Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Entfernen von Searchcore Toolbar und SpyHunter

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.

Antwort
Alt 09.03.2012, 12:31   #1
Trevita
 
Entfernen von Searchcore Toolbar und SpyHunter - Standard

Entfernen von Searchcore Toolbar und SpyHunter



Hallo zusammen,

scheinbar habe ich mir gestern "Searchcore Toolbar" eingefangen. Beim versuch dies schnell zu entfernen bin ich auch noch auf "SpyHunter" reingefallen.
Spyhunter habe ich über Systemsteuerung deinstalliert, habe aber in verschiedenen Foren gelesen, dass dies nicht ausreicht.

Könnt ihr mir helfen diese beiden Programme verlässlich von meinem System zu löschen.

Vielen Dank!

Alt 10.03.2012, 15:56   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Entfernen von Searchcore Toolbar und SpyHunter - Standard

Entfernen von Searchcore Toolbar und SpyHunter



Bitte nun routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:
ATTFilter
 hier steht das Log
         
__________________

__________________

Alt 11.03.2012, 18:13   #3
Trevita
 
Entfernen von Searchcore Toolbar und SpyHunter - Standard

Entfernen von Searchcore Toolbar und SpyHunter



Ok. Auf gehts

Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.10.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Rebekka :: BUBBLES [Administrator]

Schutz: Deaktiviert

10.03.2012 18:15:51
mbam-log-2012-03-10 (18-15-51).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 451052
Laufzeit: 1 Stunde(n), 39 Minute(n), 28 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\Rebekka\Downloads\Townopolis - Gold\Townopolis - Gold.exe (Trojan.MultiDropper) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)
         
Code:
ATTFilter
 ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=b9f1a3533de49c46a4320990d5bd4ef9
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-03-11 05:34:38
# local_time=2012-03-11 06:34:38 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 12875026 12875026 0 0
# compatibility_mode=5893 16776573 100 94 49933 83109698 0 0
# compatibility_mode=8192 67108863 100 0 189399 189399 0 0
# scanned=272021
# found=17
# cleaned=0
# scan_time=7450
C:\Program Files (x86)\Searchcore Toolbar\Datamngr\BrowserConnection.dll	Win32/Toolbar.SearchSuite application (unable to clean)	00000000000000000000000000000000	I
C:\Program Files (x86)\Searchcore Toolbar\Datamngr\datamngr.dll	Win32/Toolbar.SearchSuite application (unable to clean)	00000000000000000000000000000000	I
C:\Program Files (x86)\Searchcore Toolbar\Datamngr\datamngrUI.exe	a variant of Win32/Toolbar.SearchSuite application (unable to clean)	00000000000000000000000000000000	I
C:\Program Files (x86)\Searchcore Toolbar\Datamngr\DnsBHO.dll	Win32/Toolbar.SearchSuite application (unable to clean)	00000000000000000000000000000000	I
C:\Program Files (x86)\Searchcore Toolbar\Datamngr\IEBHO.dll	Win32/Toolbar.SearchSuite application (unable to clean)	00000000000000000000000000000000	I
C:\ProgramData\IBUpdaterService\ibsvc.exe	a variant of Win32/InstallBrain application (unable to clean)	00000000000000000000000000000000	I
C:\Users\All Users\IBUpdaterService\ibsvc.exe	a variant of Win32/InstallBrain application (unable to clean)	00000000000000000000000000000000	I
C:\Users\Rebekka\Downloads\AerieSpiritoftheForest_1662.exe	Win32/Toolbar.Zugo application (unable to clean)	00000000000000000000000000000000	I
C:\Users\Rebekka\Downloads\HotelMogulLasVegas_1662.exe	Win32/Toolbar.Zugo application (unable to clean)	00000000000000000000000000000000	I
C:\Users\Rebekka\Downloads\RescueTeam_1662.exe	Win32/Toolbar.Zugo application (unable to clean)	00000000000000000000000000000000	I
C:\Users\Rebekka\Downloads\SherlockHolmesandtheHoundoftheBaskervilles_1662.exe	Win32/Toolbar.Zugo application (unable to clean)	00000000000000000000000000000000	I
C:\Users\Rebekka\Downloads\SubAlawarComFictionFixersAdventuresinWonderland.exe	Win32/Toolbar.Zugo application (unable to clean)	00000000000000000000000000000000	I
C:\Users\Rebekka\Downloads\SubAlawarComGourmania3ZooZoom_10833.exe	Win32/Toolbar.Zugo application (unable to clean)	00000000000000000000000000000000	I
C:\Users\Rebekka\Downloads\SubAlawarComVirtualFarm2.exe	Win32/Toolbar.Zugo application (unable to clean)	00000000000000000000000000000000	I
C:\Users\Rebekka\Music\to be sorted\Monkey Island 1 and 2\AUTORUN.INF	INF/Autorun.gen trojan (unable to clean)	00000000000000000000000000000000	I
I:\$RECYCLE.BIN\S-1-5-21-2976300757-1645887798-770059044-1000\$RFVD8GI\Backup Set 2012-03-04 190001\Backup Files 2012-03-04 190001\Backup files 5.zip	INF/Autorun.gen trojan (unable to clean)	00000000000000000000000000000000	I
${Memory}	a variant of Win32/Toolbar.SearchSuite application	00000000000000000000000000000000	I
         
__________________

Alt 12.03.2012, 14:11   #4
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Entfernen von Searchcore Toolbar und SpyHunter - Standard

Entfernen von Searchcore Toolbar und SpyHunter



Zitat:
C:\Users\Rebekka\Downloads\Townopolis - Gold\Townopolis - Gold.exe
C:\Users\Rebekka\Downloads\SherlockHolmesandtheHoundoftheBaskervilles_1662.exe
Was ist das und aus welcher Quelle kommt das?

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.
__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 12.03.2012, 18:04   #5
Trevita
 
Entfernen von Searchcore Toolbar und SpyHunter - Standard

Entfernen von Searchcore Toolbar und SpyHunter



Beide dateien müßten zu Testversionen von Spielen gehören (vollversion 60 min testen) Die Quelle weiß ich leider nicht mehr. Sind aber keine dateien die benötigt werden und könnten jederzeit "gelöscht" werden.

Hier alle Logs:
Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.09.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Rebekka :: BUBBLES [Administrator]

Schutz: Aktiviert

09.03.2012 12:20:57
mbam-log-2012-03-09 (12-20-57).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 197616
Laufzeit: 13 Minute(n), 24 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 1
HKCU\SOFTWARE\Trymedia Systems (Adware.TryMedia) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Extracted\password.txt (Malware.Trace) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)
         
Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.09.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Rebekka :: BUBBLES [Administrator]

Schutz: Aktiviert

09.03.2012 12:35:16
mbam-log-2012-03-09 (12-35-16).txt

Art des Suchlaufs: Flash-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: Registrierung | Dateisystem | P2P
Durchsuchte Objekte: 156815
Laufzeit: 1 Minute(n), 

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         
Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.09.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Rebekka :: BUBBLES [Administrator]

Schutz: Aktiviert

09.03.2012 12:36:41
mbam-log-2012-03-09 (12-36-41).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 81690
Laufzeit: 36 Minute(n), 15 Sekunde(n) [Abgebrochen]

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         

Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.10.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Rebekka :: BUBBLES [Administrator]

Schutz: Deaktiviert

10.03.2012 18:10:53
mbam-log-2012-03-10 (18-10-53).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 46011
Laufzeit: 4 Minute(n), 5 Sekunde(n) [Abgebrochen]

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         
Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.10.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Rebekka :: BUBBLES [Administrator]

Schutz: Deaktiviert

10.03.2012 18:15:51
mbam-log-2012-03-10 (18-15-51).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 451052
Laufzeit: 1 Stunde(n), 39 Minute(n), 28 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\Rebekka\Downloads\Townopolis - Gold\Townopolis - Gold.exe (Trojan.MultiDropper) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)
         

Ach und bevor ichs vergess schonmal vielen Dank für deine Hilfe


Alt 12.03.2012, 18:51   #6
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Entfernen von Searchcore Toolbar und SpyHunter - Standard

Entfernen von Searchcore Toolbar und SpyHunter



Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:
ATTFilter
 hier steht das Log
         
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Starte bitte die OTL.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Kopiere nun den kompletten Inhalt aus der untenstehenden Codebox in die Textbox von OTL - wenn OTL auf deutsch ist wird sie mit beschriftet
Code:
ATTFilter
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT
         
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Klick auf .
  • Kopiere nun den Inhalt aus OTL.txt hier in Deinen Thread
__________________
--> Entfernen von Searchcore Toolbar und SpyHunter

Alt 13.03.2012, 18:17   #7
Trevita
 
Entfernen von Searchcore Toolbar und SpyHunter - Standard

Entfernen von Searchcore Toolbar und SpyHunter



Sorry kann nicht das Log nicht im Code Tag posten - bekomme die meldung das meine nachricht zu lang ist. Deshalb hab ichs als Anhang angespeichert

Alt 13.03.2012, 18:25   #8
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Entfernen von Searchcore Toolbar und SpyHunter - Standard

