Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Cyber Crime Investigation Department Österreich - Trojaner

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 10.09.2012, 16:06   #16
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Wieso von der falschen Seite?
Wir verlinken unsere Tools automatisch immer auf die richtige Seite!
Wenn du aus anderen Quellen lädst kannst du dir wieder Dreck, Toolbars oder richtig fiese Schädlinge einhandeln!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 10.09.2012, 16:38   #17
ChrisK7
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Ja ich weiß, nur habe ich den Link nicht gleich gefunden. Aber den zweiten Scanvorgang habe ich mit dem OTL gemacht, welches ihr bei eurer Anleitung verlinkt hattet. Mein Fehler!
__________________


Alt 10.09.2012, 20:08   #18
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:
ATTFilter
:OTL
FF - user.js - File not found
IE - HKU\S-1-5-21-2205288494-3300817759-3993977911-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.64.11:8080
O2 - BHO: (GMX Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3:64bit: - HKLM\..\Toolbar: (GMX Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Programme\GMX Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3 - HKLM\..\Toolbar: (GMX Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3:64bit: - HKU\S-1-5-21-2205288494-3300817759-3993977911-1000\..\Toolbar\WebBrowser: (GMX Toolbar) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Programme\GMX Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3 - HKU\S-1-5-21-2205288494-3300817759-3993977911-1000\..\Toolbar\WebBrowser: (GMX Toolbar) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O2:64bit: - BHO: (GMX Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Programme\GMX Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O4 - HKLM..\Run: []  File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{2bb5eef1-8255-11e1-b86f-4ceb42085989}\Shell - "" = AutoRun
O33 - MountPoints2\{2bb5eef1-8255-11e1-b86f-4ceb42085989}\Shell\AutoRun\command - "" = E:\.\Autorun.exe AUTORUN=1
O33 - MountPoints2\{741fdd7d-8252-11e1-84a7-4ceb42085989}\Shell - "" = AutoRun
O33 - MountPoints2\{741fdd7d-8252-11e1-84a7-4ceb42085989}\Shell\AutoRun\command - "" = E:\.\Autorun.exe AUTORUN=1
O33 - MountPoints2\{d0e7913b-b491-11e1-a55b-4ceb42085989}\Shell - "" = AutoRun
O33 - MountPoints2\{d0e7913b-b491-11e1-a55b-4ceb42085989}\Shell\AutoRun\command - "" = F:\.\Autorun.exe AUTORUN=1
:Files
C:\Users\Christian\AppData\Local\{*
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]
         
Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________
__________________

Alt 10.09.2012, 20:50   #19
ChrisK7
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Hab ich gemacht, hier das Scriptfile:

Code:
ATTFilter
All processes killed
========== OTL ==========
HKU\S-1-5-21-2205288494-3300817759-3993977911-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BF42D4A8-016E-4fcd-B1EB-837659FD77C6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BF42D4A8-016E-4fcd-B1EB-837659FD77C6}\ deleted successfully.
C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{C424171E-592A-415a-9EB1-DFD6D95D3530} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415a-9EB1-DFD6D95D3530}\ deleted successfully.
C:\Programme\GMX Toolbar\IE\uitb.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{C424171E-592A-415a-9EB1-DFD6D95D3530} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415a-9EB1-DFD6D95D3530}\ deleted successfully.
File C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll not found.
64bit-Registry value HKEY_USERS\S-1-5-21-2205288494-3300817759-3993977911-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C424171E-592A-415A-9EB1-DFD6D95D3530} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415A-9EB1-DFD6D95D3530}\ not found.
File C:\Programme\GMX Toolbar\IE\uitb.dll not found.
Registry value HKEY_USERS\S-1-5-21-2205288494-3300817759-3993977911-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C424171E-592A-415A-9EB1-DFD6D95D3530} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415A-9EB1-DFD6D95D3530}\ not found.
File C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll not found.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BF42D4A8-016E-4fcd-B1EB-837659FD77C6}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BF42D4A8-016E-4fcd-B1EB-837659FD77C6}\ deleted successfully.
File C:\Programme\GMX Toolbar\IE\uitb.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoControlPanel deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bb5eef1-8255-11e1-b86f-4ceb42085989}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2bb5eef1-8255-11e1-b86f-4ceb42085989}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bb5eef1-8255-11e1-b86f-4ceb42085989}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2bb5eef1-8255-11e1-b86f-4ceb42085989}\ not found.
File E:\.\Autorun.exe AUTORUN=1 not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{741fdd7d-8252-11e1-84a7-4ceb42085989}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{741fdd7d-8252-11e1-84a7-4ceb42085989}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{741fdd7d-8252-11e1-84a7-4ceb42085989}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{741fdd7d-8252-11e1-84a7-4ceb42085989}\ not found.
File E:\.\Autorun.exe AUTORUN=1 not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d0e7913b-b491-11e1-a55b-4ceb42085989}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d0e7913b-b491-11e1-a55b-4ceb42085989}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d0e7913b-b491-11e1-a55b-4ceb42085989}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d0e7913b-b491-11e1-a55b-4ceb42085989}\ not found.
File F:\.\Autorun.exe AUTORUN=1 not found.
========== FILES ==========
C:\Users\Christian\AppData\Local\{00A44926-69AE-429F-85DD-C185C3FEFDF5} folder moved successfully.
C:\Users\Christian\AppData\Local\{01AA8E6E-A061-45CF-BF4B-EFB5A9A81FA3} folder moved successfully.
C:\Users\Christian\AppData\Local\{028C1121-CDCA-479D-994C-49007FADBC08} folder moved successfully.
C:\Users\Christian\AppData\Local\{0293E9A7-7BF6-4899-9B8A-92E304CB837F} folder moved successfully.
C:\Users\Christian\AppData\Local\{02A9690E-6D83-4D57-AC69-DE392E6796EC} folder moved successfully.
C:\Users\Christian\AppData\Local\{02CB066A-02C8-4D75-9F78-E519A8F58B35} folder moved successfully.
C:\Users\Christian\AppData\Local\{032D2104-0342-4238-AB19-CF1306071BCC} folder moved successfully.
C:\Users\Christian\AppData\Local\{04D0F3CF-10FD-4950-9F43-FD7562C04339} folder moved successfully.
C:\Users\Christian\AppData\Local\{07E3312F-45A3-45B0-86BF-70065B6A687A} folder moved successfully.
C:\Users\Christian\AppData\Local\{08834E3D-CF11-4A99-91D9-77662D3394C8} folder moved successfully.
C:\Users\Christian\AppData\Local\{09E5DED4-1699-4DE9-9E18-33385CC08410} folder moved successfully.
C:\Users\Christian\AppData\Local\{0AB27FDF-F569-467B-96D4-9E272BA66504} folder moved successfully.
C:\Users\Christian\AppData\Local\{0BFF7C4E-6105-4051-A8EF-0CB1EC5FE91D} folder moved successfully.
C:\Users\Christian\AppData\Local\{0C17A292-9C75-4F07-9B8B-793B2852A0CF} folder moved successfully.
C:\Users\Christian\AppData\Local\{0C3008AA-C28C-42AC-8D5B-FDA7A24E2B27} folder moved successfully.
C:\Users\Christian\AppData\Local\{0DE9717A-732A-4369-994E-9D7493B90AFD} folder moved successfully.
C:\Users\Christian\AppData\Local\{0DF9657F-FCAC-4FDE-B348-73B14E88B4F7} folder moved successfully.
C:\Users\Christian\AppData\Local\{0F684264-B6D3-4AF8-B663-B20A14BA8B33} folder moved successfully.
C:\Users\Christian\AppData\Local\{1096DD4D-4298-491A-821F-BC995E8B6119} folder moved successfully.
C:\Users\Christian\AppData\Local\{10A65D41-CD32-4BBD-AF47-712B505C3F6E} folder moved successfully.
C:\Users\Christian\AppData\Local\{10BD7F28-0061-4835-8AAD-45BAFB9BC5EC} folder moved successfully.
C:\Users\Christian\AppData\Local\{10DFA9AA-9DD0-4864-BA14-42DCB271811F} folder moved successfully.
C:\Users\Christian\AppData\Local\{118B42CF-C9F1-4B81-899C-573B1EDA2652} folder moved successfully.
C:\Users\Christian\AppData\Local\{11A23F78-C90B-4829-B3CB-002079658114} folder moved successfully.
C:\Users\Christian\AppData\Local\{11E62DB1-6240-4A39-A347-EF2963CE288D} folder moved successfully.
C:\Users\Christian\AppData\Local\{12267774-6C1C-4916-99AB-DE0176E26A7B} folder moved successfully.
C:\Users\Christian\AppData\Local\{127D1D0C-2FE3-44A0-B734-A38CB3B3838F} folder moved successfully.
C:\Users\Christian\AppData\Local\{12F656B5-FCAF-439D-B022-734372DE38DF} folder moved successfully.
C:\Users\Christian\AppData\Local\{1308A159-595F-4BF0-9BBE-E3A8C5F7F103} folder moved successfully.
C:\Users\Christian\AppData\Local\{1406DB31-90AC-49BB-882B-D7BB34F7D251} folder moved successfully.
C:\Users\Christian\AppData\Local\{14EBD7E9-90DE-4A2D-8FCE-30C1CBD52E87} folder moved successfully.
C:\Users\Christian\AppData\Local\{1529CBC0-BB73-4E8D-9AD2-3B5B8B3713EF} folder moved successfully.
C:\Users\Christian\AppData\Local\{159F64C4-FDC9-40BF-8AAE-F0357861F313} folder moved successfully.
C:\Users\Christian\AppData\Local\{15A3C6CC-BB19-4AFF-866D-EF9BFBE97F53} folder moved successfully.
C:\Users\Christian\AppData\Local\{1602A8F1-984B-4FAE-8EB6-2B56D4CA297E} folder moved successfully.
C:\Users\Christian\AppData\Local\{173441B0-1E62-416F-8B0A-208D967397AF} folder moved successfully.
C:\Users\Christian\AppData\Local\{17E21239-7D38-483F-B19C-B7A80C5CA30E} folder moved successfully.
C:\Users\Christian\AppData\Local\{180CFE93-AA8C-4F38-A335-0BA1C487AE5D} folder moved successfully.
C:\Users\Christian\AppData\Local\{190756E5-051C-4CA6-984B-8886F4174740} folder moved successfully.
C:\Users\Christian\AppData\Local\{19AF43B0-CBD6-45D4-A8B7-48F8A3E34C94} folder moved successfully.
C:\Users\Christian\AppData\Local\{19EC3999-236B-4BE9-A6B0-36103D6F43DB} folder moved successfully.
C:\Users\Christian\AppData\Local\{1AF0FBC9-E476-47EB-88E9-B991AD0D9B18} folder moved successfully.
C:\Users\Christian\AppData\Local\{1B01E345-3182-4D93-B123-5A37BFC79335} folder moved successfully.
C:\Users\Christian\AppData\Local\{1B8B1F78-35B0-4DBC-91DB-3BC2512B9535} folder moved successfully.
C:\Users\Christian\AppData\Local\{1C405DB1-0D96-4301-A3FA-BD870BBC51D7} folder moved successfully.
C:\Users\Christian\AppData\Local\{1C472044-6013-4DC7-B157-DEBCB9229F69} folder moved successfully.
C:\Users\Christian\AppData\Local\{1C5C44B3-3940-4B70-A6F9-B3272E0D7DF4} folder moved successfully.
C:\Users\Christian\AppData\Local\{1DE4B513-811F-4B38-9834-493B9239D48B} folder moved successfully.
C:\Users\Christian\AppData\Local\{1E14E81A-F3C6-42FB-9DC2-05327C9557D7} folder moved successfully.
C:\Users\Christian\AppData\Local\{1EC1D225-4743-4F88-9F3E-699A1F07F219} folder moved successfully.
C:\Users\Christian\AppData\Local\{1EFF66C9-59C0-4428-9B46-91FB0FC95797} folder moved successfully.
C:\Users\Christian\AppData\Local\{1F1C765D-EFF2-462B-8CD1-D11F27BE6685} folder moved successfully.
C:\Users\Christian\AppData\Local\{1F576B3F-6677-417A-8A3C-0298BD21B6C5} folder moved successfully.
C:\Users\Christian\AppData\Local\{201A16B7-4C63-4E8D-8DE6-C15C482EE951} folder moved successfully.
C:\Users\Christian\AppData\Local\{2033091E-6159-422C-AE81-997FB1FF9551} folder moved successfully.
C:\Users\Christian\AppData\Local\{20627357-8450-470F-9A03-F33397E4CC43} folder moved successfully.
C:\Users\Christian\AppData\Local\{208D0712-4CCC-4360-978E-FA42FA8F8194} folder moved successfully.
C:\Users\Christian\AppData\Local\{2095252E-13AE-4F98-9CE6-0CBA75F525C9} folder moved successfully.
C:\Users\Christian\AppData\Local\{20FF5A40-C397-44FE-8F58-25081CF98DF4} folder moved successfully.
C:\Users\Christian\AppData\Local\{21529A7F-125C-4E8A-8887-64A8111973DB} folder moved successfully.
C:\Users\Christian\AppData\Local\{22E39B76-D2E5-483B-931F-CC6CB4305177} folder moved successfully.
C:\Users\Christian\AppData\Local\{231415C6-7F00-4478-8ABB-EA94FE5C93B3} folder moved successfully.
C:\Users\Christian\AppData\Local\{23420D90-BC5E-4381-B4BD-8E3078007E54} folder moved successfully.
C:\Users\Christian\AppData\Local\{2385D0E9-CC00-4669-9F6B-8DC9201233B7} folder moved successfully.
C:\Users\Christian\AppData\Local\{23ED0FBC-0827-4A22-8D46-CB027C174839} folder moved successfully.
C:\Users\Christian\AppData\Local\{24DF72E5-3218-4092-9460-E3AC6449F10E} folder moved successfully.
C:\Users\Christian\AppData\Local\{25273AFB-1A36-4198-8E94-1D706C2EA863} folder moved successfully.
C:\Users\Christian\AppData\Local\{2540AA2D-DB9B-469B-827C-C600DF0B5378} folder moved successfully.
C:\Users\Christian\AppData\Local\{25EE239A-1BAE-476B-B93B-8FE915F44BA0} folder moved successfully.
C:\Users\Christian\AppData\Local\{26C293AE-6B2E-40BB-9A52-8677DFF0DA73} folder moved successfully.
C:\Users\Christian\AppData\Local\{27476095-1334-48E7-8A05-0AA31198A381} folder moved successfully.
C:\Users\Christian\AppData\Local\{27DD53EE-B307-4B27-B4CE-3989DB139C8B} folder moved successfully.
C:\Users\Christian\AppData\Local\{28005A83-6BAA-4B14-8DA8-AF3946916CDA} folder moved successfully.
C:\Users\Christian\AppData\Local\{2817C09A-263D-4141-8C58-83350BD4A42F} folder moved successfully.
C:\Users\Christian\AppData\Local\{2853C147-86BA-4166-A8F2-E92FD7BBF7AE} folder moved successfully.
C:\Users\Christian\AppData\Local\{2AE3DE50-5606-4EF5-83DC-BCCBA1F67EFE} folder moved successfully.
C:\Users\Christian\AppData\Local\{2B1491DE-8687-4B07-A02B-359AD8D09B26} folder moved successfully.
C:\Users\Christian\AppData\Local\{2C54BF74-5BB0-408A-B56E-5285460D797D} folder moved successfully.
C:\Users\Christian\AppData\Local\{2C7FE6C3-823A-4698-BDA9-0981A36A3C89} folder moved successfully.
C:\Users\Christian\AppData\Local\{2C9B84A9-1A74-4A4F-84A3-6E99B43FB95C} folder moved successfully.
C:\Users\Christian\AppData\Local\{2CAE2C9A-CBC7-4BCC-A0DB-37848E9AAA5C} folder moved successfully.
C:\Users\Christian\AppData\Local\{2CFA1937-33F8-4580-873C-A114324679F8} folder moved successfully.
C:\Users\Christian\AppData\Local\{2D562BE3-CF91-423B-9C8C-37A4B8CA40F1} folder moved successfully.
C:\Users\Christian\AppData\Local\{2DB725E3-FE73-44E3-927B-04C2B7A6C07F} folder moved successfully.
C:\Users\Christian\AppData\Local\{2E775598-F21D-4069-8992-BFC803F4F89E} folder moved successfully.
C:\Users\Christian\AppData\Local\{2EAA65F9-C479-43F1-B5FE-39AF8C2CC94C} folder moved successfully.
C:\Users\Christian\AppData\Local\{2EB9266B-60A3-4E27-BABF-159EFC1DA737} folder moved successfully.
C:\Users\Christian\AppData\Local\{2F525FF9-3055-4ED0-AC86-E567C99B69AE} folder moved successfully.
C:\Users\Christian\AppData\Local\{2F780480-27ED-4D22-B580-D6E4B66B9EF7} folder moved successfully.
C:\Users\Christian\AppData\Local\{2FD67F77-A50B-4DB4-88D8-B4EF1D468D98} folder moved successfully.
C:\Users\Christian\AppData\Local\{31A0B7CD-C0AC-40E6-9379-2FFB759B43A7} folder moved successfully.
