-03 15:24 - 2014-04-03 15:24 - 00000000 ____D () C:\ProgramData\imif 2014-04-03 15:24 - 2014-04-03 15:24 - 00000000 ____D () C:\ProgramData\exqr 2014-04-03 15:24 - 2014-04-03 15:24 - 00000000 ____D () C:\ProgramData\equg 2014-04-03 15:24 - 2014-04-03 15:24 - 00000000 ____D () C:\ProgramData\axaq 2014-04-03 15:24 - 2014-04-03 15:24 - 00000000 ____D () C:\ProgramData\alan 2014-04-03 15:24 - 2014-04-03 15:23 - 00000000 ____D () C:\ProgramData\uznm 2014-04-03 15:24 - 2014-04-03 15:17 - 00000000 ____D () C:\ProgramData\ujen 2014-04-03 15:24 - 2014-04-03 14:36 - 00000000 ____D () C:\ProgramData\ufow 2014-04-03 15:23 - 2014-04-03 15:23 - 00000000 ____D () C:\ProgramData\ysab 2014-04-03 15:23 - 2014-04-03 15:23 - 00000000 ____D () C:\ProgramData\yhyw 2014-04-03 15:23 - 2014-04-03 15:23 - 00000000 ____D () C:\ProgramData\yhys 2014-04-03 15:23 - 2014-04-03 15:23 - 00000000 ____D () C:\ProgramData\yhis 2014-04-03 15:23 - 2014-04-03 15:23 - 00000000 ____D () C:\ProgramData\xlug 2014-04-03 15:23 - 2014-04-03 15:23 - 00000000 ____D () C:\ProgramData\uwum 2014-04-03 15:23 - 2014-04-03 15:23 - 00000000 ____D () C:\ProgramData\ipaj 2014-04-03 15:23 - 2014-04-03 15:23 - 00000000 ____D () C:\ProgramData\inyv 2014-04-03 15:23 - 2014-04-03 15:23 - 00000000 ____D () C:\ProgramData\engx 2014-04-03 15:23 - 2014-04-03 15:23 - 00000000 ____D () C:\ProgramData\ejed 2014-04-03 15:23 - 2014-04-03 15:23 - 00000000 ____D () C:\ProgramData\ahiw 2014-04-03 15:23 - 2014-04-03 15:22 - 00000000 ____D () C:\ProgramData\epuq 2014-04-03 15:22 - 2014-04-03 15:22 - 00000000 ____D () C:\ProgramData\xluv 2014-04-03 15:22 - 2014-04-03 15:22 - 00000000 ____D () C:\ProgramData\ufjh 2014-04-03 15:22 - 2014-04-03 15:22 - 00000000 ____D () C:\ProgramData\olep 2014-04-03 15:22 - 2014-04-03 15:22 - 00000000 ____D () C:\ProgramData\knaq 2014-04-03 15:22 - 2014-04-03 15:22 - 00000000 ____D () C:\ProgramData\gmos 2014-04-03 15:22 - 2014-04-03 15:22 - 00000000 ____D () C:\ProgramData\exuj 2014-04-03 15:22 - 2014-04-03 15:22 - 00000000 ____D () C:\ProgramData\btaw 2014-04-03 15:22 - 2014-04-03 15:22 - 00000000 ____D () C:\ProgramData\agyx 2014-04-03 15:22 - 2014-04-03 15:16 - 00000000 ____D () C:\ProgramData\ebum 2014-04-03 15:22 - 2014-04-03 14:47 - 00000000 ____D () C:\ProgramData\oqep 2014-04-03 15:22 - 2014-04-03 14:20 - 00000000 ____D () C:\ProgramData\ozoc 2014-04-03 15:21 - 2014-04-03 15:21 - 00000000 ____D () C:\ProgramData\yjyl 2014-04-03 15:21 - 2014-04-03 15:21 - 00000000 ____D () C:\ProgramData\uron 2014-04-03 15:21 - 2014-04-03 15:21 - 00000000 ____D () C:\ProgramData\owut 2014-04-03 15:21 - 2014-04-03 15:21 - 00000000 ____D () C:\ProgramData\odpn 2014-04-03 15:21 - 2014-04-03 15:21 - 00000000 ____D () C:\ProgramData\ixaq 2014-04-03 15:21 - 2014-04-03 15:21 - 00000000 ____D () C:\ProgramData\iril 2014-04-03 15:21 - 2014-04-03 15:21 - 00000000 ____D () C:\ProgramData\ipix 2014-04-03 15:21 - 2014-04-03 15:21 - 00000000 ____D () C:\ProgramData\ific 2014-04-03 15:21 - 2014-04-03 15:21 - 00000000 ____D () C:\ProgramData\ekez 2014-04-03 15:21 - 2014-04-03 15:20 - 00000000 ____D () C:\ProgramData\owef 2014-04-03 15:21 - 2014-04-03 14:52 - 00000000 ____D () C:\ProgramData\ozum 2014-04-03 15:21 - 2014-04-03 14:21 - 00000000 ____D () C:\ProgramData\ejen 2014-04-03 15:20 - 2014-04-03 15:20 - 00000000 ____D () C:\ProgramData\yvid 2014-04-03 15:20 - 2014-04-03 15:20 - 00000000 ____D () C:\ProgramData\yfim 2014-04-03 15:20 - 2014-04-03 15:20 - 00000000 ____D () C:\ProgramData\uhut 2014-04-03 15:20 - 2014-04-03 15:20 - 00000000 ____D () C:\ProgramData\rdox 2014-04-03 15:20 - 2014-04-03 15:20 - 00000000 ____D () C:\ProgramData\oveg 2014-04-03 15:20 - 2014-04-03 15:20 - 00000000 ____D () C:\ProgramData\jxur 2014-04-03 15:20 - 2014-04-03 15:20 - 00000000 ____D () C:\ProgramData\jjoj 2014-04-03 15:20 - 2014-04-03 15:20 - 00000000 ____D () C:\ProgramData\ifyt 2014-04-03 15:20 - 2014-04-03 15:20 - 00000000 ____D () C:\ProgramData\etow 2014-04-03 15:20 - 2014-04-03 15:12 - 00000000 ____D () C:\ProgramData\ohuf 2014-04-03 15:20 - 2014-04-03 14:56 - 00000000 ____D () C:\ProgramData\ehem 2014-04-03 15:20 - 2014-04-03 14:21 - 00000000 ____D () C:\ProgramData\udon 2014-04-03 15:19 - 2014-04-03 15:19 - 00000000 ____D () C:\ProgramData\yktk 2014-04-03 15:19 - 2014-04-03 15:19 - 00000000 ____D () C:\ProgramData\ygix 2014-04-03 15:19 - 2014-04-03 15:19 - 00000000 ____D () C:\ProgramData\ycik 2014-04-03 15:19 - 2014-04-03 15:19 - 00000000 ____D () C:\ProgramData\upug 2014-04-03 15:19 - 2014-04-03 15:19 - 00000000 ____D () C:\ProgramData\onex 2014-04-03 15:19 - 2014-04-03 15:19 - 00000000 ____D () C:\ProgramData\oceb 2014-04-03 15:19 - 2014-04-03 15:19 - 00000000 ____D () C:\ProgramData\aziw 2014-04-03 15:19 - 2014-04-03 15:07 - 00000000 ____D () C:\ProgramData\asyw 2014-04-03 15:19 - 2014-04-03 14:58 - 00000000 ____D () C:\ProgramData\etus 2014-04-03 15:19 - 2014-04-03 14:44 - 00000000 ____D () C:\ProgramData\ycym 2014-04-03 15:18 - 2014-04-03 15:18 - 00000000 ____D () C:\ProgramData\ywas 2014-04-03 15:18 - 2014-04-03 15:18 - 00000000 ____D () C:\ProgramData\uvov 2014-04-03 15:18 - 2014-04-03 15:18 - 00000000 ____D () C:\ProgramData\usuk 2014-04-03 15:18 - 2014-04-03 15:18 - 00000000 ____D () C:\ProgramData\uqep 2014-04-03 15:18 - 2014-04-03 15:18 - 00000000 ____D () C:\ProgramData\obot 2014-04-03 15:18 - 2014-04-03 15:18 - 00000000 ____D () C:\ProgramData\lmob 2014-04-03 15:18 - 2014-04-03 15:18 - 00000000 ____D () C:\ProgramData\ikam 2014-04-03 15:18 - 2014-04-03 15:18 - 00000000 ____D () C:\ProgramData\awtw 2014-04-03 15:18 - 2014-04-03 15:18 - 00000000 ____D () C:\ProgramData\araq 2014-04-03 15:18 - 2014-04-03 15:18 - 00000000 ____D () C:\ProgramData\anap 2014-04-03 15:18 - 2014-04-03 15:06 - 00000000 ____D () C:\ProgramData\efos 2014-04-03 15:18 - 2014-04-03 14:51 - 00000000 ____D () C:\ProgramData\omow 2014-04-03 15:17 - 2014-04-03 15:17 - 00000000 ____D () C:\ProgramData\vlep 2014-04-03 15:17 - 2014-04-03 15:17 - 00000000 ____D () C:\ProgramData\uned 2014-04-03 15:17 - 2014-04-03 15:17 - 00000000 ____D () C:\ProgramData\ipyj 2014-04-03 15:17 - 2014-04-03 15:17 - 00000000 ____D () C:\ProgramData\akyt 2014-04-03 15:17 - 2014-04-03 15:16 - 00000000 ____D () C:\ProgramData\axag 2014-04-03 15:17 - 2014-04-03 15:03 - 00000000 ____D () C:\ProgramData\ykam 2014-04-03 15:17 - 2014-04-03 15:00 - 00000000 ____D () C:\ProgramData\izyw 2014-04-03 15:17 - 2014-04-03 14:48 - 00000000 ____D () C:\ProgramData\emeb 2014-04-03 15:17 - 2014-04-03 14:16 - 00000000 ____D () C:\ProgramData\ipid 2014-04-03 15:17 - 2014-04-03 14:16 - 00000000 ____D () C:\ProgramData\axil 2014-04-03 15:17 - 2014-04-03 14:10 - 00000000 ____D () C:\ProgramData\ylan 2014-04-03 15:16 - 2014-04-03 15:16 - 00000000 ____D () C:\ProgramData\uwut 2014-04-03 15:16 - 2014-04-03 15:16 - 00000000 ____D () C:\ProgramData\utgh 2014-04-03 15:16 - 2014-04-03 15:16 - 00000000 ____D () C:\ProgramData\ufub 2014-04-03 15:16 - 2014-04-03 15:16 - 00000000 ____D () C:\ProgramData\ixav 2014-04-03 15:16 - 2014-04-03 15:16 - 00000000 ____D () C:\ProgramData\idav 2014-04-03 15:16 - 2014-04-03 15:16 - 00000000 ____D () C:\ProgramData\idal 2014-04-03 15:16 - 2014-04-03 15:16 - 00000000 ____D () C:\ProgramData\ekeh 2014-04-03 15:16 - 2014-04-03 15:16 - 00000000 ____D () C:\ProgramData\ebek 2014-04-03 15:16 - 2014-04-03 15:16 - 00000000 ____D () C:\ProgramData\avir 2014-04-03 15:16 - 2014-04-03 15:15 - 00000000 ____D () C:\ProgramData\ylyn 2014-04-03 15:16 - 2014-04-03 15:02 - 00000000 ____D () C:\ProgramData\ecuw 2014-04-03 15:15 - 2014-04-03 15:15 - 00000000 ____D () C:\ProgramData\ylij 2014-04-03 15:15 - 2014-04-03 15:15 - 00000000 ____D () C:\ProgramData\ugqg 2014-04-03 15:15 - 2014-04-03 15:15 - 00000000 ____D () C:\ProgramData\okoz 2014-04-03 15:15 - 2014-04-03 15:15 - 00000000 ____D () C:\ProgramData\ofuh 2014-04-03 15:15 - 2014-04-03 15:15 - 00000000 ____D () C:\ProgramData\ifzc 2014-04-03 15:15 - 2014-04-03 15:15 - 00000000 ____D () C:\ProgramData\egep 2014-04-03 15:15 - 2014-04-03 15:14 - 00000000 ____D () C:\ProgramData\ymaf 2014-04-03 15:15 - 2014-04-03 14:55 - 00000000 ____D () C:\ProgramData\ywaw 2014-04-03 15:15 - 2014-04-03 14:43 - 00000000 ____D () C:\ProgramData\adig 2014-04-03 15:15 - 2014-04-03 14:40 - 00000000 ____D () C:\ProgramData\ifym 2014-04-03 15:15 - 2014-04-03 14:26 - 00000000 ____D () C:\ProgramData\ymam 2014-04-03 15:14 - 2014-04-03 15:14 - 00000000 ____D () C:\ProgramData\unun 2014-04-03 15:14 - 2014-04-03 15:14 - 00000000 ____D () C:\ProgramData\otnh 2014-04-03 15:14 - 2014-04-03 15:14 - 00000000 ____D () C:\ProgramData\ofoz 2014-04-03 15:14 - 2014-04-03 15:14 - 00000000 ____D () C:\ProgramData\azys 2014-04-03 15:14 - 2014-04-03 15:14 - 00000000 ____D () C:\ProgramData\azah 2014-04-03 15:14 - 2014-04-03 15:14 - 00000000 ____D () C:\ProgramData\awib 2014-04-03 15:14 - 2014-04-03 15:14 - 00000000 ____D () C:\ProgramData\asih 2014-04-03 15:14 - 2014-04-03 15:13 - 00000000 ____D () C:\ProgramData\lsom 2014-04-03 15:14 - 2014-04-03 14:40 - 00000000 ____D () C:\ProgramData\ipij 2014-04-03 15:14 - 2014-04-03 14:23 - 00000000 ____D () C:\ProgramData\yxip 2014-04-03 15:14 - 2014-04-03 14:14 - 00000000 ____D () C:\ProgramData\upel 2014-04-03 15:13 - 2014-04-03 15:13 - 00000000 ____D () C:\ProgramData\upol 2014-04-03 15:13 - 2014-04-03 15:13 - 00000000 ____D () C:\ProgramData\ugov 2014-04-03 15:13 - 2014-04-03 15:13 - 00000000 ____D () C:\ProgramData\oxun 2014-04-03 15:13 - 2014-04-03 15:13 - 00000000 ____D () C:\ProgramData\oxor 2014-04-03 15:13 - 2014-04-03 15:13 - 00000000 ____D () C:\ProgramData\jnjn 2014-04-03 15:13 - 2014-04-03 15:13 - 00000000 ____D () C:\ProgramData\hxil 2014-04-03 15:13 - 2014-04-03 15:13 - 00000000 ____D () C:\ProgramData\enor 2014-04-03 15:13 - 2014-04-03 15:13 - 00000000 ____D () C:\ProgramData\bsbs 2014-04-03 15:13 - 2014-04-03 15:05 - 00000000 ____D () C:\ProgramData\orej 2014-04-03 15:13 - 2014-04-03 14:32 - 00000000 ____D () C:\ProgramData\ohef 2014-04-03 15:13 - 2014-04-03 14:15 - 00000000 ____D () C:\ProgramData\avaj 2014-04-03 15:12 - 2014-04-03 15:12 - 00000000 ____D () C:\ProgramData\ypin 2014-04-03 15:12 - 2014-04-03 15:12 - 00000000 ____D () C:\ProgramData\otlb 2014-04-03 15:12 - 2014-04-03 15:12 - 00000000 ____D () C:\ProgramData\oboc 2014-04-03 15:12 - 2014-04-03 15:12 - 00000000 ____D () C:\ProgramData\jfgs 2014-04-03 15:12 - 2014-04-03 15:12 - 00000000 ____D () C:\ProgramData\idyq 2014-04-03 15:12 - 2014-04-03 15:12 - 00000000 ____D () C:\ProgramData\ezjf 2014-04-03 15:12 - 2014-04-03 15:12 - 00000000 ____D () C:\ProgramData\dwqc 2014-04-03 15:12 - 2014-04-03 15:12 - 00000000 ____D () C:\ProgramData\awih 2014-04-03 15:12 - 2014-04-03 15:11 - 00000000 ____D () C:\ProgramData\fral 2014-04-03 15:12 - 2014-04-03 14:53 - 00000000 ____D () C:\ProgramData\ityk 2014-04-03 15:12 - 2014-04-03 14:16 - 00000000 ____D () C:\ProgramData\ivix 2014-04-03 15:11 - 2014-04-03 15:11 - 00000000 ____D () C:\ProgramData\ydav 2014-04-03 15:11 - 2014-04-03 15:11 - 00000000 ____D () C:\ProgramData\uvoq 2014-04-03 15:11 - 2014-04-03 15:11 - 00000000 ____D () C:\ProgramData\qnex 2014-04-03 15:11 - 2014-04-03 15:11 - 00000000 ____D () C:\ProgramData\pron 2014-04-03 15:11 - 2014-04-03 15:11 - 00000000 ____D () C:\ProgramData\inig 2014-04-03 15:11 - 2014-04-03 15:11 - 00000000 ____D () C:\ProgramData\erxr 2014-04-03 15:11 - 2014-04-03 15:11 - 00000000 ____D () C:\ProgramData\ekew 2014-04-03 15:11 - 2014-04-03 15:11 - 00000000 ____D () C:\ProgramData\edur 2014-04-03 15:11 - 2014-04-03 15:10 - 00000000 ____D () C:\ProgramData\akzk 2014-04-03 15:11 - 2014-04-03 14:57 - 00000000 ____D () C:\ProgramData\odod 2014-04-03 15:11 - 2014-04-03 14:36 - 00000000 ____D () C:\ProgramData\ykyf 2014-04-03 15:10 - 2014-04-03 15:10 - 00000000 ____D () C:\ProgramData\yfyt 2014-04-03 15:10 - 2014-04-03 15:10 - 00000000 ____D () C:\ProgramData\ulqp 2014-04-03 15:10 - 2014-04-03 15:10 - 00000000 ____D () C:\ProgramData\ulov 2014-04-03 15:10 - 2014-04-03 15:10 - 00000000 ____D () C:\ProgramData\knal 2014-04-03 15:10 - 2014-04-03 15:10 - 00000000 ____D () C:\ProgramData\isiw 2014-04-03 15:10 - 2014-04-03 15:10 - 00000000 ____D () C:\ProgramData\ewec 2014-04-03 15:10 - 2014-04-03 15:10 - 00000000 ____D () C:\ProgramData\apir 2014-04-03 15:10 - 2014-04-03 15:10 - 00000000 ____D () C:\ProgramData\agax 2014-04-03 15:10 - 2014-04-03 15:09 - 00000000 ____D () C:\ProgramData\yvan 2014-04-03 15:10 - 2014-04-03 15:06 - 00000000 ____D () C:\ProgramData\upop 2014-04-03 15:10 - 2014-04-03 15:00 - 00000000 ____D () C:\ProgramData\yfic 2014-04-03 15:10 - 2014-04-03 14:54 - 00000000 ____D () C:\ProgramData\ehot 2014-04-03 15:09 - 2014-04-03 15:09 - 00000000 ____D () C:\ProgramData\ywyz 2014-04-03 15:09 - 2014-04-03 15:09 - 00000000 ____D () C:\ProgramData\ugug 2014-04-03 15:09 - 2014-04-03 15:09 - 00000000 ____D () C:\ProgramData\opeg 2014-04-03 15:09 - 2014-04-03 15:09 - 00000000 ____D () C:\ProgramData\ipyd 2014-04-03 15:09 - 2014-04-03 15:09 - 00000000 ____D () C:\ProgramData\erjx 2014-04-03 15:09 - 2014-04-03 15:09 - 00000000 ____D () C:\ProgramData\dbot 2014-04-03 15:09 - 2014-04-03 15:09 - 00000000 ____D () C:\ProgramData\akak 2014-04-03 15:09 - 2014-04-03 15:08 - 00000000 ____D () C:\ProgramData\ujoj 2014-04-03 15:09 - 2014-04-03 15:03 - 00000000 ____D () C:\ProgramData\olev 2014-04-03 15:09 - 2014-04-03 14:48 - 00000000 ____D () C:\ProgramData\eduj 2014-04-03 15:09 - 2014-04-03 14:43 - 00000000 ____D () C:\ProgramData\inal 2014-04-03 15:08 - 2014-04-03 15:08 - 00000000 ____D () C:\ProgramData\yfat 2014-04-03 15:08 - 2014-04-03 15:08 - 00000000 ____D () C:\ProgramData\ufeh 2014-04-03 15:08 - 2014-04-03 15:08 - 00000000 ____D () C:\ProgramData\ofeb 2014-04-03 15:08 - 2014-04-03 15:08 - 00000000 ____D () C:\ProgramData\lsek 2014-04-03 15:08 - 2014-04-03 15:08 - 00000000 ____D () C:\ProgramData\iqyr 2014-04-03 15:08 - 2014-04-03 15:08 - 00000000 ____D () C:\ProgramData\ilbn 2014-04-03 15:08 - 2014-04-03 15:08 - 00000000 ____D () C:\ProgramData\icyk 2014-04-03 15:08 - 2014-04-03 15:08 - 00000000 ____D () C:\ProgramData\adtv 2014-04-03 15:08 - 2014-04-03 15:08 - 00000000 ____D () C:\ProgramData\adfg 2014-04-03 15:08 - 2014-04-03 14:23 - 00000000 ____D () C:\ProgramData\ylin 2014-04-03 15:07 - 2014-04-03 15:07 - 00000000 ____D () C:\ProgramData\yzsz 2014-04-03 15:07 - 2014-04-03 15:07 - 00000000 ____D () C:\ProgramData\ywiw 2014-04-03 15:07 - 2014-04-03 15:07 - 00000000 ____D () C:\ProgramData\yril 2014-04-03 15:07 - 2014-04-03 15:07 - 00000000 ____D () C:\ProgramData\ypkx 2014-04-03 15:07 - 2014-04-03 15:07 - 00000000 ____D () C:\ProgramData\ygan 2014-04-03 15:07 - 2014-04-03 15:07 - 00000000 ____D () C:\ProgramData\udnd 2014-04-03 15:07 - 2014-04-03 15:07 - 00000000 ____D () C:\ProgramData\amim 2014-04-03 15:07 - 2014-04-03 14:56 - 00000000 ____D () C:\ProgramData\ulug 2014-04-03 15:07 - 2014-04-03 14:42 - 00000000 ____D () C:\ProgramData\yjiv 2014-04-03 15:07 - 2014-04-03 14:27 - 00000000 ____D () C:\ProgramData\ylad 2014-04-03 15:07 - 2014-04-03 14:09 - 00000000 ____D () C:\ProgramData\udun 2014-04-03 15:06 - 2014-04-03 15:06 - 00000000 ____D () C:\ProgramData\ywiz 2014-04-03 15:06 - 2014-04-03 15:06 - 00000000 ____D () C:\ProgramData\odor 2014-04-03 15:06 - 2014-04-03 15:06 - 00000000 ____D () C:\ProgramData\iryv 2014-04-03 15:06 - 2014-04-03 15:06 - 00000000 ____D () C:\ProgramData\edgd 2014-04-03 15:06 - 2014-04-03 15:06 - 00000000 ____D () C:\ProgramData\akkf 2014-04-03 15:06 - 2014-04-03 15:06 - 00000000 ____D () C:\ProgramData\abaw 2014-04-03 15:06 - 2014-04-03 15:05 - 00000000 ____D () C:\ProgramData\ygyj 2014-04-03 15:06 - 2014-04-03 14:49 - 00000000 ____D () C:\ProgramData\awaz 2014-04-03 15:06 - 2014-04-03 14:20 - 00000000 ____D () C:\ProgramData\ydig 2014-04-03 15:06 - 2014-04-03 14:18 - 00000000 ____D () C:\ProgramData\ikic 2014-04-03 15:05 - 2014-04-03 15:05 - 00000000 ____D () C:\ProgramData\uzuc 2014-04-03 15:05 - 2014-04-03 15:05 - 00000000 ____D () C:\ProgramData\uror 2014-04-03 15:05 - 2014-04-03 15:05 - 00000000 ____D () C:\ProgramData\umps 2014-04-03 15:05 - 2014-04-03 15:05 - 00000000 ____D () C:\ProgramData\qwet 2014-04-03 15:05 - 2014-04-03 15:05 - 00000000 ____D () C:\ProgramData\jjon 2014-04-03 15:05 - 2014-04-03 15:05 - 00000000 ____D () C:\ProgramData\ilad 2014-04-03 15:05 - 2014-04-03 15:05 - 00000000 ____D () C:\ProgramData\ijiv 2014-04-03 15:05 - 2014-04-03 15:05 - 00000000 ____D () C:\ProgramData\anmv 2014-04-03 15:05 - 2014-04-03 15:04 - 00000000 ____D () C:\ProgramData\aryp 2014-04-03 15:05 - 2014-04-03 14:29 - 00000000 ____D () C:\ProgramData\afik 2014-04-03 15:05 - 2014-04-03 14:13 - 00000000 ____D () C:\ProgramData\ecuh 2014-04-03 15:04 - 2014-04-03 15:04 - 00000000 ____D () C:\ProgramData\uxoj 2014-04-03 15:04 - 2014-04-03 15:04 - 00000000 ____D () C:\ProgramData\omuw 2014-04-03 15:04 - 2014-04-03 15:04 - 00000000 ____D () C:\ProgramData\obum 2014-04-03 15:04 - 2014-04-03 15:04 - 00000000 ____D () C:\ProgramData\jlol 2014-04-03 15:04 - 2014-04-03 15:04 - 00000000 ____D () C:\ProgramData\jkez 2014-04-03 15:04 - 2014-04-03 15:04 - 00000000 ____D () C:\ProgramData\exux 2014-04-03 15:04 - 2014-04-03 15:04 - 00000000 ____D () C:\ProgramData\djud 2014-04-03 15:04 - 2014-04-03 15:03 - 00000000 ____D () C:\ProgramData\ajig 2014-04-03 15:04 - 2014-04-03 14:49 - 00000000 ____D () C:\ProgramData\ywah 2014-04-03 15:04 - 2014-04-03 14:18 - 00000000 ____D () C:\ProgramData\asib 2014-04-03 15:04 - 2014-04-03 14:08 - 00000000 ____D () C:\ProgramData\ijyl 2014-04-03 15:03 - 2014-04-03 15:03 - 00000000 ____D () C:\ProgramData\ylaj 2014-04-03 15:03 - 2014-04-03 15:03 - 00000000 ____D () C:\ProgramData\ykaf 2014-04-03 15:03 - 2014-04-03 15:03 - 00000000 ____D () C:\ProgramData\uhum 2014-04-03 15:03 - 2014-04-03 15:03 - 00000000 ____D () C:\ProgramData\osoc 2014-04-03 15:03 - 2014-04-03 15:03 - 00000000 ____D () C:\ProgramData\egug 2014-04-03 15:03 - 2014-04-03 15:03 - 00000000 ____D () C:\ProgramData\aryg 2014-04-03 15:03 - 2014-04-03 15:02 - 00000000 ____D () C:\ProgramData\lzec 2014-04-03 15:03 - 2014-04-03 14:41 - 00000000 ____D () C:\ProgramData\ufob 2014-04-03 15:03 - 2014-04-03 14:21 - 00000000 ____D () C:\ProgramData\egop 2014-04-03 15:02 - 2014-04-03 15:02 - 00000000 ____D () C:\ProgramData\opjl 2014-04-03 15:02 - 2014-04-03 15:02 - 00000000 ____D () C:\ProgramData\ndur 2014-04-03 15:02 - 2014-04-03 15:02 - 00000000 ____D () C:\ProgramData\kzas 2014-04-03 15:02 - 2014-04-03 15:02 - 00000000 ____D () C:\ProgramData\iraq 2014-04-03 15:02 - 2014-04-03 15:02 - 00000000 ____D () C:\ProgramData\erur 2014-04-03 15:02 - 2014-04-03 15:02 - 00000000 ____D () C:\ProgramData\azyh 2014-04-03 15:02 - 2014-04-03 15:02 - 00000000 ____D () C:\ProgramData\asaw 2014-04-03 15:02 - 2014-04-03 15:02 - 00000000 ____D () C:\ProgramData\asas 2014-04-03 15:02 - 2014-04-03 15:01 - 00000000 ____D () C:\ProgramData\acac 2014-04-03 15:02 - 2014-04-03 14:56 - 00000000 ____D () C:\ProgramData\ydip 2014-04-03 15:01 - 2014-04-03 15:01 - 00000000 ____D () C:\ProgramData\ywss 2014-04-03 15:01 - 2014-04-03 15:01 - 00000000 ____D () C:\ProgramData\oqpp 2014-04-03 15:01 - 2014-04-03 15:01 - 00000000 ____D () C:\ProgramData\okgw 2014-04-03 15:01 - 2014-04-03 15:01 - 00000000 ____D () C:\ProgramData\ogug 2014-04-03 15:01 - 2014-04-03 15:01 - 00000000 ____D () C:\ProgramData\ofow 2014-04-03 15:01 - 2014-04-03 15:01 - 00000000 ____D () C:\ProgramData\jteb 2014-04-03 15:01 - 2014-04-03 15:01 - 00000000 ____D () C:\ProgramData\izah 2014-04-03 15:01 - 2014-04-03 15:01 - 00000000 ____D () C:\ProgramData\igar 2014-04-03 15:01 - 2014-04-03 15:01 - 00000000 ____D () C:\ProgramData\ejqd 2014-04-03 15:01 - 2014-04-03 15:01 - 00000000 ____D () C:\ProgramData\egll 2014-04-03 15:01 - 2014-04-03 15:00 - 00000000 ____D () C:\ProgramData\zhis 2014-04-03 15:01 - 2014-04-03 14:33 - 00000000 ____D () C:\ProgramData\erox 2014-04-03 15:00 - 2014-04-03 15:00 - 00000000 ____D () C:\ProgramData\uvuv 2014-04-03 15:00 - 2014-04-03 15:00 - 00000000 ____D () C:\ProgramData\ifyc 2014-04-03 15:00 - 2014-04-03 15:00 - 00000000 ____D () C:\ProgramData\evop 2014-04-03 15:00 - 2014-04-03 15:00 - 00000000 ____D () C:\ProgramData\esef 2014-04-03 15:00 - 2014-04-03 15:00 - 00000000 ____D () C:\ProgramData\ejon 2014-04-03 15:00 - 2014-04-03 15:00 - 00000000 ____D () C:\ProgramData\ahys 2014-04-03 15:00 - 2014-04-03 15:00 - 00000000 ____D () C:\ProgramData\acyt 2014-04-03 15:00 - 2014-04-03 14:59 - 00000000 ____D () C:\ProgramData\icic 2014-04-03 15:00 - 2014-04-03 14:25 - 00000000 ____D () C:\ProgramData\egup 2014-04-03 14:59 - 2014-04-03 14:59 - 00000000 ____D () C:\ProgramData\ytat 2014-04-03 14:59 - 2014-04-03 14:59 - 00000000 ____D () C:\ProgramData\ygij 2014-04-03 14:59 - 2014-04-03 14:59 - 00000000 ____D () C:\ProgramData\uvel 2014-04-03 14:59 - 2014-04-03 14:59 - 00000000 ____D () C:\ProgramData\uveg 2014-04-03 14:59 - 2014-04-03 14:59 - 00000000 ____D () C:\ProgramData\uhok 2014-04-03 14:59 - 2014-04-03 14:59 - 00000000 ____D () C:\ProgramData\udxr 2014-04-03 14:59 - 2014-04-03 14:59 - 00000000 ____D () C:\ProgramData\oded 2014-04-03 14:59 - 2014-04-03 14:59 - 00000000 ____D () C:\ProgramData\bcik 2014-04-03 14:59 - 2014-04-03 14:59 - 00000000 ____D () C:\ProgramData\awyw 2014-04-03 14:59 - 2014-04-03 14:18 - 00000000 ____D () C:\ProgramData\uxed 2014-04-03 14:59 - 2014-04-03 14:17 - 00000000 ____D () C:\ProgramData\ydal 2014-04-03 14:58 - 2014-04-03 14:58 - 00000000 ____D () C:\ProgramData\ytyf 2014-04-03 14:58 - 2014-04-03 14:58 - 00000000 ____D () C:\ProgramData\ycac 2014-04-03 14:58 - 2014-04-03 14:58 - 00000000 ____D () C:\ProgramData\qzef 2014-04-03 14:58 - 2014-04-03 14:58 - 00000000 ____D () C:\ProgramData\ohjf 2014-04-03 14:58 - 2014-04-03 14:58 - 00000000 ____D () C:\ProgramData\ivbx 2014-04-03 14:58 - 2014-04-03 14:58 - 00000000 ____D () C:\ProgramData\dlog 2014-04-03 14:58 - 2014-04-03 14:58 - 00000000 ____D () C:\ProgramData\avmn 2014-04-03 14:58 - 2014-04-03 14:57 - 00000000 ____D () C:\ProgramData\ojdn 2014-04-03 14:58 - 2014-04-03 14:20 - 00000000 ____D () C:\ProgramData\yrav 2014-04-03 14:57 - 2014-04-03 14:57 - 00000000 ____D () C:\ProgramData\yfkk 2014-04-03 14:57 - 2014-04-03 14:57 - 00000000 ____D () C:\ProgramData\pzoc 2014-04-03 14:57 - 2014-04-03 14:57 - 00000000 ____D () C:\ProgramData\otos 2014-04-03 14:57 - 2014-04-03 14:57 - 00000000 ____D () C:\ProgramData\hmim 2014-04-03 14:57 - 2014-04-03 14:57 - 00000000 ____D () C:\ProgramData\epog 2014-04-03 14:57 - 2014-04-03 14:57 - 00000000 ____D () C:\ProgramData\ebec 2014-04-03 14:57 - 2014-04-03 14:57 - 00000000 ____D () C:\ProgramData\avyj 2014-04-03 14:57 - 2014-04-03 14:40 - 00000000 ____D () C:\ProgramData\igij 2014-04-03 14:57 - 2014-04-03 14:18 - 00000000 ____D () C:\ProgramData\ejoj 2014-04-03 14:57 - 2014-04-03 14:16 - 00000000 ____D () C:\ProgramData\ohot 2014-04-03 14:57 - 2014-04-03 14:13 - 00000000 ____D () C:\ProgramData\ijag 2014-04-03 14:56 - 2014-04-03 14:56 - 00000000 ____D () C:\ProgramData\ugog 2014-04-03 14:56 - 2014-04-03 14:56 - 00000000 ____D () C:\ProgramData\ivij 2014-04-03 14:56 - 2014-04-03 14:56 - 00000000 ____D () C:\ProgramData\evel 2014-04-03 14:56 - 2014-04-03 14:56 - 00000000 ____D () C:\ProgramData\emez 2014-04-03 14:56 - 2014-04-03 14:56 - 00000000 ____D () C:\ProgramData\ebrt 2014-04-03 14:56 - 2014-04-03 14:51 - 00000000 ____D () C:\ProgramData\esec 2014-04-03 14:56 - 2014-04-03 14:28 - 00000000 ____D () C:\ProgramData\amic 2014-04-03 14:56 - 2014-04-03 14:13 - 00000000 ____D () C:\ProgramData\ylir 2014-04-03 14:55 - 2014-04-03 14:55 - 00000000 ____D () C:\ProgramData\uruj 2014-04-03 14:55 - 2014-04-03 14:55 - 00000000 ____D () C:\ProgramData\unpd 2014-04-03 14:55 - 2014-04-03 14:55 - 00000000 ____D () C:\ProgramData\odox 2014-04-03 14:55 - 2014-04-03 14:55 - 00000000 ____D () C:\ProgramData\obuf 2014-04-03 14:55 - 2014-04-03 14:55 - 00000000 ____D () C:\ProgramData\izmw 2014-04-03 14:55 - 2014-04-03 14:55 - 00000000 ____D () C:\ProgramData\enqn 2014-04-03 14:55 - 2014-04-03 14:55 - 00000000 ____D () C:\ProgramData\azih 2014-04-03 14:55 - 2014-04-03 14:55 - 00000000 ____D () C:\ProgramData\atif 2014-04-03 14:55 - 2014-04-03 14:55 - 00000000 ____D () C:\ProgramData\agar 2014-04-03 14:55 - 2014-04-03 14:36 - 00000000 ____D () C:\ProgramData\epoq 2014-04-03 14:55 - 2014-04-03 14:21 - 00000000 ____D () C:\ProgramData\upeg 2014-04-03 14:54 - 2014-04-03 14:54 - 00000000 ____D () C:\ProgramData\ygax 2014-04-03 14:54 - 2014-04-03 14:54 - 00000000 ____D () C:\ProgramData\itif 2014-04-03 14:54 - 2014-04-03 14:54 - 00000000 ____D () C:\ProgramData\isib 2014-04-03 14:54 - 2014-04-03 14:54 - 00000000 ____D () C:\ProgramData\imat 2014-04-03 14:54 - 2014-04-03 14:54 - 00000000 ____D () C:\ProgramData\exen 2014-04-03 14:54 - 2014-04-03 14:54 - 00000000 ____D () C:\ProgramData\emoh 2014-04-03 14:54 - 2014-04-03 14:54 - 00000000 ____D () C:\ProgramData\aril 2014-04-03 14:54 - 2014-04-03 14:54 - 00000000 ____D () C:\ProgramData\afak 2014-04-03 14:54 - 2014-04-03 14:27 - 00000000 ____D () C:\ProgramData\uxod 2014-04-03 14:54 - 2014-04-03 14:12 - 00000000 ____D () C:\ProgramData\ujor 2014-04-03 14:54 - 2014-04-03 14:09 - 00000000 ____D () C:\ProgramData\yqir 2014-04-03 14:53 - 2014-04-03 14:53 - 00000000 ____D () C:\ProgramData\vsut 2014-04-03 14:53 - 2014-04-03 14:53 - 00000000 ____D () C:\ProgramData\ogov 2014-04-03 14:53 - 2014-04-03 14:53 - 00000000 ____D () C:\ProgramData\icak 2014-04-03 14:53 - 2014-04-03 14:53 - 00000000 ____D () C:\ProgramData\ezdc 2014-04-03 14:53 - 2014-04-03 14:53 - 00000000 ____D () C:\ProgramData\agyj 2014-04-03 14:53 - 2014-04-03 14:53 - 00000000 ____D () C:\ProgramData\afyt 2014-04-03 14:53 - 2014-04-03 14:52 - 00000000 ____D () C:\ProgramData\ofob 2014-04-03 14:53 - 2014-04-03 14:45 - 00000000 ____D () C:\ProgramData\ydyq 2014-04-03 14:53 - 2014-04-03 14:28 - 00000000 ____D () C:\ProgramData\owok 2014-04-03 14:52 - 2014-04-03 14:52 - 00000000 ____D () C:\ProgramData\ymak 2014-04-03 14:52 - 2014-04-03 14:52 - 00000000 ____D () C:\ProgramData\usek 2014-04-03 14:52 - 2014-04-03 14:52 - 00000000 ____D () C:\ProgramData\uluv 2014-04-03 14:52 - 2014-04-03 14:52 - 00000000 ____D () C:\ProgramData\smac 2014-04-03 14:52 - 2014-04-03 14:52 - 00000000 ____D () C:\ProgramData\ozjt 2014-04-03 14:52 - 2014-04-03 14:52 - 00000000 ____D () C:\ProgramData\ilax 2014-04-03 14:52 - 2014-04-03 14:52 - 00000000 ____D () C:\ProgramData\igax 2014-04-03 14:52 - 2014-04-03 14:51 - 00000000 ____D () C:\ProgramData\hhyh 2014-04-03 14:52 - 2014-04-03 14:43 - 00000000 ____D () C:\ProgramData\ahih 2014-04-03 14:52 - 2014-04-03 14:29 - 00000000 ____D () C:\ProgramData\utoz 2014-04-03 14:51 - 2014-04-03 14:51 - 00000000 ____D () C:\ProgramData\wmit 2014-04-03 14:51 - 2014-04-03 14:51 - 00000000 ____D () C:\ProgramData\utew 2014-04-03 14:51 - 2014-04-03 14:51 - 00000000 ____D () C:\ProgramData\orun 2014-04-03 14:51 - 2014-04-03 14:51 - 00000000 ____D () C:\ProgramData\oquv 2014-04-03 14:51 - 2014-04-03 14:51 - 00000000 ____D () C:\ProgramData\jfus 2014-04-03 14:51 - 2014-04-03 14:51 - 00000000 ____D () C:\ProgramData\ixiq 2014-04-03 14:51 - 2014-04-03 14:51 - 00000000 ____D () C:\ProgramData\efqh 2014-04-03 14:51 - 2014-04-03 14:51 - 00000000 ____D () C:\ProgramData\axal 2014-04-03 14:51 - 2014-04-03 14:51 - 00000000 ____D () C:\ProgramData\asys 2014-04-03 14:51 - 2014-04-03 14:50 - 00000000 ____D () C:\ProgramData\bxal 2014-04-03 14:50 - 2014-04-03 14:50 - 00000000 ____D () C:\ProgramData\yzih 2014-04-03 14:50 - 2014-04-03 14:50 - 00000000 ____D () C:\ProgramData\xklh 2014-04-03 14:50 - 2014-04-03 14:50 - 00000000 ____D () C:\ProgramData\usef 2014-04-03 14:50 - 2014-04-03 14:50 - 00000000 ____D () C:\ProgramData\ozuk 2014-04-03 14:50 - 2014-04-03 14:50 - 00000000 ____D () C:\ProgramData\ijig 2014-04-03 14:50 - 2014-04-03 14:50 - 00000000 ____D () C:\ProgramData\idip 2014-04-03 14:50 - 2014-04-03 14:50 - 00000000 ____D () C:\ProgramData\esuk 2014-04-03 14:50 - 2014-04-03 14:50 - 00000000 ____D () C:\ProgramData\ehuf 2014-04-03 14:50 - 2014-04-03 14:50 - 00000000 ____D () C:\ProgramData\agij 2014-04-03 14:50 - 2014-04-03 14:11 - 00000000 ____D () C:\ProgramData\ujod 2014-04-03 14:49 - 2014-04-03 14:49 - 00000000 ____D () C:\ProgramData\ykwf 2014-04-03 14:49 - 2014-04-03 14:49 - 00000000 ____D () C:\ProgramData\otuw 2014-04-03 14:49 - 2014-04-03 14:49 - 00000000 ____D () C:\ProgramData\otew 2014-04-03 14:49 - 2014-04-03 14:49 - 00000000 ____D () C:\ProgramData\opul 2014-04-03 14:49 - 2014-04-03 14:49 - 00000000 ____D () C:\ProgramData\ollg 2014-04-03 14:49 - 2014-04-03 14:49 - 00000000 ____D () C:\ProgramData\isah 2014-04-03 14:49 - 2014-04-03 14:49 - 00000000 ____D () C:\ProgramData\icam 2014-04-03 14:49 - 2014-04-03 14:49 - 00000000 ____D () C:\ProgramData\epep 2014-04-03 14:49 - 2014-04-03 14:47 - 00000000 ____D () C:\ProgramData\otow 2014-04-03 14:49 - 2014-04-03 14:27 - 00000000 ____D () C:\ProgramData\ybyb 2014-04-03 14:49 - 2014-04-03 14:12 - 00000000 ____D () C:\ProgramData\evov 2014-04-03 14:48 - 2014-04-03 14:48 - 00000000 ____D () C:\ProgramData\yzah 2014-04-03 14:48 - 2014-04-03 14:48 - 00000000 ____D () C:\ProgramData\yvyj 2014-04-03 14:48 - 2014-04-03 14:48 - 00000000 ____D () C:\ProgramData\tfit 2014-04-03 14:48 - 2014-04-03 14:48 - 00000000 ____D () C:\ProgramData\shis 2014-04-03 14:48 - 2014-04-03 14:48 - 00000000 ____D () C:\ProgramData\ipin 2014-04-03 14:48 - 2014-04-03 14:48 - 00000000 ____D () C:\ProgramData\ihyw 2014-04-03 14:48 - 2014-04-03 14:48 - 00000000 ____D () C:\ProgramData\exoj 2014-04-03 14:48 - 2014-04-03 14:48 - 00000000 ____D () C:\ProgramData\chys 2014-04-03 14:47 - 2014-04-03 14:47 - 00000000 ____D () C:\ProgramData\yxiq 2014-04-03 14:47 - 2014-04-03 14:47 - 00000000 ____D () C:\ProgramData\ysyw 2014-04-03 14:47 - 2014-04-03 14:47 - 00000000 ____D () C:\ProgramData\oxex 2014-04-03 14:47 - 2014-04-03 14:47 - 00000000 ____D () C:\ProgramData\lzoc 2014-04-03 14:47 - 2014-04-03 14:47 - 00000000 ____D () C:\ProgramData\iqyd 2014-04-03 14:47 - 2014-04-03 14:47 - 00000000 ____D () C:\ProgramData\gcuz 2014-04-03 14:47 - 2014-04-03 14:47 - 00000000 ____D () C:\ProgramData\fwyz 2014-04-03 14:47 - 2014-04-03 14:47 - 00000000 ____D () C:\ProgramData\acif 2014-04-03 14:47 - 2014-04-03 14:46 - 00000000 ____D () C:\ProgramData\ehuc 2014-04-03 14:47 - 2014-04-03 14:34 - 00000000 ____D () C:\ProgramData\ewof 2014-04-03 14:46 - 2014-04-03 14:46 - 00000000 ____D () C:\ProgramData\utub 2014-04-03 14:46 - 2014-04-03 14:46 - 00000000 ____D () C:\ProgramData\upep 2014-04-03 14:46 - 2014-04-03 14:46 - 00000000 ____D () C:\ProgramData\unox 2014-04-03 14:46 - 2014-04-03 14:46 - 00000000 ____D () C:\ProgramData\ubjm 2014-04-03 14:46 - 2014-04-03 14:46 - 00000000 ____D () C:\ProgramData\oxej 2014-04-03 14:46 - 2014-04-03 14:46 - 00000000 ____D () C:\ProgramData\omoz 2014-04-03 14:46 - 2014-04-03 14:46 - 00000000 ____D () C:\ProgramData\ohuc 2014-04-03 14:46 - 2014-04-03 14:46 - 00000000 ____D () C:\ProgramData\mqsd 2014-04-03 14:46 - 2014-04-03 14:46 - 00000000 ____D () C:\ProgramData\isyh 2014-04-03 14:46 - 2014-04-03 14:46 - 00000000 ____D () C:\ProgramData\agyr 2014-04-03 14:46 - 2014-04-03 14:45 - 00000000 ____D () C:\ProgramData\fvir 2014-04-03 14:45 - 2014-04-03 14:45 - 00000000 ____D () C:\ProgramData\yzas 2014-04-03 14:45 - 2014-04-03 14:45 - 00000000 ____D () C:\ProgramData\ynil 2014-04-03 14:45 - 2014-04-03 14:45 - 00000000 ____D () C:\ProgramData\utak 2014-04-03 14:45 - 2014-04-03 14:45 - 00000000 ____D () C:\ProgramData\urej 2014-04-03 14:45 - 2014-04-03 14:45 - 00000000 ____D () C:\ProgramData\tcat 2014-04-03 14:45 - 2014-04-03 14:45 - 00000000 ____D () C:\ProgramData\ifim 2014-04-03 14:45 - 2014-04-03 14:45 - 00000000 ____D () C:\ProgramData\ibaz 2014-04-03 14:45 - 2014-04-03 14:45 - 00000000 ____D () C:\ProgramData\asab 2014-04-03 14:45 - 2014-04-03 14:44 - 00000000 ____D () C:\ProgramData\ajyq 2014-04-03 14:45 - 2014-04-03 14:42 - 00000000 ____D () C:\ProgramData\ozof 2014-04-03 14:44 - 2014-04-03 14:44 - 00000000 ____D () C:\ProgramData\uqlq 2014-04-03 14:44 - 2014-04-03 14:44 - 00000000 ____D () C:\ProgramData\uguq 2014-04-03 14:44 - 2014-04-03 14:44 - 00000000 ____D () C:\ProgramData\olgq 2014-04-03 14:44 - 2014-04-03 14:44 - 00000000 ____D () C:\ProgramData\ihyb 2014-04-03 14:44 - 2014-04-03 14:44 - 00000000 ____D () C:\ProgramData\hsiz 2014-04-03 14:44 - 2014-04-03 14:44 - 00000000 ____D () C:\ProgramData\ewoc 2014-04-03 14:44 - 2014-04-03 14:44 - 00000000 ____D () C:\ProgramData\ajip 2014-04-03 14:44 - 2014-04-03 14:43 - 00000000 ____D () C:\ProgramData\iftc 2014-04-03 14:44 - 2014-04-03 14:43 - 00000000 ____D () C:\ProgramData\atit 2014-04-03 14:44 - 2014-04-03 14:39 - 00000000 ____D () C:\ProgramData\ifyf 2014-04-03 14:44 - 2014-04-03 14:31 - 00000000 ____D () C:\ProgramData\erux 2014-04-03 14:43 - 2014-04-03 14:43 - 00000000 ____D () C:\ProgramData\ydyv 2014-04-03 14:43 - 2014-04-03 14:43 - 00000000 ____D () C:\ProgramData\upuq 2014-04-03 14:43 - 2014-04-03 14:43 - 00000000 ____D () C:\ProgramData\olul 2014-04-03 14:43 - 2014-04-03 14:43 - 00000000 ____D () C:\ProgramData\okeb 2014-04-03 14:43 - 2014-04-03 14:43 - 00000000 ____D () C:\ProgramData\esdt 2014-04-03 14:43 - 2014-04-03 14:43 - 00000000 ____D () C:\ProgramData\aqyj 2014-04-03 14:43 - 2014-04-03 14:42 - 00000000 ____D () C:\ProgramData\yntp 2014-04-03 14:43 - 2014-04-03 14:10 - 00000000 ____D () C:\ProgramData\ihys 2014-04-03 14:42 - 2014-04-03 14:42 - 00000000 ____D () C:\ProgramData\ypij 2014-04-03 14:42 - 2014-04-03 14:42 - 00000000 ____D () C:\ProgramData\ygyx 2014-04-03 14:42 - 2014-04-03 14:42 - 00000000 ____D () C:\ProgramData\owof 2014-04-03 14:42 - 2014-04-03 14:42 - 00000000 ____D () C:\ProgramData\inyl 