Entfernen von Searchcore Toolbar und SpyHunter



Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:
ATTFilter
:OTL
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}
IE:64bit: - HKLM\..\SearchScopes\{8B298634-17E9-4B2C-90A2-D1D12D08C99B}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=131133&systemid=426&sr=0&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}
IE - HKLM\..\SearchScopes\{9550359F-8F71-43F0-8CD0-CEAC0EA7AFD3}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=131133&systemid=426&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-2976300757-1645887798-770059044-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USCON/8
IE - HKU\S-1-5-21-2976300757-1645887798-770059044-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchcore.net/426
IE - HKU\S-1-5-21-2976300757-1645887798-770059044-1000\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}
IE - HKU\S-1-5-21-2976300757-1645887798-770059044-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=131133&systemid=426&sr=0&q={searchTerms}
FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Search Results"
FF - prefs.js..browser.startup.homepage: "http://www.searchcore.net/426"
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=131133&systemid=426&sr=0&q="
[2011.09.07 18:25:25 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012.03.08 18:37:21 | 000,000,000 | ---D | M] (Searchcore Toolbar) -- C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}
[2012.03.08 18:37:17 | 000,002,525 | ---- | M] () -- C:\Users\Rebekka\AppData\Roaming\Mozilla\Firefox\Profiles\vk5kexl5.default\searchplugins\Search_Results.xml
[2012.01.25 20:29:40 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.01.25 20:29:40 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012.01.25 20:29:40 | 000,001,180 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012.03.08 18:37:17 | 000,002,525 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
[2012.01.25 20:29:40 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
O2 - BHO: (DataMngr) - {7DA17D5A-5718-4130-A605-FC316C827836} - C:\PROGRA~2\SEARCH~1\Datamngr\BROWSE~1.DLL (Discordia , LTD)
O2:64bit: - BHO: (DataMngr) - {7DA17D5A-5718-4130-A605-FC316C827836} - C:\PROGRA~2\SEARCH~1\Datamngr\x64\BROWSE~1.DLL (Discordia , LTD)
O2 - BHO: (GetRight IE Helper) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files (x86)\GetRight\xx2gr.dll (Headlight Software, Inc.)
O2 - BHO: (DataMngr) - {7DA17D5A-5718-4130-A605-FC316C827836} - C:\PROGRA~2\SEARCH~1\Datamngr\BROWSE~1.DLL (Discordia , LTD)
O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files (x86)\Games\iWin Games\iWinGamesHookIE.dll (iWin Inc.)
O2 - BHO: (Searchcore Toolbar) - {af6ac4f2-9825-4fb6-a600-92bc5361f209} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchcoredtx.dll ()
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Searchcore Toolbar) - {af6ac4f2-9825-4fb6-a600-92bc5361f209} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchcoredtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2976300757-1645887798-770059044-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk =  File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk =  File not found
O4 - Startup: C:\Users\Rebekka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk =  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\S-1-5-21-2976300757-1645887798-770059044-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programme\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programme\PartyGaming\PartyPoker\RunApp.exe ()
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\Datamngr\x64\datamngr.dll) - C:\PROGRA~2\SEARCH~1\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\Datamngr\x64\IEBHO.dll) - C:\PROGRA~2\SEARCH~1\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\Datamngr\datamngr.dll) - C:\PROGRA~2\SEARCH~1\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll) - C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll (Discordia, LTD)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003.10.07 17:01:10 | 000,184,320 | R--- | M] (<A>lthammer <I>nteractive <M>ultimedia, Stuttgart.) - D:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2011.10.26 18:16:24 | 000,000,050 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2011.11.04 22:37:34 | 000,000,261 | R--- | M] () - D:\autorun.ini -- [ CDFS ]
O32 - Unable to obtain root file information for disk I:\
O33 - MountPoints2\{74b36606-f5d9-11de-a54b-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{74b36606-f5d9-11de-a54b-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Autorun.exe -- [2003.10.07 17:01:10 | 000,184,320 | R--- | M] (<A>lthammer <I>nteractive <M>ultimedia, Stuttgart.)
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:C22674B6
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:F78CC2A2
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:12D2EB9C
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:AAA14AF9
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:A3750BE5
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:78DEA3A4
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:31106FCB
@Alternate Data Stream - 68 bytes -> C:\Users\Rebekka\Documents\Reb.jpg:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Users\Rebekka\Documents\FA in da wurscht.mp3:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Users\Rebekka\Documents\DS-10023.wav:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Users\Rebekka\Documents\DS-10022.wav:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Users\Rebekka\Documents\3.wav:KAVICHS
@Alternate Data Stream - 253 bytes -> C:\ProgramData\TEMP:258D2F8B
@Alternate Data Stream - 248 bytes -> C:\ProgramData\TEMP:5DB36C47
@Alternate Data Stream - 246 bytes -> C:\ProgramData\TEMP:AE289451
@Alternate Data Stream - 238 bytes -> C:\ProgramData\TEMP:E5BA9ADD
@Alternate Data Stream - 237 bytes -> C:\ProgramData\TEMP:751D6870
@Alternate Data Stream - 233 bytes -> C:\ProgramData\TEMP:E9900C74
@Alternate Data Stream - 233 bytes -> C:\ProgramData\TEMP:BC1F7CAE
@Alternate Data Stream - 233 bytes -> C:\ProgramData\TEMP:696F7DA7
@Alternate Data Stream - 233 bytes -> C:\ProgramData\TEMP:38FF076E
@Alternate Data Stream - 232 bytes -> C:\ProgramData\TEMP:E6537A16
@Alternate Data Stream - 231 bytes -> C:\ProgramData\TEMP:2211E7A0
@Alternate Data Stream - 230 bytes -> C:\ProgramData\TEMP:1A15E356
@Alternate Data Stream - 229 bytes -> C:\ProgramData\TEMP:88AE8AB0
@Alternate Data Stream - 229 bytes -> C:\ProgramData\TEMP:762408BA
@Alternate Data Stream - 228 bytes -> C:\ProgramData\TEMP:93B0BB6F
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:9CF728A6
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:3EC5BC08
@Alternate Data Stream - 226 bytes -> C:\ProgramData\TEMP:F986CC21
@Alternate Data Stream - 226 bytes -> C:\ProgramData\TEMP:EA7D76BE
@Alternate Data Stream - 226 bytes -> C:\ProgramData\TEMP:9D6EAEC3
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:99AC3203
@Alternate Data Stream - 223 bytes -> C:\ProgramData\TEMP:BCDC6E07
@Alternate Data Stream - 223 bytes -> C:\ProgramData\TEMP:A3B8F70C
@Alternate Data Stream - 223 bytes -> C:\ProgramData\TEMP:7ADB695A
@Alternate Data Stream - 222 bytes -> C:\ProgramData\TEMP:3815BC84
@Alternate Data Stream - 220 bytes -> C:\ProgramData\TEMP:57EE48CA
@Alternate Data Stream - 218 bytes -> C:\ProgramData\TEMP:D1713795
@Alternate Data Stream - 218 bytes -> C:\ProgramData\TEMP:8E5EA40F
@Alternate Data Stream - 218 bytes -> C:\ProgramData\TEMP:78739EC9
@Alternate Data Stream - 217 bytes -> C:\ProgramData\TEMP:1E86ADD2
@Alternate Data Stream - 216 bytes -> C:\ProgramData\TEMP:D6D084A5
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:ADFAD95A
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:1CDEDE11
@Alternate Data Stream - 213 bytes -> C:\ProgramData\TEMP:DD95E6D9
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:BC076721
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:1B9E79B3
@Alternate Data Stream - 211 bytes -> C:\ProgramData\TEMP:6423D635
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:F7401CCF
@Alternate Data Stream - 209 bytes -> C:\ProgramData\TEMP:A9ABA3FF
@Alternate Data Stream - 209 bytes -> C:\ProgramData\TEMP:3571475C
@Alternate Data Stream - 208 bytes -> C:\ProgramData\TEMP:7E0EFF7B
@Alternate Data Stream - 207 bytes -> C:\ProgramData\TEMP:12EA4DC9
@Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:831C6B2D
@Alternate Data Stream - 202 bytes -> C:\ProgramData\TEMP:D7DA89B1
@Alternate Data Stream - 200 bytes -> C:\ProgramData\TEMP:708BB0FA
@Alternate Data Stream - 191 bytes -> C:\ProgramData\TEMP:CF61CE5A
@Alternate Data Stream - 190 bytes -> C:\ProgramData\TEMP:7920E530
@Alternate Data Stream - 184 bytes -> C:\ProgramData\TEMP:D1CD3D34
@Alternate Data Stream - 183 bytes -> C:\ProgramData\TEMP:76B3F064
@Alternate Data Stream - 182 bytes -> C:\ProgramData\TEMP:5BB3023B
@Alternate Data Stream - 181 bytes -> C:\ProgramData\TEMP:F70FE0AF
@Alternate Data Stream - 177 bytes -> C:\ProgramData\TEMP:E1362456
@Alternate Data Stream - 176 bytes -> C:\ProgramData\TEMP:BBB26FD3
@Alternate Data Stream - 173 bytes -> C:\ProgramData\TEMP:3B3A78C3
@Alternate Data Stream - 173 bytes -> C:\ProgramData\TEMP:319F93F3
@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:1A39A615
@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:03D3B5A1
@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:3E74CCD1
@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:3A171849
@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:128E1E7A
@Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:DD042F8C
@Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:B1512DC7
@Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:A01C2541
@Alternate Data Stream - 165 bytes -> C:\ProgramData\TEMP:30759574
@Alternate Data Stream - 163 bytes -> C:\ProgramData\TEMP:F9C33F77
@Alternate Data Stream - 162 bytes -> C:\ProgramData\TEMP:33255E85
@Alternate Data Stream - 161 bytes -> C:\ProgramData\TEMP:D84B3BE0
@Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:2199794C
@Alternate Data Stream - 154 bytes -> C:\ProgramData\TEMP:8BE19F9B
@Alternate Data Stream - 154 bytes -> C:\ProgramData\TEMP:43A63A0B
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:319D783D
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:A14921CB
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:86725A4F
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:859A3B1A
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:14A1BBE3
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:EAEE7554
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:C9BC8592
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:C0893153
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:961B84C5
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:3FB26DBA
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:F5FC5DCE
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:B8791731
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:8AEA12E8
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:7A8516BD
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:63210866
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:3A306D2E
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:EF0C5444
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:CA8D6B60
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:C0A9B815
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:BB718C46
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:BAF99E9B
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:B1381B34
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:9F82C43C
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:9E46FAD0
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:5CDDFF04
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:3A7527E8
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:36608448
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:2C4CFF17
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0DE96CF5
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:F3591DDB
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:ED2D63E4
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:CAF8DAC8
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:5C0940F1
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:3969ACF7
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:22416D17
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:1E147929
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:149327FE
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:124B94C0
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0EC7A545
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:04A18F36
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:041C0562
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:F142DBA9
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:48F5C64F
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:3A4C8FE7
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:349E5B74
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:2F8138B7
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:2502B755
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:178093AE
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:0194DAD3
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:FF30B9F7
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:FBB47A4A
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:B722BCE5
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:A6D89509
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:A4AF8D0D
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:95079543
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:908A1B53
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:89D8776D
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:3DCE5578
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:39EDBD33
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:F301EDA7
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:E6A96BE9
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:D0AB0B4A
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:A8DFD30C
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:A851461E
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:981456CB
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:943971F5
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:938EB9FC
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:8F6B26FD
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:701FCC18
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:6E2D80C8
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:6757F885
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:56C66609
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:371A321E
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:35629AE6
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:22910851
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:19474103
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:0BA6C13A
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:FFA87584
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:FAB64002
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:F56BE392
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:BCDBBA6D
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:AF24D911
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:A95624CB
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:A819A132
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:9A8F071F
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:99C301D0
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:7BE99D8F
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:6C75AF4C
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:62AC0CCE
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:5CE91C67
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:4F7FE589
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:4A01545C
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:29C0641D
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:223AE803
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:1E2D49E0
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:13019F4B
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:12E8505A
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:12D21A9A
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:0E8117B1
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:08E5EE32
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:06EAFA0B
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:FD38E906
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:FC70A22A
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:F7A0076D
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:C8CF775A
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:A92EA958
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:96646EC1
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:88C0A705
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:76953F21
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:71112705
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:68C30762
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:627153F1
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:40EE25BB
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:217A2324
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:114C90CA
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:FFD58FFB
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:EA1919C7
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:E99D1D3C
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:E6C6EB3B
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:E14FA16F
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:D8D58038
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:BF640EE5
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:B77DC80B
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:942805E4
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:90FA53E2
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:7F92D995
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:7E4E56EA
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:678C1866
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:5520ED93
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:4F28299B
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:415F73A0
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:3AF262FC
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:2D8B851C
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:15C28023
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:138A0A84
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:137E60A0
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:0BACBDD9
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:EAA88D28
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:E54E4E8D
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:DB0AE21A
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:D770A15D
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:B0A727D1
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:91A75192
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:80EA2EA3
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:58E7BF91
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:34C443B4
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:2CED8825
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:0F88E176
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:DDF112BD
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:DCE3590B
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:DB4C77AD
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:D7B7645F
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:C49A5AD1
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:AE5333A1
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:96A74292
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:94B46CA2
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:9491C9C7
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:9338F136
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:7CAC05C3
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:7C85EDF8
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:68A41423
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:6762B11B
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:639E673D
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:626A6161
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:53DF4438
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:4EC7F009
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:4600FBEE
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:3ECC91D7
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:1C201DEB
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:183A9046
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:164561C8
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:1234ADAE
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:10E0E83D
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:0BBF232A
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:08801FDB
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:0785072C
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:05670151
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:EFE7D3C9
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:EB68CA55
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:E060D418
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:BACB6B6C
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:AB3339EF
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:9720EBEF
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:87452B14
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:7BFAAE70
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:4149A170
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:3B07E6F4
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:31346E1D
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:2885CBFA
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:217A2A36
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:118DA42D
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:0ED1C542
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:F2B81C2E
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:EE198B1F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:ED9B661E
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:C3A9C939
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:BA5EEDA7
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:B4258C5D
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:91A12471
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:90A2AD6F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:90595C34
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:88E8CC2E
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:756A3FF0
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:737160C1
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:54380FEC
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:4AC7B5C1
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:479B1CF9
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:3E8082DA
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:3C0887BF
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:384AA0FD
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:2C399CCA
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:2AE74FF9
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:1B3549F2
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:008586AE
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:FCBEDCFD
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:FC836199
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F84B8DB5
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E411AA0D
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:CE8A42A3
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:BD8010FE
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:AA0017FD
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:A76A1B1B
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:A6FD3255
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:A6F3094D
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:9DB67071
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:9C3AAD57
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:92DB4653
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:81697BDB
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:7C8AA9A6
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:7BB47057
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:77B64C59
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:4B1CFD78
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:1DD8718C
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:06C34166
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:012BC84F
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:E8C44CB4
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:D0757AAB
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:CBAF0C30
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:C9E80AA2
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:C2F24DB5
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:BD34FFC5
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:B190BE3A
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:A0921B2C
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:9FD757A9
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:89E0CDE8
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:869E45C2
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:62EBE39C
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:6107A753
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:4DDE401B
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:393F7B1E
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:38337420
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:274516E7
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:0E5CFA74
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:0AACFF9D
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:F3BA8C7D
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:EC0279DC
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:E5B07840
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:E3F9A53E
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:D3A89E47
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:D0003616
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:CBB4BFCD
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:B0FAC520
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:A42FABF7
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:9D605054
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:983B4DC0
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:7EB8837A
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:587F3582
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:518C333F
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:4C3D5A8B
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:2E3F04BC
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:2216A431
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:0A423B55
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:041ED421
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:014BC3B4
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:EDC68C62
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:C48905F4
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:C43C957E
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:BE6B5FC3
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:B477FB2B
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:A5241382
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:A1023D41
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:99B20AD0
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:8855A119
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:5A9F1AE5
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:553056F1
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:51E83E25
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:3D6B89CE
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:3B454A5C
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:3AC0ED43
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:317747FA
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:29F0CA7D
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:1A684377
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:16C16B18
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:013CE219
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:EAF954B6
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:E3843FA6
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:D0BA3B35
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:D026A5A4
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:C9B27A06
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:B54E4B5A
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:B1E64E47
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:A6F28514
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:91DEEE71
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:8B4640AA
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:88FD3ED6
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:864881BF
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:75798D9A
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:6DDD2723
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:64D6413B
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:624A6897
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:609CAC7C
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:5E73E1C2
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:59465B40
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:53B8C5D2
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:4CC33C80
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:471AD3D0
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:3CA557DB
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:39DFF372
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:36A39835
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:31C9BA96
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:30308E0E
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:1585E7B2
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:14B2E0BD
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:1379054C
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:0FE0A03C
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:011B8910
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:D80C94F4
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:D5E0200E
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:D453E38B
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:C8033E19
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:C0BCE04B
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:BEACE4C8
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:B0456F0C
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:A9223B61
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:977F2E85
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:700B9342
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:5D9FEC13
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:3B59291C
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:39637387
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:36CB2BB0
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:32211F93
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:10D45FC3
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:0ACF1AF5
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:E894A3ED
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:D999FFD5
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:D9987109
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:D01ACC06
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:CADCEDF4
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:C83D135D
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:C3AD9507
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:BAFAD1DF
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:AB15E5CC
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:A4CB1038
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:8678F6BD
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:73B78E79
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:71AEFFEB
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:6017A808
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:4465CF27
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:3ED67A23
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:29861223
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:1416AAA6
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:F585E6E5
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:DCB1165A
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:DCA79AB3
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:D9771F40
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:D9656460
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:D3B928B0
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:C859F017
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:A9339169
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:A18D1A5B
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:927EC486
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:905BCB57
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:831F2C78
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:52F4CBFF
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:4FA837B4
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:2B856118
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:1181620C
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:10CFA7D4
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:02D1A2F4
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:F3366735
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:DD9FFC08
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:D72D7897
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:CAE777AD
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:94874C0A
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:93EC8514
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:830267C4
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:81980DF5
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:7EC01D6D
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:769DE8D6
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:6BFA43EB
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:6247E766
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:2A51A8DF
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:2498D8A2
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:04ADB7A6
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:F26F5952
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:BEE39E9B
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:BB1102D7
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:B8EB1B99
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:7BB20DE8
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:63387B59
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:424D7CFE
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:3651A580
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:2B40A7DB
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:23834E1E
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:1CE25169
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:0988A428
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:063969F8
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:FF9C44FE
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:EDD0DF13
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:E83EE313
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:E4AE7DC8
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:C76CFF82
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:C370B84F
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:B0C6C5CF
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:AABCC5A7
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:A6D6E537
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:9EE6560D
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:8DD20B4A
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:66871744
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:3CAE2A70
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:3AD6342E
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:2EB79F01
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:2B4FA895
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:26499772
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:202CF111
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:04BB186B
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:FB65A4AA
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:E6EC5C2A
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:CB299F13
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:BE40C8A2
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:B139DDF3
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:AEC3F61D
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:A5584049
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:9FC77097
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:8FA03A6A
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:85B3C587
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:823606DE
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:6FD36C4B
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:5BC73C48
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:5B09C4D9
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:24C072FF
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:20DF40C7
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D576A536
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C186F20B
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A279C25A
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A17CCD03
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:9E05DEB0
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:90108DD7
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:839ADBB2
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:824FDFA6
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:81413F67
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:79FD1F58
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:5E8C18F1
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:488F7244
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:3C9B05C4
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:397D67BA
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:39613F68
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:34EFF1F2
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:2729B5B9
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:268BA8AB
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:247D483C
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:1DB77A89
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:1968990D
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:11D3EBBB
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:F5D01D7C
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:D2397415
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:BCFEA004
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:B6E6C4EA
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:85376176
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:834DD57E
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:79875988
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:4726B04C
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:3EC1B848
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:348A3734
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:28819F45
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:206470A5
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:109734F6
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:E2CFA9CD
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:E21433CE
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:D39B2133
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:C36D0DFD
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:AE9351E0
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:9B2BD056
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:98982C88
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:8836A712
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:8204AA35
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:701B92FB
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:65137F0D
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:5D10C56A
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:596E986D
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:57619D72
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:5511B474
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4EA002DF
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4A2862FF
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:2ADF9928
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:2652902F
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:000D6A25
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:DC0B1070
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:DA7655EA
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:CBE042C1
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:C6920A5D
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:C30487EE
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:9BAC4211
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:9670EFE7
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:962308D2
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:9603033A
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:7E239580
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:765C6A14
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:73AFBB96
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:6F690C1B
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:65B8AF94
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5A8F8A0C
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:4CD3F344
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:4C31986D
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:41884BBE
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:39EFEA80
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:3086B95F
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:12258D63
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:0483BBEB
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:00AA4B31
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:EE69D7DF
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:E0A09032
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:CFF6B3FF
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:C22FB597
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:AB422E00
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:A8606E6E
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:A4E7D25F
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:A18FA397
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:93F0301A
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:91DAFF12
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:8BE7A048
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:774A0E14
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:697DDE2B
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:689AB7E9
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:3DB6F365
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:386B39C3
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:378824DE
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:330B710D
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:14B884E8
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:0D52F295
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:073139EC
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:F164CEA1
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:EC20549D
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:D9592966
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:CDCDE97C
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:CA2C26FF
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:B1786630
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:A5911AD8
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:6837B088
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:55DC0180
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:26A148EB
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:1B389835
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:13CDB0E0
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:EE7AAC75
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:EA9ACCA7
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:C0913157
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:AC8449E8
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:A5264343
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:857692EC
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:6EE5C3ED
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:6A0A47E7
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:49508BCE
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:2E9900EE
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:29B37860
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:27652001
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:25BB767E
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:08927BEA
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:8DD36B71
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:67CF910D
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:38D2EA83
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:2D2461E7
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:0968E571
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:05F547A9
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:E3615992
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:BF6A2C54
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:B3196E8D
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:A0CB43B2
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:8BFA0030
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:27974442
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:1604D047
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:ECF3C50F
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:C8182692
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:AECF4772
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:A688EF17
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:86B7FDDB
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:68A56598
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:6813E7F4
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:63C29481
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:512E1728
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:4EFA2FC7
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:14362DF8
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:E0EBA003
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:D882BE37
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:A4241298
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:A05F750A
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:9D03192E
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:8075370B
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:224B562C
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:07C99568
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:02CC0035
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:E690114B
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DF0BC727
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:15752405
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:8247A199
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:6BF0805F
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:5197985B
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:3D36932D
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:EB5BDBB0
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:3595B780
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:DBEF355E
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:95198126
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:592D7272
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:1ECED34B
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:28CDD861
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:27C3CD07
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:74091520
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:45912F61
:Commands
[emptytemp]
[resethosts]
         
Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 18.03.2012, 17:02   #9
Trevita
 
Entfernen von Searchcore Toolbar und SpyHunter - Standard

Entfernen von Searchcore Toolbar und SpyHunter



Auf den ersten Blick siehts so aus als hätte es geklappt
( kein Searchcore mehr zu sehen)

Code:
ATTFilter
 All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8B298634-17E9-4B2C-90A2-D1D12D08C99B}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B298634-17E9-4B2C-90A2-D1D12D08C99B}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}\ not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9550359F-8F71-43F0-8CD0-CEAC0EA7AFD3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9550359F-8F71-43F0-8CD0-CEAC0EA7AFD3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}\ not found.
HKU\S-1-5-21-2976300757-1645887798-770059044-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKU\S-1-5-21-2976300757-1645887798-770059044-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_USERS\S-1-5-21-2976300757-1645887798-770059044-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-2976300757-1645887798-770059044-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}\ not found.
Prefs.js: "Search Results" removed from browser.search.defaultenginename
Prefs.js: "Search Results" removed from browser.search.order.1
Prefs.js: "Search Results" removed from browser.search.selectedEngine
Prefs.js: "hxxp://www.searchcore.net/426" removed from browser.startup.homepage
Prefs.js: "hxxp://dts.search-results.com/sr?src=ffb&appid=131133&systemid=426&sr=0&q=" removed from keyword.URL
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGPSControl.plugin\Contents\Resources\English.lproj folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGPSControl.plugin\Contents\Resources folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGPSControl.plugin\Contents\MacOS folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGPSControl.plugin\Contents folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGPSControl.plugin folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\components folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\searchbar folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\options folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\weatherbutton\panels\images folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\weatherbutton\panels folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\weatherbutton\icons folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\weatherbutton folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\uwa folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\radio\images folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\radio\css folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\radio folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\panels\images folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\panels\default\scripts folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\panels\default\images folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\panels\default\css folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\panels\default folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\panels\css folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib\panels folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin\lib folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\skin folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\widgets\net.vmn.www.WebTV\skin\scripts folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\widgets\net.vmn.www.WebTV\skin\images folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\widgets\net.vmn.www.WebTV\skin\css folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\widgets\net.vmn.www.WebTV\skin folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\widgets\net.vmn.www.WebTV\js folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\widgets\net.vmn.www.WebTV\images folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\widgets\net.vmn.www.WebTV\css folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\widgets\net.vmn.www.WebTV folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\widgets\net.vmn.www.RadioBeta folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\widgets folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\modules folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\lib folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\data\search folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content\data folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome\content folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\chrome folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\mozilla\Firefox\Profiles\vk5kexl5.default\extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209} folder moved successfully.
C:\Users\Rebekka\AppData\Roaming\Mozilla\Firefox\Profiles\vk5kexl5.default\searchplugins\Search_Results.xml moved successfully.
C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml moved successfully.
C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml moved successfully.
C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml moved successfully.
C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml moved successfully.
C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DA17D5A-5718-4130-A605-FC316C827836}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DA17D5A-5718-4130-A605-FC316C827836}\ deleted successfully.
C:\PROGRA~2\SEARCH~1\Datamngr\BROWSE~1.DLL moved successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DA17D5A-5718-4130-A605-FC316C827836}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DA17D5A-5718-4130-A605-FC316C827836}\ deleted successfully.
C:\PROGRA~2\SEARCH~1\Datamngr\x64\BROWSE~1.DLL moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31FF080D-12A3-439A-A2EF-4BA95A3148E8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31FF080D-12A3-439A-A2EF-4BA95A3148E8}\ deleted successfully.
C:\Program Files (x86)\GetRight\xx2gr.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DA17D5A-5718-4130-A605-FC316C827836}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DA17D5A-5718-4130-A605-FC316C827836}\ not found.
File C:\PROGRA~2\SEARCH~1\Datamngr\BROWSE~1.DLL not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8CA5ED52-F3FB-4414-A105-2E3491156990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}\ deleted successfully.
C:\Program Files (x86)\Games\iWin Games\iWinGamesHookIE.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\ deleted successfully.
C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchcoredtx.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{af6ac4f2-9825-4fb6-a600-92bc5361f209} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{af6ac4f2-9825-4fb6-a600-92bc5361f209}\ not found.
File C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchcoredtx.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2976300757-1645887798-770059044-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\WinampAgent deleted successfully.
C:\Program Files (x86)\Winamp\winampa.exe moved successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk moved successfully.
File move failed. C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk scheduled to be moved on reboot.
C:\Users\Rebekka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\PromptOnSecureDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLUA deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2976300757-1645887798-770059044-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
C:\Programme\PartyGaming\PartyPoker\RunApp.exe moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
File C:\Programme\PartyGaming\PartyPoker\RunApp.exe not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\SEARCH~1\Datamngr\x64\datamngr.dll deleted successfully.
C:\PROGRA~2\SEARCH~1\Datamngr\x64\datamngr.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\SEARCH~1\Datamngr\x64\IEBHO.dll deleted successfully.
C:\PROGRA~2\SEARCH~1\Datamngr\x64\IEBHO.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\SEARCH~1\Datamngr\datamngr.dll deleted successfully.
C:\PROGRA~2\SEARCH~1\Datamngr\datamngr.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll deleted successfully.
C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
File move failed. D:\Autorun.exe scheduled to be moved on reboot.
File move failed. D:\autorun.inf scheduled to be moved on reboot.
File move failed. D:\autorun.ini scheduled to be moved on reboot.
File  not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74b36606-f5d9-11de-a54b-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74b36606-f5d9-11de-a54b-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74b36606-f5d9-11de-a54b-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74b36606-f5d9-11de-a54b-806e6f6e6963}\ not found.
File move failed. D:\Autorun.exe scheduled to be moved on reboot.
ADS C:\ProgramData\TEMP:C22674B6 deleted successfully.
ADS C:\ProgramData\TEMP:F78CC2A2 deleted successfully.
ADS C:\ProgramData\TEMP:12D2EB9C deleted successfully.
ADS C:\ProgramData\TEMP:AAA14AF9 deleted successfully.
ADS C:\ProgramData\TEMP:A3750BE5 deleted successfully.
ADS C:\ProgramData\TEMP:78DEA3A4 deleted successfully.
ADS C:\ProgramData\TEMP:31106FCB deleted successfully.
ADS C:\Users\Rebekka\Documents\Reb.jpg:KAVICHS deleted successfully.
ADS C:\Users\Rebekka\Documents\FA in da wurscht.mp3:KAVICHS deleted successfully.
ADS C:\Users\Rebekka\Documents\DS-10023.wav:KAVICHS deleted successfully.