C:\Users\Christian\AppData\Local\{3265E914-F729-427B-9003-E0FE4840A29F} folder moved successfully.
C:\Users\Christian\AppData\Local\{3422DFB3-7B05-4112-9BA8-8F66BCC5EBD7} folder moved successfully.
C:\Users\Christian\AppData\Local\{3492E815-F9C7-4C02-8AAD-9CDA2FDEBB87} folder moved successfully.
C:\Users\Christian\AppData\Local\{355DF23E-8983-4264-A0F0-E29128153E65} folder moved successfully.
C:\Users\Christian\AppData\Local\{35982AC3-E455-4DCE-9352-D1164F1091E3} folder moved successfully.
C:\Users\Christian\AppData\Local\{36669D3D-E6B6-4E3E-9F56-8B0F9521F3F4} folder moved successfully.
C:\Users\Christian\AppData\Local\{36AF91DA-D291-4A39-B1A3-3F4892CF167C} folder moved successfully.
C:\Users\Christian\AppData\Local\{37106BE5-E780-4FBF-AD32-B7F2F131B660} folder moved successfully.
C:\Users\Christian\AppData\Local\{37DE023E-40A5-48A4-8B3C-201848278D62} folder moved successfully.
C:\Users\Christian\AppData\Local\{383A4D29-6067-47E9-A85A-11B3190FF062} folder moved successfully.
C:\Users\Christian\AppData\Local\{383C525B-8FFE-4136-A511-9B43559EB54A} folder moved successfully.
C:\Users\Christian\AppData\Local\{38626F7B-CCE7-43CB-9BCC-CE9A5FDD2031} folder moved successfully.
C:\Users\Christian\AppData\Local\{38ED4FF6-ED66-4566-A0AB-1D6806E7D1FC} folder moved successfully.
C:\Users\Christian\AppData\Local\{39142782-B914-42F3-AA5E-438BF9F3D02C} folder moved successfully.
C:\Users\Christian\AppData\Local\{3928B926-1782-4FAA-99EA-B4068CAB72FB} folder moved successfully.
C:\Users\Christian\AppData\Local\{3AB0FC81-114A-4FC2-84ED-E16075CAEF50} folder moved successfully.
C:\Users\Christian\AppData\Local\{3C1C870B-DB39-4F12-9434-BD3628C788CD} folder moved successfully.
C:\Users\Christian\AppData\Local\{3C602F47-6C98-4708-805B-25083F83DB40} folder moved successfully.
C:\Users\Christian\AppData\Local\{3C983C15-D670-49DD-B740-F401C409FFA2} folder moved successfully.
C:\Users\Christian\AppData\Local\{3CA81D8D-857C-45AC-85C5-B493471E6368} folder moved successfully.
C:\Users\Christian\AppData\Local\{3D2FFEB6-8418-47D1-AE50-41B56C60D539} folder moved successfully.
C:\Users\Christian\AppData\Local\{3DA4305B-0ABA-4420-B0A3-4040D5028A73} folder moved successfully.
C:\Users\Christian\AppData\Local\{3EAF06AB-B98C-49D3-8C5F-2CCA7061B6C0} folder moved successfully.
C:\Users\Christian\AppData\Local\{3EE9F8AE-BEC1-41F0-B8E3-216BF19E6C70} folder moved successfully.
C:\Users\Christian\AppData\Local\{3F291BE3-D220-4783-9EF9-68C1DB0C4892} folder moved successfully.
C:\Users\Christian\AppData\Local\{3F42549F-6968-4AA1-A113-7FB4825FC43C} folder moved successfully.
C:\Users\Christian\AppData\Local\{3FE69590-BE6D-4FC0-BEDC-CA26B5B22FE9} folder moved successfully.
C:\Users\Christian\AppData\Local\{3FF17456-15A2-4EEA-91EE-2B4E9DC6C068} folder moved successfully.
C:\Users\Christian\AppData\Local\{400A6C73-629B-4AA1-A486-5BE3C5AE6C9E} folder moved successfully.
C:\Users\Christian\AppData\Local\{404F46FF-E520-4023-939B-99284723A6EF} folder moved successfully.
C:\Users\Christian\AppData\Local\{424B7434-33DE-4182-B9FB-B574637582BD} folder moved successfully.
C:\Users\Christian\AppData\Local\{431B45E9-DBEC-4869-ABA8-5251677907F4} folder moved successfully.
C:\Users\Christian\AppData\Local\{4370ACD8-4E30-4A47-923A-1ABC2E65AE78} folder moved successfully.
C:\Users\Christian\AppData\Local\{43D66EF4-FEF1-4FA7-B2E7-EE9731B6AF86} folder moved successfully.
C:\Users\Christian\AppData\Local\{43E15F56-7811-4A0B-A999-B8D75C9957E7} folder moved successfully.
C:\Users\Christian\AppData\Local\{44B548CE-54C6-4A49-8C9E-5049CAF10503} folder moved successfully.
C:\Users\Christian\AppData\Local\{452A94FE-B7D8-4DE9-8260-98ADDCA80E78} folder moved successfully.
C:\Users\Christian\AppData\Local\{45E89EB7-5C0E-46E1-A413-02C68A2D653C} folder moved successfully.
C:\Users\Christian\AppData\Local\{46529E2E-00D1-4443-9B5C-DE6D8B7610F4} folder moved successfully.
C:\Users\Christian\AppData\Local\{479F0BA9-7991-46C4-B2CC-EFE8461101B2} folder moved successfully.
C:\Users\Christian\AppData\Local\{47C6576C-9A19-4C3C-B28E-5669B9F8D220} folder moved successfully.
C:\Users\Christian\AppData\Local\{47CF86C0-156A-43BC-98B0-6B07565154B4} folder moved successfully.
C:\Users\Christian\AppData\Local\{48B67BA0-641B-4375-878E-C02CB2067B8F} folder moved successfully.
C:\Users\Christian\AppData\Local\{491206A5-AE3A-408A-8BAB-1939A43ED807} folder moved successfully.
C:\Users\Christian\AppData\Local\{497F178D-938C-421A-B65F-CA3763F86558} folder moved successfully.
C:\Users\Christian\AppData\Local\{4993CF96-2AE3-4A13-BCC7-7BA42794A566} folder moved successfully.
C:\Users\Christian\AppData\Local\{4A8D8492-10DE-4194-A14A-DF58AB79E7D4} folder moved successfully.
C:\Users\Christian\AppData\Local\{4A90932E-E241-47C8-8F3F-A8A6602FDF23} folder moved successfully.
C:\Users\Christian\AppData\Local\{4B0CADFD-0160-4F27-B59B-75D68600F321} folder moved successfully.
C:\Users\Christian\AppData\Local\{4BB42B38-FAEB-40E9-ABB6-4BEE6AC0F5D0} folder moved successfully.
C:\Users\Christian\AppData\Local\{4CE3D797-5814-4869-B388-20C59EAAD49F} folder moved successfully.
C:\Users\Christian\AppData\Local\{4D65322F-1ABA-4F26-8222-C3AB989A7EC5} folder moved successfully.
C:\Users\Christian\AppData\Local\{4DD80D53-37B9-4839-835B-03C9385FAB8C} folder moved successfully.
C:\Users\Christian\AppData\Local\{4E093603-D170-4A8D-B1FF-BEF408DF4F92} folder moved successfully.
C:\Users\Christian\AppData\Local\{4E13E891-0249-4EB1-9892-1B3979514C27} folder moved successfully.
C:\Users\Christian\AppData\Local\{4E21E3CC-9B46-43D8-BE4E-6EBDFFEE660A} folder moved successfully.
C:\Users\Christian\AppData\Local\{4F46B9E1-2638-4824-B934-C084E1214F5E} folder moved successfully.
C:\Users\Christian\AppData\Local\{4FBE4DCC-8DA5-46E0-9E66-D5E0F7753555} folder moved successfully.
C:\Users\Christian\AppData\Local\{4FD4E571-C29B-4186-9399-E568F127F8E3} folder moved successfully.
C:\Users\Christian\AppData\Local\{50F7A330-E568-46F4-A077-775408B9DD43} folder moved successfully.
C:\Users\Christian\AppData\Local\{5179D117-1BCE-4F3A-A2A1-F430F3B48898} folder moved successfully.
C:\Users\Christian\AppData\Local\{5215B37B-F575-4777-8707-25237C95116E} folder moved successfully.
C:\Users\Christian\AppData\Local\{52513D19-0518-4387-9D2F-6A5A8B444B4C} folder moved successfully.
C:\Users\Christian\AppData\Local\{5285938A-1DE5-45F7-AA1D-27BB652D7CA4} folder moved successfully.
C:\Users\Christian\AppData\Local\{52DF4FFA-6CDE-4612-865B-60AD2C13225B} folder moved successfully.
C:\Users\Christian\AppData\Local\{52E95032-C866-43DB-89B2-DA7D6D4191C8} folder moved successfully.
C:\Users\Christian\AppData\Local\{5304CC19-7D73-45F2-8926-5ACA9E8B49DC} folder moved successfully.
C:\Users\Christian\AppData\Local\{53B0D2B3-1F37-4340-91A1-991B495D1996} folder moved successfully.
C:\Users\Christian\AppData\Local\{53FF9FD8-3DB7-4179-ADA0-9E8F66CC5F21} folder moved successfully.
C:\Users\Christian\AppData\Local\{5451155E-4F4F-486D-81F7-664C04E1BD8F} folder moved successfully.
C:\Users\Christian\AppData\Local\{54EC0B34-2BE6-49FB-83F0-657D5FAEB3FC} folder moved successfully.
C:\Users\Christian\AppData\Local\{55CE4324-C015-4A4E-9B86-8E3C15E736B9} folder moved successfully.
C:\Users\Christian\AppData\Local\{55DD86E9-654B-4C81-876A-885C28C59565} folder moved successfully.
C:\Users\Christian\AppData\Local\{55F001EF-1AF7-47B0-B5C8-5603E899D347} folder moved successfully.
C:\Users\Christian\AppData\Local\{56793849-4B8C-43E8-8464-AD40D8E110A6} folder moved successfully.
C:\Users\Christian\AppData\Local\{56994CF6-9449-4D44-BF15-0531EDECD847} folder moved successfully.
C:\Users\Christian\AppData\Local\{5747BD3C-2A43-4108-AEB2-67883FABA55C} folder moved successfully.
C:\Users\Christian\AppData\Local\{57C5E922-686E-44E9-A0E0-9289460564D3} folder moved successfully.
C:\Users\Christian\AppData\Local\{5975BB0B-EC98-4711-81F8-C3CA636CBAEE} folder moved successfully.
C:\Users\Christian\AppData\Local\{5AD3DA3E-CFBB-456F-853C-5B7DB0EAB03D} folder moved successfully.
C:\Users\Christian\AppData\Local\{5B42770D-121C-41B1-8DB9-51203ECEBDC0} folder moved successfully.
C:\Users\Christian\AppData\Local\{5D8C9100-5A17-44BA-9EDA-57C8FB4E6F6F} folder moved successfully.
C:\Users\Christian\AppData\Local\{5E77F598-5FB1-466F-BB2F-01128D852099} folder moved successfully.
C:\Users\Christian\AppData\Local\{5E8799AF-9C39-41AC-998B-E0B837B32BE1} folder moved successfully.
C:\Users\Christian\AppData\Local\{5EBB2684-B4AD-47CE-98E9-EAEE2BF1EE9E} folder moved successfully.
C:\Users\Christian\AppData\Local\{5EF77CF4-FA9E-4EB5-AA25-4A8F7A2A77DD} folder moved successfully.
C:\Users\Christian\AppData\Local\{5FB246AD-30A1-40AC-AA4E-B38EEBE0604C} folder moved successfully.
C:\Users\Christian\AppData\Local\{605F125C-713A-42CC-BEAE-6EF749AE96BE} folder moved successfully.
C:\Users\Christian\AppData\Local\{609CAC23-8641-4712-89C9-2A79B716A49C} folder moved successfully.
C:\Users\Christian\AppData\Local\{60E00F28-E035-425F-81E6-7E182AD173C2} folder moved successfully.
C:\Users\Christian\AppData\Local\{6189E825-EFCB-4D51-A0D6-20FBAE4816AB} folder moved successfully.
C:\Users\Christian\AppData\Local\{6191BE32-96D3-4BBD-A32D-AA7414311492} folder moved successfully.
C:\Users\Christian\AppData\Local\{61EAF557-B477-478A-A8B1-7799A969D10B} folder moved successfully.
C:\Users\Christian\AppData\Local\{61F67918-07D7-40C0-A700-3A58DA45B04E} folder moved successfully.
C:\Users\Christian\AppData\Local\{623A2F05-5A04-4A9E-BF7C-D65E93EABB21} folder moved successfully.
C:\Users\Christian\AppData\Local\{6252E9A6-7109-4135-8E09-F150CE826BBB} folder moved successfully.
C:\Users\Christian\AppData\Local\{62D761BC-12E6-43A6-93CF-58E43A197092} folder moved successfully.
C:\Users\Christian\AppData\Local\{635CF4B6-FC87-4DFE-9B4B-6A39B9B160F1} folder moved successfully.
C:\Users\Christian\AppData\Local\{63603236-3B7A-43D5-B3F0-CE57CECFCACF} folder moved successfully.
C:\Users\Christian\AppData\Local\{6363A9EF-620D-4D6E-81D6-84700453FCE1} folder moved successfully.
C:\Users\Christian\AppData\Local\{65A5AC65-9221-4D8D-891A-3265440F5C01} folder moved successfully.
C:\Users\Christian\AppData\Local\{66B698B7-CC3C-4AD9-AF3D-72E3636105DB} folder moved successfully.
C:\Users\Christian\AppData\Local\{67A67CCF-0D61-4CFC-ACC7-5F4BB8A44E67} folder moved successfully.
C:\Users\Christian\AppData\Local\{67DC27A9-7FB3-4039-9C5B-CC0E83D4B281} folder moved successfully.
C:\Users\Christian\AppData\Local\{67FEC91D-6207-4F8E-A8F1-34F80B0A505C} folder moved successfully.
C:\Users\Christian\AppData\Local\{68B1BC93-94B7-498A-B161-6527E7377783} folder moved successfully.
C:\Users\Christian\AppData\Local\{6976EB37-71F6-4165-B704-E020E3244E99} folder moved successfully.
C:\Users\Christian\AppData\Local\{69AB1A04-BA6A-4F21-8F10-E1407AAC092A} folder moved successfully.
C:\Users\Christian\AppData\Local\{69DA50D6-340A-4BAC-BFA2-FB643BD682BC} folder moved successfully.
C:\Users\Christian\AppData\Local\{69F24DDC-1E98-403C-92E9-59C051207593} folder moved successfully.
C:\Users\Christian\AppData\Local\{6A2475FD-BF91-4C86-A956-C58211774907} folder moved successfully.
C:\Users\Christian\AppData\Local\{6AE2C6B2-CFFB-46D8-AFDC-D63519065346} folder moved successfully.
C:\Users\Christian\AppData\Local\{6B0F60C1-80D1-4F4B-8B2B-735203E3C90D} folder moved successfully.
C:\Users\Christian\AppData\Local\{6BC7C52B-D6F6-44A8-B3C8-F720DA0C2618} folder moved successfully.
C:\Users\Christian\AppData\Local\{6C2E3ED0-B2E8-43D4-83C3-544E2CFADF50} folder moved successfully.
C:\Users\Christian\AppData\Local\{6C5560A8-B1EB-40E6-BD56-CBFC53E28AAD} folder moved successfully.
C:\Users\Christian\AppData\Local\{6C639A83-9250-483A-BA90-55206250C7AE} folder moved successfully.
C:\Users\Christian\AppData\Local\{6CFA5FCD-EBE8-4C71-8235-F91C4125F89C} folder moved successfully.
C:\Users\Christian\AppData\Local\{6D16E651-C6ED-4899-924A-CCB2E8E57CF5} folder moved successfully.
C:\Users\Christian\AppData\Local\{6E268235-6A0E-4B97-B27D-D03667C94726} folder moved successfully.
C:\Users\Christian\AppData\Local\{6F736609-1E89-4781-A028-06C378CC895A} folder moved successfully.
C:\Users\Christian\AppData\Local\{6FDAB261-40D1-4D50-95F1-D527855EE980} folder moved successfully.
C:\Users\Christian\AppData\Local\{7000DFE7-C664-414F-8A96-2719B1831CC2} folder moved successfully.
C:\Users\Christian\AppData\Local\{705E48CD-926A-4A11-AB5E-B3A1398F55A4} folder moved successfully.
C:\Users\Christian\AppData\Local\{70843C38-C6A5-4F0D-9E71-F3912EAA11C7} folder moved successfully.
C:\Users\Christian\AppData\Local\{70AD62E2-C62E-4B63-83D1-D801A799E64E} folder moved successfully.
C:\Users\Christian\AppData\Local\{71716551-583E-4188-9C1E-056A83A905B3} folder moved successfully.
C:\Users\Christian\AppData\Local\{71D4F41E-EDB3-440A-96BA-A5881047BC6E} folder moved successfully.