2014-04-03 14:42 - 2014-04-03 14:42 - 00000000 ____D () C:\ProgramData\ewjm 2014-04-03 14:42 - 2014-04-03 14:42 - 00000000 ____D () C:\ProgramData\etuh 2014-04-03 14:42 - 2014-04-03 14:42 - 00000000 ____D () C:\ProgramData\arkv 2014-04-03 14:42 - 2014-04-03 14:42 - 00000000 ____D () C:\ProgramData\arcg 2014-04-03 14:41 - 2014-04-03 14:41 - 00000000 ____D () C:\ProgramData\ykyc 2014-04-03 14:41 - 2014-04-03 14:41 - 00000000 ____D () C:\ProgramData\yjag 2014-04-03 14:41 - 2014-04-03 14:41 - 00000000 ____D () C:\ProgramData\uqpp 2014-04-03 14:41 - 2014-04-03 14:41 - 00000000 ____D () C:\ProgramData\orex 2014-04-03 14:41 - 2014-04-03 14:41 - 00000000 ____D () C:\ProgramData\kfat 2014-04-03 14:41 - 2014-04-03 14:41 - 00000000 ____D () C:\ProgramData\igmd 2014-04-03 14:41 - 2014-04-03 14:41 - 00000000 ____D () C:\ProgramData\ibah 2014-04-03 14:41 - 2014-04-03 14:41 - 00000000 ____D () C:\ProgramData\epdp 2014-04-03 14:41 - 2014-04-03 14:41 - 00000000 ____D () C:\ProgramData\enun 2014-04-03 14:41 - 2014-04-03 14:41 - 00000000 ____D () C:\ProgramData\ejod 2014-04-03 14:41 - 2014-04-03 14:40 - 00000000 ____D () C:\ProgramData\jder 2014-04-03 14:40 - 2014-04-03 14:40 - 00000000 ____D () C:\ProgramData\yxaq 2014-04-03 14:40 - 2014-04-03 14:40 - 00000000 ____D () C:\ProgramData\yfif 2014-04-03 14:40 - 2014-04-03 14:40 - 00000000 ____D () C:\ProgramData\ovlg 2014-04-03 14:40 - 2014-04-03 14:40 - 00000000 ____D () C:\ProgramData\nmuw 2014-04-03 14:40 - 2014-04-03 14:40 - 00000000 ____D () C:\ProgramData\nboc 2014-04-03 14:40 - 2014-04-03 14:40 - 00000000 ____D () C:\ProgramData\iqar 2014-04-03 14:40 - 2014-04-03 14:40 - 00000000 ____D () C:\ProgramData\afyf 2014-04-03 14:39 - 2014-04-03 14:39 - 00000000 ____D () C:\ProgramData\ydap 2014-04-03 14:39 - 2014-04-03 14:39 - 00000000 ____D () C:\ProgramData\ycyc 2014-04-03 14:39 - 2014-04-03 14:39 - 00000000 ____D () C:\ProgramData\ufuh 2014-04-03 14:39 - 2014-04-03 14:39 - 00000000 ____D () C:\ProgramData\ubum 2014-04-03 14:39 - 2014-04-03 14:39 - 00000000 ____D () C:\ProgramData\scit 2014-04-03 14:39 - 2014-04-03 14:39 - 00000000 ____D () C:\ProgramData\otoh 2014-04-03 14:39 - 2014-04-03 14:39 - 00000000 ____D () C:\ProgramData\ogup 2014-04-03 14:39 - 2014-04-03 14:39 - 00000000 ____D () C:\ProgramData\odur 2014-04-03 14:39 - 2014-04-03 14:39 - 00000000 ____D () C:\ProgramData\icit 2014-04-03 14:39 - 2014-04-03 14:39 - 00000000 ____D () C:\ProgramData\eqoq 2014-04-03 14:39 - 2014-04-03 14:39 - 00000000 ____D () C:\ProgramData\afaf 2014-04-03 14:39 - 2014-04-03 14:38 - 00000000 ____D () C:\ProgramData\ohoc 2014-04-03 14:38 - 2014-04-03 14:38 - 00000000 ____D () C:\ProgramData\ynaq 2014-04-03 14:38 - 2014-04-03 14:38 - 00000000 ____D () C:\ProgramData\ylyr 2014-04-03 14:38 - 2014-04-03 14:38 - 00000000 ____D () C:\ProgramData\vdox 2014-04-03 14:38 - 2014-04-03 14:38 - 00000000 ____D () C:\ProgramData\umos 2014-04-03 14:38 - 2014-04-03 14:38 - 00000000 ____D () C:\ProgramData\uloq 2014-04-03 14:38 - 2014-04-03 14:38 - 00000000 ____D () C:\ProgramData\uhec 2014-04-03 14:38 - 2014-04-03 14:38 - 00000000 ____D () C:\ProgramData\sxiq 2014-04-03 14:38 - 2014-04-03 14:38 - 00000000 ____D () C:\ProgramData\omob 2014-04-03 14:38 - 2014-04-03 14:38 - 00000000 ____D () C:\ProgramData\iryg 2014-04-03 14:38 - 2014-04-03 14:38 - 00000000 ____D () C:\ProgramData\ipyx 2014-04-03 14:38 - 2014-04-03 14:38 - 00000000 ____D () C:\ProgramData\anbl 2014-04-03 14:38 - 2014-04-03 14:37 - 00000000 ____D () C:\ProgramData\ilsx 2014-04-03 14:37 - 2014-04-03 14:37 - 00000000 ____D () C:\ProgramData\yxig 2014-04-03 14:37 - 2014-04-03 14:37 - 00000000 ____D () C:\ProgramData\ykyk 2014-04-03 14:37 - 2014-04-03 14:37 - 00000000 ____D () C:\ProgramData\upjl 2014-04-03 14:37 - 2014-04-03 14:37 - 00000000 ____D () C:\ProgramData\twys 2014-04-03 14:37 - 2014-04-03 14:37 - 00000000 ____D () C:\ProgramData\pgvq 2014-04-03 14:37 - 2014-04-03 14:37 - 00000000 ____D () C:\ProgramData\iwyz 2014-04-03 14:37 - 2014-04-03 14:37 - 00000000 ____D () C:\ProgramData\iwih 2014-04-03 14:37 - 2014-04-03 14:37 - 00000000 ____D () C:\ProgramData\etub 2014-04-03 14:37 - 2014-04-03 14:37 - 00000000 ____D () C:\ProgramData\emuw 2014-04-03 14:37 - 2014-04-03 14:37 - 00000000 ____D () C:\ProgramData\bdyl 2014-04-03 14:37 - 2014-04-03 14:36 - 00000000 ____D () C:\ProgramData\ilyn 2014-04-03 14:36 - 2014-04-03 14:36 - 00000000 ____D () C:\ProgramData\uwok 2014-04-03 14:36 - 2014-04-03 14:36 - 00000000 ____D () C:\ProgramData\upul 2014-04-03 14:36 - 2014-04-03 14:36 - 00000000 ____D () C:\ProgramData\owgk 2014-04-03 14:36 - 2014-04-03 14:36 - 00000000 ____D () C:\ProgramData\otus 2014-04-03 14:36 - 2014-04-03 14:36 - 00000000 ____D () C:\ProgramData\ofeh 2014-04-03 14:36 - 2014-04-03 14:36 - 00000000 ____D () C:\ProgramData\ekus 2014-04-03 14:36 - 2014-04-03 14:35 - 00000000 ____D () C:\ProgramData\ikac 2014-04-03 14:35 - 2014-04-03 14:35 - 00000000 ____D () C:\ProgramData\ykim 2014-04-03 14:35 - 2014-04-03 14:35 - 00000000 ____D () C:\ProgramData\uxur 2014-04-03 14:35 - 2014-04-03 14:35 - 00000000 ____D () C:\ProgramData\urjx 2014-04-03 14:35 - 2014-04-03 14:35 - 00000000 ____D () C:\ProgramData\uqol 2014-04-03 14:35 - 2014-04-03 14:35 - 00000000 ____D () C:\ProgramData\unqn 2014-04-03 14:35 - 2014-04-03 14:35 - 00000000 ____D () C:\ProgramData\uhoc 2014-04-03 14:35 - 2014-04-03 14:35 - 00000000 ____D () C:\ProgramData\kbts 2014-04-03 14:35 - 2014-04-03 14:35 - 00000000 ____D () C:\ProgramData\ifit 2014-04-03 14:35 - 2014-04-03 14:35 - 00000000 ____D () C:\ProgramData\ezoc 2014-04-03 14:35 - 2014-04-03 14:35 - 00000000 ____D () C:\ProgramData\ewut 2014-04-03 14:35 - 2014-04-03 14:21 - 00000000 ____D () C:\ProgramData\yzyh 2014-04-03 14:34 - 2014-04-03 14:34 - 00000000 ____D () C:\ProgramData\ugup 2014-04-03 14:34 - 2014-04-03 14:34 - 00000000 ____D () C:\ProgramData\udex 2014-04-03 14:34 - 2014-04-03 14:34 - 00000000 ____D () C:\ProgramData\opeq 2014-04-03 14:34 - 2014-04-03 14:34 - 00000000 ____D () C:\ProgramData\inyg 2014-04-03 14:34 - 2014-04-03 14:34 - 00000000 ____D () C:\ProgramData\ikak 2014-04-03 14:34 - 2014-04-03 14:34 - 00000000 ____D () C:\ProgramData\ezrf 2014-04-03 14:34 - 2014-04-03 14:34 - 00000000 ____D () C:\ProgramData\ezom 2014-04-03 14:34 - 2014-04-03 14:34 - 00000000 ____D () C:\ProgramData\edud 2014-04-03 14:34 - 2014-04-03 14:34 - 00000000 ____D () C:\ProgramData\asyb 2014-04-03 14:34 - 2014-04-03 14:34 - 00000000 ____D () C:\ProgramData\ahib 2014-04-03 14:34 - 2014-04-03 14:33 - 00000000 ____D () C:\ProgramData\otqz 2014-04-03 14:33 - 2014-04-03 14:33 - 00000000 ____D () C:\ProgramData\zvyj 2014-04-03 14:33 - 2014-04-03 14:33 - 00000000 ____D () C:\ProgramData\ytac 2014-04-03 14:33 - 2014-04-03 14:33 - 00000000 ____D () C:\ProgramData\opuq 2014-04-03 14:33 - 2014-04-03 14:33 - 00000000 ____D () C:\ProgramData\opel 2014-04-03 14:33 - 2014-04-03 14:33 - 00000000 ____D () C:\ProgramData\ixag 2014-04-03 14:33 - 2014-04-03 14:33 - 00000000 ____D () C:\ProgramData\ahiz 2014-04-03 14:33 - 2014-04-03 14:32 - 00000000 ____D () C:\ProgramData\ackt 2014-04-03 14:33 - 2014-04-03 14:12 - 00000000 ____D () C:\ProgramData\afym 2014-04-03 14:32 - 2014-04-03 14:32 - 00000000 ____D () C:\ProgramData\yrap 2014-04-03 14:32 - 2014-04-03 14:32 - 00000000 ____D () C:\ProgramData\uwoc 2014-04-03 14:32 - 2014-04-03 14:32 - 00000000 ____D () C:\ProgramData\iziz 2014-04-03 14:32 - 2014-04-03 14:32 - 00000000 ____D () C:\ProgramData\imik 2014-04-03 14:32 - 2014-04-03 14:32 - 00000000 ____D () C:\ProgramData\igyj 2014-04-03 14:32 - 2014-04-03 14:32 - 00000000 ____D () C:\ProgramData\hxag 2014-04-03 14:32 - 2014-04-03 14:32 - 00000000 ____D () C:\ProgramData\awab 2014-04-03 14:32 - 2014-04-03 14:32 - 00000000 ____D () C:\ProgramData\arip 2014-04-03 14:32 - 2014-04-03 14:32 - 00000000 ____D () C:\ProgramData\adap 2014-04-03 14:32 - 2014-04-03 14:31 - 00000000 ____D () C:\ProgramData\awas 2014-04-03 14:32 - 2014-04-03 14:29 - 00000000 ____D () C:\ProgramData\uduj 2014-04-03 14:31 - 2014-04-03 14:31 - 00000000 ____D () C:\ProgramData\ubok 2014-04-03 14:31 - 2014-04-03 14:31 - 00000000 ____D () C:\ProgramData\orux 2014-04-03 14:31 - 2014-04-03 14:31 - 00000000 ____D () C:\ProgramData\ohof 2014-04-03 14:31 - 2014-04-03 14:31 - 00000000 ____D () C:\ProgramData\ifaf 2014-04-03 14:31 - 2014-04-03 14:31 - 00000000 ____D () C:\ProgramData\idzq 2014-04-03 14:31 - 2014-04-03 14:31 - 00000000 ____D () C:\ProgramData\ecrs 2014-04-03 14:31 - 2014-04-03 14:31 - 00000000 ____D () C:\ProgramData\ajiq 2014-04-03 14:31 - 2014-04-03 14:31 - 00000000 ____D () C:\ProgramData\acik 2014-04-03 14:31 - 2014-04-03 14:31 - 00000000 ____D () C:\ProgramData\abih 2014-04-03 14:31 - 2014-04-03 14:30 - 00000000 ____D () C:\ProgramData\ajag 2014-04-03 14:30 - 2014-04-03 14:30 - 00000000 ____D () C:\ProgramData\wbyh 2014-04-03 14:30 - 2014-04-03 14:30 - 00000000 ____D () C:\ProgramData\ssss 2014-04-03 14:30 - 2014-04-03 14:30 - 00000000 ____D () C:\ProgramData\ojux 2014-04-03 14:30 - 2014-04-03 14:30 - 00000000 ____D () C:\ProgramData\obok 2014-04-03 14:30 - 2014-04-03 14:30 - 00000000 ____D () C:\ProgramData\lxvn 2014-04-03 14:30 - 2014-04-03 14:30 - 00000000 ____D () C:\ProgramData\inyp 2014-04-03 14:30 - 2014-04-03 14:30 - 00000000 ____D () C:\ProgramData\ihih 2014-04-03 14:30 - 2014-04-03 14:30 - 00000000 ____D () C:\ProgramData\afyc 2014-04-03 14:30 - 2014-04-03 14:30 - 00000000 ____D () C:\ProgramData\afac 2014-04-03 14:30 - 2014-04-03 14:29 - 00000000 ____D () C:\ProgramData\ewuk 2014-04-03 14:30 - 2014-04-03 14:13 - 00000000 ____D () C:\ProgramData\izis 2014-04-03 14:29 - 2014-04-03 14:29 - 00000000 ____D () C:\ProgramData\yfyc 2014-04-03 14:29 - 2014-04-03 14:29 - 00000000 ____D () C:\ProgramData\xxon 2014-04-03 14:29 - 2014-04-03 14:29 - 00000000 ____D () C:\ProgramData\xkes 2014-04-03 14:29 - 2014-04-03 14:29 - 00000000 ____D () C:\ProgramData\vnpd 2014-04-03 14:29 - 2014-04-03 14:29 - 00000000 ____D () C:\ProgramData\tbys 2014-04-03 14:29 - 2014-04-03 14:29 - 00000000 ____D () C:\ProgramData\oxux 2014-04-03 14:29 - 2014-04-03 14:29 - 00000000 ____D () C:\ProgramData\ewem 2014-04-03 14:29 - 2014-04-03 14:29 - 00000000 ____D () C:\ProgramData\aksc 2014-04-03 14:29 - 2014-04-03 14:28 - 00000000 ____D () C:\ProgramData\udjj 2014-04-03 14:28 - 2014-04-03 14:28 - 00000000 ____D () C:\ProgramData\ydiq 2014-04-03 14:28 - 2014-04-03 14:28 - 00000000 ____D () C:\ProgramData\ydcq 2014-04-03 14:28 - 2014-04-03 14:28 - 00000000 ____D () C:\ProgramData\udur 2014-04-03 14:28 - 2014-04-03 14:28 - 00000000 ____D () C:\ProgramData\ivmn 2014-04-03 14:28 - 2014-04-03 14:28 - 00000000 ____D () C:\ProgramData\idiv 2014-04-03 14:28 - 2014-04-03 14:28 - 00000000 ____D () C:\ProgramData\etoh 2014-04-03 14:28 - 2014-04-03 14:28 - 00000000 ____D () C:\ProgramData\amyc 2014-04-03 14:28 - 2014-04-03 14:27 - 00000000 ____D () C:\ProgramData\uhof 2014-04-03 14:28 - 2014-04-03 14:14 - 00000000 ____D () C:\ProgramData\icif 2014-04-03 14:27 - 2014-04-03 14:27 - 00000000 ____D () C:\ProgramData\yhiw 2014-04-03 14:27 - 2014-04-03 14:27 - 00000000 ____D () C:\ProgramData\ybmw 2014-04-03 14:27 - 2014-04-03 14:27 - 00000000 ____D () C:\ProgramData\usot 2014-04-03 14:27 - 2014-04-03 14:27 - 00000000 ____D () C:\ProgramData\mwaw 2014-04-03 14:27 - 2014-04-03 14:27 - 00000000 ____D () C:\ProgramData\epop 2014-04-03 14:27 - 2014-04-03 14:27 - 00000000 ____D () C:\ProgramData\aryq 2014-04-03 14:27 - 2014-04-03 14:27 - 00000000 ____D () C:\ProgramData\adyv 2014-04-03 14:27 - 2014-04-03 14:26 - 00000000 ____D () C:\ProgramData\ebuk 2014-04-03 14:27 - 2014-04-03 14:23 - 00000000 ____D () C:\ProgramData\otez 2014-04-03 14:26 - 2014-04-03 14:26 - 00000000 ____D () C:\ProgramData\yvax 2014-04-03 14:26 - 2014-04-03 14:26 - 00000000 ____D () C:\ProgramData\uxdx 2014-04-03 14:26 - 2014-04-03 14:26 - 00000000 ____D () C:\ProgramData\umes 2014-04-03 14:26 - 2014-04-03 14:26 - 00000000 ____D () C:\ProgramData\ohgt 2014-04-03 14:26 - 2014-04-03 14:26 - 00000000 ____D () C:\ProgramData\jhok 2014-04-03 14:26 - 2014-04-03 14:26 - 00000000 ____D () C:\ProgramData\ivsj 2014-04-03 14:26 - 2014-04-03 14:26 - 00000000 ____D () C:\ProgramData\ikmt 2014-04-03 14:26 - 2014-04-03 14:26 - 00000000 ____D () C:\ProgramData\idyp 2014-04-03 14:26 - 2014-04-03 14:26 - 00000000 ____D () C:\ProgramData\dwem 2014-04-03 14:26 - 2014-04-03 14:26 - 00000000 ____D () C:\ProgramData\ajsv 2014-04-03 14:26 - 2014-04-03 14:25 - 00000000 ____D () C:\ProgramData\ebuc 2014-04-03 14:25 - 2014-04-03 14:25 - 00000000 ____D () C:\ProgramData\uqeg 2014-04-03 14:25 - 2014-04-03 14:25 - 00000000 ____D () C:\ProgramData\unex 2014-04-03 14:25 - 2014-04-03 14:25 - 00000000 ____D () C:\ProgramData\udud 2014-04-03 14:25 - 2014-04-03 14:25 - 00000000 ____D () C:\ProgramData\oqqv 2014-04-03 14:25 - 2014-04-03 14:25 - 00000000 ____D () C:\ProgramData\izyz 2014-04-03 14:25 - 2014-04-03 14:25 - 00000000 ____D () C:\ProgramData\iriq 2014-04-03 14:25 - 2014-04-03 14:25 - 00000000 ____D () C:\ProgramData\imit 2014-04-03 14:25 - 2014-04-03 14:25 - 00000000 ____D () C:\ProgramData\hcyc 2014-04-03 14:25 - 2014-04-03 14:25 - 00000000 ____D () C:\ProgramData\edon 2014-04-03 14:25 - 2014-04-03 14:25 - 00000000 ____D () C:\ProgramData\afif 2014-04-03 14:25 - 2014-04-03 14:24 - 00000000 ____D () C:\ProgramData\eset 2014-04-03 14:24 - 2014-04-03 14:24 - 00000000 ____D () C:\ProgramData\yziw 2014-04-03 14:24 - 2014-04-03 14:24 - 00000000 ____D () C:\ProgramData\uxox 2014-04-03 14:24 - 2014-04-03 14:24 - 00000000 ____D () C:\ProgramData\tlan 2014-04-03 14:24 - 2014-04-03 14:24 - 00000000 ____D () C:\ProgramData\ored 2014-04-03 14:24 - 2014-04-03 14:24 - 00000000 ____D () C:\ProgramData\opug 2014-04-03 14:24 - 2014-04-03 14:24 - 00000000 ____D () C:\ProgramData\ityf 2014-04-03 14:24 - 2014-04-03 14:24 - 00000000 ____D () C:\ProgramData\epul 2014-04-03 14:24 - 2014-04-03 14:24 - 00000000 ____D () C:\ProgramData\eguq 2014-04-03 14:24 - 2014-04-03 14:23 - 00000000 ____D () C:\ProgramData\oleg 2014-04-03 14:23 - 2014-04-03 14:23 - 00000000 ____D () C:\ProgramData\wjav 2014-04-03 14:23 - 2014-04-03 14:23 - 00000000 ____D () C:\ProgramData\uhdm 2014-04-03 14:23 - 2014-04-03 14:23 - 00000000 ____D () C:\ProgramData\ovog 2014-04-03 14:23 - 2014-04-03 14:23 - 00000000 ____D () C:\ProgramData\ohrk 2014-04-03 14:23 - 2014-04-03 14:23 - 00000000 ____D () C:\ProgramData\ibts 2014-04-03 14:23 - 2014-04-03 14:23 - 00000000 ____D () C:\ProgramData\anyp 2014-04-03 14:23 - 2014-04-03 14:23 - 00000000 ____D () C:\ProgramData\ajiv 2014-04-03 14:23 - 2014-04-03 14:22 - 00000000 ____D () C:\ProgramData\jfew 2014-04-03 14:22 - 2014-04-03 14:22 - 00000000 ____D () C:\ProgramData\wnyl 2014-04-03 14:22 - 2014-04-03 14:22 - 00000000 ____D () C:\ProgramData\unur 2014-04-03 14:22 - 2014-04-03 14:22 - 00000000 ____D () C:\ProgramData\pdex 2014-04-03 14:22 - 2014-04-03 14:22 - 00000000 ____D () C:\ProgramData\kzab 2014-04-03 14:22 - 2014-04-03 14:22 - 00000000 ____D () C:\ProgramData\inip 2014-04-03 14:22 - 2014-04-03 14:22 - 00000000 ____D () C:\ProgramData\eqeq 2014-04-03 14:22 - 2014-04-03 14:22 - 00000000 ____D () C:\ProgramData\epug 2014-04-03 14:22 - 2014-04-03 14:22 - 00000000 ____D () C:\ProgramData\atff 2014-04-03 14:22 - 2014-04-03 14:22 - 00000000 ____D () C:\ProgramData\asis 2014-04-03 14:22 - 2014-04-03 14:22 - 00000000 ____D () C:\ProgramData\ashh 2014-04-03 14:22 - 2014-04-03 14:22 - 00000000 ____D () C:\ProgramData\adal 2014-04-03 14:22 - 2014-04-03 14:21 - 00000000 ____D () C:\ProgramData\erdd 2014-04-03 14:21 - 2014-04-03 14:21 - 00000000 ____D () C:\ProgramData\uvop 2014-04-03 14:21 - 2014-04-03 14:21 - 00000000 ____D () C:\ProgramData\unor 2014-04-03 14:21 - 2014-04-03 14:21 - 00000000 ____D () C:\ProgramData\pren 2014-04-03 14:21 - 2014-04-03 14:21 - 00000000 ____D () C:\ProgramData\orgj 2014-04-03 14:21 - 2014-04-03 14:21 - 00000000 ____D () C:\ProgramData\ahas 2014-04-03 14:21 - 2014-04-03 14:20 - 00000000 ____D () C:\ProgramData\ebef 2014-04-03 14:20 - 2014-04-03 14:20 - 00000000 ____D () C:\ProgramData\ytaf 2014-04-03 14:20 - 2014-04-03 14:20 - 00000000 ____D () C:\ProgramData\unoj 2014-04-03 14:20 - 2014-04-03 14:20 - 00000000 ____D () C:\ProgramData\tpaj 2014-04-03 14:20 - 2014-04-03 14:20 - 00000000 ____D () C:\ProgramData\slir 2014-04-03 14:20 - 2014-04-03 14:20 - 00000000 ____D () C:\ProgramData\jqug 2014-04-03 14:20 - 2014-04-03 14:20 - 00000000 ____D () C:\ProgramData\ikif 2014-04-03 14:20 - 2014-04-03 14:20 - 00000000 ____D () C:\ProgramData\fhaw 2014-04-03 14:20 - 2014-04-03 14:20 - 00000000 ____D () C:\ProgramData\ahis 2014-04-03 14:20 - 2014-04-03 14:19 - 00000000 ____D () C:\ProgramData\otob 2014-04-03 14:19 - 2014-04-03 14:19 - 00000000 ____D () C:\ProgramData\sryp 2014-04-03 14:19 - 2014-04-03 14:19 - 00000000 ____D () C:\ProgramData\sdyg 2014-04-03 14:19 - 2014-04-03 14:19 - 