ADS C:\Users\Rebekka\Documents\DS-10022.wav:KAVICHS deleted successfully.
ADS C:\Users\Rebekka\Documents\3.wav:KAVICHS deleted successfully.
ADS C:\ProgramData\TEMP:258D2F8B deleted successfully.
ADS C:\ProgramData\TEMP:5DB36C47 deleted successfully.
ADS C:\ProgramData\TEMP:AE289451 deleted successfully.
ADS C:\ProgramData\TEMP:E5BA9ADD deleted successfully.
ADS C:\ProgramData\TEMP:751D6870 deleted successfully.
ADS C:\ProgramData\TEMP:E9900C74 deleted successfully.
ADS C:\ProgramData\TEMP:BC1F7CAE deleted successfully.
ADS C:\ProgramData\TEMP:696F7DA7 deleted successfully.
ADS C:\ProgramData\TEMP:38FF076E deleted successfully.
ADS C:\ProgramData\TEMP:E6537A16 deleted successfully.
ADS C:\ProgramData\TEMP:2211E7A0 deleted successfully.
ADS C:\ProgramData\TEMP:1A15E356 deleted successfully.
ADS C:\ProgramData\TEMP:88AE8AB0 deleted successfully.
ADS C:\ProgramData\TEMP:762408BA deleted successfully.
ADS C:\ProgramData\TEMP:93B0BB6F deleted successfully.
ADS C:\ProgramData\TEMP:9CF728A6 deleted successfully.
ADS C:\ProgramData\TEMP:3EC5BC08 deleted successfully.
ADS C:\ProgramData\TEMP:F986CC21 deleted successfully.
ADS C:\ProgramData\TEMP:EA7D76BE deleted successfully.
ADS C:\ProgramData\TEMP:9D6EAEC3 deleted successfully.
ADS C:\ProgramData\TEMP:99AC3203 deleted successfully.
ADS C:\ProgramData\TEMP:BCDC6E07 deleted successfully.
ADS C:\ProgramData\TEMP:A3B8F70C deleted successfully.
ADS C:\ProgramData\TEMP:7ADB695A deleted successfully.
ADS C:\ProgramData\TEMP:3815BC84 deleted successfully.
ADS C:\ProgramData\TEMP:57EE48CA deleted successfully.
ADS C:\ProgramData\TEMP:D1713795 deleted successfully.
ADS C:\ProgramData\TEMP:8E5EA40F deleted successfully.
ADS C:\ProgramData\TEMP:78739EC9 deleted successfully.
ADS C:\ProgramData\TEMP:1E86ADD2 deleted successfully.
ADS C:\ProgramData\TEMP:D6D084A5 deleted successfully.
ADS C:\ProgramData\TEMP:ADFAD95A deleted successfully.
ADS C:\ProgramData\TEMP:1CDEDE11 deleted successfully.
ADS C:\ProgramData\TEMP:DD95E6D9 deleted successfully.
ADS C:\ProgramData\TEMP:BC076721 deleted successfully.
ADS C:\ProgramData\TEMP:1B9E79B3 deleted successfully.
ADS C:\ProgramData\TEMP:6423D635 deleted successfully.
ADS C:\ProgramData\TEMP:F7401CCF deleted successfully.
ADS C:\ProgramData\TEMP:A9ABA3FF deleted successfully.
ADS C:\ProgramData\TEMP:3571475C deleted successfully.
ADS C:\ProgramData\TEMP:7E0EFF7B deleted successfully.
ADS C:\ProgramData\TEMP:12EA4DC9 deleted successfully.
ADS C:\ProgramData\TEMP:831C6B2D deleted successfully.
ADS C:\ProgramData\TEMP:D7DA89B1 deleted successfully.
ADS C:\ProgramData\TEMP:708BB0FA deleted successfully.
ADS C:\ProgramData\TEMP:CF61CE5A deleted successfully.
ADS C:\ProgramData\TEMP:7920E530 deleted successfully.
ADS C:\ProgramData\TEMP:D1CD3D34 deleted successfully.
ADS C:\ProgramData\TEMP:76B3F064 deleted successfully.
ADS C:\ProgramData\TEMP:5BB3023B deleted successfully.
ADS C:\ProgramData\TEMP:F70FE0AF deleted successfully.
ADS C:\ProgramData\TEMP:E1362456 deleted successfully.
ADS C:\ProgramData\TEMP:BBB26FD3 deleted successfully.
ADS C:\ProgramData\TEMP:3B3A78C3 deleted successfully.
ADS C:\ProgramData\TEMP:319F93F3 deleted successfully.
ADS C:\ProgramData\TEMP:1A39A615 deleted successfully.
ADS C:\ProgramData\TEMP:03D3B5A1 deleted successfully.
ADS C:\ProgramData\TEMP:3E74CCD1 deleted successfully.
ADS C:\ProgramData\TEMP:3A171849 deleted successfully.
ADS C:\ProgramData\TEMP:128E1E7A deleted successfully.
ADS C:\ProgramData\TEMP:DD042F8C deleted successfully.
ADS C:\ProgramData\TEMP:B1512DC7 deleted successfully.
ADS C:\ProgramData\TEMP:A01C2541 deleted successfully.
ADS C:\ProgramData\TEMP:30759574 deleted successfully.
ADS C:\ProgramData\TEMP:F9C33F77 deleted successfully.
ADS C:\ProgramData\TEMP:33255E85 deleted successfully.
ADS C:\ProgramData\TEMP:D84B3BE0 deleted successfully.
ADS C:\ProgramData\TEMP:2199794C deleted successfully.
ADS C:\ProgramData\TEMP:8BE19F9B deleted successfully.
ADS C:\ProgramData\TEMP:43A63A0B deleted successfully.
ADS C:\ProgramData\TEMP:319D783D deleted successfully.
ADS C:\ProgramData\TEMP:A14921CB deleted successfully.
ADS C:\ProgramData\TEMP:86725A4F deleted successfully.
ADS C:\ProgramData\TEMP:859A3B1A deleted successfully.
ADS C:\ProgramData\TEMP:14A1BBE3 deleted successfully.
ADS C:\ProgramData\TEMP:EAEE7554 deleted successfully.
ADS C:\ProgramData\TEMP:C9BC8592 deleted successfully.
ADS C:\ProgramData\TEMP:C0893153 deleted successfully.
ADS C:\ProgramData\TEMP:961B84C5 deleted successfully.
ADS C:\ProgramData\TEMP:3FB26DBA deleted successfully.
ADS C:\ProgramData\TEMP:F5FC5DCE deleted successfully.
ADS C:\ProgramData\TEMP:B8791731 deleted successfully.
ADS C:\ProgramData\TEMP:8AEA12E8 deleted successfully.
ADS C:\ProgramData\TEMP:7A8516BD deleted successfully.
ADS C:\ProgramData\TEMP:63210866 deleted successfully.
ADS C:\ProgramData\TEMP:3A306D2E deleted successfully.
ADS C:\ProgramData\TEMP:EF0C5444 deleted successfully.
ADS C:\ProgramData\TEMP:CA8D6B60 deleted successfully.
ADS C:\ProgramData\TEMP:C0A9B815 deleted successfully.
ADS C:\ProgramData\TEMP:BB718C46 deleted successfully.
ADS C:\ProgramData\TEMP:BAF99E9B deleted successfully.
ADS C:\ProgramData\TEMP:B1381B34 deleted successfully.
ADS C:\ProgramData\TEMP:9F82C43C deleted successfully.
ADS C:\ProgramData\TEMP:9E46FAD0 deleted successfully.
ADS C:\ProgramData\TEMP:5CDDFF04 deleted successfully.
ADS C:\ProgramData\TEMP:3A7527E8 deleted successfully.
ADS C:\ProgramData\TEMP:36608448 deleted successfully.
ADS C:\ProgramData\TEMP:2C4CFF17 deleted successfully.
ADS C:\ProgramData\TEMP:0DE96CF5 deleted successfully.
ADS C:\ProgramData\TEMP:F3591DDB deleted successfully.
ADS C:\ProgramData\TEMP:ED2D63E4 deleted successfully.
ADS C:\ProgramData\TEMP:CAF8DAC8 deleted successfully.
ADS C:\ProgramData\TEMP:5C0940F1 deleted successfully.
ADS C:\ProgramData\TEMP:3969ACF7 deleted successfully.
ADS C:\ProgramData\TEMP:22416D17 deleted successfully.
ADS C:\ProgramData\TEMP:1E147929 deleted successfully.
ADS C:\ProgramData\TEMP:149327FE deleted successfully.
ADS C:\ProgramData\TEMP:124B94C0 deleted successfully.
ADS C:\ProgramData\TEMP:0EC7A545 deleted successfully.
ADS C:\ProgramData\TEMP:04A18F36 deleted successfully.
ADS C:\ProgramData\TEMP:041C0562 deleted successfully.
ADS C:\ProgramData\TEMP:F142DBA9 deleted successfully.
ADS C:\ProgramData\TEMP:48F5C64F deleted successfully.
ADS C:\ProgramData\TEMP:3A4C8FE7 deleted successfully.
ADS C:\ProgramData\TEMP:349E5B74 deleted successfully.
ADS C:\ProgramData\TEMP:2F8138B7 deleted successfully.
ADS C:\ProgramData\TEMP:2502B755 deleted successfully.
ADS C:\ProgramData\TEMP:178093AE deleted successfully.
ADS C:\ProgramData\TEMP:0194DAD3 deleted successfully.
ADS C:\ProgramData\TEMP:FF30B9F7 deleted successfully.
ADS C:\ProgramData\TEMP:FBB47A4A deleted successfully.
ADS C:\ProgramData\TEMP:B722BCE5 deleted successfully.
ADS C:\ProgramData\TEMP:A6D89509 deleted successfully.
ADS C:\ProgramData\TEMP:A4AF8D0D deleted successfully.
ADS C:\ProgramData\TEMP:95079543 deleted successfully.
ADS C:\ProgramData\TEMP:908A1B53 deleted successfully.
ADS C:\ProgramData\TEMP:89D8776D deleted successfully.
ADS C:\ProgramData\TEMP:3DCE5578 deleted successfully.
ADS C:\ProgramData\TEMP:39EDBD33 deleted successfully.
ADS C:\ProgramData\TEMP:F301EDA7 deleted successfully.
ADS C:\ProgramData\TEMP:E6A96BE9 deleted successfully.
ADS C:\ProgramData\TEMP:D0AB0B4A deleted successfully.
ADS C:\ProgramData\TEMP:A8DFD30C deleted successfully.
ADS C:\ProgramData\TEMP:A851461E deleted successfully.
ADS C:\ProgramData\TEMP:981456CB deleted successfully.
ADS C:\ProgramData\TEMP:943971F5 deleted successfully.
ADS C:\ProgramData\TEMP:938EB9FC deleted successfully.
ADS C:\ProgramData\TEMP:8F6B26FD deleted successfully.
ADS C:\ProgramData\TEMP:701FCC18 deleted successfully.
ADS C:\ProgramData\TEMP:6E2D80C8 deleted successfully.
ADS C:\ProgramData\TEMP:6757F885 deleted successfully.
ADS C:\ProgramData\TEMP:56C66609 deleted successfully.
ADS C:\ProgramData\TEMP:371A321E deleted successfully.
ADS C:\ProgramData\TEMP:35629AE6 deleted successfully.
ADS C:\ProgramData\TEMP:22910851 deleted successfully.
ADS C:\ProgramData\TEMP:19474103 deleted successfully.
ADS C:\ProgramData\TEMP:0BA6C13A deleted successfully.
ADS C:\ProgramData\TEMP:FFA87584 deleted successfully.
ADS C:\ProgramData\TEMP:FAB64002 deleted successfully.
ADS C:\ProgramData\TEMP:F56BE392 deleted successfully.
ADS C:\ProgramData\TEMP:BCDBBA6D deleted successfully.
ADS C:\ProgramData\TEMP:AF24D911 deleted successfully.
ADS C:\ProgramData\TEMP:A95624CB deleted successfully.
ADS C:\ProgramData\TEMP:A819A132 deleted successfully.
ADS C:\ProgramData\TEMP:9A8F071F deleted successfully.
ADS C:\ProgramData\TEMP:99C301D0 deleted successfully.
ADS C:\ProgramData\TEMP:7BE99D8F deleted successfully.
ADS C:\ProgramData\TEMP:6C75AF4C deleted successfully.
ADS C:\ProgramData\TEMP:62AC0CCE deleted successfully.
ADS C:\ProgramData\TEMP:5CE91C67 deleted successfully.
ADS C:\ProgramData\TEMP:4F7FE589 deleted successfully.
ADS C:\ProgramData\TEMP:4A01545C deleted successfully.
ADS C:\ProgramData\TEMP:29C0641D deleted successfully.
ADS C:\ProgramData\TEMP:223AE803 deleted successfully.
ADS C:\ProgramData\TEMP:1E2D49E0 deleted successfully.
ADS C:\ProgramData\TEMP:13019F4B deleted successfully.
ADS C:\ProgramData\TEMP:12E8505A deleted successfully.
ADS C:\ProgramData\TEMP:12D21A9A deleted successfully.
ADS C:\ProgramData\TEMP:0E8117B1 deleted successfully.
ADS C:\ProgramData\TEMP:08E5EE32 deleted successfully.
ADS C:\ProgramData\TEMP:06EAFA0B deleted successfully.
ADS C:\ProgramData\TEMP:FD38E906 deleted successfully.