C:\Users\Christian\AppData\Local\{727ACD79-606A-4E20-B844-F651528605F6} folder moved successfully.
C:\Users\Christian\AppData\Local\{72C128B9-283D-4833-B2A3-737A0C2E724B} folder moved successfully.
C:\Users\Christian\AppData\Local\{731AA607-CA4D-4439-91C6-0B6517DB69AD} folder moved successfully.
C:\Users\Christian\AppData\Local\{739481A4-2332-4E94-B4EA-6419B00A0933} folder moved successfully.
C:\Users\Christian\AppData\Local\{73954663-D5A3-4BAB-BC0F-2D1DBF245228} folder moved successfully.
C:\Users\Christian\AppData\Local\{74653C8E-D80C-4DF9-8A28-F024D3604310} folder moved successfully.
C:\Users\Christian\AppData\Local\{74B2630E-EE6E-4818-B280-13C8E3D13D00} folder moved successfully.
C:\Users\Christian\AppData\Local\{74F794D9-86FA-4692-8DFD-29EC4A9D688E} folder moved successfully.
C:\Users\Christian\AppData\Local\{7544A7B0-49A8-4B75-B827-DCB1D819D393} folder moved successfully.
C:\Users\Christian\AppData\Local\{75EA96A1-DE0F-4449-92A6-F64398B59A49} folder moved successfully.
C:\Users\Christian\AppData\Local\{7609DD1E-6B84-49F7-A22C-DF6FB8972177} folder moved successfully.
C:\Users\Christian\AppData\Local\{778D2745-F4BF-4C83-B207-28B26EF9D56C} folder moved successfully.
C:\Users\Christian\AppData\Local\{784A58AC-A16A-4B13-812B-AB96C500A127} folder moved successfully.
C:\Users\Christian\AppData\Local\{78585DEF-1173-43DC-8EEB-A90195EEEF51} folder moved successfully.
C:\Users\Christian\AppData\Local\{78D6031E-6144-45A5-8608-DA2784C256B1} folder moved successfully.
C:\Users\Christian\AppData\Local\{7921DD2B-231D-46BA-AA8B-3A93053C7528} folder moved successfully.
C:\Users\Christian\AppData\Local\{795C9094-DE2A-46EC-9FC6-046247E2E65E} folder moved successfully.
C:\Users\Christian\AppData\Local\{79FC11BD-8CD1-4A8C-8F18-5A9A9B89E760} folder moved successfully.
C:\Users\Christian\AppData\Local\{7A3CAC8C-22B7-4C50-90E8-48582CC995F9} folder moved successfully.
C:\Users\Christian\AppData\Local\{7A98BD34-A04A-42B4-9B4D-20773B236079} folder moved successfully.
C:\Users\Christian\AppData\Local\{7AEDECE0-D4AC-43B8-9634-9EBBE185FF58} folder moved successfully.
C:\Users\Christian\AppData\Local\{7B988E60-93ED-4966-8540-4B64D9CCC953} folder moved successfully.
C:\Users\Christian\AppData\Local\{7C6179D6-CFBD-4CA5-A3AB-48B6662BE1FB} folder moved successfully.
C:\Users\Christian\AppData\Local\{7D14AEEC-3F7E-4F9A-8D32-38FD04F21C1C} folder moved successfully.
C:\Users\Christian\AppData\Local\{7DEE4D08-A68D-4998-9BF6-5FF3DDADC03C} folder moved successfully.
C:\Users\Christian\AppData\Local\{7ECA1A7A-69D4-460B-BD20-BEC6779FF28F} folder moved successfully.
C:\Users\Christian\AppData\Local\{7F7E3A9A-F94C-43F3-BA36-94681191FD81} folder moved successfully.
C:\Users\Christian\AppData\Local\{7F858720-0527-49F4-AF4A-69CB58B40229} folder moved successfully.
C:\Users\Christian\AppData\Local\{7FCCE8EB-0143-4678-8A68-44D44A754DB6} folder moved successfully.
C:\Users\Christian\AppData\Local\{80603FE1-16E1-4F98-AAAB-8576B216A0B1} folder moved successfully.
C:\Users\Christian\AppData\Local\{8157E372-6ACA-4A12-9DC6-978ED649FEFA} folder moved successfully.
C:\Users\Christian\AppData\Local\{821BE524-45D1-4C00-8D35-F6F6AA8D2D01} folder moved successfully.
C:\Users\Christian\AppData\Local\{826FFF15-2636-4853-BEE8-D2E048F17214} folder moved successfully.
C:\Users\Christian\AppData\Local\{82A5D821-9DE9-44E6-8C1B-FDCE996BF233} folder moved successfully.
C:\Users\Christian\AppData\Local\{843AF0B8-2BC3-4EA4-9E48-0F5515B194CA} folder moved successfully.
C:\Users\Christian\AppData\Local\{85BA4183-A65F-460D-9152-9CD8144DD044} folder moved successfully.
C:\Users\Christian\AppData\Local\{864FA1F2-2C14-4993-98C3-8322FDF93A12} folder moved successfully.
C:\Users\Christian\AppData\Local\{8703D913-A391-4BB8-A1F5-70755D96A3D6} folder moved successfully.
C:\Users\Christian\AppData\Local\{87C23FAB-7196-452B-B8A2-84BD2F1F9E09} folder moved successfully.
C:\Users\Christian\AppData\Local\{87E43272-841D-480C-999F-261CB79BE236} folder moved successfully.
C:\Users\Christian\AppData\Local\{87E60E83-4EF1-4DAF-AA1E-4A09D3066D4F} folder moved successfully.
C:\Users\Christian\AppData\Local\{87E66B1F-3D5E-4B27-8092-B0F6BC640CA1} folder moved successfully.
C:\Users\Christian\AppData\Local\{892FBE49-C9BF-4341-94FA-60F6678ED68B} folder moved successfully.
C:\Users\Christian\AppData\Local\{8957DC13-7FEE-42C3-9A02-5C078F619FD3} folder moved successfully.
C:\Users\Christian\AppData\Local\{899DBC9C-234E-4749-A515-24A8283BA730} folder moved successfully.
C:\Users\Christian\AppData\Local\{89B6F162-8583-4610-B242-3486DBFED677} folder moved successfully.
C:\Users\Christian\AppData\Local\{89C6D2BF-3CEA-4CEB-83EB-881D3900CEDC} folder moved successfully.
C:\Users\Christian\AppData\Local\{8A815043-01D8-44E4-9A6E-B6A5AF72724B} folder moved successfully.
C:\Users\Christian\AppData\Local\{8AD0EC45-09DA-4F64-A65B-A510BAC85629} folder moved successfully.
C:\Users\Christian\AppData\Local\{8B0A64A2-0C34-40BE-94AD-3FFC2608771B} folder moved successfully.
C:\Users\Christian\AppData\Local\{8B4617B7-7333-4DF3-BFF6-FDC0BAEC074D} folder moved successfully.
C:\Users\Christian\AppData\Local\{8C4F6575-213F-4964-BF5B-7B0BB487C71E} folder moved successfully.
C:\Users\Christian\AppData\Local\{8CE94E5F-83E6-4B5A-84F2-546BEFC9F691} folder moved successfully.
C:\Users\Christian\AppData\Local\{8D2FBF1E-B916-4091-ACDE-17EA2BE7CAA4} folder moved successfully.
C:\Users\Christian\AppData\Local\{8D5552D6-FE47-416D-95E1-EE787427F182} folder moved successfully.
C:\Users\Christian\AppData\Local\{8EC00B5B-C2A6-4138-AD03-B688861DE295} folder moved successfully.
C:\Users\Christian\AppData\Local\{8F490C40-6793-4657-AF08-AA6200AB3553} folder moved successfully.
C:\Users\Christian\AppData\Local\{8F5C276E-4351-45C5-B1B3-721B94F95004} folder moved successfully.
C:\Users\Christian\AppData\Local\{8FBC612C-C969-460A-B7A8-579346C2D436} folder moved successfully.
C:\Users\Christian\AppData\Local\{9180285F-673D-4022-A0F8-935ECEFAE47E} folder moved successfully.
C:\Users\Christian\AppData\Local\{91C26A63-5082-424A-8BA3-FDBCD1BF9C92} folder moved successfully.
C:\Users\Christian\AppData\Local\{924B8327-F424-4A3C-B19F-E9D53B308772} folder moved successfully.
C:\Users\Christian\AppData\Local\{939D3138-BCE9-4A09-A274-37213455C708} folder moved successfully.
C:\Users\Christian\AppData\Local\{93DB8A72-429E-4EBF-AC65-674A7E0AD900} folder moved successfully.
C:\Users\Christian\AppData\Local\{955E8EAF-509D-461F-967C-82113C0FFD96} folder moved successfully.
C:\Users\Christian\AppData\Local\{95BA3EF9-FA6D-4879-A0ED-5C2F94B1D3DB} folder moved successfully.
C:\Users\Christian\AppData\Local\{987AF278-1063-47F0-BB60-9D4D6591A909} folder moved successfully.
C:\Users\Christian\AppData\Local\{9A587A8F-DB85-476E-B5E4-7669D6E76F1D} folder moved successfully.
C:\Users\Christian\AppData\Local\{9A94926F-EE5B-4C2D-9F76-899302EDC3EF} folder moved successfully.
C:\Users\Christian\AppData\Local\{9BA287F6-18EB-43B9-B5ED-C55CC3AA0A45} folder moved successfully.
C:\Users\Christian\AppData\Local\{9CD46CAD-128B-4328-A649-8FE2E40F7A75} folder moved successfully.
C:\Users\Christian\AppData\Local\{9CFDC041-7A5D-48B0-AD3E-F6B0973CEE5A} folder moved successfully.
C:\Users\Christian\AppData\Local\{9D5A472F-E79F-4070-93B4-767B1480EA72} folder moved successfully.
C:\Users\Christian\AppData\Local\{9D88E92D-8A95-4DC6-B07C-9B8296B64191} folder moved successfully.
C:\Users\Christian\AppData\Local\{9D8A9A35-F460-472D-A5B6-6814139FAE6A} folder moved successfully.
C:\Users\Christian\AppData\Local\{9DA4F222-1312-428A-AC46-479BAB552B70} folder moved successfully.
C:\Users\Christian\AppData\Local\{9F0AC725-AFBD-40B3-92F4-65185ECDC706} folder moved successfully.
C:\Users\Christian\AppData\Local\{9F45DF2D-E976-49CE-B36E-8783D5BAA461} folder moved successfully.
C:\Users\Christian\AppData\Local\{9F49CB41-F4FD-4086-819C-6594F8271ADF} folder moved successfully.
C:\Users\Christian\AppData\Local\{9F7BED0A-68CD-4E1D-B857-D9B136EA8425} folder moved successfully.
C:\Users\Christian\AppData\Local\{A027B344-8BA7-4434-87C6-8EA07BA4166B} folder moved successfully.
C:\Users\Christian\AppData\Local\{A030E5DA-27E0-44D3-9E1B-E378B73E05FC} folder moved successfully.
C:\Users\Christian\AppData\Local\{A0446503-AC7F-4E60-8DA0-E5AB0C60AF86} folder moved successfully.
C:\Users\Christian\AppData\Local\{A075BA28-A738-43CD-B327-04EF2F73B85C} folder moved successfully.
C:\Users\Christian\AppData\Local\{A1FEA2AC-81A8-46F9-B7E5-89204FFCE2CD} folder moved successfully.
C:\Users\Christian\AppData\Local\{A22AC089-F5E5-4961-AE06-D3D5627214E9} folder moved successfully.
C:\Users\Christian\AppData\Local\{A28D8996-1885-4D71-9DE9-7F5B8CCFAED9} folder moved successfully.
C:\Users\Christian\AppData\Local\{A338E0DA-1221-4E2D-8D55-4A0D1A7F0AE5} folder moved successfully.
C:\Users\Christian\AppData\Local\{A34DF641-86BB-4CDC-A63D-2FC4F7929000} folder moved successfully.
C:\Users\Christian\AppData\Local\{A4216F3D-3602-45A5-9F83-34FDFC655145} folder moved successfully.
C:\Users\Christian\AppData\Local\{A488A60D-EE1E-432B-A9D6-373B1EBD37A6} folder moved successfully.
C:\Users\Christian\AppData\Local\{A4BAF7A1-FF51-409B-B5E9-BE13D216D329} folder moved successfully.
C:\Users\Christian\AppData\Local\{A52EE70E-0870-4D99-8626-6E43F5D7530D} folder moved successfully.
C:\Users\Christian\AppData\Local\{A5903261-5458-4133-913F-61D6BF89D69A} folder moved successfully.
C:\Users\Christian\AppData\Local\{A5B4CE67-947D-4F26-806E-4D9F9CF4A7BE} folder moved successfully.
C:\Users\Christian\AppData\Local\{A6041317-CD3F-4794-9334-A566B474E509} folder moved successfully.
C:\Users\Christian\AppData\Local\{A68AF949-3C59-4AE5-86E5-B6A76AED14A3} folder moved successfully.
C:\Users\Christian\AppData\Local\{A7615695-BC51-4168-8637-DDE54938AE32} folder moved successfully.
C:\Users\Christian\AppData\Local\{A784577F-AC5A-4CC7-9ABA-FC131EC63897} folder moved successfully.
C:\Users\Christian\AppData\Local\{A7B291F6-5BD4-400A-88D5-A41D80722156} folder moved successfully.
C:\Users\Christian\AppData\Local\{A8D34D08-1032-466D-9E63-9AF92F86C096} folder moved successfully.
C:\Users\Christian\AppData\Local\{ABA3555C-5E72-4ABA-B850-2477CA13A568} folder moved successfully.
C:\Users\Christian\AppData\Local\{AC9EE3FF-C099-4AB1-B65B-FC0E66D3587D} folder moved successfully.
C:\Users\Christian\AppData\Local\{AE7E3699-471B-47B7-B8F2-41018E334861} folder moved successfully.
C:\Users\Christian\AppData\Local\{AEB7DBEF-D1C4-4F93-A789-0C4063532FFA} folder moved successfully.
C:\Users\Christian\AppData\Local\{AF18D99F-2049-4996-834E-3CE252216295} folder moved successfully.
C:\Users\Christian\AppData\Local\{AF64B89C-0014-4037-88B2-C995B41918D3} folder moved successfully.
C:\Users\Christian\AppData\Local\{B08925F2-C000-46B5-A521-51A2A66553A2} folder moved successfully.
C:\Users\Christian\AppData\Local\{B0C144B4-8EB0-4F6B-9032-3563A137D62D} folder moved successfully.
C:\Users\Christian\AppData\Local\{B189967C-344B-4500-A359-998B5C4E815F} folder moved successfully.
C:\Users\Christian\AppData\Local\{B26F7D92-1332-4242-B8AC-1686DC49023D} folder moved successfully.
C:\Users\Christian\AppData\Local\{B33B433A-C4A8-4CBE-9CCA-FBC1FC8D7182} folder moved successfully.
C:\Users\Christian\AppData\Local\{B3803599-D42E-47BD-A70B-8D5C608E1ADB} folder moved successfully.
C:\Users\Christian\AppData\Local\{B3942FD2-4E72-4C75-B90B-563CA7C2902D} folder moved successfully.
C:\Users\Christian\AppData\Local\{B3DAE13F-1481-43DD-AE04-9D3F907C7696} folder moved successfully.
C:\Users\Christian\AppData\Local\{B51A90B3-4453-435F-BA43-A832482116D0} folder moved successfully.
C:\Users\Christian\AppData\Local\{B559A07C-593D-40AF-B8AF-CB63318EF7B6} folder moved successfully.
C:\Users\Christian\AppData\Local\{B58A63B1-9ED8-47E7-AB52-4EA713A4F7CE} folder moved successfully.
C:\Users\Christian\AppData\Local\{B5A5B607-497F-4A5A-98EA-CAD64F7CA391} folder moved successfully.
C:\Users\Christian\AppData\Local\{B5B96551-514A-452F-8154-48D63F274130} folder moved successfully.
C:\Users\Christian\AppData\Local\{B5CA66DD-3177-460D-9ACB-2D21A25380E8} folder moved successfully.
C:\Users\Christian\AppData\Local\{B5F017E4-244F-4F88-82F7-394C3AF01647} folder moved successfully.
C:\Users\Christian\AppData\Local\{B6448FA4-2DAD-47AD-A47E-A3D22D1C6CB6} folder moved successfully.
C:\Users\Christian\AppData\Local\{B6ACE21E-C62E-4A8B-865C-E75005417074} folder moved successfully.
C:\Users\Christian\AppData\Local\{B7341C8D-5277-4ECD-8061-CC86A0507D69} folder moved successfully.
C:\Users\Christian\AppData\Local\{B82AE506-21FF-42C0-97BB-3BC965D9C399} folder moved successfully.
C:\Users\Christian\AppData\Local\{B837D1F5-B1AE-45FE-A800-14536021E072} folder moved successfully.
C:\Users\Christian\AppData\Local\{B86B1F68-3CB5-47A6-B1ED-CB75AE056A03} folder moved successfully.
C:\Users\Christian\AppData\Local\{B8BE0A8E-A379-4115-8B1F-A772AAF2AB48} folder moved successfully.