00000000 ____D () C:\ProgramData\qzum 2014-04-03 14:19 - 2014-04-03 14:19 - 00000000 ____D () C:\ProgramData\iwib 2014-04-03 14:19 - 2014-04-03 14:19 - 00000000 ____D () C:\ProgramData\ivwr 2014-04-03 14:19 - 2014-04-03 14:19 - 00000000 ____D () C:\ProgramData\ilyx 2014-04-03 14:19 - 2014-04-03 14:19 - 00000000 ____D () C:\ProgramData\ilix 2014-04-03 14:19 - 2014-04-03 14:19 - 00000000 ____D () C:\ProgramData\dxrd 2014-04-03 14:19 - 2014-04-03 14:19 - 00000000 ____D () C:\ProgramData\dmes 2014-04-03 14:19 - 2014-04-03 14:18 - 00000000 ____D () C:\ProgramData\ppug 2014-04-03 14:19 - 2014-04-03 14:13 - 00000000 ____D () C:\ProgramData\ygar 2014-04-03 14:18 - 2014-04-03 14:18 - 00000000 ____D () C:\ProgramData\usok 2014-04-03 14:18 - 2014-04-03 14:18 - 00000000 ____D () C:\ProgramData\upev 2014-04-03 14:18 - 2014-04-03 14:18 - 00000000 ____D () C:\ProgramData\ogol 2014-04-03 14:18 - 2014-04-03 14:18 - 00000000 ____D () C:\ProgramData\ofrz 2014-04-03 14:18 - 2014-04-03 14:17 - 00000000 ____D () C:\ProgramData\bjiv 2014-04-03 14:18 - 2014-04-03 14:15 - 00000000 ____D () C:\ProgramData\yqaj 2014-04-03 14:18 - 2014-04-03 14:11 - 00000000 ____D () C:\ProgramData\ykat 2014-04-03 14:17 - 2014-04-03 14:17 - 00000000 ____D () C:\ProgramData\upeq 2014-04-03 14:17 - 2014-04-03 14:17 - 00000000 ____D () C:\ProgramData\tmac 2014-04-03 14:17 - 2014-04-03 14:17 - 00000000 ____D () C:\ProgramData\pzdc 2014-04-03 14:17 - 2014-04-03 14:17 - 00000000 ____D () C:\ProgramData\ozef 2014-04-03 14:17 - 2014-04-03 14:17 - 00000000 ____D () C:\ProgramData\ojed 2014-04-03 14:17 - 2014-04-03 14:17 - 00000000 ____D () C:\ProgramData\ksab 2014-04-03 14:17 - 2014-04-03 14:17 - 00000000 ____D () C:\ProgramData\epov 2014-04-03 14:17 - 2014-04-03 14:17 - 00000000 ____D () C:\ProgramData\eceh 2014-04-03 14:17 - 2014-04-03 14:17 - 00000000 ____D () C:\ProgramData\amyk 2014-04-03 14:17 - 2014-04-03 14:16 - 00000000 ____D () C:\ProgramData\okes 2014-04-03 14:16 - 2014-04-03 14:16 - 00000000 ____D () C:\ProgramData\ujux 2014-04-03 14:16 - 2014-04-03 14:16 - 00000000 ____D () C:\ProgramData\ojox 2014-04-03 14:16 - 2014-04-03 14:16 - 00000000 ____D () C:\ProgramData\ilyr 2014-04-03 14:16 - 2014-04-03 14:16 - 00000000 ____D () C:\ProgramData\efus 2014-04-03 14:16 - 2014-04-03 14:16 - 00000000 ____D () C:\ProgramData\alix 2014-04-03 14:16 - 2014-04-03 14:15 - 00000000 ____D () C:\ProgramData\iriv 2014-04-03 14:16 - 2014-04-03 14:11 - 00000000 ____D () C:\ProgramData\ezuf 2014-04-03 14:16 - 2014-04-03 14:10 - 00000000 ____D () C:\ProgramData\epeg 2014-04-03 14:15 - 2014-04-03 14:15 - 00000000 ____D () C:\ProgramData\ynag 2014-04-03 14:15 - 2014-04-03 14:15 - 00000000 ____D () C:\ProgramData\ybis 2014-04-03 14:15 - 2014-04-03 14:15 - 00000000 ____D () C:\ProgramData\vgoq 2014-04-03 14:15 - 2014-04-03 14:15 - 00000000 ____D () C:\ProgramData\ukez 2014-04-03 14:15 - 2014-04-03 14:15 - 00000000 ____D () C:\ProgramData\udrr 2014-04-03 14:15 - 2014-04-03 14:15 - 00000000 ____D () C:\ProgramData\ucph 2014-04-03 14:15 - 2014-04-03 14:15 - 00000000 ____D () C:\ProgramData\ezrc 2014-04-03 14:15 - 2014-04-03 14:15 - 00000000 ____D () C:\ProgramData\ewed 2014-04-03 14:15 - 2014-04-03 14:15 - 00000000 ____D () C:\ProgramData\ebok 2014-04-03 14:15 - 2014-04-03 14:14 - 00000000 ____D () C:\ProgramData\eguv 2014-04-03 14:14 - 2014-04-03 14:14 - 00000000 ____D () C:\ProgramData\yzis 2014-04-03 14:14 - 2014-04-03 14:14 - 00000000 ____D () C:\ProgramData\ysyb 2014-04-03 14:14 - 2014-04-03 14:14 - 00000000 ____D () C:\ProgramData\ujrj 2014-04-03 14:14 - 2014-04-03 14:14 - 00000000 ____D () C:\ProgramData\qfus 2014-04-03 14:14 - 2014-04-03 14:14 - 00000000 ____D () C:\ProgramData\pkrh 2014-04-03 14:14 - 2014-04-03 14:14 - 00000000 ____D () C:\ProgramData\orud 2014-04-03 14:14 - 2014-04-03 14:14 - 00000000 ____D () C:\ProgramData\exud 2014-04-03 14:14 - 2014-04-03 14:14 - 00000000 ____D () C:\ProgramData\awiz 2014-04-03 14:13 - 2014-04-03 14:13 - 00000000 ____D () C:\ProgramData\ypmj 2014-04-03 14:13 - 2014-04-03 14:13 - 00000000 ____D () C:\ProgramData\wsaz 2014-04-03 14:13 - 2014-04-03 14:13 - 00000000 ____D () C:\ProgramData\ofew 2014-04-03 14:13 - 2014-04-03 14:13 - 00000000 ____D () C:\ProgramData\ewek 2014-04-03 14:13 - 2014-04-03 14:13 - 00000000 ____D () C:\ProgramData\evog 2014-04-03 14:13 - 2014-04-03 14:13 - 00000000 ____D () C:\ProgramData\eprv 2014-04-03 14:13 - 2014-04-03 14:13 - 00000000 ____D () C:\ProgramData\anyv 2014-04-03 14:13 - 2014-04-03 14:12 - 00000000 ____D () C:\ProgramData\iwab 2014-04-03 14:12 - 2014-04-03 14:12 - 00000000 ____D () C:\ProgramData\ywib 2014-04-03 14:12 - 2014-04-03 14:12 - 00000000 ____D () C:\ProgramData\ugel 2014-04-03 14:12 - 2014-04-03 14:12 - 00000000 ____D () C:\ProgramData\shaw 2014-04-03 14:12 - 2014-04-03 14:12 - 00000000 ____D () C:\ProgramData\rjej 2014-04-03 14:12 - 2014-04-03 14:12 - 00000000 ____D () C:\ProgramData\ityt 2014-04-03 14:12 - 2014-04-03 14:12 - 00000000 ____D () C:\ProgramData\epev 2014-04-03 14:12 - 2014-04-03 14:12 - 00000000 ____D () C:\ProgramData\axyg 2014-04-03 14:12 - 2014-04-03 14:12 - 00000000 ____D () C:\ProgramData\aqix 2014-04-03 14:12 - 2014-04-03 14:11 - 00000000 ____D () C:\ProgramData\iwis 2014-04-03 14:11 - 2014-04-03 14:11 - 00000000 ____D () C:\ProgramData\uzok 2014-04-03 14:11 - 2014-04-03 14:11 - 00000000 ____D () C:\ProgramData\ugeg 2014-04-03 14:11 - 2014-04-03 14:11 - 00000000 ____D () C:\ProgramData\inhv 2014-04-03 14:11 - 2014-04-03 14:11 - 00000000 ____D () C:\ProgramData\ewef 2014-04-03 14:11 - 2014-04-03 14:11 - 00000000 ____D () C:\ProgramData\dded 2014-04-03 14:11 - 2014-04-03 14:11 - 00000000 ____D () C:\ProgramData\awzs 2014-04-03 14:11 - 2014-04-03 14:11 - 00000000 ____D () C:\ProgramData\aryv 2014-04-03 14:11 - 2014-04-03 14:11 - 00000000 ____D () C:\ProgramData\aqad 2014-04-03 14:10 - 2014-04-03 14:10 - 00000000 ____D () C:\ProgramData\skwf 2014-04-03 14:10 - 2014-04-03 14:10 - 00000000 ____D () C:\ProgramData\oqop 2014-04-03 14:10 - 2014-04-03 14:10 - 00000000 ____D () C:\ProgramData\ojpx 2014-04-03 14:10 - 2014-04-03 14:10 - 00000000 ____D () C:\ProgramData\idhg 2014-04-03 14:10 - 2014-04-03 14:10 - 00000000 ____D () C:\ProgramData\fmkt 2014-04-03 14:10 - 2014-04-03 14:10 - 00000000 ____D () C:\ProgramData\ezec 2014-04-03 14:10 - 2014-04-03 14:10 - 00000000 ____D () C:\ProgramData\elog 2014-04-03 14:10 - 2014-04-03 14:09 - 00000000 ____D () C:\ProgramData\uvol 2014-04-03 14:09 - 2014-04-03 14:09 - 00000000 ____D () C:\ProgramData\otoz 2014-04-03 14:09 - 2014-04-03 14:09 - 00000000 ____D () C:\ProgramData\oklh 2014-04-03 14:09 - 2014-04-03 14:09 - 00000000 ____D () C:\ProgramData\ofes 2014-04-03 14:09 - 2014-04-03 14:09 - 00000000 ____D () C:\ProgramData\ocos 2014-04-03 14:09 - 2014-04-03 14:09 - 00000000 ____D () C:\ProgramData\icyt 2014-04-03 14:09 - 2014-04-03 14:09 - 00000000 ____D () C:\ProgramData\ewum 2014-04-03 14:09 - 2014-04-03 14:09 - 00000000 ____D () C:\ProgramData\eveg 2014-04-03 14:09 - 2014-04-03 14:09 - 00000000 ____D () C:\ProgramData\eloq 2014-04-03 14:09 - 2014-04-03 14:09 - 00000000 ____D () C:\ProgramData\aqax 2014-04-03 14:09 - 2014-04-03 14:08 - 00000000 ____D () C:\ProgramData\ylix 2014-04-03 14:08 - 2014-04-03 14:08 - 00000000 ____D () C:\ProgramData\ubom 2014-04-03 14:08 - 2014-04-03 14:08 - 00000000 ____D () C:\ProgramData\ipir 2014-04-03 14:08 - 2014-04-03 14:08 - 00000000 ____D () C:\ProgramData\efjh ***************** C:\ProgramData\icuf => Moved successfully. C:\ProgramData\usjk => Moved successfully. C:\ProgramData\kghd => Moved successfully. C:\ProgramData\okew => Moved successfully. C:\ProgramData\ozet => Moved successfully. C:\ProgramData\yjil => Moved successfully. C:\ProgramData\ynyp => Moved successfully. C:\ProgramData\oqup => Moved successfully. C:\ProgramData\objm => Moved successfully. C:\ProgramData\jjun => Moved successfully. C:\ProgramData\imif => Moved successfully. C:\ProgramData\exqr => Moved successfully. C:\ProgramData\equg => Moved successfully. C:\ProgramData\axaq => Moved successfully. C:\ProgramData\alan => Moved successfully. C:\ProgramData\uznm => Moved successfully. C:\ProgramData\ujen => Moved successfully. C:\ProgramData\ufow => Moved successfully. C:\ProgramData\ysab => Moved successfully. C:\ProgramData\yhyw => Moved successfully. C:\ProgramData\yhys => Moved successfully. C:\ProgramData\yhis => Moved successfully. C:\ProgramData\xlug => Moved successfully. C:\ProgramData\uwum => Moved successfully. C:\ProgramData\ipaj => Moved successfully. C:\ProgramData\inyv => Moved successfully. C:\ProgramData\engx => Moved successfully. C:\ProgramData\ejed => Moved successfully. C:\ProgramData\ahiw => Moved successfully. C:\ProgramData\epuq => Moved successfully. C:\ProgramData\xluv => Moved successfully. C:\ProgramData\ufjh => Moved successfully. C:\ProgramData\olep => Moved successfully. C:\ProgramData\knaq => Moved successfully. C:\ProgramData\gmos => Moved successfully. C:\ProgramData\exuj => Moved successfully. C:\ProgramData\btaw => Moved successfully. C:\ProgramData\agyx => Moved successfully. C:\ProgramData\ebum => Moved successfully. C:\ProgramData\oqep => Moved successfully. C:\ProgramData\ozoc => Moved successfully. C:\ProgramData\yjyl => Moved successfully. C:\ProgramData\uron => Moved successfully. C:\ProgramData\owut => Moved successfully. C:\ProgramData\odpn => Moved successfully. C:\ProgramData\ixaq => Moved successfully. C:\ProgramData\iril => Moved successfully. C:\ProgramData\ipix => Moved successfully. C:\ProgramData\ific => Moved successfully. C:\ProgramData\ekez => Moved successfully. C:\ProgramData\owef => Moved successfully. C:\ProgramData\ozum => Moved successfully. C:\ProgramData\ejen => Moved successfully. C:\ProgramData\yvid => Moved successfully. C:\ProgramData\yfim => Moved successfully. C:\ProgramData\uhut => Moved successfully. C:\ProgramData\rdox => Moved successfully. C:\ProgramData\oveg => Moved successfully. C:\ProgramData\jxur => Moved successfully. C:\ProgramData\jjoj => Moved successfully. C:\ProgramData\ifyt => Moved successfully. C:\ProgramData\etow => Moved successfully. C:\ProgramData\ohuf => Moved successfully. C:\ProgramData\ehem => Moved successfully. C:\ProgramData\udon => Moved successfully. C:\ProgramData\yktk => Moved successfully. C:\ProgramData\ygix => Moved successfully. C:\ProgramData\ycik => Moved successfully. C:\ProgramData\upug => Moved successfully. C:\ProgramData\onex => Moved successfully. C:\ProgramData\oceb => Moved successfully. C:\ProgramData\aziw => Moved successfully. C:\ProgramData\asyw => Moved successfully. C:\ProgramData\etus => Moved successfully. C:\ProgramData\ycym => Moved successfully. C:\ProgramData\ywas => Moved successfully. C:\ProgramData\uvov => Moved successfully. C:\ProgramData\usuk => Moved successfully. C:\ProgramData\uqep => Moved successfully. C:\ProgramData\obot => Moved successfully. C:\ProgramData\lmob => Moved successfully. C:\ProgramData\ikam => Moved successfully. C:\ProgramData\awtw => Moved successfully. C:\ProgramData\araq => Moved successfully. C:\ProgramData\anap => Moved successfully. C:\ProgramData\efos => Moved successfully. C:\ProgramData\omow => Moved successfully. C:\ProgramData\vlep => Moved successfully. C:\ProgramData\uned => Moved successfully. C:\ProgramData\ipyj => Moved successfully. C:\ProgramData\akyt => Moved successfully. C:\ProgramData\axag => Moved successfully. C:\ProgramData\ykam => Moved successfully. C:\ProgramData\izyw => Moved successfully. C:\ProgramData\emeb => Moved successfully. C:\ProgramData\ipid => Moved successfully. C:\ProgramData\axil => Moved successfully. C:\ProgramData\ylan => Moved successfully. C:\ProgramData\uwut => Moved successfully. C:\ProgramData\utgh => Moved successfully. C:\ProgramData\ufub => Moved successfully. C:\ProgramData\ixav => Moved successfully. C:\ProgramData\idav => Moved successfully. C:\ProgramData\idal => Moved successfully. C:\ProgramData\ekeh => Moved successfully. C:\ProgramData\ebek => Moved successfully. C:\ProgramData\avir => Moved successfully. C:\ProgramData\ylyn => Moved successfully. C:\ProgramData\ecuw => Moved successfully. C:\ProgramData\ylij => Moved successfully. C:\ProgramData\ugqg => Moved successfully. C:\ProgramData\okoz => Moved successfully. C:\ProgramData\ofuh => Moved successfully. C:\ProgramData\ifzc => Moved successfully. C:\ProgramData\egep => Moved successfully. C:\ProgramData\ymaf => Moved successfully. C:\ProgramData\ywaw => Moved successfully. C:\ProgramData\adig => Moved successfully. C:\ProgramData\ifym => Moved successfully. C:\ProgramData\ymam => Moved successfully. C:\ProgramData\unun => Moved successfully. C:\ProgramData\otnh => Moved successfully. C:\ProgramData\ofoz => Moved successfully. C:\ProgramData\azys => Moved successfully. C:\ProgramData\azah => Moved successfully. C:\ProgramData\awib => Moved successfully. C:\ProgramData\asih => Moved successfully. C:\ProgramData\lsom => Moved successfully. C:\ProgramData\ipij => Moved successfully. C:\ProgramData\yxip => Moved successfully. C:\ProgramData\upel => Moved successfully. C:\ProgramData\upol => Moved successfully. C:\ProgramData\ugov => Moved successfully. C:\ProgramData\oxun => Moved successfully. C:\ProgramData\oxor => Moved successfully. C:\ProgramData\jnjn => Moved successfully. C:\ProgramData\hxil => Moved successfully. C:\ProgramData\enor => Moved successfully. C:\ProgramData\bsbs => Moved successfully. C:\ProgramData\orej => Moved successfully. C:\ProgramData\ohef => Moved successfully. C:\ProgramData\avaj => Moved successfully. C:\ProgramData\ypin => Moved successfully. C:\ProgramData\otlb => Moved successfully. C:\ProgramData\oboc => Moved successfully. C:\ProgramData\jfgs => Moved successfully. C:\ProgramData\idyq => Moved successfully. C:\ProgramData\ezjf => Moved successfully. C:\ProgramData\dwqc => Moved successfully. C:\ProgramData\awih => Moved successfully. C:\ProgramData\fral => Moved successfully. C:\ProgramData\ityk => Moved successfully. C:\ProgramData\ivix => Moved successfully. C:\ProgramData\ydav => Moved successfully. C:\ProgramData\uvoq => Moved successfully. C:\ProgramData\qnex => Moved successfully. C:\ProgramData\pron => Moved successfully. C:\ProgramData\inig => Moved successfully. C:\ProgramData\erxr => Moved successfully. C:\ProgramData\ekew => Moved successfully. C:\ProgramData\edur => Moved successfully. C:\ProgramData\akzk => Moved successfully. C:\ProgramData\odod => Moved successfully. C:\ProgramData\ykyf => Moved successfully. C:\ProgramData\yfyt => Moved successfully. C:\ProgramData\ulqp => Moved successfully. C:\ProgramData\ulov => Moved successfully. C:\ProgramData\knal => Moved successfully. C:\ProgramData\isiw => Moved successfully. C:\ProgramData\ewec => Moved successfully. C:\ProgramData\apir => Moved successfully. C:\ProgramData\agax => Moved successfully. C:\ProgramData\yvan => Moved successfully. C:\ProgramData\upop => Moved successfully. C:\ProgramData\yfic => Moved successfully. C:\ProgramData\ehot => Moved successfully. C:\ProgramData\ywyz => Moved successfully. C:\ProgramData\ugug => Moved successfully. C:\ProgramData\opeg => Moved successfully. C:\ProgramData\ipyd => Moved successfully. C:\ProgramData\erjx => Moved successfully. C:\ProgramData\dbot => Moved successfully. C:\ProgramData\akak => Moved successfully. C:\ProgramData\ujoj => Moved successfully. C:\ProgramData\olev => Moved successfully. C:\ProgramData\eduj => Moved successfully. C:\ProgramData\inal => Moved successfully. C:\ProgramData\yfat => Moved successfully. C:\ProgramData\ufeh => Moved successfully. C:\ProgramData\ofeb => Moved successfully. C:\ProgramData\lsek => Moved successfully. C:\ProgramData\iqyr => Moved successfully. C:\ProgramData\ilbn => Moved successfully. C:\ProgramData\icyk => Moved successfully. C:\ProgramData\adtv => Moved successfully. C:\ProgramData\adfg => Moved successfully. C:\ProgramData\ylin => Moved successfully. C:\ProgramData\yzsz => Moved successfully. C:\ProgramData\ywiw => Moved successfully. C:\ProgramData\yril => Moved successfully. C:\ProgramData\ypkx => Moved successfully. C:\ProgramData\ygan => Moved successfully. C:\ProgramData\udnd => Moved successfully. C:\ProgramData\amim => Moved successfully. C:\ProgramData\ulug => Moved successfully. C:\ProgramData\yjiv => Moved successfully. C:\ProgramData\ylad => Moved successfully. C:\ProgramData\udun => Moved successfully. C:\ProgramData\ywiz => Moved successfully. C:\ProgramData\odor => Moved successfully. C:\ProgramData\iryv => Moved successfully. C:\ProgramData\edgd => Moved successfully. C:\ProgramData\akkf => Moved successfully. C:\ProgramData\abaw => Moved successfully. C:\ProgramData\ygyj => Moved successfully. C:\ProgramData\awaz => Moved successfully. C:\ProgramData\ydig => Moved successfully. C:\ProgramData\ikic => Moved successfully. C:\ProgramData\uzuc => Moved