ADS C:\ProgramData\TEMP:FC70A22A deleted successfully.
ADS C:\ProgramData\TEMP:F7A0076D deleted successfully.
ADS C:\ProgramData\TEMP:C8CF775A deleted successfully.
ADS C:\ProgramData\TEMP:A92EA958 deleted successfully.
ADS C:\ProgramData\TEMP:96646EC1 deleted successfully.
ADS C:\ProgramData\TEMP:88C0A705 deleted successfully.
ADS C:\ProgramData\TEMP:76953F21 deleted successfully.
ADS C:\ProgramData\TEMP:71112705 deleted successfully.
ADS C:\ProgramData\TEMP:68C30762 deleted successfully.
ADS C:\ProgramData\TEMP:627153F1 deleted successfully.
ADS C:\ProgramData\TEMP:40EE25BB deleted successfully.
ADS C:\ProgramData\TEMP:217A2324 deleted successfully.
ADS C:\ProgramData\TEMP:114C90CA deleted successfully.
ADS C:\ProgramData\TEMP:FFD58FFB deleted successfully.
ADS C:\ProgramData\TEMP:EA1919C7 deleted successfully.
ADS C:\ProgramData\TEMP:E99D1D3C deleted successfully.
ADS C:\ProgramData\TEMP:E6C6EB3B deleted successfully.
ADS C:\ProgramData\TEMP:E14FA16F deleted successfully.
ADS C:\ProgramData\TEMP:D8D58038 deleted successfully.
ADS C:\ProgramData\TEMP:BF640EE5 deleted successfully.
ADS C:\ProgramData\TEMP:B77DC80B deleted successfully.
ADS C:\ProgramData\TEMP:942805E4 deleted successfully.
ADS C:\ProgramData\TEMP:90FA53E2 deleted successfully.
ADS C:\ProgramData\TEMP:7F92D995 deleted successfully.
ADS C:\ProgramData\TEMP:7E4E56EA deleted successfully.
ADS C:\ProgramData\TEMP:678C1866 deleted successfully.
ADS C:\ProgramData\TEMP:5520ED93 deleted successfully.
ADS C:\ProgramData\TEMP:4F28299B deleted successfully.
ADS C:\ProgramData\TEMP:415F73A0 deleted successfully.
ADS C:\ProgramData\TEMP:3AF262FC deleted successfully.
ADS C:\ProgramData\TEMP:2D8B851C deleted successfully.
ADS C:\ProgramData\TEMP:15C28023 deleted successfully.
ADS C:\ProgramData\TEMP:138A0A84 deleted successfully.
ADS C:\ProgramData\TEMP:137E60A0 deleted successfully.
ADS C:\ProgramData\TEMP:0BACBDD9 deleted successfully.
ADS C:\ProgramData\TEMP:EAA88D28 deleted successfully.
ADS C:\ProgramData\TEMP:E54E4E8D deleted successfully.
ADS C:\ProgramData\TEMP:DB0AE21A deleted successfully.
ADS C:\ProgramData\TEMP:D770A15D deleted successfully.
ADS C:\ProgramData\TEMP:B0A727D1 deleted successfully.
ADS C:\ProgramData\TEMP:91A75192 deleted successfully.
ADS C:\ProgramData\TEMP:80EA2EA3 deleted successfully.
ADS C:\ProgramData\TEMP:58E7BF91 deleted successfully.
ADS C:\ProgramData\TEMP:34C443B4 deleted successfully.
ADS C:\ProgramData\TEMP:2CED8825 deleted successfully.
ADS C:\ProgramData\TEMP:0F88E176 deleted successfully.
ADS C:\ProgramData\TEMP:DDF112BD deleted successfully.
ADS C:\ProgramData\TEMP:DCE3590B deleted successfully.
ADS C:\ProgramData\TEMP:DB4C77AD deleted successfully.
ADS C:\ProgramData\TEMP:D7B7645F deleted successfully.
ADS C:\ProgramData\TEMP:C49A5AD1 deleted successfully.
ADS C:\ProgramData\TEMP:AE5333A1 deleted successfully.
ADS C:\ProgramData\TEMP:96A74292 deleted successfully.
ADS C:\ProgramData\TEMP:94B46CA2 deleted successfully.
ADS C:\ProgramData\TEMP:9491C9C7 deleted successfully.
ADS C:\ProgramData\TEMP:9338F136 deleted successfully.
ADS C:\ProgramData\TEMP:7CAC05C3 deleted successfully.
ADS C:\ProgramData\TEMP:7C85EDF8 deleted successfully.
ADS C:\ProgramData\TEMP:68A41423 deleted successfully.
ADS C:\ProgramData\TEMP:6762B11B deleted successfully.
ADS C:\ProgramData\TEMP:639E673D deleted successfully.
ADS C:\ProgramData\TEMP:626A6161 deleted successfully.
ADS C:\ProgramData\TEMP:53DF4438 deleted successfully.
ADS C:\ProgramData\TEMP:4EC7F009 deleted successfully.
ADS C:\ProgramData\TEMP:4600FBEE deleted successfully.
ADS C:\ProgramData\TEMP:3ECC91D7 deleted successfully.
ADS C:\ProgramData\TEMP:1C201DEB deleted successfully.
ADS C:\ProgramData\TEMP:183A9046 deleted successfully.
ADS C:\ProgramData\TEMP:164561C8 deleted successfully.
ADS C:\ProgramData\TEMP:1234ADAE deleted successfully.
ADS C:\ProgramData\TEMP:10E0E83D deleted successfully.
ADS C:\ProgramData\TEMP:0BBF232A deleted successfully.
ADS C:\ProgramData\TEMP:08801FDB deleted successfully.
ADS C:\ProgramData\TEMP:0785072C deleted successfully.
ADS C:\ProgramData\TEMP:05670151 deleted successfully.
ADS C:\ProgramData\TEMP:EFE7D3C9 deleted successfully.
ADS C:\ProgramData\TEMP:EB68CA55 deleted successfully.
ADS C:\ProgramData\TEMP:E060D418 deleted successfully.
ADS C:\ProgramData\TEMP:BACB6B6C deleted successfully.
ADS C:\ProgramData\TEMP:AB3339EF deleted successfully.
ADS C:\ProgramData\TEMP:9720EBEF deleted successfully.
ADS C:\ProgramData\TEMP:87452B14 deleted successfully.
ADS C:\ProgramData\TEMP:7BFAAE70 deleted successfully.
ADS C:\ProgramData\TEMP:4149A170 deleted successfully.
ADS C:\ProgramData\TEMP:3B07E6F4 deleted successfully.
ADS C:\ProgramData\TEMP:31346E1D deleted successfully.
ADS C:\ProgramData\TEMP:2885CBFA deleted successfully.
ADS C:\ProgramData\TEMP:217A2A36 deleted successfully.
ADS C:\ProgramData\TEMP:118DA42D deleted successfully.
ADS C:\ProgramData\TEMP:0ED1C542 deleted successfully.
ADS C:\ProgramData\TEMP:F2B81C2E deleted successfully.
ADS C:\ProgramData\TEMP:EE198B1F deleted successfully.
ADS C:\ProgramData\TEMP:ED9B661E deleted successfully.
ADS C:\ProgramData\TEMP:C3A9C939 deleted successfully.
ADS C:\ProgramData\TEMP:BA5EEDA7 deleted successfully.
ADS C:\ProgramData\TEMP:B4258C5D deleted successfully.
ADS C:\ProgramData\TEMP:91A12471 deleted successfully.
ADS C:\ProgramData\TEMP:90A2AD6F deleted successfully.
ADS C:\ProgramData\TEMP:90595C34 deleted successfully.
ADS C:\ProgramData\TEMP:88E8CC2E deleted successfully.
ADS C:\ProgramData\TEMP:756A3FF0 deleted successfully.
ADS C:\ProgramData\TEMP:737160C1 deleted successfully.
ADS C:\ProgramData\TEMP:54380FEC deleted successfully.
ADS C:\ProgramData\TEMP:4AC7B5C1 deleted successfully.
ADS C:\ProgramData\TEMP:479B1CF9 deleted successfully.
ADS C:\ProgramData\TEMP:3E8082DA deleted successfully.
ADS C:\ProgramData\TEMP:3C0887BF deleted successfully.
ADS C:\ProgramData\TEMP:384AA0FD deleted successfully.
ADS C:\ProgramData\TEMP:2C399CCA deleted successfully.
ADS C:\ProgramData\TEMP:2AE74FF9 deleted successfully.
ADS C:\ProgramData\TEMP:1B3549F2 deleted successfully.
ADS C:\ProgramData\TEMP:008586AE deleted successfully.
ADS C:\ProgramData\TEMP:FCBEDCFD deleted successfully.
ADS C:\ProgramData\TEMP:FC836199 deleted successfully.
ADS C:\ProgramData\TEMP:F84B8DB5 deleted successfully.
ADS C:\ProgramData\TEMP:E411AA0D deleted successfully.
ADS C:\ProgramData\TEMP:CE8A42A3 deleted successfully.
ADS C:\ProgramData\TEMP:BD8010FE deleted successfully.
ADS C:\ProgramData\TEMP:AA0017FD deleted successfully.
ADS C:\ProgramData\TEMP:A76A1B1B deleted successfully.
ADS C:\ProgramData\TEMP:A6FD3255 deleted successfully.
ADS C:\ProgramData\TEMP:A6F3094D deleted successfully.
ADS C:\ProgramData\TEMP:9DB67071 deleted successfully.
ADS C:\ProgramData\TEMP:9C3AAD57 deleted successfully.
ADS C:\ProgramData\TEMP:92DB4653 deleted successfully.
ADS C:\ProgramData\TEMP:81697BDB deleted successfully.
ADS C:\ProgramData\TEMP:7C8AA9A6 deleted successfully.
ADS C:\ProgramData\TEMP:7BB47057 deleted successfully.
ADS C:\ProgramData\TEMP:77B64C59 deleted successfully.
ADS C:\ProgramData\TEMP:4B1CFD78 deleted successfully.
ADS C:\ProgramData\TEMP:1DD8718C deleted successfully.
ADS C:\ProgramData\TEMP:06C34166 deleted successfully.
ADS C:\ProgramData\TEMP:012BC84F deleted successfully.
ADS C:\ProgramData\TEMP:E8C44CB4 deleted successfully.
ADS C:\ProgramData\TEMP:D0757AAB deleted successfully.
ADS C:\ProgramData\TEMP:CBAF0C30 deleted successfully.
ADS C:\ProgramData\TEMP:C9E80AA2 deleted successfully.
ADS C:\ProgramData\TEMP:C2F24DB5 deleted successfully.
ADS C:\ProgramData\TEMP:BD34FFC5 deleted successfully.
ADS C:\ProgramData\TEMP:B190BE3A deleted successfully.
ADS C:\ProgramData\TEMP:A0921B2C deleted successfully.
ADS C:\ProgramData\TEMP:9FD757A9 deleted successfully.
ADS C:\ProgramData\TEMP:89E0CDE8 deleted successfully.
ADS C:\ProgramData\TEMP:869E45C2 deleted successfully.
ADS C:\ProgramData\TEMP:62EBE39C deleted successfully.
ADS C:\ProgramData\TEMP:6107A753 deleted successfully.
ADS C:\ProgramData\TEMP:4DDE401B deleted successfully.
ADS C:\ProgramData\TEMP:393F7B1E deleted successfully.
ADS C:\ProgramData\TEMP:38337420 deleted successfully.
ADS C:\ProgramData\TEMP:274516E7 deleted successfully.
ADS C:\ProgramData\TEMP:0E5CFA74 deleted successfully.
ADS C:\ProgramData\TEMP:0AACFF9D deleted successfully.
ADS C:\ProgramData\TEMP:F3BA8C7D deleted successfully.
ADS C:\ProgramData\TEMP:EC0279DC deleted successfully.
ADS C:\ProgramData\TEMP:E5B07840 deleted successfully.
ADS C:\ProgramData\TEMP:E3F9A53E deleted successfully.
ADS C:\ProgramData\TEMP:D3A89E47 deleted successfully.
ADS C:\ProgramData\TEMP:D0003616 deleted successfully.
ADS C:\ProgramData\TEMP:CBB4BFCD deleted successfully.
ADS C:\ProgramData\TEMP:B0FAC520 deleted successfully.
ADS C:\ProgramData\TEMP:A42FABF7 deleted successfully.
ADS C:\ProgramData\TEMP:9D605054 deleted successfully.
ADS C:\ProgramData\TEMP:983B4DC0 deleted successfully.
ADS C:\ProgramData\TEMP:7EB8837A deleted successfully.
ADS C:\ProgramData\TEMP:587F3582 deleted successfully.
ADS C:\ProgramData\TEMP:518C333F deleted successfully.
ADS C:\ProgramData\TEMP:4C3D5A8B deleted successfully.
ADS C:\ProgramData\TEMP:2E3F04BC deleted successfully.
ADS C:\ProgramData\TEMP:2216A431 deleted successfully.
ADS C:\ProgramData\TEMP:0A423B55 deleted successfully.
ADS C:\ProgramData\TEMP:041ED421 deleted successfully.
ADS C:\ProgramData\TEMP:014BC3B4 deleted successfully.
ADS C:\ProgramData\TEMP:EDC68C62 deleted successfully.
ADS C:\ProgramData\TEMP:C48905F4 deleted successfully.
ADS C:\ProgramData\TEMP:C43C957E deleted successfully.