C:\Users\Christian\AppData\Local\{B926DAFE-EC82-4351-9C3F-3CCB45611858} folder moved successfully.
C:\Users\Christian\AppData\Local\{B9CC6527-06BC-42A5-9788-9247273E5803} folder moved successfully.
C:\Users\Christian\AppData\Local\{B9EF8720-CB1C-496A-A93E-F03193E088BE} folder moved successfully.
C:\Users\Christian\AppData\Local\{BA90F085-59D1-4C0F-B4FE-0CEB50392492} folder moved successfully.
C:\Users\Christian\AppData\Local\{BA9103A0-9833-4002-BFFE-4418245412FF} folder moved successfully.
C:\Users\Christian\AppData\Local\{BC12877A-2C1B-4C00-9182-634E05E31688} folder moved successfully.
C:\Users\Christian\AppData\Local\{BD513A21-2A09-4D58-BE88-F3406FB80734} folder moved successfully.
C:\Users\Christian\AppData\Local\{BE054F1F-0AC9-42F3-B34E-99D726BBC938} folder moved successfully.
C:\Users\Christian\AppData\Local\{BE983905-E248-4022-B86D-3D629D4CF13F} folder moved successfully.
C:\Users\Christian\AppData\Local\{BED3D764-C0AC-4B48-9232-E04A111B2AD6} folder moved successfully.
C:\Users\Christian\AppData\Local\{BF1E253E-41BA-4A49-B851-C9B887355612} folder moved successfully.
C:\Users\Christian\AppData\Local\{BF716A51-4A8B-4A8C-A830-D1BEDD235ED2} folder moved successfully.
C:\Users\Christian\AppData\Local\{BF882416-3C44-4FB1-9932-91FDCC302568} folder moved successfully.
C:\Users\Christian\AppData\Local\{BFBB3EA2-5693-465B-A295-D58CDFE5E511} folder moved successfully.
C:\Users\Christian\AppData\Local\{C025FD74-6225-4830-B742-3CFAA6EB361C} folder moved successfully.
C:\Users\Christian\AppData\Local\{C13F1101-DAE0-4F61-8403-0313796F74FB} folder moved successfully.
C:\Users\Christian\AppData\Local\{C1587E16-1AB8-4034-A5A4-1BC558DEF612} folder moved successfully.
C:\Users\Christian\AppData\Local\{C190F3E7-C3DC-4937-867B-DE91B1A95DAD} folder moved successfully.
C:\Users\Christian\AppData\Local\{C1A7B417-CBA1-468F-A81B-A73D79A26E4B} folder moved successfully.
C:\Users\Christian\AppData\Local\{C246FFFB-9C76-4F7E-8AEE-B420CA6C94C7} folder moved successfully.
C:\Users\Christian\AppData\Local\{C2828847-142F-4631-9868-56618AD39B0F} folder moved successfully.
C:\Users\Christian\AppData\Local\{C2B8E1FF-A6E9-49AA-93BA-31826A58D51F} folder moved successfully.
C:\Users\Christian\AppData\Local\{C2BB8914-2992-4337-9D12-0B9568F63136} folder moved successfully.
C:\Users\Christian\AppData\Local\{C3838E36-A33B-4D17-BC0B-B874B275518D} folder moved successfully.
C:\Users\Christian\AppData\Local\{C3A58C96-C7BB-469A-9691-42DD63AAA9A9} folder moved successfully.
C:\Users\Christian\AppData\Local\{C3D7CF15-F070-404B-B223-C2639DFF3934} folder moved successfully.
C:\Users\Christian\AppData\Local\{C4FF3CFD-CBCB-4DDF-A552-8A22F3E4B5B8} folder moved successfully.
C:\Users\Christian\AppData\Local\{C63601A6-D7C1-4372-B9B6-91EA36B9B197} folder moved successfully.
C:\Users\Christian\AppData\Local\{C717AE84-CF02-4129-963E-89B8AC45C590} folder moved successfully.
C:\Users\Christian\AppData\Local\{C73ED8A0-2C6E-48BB-8929-8BCC030F7920} folder moved successfully.
C:\Users\Christian\AppData\Local\{C828485D-EAC3-417F-A0B0-FBDF02D11641} folder moved successfully.
C:\Users\Christian\AppData\Local\{C832D298-B460-435D-BFB9-0F34888DE884} folder moved successfully.
C:\Users\Christian\AppData\Local\{C853C760-11B7-440A-B89F-47A18B22A8E9} folder moved successfully.
C:\Users\Christian\AppData\Local\{C87F46E0-B1E7-4C90-B7F9-F4E49F8346B1} folder moved successfully.
C:\Users\Christian\AppData\Local\{C8CC4423-F8DE-44E8-9EA7-29EAD0D39F31} folder moved successfully.
C:\Users\Christian\AppData\Local\{C8E2190D-F5A3-478C-8D56-4E17E2521218} folder moved successfully.
C:\Users\Christian\AppData\Local\{C8EEED1A-5524-4C21-9187-70E4AFD56674} folder moved successfully.
C:\Users\Christian\AppData\Local\{C9E20A22-AB5B-4FF3-81DE-47CAD5F19127} folder moved successfully.
C:\Users\Christian\AppData\Local\{CCF6C34B-9BA0-410E-91B1-8981AAF9F743} folder moved successfully.
C:\Users\Christian\AppData\Local\{CD4C5DF1-88B2-4D3D-8092-205E63A0C12B} folder moved successfully.
C:\Users\Christian\AppData\Local\{CD56B37A-B051-43F4-BA15-E19AC53A6A0C} folder moved successfully.
C:\Users\Christian\AppData\Local\{CDBA5185-E0D7-45E9-BCF5-E5A15F503954} folder moved successfully.
C:\Users\Christian\AppData\Local\{CE2DA560-A606-4379-83A2-88BDAB574AE9} folder moved successfully.
C:\Users\Christian\AppData\Local\{CF7951FC-B386-48BF-AF7D-8EFA00848A8F} folder moved successfully.
C:\Users\Christian\AppData\Local\{CFCBC6FD-872C-4EEC-9BC4-2BA07CC69853} folder moved successfully.
C:\Users\Christian\AppData\Local\{CFD38B6F-FE17-43C9-A7CF-C9949D7B5740} folder moved successfully.
C:\Users\Christian\AppData\Local\{D0F12E09-4958-492D-844F-27C59F1CFD97} folder moved successfully.
C:\Users\Christian\AppData\Local\{D1CEED03-1D73-4860-B87E-A56F3EB51FAF} folder moved successfully.
C:\Users\Christian\AppData\Local\{D2F949EB-15BC-46AE-8FDA-2394542FBC80} folder moved successfully.
C:\Users\Christian\AppData\Local\{D32AE833-5B33-43FA-9BFF-F9F39EF1ACAD} folder moved successfully.
C:\Users\Christian\AppData\Local\{D351AACF-B814-46FF-858A-E359AE37A544} folder moved successfully.
C:\Users\Christian\AppData\Local\{D392A9AC-BB2F-44B3-8F9E-DCC42D729B42} folder moved successfully.
C:\Users\Christian\AppData\Local\{D3F346B3-852B-4EB3-8776-F2A175D35771} folder moved successfully.
C:\Users\Christian\AppData\Local\{D4C99F68-34B3-4B0B-85A1-D737DC265BD0} folder moved successfully.
C:\Users\Christian\AppData\Local\{D4D33A6B-8F79-45B0-9752-71BD0BE427C1} folder moved successfully.
C:\Users\Christian\AppData\Local\{D5289D44-BC3F-487A-B50E-70B19B9142C7} folder moved successfully.
C:\Users\Christian\AppData\Local\{D58B6324-612C-48C3-ADF1-2EA1DB96E5E3} folder moved successfully.
C:\Users\Christian\AppData\Local\{D5950A37-89A5-43A3-B1CF-095119F0C6D1} folder moved successfully.
C:\Users\Christian\AppData\Local\{D5FEFCD8-39B2-4E03-B47F-2A521F8D0C8A} folder moved successfully.
C:\Users\Christian\AppData\Local\{D67B3056-742C-4F50-860D-F685A4CAC712} folder moved successfully.
C:\Users\Christian\AppData\Local\{D77C9A5B-8337-482B-96E8-F7F19B011302} folder moved successfully.
C:\Users\Christian\AppData\Local\{D7E0A694-0EE3-43F8-9270-2EDFC65A4AE7} folder moved successfully.
C:\Users\Christian\AppData\Local\{D8611D9B-C433-4288-BF21-8F9E15FB9453} folder moved successfully.
C:\Users\Christian\AppData\Local\{D8660A8E-0BCF-463C-867E-63A512E47EA1} folder moved successfully.
C:\Users\Christian\AppData\Local\{D8D4157A-61E6-4065-9203-31E9B9F8A53C} folder moved successfully.
C:\Users\Christian\AppData\Local\{D8F48545-4544-4794-A5A6-63B839BA2723} folder moved successfully.
C:\Users\Christian\AppData\Local\{D9628E2E-C9D8-48EA-A719-C8D6909A51E6} folder moved successfully.
C:\Users\Christian\AppData\Local\{D9B811D4-A54E-404E-B34D-E8EF13E9566B} folder moved successfully.
C:\Users\Christian\AppData\Local\{D9EA72E1-2B25-4597-880D-F071191F97BB} folder moved successfully.
C:\Users\Christian\AppData\Local\{DA9130EA-B013-4E6B-BCE9-BAFA2BC7B0AF} folder moved successfully.
C:\Users\Christian\AppData\Local\{DB26D550-FDD3-4F99-AD74-EFA985B32130} folder moved successfully.
C:\Users\Christian\AppData\Local\{DBC9DD2F-AE6A-4BBF-871F-B7D8A3FBBCC6} folder moved successfully.
C:\Users\Christian\AppData\Local\{DC784CEA-C5F7-4DD5-98C5-752053972509} folder moved successfully.
C:\Users\Christian\AppData\Local\{DCD13A33-E3DA-400C-A5DB-B7A008C494EE} folder moved successfully.
C:\Users\Christian\AppData\Local\{DD6360BC-EA82-4FDC-86C7-5C29A2F56DD7} folder moved successfully.
C:\Users\Christian\AppData\Local\{DE3FF879-671B-4710-A319-0E9E26633801} folder moved successfully.
C:\Users\Christian\AppData\Local\{DE930E47-2241-4D3A-A43E-873471536B6D} folder moved successfully.
C:\Users\Christian\AppData\Local\{DEF44407-D912-4FDF-8C88-B9FF2F56293C} folder moved successfully.
C:\Users\Christian\AppData\Local\{DFDE7001-1F6A-4DBC-84EA-77C4D85719A4} folder moved successfully.
C:\Users\Christian\AppData\Local\{E0870B80-D3F0-4D8D-8DFB-1BD1B8FEF59A} folder moved successfully.
C:\Users\Christian\AppData\Local\{E1403B31-7636-44F8-9DD9-FD6B1020E45B} folder moved successfully.
C:\Users\Christian\AppData\Local\{E150C20B-9AC0-4695-9C9B-3026A65AD33F} folder moved successfully.
C:\Users\Christian\AppData\Local\{E17A4A4C-A6D4-4000-BEDA-08DB1EB5F44E} folder moved successfully.
C:\Users\Christian\AppData\Local\{E1ED2B89-ACEE-498E-9488-20A91DF817D3} folder moved successfully.
C:\Users\Christian\AppData\Local\{E254D801-A31E-4F3D-8A5C-438CB482B23D} folder moved successfully.
C:\Users\Christian\AppData\Local\{E2793FF7-A854-4E82-B1F8-42D201C018AD} folder moved successfully.
C:\Users\Christian\AppData\Local\{E2ABB98F-B765-40FA-8C4D-1B991D07A49A} folder moved successfully.
C:\Users\Christian\AppData\Local\{E2F8AC9C-1A82-4625-8F2B-059EA3ED4CF2} folder moved successfully.
C:\Users\Christian\AppData\Local\{E3EB01A8-6DF9-4F88-97E5-F99AE2299D22} folder moved successfully.
C:\Users\Christian\AppData\Local\{E43DFFC2-C4A6-4144-9354-085AE754B059} folder moved successfully.
C:\Users\Christian\AppData\Local\{E46D71AD-4419-4415-BD65-4A85F24DA720} folder moved successfully.
C:\Users\Christian\AppData\Local\{E56A46FC-EB33-45B1-A710-7B6718C15B4F} folder moved successfully.
C:\Users\Christian\AppData\Local\{E6226C86-27FB-4C70-9331-986FADFB4265} folder moved successfully.
C:\Users\Christian\AppData\Local\{E6281AE8-3D13-40A8-BECE-F0204F21BAC1} folder moved successfully.
C:\Users\Christian\AppData\Local\{E655C10F-69C6-4C95-9B0E-BDD5F4E55468} folder moved successfully.
C:\Users\Christian\AppData\Local\{E76B8994-DEE4-4A76-B08E-5C8160303876} folder moved successfully.
C:\Users\Christian\AppData\Local\{E7952C05-24E1-46FB-8365-912E89DCEF18} folder moved successfully.
C:\Users\Christian\AppData\Local\{E88AC612-3CC1-43F7-99BF-B9BC96ACB376} folder moved successfully.
C:\Users\Christian\AppData\Local\{E88DBC9B-5A31-4FC2-AD32-4D80DF611D44} folder moved successfully.
C:\Users\Christian\AppData\Local\{E8C6269F-C2D9-4AF3-9195-BE58A50C8547} folder moved successfully.
C:\Users\Christian\AppData\Local\{EAC78821-5968-4C99-98ED-FC01580AF51F} folder moved successfully.
C:\Users\Christian\AppData\Local\{EBB3F83F-BB55-4068-A830-812AB19BF35C} folder moved successfully.
C:\Users\Christian\AppData\Local\{EC022B39-1792-41ED-99A9-A87BAC8E4FF1} folder moved successfully.
C:\Users\Christian\AppData\Local\{EC6C3211-6CDE-4A45-A1F9-97F90AF9D2DB} folder moved successfully.
C:\Users\Christian\AppData\Local\{ED28FC12-76E3-4D67-804E-BB1C27D47C46} folder moved successfully.
C:\Users\Christian\AppData\Local\{ED2A820D-617F-4864-B412-E621A5B6528C} folder moved successfully.
C:\Users\Christian\AppData\Local\{ED98DA83-2D83-4C73-A3FC-4C69EE1CE526} folder moved successfully.
C:\Users\Christian\AppData\Local\{EE13D55D-1511-46B2-8CA3-465FC087813B} folder moved successfully.
C:\Users\Christian\AppData\Local\{EE16D0A0-BD66-4586-8819-37075E358308} folder moved successfully.
C:\Users\Christian\AppData\Local\{EECB199F-ABA8-4B06-9B11-44303A64B2DE} folder moved successfully.
C:\Users\Christian\AppData\Local\{EF869C9B-0272-484F-8FBE-28AB64E68AB8} folder moved successfully.
C:\Users\Christian\AppData\Local\{F0327F5A-D5A7-4192-B9B5-BFA02460D1C4} folder moved successfully.
C:\Users\Christian\AppData\Local\{F0B1D3EB-8EC7-4A48-A131-8724090F910E} folder moved successfully.
C:\Users\Christian\AppData\Local\{F0BCB514-0B42-482D-A95A-E918981DD76F} folder moved successfully.
C:\Users\Christian\AppData\Local\{F22AF967-EA74-42CC-A786-14CE0045C694} folder moved successfully.
C:\Users\Christian\AppData\Local\{F262040E-09F2-45DC-A36A-922B779D92EE} folder moved successfully.
C:\Users\Christian\AppData\Local\{F2CEA5DA-83A3-455B-ADC5-B6C4BD962128} folder moved successfully.
C:\Users\Christian\AppData\Local\{F37475E6-8CF8-41A6-92BC-8F26C45FCA74} folder moved successfully.
C:\Users\Christian\AppData\Local\{F3A565B1-A132-461F-B84A-C56F5BCBCC08} folder moved successfully.
C:\Users\Christian\AppData\Local\{F3AE7132-A49C-4698-9E9F-028D75AF0E53} folder moved successfully.
C:\Users\Christian\AppData\Local\{F4447EAA-24AC-454F-A201-25070B392EB8} folder moved successfully.
C:\Users\Christian\AppData\Local\{F4457611-2266-49A2-BED4-0553E0332B42} folder moved successfully.
C:\Users\Christian\AppData\Local\{F490A84D-1B9B-463D-92F3-84298C50167F} folder moved successfully.
C:\Users\Christian\AppData\Local\{F545AA3D-56D2-4CA1-86C5-E972202D5FF8} folder moved successfully.
C:\Users\Christian\AppData\Local\{F647B220-8327-4A63-AB04-8273533E1BBD} folder moved successfully.
C:\Users\Christian\AppData\Local\{F66DA19E-4010-4D56-8199-104AB7104EBD} folder moved successfully.
C:\Users\Christian\AppData\Local\{F6E2CCD9-CC9E-4597-83E2-08C8F0D25635} folder moved successfully.
C:\Users\Christian\AppData\Local\{F7025C39-DD92-4BC2-A47C-575AC97752DA} folder moved successfully.