successfully. C:\ProgramData\uror => Moved successfully. C:\ProgramData\umps => Moved successfully. C:\ProgramData\qwet => Moved successfully. C:\ProgramData\jjon => Moved successfully. C:\ProgramData\ilad => Moved successfully. C:\ProgramData\ijiv => Moved successfully. C:\ProgramData\anmv => Moved successfully. C:\ProgramData\aryp => Moved successfully. C:\ProgramData\afik => Moved successfully. C:\ProgramData\ecuh => Moved successfully. C:\ProgramData\uxoj => Moved successfully. C:\ProgramData\omuw => Moved successfully. C:\ProgramData\obum => Moved successfully. C:\ProgramData\jlol => Moved successfully. C:\ProgramData\jkez => Moved successfully. C:\ProgramData\exux => Moved successfully. C:\ProgramData\djud => Moved successfully. C:\ProgramData\ajig => Moved successfully. C:\ProgramData\ywah => Moved successfully. C:\ProgramData\asib => Moved successfully. C:\ProgramData\ijyl => Moved successfully. C:\ProgramData\ylaj => Moved successfully. C:\ProgramData\ykaf => Moved successfully. C:\ProgramData\uhum => Moved successfully. C:\ProgramData\osoc => Moved successfully. C:\ProgramData\egug => Moved successfully. C:\ProgramData\aryg => Moved successfully. C:\ProgramData\lzec => Moved successfully. C:\ProgramData\ufob => Moved successfully. C:\ProgramData\egop => Moved successfully. C:\ProgramData\opjl => Moved successfully. C:\ProgramData\ndur => Moved successfully. C:\ProgramData\kzas => Moved successfully. C:\ProgramData\iraq => Moved successfully. C:\ProgramData\erur => Moved successfully. C:\ProgramData\azyh => Moved successfully. C:\ProgramData\asaw => Moved successfully. C:\ProgramData\asas => Moved successfully. C:\ProgramData\acac => Moved successfully. C:\ProgramData\ydip => Moved successfully. C:\ProgramData\ywss => Moved successfully. C:\ProgramData\oqpp => Moved successfully. C:\ProgramData\okgw => Moved successfully. C:\ProgramData\ogug => Moved successfully. C:\ProgramData\ofow => Moved successfully. C:\ProgramData\jteb => Moved successfully. C:\ProgramData\izah => Moved successfully. C:\ProgramData\igar => Moved successfully. C:\ProgramData\ejqd => Moved successfully. C:\ProgramData\egll => Moved successfully. C:\ProgramData\zhis => Moved successfully. C:\ProgramData\erox => Moved successfully. C:\ProgramData\uvuv => Moved successfully. C:\ProgramData\ifyc => Moved successfully. C:\ProgramData\evop => Moved successfully. C:\ProgramData\esef => Moved successfully. C:\ProgramData\ejon => Moved successfully. C:\ProgramData\ahys => Moved successfully. C:\ProgramData\acyt => Moved successfully. C:\ProgramData\icic => Moved successfully. C:\ProgramData\egup => Moved successfully. C:\ProgramData\ytat => Moved successfully. C:\ProgramData\ygij => Moved successfully. C:\ProgramData\uvel => Moved successfully. C:\ProgramData\uveg => Moved successfully. C:\ProgramData\uhok => Moved successfully. C:\ProgramData\udxr => Moved successfully. C:\ProgramData\oded => Moved successfully. C:\ProgramData\bcik => Moved successfully. C:\ProgramData\awyw => Moved successfully. C:\ProgramData\uxed => Moved successfully. C:\ProgramData\ydal => Moved successfully. C:\ProgramData\ytyf => Moved successfully. C:\ProgramData\ycac => Moved successfully. C:\ProgramData\qzef => Moved successfully. C:\ProgramData\ohjf => Moved successfully. C:\ProgramData\ivbx => Moved successfully. C:\ProgramData\dlog => Moved successfully. C:\ProgramData\avmn => Moved successfully. C:\ProgramData\ojdn => Moved successfully. C:\ProgramData\yrav => Moved successfully. C:\ProgramData\yfkk => Moved successfully. C:\ProgramData\pzoc => Moved successfully. C:\ProgramData\otos => Moved successfully. C:\ProgramData\hmim => Moved successfully. C:\ProgramData\epog => Moved successfully. C:\ProgramData\ebec => Moved successfully. C:\ProgramData\avyj => Moved successfully. C:\ProgramData\igij => Moved successfully. C:\ProgramData\ejoj => Moved successfully. C:\ProgramData\ohot => Moved successfully. C:\ProgramData\ijag => Moved successfully. C:\ProgramData\ugog => Moved successfully. C:\ProgramData\ivij => Moved successfully. C:\ProgramData\evel => Moved successfully. C:\ProgramData\emez => Moved successfully. C:\ProgramData\ebrt => Moved successfully. C:\ProgramData\esec => Moved successfully. C:\ProgramData\amic => Moved successfully. C:\ProgramData\ylir => Moved successfully. C:\ProgramData\uruj => Moved successfully. C:\ProgramData\unpd => Moved successfully. C:\ProgramData\odox => Moved successfully. C:\ProgramData\obuf => Moved successfully. C:\ProgramData\izmw => Moved successfully. C:\ProgramData\enqn => Moved successfully. C:\ProgramData\azih => Moved successfully. C:\ProgramData\atif => Moved successfully. C:\ProgramData\agar => Moved successfully. C:\ProgramData\epoq => Moved successfully. C:\ProgramData\upeg => Moved successfully. C:\ProgramData\ygax => Moved successfully. C:\ProgramData\itif => Moved successfully. C:\ProgramData\isib => Moved successfully. C:\ProgramData\imat => Moved successfully. C:\ProgramData\exen => Moved successfully. C:\ProgramData\emoh => Moved successfully. C:\ProgramData\aril => Moved successfully. C:\ProgramData\afak => Moved successfully. C:\ProgramData\uxod => Moved successfully. C:\ProgramData\ujor => Moved successfully. C:\ProgramData\yqir => Moved successfully. C:\ProgramData\vsut => Moved successfully. C:\ProgramData\ogov => Moved successfully. C:\ProgramData\icak => Moved successfully. C:\ProgramData\ezdc => Moved successfully. C:\ProgramData\agyj => Moved successfully. C:\ProgramData\afyt => Moved successfully. C:\ProgramData\ofob => Moved successfully. C:\ProgramData\ydyq => Moved successfully. C:\ProgramData\owok => Moved successfully. C:\ProgramData\ymak => Moved successfully. C:\ProgramData\usek => Moved successfully. C:\ProgramData\uluv => Moved successfully. C:\ProgramData\smac => Moved successfully. C:\ProgramData\ozjt => Moved successfully. C:\ProgramData\ilax => Moved successfully. C:\ProgramData\igax => Moved successfully. C:\ProgramData\hhyh => Moved successfully. C:\ProgramData\ahih => Moved successfully. C:\ProgramData\utoz => Moved successfully. C:\ProgramData\wmit => Moved successfully. C:\ProgramData\utew => Moved successfully. C:\ProgramData\orun => Moved successfully. C:\ProgramData\oquv => Moved successfully. C:\ProgramData\jfus => Moved successfully. C:\ProgramData\ixiq => Moved successfully. C:\ProgramData\efqh => Moved successfully. C:\ProgramData\axal => Moved successfully. C:\ProgramData\asys => Moved successfully. C:\ProgramData\bxal => Moved successfully. C:\ProgramData\yzih => Moved successfully. C:\ProgramData\xklh => Moved successfully. C:\ProgramData\usef => Moved successfully. C:\ProgramData\ozuk => Moved successfully. C:\ProgramData\ijig => Moved successfully. C:\ProgramData\idip => Moved successfully. C:\ProgramData\esuk => Moved successfully. C:\ProgramData\ehuf => Moved successfully. C:\ProgramData\agij => Moved successfully. C:\ProgramData\ujod => Moved successfully. C:\ProgramData\ykwf => Moved successfully. C:\ProgramData\otuw => Moved successfully. C:\ProgramData\otew => Moved successfully. C:\ProgramData\opul => Moved successfully. C:\ProgramData\ollg => Moved successfully. C:\ProgramData\isah => Moved successfully. C:\ProgramData\icam => Moved successfully. C:\ProgramData\epep => Moved successfully. C:\ProgramData\otow => Moved successfully. C:\ProgramData\ybyb => Moved successfully. C:\ProgramData\evov => Moved successfully. C:\ProgramData\yzah => Moved successfully. C:\ProgramData\yvyj => Moved successfully. C:\ProgramData\tfit => Moved successfully. C:\ProgramData\shis => Moved successfully. C:\ProgramData\ipin => Moved successfully. C:\ProgramData\ihyw => Moved successfully. C:\ProgramData\exoj => Moved successfully. C:\ProgramData\chys => Moved successfully. C:\ProgramData\yxiq => Moved successfully. C:\ProgramData\ysyw => Moved successfully. C:\ProgramData\oxex => Moved successfully. C:\ProgramData\lzoc => Moved successfully. C:\ProgramData\iqyd => Moved successfully. C:\ProgramData\gcuz => Moved successfully. C:\ProgramData\fwyz => Moved successfully. C:\ProgramData\acif => Moved successfully. C:\ProgramData\ehuc => Moved successfully. C:\ProgramData\ewof => Moved successfully. C:\ProgramData\utub => Moved successfully. C:\ProgramData\upep => Moved successfully. C:\ProgramData\unox => Moved successfully. C:\ProgramData\ubjm => Moved successfully. C:\ProgramData\oxej => Moved successfully. C:\ProgramData\omoz => Moved successfully. C:\ProgramData\ohuc => Moved successfully. C:\ProgramData\mqsd => Moved successfully. C:\ProgramData\isyh => Moved successfully. C:\ProgramData\agyr => Moved successfully. C:\ProgramData\fvir => Moved successfully. C:\ProgramData\yzas => Moved successfully. C:\ProgramData\ynil => Moved successfully. C:\ProgramData\utak => Moved successfully. C:\ProgramData\urej => Moved successfully. C:\ProgramData\tcat => Moved successfully. C:\ProgramData\ifim => Moved successfully. C:\ProgramData\ibaz => Moved successfully. C:\ProgramData\asab => Moved successfully. C:\ProgramData\ajyq => Moved successfully. C:\ProgramData\ozof => Moved successfully. C:\ProgramData\uqlq => Moved successfully. C:\ProgramData\uguq => Moved successfully. C:\ProgramData\olgq => Moved successfully. C:\ProgramData\ihyb => Moved successfully. C:\ProgramData\hsiz => Moved successfully. C:\ProgramData\ewoc => Moved successfully. C:\ProgramData\ajip => Moved successfully. C:\ProgramData\iftc => Moved successfully. C:\ProgramData\atit => Moved successfully. C:\ProgramData\ifyf => Moved successfully. C:\ProgramData\erux => Moved successfully. C:\ProgramData\ydyv => Moved successfully. C:\ProgramData\upuq => Moved successfully. C:\ProgramData\olul => Moved successfully. C:\ProgramData\okeb => Moved successfully. C:\ProgramData\esdt => Moved successfully. C:\ProgramData\aqyj => Moved successfully. C:\ProgramData\yntp => Moved successfully. C:\ProgramData\ihys => Moved successfully. C:\ProgramData\ypij => Moved successfully. C:\ProgramData\ygyx => Moved successfully. C:\ProgramData\owof => Moved successfully. C:\ProgramData\inyl => Moved successfully. C:\ProgramData\ewjm => Moved successfully. C:\ProgramData\etuh => Moved successfully. C:\ProgramData\arkv => Moved successfully. C:\ProgramData\arcg => Moved successfully. C:\ProgramData\ykyc => Moved successfully. C:\ProgramData\yjag => Moved successfully. C:\ProgramData\uqpp => Moved successfully. C:\ProgramData\orex => Moved successfully. C:\ProgramData\kfat => Moved successfully. C:\ProgramData\igmd => Moved successfully. C:\ProgramData\ibah => Moved successfully. C:\ProgramData\epdp => Moved successfully. C:\ProgramData\enun => Moved successfully. C:\ProgramData\ejod => Moved successfully. C:\ProgramData\jder => Moved successfully. C:\ProgramData\yxaq => Moved successfully. C:\ProgramData\yfif => Moved successfully. C:\ProgramData\ovlg => Moved successfully. C:\ProgramData\nmuw => Moved successfully. C:\ProgramData\nboc => Moved successfully. C:\ProgramData\iqar => Moved successfully. C:\ProgramData\afyf => Moved successfully. C:\ProgramData\ydap => Moved successfully. C:\ProgramData\ycyc => Moved successfully. C:\ProgramData\ufuh => Moved successfully. C:\ProgramData\ubum => Moved successfully. C:\ProgramData\scit => Moved successfully. C:\ProgramData\otoh => Moved successfully. C:\ProgramData\ogup => Moved successfully. C:\ProgramData\odur => Moved successfully. C:\ProgramData\icit => Moved successfully. C:\ProgramData\eqoq => Moved successfully. C:\ProgramData\afaf => Moved successfully. C:\ProgramData\ohoc => Moved successfully. C:\ProgramData\ynaq => Moved successfully. C:\ProgramData\ylyr => Moved successfully. C:\ProgramData\vdox => Moved successfully. C:\ProgramData\umos => Moved successfully. C:\ProgramData\uloq => Moved successfully. C:\ProgramData\uhec => Moved successfully. C:\ProgramData\sxiq => Moved successfully. C:\ProgramData\omob => Moved successfully. C:\ProgramData\iryg => Moved successfully. C:\ProgramData\ipyx => Moved successfully. C:\ProgramData\anbl => Moved successfully. C:\ProgramData\ilsx => Moved successfully. C:\ProgramData\yxig => Moved successfully. C:\ProgramData\ykyk => Moved successfully. C:\ProgramData\upjl => Moved successfully. C:\ProgramData\twys => Moved successfully. C:\ProgramData\pgvq => Moved successfully. C:\ProgramData\iwyz => Moved successfully. C:\ProgramData\iwih => Moved successfully. C:\ProgramData\etub => Moved successfully. C:\ProgramData\emuw => Moved successfully. C:\ProgramData\bdyl => Moved successfully. C:\ProgramData\ilyn => Moved successfully. C:\ProgramData\uwok => Moved successfully. C:\ProgramData\upul => Moved successfully. C:\ProgramData\owgk => Moved successfully. C:\ProgramData\otus => Moved successfully. C:\ProgramData\ofeh => Moved successfully. C:\ProgramData\ekus => Moved successfully. C:\ProgramData\ikac => Moved successfully. C:\ProgramData\ykim => Moved successfully. C:\ProgramData\uxur => Moved successfully. C:\ProgramData\urjx => Moved successfully. C:\ProgramData\uqol => Moved successfully. C:\ProgramData\unqn => Moved successfully. C:\ProgramData\uhoc => Moved successfully. C:\ProgramData\kbts => Moved successfully. C:\ProgramData\ifit => Moved successfully. C:\ProgramData\ezoc => Moved successfully. C:\ProgramData\ewut => Moved successfully. C:\ProgramData\yzyh => Moved successfully. C:\ProgramData\ugup => Moved successfully. C:\ProgramData\udex => Moved successfully. C:\ProgramData\opeq => Moved successfully. C:\ProgramData\inyg => Moved successfully. C:\ProgramData\ikak => Moved successfully. C:\ProgramData\ezrf => Moved successfully. C:\ProgramData\ezom => Moved successfully. C:\ProgramData\edud => Moved successfully. C:\ProgramData\asyb => Moved successfully. C:\ProgramData\ahib => Moved successfully. C:\ProgramData\otqz => Moved successfully. C:\ProgramData\zvyj => Moved successfully. C:\ProgramData\ytac => Moved successfully. C:\ProgramData\opuq => Moved successfully. C:\ProgramData\opel => Moved successfully. C:\ProgramData\ixag => Moved successfully. C:\ProgramData\ahiz => Moved successfully. C:\ProgramData\ackt => Moved successfully. C:\ProgramData\afym => Moved successfully. C:\ProgramData\yrap => Moved successfully. C:\ProgramData\uwoc => Moved successfully. C:\ProgramData\iziz => Moved successfully. C:\ProgramData\imik => Moved successfully. C:\ProgramData\igyj => Moved successfully. C:\ProgramData\hxag => Moved successfully. C:\ProgramData\awab => Moved successfully. C:\ProgramData\arip => Moved successfully. C:\ProgramData\adap => Moved successfully. C:\ProgramData\awas => Moved successfully. C:\ProgramData\uduj => Moved successfully. C:\ProgramData\ubok => Moved successfully. C:\ProgramData\orux => Moved successfully. C:\ProgramData\ohof => Moved successfully. C:\ProgramData\ifaf => Moved successfully. C:\ProgramData\idzq => Moved successfully. C:\ProgramData\ecrs => Moved successfully. C:\ProgramData\ajiq => Moved successfully. C:\ProgramData\acik => Moved successfully. C:\ProgramData\abih => Moved successfully. C:\ProgramData\ajag => Moved successfully. C:\ProgramData\wbyh => Moved successfully. C:\ProgramData\ssss => Moved successfully. C:\ProgramData\ojux => Moved successfully. C:\ProgramData\obok => Moved successfully. C:\ProgramData\lxvn => Moved successfully. C:\ProgramData\inyp => Moved successfully. C:\ProgramData\ihih => Moved successfully. C:\ProgramData\afyc => Moved successfully. C:\ProgramData\afac => Moved successfully. C:\ProgramData\ewuk => Moved successfully. C:\ProgramData\izis => Moved successfully. C:\ProgramData\yfyc => Moved successfully. C:\ProgramData\xxon => Moved successfully. C:\ProgramData\xkes => Moved successfully. C:\ProgramData\vnpd => Moved successfully. C:\ProgramData\tbys => Moved successfully. C:\ProgramData\oxux => Moved successfully. C:\ProgramData\ewem => Moved successfully. C:\ProgramData\aksc => Moved successfully. C:\ProgramData\udjj => Moved successfully. C:\ProgramData\ydiq => Moved successfully. C:\ProgramData\ydcq => Moved successfully. C:\ProgramData\udur => Moved successfully. C:\ProgramData\ivmn => Moved successfully. C:\ProgramData\idiv => Moved successfully. C:\ProgramData\etoh => Moved successfully. C:\ProgramData\amyc => Moved successfully. C:\ProgramData\uhof => Moved successfully. C:\ProgramData\icif => Moved successfully. C:\ProgramData\yhiw => Moved successfully. C:\ProgramData\ybmw => Moved successfully. C:\ProgramData\usot => Moved successfully. C:\ProgramData\mwaw => Moved successfully. C:\ProgramData\epop => Moved successfully. C:\ProgramData\aryq => Moved successfully. C:\ProgramData\adyv => Moved successfully. C:\ProgramData\ebuk => Moved successfully. C:\ProgramData\otez => Moved successfully. C:\ProgramData\yvax => Moved successfully. C:\ProgramData\uxdx => Moved successfully. C:\ProgramData\umes => Moved successfully. C:\ProgramData\ohgt => Moved successfully. C:\ProgramData\jhok => Moved successfully. C:\ProgramData\ivsj => Moved successfully. C:\ProgramData\ikmt => Moved successfully. C:\ProgramData\idyp => Moved successfully. C:\ProgramData\dwem => Moved successfully. C:\ProgramData\ajsv => Moved successfully. C:\ProgramData\ebuc => Moved successfully. C:\ProgramData\uqeg => Moved successfully. C:\ProgramData\unex => Moved successfully. C:\ProgramData\udud => Moved successfully. C:\ProgramData\oqqv => Moved successfully. C:\ProgramData\izyz => Moved successfully. C:\ProgramData\iriq => Moved successfully. C:\ProgramData\imit => Moved successfully. C:\ProgramData\hcyc => Moved successfully. C:\ProgramData\edon => Moved successfully. C:\ProgramData\afif => Moved successfully. C:\ProgramData\eset => Moved successfully. C:\ProgramData\yziw => Moved successfully. C:\ProgramData\uxox => Moved successfully. C:\ProgramData\tlan => Moved successfully. C:\ProgramData\ored => Moved successfully. C:\ProgramData\opug => Moved successfully. C:\ProgramData\ityf => Moved successfully. C:\ProgramData\epul => Moved successfully. C:\ProgramData\eguq => Moved successfully. C:\ProgramData\oleg => Moved successfully. C:\ProgramData\wjav => Moved successfully. C:\ProgramData\uhdm => Moved successfully. C:\ProgramData\ovog => Moved successfully. C:\ProgramData\ohrk => Moved successfully. C:\ProgramData\ibts => Moved successfully. C:\ProgramData\anyp => Moved successfully. C:\ProgramData\ajiv => Moved successfully. C:\ProgramData\jfew => Moved successfully. C:\ProgramData\wnyl => Moved successfully. C:\ProgramData\unur => Moved successfully. C:\ProgramData\pdex => Moved successfully. C:\ProgramData\kzab => Moved successfully. C:\ProgramData\inip => Moved successfully. C:\ProgramData\eqeq => Moved successfully. C:\ProgramData\epug => Moved successfully. C:\ProgramData\atff => Moved successfully. C:\ProgramData\asis => Moved successfully. C:\ProgramData\ashh => Moved successfully. C:\ProgramData\adal => Moved successfully. C:\ProgramData\erdd => Moved successfully. C:\ProgramData\uvop => Moved successfully. C:\ProgramData\unor => Moved successfully. C:\ProgramData\pren => Moved successfully. C:\ProgramData\orgj => Moved successfully. C:\ProgramData\ahas => Moved successfully. C:\ProgramData\ebef => Moved successfully. C:\ProgramData\ytaf => Moved successfully. C:\ProgramData\unoj => Moved successfully. C:\ProgramData\tpaj => Moved successfully. C:\ProgramData\slir => Moved successfully. C:\ProgramData\jqug => Moved successfully. C:\ProgramData\ikif => Moved successfully. C:\ProgramData\fhaw => Moved successfully. C:\ProgramData\ahis => Moved successfully. C:\ProgramData\otob => Moved successfully. C:\ProgramData\sryp => Moved successfully. C:\ProgramData\sdyg => Moved successfully. C:\ProgramData\qzum => Moved successfully. C:\ProgramData\iwib => Moved successfully. C:\ProgramData\ivwr => Moved successfully. C:\ProgramData\ilyx => Moved successfully. C:\ProgramData\ilix => Moved successfully. C:\ProgramData\dxrd => Moved successfully. C:\ProgramData\dmes => Moved successfully. C:\ProgramData\ppug => Moved successfully. C:\ProgramData\ygar => Moved successfully. C:\ProgramData\usok => Moved successfully. C:\ProgramData\upev => Moved successfully. C:\ProgramData\ogol => Moved successfully. C:\ProgramData\ofrz => Moved successfully. C:\ProgramData\bjiv => Moved successfully. C:\ProgramData\yqaj => Moved successfully. C:\ProgramData\ykat => Moved successfully. C:\ProgramData\upeq => Moved successfully. C:\ProgramData\tmac => Moved successfully. C:\ProgramData\pzdc => Moved successfully. C:\ProgramData\ozef => Moved successfully. C:\ProgramData\ojed => Moved successfully. C:\ProgramData\ksab => Moved successfully. C:\ProgramData\epov => Moved successfully. C:\ProgramData\eceh => Moved successfully. C:\ProgramData\amyk => Moved successfully. C:\ProgramData\okes => Moved successfully. C:\ProgramData\ujux => Moved successfully. C:\ProgramData\ojox => Moved successfully. C:\ProgramData\ilyr => Moved successfully. C:\ProgramData\efus => Moved successfully. C:\ProgramData\alix => Moved successfully. C:\ProgramData\iriv => Moved successfully. C:\ProgramData\ezuf => Moved successfully. C:\ProgramData\epeg => Moved successfully. C:\ProgramData\ynag => Moved successfully. C:\ProgramData\ybis => Moved successfully. C:\ProgramData\vgoq => Moved successfully. C:\ProgramData\ukez => Moved successfully. C:\ProgramData\udrr => Moved successfully. C:\ProgramData\ucph => Moved successfully. C:\ProgramData\ezrc => Moved successfully. C:\ProgramData\ewed => Moved successfully. C:\ProgramData\ebok => Moved successfully. C:\ProgramData\eguv => Moved successfully. C:\ProgramData\yzis => Moved successfully. C:\ProgramData\ysyb => Moved successfully. C:\ProgramData\ujrj => Moved successfully. C:\ProgramData\qfus => Moved successfully. C:\ProgramData\pkrh => Moved successfully. C:\ProgramData\orud => Moved successfully. C:\ProgramData\exud => Moved successfully. C:\ProgramData\awiz => Moved successfully. C:\ProgramData\ypmj => Moved successfully. C:\ProgramData\wsaz => Moved successfully. C:\ProgramData\ofew => Moved successfully. C:\ProgramData\ewek => Moved successfully. C:\ProgramData\evog => Moved successfully. C:\ProgramData\eprv => Moved successfully. C:\ProgramData\anyv => Moved successfully. C:\ProgramData\iwab => Moved successfully. C:\ProgramData\ywib => Moved successfully. C:\ProgramData\ugel => Moved successfully. C:\ProgramData\shaw => Moved successfully. C:\ProgramData\rjej => Moved successfully. C:\ProgramData\ityt => Moved successfully. C:\ProgramData\epev => Moved successfully. C:\ProgramData\axyg => Moved successfully. C:\ProgramData\aqix => Moved successfully. C:\ProgramData\iwis => Moved successfully. C:\ProgramData\uzok => Moved successfully. C:\ProgramData\ugeg => Moved successfully. C:\ProgramData\inhv => Moved successfully. C:\ProgramData\ewef => Moved successfully. C:\ProgramData\dded => Moved successfully. C:\ProgramData\awzs => Moved successfully. C:\ProgramData\aryv => Moved successfully. C:\ProgramData\aqad => Moved successfully. C:\ProgramData\skwf => Moved successfully. C:\ProgramData\oqop => Moved successfully. C:\ProgramData\ojpx => Moved successfully. C:\ProgramData\idhg => Moved successfully. C:\ProgramData\fmkt => Moved successfully. C:\ProgramData\ezec => Moved successfully. C:\ProgramData\elog => Moved successfully. C:\ProgramData\uvol => Moved successfully. C:\ProgramData\otoz => Moved successfully. C:\ProgramData\oklh => Moved successfully. C:\ProgramData\ofes => Moved successfully. C:\ProgramData\ocos => Moved successfully. C:\ProgramData\icyt => Moved successfully. C:\ProgramData\ewum => Moved successfully. C:\ProgramData\eveg => Moved successfully. C:\ProgramData\eloq => Moved successfully. C:\ProgramData\aqax => Moved successfully. C:\ProgramData\ylix => Moved successfully. C:\ProgramData\ubom => Moved successfully. C:\ProgramData\ipir => Moved successfully. C:\ProgramData\efjh => Moved successfully. ==== End of Fixlog ==== Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 05.04.2014 Suchlauf-Zeit: 09:53:33 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.05.02 Rootkit Datenbank: v2014.03.27.01 Lizenz: Testversion Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: landumhollabrunn Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 249945 Verstrichene Zeit: 12 Min, 48 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=3ca60605e6232542884e1fcc8bc23578 # engine=17763 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-05 09:52:24 # local_time=2014-04-05 11:52:24 (+0100, Mitteleuropäische Sommerzeit) # country="Austria" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 22811013 148321394 0 0 # scanned=137264 # found=0 # cleaned=0 # scan_time=6341 |
05.04.2014, 11:04 | #17 |
| Hesperbot nach Telebanking FRST Logfile:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by landumhollabrunn (administrator) on LANDUMHOLLABRUN on 05-04-2014 11:57:15 Running from C:\Users\landumhollabrunn\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\A1 Dashboard\A1Dashboard_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidFind.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\A1 Dashboard\A1Dashboard_Launcher.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNAutoCon.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.EXE (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (WebToGo Gmbh) C:\Program Files (x86)\A1 Dashboard\A1Dashboard.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_12_0_0_77_ActiveX.exe (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-13] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277992 2011-11-15] (Realtek Semiconductor) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [589176 2011-12-20] (Alps Electric Co., Ltd.) HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11406608 2011-12-20] (Intel Corporation) HKLM\...\Run: [LoadFUJ02E3] - C:\Program Files\Fujitsu\FUJ02E3\fuj02e3.exe [76104 2011-11-24] (FUJITSU LIMITED) HKLM\...\Run: [PSUTility] - C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [205168 2011-10-03] (FUJITSU LIMITED) HKLM\...\Run: [LoadFujitsuQuickTouch] - C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [158024 2011-10-01] (FUJITSU LIMITED) HKLM\...\Run: [LoadBtnHnd] - C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe [23368 2011-10-01] (FUJITSU LIMITED) HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-06] (Intel Corporation) HKLM-x32\...\Run: [IndicatorUtility] - C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [48752 2010-09-30] (FUJITSU LIMITED) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [YouCam Service] - C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [255208 2012-03-21] (CyberLink Corp.) HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [TAG_A1Dashboard_Launcher.exe] - C:\Program Files (x86)\A1 Dashboard\A1Dashboard_Launcher.exe [531000 2013-07-03] () Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk ShortcutTarget: LaunchCenter.lnk -> C:\Program Files\Fujitsu\LaunchCenter\lcStarter.exe (Fujitsu Technology Solutions) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\newreminderdialog.lnk ShortcutTarget: newreminderdialog.lnk -> C:\Program Files\Fujitsu\FujitsuRecovery\NewReminderDialog.exe (Fujitsu Technology Solutions) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk ShortcutTarget: LaunchCenter.lnk -> C:\Program Files\Fujitsu\LaunchCenter\lcStarter.exe (Fujitsu Technology Solutions) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\newreminderdialog.lnk ShortcutTarget: newreminderdialog.lnk -> C:\Program Files\Fujitsu\FujitsuRecovery\NewReminderDialog.exe (Fujitsu Technology Solutions) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://landumhollabrunn.at/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=FTSH&bmod=FTSH; StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {19BF8574-BCDD-4FDB-90B2-115759B4B8FD} URL = SearchScopes: HKCU - {19BF8574-BCDD-4FDB-90B2-115759B4B8FD} URL = BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Tcpip\..\Interfaces\{0505D1E1-F888-4885-A0EE-12748D60855D}: [NameServer]194.48.128.199 194.48.139.254 ==================== Services (Whitelisted) ================= R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [225280 2011-08-05] (DTS, Inc) R2 FUJ02E3Service; C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [76104 2011-11-24] (FUJITSU LIMITED) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] () S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [2213376 2011-12-22] (FUJITSU LIMITED) R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63856 2011-10-03] (FUJITSU LIMITED) R2 TAG_Service; C:\Program Files (x86)\A1 Dashboard\A1Dashboard_Service.exe [510520 2013-07-03] () R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2012-01-06] (Microsoft Corporation) R0 FBIOSDRV; C:\Windows\System32\Drivers\FBIOSDRV.sys [21104 2009-06-24] (FUJITSU LIMITED) R3 FUJ02B1; C:\Windows\system32\drivers\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED) R3 FUJ02E3; C:\Windows\system32\drivers\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED) R3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [101120 2007-03-21] (Huawei Technologies Co., Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-05] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1812608 2011-12-28] () S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-05 09:57 - 2014-04-05 09:57 - 00001164 _____ () C:\Users\landumhollabrunn\Desktop\mbam.txt 2014-04-05 09:41 - 2014-04-05 09:41 - 02347384 _____ (ESET) C:\Users\landumhollabrunn\Desktop\esetsmartinstaller_enu.exe 2014-04-05 09:37 - 2014-04-05 09:39 - 00001108 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-05 09:36 - 2014-04-05 09:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-05 09:36 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-05 09:36 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-05 09:36 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-04 11:06 - 2014-04-04 11:06 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\landumhollabrunn\Desktop\tdsskiller.exe 2014-04-04 09:47 - 2014-04-04 09:47 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{6B362FE1-056C-4FB8-A0D5-14B5C61EB9F1} 2014-04-04 09:29 - 2014-04-05 11:57 - 00012995 _____ () C:\Users\landumhollabrunn\Desktop\FRST.txt 2014-04-04 09:28 - 2014-04-04 09:28 - 00028228 _____ () C:\Users\landumhollabrunn\Desktop\ComboFix.txt 2014-04-04 07:49 - 2014-04-04 07:49 - 05193944 ____R (Swearware) C:\Users\landumhollabrunn\Desktop\ComboFix.exe 2014-04-03 14:41 - 2014-04-03 14:42 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{8659CC7B-74B5-47E7-B1DC-1CB395F008D5} 2014-04-03 11:05 - 2014-04-03 11:05 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{CAC68900-655D-41C8-B222-3D2CFA1EC8E4} 2014-04-03 08:00 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-03 08:00 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-03 08:00 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-03 08:00 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-03 08:00 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-03 08:00 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-03 08:00 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-03 08:00 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-02 17:14 - 2014-04-04 09:08 - 00000000 ____D () C:\Qoobox 2014-04-02 17:13 - 2014-04-03 09:20 - 00000000 ____D () C:\Windows\erdnt 2014-04-02 16:48 - 2014-04-02 16:57 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Roaming\TAG 2014-04-02 16:48 - 2014-04-02 16:48 - 00001974 _____ () C:\Users\Public\Desktop\A1 Dashboard.lnk 2014-04-02 16:48 - 2014-04-02 16:48 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Roaming\Sierra Wireless 2014-04-02 16:48 - 2014-04-02 16:48 - 00000000 ____D () C:\Program Files (x86)\A1 Dashboard 2014-04-02 16:48 - 2011-08-16 21:47 - 00223232 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys 2014-04-02 16:17 - 2014-04-02 16:17 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf 2014-04-02 16:14 - 2014-04-02 16:14 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Roaming\Vodafone 2014-04-02 16:12 - 2014-04-02 16:12 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_vodafone_K3805-z_dc_enum_01009.Wdf 2014-04-02 16:11 - 2014-04-02 16:43 - 00000000 ____D () C:\ProgramData\Vodafone 2014-04-02 16:10 - 2014-04-02 16:10 - 00000000 ____D () C:\ProgramData\FLEXnet 2014-04-02 16:09 - 2014-04-02 16:09 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\Downloaded Installations 2014-04-02 15:50 - 2007-03-21 19:46 - 00101120 _____ (Huawei Technologies Co., Ltd.) C:\Windows\SysWOW64\Drivers\ewusbmdm.sys 2014-04-02 15:50 - 2007-03-21 19:46 - 00023424 _____ (Huawei Tech. Co., Ltd.) C:\Windows\SysWOW64\Drivers\ewdcsc.sys 2014-04-02 15:49 - 2014-04-02 15:49 - 00000000 ____D () C:\Program Files (x86)\Huawei technologies 2014-04-02 14:26 - 2014-04-05 11:57 - 00000000 ____D () C:\FRST 2014-04-02 14:11 - 2014-04-02 14:10 - 02157056 _____ (Farbar) C:\Users\landumhollabrunn\Desktop\FRST64.exe 2014-04-02 12:08 - 2014-04-02 12:08 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{D4D4BD83-A465-4628-BE50-F99B2ECE4106} 2014-04-01 08:48 - 2014-04-01 08:48 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{59848102-330C-4FE5-AABD-F9F020FC7EB2} 2014-03-31 10:49 - 2014-03-31 10:52 - 00000000 ____D () C:\Users\landumhollabrunn\Desktop\Siegerwein 2014-03-31 09:01 - 2014-03-31 09:01 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{CAE9EA0C-B471-475F-85B2-78941E001E17} 2014-03-28 10:07 - 2014-03-28 10:07 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{4C681DBC-2746-4DB9-B59A-7252ACFF6964} 2014-03-27 14:37 - 2014-03-27 14:39 - 00000000 ____D () C:\AdwCleaner 2014-03-27 14:16 - 2014-04-05 09:40 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-27 14:15 - 