ADS C:\ProgramData\TEMP:BE6B5FC3 deleted successfully.
ADS C:\ProgramData\TEMP:B477FB2B deleted successfully.
ADS C:\ProgramData\TEMP:A5241382 deleted successfully.
ADS C:\ProgramData\TEMP:A1023D41 deleted successfully.
ADS C:\ProgramData\TEMP:99B20AD0 deleted successfully.
ADS C:\ProgramData\TEMP:8855A119 deleted successfully.
ADS C:\ProgramData\TEMP:5A9F1AE5 deleted successfully.
ADS C:\ProgramData\TEMP:553056F1 deleted successfully.
ADS C:\ProgramData\TEMP:51E83E25 deleted successfully.
ADS C:\ProgramData\TEMP:3D6B89CE deleted successfully.
ADS C:\ProgramData\TEMP:3B454A5C deleted successfully.
ADS C:\ProgramData\TEMP:3AC0ED43 deleted successfully.
ADS C:\ProgramData\TEMP:317747FA deleted successfully.
ADS C:\ProgramData\TEMP:29F0CA7D deleted successfully.
ADS C:\ProgramData\TEMP:1A684377 deleted successfully.
ADS C:\ProgramData\TEMP:16C16B18 deleted successfully.
ADS C:\ProgramData\TEMP:013CE219 deleted successfully.
ADS C:\ProgramData\TEMP:EAF954B6 deleted successfully.
ADS C:\ProgramData\TEMP:E3843FA6 deleted successfully.
ADS C:\ProgramData\TEMP:D0BA3B35 deleted successfully.
ADS C:\ProgramData\TEMP:D026A5A4 deleted successfully.
ADS C:\ProgramData\TEMP:C9B27A06 deleted successfully.
ADS C:\ProgramData\TEMP:B54E4B5A deleted successfully.
ADS C:\ProgramData\TEMP:B1E64E47 deleted successfully.
ADS C:\ProgramData\TEMP:A6F28514 deleted successfully.
ADS C:\ProgramData\TEMP:91DEEE71 deleted successfully.
ADS C:\ProgramData\TEMP:8B4640AA deleted successfully.
ADS C:\ProgramData\TEMP:88FD3ED6 deleted successfully.
ADS C:\ProgramData\TEMP:864881BF deleted successfully.
ADS C:\ProgramData\TEMP:75798D9A deleted successfully.
ADS C:\ProgramData\TEMP:6DDD2723 deleted successfully.
ADS C:\ProgramData\TEMP:64D6413B deleted successfully.
ADS C:\ProgramData\TEMP:624A6897 deleted successfully.
ADS C:\ProgramData\TEMP:609CAC7C deleted successfully.
ADS C:\ProgramData\TEMP:5E73E1C2 deleted successfully.
ADS C:\ProgramData\TEMP:59465B40 deleted successfully.
ADS C:\ProgramData\TEMP:53B8C5D2 deleted successfully.
ADS C:\ProgramData\TEMP:4CC33C80 deleted successfully.
ADS C:\ProgramData\TEMP:471AD3D0 deleted successfully.
ADS C:\ProgramData\TEMP:3CA557DB deleted successfully.
ADS C:\ProgramData\TEMP:39DFF372 deleted successfully.
ADS C:\ProgramData\TEMP:36A39835 deleted successfully.
ADS C:\ProgramData\TEMP:31C9BA96 deleted successfully.
ADS C:\ProgramData\TEMP:30308E0E deleted successfully.
ADS C:\ProgramData\TEMP:1585E7B2 deleted successfully.
ADS C:\ProgramData\TEMP:14B2E0BD deleted successfully.
ADS C:\ProgramData\TEMP:1379054C deleted successfully.
ADS C:\ProgramData\TEMP:0FE0A03C deleted successfully.
ADS C:\ProgramData\TEMP:011B8910 deleted successfully.
ADS C:\ProgramData\TEMP:D80C94F4 deleted successfully.
ADS C:\ProgramData\TEMP:D5E0200E deleted successfully.
ADS C:\ProgramData\TEMP:D453E38B deleted successfully.
ADS C:\ProgramData\TEMP:C8033E19 deleted successfully.
ADS C:\ProgramData\TEMP:C0BCE04B deleted successfully.
ADS C:\ProgramData\TEMP:BEACE4C8 deleted successfully.
ADS C:\ProgramData\TEMP:B0456F0C deleted successfully.
ADS C:\ProgramData\TEMP:A9223B61 deleted successfully.
ADS C:\ProgramData\TEMP:977F2E85 deleted successfully.
ADS C:\ProgramData\TEMP:700B9342 deleted successfully.
ADS C:\ProgramData\TEMP:5D9FEC13 deleted successfully.
ADS C:\ProgramData\TEMP:3B59291C deleted successfully.
ADS C:\ProgramData\TEMP:39637387 deleted successfully.
ADS C:\ProgramData\TEMP:36CB2BB0 deleted successfully.
ADS C:\ProgramData\TEMP:32211F93 deleted successfully.
ADS C:\ProgramData\TEMP:10D45FC3 deleted successfully.
ADS C:\ProgramData\TEMP:0ACF1AF5 deleted successfully.
ADS C:\ProgramData\TEMP:E894A3ED deleted successfully.
ADS C:\ProgramData\TEMP:D999FFD5 deleted successfully.
ADS C:\ProgramData\TEMP:D9987109 deleted successfully.
ADS C:\ProgramData\TEMP:D01ACC06 deleted successfully.
ADS C:\ProgramData\TEMP:CADCEDF4 deleted successfully.
ADS C:\ProgramData\TEMP:C83D135D deleted successfully.
ADS C:\ProgramData\TEMP:C3AD9507 deleted successfully.
ADS C:\ProgramData\TEMP:BAFAD1DF deleted successfully.
ADS C:\ProgramData\TEMP:AB15E5CC deleted successfully.
ADS C:\ProgramData\TEMP:A4CB1038 deleted successfully.
ADS C:\ProgramData\TEMP:8678F6BD deleted successfully.
ADS C:\ProgramData\TEMP:73B78E79 deleted successfully.
ADS C:\ProgramData\TEMP:71AEFFEB deleted successfully.
ADS C:\ProgramData\TEMP:6017A808 deleted successfully.
ADS C:\ProgramData\TEMP:4465CF27 deleted successfully.
ADS C:\ProgramData\TEMP:3ED67A23 deleted successfully.
ADS C:\ProgramData\TEMP:29861223 deleted successfully.
ADS C:\ProgramData\TEMP:1416AAA6 deleted successfully.
ADS C:\ProgramData\TEMP:F585E6E5 deleted successfully.
ADS C:\ProgramData\TEMP:DCB1165A deleted successfully.
ADS C:\ProgramData\TEMP:DCA79AB3 deleted successfully.
ADS C:\ProgramData\TEMP:D9771F40 deleted successfully.
ADS C:\ProgramData\TEMP:D9656460 deleted successfully.
ADS C:\ProgramData\TEMP:D3B928B0 deleted successfully.
ADS C:\ProgramData\TEMP:C859F017 deleted successfully.
ADS C:\ProgramData\TEMP:A9339169 deleted successfully.
ADS C:\ProgramData\TEMP:A18D1A5B deleted successfully.
ADS C:\ProgramData\TEMP:927EC486 deleted successfully.
ADS C:\ProgramData\TEMP:905BCB57 deleted successfully.
ADS C:\ProgramData\TEMP:831F2C78 deleted successfully.
ADS C:\ProgramData\TEMP:52F4CBFF deleted successfully.
ADS C:\ProgramData\TEMP:4FA837B4 deleted successfully.
ADS C:\ProgramData\TEMP:2B856118 deleted successfully.
ADS C:\ProgramData\TEMP:1181620C deleted successfully.
ADS C:\ProgramData\TEMP:10CFA7D4 deleted successfully.
ADS C:\ProgramData\TEMP:02D1A2F4 deleted successfully.
ADS C:\ProgramData\TEMP:F3366735 deleted successfully.
ADS C:\ProgramData\TEMP:DD9FFC08 deleted successfully.
ADS C:\ProgramData\TEMP:D72D7897 deleted successfully.
ADS C:\ProgramData\TEMP:CAE777AD deleted successfully.
ADS C:\ProgramData\TEMP:94874C0A deleted successfully.
ADS C:\ProgramData\TEMP:93EC8514 deleted successfully.
ADS C:\ProgramData\TEMP:830267C4 deleted successfully.
ADS C:\ProgramData\TEMP:81980DF5 deleted successfully.
ADS C:\ProgramData\TEMP:7EC01D6D deleted successfully.
ADS C:\ProgramData\TEMP:769DE8D6 deleted successfully.
ADS C:\ProgramData\TEMP:6BFA43EB deleted successfully.
ADS C:\ProgramData\TEMP:6247E766 deleted successfully.
ADS C:\ProgramData\TEMP:2A51A8DF deleted successfully.
ADS C:\ProgramData\TEMP:2498D8A2 deleted successfully.
ADS C:\ProgramData\TEMP:04ADB7A6 deleted successfully.
ADS C:\ProgramData\TEMP:F26F5952 deleted successfully.
ADS C:\ProgramData\TEMP:BEE39E9B deleted successfully.
ADS C:\ProgramData\TEMP:BB1102D7 deleted successfully.
ADS C:\ProgramData\TEMP:B8EB1B99 deleted successfully.
ADS C:\ProgramData\TEMP:7BB20DE8 deleted successfully.
ADS C:\ProgramData\TEMP:63387B59 deleted successfully.
ADS C:\ProgramData\TEMP:424D7CFE deleted successfully.
ADS C:\ProgramData\TEMP:3651A580 deleted successfully.
ADS C:\ProgramData\TEMP:2B40A7DB deleted successfully.
ADS C:\ProgramData\TEMP:23834E1E deleted successfully.
ADS C:\ProgramData\TEMP:1CE25169 deleted successfully.
ADS C:\ProgramData\TEMP:0988A428 deleted successfully.
ADS C:\ProgramData\TEMP:063969F8 deleted successfully.
ADS C:\ProgramData\TEMP:FF9C44FE deleted successfully.
ADS C:\ProgramData\TEMP:EDD0DF13 deleted successfully.
ADS C:\ProgramData\TEMP:E83EE313 deleted successfully.
ADS C:\ProgramData\TEMP:E4AE7DC8 deleted successfully.
ADS C:\ProgramData\TEMP:C76CFF82 deleted successfully.
ADS C:\ProgramData\TEMP:C370B84F deleted successfully.
ADS C:\ProgramData\TEMP:B0C6C5CF deleted successfully.
ADS C:\ProgramData\TEMP:AABCC5A7 deleted successfully.
ADS C:\ProgramData\TEMP:A6D6E537 deleted successfully.
ADS C:\ProgramData\TEMP:9EE6560D deleted successfully.
ADS C:\ProgramData\TEMP:8DD20B4A deleted successfully.
ADS C:\ProgramData\TEMP:66871744 deleted successfully.
ADS C:\ProgramData\TEMP:3CAE2A70 deleted successfully.
ADS C:\ProgramData\TEMP:3AD6342E deleted successfully.
ADS C:\ProgramData\TEMP:2EB79F01 deleted successfully.
ADS C:\ProgramData\TEMP:2B4FA895 deleted successfully.
ADS C:\ProgramData\TEMP:26499772 deleted successfully.
ADS C:\ProgramData\TEMP:202CF111 deleted successfully.
ADS C:\ProgramData\TEMP:04BB186B deleted successfully.
ADS C:\ProgramData\TEMP:FB65A4AA deleted successfully.
ADS C:\ProgramData\TEMP:E6EC5C2A deleted successfully.
ADS C:\ProgramData\TEMP:CB299F13 deleted successfully.
ADS C:\ProgramData\TEMP:BE40C8A2 deleted successfully.
ADS C:\ProgramData\TEMP:B139DDF3 deleted successfully.
ADS C:\ProgramData\TEMP:AEC3F61D deleted successfully.
ADS C:\ProgramData\TEMP:A5584049 deleted successfully.
ADS C:\ProgramData\TEMP:9FC77097 deleted successfully.
ADS C:\ProgramData\TEMP:8FA03A6A deleted successfully.
ADS C:\ProgramData\TEMP:85B3C587 deleted successfully.
ADS C:\ProgramData\TEMP:823606DE deleted successfully.
ADS C:\ProgramData\TEMP:6FD36C4B deleted successfully.
ADS C:\ProgramData\TEMP:5BC73C48 deleted successfully.
ADS C:\ProgramData\TEMP:5B09C4D9 deleted successfully.
ADS C:\ProgramData\TEMP:24C072FF deleted successfully.
ADS C:\ProgramData\TEMP:20DF40C7 deleted successfully.
ADS C:\ProgramData\TEMP:D576A536 deleted successfully.
ADS C:\ProgramData\TEMP:C186F20B deleted successfully.
ADS C:\ProgramData\TEMP:A279C25A deleted successfully.
ADS C:\ProgramData\TEMP:A17CCD03 deleted successfully.
ADS C:\ProgramData\TEMP:9E05DEB0 deleted successfully.
ADS C:\ProgramData\TEMP:90108DD7 deleted successfully.
ADS C:\ProgramData\TEMP:839ADBB2 deleted successfully.
ADS C:\ProgramData\TEMP:824FDFA6 deleted successfully.
ADS C:\ProgramData\TEMP:81413F67 deleted successfully.