C:\Users\Christian\AppData\Local\{F72D20EF-1C59-457A-9FB1-62C3606F1B8B} folder moved successfully.
C:\Users\Christian\AppData\Local\{F73191AF-D0A8-45B1-BD09-325D71D6688A} folder moved successfully.
C:\Users\Christian\AppData\Local\{F8243C51-1A9B-454A-8B60-05B3378E3380} folder moved successfully.
C:\Users\Christian\AppData\Local\{F8865FF6-A34E-46D1-A8EE-F35475CDB4C7} folder moved successfully.
C:\Users\Christian\AppData\Local\{FA1C1ADF-2D12-43CE-8DE3-EF06F0131E43} folder moved successfully.
C:\Users\Christian\AppData\Local\{FA3EF43D-FF38-4911-8305-F19A552BA2B1} folder moved successfully.
C:\Users\Christian\AppData\Local\{FB2EF0A0-F027-4FEC-8DCD-73AEDBC89829} folder moved successfully.
C:\Users\Christian\AppData\Local\{FBFA1D70-6352-4ED7-897C-485CEAB65606} folder moved successfully.
C:\Users\Christian\AppData\Local\{FC0BD9BE-59BA-4932-B9E9-8E743F72A1A3} folder moved successfully.
C:\Users\Christian\AppData\Local\{FCD81F10-C237-485F-82A4-22A80F531523} folder moved successfully.
C:\Users\Christian\AppData\Local\{FCF292AC-9AC8-4B2F-B571-A0EB945000A7} folder moved successfully.
C:\Users\Christian\AppData\Local\{FEA4B26B-F362-4F18-9472-482DA393A5D8} folder moved successfully.
C:\Users\Christian\AppData\Local\{FF6A934D-0DA3-435E-8ED4-2C94818133FA} folder moved successfully.
C:\Users\Christian\AppData\Local\{FF6B2C73-B698-4167-886E-C8B6DDFE0682} folder moved successfully.
C:\Users\Christian\AppData\Local\{FFD2C7BC-4A60-4412-A95B-A61F426FD048} folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\splash folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Users\Christian\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Christian\Desktop\cmd.bat deleted successfully.
C:\Users\Christian\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Christian
->Temp folder emptied: 1464766596 bytes
->Temporary Internet Files folder emptied: 2120910516 bytes
->FireFox cache emptied: 633733936 bytes
->Flash cache emptied: 50011 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: UpdatusUser
 
User: UpdatusUser.Christian-PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 389691976 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes
RecycleBin emptied: 110177128 bytes
 
Total Files Cleaned = 4.501,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.61.3 log created on 09102012_214105

Files\Folders moved on Reboot...
C:\Users\Christian\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Windows\temp\mcafee_yRlx5QOmKorl9gU not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
         

Alt 10.09.2012, 22:03   #20
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!


__________________
Logfiles bitte immer in CODE-Tags posten

Alt 11.09.2012, 14:23   #21
ChrisK7
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Hier das Log vom TDSS-Killer:

Code:
ATTFilter
15:20:16.0946 5156  TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
15:20:17.0121 5156  ============================================================
15:20:17.0121 5156  Current date / time: 2012/09/11 15:20:17.0121
15:20:17.0121 5156  SystemInfo:
15:20:17.0121 5156  
15:20:17.0121 5156  OS Version: 6.1.7601 ServicePack: 1.0
15:20:17.0121 5156  Product type: Workstation
15:20:17.0121 5156  ComputerName: CHRISTIAN-PC
15:20:17.0121 5156  UserName: Christian
15:20:17.0121 5156  Windows directory: C:\Windows
15:20:17.0121 5156  System windows directory: C:\Windows
15:20:17.0121 5156  Running under WOW64
15:20:17.0121 5156  Processor architecture: Intel x64
15:20:17.0121 5156  Number of processors: 8
15:20:17.0121 5156  Page size: 0x1000
15:20:17.0121 5156  Boot type: Normal boot
15:20:17.0121 5156  ============================================================
15:20:17.0677 5156  Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:20:17.0697 5156  ============================================================
15:20:17.0697 5156  \Device\Harddisk0\DR0:
15:20:17.0697 5156  MBR partitions:
15:20:17.0697 5156  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x34000, BlocksNum 0x2710000
15:20:17.0697 5156  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x2744000, BlocksNum 0x54E01EF0
15:20:17.0697 5156  ============================================================
15:20:17.0729 5156  C: <-> \Device\Harddisk0\DR0\Partition2
15:20:17.0730 5156  ============================================================
15:20:17.0730 5156  Initialize success
15:20:17.0730 5156  ============================================================
15:20:57.0149 7604  ============================================================
15:20:57.0149 7604  Scan started
15:20:57.0149 7604  Mode: Manual; SigCheck; TDLFS; 
15:20:57.0149 7604  ============================================================
15:21:00.0470 7604  ================ Scan system memory ========================
15:21:00.0470 7604  System memory - ok
15:21:00.0471 7604  ================ Scan services =============================
15:21:02.0207 7604  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
15:21:02.0290 7604  1394ohci - ok
15:21:02.0372 7604  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
15:21:02.0409 7604  ACPI - ok
15:21:02.0569 7604  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
15:21:02.0889 7604  AcpiPmi - ok
15:21:03.0393 7604  [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
15:21:03.0408 7604  AdobeARMservice - ok
15:21:03.0531 7604  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys
15:21:03.0549 7604  adp94xx - ok
15:21:03.0648 7604  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci         C:\Windows\system32\drivers\adpahci.sys
15:21:03.0664 7604  adpahci - ok
15:21:03.0749 7604  [ E109549C90F62FB570B9540C4B148E54 ] adpu320         C:\Windows\system32\drivers\adpu320.sys
15:21:03.0765 7604  adpu320 - ok
15:21:03.0886 7604  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
15:21:05.0526 7604  AeLookupSvc - ok
15:21:05.0868 7604  [ D1E343BC00136CE03C4D403194D06A80 ] AERTFilters     C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
15:21:05.0879 7604  AERTFilters - ok
15:21:05.0963 7604  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD             C:\Windows\system32\drivers\afd.sys
15:21:06.0075 7604  AFD - ok
15:21:06.0313 7604  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows\system32\drivers\agp440.sys
15:21:06.0325 7604  agp440 - ok
15:21:06.0373 7604  [ 3290D6946B5E30E70414990574883DDB ] ALG             C:\Windows\System32\alg.exe
15:21:06.0492 7604  ALG - ok
15:21:06.0568 7604  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows\system32\drivers\aliide.sys
15:21:06.0583 7604  aliide - ok
15:21:06.0609 7604  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows\system32\drivers\amdide.sys
15:21:06.0626 7604  amdide - ok
15:21:06.0864 7604  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8           C:\Windows\system32\drivers\amdk8.sys
15:21:06.0969 7604  AmdK8 - ok
15:21:06.0988 7604  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
15:21:07.0020 7604  AmdPPM - ok
15:21:07.0090 7604  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
15:21:07.0101 7604  amdsata - ok
15:21:07.0151 7604  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
15:21:07.0164 7604  amdsbs - ok
15:21:07.0183 7604  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
15:21:07.0192 7604  amdxata - ok
15:21:07.0321 7604  [ 89A69C3F2F319B43379399547526D952 ] AppID           C:\Windows\system32\drivers\appid.sys
15:21:09.0244 7604  AppID - ok
15:21:09.0335 7604  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
15:21:09.0385 7604  AppIDSvc - ok
15:21:09.0455 7604  [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo         C:\Windows\System32\appinfo.dll
15:21:09.0515 7604  Appinfo - ok
15:21:09.0603 7604  [ F401929EE0CC92BFE7F15161CA535383 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
15:21:09.0654 7604  Apple Mobile Device - ok
15:21:09.0770 7604  [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt         C:\Windows\System32\appmgmts.dll
15:21:09.0819 7604  AppMgmt - ok
15:21:09.0883 7604  [ C484F8CEB1717C540242531DB7845C4E ] arc             C:\Windows\system32\drivers\arc.sys
15:21:09.0894 7604  arc - ok
15:21:09.0931 7604  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows\system32\drivers\arcsas.sys
15:21:09.0942 7604  arcsas - ok
15:21:10.0032 7604  [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
15:21:10.0170 7604  aspnet_state - ok
15:21:10.0189 7604  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
15:21:10.0234 7604  AsyncMac - ok
15:21:10.0276 7604  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi           C:\Windows\system32\drivers\atapi.sys
15:21:10.0285 7604  atapi - ok
15:21:10.0519 7604  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
15:21:10.0584 7604  AudioEndpointBuilder - ok
15:21:10.0602 7604  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
15:21:10.0635 7604  AudioSrv - ok
15:21:10.0650 7604  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\Windows\System32\AxInstSV.dll
15:21:10.0717 7604  AxInstSV - ok
15:21:10.0747 7604  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv         C:\Windows\system32\drivers\bxvbda.sys
15:21:10.0783 7604  b06bdrv - ok
15:21:10.0889 7604  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
15:21:10.0947 7604  b57nd60a - ok
15:21:11.0021 7604  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows\System32\bdesvc.dll
15:21:11.0100 7604  BDESVC - ok
15:21:11.0148 7604  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
15:21:11.0196 7604  Beep - ok
15:21:11.0231 7604  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE             C:\Windows\System32\bfe.dll
15:21:11.0283 7604  BFE - ok
15:21:11.0312 7604  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\Windows\System32\qmgr.dll
15:21:11.0369 7604  BITS - ok
15:21:11.0391 7604  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
15:21:11.0414 7604  blbdrive - ok
15:21:11.0612 7604  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
15:21:11.0624 7604  Bonjour Service - ok
15:21:11.0722 7604  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
15:21:11.0745 7604  bowser - ok
15:21:11.0778 7604  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
15:21:11.0798 7604  BrFiltLo - ok
15:21:11.0812 7604  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
15:21:11.0825 7604  BrFiltUp - ok
15:21:11.0865 7604  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser         C:\Windows\System32\browser.dll
15:21:11.0898 7604  Browser - ok
15:21:11.0911 7604  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
15:21:11.0964 7604  Brserid - ok
15:21:11.0978 7604  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
15:21:12.0005 7604  BrSerWdm - ok
15:21:12.0035 7604  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
15:21:12.0084 7604  BrUsbMdm - ok
15:21:12.0102 7604  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
15:21:12.0145 7604  BrUsbSer - ok
15:21:12.0287 7604  [ CF98190A94F62E405C8CB255018B2315 ] BthEnum         C:\Windows\system32\drivers\BthEnum.sys
15:21:12.0332 7604  BthEnum - ok
15:21:12.0344 7604  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
15:21:12.0367 7604  BTHMODEM - ok
15:21:12.0383 7604  [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan          C:\Windows\system32\DRIVERS\bthpan.sys
15:21:12.0405 7604  BthPan - ok
15:21:12.0461 7604  [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT         C:\Windows\System32\Drivers\BTHport.sys
15:21:12.0494 7604  BTHPORT - ok
15:21:12.0528 7604  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv         C:\Windows\system32\bthserv.dll
15:21:12.0558 7604  bthserv - ok
15:21:12.0595 7604  [ F188B7394D81010767B6DF3178519A37 ] BTHUSB          C:\Windows\System32\Drivers\BTHUSB.sys
15:21:12.0637 7604  BTHUSB - ok
15:21:12.0779 7604  [ 40C6FEC49D1CC4D112368A2BCD2BCBB7 ] btmhsf          C:\Windows\system32\DRIVERS\btmhsf.sys
15:21:12.0813 7604  btmhsf - ok
15:21:12.0845 7604  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
15:21:12.0905 7604  cdfs - ok
15:21:12.0934 7604  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
15:21:12.0948 7604  cdrom - ok
15:21:12.0977 7604  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc     C:\Windows\System32\certprop.dll
15:21:13.0023 7604  CertPropSvc - ok
15:21:13.0038 7604  [ 274CE03459896006F7A5069266E0469E ] cfwids          C:\Windows\system32\drivers\cfwids.sys
15:21:13.0100 7604  cfwids - ok
15:21:13.0118 7604  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows\system32\drivers\circlass.sys
15:21:13.0139 7604  circlass - ok
15:21:13.0159 7604  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows\system32\CLFS.sys
15:21:13.0175 7604  CLFS - ok
15:21:13.0384 7604  [ BB86F147B2A7152E4B4D71A2F0A87D41 ] CLKMSVC10_9EC60124 C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe
15:21:13.0397 7604  CLKMSVC10_9EC60124 - ok
15:21:13.0581 7604  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
15:21:13.0592 7604  clr_optimization_v2.0.50727_32 - ok
15:21:13.0616 7604  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
15:21:13.0628 7604  clr_optimization_v2.0.50727_64 - ok
15:21:13.0684 7604  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
15:21:13.0978 7604  clr_optimization_v4.0.30319_32 - ok
15:21:14.0061 7604  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
15:21:14.0088 7604  clr_optimization_v4.0.30319_64 - ok
15:21:14.0139 7604  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
15:21:14.0160 7604  CmBatt - ok
15:21:14.0169 7604  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows\system32\drivers\cmdide.sys
15:21:14.0180 7604  cmdide - ok
15:21:14.0209 7604  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG             C:\Windows\system32\Drivers\cng.sys
15:21:14.0237 7604  CNG - ok
15:21:14.0259 7604  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
15:21:14.0268 7604  Compbatt - ok
15:21:14.0279 7604  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
15:21:14.0304 7604  CompositeBus - ok
15:21:14.0316 7604  COMSysApp - ok
15:21:14.0333 7604  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk         C:\Windows\system32\drivers\crcdisk.sys
15:21:14.0343 7604  crcdisk - ok
15:21:14.0380 7604  [ 4F5414602E2544A4554D95517948B705 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
15:21:14.0402 7604  CryptSvc - ok
15:21:14.0506 7604  [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC             C:\Windows\system32\drivers\csc.sys
15:21:14.0583 7604  CSC - ok
15:21:14.0745 7604  [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService      C:\Windows\System32\cscsvc.dll
15:21:14.0778 7604  CscService - ok
15:21:14.0810 7604  [ BC3D4F90978CD7C8EABD1BAF3BF7873A ] CtClsFlt        C:\Windows\system32\DRIVERS\CtClsFlt.sys
15:21:14.0835 7604  CtClsFlt - ok
15:21:14.0877 7604  [ 7AF9DAC504FBD047CBC3E64AE52C92BF ] dc3d            C:\Windows\system32\DRIVERS\dc3d.sys
15:21:14.0906 7604  dc3d - ok
15:21:14.0946 7604  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\Windows\system32\rpcss.dll
15:21:14.0990 7604  DcomLaunch - ok
15:21:15.0077 7604  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc       C:\Windows\System32\defragsvc.dll
15:21:15.0125 7604  defragsvc - ok
15:21:15.0152 7604  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
15:21:15.0209 7604  DfsC - ok
15:21:15.0292 7604  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\Windows\system32\dhcpcore.dll
15:21:15.0345 7604  Dhcp - ok
15:21:15.0361 7604  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows\system32\drivers\discache.sys
15:21:15.0396 7604  discache - ok
15:21:15.0427 7604  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows\system32\drivers\disk.sys
15:21:15.0438 7604  Disk - ok
15:21:15.0469 7604  [ 5DB085A8A6600BE6401F2B24EECB5415 ] dmvsc           C:\Windows\system32\drivers\dmvsc.sys
15:21:15.0495 7604  dmvsc - ok
15:21:15.0515 7604  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
15:21:15.0547 7604  Dnscache - ok
15:21:15.0575 7604  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc         C:\Windows\System32\dot3svc.dll
15:21:15.0615 7604  dot3svc - ok
15:21:15.0668 7604  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS             C:\Windows\system32\dps.dll
15:21:15.0725 7604  DPS - ok
15:21:15.0788 7604  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
15:21:15.0829 7604  drmkaud - ok
15:21:15.0946 7604  [ 46571ED73AE84469DCA53081D33CF3C8 ] dtsoftbus01     C:\Windows\system32\DRIVERS\dtsoftbus01.sys
15:21:15.0958 7604  dtsoftbus01 - ok
15:21:15.0992 7604  [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
15:21:16.0012 7604  DXGKrnl - ok
15:21:16.0047 7604  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost         C:\Windows\System32\eapsvc.dll
15:21:16.0085 7604  EapHost - ok
15:21:17.0184 7604  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv           C:\Windows\system32\drivers\evbda.sys
15:21:17.0388 7604  ebdrv - ok
15:21:17.0412 7604  [ C118A82CD78818C29AB228366EBF81C3 ] EFS             C:\Windows\System32\lsass.exe
15:21:17.0466 7604  EFS - ok
15:21:17.0608 7604  [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
15:21:17.0699 7604  ehRecvr - ok
15:21:17.0720 7604  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched         C:\Windows\ehome\ehsched.exe