2014-03-27 14:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-27 09:44 - 2014-03-27 09:44 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{3B581A92-C415-4CD1-9998-7DE823F1F6E2} 2014-03-26 09:53 - 2014-03-26 09:54 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{88F9F5EF-FA11-441F-A765-4B2096E914C8} 2014-03-25 09:13 - 2014-03-25 09:13 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{90A3350E-AAB3-4D60-9785-F16D173F445E} 2014-03-24 10:00 - 2014-03-24 10:00 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{DBF45460-D52B-4337-ACD8-7F7D4C48FB00} 2014-03-21 09:32 - 2014-03-21 09:33 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{447E48D2-D74F-47A9-BBB8-75D974A3201C} 2014-03-19 10:29 - 2014-03-19 10:29 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{B1BBBE17-7F4F-4044-8B3B-2EF03E3BF39A} 2014-03-18 09:12 - 2014-03-18 09:12 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{A71E70F9-6789-4F28-AAB9-E2EB0421E10E} 2014-03-17 11:20 - 2014-03-17 11:20 - 00001543 _____ () C:\Users\landumhollabrunn\AppData\Local\recently-used.xbel 2014-03-17 09:26 - 2014-03-17 09:26 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{39321BCF-8928-477F-9C5A-E7A0715923A5} 2014-03-14 10:14 - 2014-03-14 10:14 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{9CAF92FB-63F9-4650-897F-262D57E904F0} 2014-03-14 09:18 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-14 09:18 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-14 09:18 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-14 09:18 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-14 09:18 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-14 09:18 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-14 09:18 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-14 09:18 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-14 09:18 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-14 09:18 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-14 09:18 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-14 09:18 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-14 09:18 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-14 09:18 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-14 09:18 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-14 09:18 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-14 09:18 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-14 09:18 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-14 09:18 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-14 09:18 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-14 09:18 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-14 09:17 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-14 09:17 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-14 09:17 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-14 09:17 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-14 09:17 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-14 09:17 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-14 09:17 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-14 09:17 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-14 09:17 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-14 09:17 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-14 09:17 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-14 09:17 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-14 09:17 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-14 09:17 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-14 09:17 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-14 09:17 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-14 09:17 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-14 09:17 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-14 09:17 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-14 09:17 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-14 09:17 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-14 09:17 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-14 09:17 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-14 09:16 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-14 09:16 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-14 09:16 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-14 09:16 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-13 09:18 - 2014-03-13 09:18 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{E12FD4C4-9A32-438F-AA30-419D45349138} 2014-03-12 09:44 - 2014-03-12 09:44 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{DA97A697-88E1-4F2D-B9B1-7FC1AF83655A} 2014-03-11 09:40 - 2014-03-11 09:40 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{8BFB0828-F46E-42F0-8CCD-204F374666D4} 2014-03-10 09:17 - 2014-03-10 09:17 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{711BF6FB-AAF0-44A5-8532-23D388F4E9AD} 2014-03-07 10:20 - 2014-03-07 10:20 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{56156112-1BB8-4EA5-BA8C-D5D5739FB7BB} 2014-03-06 10:26 - 2014-03-06 10:26 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{EAF36207-84D1-4451-BC3B-8C52FF3D95A0} ==================== One Month Modified Files and Folders ======= 2014-04-05 11:57 - 2014-04-04 09:29 - 00012995 _____ () C:\Users\landumhollabrunn\Desktop\FRST.txt 2014-04-05 11:57 - 2014-04-02 14:26 - 00000000 ____D () C:\FRST 2014-04-05 11:29 - 2013-09-02 09:27 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-05 10:40 - 2013-04-05 11:59 - 01251094 _____ () C:\Windows\WindowsUpdate.log 2014-04-05 10:02 - 2012-01-06 19:54 - 00699666 _____ () C:\Windows\system32\perfh007.dat 2014-04-05 10:02 - 2012-01-06 19:54 - 00149774 _____ () C:\Windows\system32\perfc007.dat 2014-04-05 10:02 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-05 09:57 - 2014-04-05 09:57 - 00001164 _____ () C:\Users\landumhollabrunn\Desktop\mbam.txt 2014-04-05 09:41 - 2014-04-05 09:41 - 02347384 _____ (ESET) C:\Users\landumhollabrunn\Desktop\esetsmartinstaller_enu.exe 2014-04-05 09:40 - 2014-03-27 14:16 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-05 09:39 - 2014-04-05 09:37 - 00001108 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-05 09:39 - 2014-04-05 09:36 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-05 09:24 - 2009-07-14 06:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-05 09:24 - 2009-07-14 06:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-05 09:18 - 2013-04-05 12:25 - 00000000 ____D () C:\Users\landumhollabrunn\Documents\Youcam 2014-04-05 09:17 - 2013-07-15 10:27 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\FreePDF_XP 2014-04-05 09:17 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-05 09:16 - 2009-07-14 06:51 - 00087407 _____ () C:\Windows\setupact.log 2014-04-04 11:06 - 2014-04-04 11:06 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\landumhollabrunn\Desktop\tdsskiller.exe 2014-04-04 09:47 - 2014-04-04 09:47 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{6B362FE1-056C-4FB8-A0D5-14B5C61EB9F1} 2014-04-04 09:43 - 2010-11-21 05:47 - 00942398 _____ () C:\Windows\PFRO.log 2014-04-04 09:38 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-04-04 09:28 - 2014-04-04 09:28 - 00028228 _____ () C:\Users\landumhollabrunn\Desktop\ComboFix.txt 2014-04-04 09:08 - 2014-04-02 17:14 - 00000000 ____D () C:\Qoobox 2014-04-04 09:05 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-04 07:49 - 2014-04-04 07:49 - 05193944 ____R (Swearware) C:\Users\landumhollabrunn\Desktop\ComboFix.exe 2014-04-03 15:56 - 2013-04-17 10:59 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\CrashDumps 2014-04-03 14:42 - 2014-04-03 14:41 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{8659CC7B-74B5-47E7-B1DC-1CB395F008D5} 2014-04-03 13:12 - 2014-01-28 10:37 - 00000000 ____D () C:\ProgramData\Sun 2014-04-03 11:05 - 2014-04-03 11:05 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{CAC68900-655D-41C8-B222-3D2CFA1EC8E4} 2014-04-03 09:51 - 2014-04-05 09:36 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-05 09:36 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-05 09:36 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-03 09:22 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-04-03 09:20 - 2014-04-02 17:13 - 00000000 ____D () C:\Windows\erdnt 2014-04-02 16:57 - 2014-04-02 16:48 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Roaming\TAG 2014-04-02 16:48 - 2014-04-02 16:48 - 00001974 _____ () C:\Users\Public\Desktop\A1 Dashboard.lnk 2014-04-02 16:48 - 2014-04-02 16:48 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Roaming\Sierra Wireless 2014-04-02 16:48 - 2014-04-02 16:48 - 00000000 ____D () C:\Program Files (x86)\A1 Dashboard 2014-04-02 16:45 - 2013-04-05 12:01 - 00090136 _____ () C:\Users\landumhollabrunn\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-02 16:44 - 2009-07-14 06:45 - 00351552 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-02 16:43 - 2014-04-02 16:11 - 00000000 ____D () C:\ProgramData\Vodafone 2014-04-02 16:17 - 2014-04-02 16:17 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf 2014-04-02 16:14 - 2014-04-02 16:14 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Roaming\Vodafone 2014-04-02 16:12 - 2014-04-02 16:12 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_vodafone_K3805-z_dc_enum_01009.Wdf 2014-04-02 16:10 - 2014-04-02 16:10 - 00000000 ____D () C:\ProgramData\FLEXnet 2014-04-02 16:09 - 2014-04-02 16:09 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\Downloaded Installations 2014-04-02 15:49 - 2014-04-02 15:49 - 00000000 ____D () C:\Program Files (x86)\Huawei technologies 2014-04-02 15:49 - 2012-03-02 20:29 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-02 14:10 - 2014-04-02 14:11 - 02157056 _____ (Farbar) C:\Users\landumhollabrunn\Desktop\FRST64.exe 2014-04-02 12:08 - 2014-04-02 12:08 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{D4D4BD83-A465-4628-BE50-F99B2ECE4106} 2014-04-02 11:41 - 2013-04-05 12:01 - 00000000 ____D () C:\Users\landumhollabrunn 2014-04-02 11:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-04-01 08:48 - 2014-04-01 08:48 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{59848102-330C-4FE5-AABD-F9F020FC7EB2} 2014-03-31 10:52 - 2014-03-31 10:49 - 00000000 ____D () C:\Users\landumhollabrunn\Desktop\Siegerwein 2014-03-31 09:01 - 2014-03-31 09:01 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{CAE9EA0C-B471-475F-85B2-78941E001E17} 2014-03-28 10:07 - 2014-03-28 10:07 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{4C681DBC-2746-4DB9-B59A-7252ACFF6964} 2014-03-27 14:39 - 2014-03-27 14:37 - 00000000 ____D () C:\AdwCleaner 2014-03-27 14:15 - 2014-03-27 14:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-27 09:44 - 2014-03-27 09:44 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{3B581A92-C415-4CD1-9998-7DE823F1F6E2} 2014-03-26 10:33 - 2013-04-08 09:45 - 00001912 _____ () C:\Windows\epplauncher.mif 2014-03-26 10:33 - 2013-04-08 09:45 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-03-26 10:33 - 2013-04-08 09:45 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client 2014-03-26 09:54 - 2014-03-26 09:53 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{88F9F5EF-FA11-441F-A765-4B2096E914C8} 2014-03-25 09:13 - 2014-03-25 09:13 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{90A3350E-AAB3-4D60-9785-F16D173F445E} 2014-03-24 10:00 - 2014-03-24 10:00 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{DBF45460-D52B-4337-ACD8-7F7D4C48FB00} 2014-03-21 09:33 - 2014-03-21 09:32 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{447E48D2-D74F-47A9-BBB8-75D974A3201C} 2014-03-19 10:29 - 2014-03-19 10:29 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{B1BBBE17-7F4F-4044-8B3B-2EF03E3BF39A} 2014-03-18 09:12 - 2014-03-18 09:12 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{A71E70F9-6789-4F28-AAB9-E2EB0421E10E} 2014-03-17 11:20 - 2014-03-17 11:20 - 00001543 _____ () C:\Users\landumhollabrunn\AppData\Local\recently-used.xbel 2014-03-17 11:20 - 2013-09-02 09:34 - 00000000 ____D () C:\Users\landumhollabrunn\.gimp-2.8 2014-03-17 09:26 - 2014-03-17 09:26 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{39321BCF-8928-477F-9C5A-E7A0715923A5} 2014-03-14 12:08 - 2013-04-08 16:42 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-14 12:08 - 2013-04-08 16:42 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-14 12:05 - 2013-04-08 09:28 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-03-14 10:14 - 2014-03-14 10:14 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{9CAF92FB-63F9-4650-897F-262D57E904F0} 2014-03-13 09:18 - 2014-03-13 09:18 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{E12FD4C4-9A32-438F-AA30-419D45349138} 2014-03-12 11:29 - 2013-09-02 09:27 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-12 11:29 - 2013-04-08 13:42 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 11:29 - 2013-04-08 13:42 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-12 09:44 - 2014-03-12 09:44 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{DA97A697-88E1-4F2D-B9B1-7FC1AF83655A} 2014-03-11 10:52 - 2013-01-20 15:59 - 00133928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\NisDrvWFP.sys 2014-03-11 09:40 - 2014-03-11 09:40 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{8BFB0828-F46E-42F0-8CCD-204F374666D4} 2014-03-10 09:17 - 2014-03-10 09:17 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{711BF6FB-AAF0-44A5-8532-23D388F4E9AD} 2014-03-07 10:20 - 2014-03-07 10:20 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{56156112-1BB8-4EA5-BA8C-D5D5739FB7BB} 2014-03-06 12:15 - 2013-04-05 12:01 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\Windows Live 2014-03-06 10:26 - 2014-03-06 10:26 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{EAF36207-84D1-4451-BC3B-8C52FF3D95A0} ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-31 13:23 ==================== End Of Log ============================ --- --- --- Schick! Du hast es ihm gezeigt. |
05.04.2014, 13:14 | #18 | ||
Ruhe in Frieden † 2019 | Hesperbot nach Telebanking Hallo Ohtarwen,
__________________Zitat:
Zitat:
Denk dran, überall deine Passwörter zu ändern, das ist wichtig! >OK< So wie ich es sehe, haben wir damit alles Schadhafte entfernt. Deine Logs sind sauber. Abschließend räumen wir noch etwas auf, führen Updates durch und dann bekommst du noch etwas Lesestoff von mir. Schritt 1 Falls Du Malwarebytes-Antimalware und den ESET-Onlinescan nicht mehr benötigst, kannst Du beide Programme einfach über die Programmdeinstallation deinstallieren. Ich empfehle Dir aber zumindest Malwarebytes zu behalten, und damit einmal die Woche einen Kontrollscan zu machen. Schritt 2 Bitte vor der folgenden Aktion wieder temporär Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren. Windows-Taste + R drücke. Kopiere nun folgende Zeile in die Kommandozeile und klicke OK. Code:
ATTFilter Combofix /Uninstall Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert, damit auch aus dieser die Schädlinge verschwinden. Nun die eben deaktivierten Programme wieder aktivieren. Schritt 3 Downloade dir bitte delfix auf deinen Desktop.
Updates / Programme aktualisieren
Updates / Programme aktualisieren Nun zum Schluss noch ein paar Tipps zur Absicherung deines Systems. Aktualität des Systems Es ist extrem wichtig, dass sowohl dein System als auch die darauf installierte sicherheitsrelevante Software (Flash Player, PDF-Reader und besonders Java, sofern vorhanden) aktuell sind.
Sofern du Java nicht zwingend benötigst, solltest du es komplett deinstallieren. Windows XP Gehe auf: Start --> Systemsteuerung --> Software --> Javaversionen auswählen --> entfernen Windows Vista Gehe auf: Start --> Systemsteuerung -- > Programme --> Programme deinstallieren --> Javaversionen suchen --> entfernen Windows 7 Dazu gehe auf: den Windowsbutton in der Taskleiste --> Systemsteuerung --> Programme (Unterpunkt Programme deinstallieren) --> Programm auswählen --> entfernen Windows 8 Dazu drücke auf: Windowstaste und X dann: Programme und Funktionen -->Javaversionen auswählen --> entfernen Falls du Java doch unbedingt benötigst, dann sorge dafür, dass Java automatisch updated. Dazu:
Hier findest du eine Anleitung dazu. Antivirensoftware
Zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der Internet Explorer, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Systemleistung Lösche regelmäßig deine temporären Dateien. Ich empfehle hierzu TFC Halte dich fern von jeglichen Registry Cleanern. Diese schaden deinem System mehr als dass sie es schneller machen. Verhaltensregeln zum sichereren Surfen
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen. Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind. Falls Du Lob oder Kritik abgeben möchtest, kannst Du das sehr gerne hier tun. Wenn Du etwas für das Forum und unsere Arbeit spenden möchtest, so kannst Du das hier tun.