ADS C:\ProgramData\TEMP:79FD1F58 deleted successfully.
ADS C:\ProgramData\TEMP:5E8C18F1 deleted successfully.
ADS C:\ProgramData\TEMP:488F7244 deleted successfully.
ADS C:\ProgramData\TEMP:3C9B05C4 deleted successfully.
ADS C:\ProgramData\TEMP:397D67BA deleted successfully.
ADS C:\ProgramData\TEMP:39613F68 deleted successfully.
ADS C:\ProgramData\TEMP:34EFF1F2 deleted successfully.
ADS C:\ProgramData\TEMP:2729B5B9 deleted successfully.
ADS C:\ProgramData\TEMP:268BA8AB deleted successfully.
ADS C:\ProgramData\TEMP:247D483C deleted successfully.
ADS C:\ProgramData\TEMP:1DB77A89 deleted successfully.
ADS C:\ProgramData\TEMP:1968990D deleted successfully.
ADS C:\ProgramData\TEMP:11D3EBBB deleted successfully.
ADS C:\ProgramData\TEMP:F5D01D7C deleted successfully.
ADS C:\ProgramData\TEMP:D2397415 deleted successfully.
ADS C:\ProgramData\TEMP:BCFEA004 deleted successfully.
ADS C:\ProgramData\TEMP:B6E6C4EA deleted successfully.
ADS C:\ProgramData\TEMP:85376176 deleted successfully.
ADS C:\ProgramData\TEMP:834DD57E deleted successfully.
ADS C:\ProgramData\TEMP:79875988 deleted successfully.
ADS C:\ProgramData\TEMP:4726B04C deleted successfully.
ADS C:\ProgramData\TEMP:3EC1B848 deleted successfully.
ADS C:\ProgramData\TEMP:348A3734 deleted successfully.
ADS C:\ProgramData\TEMP:28819F45 deleted successfully.
ADS C:\ProgramData\TEMP:206470A5 deleted successfully.
ADS C:\ProgramData\TEMP:109734F6 deleted successfully.
ADS C:\ProgramData\TEMP:E2CFA9CD deleted successfully.
ADS C:\ProgramData\TEMP:E21433CE deleted successfully.
ADS C:\ProgramData\TEMP:D39B2133 deleted successfully.
ADS C:\ProgramData\TEMP:C36D0DFD deleted successfully.
ADS C:\ProgramData\TEMP:AE9351E0 deleted successfully.
ADS C:\ProgramData\TEMP:9B2BD056 deleted successfully.
ADS C:\ProgramData\TEMP:98982C88 deleted successfully.
ADS C:\ProgramData\TEMP:8836A712 deleted successfully.
ADS C:\ProgramData\TEMP:8204AA35 deleted successfully.
ADS C:\ProgramData\TEMP:701B92FB deleted successfully.
ADS C:\ProgramData\TEMP:65137F0D deleted successfully.
ADS C:\ProgramData\TEMP:5D10C56A deleted successfully.
ADS C:\ProgramData\TEMP:596E986D deleted successfully.
ADS C:\ProgramData\TEMP:57619D72 deleted successfully.
ADS C:\ProgramData\TEMP:5511B474 deleted successfully.
ADS C:\ProgramData\TEMP:4EA002DF deleted successfully.
ADS C:\ProgramData\TEMP:4A2862FF deleted successfully.
ADS C:\ProgramData\TEMP:2ADF9928 deleted successfully.
ADS C:\ProgramData\TEMP:2652902F deleted successfully.
ADS C:\ProgramData\TEMP:000D6A25 deleted successfully.
ADS C:\ProgramData\TEMP:DC0B1070 deleted successfully.
ADS C:\ProgramData\TEMP:DA7655EA deleted successfully.
ADS C:\ProgramData\TEMP:CBE042C1 deleted successfully.
ADS C:\ProgramData\TEMP:C6920A5D deleted successfully.
ADS C:\ProgramData\TEMP:C30487EE deleted successfully.
ADS C:\ProgramData\TEMP:9BAC4211 deleted successfully.
ADS C:\ProgramData\TEMP:9670EFE7 deleted successfully.
ADS C:\ProgramData\TEMP:962308D2 deleted successfully.
ADS C:\ProgramData\TEMP:9603033A deleted successfully.
ADS C:\ProgramData\TEMP:7E239580 deleted successfully.
ADS C:\ProgramData\TEMP:765C6A14 deleted successfully.
ADS C:\ProgramData\TEMP:73AFBB96 deleted successfully.
ADS C:\ProgramData\TEMP:6F690C1B deleted successfully.
ADS C:\ProgramData\TEMP:65B8AF94 deleted successfully.
ADS C:\ProgramData\TEMP:5A8F8A0C deleted successfully.
ADS C:\ProgramData\TEMP:4CD3F344 deleted successfully.
ADS C:\ProgramData\TEMP:4C31986D deleted successfully.
ADS C:\ProgramData\TEMP:41884BBE deleted successfully.
ADS C:\ProgramData\TEMP:39EFEA80 deleted successfully.
ADS C:\ProgramData\TEMP:3086B95F deleted successfully.
ADS C:\ProgramData\TEMP:12258D63 deleted successfully.
ADS C:\ProgramData\TEMP:0483BBEB deleted successfully.
ADS C:\ProgramData\TEMP:00AA4B31 deleted successfully.
ADS C:\ProgramData\TEMP:EE69D7DF deleted successfully.
ADS C:\ProgramData\TEMP:E0A09032 deleted successfully.
ADS C:\ProgramData\TEMP:CFF6B3FF deleted successfully.
ADS C:\ProgramData\TEMP:C22FB597 deleted successfully.
ADS C:\ProgramData\TEMP:AB422E00 deleted successfully.
ADS C:\ProgramData\TEMP:A8606E6E deleted successfully.
ADS C:\ProgramData\TEMP:A4E7D25F deleted successfully.
ADS C:\ProgramData\TEMP:A18FA397 deleted successfully.
ADS C:\ProgramData\TEMP:93F0301A deleted successfully.
ADS C:\ProgramData\TEMP:91DAFF12 deleted successfully.
ADS C:\ProgramData\TEMP:8BE7A048 deleted successfully.
ADS C:\ProgramData\TEMP:774A0E14 deleted successfully.
ADS C:\ProgramData\TEMP:697DDE2B deleted successfully.
ADS C:\ProgramData\TEMP:689AB7E9 deleted successfully.
ADS C:\ProgramData\TEMP:3DB6F365 deleted successfully.
ADS C:\ProgramData\TEMP:386B39C3 deleted successfully.
ADS C:\ProgramData\TEMP:378824DE deleted successfully.
ADS C:\ProgramData\TEMP:330B710D deleted successfully.
ADS C:\ProgramData\TEMP:14B884E8 deleted successfully.
ADS C:\ProgramData\TEMP:0D52F295 deleted successfully.
ADS C:\ProgramData\TEMP:073139EC deleted successfully.
ADS C:\ProgramData\TEMP:F164CEA1 deleted successfully.
ADS C:\ProgramData\TEMP:EC20549D deleted successfully.
ADS C:\ProgramData\TEMP:D9592966 deleted successfully.
ADS C:\ProgramData\TEMP:CDCDE97C deleted successfully.
ADS C:\ProgramData\TEMP:CA2C26FF deleted successfully.
ADS C:\ProgramData\TEMP:B1786630 deleted successfully.
ADS C:\ProgramData\TEMP:A5911AD8 deleted successfully.
ADS C:\ProgramData\TEMP:6837B088 deleted successfully.
ADS C:\ProgramData\TEMP:55DC0180 deleted successfully.
ADS C:\ProgramData\TEMP:26A148EB deleted successfully.
ADS C:\ProgramData\TEMP:1B389835 deleted successfully.
ADS C:\ProgramData\TEMP:13CDB0E0 deleted successfully.
ADS C:\ProgramData\TEMP:EE7AAC75 deleted successfully.
ADS C:\ProgramData\TEMP:EA9ACCA7 deleted successfully.
ADS C:\ProgramData\TEMP:C0913157 deleted successfully.
ADS C:\ProgramData\TEMP:AC8449E8 deleted successfully.
ADS C:\ProgramData\TEMP:A5264343 deleted successfully.
ADS C:\ProgramData\TEMP:857692EC deleted successfully.
ADS C:\ProgramData\TEMP:6EE5C3ED deleted successfully.
ADS C:\ProgramData\TEMP:6A0A47E7 deleted successfully.
ADS C:\ProgramData\TEMP:49508BCE deleted successfully.
ADS C:\ProgramData\TEMP:2E9900EE deleted successfully.
ADS C:\ProgramData\TEMP:29B37860 deleted successfully.
ADS C:\ProgramData\TEMP:27652001 deleted successfully.
ADS C:\ProgramData\TEMP:25BB767E deleted successfully.
ADS C:\ProgramData\TEMP:08927BEA deleted successfully.
ADS C:\ProgramData\TEMP:8DD36B71 deleted successfully.
ADS C:\ProgramData\TEMP:67CF910D deleted successfully.
ADS C:\ProgramData\TEMP:38D2EA83 deleted successfully.
ADS C:\ProgramData\TEMP:2D2461E7 deleted successfully.
ADS C:\ProgramData\TEMP:0968E571 deleted successfully.
ADS C:\ProgramData\TEMP:05F547A9 deleted successfully.
ADS C:\ProgramData\TEMP:E3615992 deleted successfully.
ADS C:\ProgramData\TEMP:BF6A2C54 deleted successfully.
ADS C:\ProgramData\TEMP:B3196E8D deleted successfully.
ADS C:\ProgramData\TEMP:A0CB43B2 deleted successfully.
ADS C:\ProgramData\TEMP:8BFA0030 deleted successfully.
ADS C:\ProgramData\TEMP:27974442 deleted successfully.
ADS C:\ProgramData\TEMP:1604D047 deleted successfully.
ADS C:\ProgramData\TEMP:ECF3C50F deleted successfully.
ADS C:\ProgramData\TEMP:C8182692 deleted successfully.
ADS C:\ProgramData\TEMP:AECF4772 deleted successfully.
ADS C:\ProgramData\TEMP:A688EF17 deleted successfully.
ADS C:\ProgramData\TEMP:86B7FDDB deleted successfully.
ADS C:\ProgramData\TEMP:68A56598 deleted successfully.
ADS C:\ProgramData\TEMP:6813E7F4 deleted successfully.
ADS C:\ProgramData\TEMP:63C29481 deleted successfully.
ADS C:\ProgramData\TEMP:512E1728 deleted successfully.
ADS C:\ProgramData\TEMP:4EFA2FC7 deleted successfully.
ADS C:\ProgramData\TEMP:14362DF8 deleted successfully.
ADS C:\ProgramData\TEMP:E0EBA003 deleted successfully.
ADS C:\ProgramData\TEMP:D882BE37 deleted successfully.
ADS C:\ProgramData\TEMP:A4241298 deleted successfully.
ADS C:\ProgramData\TEMP:A05F750A deleted successfully.
ADS C:\ProgramData\TEMP:9D03192E deleted successfully.
ADS C:\ProgramData\TEMP:8075370B deleted successfully.
ADS C:\ProgramData\TEMP:224B562C deleted successfully.
ADS C:\ProgramData\TEMP:07C99568 deleted successfully.
ADS C:\ProgramData\TEMP:02CC0035 deleted successfully.
ADS C:\ProgramData\TEMP:E690114B deleted successfully.
ADS C:\ProgramData\TEMP:DF0BC727 deleted successfully.
ADS C:\ProgramData\TEMP:15752405 deleted successfully.
ADS C:\ProgramData\TEMP:8247A199 deleted successfully.
ADS C:\ProgramData\TEMP:6BF0805F deleted successfully.
ADS C:\ProgramData\TEMP:5197985B deleted successfully.
ADS C:\ProgramData\TEMP:3D36932D deleted successfully.
ADS C:\ProgramData\TEMP:EB5BDBB0 deleted successfully.
ADS C:\ProgramData\TEMP:3595B780 deleted successfully.
ADS C:\ProgramData\TEMP:DBEF355E deleted successfully.
ADS C:\ProgramData\TEMP:95198126 deleted successfully.
ADS C:\ProgramData\TEMP:592D7272 deleted successfully.
ADS C:\ProgramData\TEMP:1ECED34B deleted successfully.
ADS C:\ProgramData\TEMP:28CDD861 deleted successfully.
ADS C:\ProgramData\TEMP:27C3CD07 deleted successfully.
ADS C:\ProgramData\TEMP:74091520 deleted successfully.
ADS C:\ProgramData\TEMP:45912F61 deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: Rebekka
->Temp folder emptied: 86824817 bytes
->Temporary Internet Files folder emptied: 1457676 bytes
->Java cache emptied: 3268950 bytes
->FireFox cache emptied: 1060571993 bytes
->Flash cache emptied: 5090 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1713808 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1068474 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67832 bytes
RecycleBin emptied: 3237973538 bytes
 