15:21:17.0738 7604  ehSched - ok
15:21:17.0772 7604  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor         C:\Windows\system32\drivers\elxstor.sys
15:21:17.0791 7604  elxstor - ok
15:21:17.0812 7604  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows\system32\drivers\errdev.sys
15:21:17.0845 7604  ErrDev - ok
15:21:17.0903 7604  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem     C:\Windows\system32\es.dll
15:21:17.0960 7604  EventSystem - ok
15:21:18.0305 7604  [ 8B6C9924B0D333DBF76086B8258A0891 ] EvtEng          C:\Program Files\Intel\WiFi\bin\EvtEng.exe
15:21:18.0356 7604  EvtEng - ok
15:21:18.0407 7604  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat           C:\Windows\system32\drivers\exfat.sys
15:21:18.0439 7604  exfat - ok
15:21:18.0498 7604  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat         C:\Windows\system32\drivers\fastfat.sys
15:21:18.0543 7604  fastfat - ok
15:21:18.0602 7604  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax             C:\Windows\system32\fxssvc.exe
15:21:18.0694 7604  Fax - ok
15:21:18.0738 7604  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc             C:\Windows\system32\drivers\fdc.sys
15:21:18.0760 7604  fdc - ok
15:21:18.0786 7604  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost         C:\Windows\system32\fdPHost.dll
15:21:18.0832 7604  fdPHost - ok
15:21:18.0859 7604  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
15:21:18.0905 7604  FDResPub - ok
15:21:18.0982 7604  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
15:21:18.0995 7604  FileInfo - ok
15:21:19.0006 7604  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
15:21:19.0050 7604  Filetrace - ok
15:21:19.0076 7604  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
15:21:19.0092 7604  flpydisk - ok
15:21:19.0122 7604  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
15:21:19.0135 7604  FltMgr - ok
15:21:19.0286 7604  [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache       C:\Windows\system32\FntCache.dll
15:21:19.0377 7604  FontCache - ok
15:21:19.0463 7604  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
15:21:19.0474 7604  FontCache3.0.0.0 - ok
15:21:19.0544 7604  [ D43703496149971890703B4B1B723EAC ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
15:21:19.0560 7604  FsDepends - ok
15:21:19.0635 7604  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
15:21:19.0644 7604  Fs_Rec - ok
15:21:19.0713 7604  [ 1F7B25B858FA27015169FE95E54108ED ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
15:21:19.0750 7604  fvevol - ok
15:21:19.0788 7604  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
15:21:19.0805 7604  gagp30kx - ok
15:21:19.0867 7604  [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
15:21:19.0875 7604  GEARAspiWDM - ok
15:21:20.0076 7604  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc           C:\Windows\System32\gpsvc.dll
15:21:20.0131 7604  gpsvc - ok
15:21:20.0192 7604  [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi         C:\Windows\system32\DRIVERS\hamachi.sys
15:21:20.0209 7604  hamachi - ok
15:21:20.0257 7604  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
15:21:20.0314 7604  hcw85cir - ok
15:21:20.0403 7604  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
15:21:20.0430 7604  HdAudAddService - ok
15:21:20.0490 7604  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
15:21:20.0522 7604  HDAudBus - ok
15:21:20.0559 7604  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt         C:\Windows\system32\drivers\HidBatt.sys
15:21:20.0590 7604  HidBatt - ok
15:21:20.0603 7604  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
15:21:20.0633 7604  HidBth - ok
15:21:20.0684 7604  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr           C:\Windows\system32\drivers\hidir.sys
15:21:20.0702 7604  HidIr - ok
15:21:20.0754 7604  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv         C:\Windows\system32\hidserv.dll
15:21:20.0782 7604  hidserv - ok
15:21:20.0851 7604  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
15:21:20.0864 7604  HidUsb - ok
15:21:20.0882 7604  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\Windows\system32\kmsvc.dll
15:21:20.0938 7604  hkmsvc - ok
15:21:20.0970 7604  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
15:21:21.0021 7604  HomeGroupListener - ok
15:21:21.0098 7604  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
15:21:21.0118 7604  HomeGroupProvider - ok
15:21:21.0164 7604  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
15:21:21.0176 7604  HpSAMD - ok
15:21:21.0319 7604  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
15:21:21.0407 7604  HTTP - ok
15:21:21.0543 7604  [ 8F9B0FC4EC3A8194BD4CBC5ED3E7ABEB ] hwdatacard      C:\Windows\system32\DRIVERS\ewusbmdm.sys
15:21:21.0573 7604  hwdatacard - ok
15:21:21.0598 7604  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
15:21:21.0607 7604  hwpolicy - ok
15:21:21.0752 7604  [ 230C041AF8DF1D2308C3AC5146E3FF4F ] hwusbdev        C:\Windows\system32\DRIVERS\ewusbdev.sys
15:21:21.0813 7604  hwusbdev - ok
15:21:21.0864 7604  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
15:21:21.0876 7604  i8042prt - ok
15:21:21.0990 7604  [ D469B77687E12FE43E344806740B624D ] iaStor          C:\Windows\system32\DRIVERS\iaStor.sys
15:21:22.0003 7604  iaStor - ok
15:21:22.0087 7604  [ 983FC69644DDF0486C8DFEA262948D1A ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
15:21:22.0096 7604  IAStorDataMgrSvc - ok
15:21:22.0187 7604  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
15:21:22.0212 7604  iaStorV - ok
15:21:22.0247 7604  [ FC47F5CF561BF0FD897EFD1A9604DCCF ] iBtFltCoex      C:\Windows\system32\DRIVERS\iBtFltCoex.sys
15:21:22.0300 7604  iBtFltCoex - ok
15:21:22.0480 7604  [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT        C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
15:21:22.0489 7604  IDriverT ( UnsignedFile.Multi.Generic ) - warning
15:21:22.0490 7604  IDriverT - detected UnsignedFile.Multi.Generic (1)
15:21:22.0652 7604  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc           C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
15:21:22.0701 7604  idsvc - ok
15:21:24.0159 7604  [ 0AC9E321D604BE48A0D72B69BA484BDC ] igfx            C:\Windows\system32\DRIVERS\igdkmd64.sys
15:21:24.0558 7604  igfx - ok
15:21:24.0606 7604  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp           C:\Windows\system32\drivers\iirsp.sys
15:21:24.0618 7604  iirsp - ok
15:21:24.0742 7604  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\Windows\System32\ikeext.dll
15:21:24.0811 7604  IKEEXT - ok
15:21:25.0382 7604  [ A9853214CC97796579D75B1F59C51DCD ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
15:21:25.0422 7604  IntcAzAudAddService - ok
15:21:25.0537 7604  [ FC727061C0F47C8059E88E05D5C8E381 ] IntcDAud        C:\Windows\system32\DRIVERS\IntcDAud.sys
15:21:25.0590 7604  IntcDAud - ok
15:21:25.0638 7604  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows\system32\drivers\intelide.sys
15:21:25.0651 7604  intelide - ok
15:21:25.0685 7604  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
15:21:25.0714 7604  intelppm - ok
15:21:25.0767 7604  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
15:21:25.0819 7604  IPBusEnum - ok
15:21:25.0845 7604  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
15:21:25.0874 7604  IpFilterDriver - ok
15:21:26.0052 7604  [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
15:21:26.0144 7604  iphlpsvc - ok
15:21:26.0217 7604  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
15:21:26.0253 7604  IPMIDRV - ok
15:21:26.0270 7604  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
15:21:26.0325 7604  IPNAT - ok
15:21:26.0587 7604  [ A9AB99EE7D39725EAFEC82732D2B3271 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
15:21:26.0605 7604  iPod Service - ok
15:21:26.0667 7604  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
15:21:26.0727 7604  IRENUM - ok
15:21:26.0746 7604  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
15:21:26.0760 7604  isapnp - ok
15:21:26.0817 7604  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
15:21:26.0858 7604  iScsiPrt - ok
15:21:26.0881 7604  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
15:21:26.0891 7604  kbdclass - ok
15:21:26.0938 7604  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
15:21:26.0990 7604  kbdhid - ok
15:21:27.0063 7604  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\Windows\system32\lsass.exe
15:21:27.0074 7604  KeyIso - ok
15:21:27.0131 7604  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
15:21:27.0143 7604  KSecDD - ok
15:21:27.0171 7604  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
15:21:27.0183 7604  KSecPkg - ok
15:21:27.0242 7604  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
15:21:27.0312 7604  ksthunk - ok
15:21:27.0422 7604  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm           C:\Windows\system32\msdtckrm.dll
15:21:27.0471 7604  KtmRm - ok
15:21:27.0554 7604  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\Windows\system32\srvsvc.dll
15:21:27.0600 7604  LanmanServer - ok
15:21:27.0645 7604  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
15:21:27.0694 7604  LanmanWorkstation - ok
15:21:29.0225 7604  [ 20CDB07017497C94A0BAD253C4BAFCBC ] LkCitadelServer C:\Windows\SysWOW64\lkcitdl.exe
15:21:29.0242 7604  LkCitadelServer - ok
15:21:29.0337 7604  [ 99121FD465F7A65AC15EEC3B4034C1E4 ] lkClassAds      C:\Windows\SysWOW64\lkads.exe
15:21:29.0347 7604  lkClassAds - ok
15:21:29.0380 7604  [ 19C8D1B03A5229CBBE1037425701F55F ] lkTimeSync      C:\Windows\SysWOW64\lktsrv.exe
15:21:29.0389 7604  lkTimeSync - ok
15:21:29.0432 7604  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
15:21:29.0485 7604  lltdio - ok
15:21:29.0561 7604  [ C1185803384AB3FEED115F79F109427F ] lltdsvc         C:\Windows\System32\lltdsvc.dll
15:21:29.0593 7604  lltdsvc - ok
15:21:29.0633 7604  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts         C:\Windows\System32\lmhsvc.dll
15:21:29.0680 7604  lmhosts - ok
15:21:29.0887 7604  [ 7F32D4C47A50E7223491E8FB9359907D ] LMS             C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
15:21:29.0989 7604  LMS - ok
15:21:30.0059 7604  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
15:21:30.0071 7604  LSI_FC - ok
15:21:30.0175 7604  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
15:21:30.0186 7604  LSI_SAS - ok
15:21:30.0255 7604  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
15:21:30.0268 7604  LSI_SAS2 - ok
15:21:30.0291 7604  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
15:21:30.0303 7604  LSI_SCSI - ok
15:21:30.0415 7604  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv           C:\Windows\system32\drivers\luafv.sys
15:21:30.0451 7604  luafv - ok
15:21:30.0722 7604  [ F48571922079BBAB289C57BAFEFE88F3 ] McAWFwk         c:\PROGRA~1\mcafee\msc\mcawfwk.exe
15:21:30.0735 7604  McAWFwk - ok
15:21:30.0825 7604  [ ACB01BF1A905356AB7F978C7FE852209 ] McMPFSvc        C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
15:21:30.0837 7604  McMPFSvc - ok
15:21:30.0841 7604  [ ACB01BF1A905356AB7F978C7FE852209 ] mcmscsvc        C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
15:21:30.0853 7604  mcmscsvc - ok
15:21:30.0862 7604  [ ACB01BF1A905356AB7F978C7FE852209 ] McNaiAnn        C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
15:21:30.0873 7604  McNaiAnn - ok
15:21:30.0896 7604  [ ACB01BF1A905356AB7F978C7FE852209 ] McNASvc         C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
15:21:30.0907 7604  McNASvc - ok
15:21:31.0126 7604  [ 44D0DA102FA7A1BE22FD7499E80DCF9B ] McODS           C:\Program Files\McAfee\VirusScan\mcods.exe
15:21:31.0153 7604  McODS - ok
15:21:31.0182 7604  [ ACB01BF1A905356AB7F978C7FE852209 ] McOobeSv        C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
15:21:31.0194 7604  McOobeSv - ok
15:21:31.0199 7604  [ ACB01BF1A905356AB7F978C7FE852209 ] McProxy         C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
15:21:31.0210 7604  McProxy - ok
15:21:31.0265 7604  [ E998E3B12101288D716558466CBF6AE1 ] McShield        C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
15:21:31.0277 7604  McShield - ok
15:21:31.0298 7604  [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
15:21:31.0321 7604  Mcx2Svc - ok
15:21:31.0350 7604  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas         C:\Windows\system32\drivers\megasas.sys
15:21:31.0361 7604  megasas - ok
15:21:31.0428 7604  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
15:21:31.0446 7604  MegaSR - ok
15:21:31.0474 7604  [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64          C:\Windows\system32\DRIVERS\HECIx64.sys
15:21:31.0483 7604  MEIx64 - ok
15:21:31.0515 7604  [ 01884CB7655C8908B43FF5E364FE6FD2 ] mfeapfk         C:\Windows\system32\drivers\mfeapfk.sys
15:21:31.0524 7604  mfeapfk - ok
15:21:31.0581 7604  [ DAB9A9CDFB04E4D68924492AA043019D ] mfeavfk         C:\Windows\system32\drivers\mfeavfk.sys
15:21:31.0594 7604  mfeavfk - ok
15:21:31.0614 7604  mfeavfk01 - ok
15:21:31.0631 7604  [ B26782C3D6045B4464017D7926877560 ] mfefire         C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
15:21:31.0641 7604  mfefire - ok
15:21:31.0677 7604  [ CE9A3680675C0907ADE16404CA967B49 ] mfefirek        C:\Windows\system32\drivers\mfefirek.sys
15:21:31.0692 7604  mfefirek - ok
15:21:31.0708 7604  [ 60CF67458DD29CD17E77F2327B1A9A54 ] mfehidk         C:\Windows\system32\drivers\mfehidk.sys
15:21:31.0729 7604  mfehidk - ok
15:21:31.0739 7604  [ A8129CFB919347F8533C934B365E9202 ] mfenlfk         C:\Windows\system32\DRIVERS\mfenlfk.sys
15:21:31.0748 7604  mfenlfk - ok
15:21:31.0771 7604  [ 5041FA2BD2B3A2693B015771BFBF6DCA ] mferkdet        C:\Windows\system32\drivers\mferkdet.sys
15:21:31.0781 7604  mferkdet - ok
15:21:31.0813 7604  [ 723A5EB6CEF7F408C3D0F15A82A6BFF8 ] mfevtp          C:\Windows\system32\mfevtps.exe
15:21:31.0827 7604  mfevtp - ok
15:21:31.0843 7604  [ 919C56DB14A0E1E2AB6DA5D2821DC26E ] mfewfpk         C:\Windows\system32\drivers\mfewfpk.sys
15:21:31.0857 7604  mfewfpk - ok
15:21:31.0993 7604  Microsoft SharePoint Workspace Audit Service - ok
15:21:32.0024 7604  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS           C:\Windows\system32\mmcss.dll
15:21:32.0054 7604  MMCSS - ok
15:21:32.0071 7604  [ 800BA92F7010378B09F9ED9270F07137 ] Modem           C:\Windows\system32\drivers\modem.sys
15:21:32.0112 7604  Modem - ok
15:21:32.0138 7604  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
15:21:32.0159 7604  monitor - ok
15:21:32.0188 7604  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
15:21:32.0198 7604  mouclass - ok
15:21:32.0208 7604  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
15:21:32.0226 7604  mouhid - ok
15:21:32.0265 7604  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
15:21:32.0276 7604  mountmgr - ok
15:21:32.0303 7604  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\Windows\system32\drivers\mpio.sys
15:21:32.0316 7604  mpio - ok
15:21:32.0340 7604  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
15:21:32.0373 7604  mpsdrv - ok
15:21:32.0477 7604  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\Windows\system32\mpssvc.dll
15:21:32.0524 7604  MpsSvc - ok
15:21:32.0554 7604  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
15:21:32.0599 7604  MRxDAV - ok
15:21:32.0627 7604  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
15:21:32.0663 7604  mrxsmb - ok
15:21:32.0704 7604  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
15:21:32.0721 7604  mrxsmb10 - ok
15:21:32.0750 7604  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
15:21:32.0762 7604  mrxsmb20 - ok
15:21:32.0790 7604  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\Windows\system32\drivers\msahci.sys
15:21:32.0799 7604  msahci - ok
15:21:32.0829 7604  [ DB801A638D011B9633829EB6F663C900 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
15:21:32.0843 7604  msdsm - ok
15:21:32.0856 7604  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC           C:\Windows\System32\msdtc.exe
15:21:32.0884 7604  MSDTC - ok
15:21:32.0911 7604  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
15:21:32.0940 7604  Msfs - ok
15:21:32.0960 7604  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
15:21:32.0998 7604  mshidkmdf - ok
15:21:33.0010 7604  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
15:21:33.0020 7604  msisadrv - ok
15:21:33.0044 7604  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
15:21:33.0085 7604  MSiSCSI - ok
15:21:33.0087 7604  msiserver - ok
15:21:33.0109 7604  [ ACB01BF1A905356AB7F978C7FE852209 ] MSK80Service    C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
15:21:33.0120 7604  MSK80Service - ok
15:21:33.0142 7604  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
15:21:33.0189 7604  MSKSSRV - ok
15:21:33.0212 7604  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
15:21:33.0252 7604  MSPCLOCK - ok
15:21:33.0264 7604  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
15:21:33.0303 7604  MSPQM - ok
15:21:33.0338 7604  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
15:21:33.0365 7604  MsRPC - ok