__________________ |
05.04.2014, 15:10 | #19 |
| Hesperbot nach Telebanking So, ich hab mit Delfix alle Tools deinstalliert, Adobe und Java (Updates täglich), upgedatet und TFC laufen gelassen. Deine weiteren Tipps gebe ich an die Laptop-Eigentümerin weiter. Passwörter wurden bzw. werden alle geändert. Liebe Sandra, ich danke dir nochmals ganz herzlich für deine Hilfe! Es ist wirklich ganz toll, dass es dieses Forum gibt! Es erspart viel Nerven, Zeit und Geld - Quirxt, wie man bei uns sagt. Alles Liebe und Gute! Ohtarwen |
05.04.2014, 20:16 | #20 |
Ruhe in Frieden † 2019 | Hesperbot nach Telebanking Hallo Ohtarwen, er reicht, wenn du die Überprüfung bei den Java Updates auf wöchentlich stelltst. So oft wird das nicht aktualisiert. Ansonsten vielen Dank für dein Lob. Alles Gute dir. Dieses Thema scheint somit erledigt zu sein. Solltest Du noch Fragen oder Probleme haben, so schicke mir bitte eine PM |
10.04.2014, 12:27 | #21 |
| Hesperbot nach Telebanking Das frischeste frst-log: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 (ATTENTION: ====> FRST version is 28 days old and could be outdated) Ran by landumhollabrunn (administrator) on LANDUMHOLLABRUN on 10-04-2014 13:05:49 Running from C:\Users\landumhollabrunn\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidFind.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNAutoCon.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.EXE (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.EXE (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_12_0_0_77_ActiveX.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-13] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277992 2011-11-15] (Realtek Semiconductor) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [589176 2011-12-20] (Alps Electric Co., Ltd.) HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11406608 2011-12-20] (Intel Corporation) HKLM\...\Run: [LoadFUJ02E3] - C:\Program Files\Fujitsu\FUJ02E3\fuj02e3.exe [76104 2011-11-24] (FUJITSU LIMITED) HKLM\...\Run: [PSUTility] - C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [205168 2011-10-03] (FUJITSU LIMITED) HKLM\...\Run: [LoadFujitsuQuickTouch] - C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [158024 2011-10-01] (FUJITSU LIMITED) HKLM\...\Run: [LoadBtnHnd] - C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe [23368 2011-10-01] (FUJITSU LIMITED) HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-06] (Intel Corporation) HKLM-x32\...\Run: [IndicatorUtility] - C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [48752 2010-09-30] (FUJITSU LIMITED) HKLM-x32\...\Run: [YouCam Service] - C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [255208 2012-03-21] (CyberLink Corp.) HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk ShortcutTarget: LaunchCenter.lnk -> C:\Program Files\Fujitsu\LaunchCenter\lcStarter.exe (Fujitsu Technology Solutions) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\newreminderdialog.lnk ShortcutTarget: newreminderdialog.lnk -> C:\Program Files\Fujitsu\FujitsuRecovery\NewReminderDialog.exe (Fujitsu Technology Solutions) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk ShortcutTarget: LaunchCenter.lnk -> C:\Program Files\Fujitsu\LaunchCenter\lcStarter.exe (Fujitsu Technology Solutions) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\newreminderdialog.lnk ShortcutTarget: newreminderdialog.lnk -> C:\Program Files\Fujitsu\FujitsuRecovery\NewReminderDialog.exe (Fujitsu Technology Solutions) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://landumhollabrunn.at/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=FTSH&bmod=FTSH; StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {19BF8574-BCDD-4FDB-90B2-115759B4B8FD} URL = SearchScopes: HKCU - {19BF8574-BCDD-4FDB-90B2-115759B4B8FD} URL = BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.0.254 ==================== Services (Whitelisted) ================= R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [225280 2011-08-05] (DTS, Inc) R2 FUJ02E3Service; C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [76104 2011-11-24] (FUJITSU LIMITED) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] () R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [2213376 2011-12-22] (FUJITSU LIMITED) R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63856 2011-10-03] (FUJITSU LIMITED) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2012-01-06] (Microsoft Corporation) R0 FBIOSDRV; C:\Windows\System32\Drivers\FBIOSDRV.sys [21104 2009-06-24] (FUJITSU LIMITED) R3 FUJ02B1; C:\Windows\system32\drivers\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED) R3 FUJ02E3; C:\Windows\system32\drivers\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-10] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1812608 2011-12-28] () S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-10 13:05 - 2014-04-10 13:06 - 00012859 _____ () C:\Users\landumhollabrunn\Desktop\FRST.txt 2014-04-10 13:05 - 2014-04-10 13:05 - 02157056 _____ (Farbar) C:\Users\landumhollabrunn\Desktop\FRST64.exe 2014-04-10 13:05 - 2014-04-10 13:05 - 00000000 ____D () C:\FRST 2014-04-10 08:26 - 2014-04-10 08:27 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{1826762A-CA77-4A95-8D3A-8797FE6E2D40} 2014-04-09 09:14 - 2014-04-09 09:14 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{E29C3CBA-1B8E-437D-9AFC-B386C982CCDD} 2014-04-09 09:08 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 09:08 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 09:08 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 09:08 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 09:08 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 09:08 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 09:08 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 09:08 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 09:08 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 09:07 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 09:07 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 09:07 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 09:07 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 09:07 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 09:07 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 09:07 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 09:07 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 09:07 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 09:07 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 09:07 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 09:07 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 09:02 - 2014-04-09 09:02 - 00000654 _____ () C:\Users\landumhollabrunn\Desktop\gemeinsamer-Ordner_SPKG1Server.lnk 2014-04-05 15:53 - 2014-04-05 15:53 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-04-05 15:50 - 2014-04-09 13:28 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-05 15:50 - 2014-04-09 13:26 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-05 15:44 - 2014-04-05 15:45 - 00001265 _____ () C:\DelFix.txt 2014-04-05 15:44 - 2014-04-05 15:44 - 00000000 ____D () C:\Windows\ERUNT 2014-04-05 15:18 - 2014-04-05 15:18 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{275588A8-5A32-4538-B59A-5005FAC1A83A} 2014-04-05 15:17 - 2014-04-05 15:17 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{4975879B-673C-450F-BCAF-A95C88F393C2} 2014-04-05 09:36 - 2014-04-05 09:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-05 09:36 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-05 09:36 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-05 09:36 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-04 09:47 - 2014-04-04 09:47 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{6B362FE1-056C-4FB8-A0D5-14B5C61EB9F1} 2014-04-03 14:41 - 2014-04-03 14:42 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{8659CC7B-74B5-47E7-B1DC-1CB395F008D5} 2014-04-03 11:05 - 2014-04-03 11:05 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{CAC68900-655D-41C8-B222-3D2CFA1EC8E4} 2014-04-02 17:13 - 2014-04-05 15:24 - 00000000 ____D () C:\Windows\erdnt 2014-04-02 16:48 - 2014-04-02 16:48 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Roaming\Sierra Wireless 2014-04-02 16:17 - 2014-04-02 16:17 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf 2014-04-02 16:14 - 2014-04-02 16:14 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Roaming\Vodafone 2014-04-02 16:12 - 2014-04-02 16:12 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_vodafone_K3805-z_dc_enum_01009.Wdf 2014-04-02 16:11 - 2014-04-02 16:43 - 00000000 ____D () C:\ProgramData\Vodafone 2014-04-02 16:10 - 2014-04-02 16:10 - 00000000 ____D () C:\ProgramData\FLEXnet 2014-04-02 16:09 - 2014-04-02 16:09 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\Downloaded Installations 2014-04-02 15:49 - 2014-04-02 15:49 - 00000000 ____D () C:\Program Files (x86)\Huawei technologies 2014-04-02 12:08 - 2014-04-02 12:08 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{D4D4BD83-A465-4628-BE50-F99B2ECE4106} 2014-04-01 08:48 - 2014-04-01 08:48 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{59848102-330C-4FE5-AABD-F9F020FC7EB2} 2014-03-31 10:49 - 2014-03-31 10:52 - 00000000 ____D () C:\Users\landumhollabrunn\Desktop\Siegerwein 2014-03-31 09:01 - 2014-03-31 09:01 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{CAE9EA0C-B471-475F-85B2-78941E001E17} 2014-03-28 10:07 - 2014-03-28 10:07 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{4C681DBC-2746-4DB9-B59A-7252ACFF6964} 2014-03-27 14:16 - 2014-04-10 08:53 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-03-27 14:15 - 2014-03-27 14:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-27 09:44 - 2014-03-27 09:44 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{3B581A92-C415-4CD1-9998-7DE823F1F6E2} 2014-03-26 09:53 - 2014-03-26 09:54 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{88F9F5EF-FA11-441F-A765-4B2096E914C8} 2014-03-25 09:13 - 2014-03-25 09:13 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{90A3350E-AAB3-4D60-9785-F16D173F445E} 2014-03-24 10:00 - 2014-03-24 10:00 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{DBF45460-D52B-4337-ACD8-7F7D4C48FB00} 2014-03-21 09:32 - 2014-03-21 09:33 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{447E48D2-D74F-47A9-BBB8-75D974A3201C} 2014-03-19 10:29 - 2014-03-19 10:29 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{B1BBBE17-7F4F-4044-8B3B-2EF03E3BF39A} 2014-03-18 09:12 - 2014-03-18 09:12 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{A71E70F9-6789-4F28-AAB9-E2EB0421E10E} 2014-03-17 11:20 - 2014-03-17 11:20 - 00001543 _____ () C:\Users\landumhollabrunn\AppData\Local\recently-used.xbel 2014-03-17 09:26 - 2014-03-17 09:26 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{39321BCF-8928-477F-9C5A-E7A0715923A5} 2014-03-14 10:14 - 2014-03-14 10:14 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{9CAF92FB-63F9-4650-897F-262D57E904F0} 2014-03-14 09:18 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-14 09:18 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-14 09:18 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-14 09:18 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-14 09:18 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-14 09:18 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-14 09:18 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-14 09:18 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-14 09:18 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-14 09:18 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-14 09:18 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-14 09:18 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-14 09:18 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-14 09:18 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-14 09:18 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-14 09:18 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-14 09:18 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-14 09:18 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-14 09:18 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-14 09:17 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-14 09:17 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-14 09:17 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-14 09:17 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-14 09:17 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-14 09:17 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-14 09:17 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-14 09:17 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-14 09:17 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-14 09:17 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-14 09:17 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-14 09:17 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-14 09:17 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-14 09:17 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-14 09:17 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-14 09:17 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-14 09:17 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-14 09:17 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-14 09:17 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-14 09:17 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-14 09:17 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-14 09:16 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-14 09:16 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-14 09:16 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-14 09:16 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-13 09:18 - 2014-03-13 09:18 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{E12FD4C4-9A32-438F-AA30-419D45349138} 2014-03-12 09:44 - 2014-03-12 09:44 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{DA97A697-88E1-4F2D-B9B1-7FC1AF83655A} 2014-03-11 09:40 - 2014-03-11 09:40 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{8BFB0828-F46E-42F0-8CCD-204F374666D4} ==================== One Month Modified Files and Folders ======= 2014-04-10 13:06 - 2014-04-10 13:05 - 00012859 _____ () C:\Users\landumhollabrunn\Desktop\FRST.txt 2014-04-10 13:05 - 2014-04-10 13:05 - 02157056 _____ (Farbar) C:\Users\landumhollabrunn\Desktop\FRST64.exe 2014-04-10 13:05 - 2014-04-10 13:05 - 00000000 ____D () C:\FRST 2014-04-10 12:32 - 2013-04-05 11:59 - 01809793 _____ () C:\Windows\WindowsUpdate.log 2014-04-10 12:29 - 2013-09-02 09:27 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-10 11:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-10 08:53 - 2014-03-27 14:16 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-10 08:32 - 2009-07-14 06:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-10 08:32 - 2009-07-14 06:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-10 08:30 - 2012-01-06 19:54 - 00699666 _____ () C:\Windows\system32\perfh007.dat 2014-04-10 08:30 - 2012-01-06 19:54 - 00149774 _____ () C:\Windows\system32\perfc007.dat 2014-04-10 08:30 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-10 08:27 - 2014-04-10 08:26 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{1826762A-CA77-4A95-8D3A-8797FE6E2D40} 2014-04-10 08:26 - 2013-07-15 10:27 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\FreePDF_XP 2014-04-10 08:26 - 2013-04-05 12:25 - 00000000 ____D () C:\Users\landumhollabrunn\Documents\Youcam 2014-04-10 08:25 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-10 08:25 - 2009-07-14 06:51 - 00087855 _____ () C:\Windows\setupact.log 2014-04-09 13:29 - 2013-04-08 09:28 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-09 13:28 - 2014-04-05 15:50 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-09 13:26 - 2014-04-05 15:50 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 09:14 - 2014-04-09 09:14 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{E29C3CBA-1B8E-437D-9AFC-B386C982CCDD} 2014-04-09 09:02 - 2014-04-09 09:02 - 00000654 _____ () C:\Users\landumhollabrunn\Desktop\gemeinsamer-Ordner_SPKG1Server.lnk 2014-04-09 09:02 - 2013-04-08 11:13 - 00001483 _____ () C:\Users\landumhollabrunn\Desktop\LuH-Daten_SPKG1Server.lnk 2014-04-09 08:54 - 2010-11-21 05:47 - 00943974 _____ () C:\Windows\PFRO.log 2014-04-05 15:56 - 2013-04-08 11:21 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\Adobe 2014-04-05 15:53 - 2014-04-05 15:53 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-04-05 15:53 - 2013-04-05 12:21 - 00000000 ____D () C:\ProgramData\Adobe 2014-04-05 15:45 - 2014-04-05 15:44 - 00001265 _____ () C:\DelFix.txt 2014-04-05 15:44 - 2014-04-05 15:44 - 00000000 ____D () C:\Windows\ERUNT 2014-04-05 15:24 - 2014-04-02 17:13 - 00000000 ____D () C:\Windows\erdnt 2014-04-05 15:18 - 2014-04-05 15:18 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{275588A8-5A32-4538-B59A-5005FAC1A83A} 2014-04-05 15:17 - 2014-04-05 15:17 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{4975879B-673C-450F-BCAF-A95C88F393C2} 2014-04-05 09:39 - 2014-04-05 09:36 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-04 09:47 - 2014-04-04 09:47 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{6B362FE1-056C-4FB8-A0D5-14B5C61EB9F1} 2014-04-04 09:38 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-04-04 09:05 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-03 15:56 - 2013-04-17 10:59 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\CrashDumps 2014-04-03 14:42 - 2014-04-03 14:41 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{8659CC7B-74B5-47E7-B1DC-1CB395F008D5} 2014-04-03 13:12 - 2014-01-28 10:37 - 00000000 ____D () C:\ProgramData\Sun 2014-04-03 11:05 - 2014-04-03 11:05 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{CAC68900-655D-41C8-B222-3D2CFA1EC8E4} 2014-04-03 09:51 - 2014-04-05 09:36 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-05 09:36 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-05 09:36 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-03 09:22 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-04-02 16:48 - 2014-04-02 16:48 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Roaming\Sierra Wireless 2014-04-02 16:45 - 2013-04-05 12:01 - 00090136 _____ () C:\Users\landumhollabrunn\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-02 16:44 - 2009-07-14 06:45 - 00351552 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-02 16:43 - 2014-04-02 16:11 - 00000000 ____D () C:\ProgramData\Vodafone 2014-04-02 16:17 - 2014-04-02 16:17 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf 2014-04-02 16:14 - 2014-04-02 16:14 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Roaming\Vodafone 2014-04-02 16:12 - 2014-04-02 16:12 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_vodafone_K3805-z_dc_enum_01009.Wdf 2014-04-02 16:10 - 2014-04-02 16:10 - 00000000 ____D () C:\ProgramData\FLEXnet 2014-04-02 16:09 - 2014-04-02 16:09 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\Downloaded Installations 2014-04-02 15:49 - 2014-04-02 15:49 - 00000000 ____D () C:\Program Files (x86)\Huawei technologies 2014-04-02 15:49 - 2012-03-02 20:29 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-02 12:08 - 2014-04-02 12:08 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{D4D4BD83-A465-4628-BE50-F99B2ECE4106} 2014-04-02 11:41 - 2013-04-05 12:01 - 00000000 ____D () C:\Users\landumhollabrunn 2014-04-02 11:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-04-01 08:48 - 2014-04-01 08:48 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{59848102-330C-4FE5-AABD-F9F020FC7EB2} 2014-03-31 10:52 - 2014-03-31 10:49 - 00000000 ____D () C:\Users\landumhollabrunn\Desktop\Siegerwein 2014-03-31 09:01 - 2014-03-31 09:01 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{CAE9EA0C-B471-475F-85B2-78941E001E17} 2014-03-31 03:16 - 2014-04-09 09:08 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 09:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 09:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 09:08 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-28 10:07 - 2014-03-28 10:07 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{4C681DBC-2746-4DB9-B59A-7252ACFF6964} 2014-03-27 14:15 - 2014-03-27 14:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-27 09:44 - 2014-03-27 09:44 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{3B581A92-C415-4CD1-9998-7DE823F1F6E2} 2014-03-26 10:33 - 2013-04-08 09:45 - 00001912 _____ () C:\Windows\epplauncher.mif 2014-03-26 10:33 - 2013-04-08 09:45 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-03-26 10:33 - 2013-04-08 09:45 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client 2014-03-26 09:54 - 2014-03-26 09:53 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{88F9F5EF-FA11-441F-A765-4B2096E914C8} 2014-03-25 09:13 - 2014-03-25 09:13 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{90A3350E-AAB3-4D60-9785-F16D173F445E} 2014-03-24 10:00 - 2014-03-24 10:00 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{DBF45460-D52B-4337-ACD8-7F7D4C48FB00} 2014-03-21 09:33 - 2014-03-21 09:32 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{447E48D2-D74F-47A9-BBB8-75D974A3201C} 2014-03-19 10:29 - 2014-03-19 10:29 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{B1BBBE17-7F4F-4044-8B3B-2EF03E3BF39A} 2014-03-18 09:12 - 2014-03-18 09:12 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{A71E70F9-6789-4F28-AAB9-E2EB0421E10E} 2014-03-17 11:20 - 2014-03-17 11:20 - 00001543 _____ () C:\Users\landumhollabrunn\AppData\Local\recently-used.xbel 2014-03-17 11:20 - 2013-09-02 09:34 - 00000000 ____D () C:\Users\landumhollabrunn\.gimp-2.8 2014-03-17 09:26 - 2014-03-17 09:26 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{39321BCF-8928-477F-9C5A-E7A0715923A5} 2014-03-14 12:08 - 2013-04-08 16:42 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-14 12:08 - 2013-04-08 16:42 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-14 10:14 - 2014-03-14 10:14 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{9CAF92FB-63F9-4650-897F-262D57E904F0} 2014-03-13 09:18 - 2014-03-13 09:18 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{E12FD4C4-9A32-438F-AA30-419D45349138} 2014-03-12 11:29 - 2013-09-02 09:27 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-12 11:29 - 2013-04-08 13:42 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 11:29 - 2013-04-08 13:42 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-12 09:44 - 2014-03-12 09:44 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{DA97A697-88E1-4F2D-B9B1-7FC1AF83655A} 2014-03-11 10:52 - 2013-01-20 15:59 - 00133928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\NisDrvWFP.sys 2014-03-11 09:40 - 2014-03-11 09:40 - 00000000 ____D () C:\Users\landumhollabrunn\AppData\Local\{8BFB0828-F46E-42F0-8CCD-204F374666D4} Some content of TEMP: ==================== C:\Users\landumhollabrunn\AppData\Local\Temp\Uninstaller.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 09:41 ==================== End Of Log ============================ --- --- --- Und mit Firefox komme ich überall hin. Heißt das, das Problem betrifft nur IE? Ohne den könnt ich leben. |
10.04.2014, 20:43 | #22 | |
Ruhe in Frieden † 2019 | Hesperbot nach Telebanking Hallo Ohtarwen. Zitat:
Mache einmal folgendes und berichte mir dann, ob du wieder alle Seiten aufrufen kannst: Schritt 1 Setze folgendermassen den Internet Explorer zurück:
|
11.04.2014, 08:44 | #23 |
| Hesperbot nach Telebanking Liebe Sandra! Das war's. Alles wieder ok! Alle Seiten lassen sich öffnen. Schön, dass sich das letzte Problem so einfach und schnell beheben hat lassen. Vielen lieben herzlichen Dank! Gerda. |
Themen zu Hesperbot nach Telebanking |
dropper, ellung, essen, essentials, hesperbot, home, home premium, nichts, phishing, premium, rechner, security, security essentials, systemwiederherstellung, telebanking, troja, trojandropper, versuch, windows, windows 7, windows 7 home, windows 7 home premium |