Total Files Cleaned = 4.189,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.36.3 log created on 03182012_175346

Files\Folders moved on Reboot...
File\Folder C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk not found!
File move failed. D:\Autorun.exe scheduled to be moved on reboot.
File move failed. D:\autorun.inf scheduled to be moved on reboot.
File move failed. D:\autorun.ini scheduled to be moved on reboot.
C:\Users\Rebekka\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...
         
ist jetzt wieder alles gut auf meinen Rechner?

Alt 19.03.2012, 15:44   #10
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Entfernen von Searchcore Toolbar und SpyHunter - Standard

Entfernen von Searchcore Toolbar und SpyHunter



Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Antwort

Themen zu Entfernen von Searchcore Toolbar und SpyHunter
deinstalliert, entferne, entfernen, foren, gestern, hallo zusammen, programme, schnell, searchcore, searchcore toolbar, spyhunter, systems, systemsteuerung, toolbar, verschiedene, verschiedenen, versuch, zusammen



Ähnliche Themen: Entfernen von Searchcore Toolbar und SpyHunter


  1. SpyHunter 4 entfernen
    Log-Analyse und Auswertung - 31.07.2015 (3)
  2. SpyHunter entfernen
    Log-Analyse und Auswertung - 02.05.2015 (11)
  3. Babylon toolbar entfernen, BrowserCompanion entfernen, DealPly entfernen, GinyasBrowserCompanions entfernen
    Log-Analyse und Auswertung - 17.12.2014 (9)
  4. Spyhunter entfernen
    Plagegeister aller Art und deren Bekämpfung - 13.09.2014 (15)
  5. Spyhunter 4 entfernen
    Plagegeister aller Art und deren Bekämpfung - 25.03.2014 (17)
  6. Spyhunter Entfernen
    Plagegeister aller Art und deren Bekämpfung - 25.03.2014 (12)
  7. Spyhunter entfernen
    Plagegeister aller Art und deren Bekämpfung - 19.11.2013 (25)
  8. Spyhunter entfernen
    Log-Analyse und Auswertung - 21.10.2013 (14)
  9. SpyHunter entfernen
    Log-Analyse und Auswertung - 22.06.2013 (7)
  10. SpyHunter entfernen
    Log-Analyse und Auswertung - 27.05.2013 (7)
  11. mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen?
    Log-Analyse und Auswertung - 08.05.2013 (8)
  12. Searchcore und mehr auf PC?
    Log-Analyse und Auswertung - 14.02.2013 (14)
  13. spyhunter 4 entfernen
    Plagegeister aller Art und deren Bekämpfung - 03.02.2013 (32)
  14. Searchcore erscheint immer wenn Firefox beendet wird.
    Plagegeister aller Art und deren Bekämpfung - 06.01.2013 (3)
  15. pdfforge und widgi toolbar, sowie SpyHunter entfernen?
    Log-Analyse und Auswertung - 04.09.2012 (1)
  16. Entfernung Searchcore Toolbar
    Plagegeister aller Art und deren Bekämpfung - 29.03.2012 (17)
  17. spyhunter, widgi toolbar, spigot....was tue ich am Besten?
    Plagegeister aller Art und deren Bekämpfung - 08.01.2012 (35)

Zum Thema Entfernen von Searchcore Toolbar und SpyHunter - Hallo zusammen, scheinbar habe ich mir gestern "Searchcore Toolbar" eingefangen. Beim versuch dies schnell zu entfernen bin ich auch noch auf "SpyHunter" reingefallen. Spyhunter habe ich über Systemsteuerung deinstalliert, habe - Entfernen von Searchcore Toolbar und SpyHunter...
Archiv
Du betrachtest: Entfernen von Searchcore Toolbar und SpyHunter auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.