15:21:33.0379 7604  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
15:21:33.0389 7604  mssmbios - ok
15:21:33.0453 7604  MSSQL$SQLEXPRESS - ok
15:21:33.0538 7604  [ 7A2A8C975356858EB38466A6B1592E8D ] MSSQLServerADHelper100 c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE
15:21:33.0548 7604  MSSQLServerADHelper100 - ok
15:21:33.0576 7604  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
15:21:33.0612 7604  MSTEE - ok
15:21:33.0625 7604  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
15:21:33.0636 7604  MTConfig - ok
15:21:33.0649 7604  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup             C:\Windows\system32\Drivers\mup.sys
15:21:33.0658 7604  Mup - ok
15:21:33.0716 7604  [ 6ED8935257672F4CD04A88A0F3DE093D ] MyWiFiDHCPDNS   C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
15:21:33.0730 7604  MyWiFiDHCPDNS - ok
15:21:33.0754 7604  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\Windows\system32\qagentRT.dll
15:21:33.0794 7604  napagent - ok
15:21:33.0834 7604  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
15:21:33.0863 7604  NativeWifiP - ok
15:21:33.0894 7604  [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS            C:\Windows\system32\drivers\ndis.sys
15:21:33.0919 7604  NDIS - ok
15:21:33.0947 7604  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
15:21:33.0986 7604  NdisCap - ok
15:21:34.0011 7604  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
15:21:34.0039 7604  NdisTapi - ok
15:21:34.0055 7604  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
15:21:34.0085 7604  Ndisuio - ok
15:21:34.0099 7604  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
15:21:34.0137 7604  NdisWan - ok
15:21:34.0146 7604  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
15:21:34.0175 7604  NDProxy - ok
15:21:34.0221 7604  [ 6F4607E2333FE21E9E3FF8133A88B35B ] Netaapl         C:\Windows\system32\DRIVERS\netaapl64.sys
15:21:34.0251 7604  Netaapl - ok
15:21:34.0269 7604  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
15:21:34.0303 7604  NetBIOS - ok
15:21:34.0314 7604  [ 09594D1089C523423B32A4229263F068 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
15:21:34.0345 7604  NetBT - ok
15:21:34.0354 7604  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\Windows\system32\lsass.exe
15:21:34.0365 7604  Netlogon - ok
15:21:34.0386 7604  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows\System32\netman.dll
15:21:34.0426 7604  Netman - ok
15:21:34.0481 7604  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:21:34.0503 7604  NetMsmqActivator - ok
15:21:34.0529 7604  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:21:34.0538 7604  NetPipeActivator - ok
15:21:34.0568 7604  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows\System32\netprofm.dll
15:21:34.0609 7604  netprofm - ok
15:21:34.0614 7604  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:21:34.0623 7604  NetTcpActivator - ok
15:21:34.0626 7604  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:21:34.0635 7604  NetTcpPortSharing - ok
15:21:34.0803 7604  [ 5D262402B0634C998F8CBCEAD7DD8676 ] NETwNs64        C:\Windows\system32\DRIVERS\NETwNs64.sys
15:21:34.0994 7604  NETwNs64 - ok
15:21:35.0018 7604  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960         C:\Windows\system32\drivers\nfrd960.sys
15:21:35.0029 7604  nfrd960 - ok
15:21:35.0124 7604  [ CEEFDE8FACE887D6DDA664940404EA58 ] NIDomainService C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe
15:21:35.0136 7604  NIDomainService - ok
15:21:35.0198 7604  [ B17093B9A2C5F874975C732C1A8BA771 ] NILM License Manager C:\Program Files (x86)\National Instruments\Shared\License Manager\Bin\lmgrd.exe
15:21:35.0232 7604  NILM License Manager ( UnsignedFile.Multi.Generic ) - warning
15:21:35.0232 7604  NILM License Manager - detected UnsignedFile.Multi.Generic (1)
15:21:35.0277 7604  niSvcLoc - ok
15:21:35.0310 7604  [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc          C:\Windows\System32\nlasvc.dll
15:21:35.0349 7604  NlaSvc - ok
15:21:35.0363 7604  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
15:21:35.0393 7604  Npfs - ok
15:21:35.0407 7604  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi             C:\Windows\system32\nsisvc.dll
15:21:35.0447 7604  nsi - ok
15:21:35.0454 7604  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
15:21:35.0484 7604  nsiproxy - ok
15:21:35.0528 7604  [ A2F74975097F52A00745F9637451FDD8 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
15:21:35.0580 7604  Ntfs - ok
15:21:35.0598 7604  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows\system32\drivers\Null.sys
15:21:35.0638 7604  Null - ok
15:21:35.0663 7604  [ A7127E86F9FFE2A53E271B56B2C4CEDF ] nusb3hub        C:\Windows\system32\DRIVERS\nusb3hub.sys
15:21:35.0679 7604  nusb3hub - ok
15:21:35.0704 7604  [ 49BBEC6F48D5F9284B03ABF3A959B19B ] nusb3xhc        C:\Windows\system32\DRIVERS\nusb3xhc.sys
15:21:35.0738 7604  nusb3xhc - ok
15:21:35.0793 7604  [ 8D4AAC74B571FC356560E5B308955E93 ] NVHDA           C:\Windows\system32\drivers\nvhda64v.sys
15:21:35.0806 7604  NVHDA - ok
15:21:35.0937 7604  [ 555DDBAF3D306154C553ACBD6780FD1E ] nvkflt          C:\Windows\system32\DRIVERS\nvkflt.sys
15:21:35.0949 7604  nvkflt - ok
15:21:36.0196 7604  [ 0EB204639119370F5F8F2871FBF4E14B ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
15:21:36.0357 7604  nvlddmkm - ok
15:21:36.0386 7604  [ 3629B8C7257C6231A3CFB44359C68B1D ] nvpciflt        C:\Windows\system32\DRIVERS\nvpciflt.sys
15:21:36.0395 7604  nvpciflt - ok
15:21:36.0426 7604  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\Windows\system32\drivers\nvraid.sys
15:21:36.0439 7604  nvraid - ok
15:21:36.0454 7604  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\Windows\system32\drivers\nvstor.sys
15:21:36.0467 7604  nvstor - ok
15:21:36.0494 7604  [ 32FF8EE6DCEE5C0CB91FF892FB1CA364 ] NVSvc           C:\Windows\system32\nvvsvc.exe
15:21:36.0519 7604  NVSvc - ok
15:21:36.0600 7604  [ BD012DC22C78BE1071BC21EB125D782F ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
15:21:36.0667 7604  nvUpdatusService - ok
15:21:36.0704 7604  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
15:21:36.0717 7604  nv_agp - ok
15:21:36.0735 7604  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
15:21:36.0747 7604  ohci1394 - ok
15:21:36.0796 7604  [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose             C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:21:36.0807 7604  ose - ok
15:21:36.0929 7604  [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc         C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
15:21:37.0072 7604  osppsvc - ok
15:21:37.0119 7604  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
15:21:37.0146 7604  p2pimsvc - ok
15:21:37.0173 7604  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows\system32\p2psvc.dll
15:21:37.0187 7604  p2psvc - ok
15:21:37.0208 7604  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport         C:\Windows\system32\drivers\parport.sys
15:21:37.0226 7604  Parport - ok
15:21:37.0264 7604  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr         C:\Windows\system32\drivers\partmgr.sys
15:21:37.0275 7604  partmgr - ok
15:21:37.0286 7604  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
15:21:37.0316 7604  PcaSvc - ok
15:21:37.0331 7604  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci             C:\Windows\system32\drivers\pci.sys
15:21:37.0344 7604  pci - ok
15:21:37.0367 7604  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows\system32\drivers\pciide.sys
15:21:37.0382 7604  pciide - ok
15:21:37.0400 7604  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
15:21:37.0415 7604  pcmcia - ok
15:21:37.0431 7604  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw             C:\Windows\system32\drivers\pcw.sys
15:21:37.0440 7604  pcw - ok
15:21:37.0456 7604  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
15:21:37.0501 7604  PEAUTH - ok
15:21:37.0546 7604  [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
15:21:37.0612 7604  PeerDistSvc - ok
15:21:37.0649 7604  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
15:21:37.0668 7604  PerfHost - ok
15:21:37.0759 7604  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla             C:\Windows\system32\pla.dll
15:21:37.0827 7604  pla - ok
15:21:37.0853 7604  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
15:21:37.0883 7604  PlugPlay - ok
15:21:37.0930 7604  [ F485770EEC8959684CC4C4786B63C06C ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
15:21:37.0964 7604  Pml Driver HPZ12 - ok
15:21:37.0982 7604  PnkBstrA - ok
15:21:38.0012 7604  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
15:21:38.0023 7604  PNRPAutoReg - ok
15:21:38.0046 7604  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
15:21:38.0059 7604  PNRPsvc - ok
15:21:38.0132 7604  [ 4F0878FD62D5F7444C5F1C4C66D9D293 ] Point64         C:\Windows\system32\DRIVERS\point64.sys
15:21:38.0140 7604  Point64 - ok
15:21:38.0194 7604  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
15:21:38.0234 7604  PolicyAgent - ok
15:21:38.0294 7604  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power           C:\Windows\system32\umpo.dll
15:21:38.0349 7604  Power - ok
15:21:38.0402 7604  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
15:21:38.0444 7604  PptpMiniport - ok
15:21:38.0461 7604  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor       C:\Windows\system32\drivers\processr.sys
15:21:38.0484 7604  Processor - ok
15:21:38.0548 7604  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc         C:\Windows\system32\profsvc.dll
15:21:38.0577 7604  ProfSvc - ok
15:21:38.0593 7604  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
15:21:38.0604 7604  ProtectedStorage - ok
15:21:38.0649 7604  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
15:21:38.0696 7604  Psched - ok
15:21:38.0774 7604  [ 0928BD20273625622722FE1DE5BBDE57 ] qicflt          C:\Windows\system32\DRIVERS\qicflt.sys
15:21:38.0783 7604  qicflt - ok
15:21:38.0843 7604  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
15:21:38.0887 7604  ql2300 - ok
15:21:38.0899 7604  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
15:21:38.0910 7604  ql40xx - ok
15:21:38.0950 7604  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE           C:\Windows\system32\qwave.dll
15:21:38.0968 7604  QWAVE - ok
15:21:38.0987 7604  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
15:21:39.0012 7604  QWAVEdrv - ok
15:21:39.0026 7604  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
15:21:39.0054 7604  RasAcd - ok
15:21:39.0079 7604  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
15:21:39.0107 7604  RasAgileVpn - ok
15:21:39.0135 7604  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto         C:\Windows\System32\rasauto.dll
15:21:39.0176 7604  RasAuto - ok
15:21:39.0189 7604  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
15:21:39.0224 7604  Rasl2tp - ok
15:21:39.0245 7604  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\Windows\System32\rasmans.dll
15:21:39.0275 7604  RasMan - ok
15:21:39.0287 7604  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
15:21:39.0325 7604  RasPppoe - ok
15:21:39.0334 7604  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
15:21:39.0374 7604  RasSstp - ok
15:21:39.0390 7604  [ 77F665941019A1594D887A74F301FA2F ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
15:21:39.0429 7604  rdbss - ok
15:21:39.0446 7604  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
15:21:39.0461 7604  rdpbus - ok
15:21:39.0479 7604  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
15:21:39.0506 7604  RDPCDD - ok
15:21:39.0531 7604  [ 1B6163C503398B23FF8B939C67747683 ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
15:21:39.0555 7604  RDPDR - ok
15:21:39.0570 7604  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
15:21:39.0605 7604  RDPENCDD - ok
15:21:39.0623 7604  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
15:21:39.0660 7604  RDPREFMP - ok
15:21:39.0696 7604  [ 70CBA1A0C98600A2AA1863479B35CB90 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
15:21:39.0724 7604  RdpVideoMiniport - ok
15:21:39.0759 7604  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
15:21:39.0807 7604  RDPWD - ok
15:21:39.0825 7604  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
15:21:39.0838 7604  rdyboost - ok
15:21:39.0910 7604  [ 189C5A8D2098E0AA14FD157A954B34FC ] RegSrvc         C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
15:21:39.0927 7604  RegSrvc - ok
15:21:39.0945 7604  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
15:21:39.0982 7604  RemoteAccess - ok
15:21:40.0005 7604  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
15:21:40.0043 7604  RemoteRegistry - ok
15:21:40.0074 7604  [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM          C:\Windows\system32\DRIVERS\rfcomm.sys
15:21:40.0096 7604  RFCOMM - ok
15:21:40.0119 7604  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
15:21:40.0184 7604  RpcEptMapper - ok
15:21:40.0199 7604  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows\system32\locator.exe
15:21:40.0218 7604  RpcLocator - ok
15:21:40.0236 7604  [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs           C:\Windows\system32\rpcss.dll
15:21:40.0268 7604  RpcSs - ok
15:21:40.0308 7604  [ CD553B8633466A6D1C115812F2619F1F ] RsFx0103        C:\Windows\system32\DRIVERS\RsFx0103.sys
15:21:40.0322 7604  RsFx0103 - ok
15:21:40.0348 7604  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
15:21:40.0387 7604  rspndr - ok
15:21:40.0511 7604  [ EE082E06A82FF630351D1E0EBBD3D8D0 ] RTL8167         C:\Windows\system32\DRIVERS\Rt64win7.sys
15:21:40.0525 7604  RTL8167 - ok
15:21:40.0559 7604  [ E60C0A09F997826C7627B244195AB581 ] s3cap           C:\Windows\system32\drivers\vms3cap.sys
15:21:40.0597 7604  s3cap - ok
15:21:40.0610 7604  [ C118A82CD78818C29AB228366EBF81C3 ] SamSs           C:\Windows\system32\lsass.exe
15:21:40.0621 7604  SamSs - ok
15:21:40.0637 7604  [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
15:21:40.0648 7604  sbp2port - ok
15:21:40.0668 7604  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows\System32\SCardSvr.dll
15:21:40.0699 7604  SCardSvr - ok
15:21:40.0720 7604  [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
15:21:40.0759 7604  scfilter - ok
15:21:40.0786 7604  [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule        C:\Windows\system32\schedsvc.dll
15:21:40.0839 7604  Schedule - ok
15:21:40.0853 7604  [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc     C:\Windows\System32\certprop.dll
15:21:40.0880 7604  SCPolicySvc - ok
15:21:40.0948 7604  [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus           C:\Windows\system32\DRIVERS\sdbus.sys
15:21:40.0970 7604  sdbus - ok
15:21:40.0991 7604  [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
15:21:41.0013 7604  SDRSVC - ok
15:21:41.0067 7604  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
15:21:41.0120 7604  secdrv - ok
15:21:41.0129 7604  [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon        C:\Windows\system32\seclogon.dll
15:21:41.0162 7604  seclogon - ok
15:21:41.0198 7604  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows\System32\sens.dll
15:21:41.0236 7604  SENS - ok
15:21:41.0246 7604  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
15:21:41.0273 7604  SensrSvc - ok
15:21:41.0293 7604  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum         C:\Windows\system32\drivers\serenum.sys
15:21:41.0311 7604  Serenum - ok
15:21:41.0334 7604  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows\system32\drivers\serial.sys
15:21:41.0361 7604  Serial - ok
15:21:41.0386 7604  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
15:21:41.0399 7604  sermouse - ok
15:21:41.0417 7604  [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv      C:\Windows\system32\sessenv.dll
15:21:41.0445 7604  SessionEnv - ok
15:21:41.0448 7604  [ A554811BCD09279536440C964AE35BBF ] sffdisk         C:\Windows\system32\DRIVERS\sffdisk.sys
15:21:41.0471 7604  sffdisk - ok
15:21:41.0474 7604  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
15:21:41.0488 7604  sffp_mmc - ok
15:21:41.0490 7604  [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd         C:\Windows\system32\DRIVERS\sffp_sd.sys
15:21:41.0512 7604  sffp_sd - ok
15:21:41.0526 7604  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy         C:\Windows\system32\drivers\sfloppy.sys
15:21:41.0540 7604  sfloppy - ok
15:21:41.0560 7604  [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess    C:\Windows\System32\ipnathlp.dll
15:21:41.0606 7604  SharedAccess - ok
15:21:41.0627 7604  [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
15:21:41.0671 7604  ShellHWDetection - ok
15:21:41.0703 7604  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
15:21:41.0715 7604  SiSRaid2 - ok
15:21:41.0727 7604  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
15:21:41.0739 7604  SiSRaid4 - ok
15:21:41.0858 7604  [ 753D254205E0A62100A050BD8B458D06 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
15:21:41.0937 7604  Skype C2C Service - ok
15:21:41.0975 7604  [ DDAA5F4A6B958FC313EBD02DD925752F ] SkypeUpdate     C:\Program Files (x86)\Skype\Updater\Updater.exe
15:21:41.0983 7604  SkypeUpdate - ok
15:21:42.0008 7604  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
15:21:42.0051 7604  Smb - ok
15:21:42.0094 7604  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
15:21:42.0107 7604  SNMPTRAP - ok
15:21:42.0119 7604  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr           C:\Windows\system32\drivers\spldr.sys
15:21:42.0128 7604  spldr - ok
15:21:42.0183 7604  [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler         C:\Windows\System32\spoolsv.exe
15:21:42.0212 7604  Spooler - ok
15:21:42.0268 7604  [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc          C:\Windows\system32\sppsvc.exe
15:21:42.0625 7604  sppsvc - ok
15:21:42.0637 7604  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify     C:\Windows\system32\sppuinotify.dll
15:21:42.0667 7604  sppuinotify - ok
15:21:42.0743 7604  [ 12E6D95CDE974B131DEFAA44BAB8B056 ] SQLAgent$SQLEXPRESS c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE
15:21:42.0760 7604  SQLAgent$SQLEXPRESS - ok
15:21:42.0808 7604  [ B54B48F6D92423440C264E91225C5FF1 ] SQLBrowser      c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
15:21:42.0823 7604  SQLBrowser - ok
15:21:42.0839 7604  [ 6D65985945B03CA59B67D0B73702FC7B ] SQLWriter       c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
15:21:42.0850 7604  SQLWriter - ok
15:21:42.0876 7604  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv             C:\Windows\system32\DRIVERS\srv.sys
15:21:42.0906 7604  srv - ok
15:21:42.0922 7604  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
15:21:42.0948 7604  srv2 - ok
15:21:42.0964 7604  [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
15:21:42.0977 7604  srvnet - ok
15:21:42.0993 7604  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
15:21:43.0023 7604  SSDPSRV - ok
15:21:43.0034 7604  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc         C:\Windows\system32\sstpsvc.dll
15:21:43.0064 7604  SstpSvc - ok
15:21:43.0088 7604  Steam Client Service - ok
15:21:43.0180 7604  [ FC0A58529A02B1EED55DDC58696B7908 ] Stereo Service  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
15:21:43.0196 7604  Stereo Service - ok
15:21:43.0211 7604  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows\system32\drivers\stexstor.sys
15:21:43.0223 7604  stexstor - ok
15:21:43.0273 7604  [ DECACB6921DED1A38642642685D77DAC ] StillCam        C:\Windows\system32\DRIVERS\serscan.sys
15:21:43.0297 7604  StillCam - ok
15:21:43.0329 7604  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc          C:\Windows\System32\wiaservc.dll
15:21:43.0361 7604  stisvc - ok
15:21:43.0380 7604  [ 7785DC213270D2FC066538DAF94087E7 ] storflt         C:\Windows\system32\drivers\vmstorfl.sys
15:21:43.0390 7604  storflt - ok
15:21:43.0415 7604  [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc         C:\Windows\system32\drivers\storvsc.sys
15:21:43.0427 7604  storvsc - ok
15:21:43.0444 7604  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
15:21:43.0454 7604  swenum - ok
15:21:43.0476 7604  [ E08E46FDD841B7184194011CA1955A0B ] swprv           C:\Windows\System32\swprv.dll
15:21:43.0524 7604  swprv - ok
15:21:43.0532 7604  [ C3A39C4079305480972D29C44B868C78 ] Synth3dVsc      C:\Windows\system32\drivers\synth3dvsc.sys
15:21:43.0544 7604  Synth3dVsc - ok
15:21:43.0573 7604  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain         C:\Windows\system32\sysmain.dll
15:21:43.0636 7604  SysMain - ok
15:21:43.0652 7604  [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
15:21:43.0670 7604  TabletInputService - ok
15:21:43.0677 7604  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv         C:\Windows\System32\tapisrv.dll
15:21:43.0718 7604  TapiSrv - ok
15:21:43.0732 7604  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS             C:\Windows\System32\tbssvc.dll
15:21:43.0761 7604  TBS - ok
15:21:43.0823 7604  [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
15:21:43.0877 7604  Tcpip - ok
15:21:43.0922 7604  [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
15:21:43.0952 7604  TCPIP6 - ok
15:21:43.0976 7604  [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
15:21:44.0017 7604  tcpipreg - ok
15:21:44.0034 7604  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
15:21:44.0072 7604  TDPIPE - ok
15:21:44.0100 7604  [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
15:21:44.0127 7604  TDTCP - ok
15:21:44.0143 7604  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
15:21:44.0172 7604  tdx - ok
15:21:44.0199 7604  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
15:21:44.0208 7604  TermDD - ok
15:21:44.0241 7604  [ 2B5BDFF688EC9871D7EC5837833374E9 ] terminpt        C:\Windows\system32\drivers\terminpt.sys
15:21:44.0274 7604  terminpt - ok
15:21:44.0368 7604  [ 2E648163254233755035B46DD7B89123 ] TermService     C:\Windows\System32\termsrv.dll
15:21:44.0424 7604  TermService - ok
15:21:44.0461 7604  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows\system32\themeservice.dll
15:21:44.0477 7604  Themes - ok
15:21:44.0510 7604  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER     C:\Windows\system32\mmcss.dll
15:21:44.0539 7604  THREADORDER - ok
15:21:44.0561 7604  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows\System32\trkwks.dll
15:21:44.0610 7604  TrkWks - ok
15:21:44.0682 7604  [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
15:21:44.0731 7604  TrustedInstaller - ok
15:21:44.0769 7604  [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
15:21:44.0818 7604  tssecsrv - ok
15:21:44.0845 7604  [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
15:21:44.0883 7604  TsUsbFlt - ok
15:21:44.0886 7604  [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD         C:\Windows\system32\drivers\TsUsbGD.sys
15:21:44.0906 7604  TsUsbGD - ok
15:21:44.0923 7604  [ E1748D04AE40118B62BC18AC86032192 ] tsusbhub        C:\Windows\system32\drivers\tsusbhub.sys
15:21:44.0951 7604  tsusbhub - ok
15:21:45.0009 7604  [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
15:21:45.0061 7604  tunnel - ok
15:21:45.0121 7604  [ FD24F98D2898BE093FE926604BE7DB99 ] TurboB          C:\Windows\system32\DRIVERS\TurboB.sys
15:21:45.0131 7604  TurboB - ok
15:21:45.0196 7604  [ 600B406A04D90F577FEA8A88D7379F08 ] TurboBoost      C:\Program Files\Intel\TurboBoost\TurboBoost.exe
15:21:45.0207 7604  TurboBoost - ok
15:21:45.0235 7604  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
15:21:45.0253 7604  uagp35 - ok
15:21:45.0311 7604  [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
15:21:45.0363 7604  udfs - ok
15:21:45.0405 7604  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect       C:\Windows\system32\UI0Detect.exe
15:21:45.0427 7604  UI0Detect - ok
15:21:45.0490 7604  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
15:21:45.0500 7604  uliagpkx - ok
15:21:45.0532 7604  [ DC54A574663A895C8763AF0FA1FF7561 ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
15:21:45.0557 7604  umbus - ok
15:21:45.0606 7604  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows\system32\drivers\umpass.sys
15:21:45.0623 7604  UmPass - ok
15:21:45.0700 7604  [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService    C:\Windows\System32\umrdp.dll
15:21:45.0734 7604  UmRdpService - ok
15:21:46.0021 7604  [ 2C16648A12999AE69A9EBF41974B0BA2 ] UNS             C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
15:21:46.0112 7604  UNS - ok
15:21:46.0140 7604  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows\System32\upnphost.dll
15:21:46.0178 7604  upnphost - ok
15:21:46.0261 7604  [ FB251567F41BC61988B26731DEC19E4B ] USBAAPL64       C:\Windows\system32\Drivers\usbaapl64.sys
15:21:46.0291 7604  USBAAPL64 - ok
15:21:46.0355 7604  [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
15:21:46.0390 7604  usbccgp - ok
15:21:46.0468 7604  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
15:21:46.0482 7604  usbcir - ok
15:21:46.0509 7604  [ C025055FE7B87701EB042095DF1A2D7B ] usbehci         C:\Windows\system32\drivers\usbehci.sys
15:21:46.0526 7604  usbehci - ok
15:21:46.0611 7604  [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
15:21:46.0637 7604  usbhub - ok
15:21:46.0652 7604  [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci         C:\Windows\system32\drivers\usbohci.sys
15:21:46.0690 7604  usbohci - ok
15:21:46.0706 7604  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows\system32\drivers\usbprint.sys
15:21:46.0739 7604  usbprint - ok
15:21:46.0783 7604  [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
15:21:46.0850 7604  USBSTOR - ok
15:21:46.0909 7604  [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
15:21:46.0949 7604  usbuhci - ok
15:21:47.0013 7604  [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
15:21:47.0071 7604  usbvideo - ok
15:21:47.0113 7604  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms           C:\Windows\System32\uxsms.dll
15:21:47.0161 7604  UxSms - ok
15:21:47.0173 7604  [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc        C:\Windows\system32\lsass.exe
15:21:47.0184 7604  VaultSvc - ok
15:21:47.0317 7604  [ 87947A6F7DD5183AABA2CB45CFF0BF26 ] VBoxDrv         C:\Windows\system32\DRIVERS\VBoxDrv.sys
15:21:47.0329 7604  VBoxDrv - ok
15:21:47.0438 7604  [ A502011EB830AD5BF4D30A940614CF4E ] VBoxNetAdp      C:\Windows\system32\DRIVERS\VBoxNetAdp.sys
15:21:47.0472 7604  VBoxNetAdp - ok
15:21:47.0486 7604  [ 9E86BB348A82EC3047D7CC75868B28AA ] VBoxNetFlt      C:\Windows\system32\DRIVERS\VBoxNetFlt.sys
15:21:47.0496 7604  VBoxNetFlt - ok
15:21:47.0518 7604  [ 5E9F3633DDDAF2F1070017DC07044C97 ] VBoxUSBMon      C:\Windows\system32\DRIVERS\VBoxUSBMon.sys
15:21:47.0529 7604  VBoxUSBMon - ok
15:21:47.0580 7604  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
15:21:47.0589 7604  vdrvroot - ok
15:21:47.0740 7604  [ 8D6B481601D01A456E75C3210F1830BE ] vds             C:\Windows\System32\vds.exe
15:21:47.0806 7604  vds - ok
15:21:47.0831 7604  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
15:21:47.0862 7604  vga - ok
15:21:47.0883 7604  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave         C:\Windows\System32\drivers\vga.sys
15:21:47.0942 7604  VgaSave - ok
15:21:47.0945 7604  VGPU - ok
15:21:47.0961 7604  [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
15:21:47.0974 7604  vhdmp - ok
15:21:48.0002 7604  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows\system32\drivers\viaide.sys
15:21:48.0013 7604  viaide - ok
15:21:48.0055 7604  [ 86EA3E79AE350FEA5331A1303054005F ] vmbus           C:\Windows\system32\drivers\vmbus.sys
15:21:48.0068 7604  vmbus - ok
15:21:48.0092 7604  [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
15:21:48.0134 7604  VMBusHID - ok
15:21:48.0165 7604  [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
15:21:48.0177 7604  volmgr - ok
15:21:48.0201 7604  [ A255814907C89BE58B79EF2F189B843B ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
15:21:48.0216 7604  volmgrx - ok
15:21:48.0253 7604  [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
15:21:48.0267 7604  volsnap - ok
15:21:48.0344 7604  [ ABD9B4A7E2D0AE51A3B8DF1AF3152D61 ] vpcbus          C:\Windows\system32\DRIVERS\vpchbus.sys
15:21:48.0371 7604  vpcbus - ok
15:21:48.0393 7604  [ 8ACDA395841538CE9713A67FE8B2A3EB ] vpcnfltr        C:\Windows\system32\DRIVERS\vpcnfltr.sys
15:21:48.0403 7604  vpcnfltr - ok
15:21:48.0433 7604  [ 31924E31BC315773E6D149B157DB46D5 ] vpcusb          C:\Windows\system32\DRIVERS\vpcusb.sys
15:21:48.0455 7604  vpcusb - ok
15:21:48.0513 7604  [ C5B651E52540E6F46DA66574C74B4898 ] vpcvmm          C:\Windows\system32\drivers\vpcvmm.sys
15:21:48.0526 7604  vpcvmm - ok
15:21:48.0602 7604  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid         C:\Windows\system32\drivers\vsmraid.sys
15:21:48.0617 7604  vsmraid - ok
15:21:48.0832 7604  [ 1928B9CA20F51BFBBAD54D2C2C447B13 ] VSPerfDrv100    C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys
15:21:48.0865 7604  VSPerfDrv100 - ok
15:21:49.0163 7604  [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS             C:\Windows\system32\vssvc.exe
15:21:49.0234 7604  VSS - ok
15:21:49.0255 7604  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
15:21:49.0292 7604  vwifibus - ok
15:21:49.0312 7604  [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
15:21:49.0372 7604  vwififlt - ok
15:21:49.0389 7604  [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp         C:\Windows\system32\DRIVERS\vwifimp.sys
15:21:49.0409 7604  vwifimp - ok
15:21:49.0537 7604  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time         C:\Windows\system32\w32time.dll
15:21:49.0572 7604  W32Time - ok
15:21:49.0608 7604  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
15:21:49.0631 7604  WacomPen - ok
15:21:49.0680 7604  [ 356AFD78A6ED4457169241AC3965230C ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
15:21:49.0722 7604  WANARP - ok
15:21:49.0746 7604  [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
15:21:49.0775 7604  Wanarpv6 - ok
15:21:49.0946 7604  [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc     C:\Windows\system32\Wat\WatAdminSvc.exe
15:21:49.0998 7604  WatAdminSvc - ok
15:21:50.0097 7604  [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine        C:\Windows\system32\wbengine.exe
15:21:50.0172 7604  wbengine - ok
15:21:50.0186 7604  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
15:21:50.0205 7604  WbioSrvc - ok
15:21:50.0224 7604  [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc         C:\Windows\System32\wcncsvc.dll
15:21:50.0253 7604  wcncsvc - ok
15:21:50.0267 7604  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
15:21:50.0294 7604  WcsPlugInService - ok
15:21:50.0318 7604  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows\system32\drivers\wd.sys
15:21:50.0328 7604  Wd - ok
15:21:50.0359 7604  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
15:21:50.0380 7604  Wdf01000 - ok
15:21:50.0391 7604  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
15:21:50.0461 7604  WdiServiceHost - ok
15:21:50.0464 7604  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost   C:\Windows\system32\wdi.dll
15:21:50.0480 7604  WdiSystemHost - ok
15:21:50.0514 7604  [ 94DC2BF6CBAAA95E369C3756D3115A76 ] wdkmd           C:\Windows\system32\DRIVERS\WDKMD.sys
15:21:50.0523 7604  wdkmd - ok
15:21:50.0539 7604  [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient       C:\Windows\System32\webclnt.dll
15:21:50.0568 7604  WebClient - ok
15:21:50.0581 7604  [ C749025A679C5103E575E3B48E092C43 ] Wecsvc          C:\Windows\system32\wecsvc.dll
15:21:50.0621 7604  Wecsvc - ok
15:21:50.0633 7604  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
15:21:50.0663 7604  wercplsupport - ok
15:21:50.0685 7604  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows\System32\WerSvc.dll
15:21:50.0714 7604  WerSvc - ok
15:21:50.0740 7604  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
15:21:50.0768 7604  WfpLwf - ok
15:21:50.0779 7604  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
15:21:50.0790 7604  WIMMount - ok
15:21:50.0811 7604  WinDefend - ok
15:21:50.0827 7604  WinHttpAutoProxySvc - ok
15:21:50.0866 7604  [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
15:21:50.0899 7604  Winmgmt - ok
15:21:50.0949 7604  [ BCB1310604AA415C4508708975B3931E ] WinRM           C:\Windows\system32\WsmSvc.dll
15:21:51.0024 7604  WinRM - ok
15:21:51.0101 7604  [ FE88B288356E7B47B74B13372ADD906D ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
15:21:51.0127 7604  WinUsb - ok
15:21:51.0150 7604  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc         C:\Windows\System32\wlansvc.dll
15:21:51.0183 7604  Wlansvc - ok
15:21:51.0261 7604  [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc         C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
15:21:51.0293 7604  wlidsvc - ok
15:21:51.0314 7604  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi         C:\Windows\system32\DRIVERS\wmiacpi.sys
15:21:51.0333 7604  WmiAcpi - ok
15:21:51.0362 7604  [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
15:21:51.0386 7604  wmiApSrv - ok
15:21:51.0412 7604  WMPNetworkSvc - ok
15:21:51.0446 7604  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
15:21:51.0468 7604  WPCSvc - ok
15:21:51.0480 7604  [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
15:21:51.0494 7604  WPDBusEnum - ok
15:21:51.0514 7604  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
15:21:51.0543 7604  ws2ifsl - ok
15:21:51.0553 7604  [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc          C:\Windows\System32\wscsvc.dll
15:21:51.0577 7604  wscsvc - ok
15:21:51.0579 7604  WSearch - ok
15:21:51.0654 7604  [ 1D448834EBAEB2D99AE7C6634B8D17BE ] WTGService      C:\Program Files (x86)\3DataManager\WTGService.exe
15:21:51.0668 7604  WTGService - ok
15:21:51.0730 7604  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
15:21:51.0798 7604  wuauserv - ok
15:21:51.0813 7604  [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
15:21:51.0853 7604  WudfPf - ok
15:21:51.0880 7604  [ CF8D590BE3373029D57AF80914190682 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
15:21:51.0920 7604  WUDFRd - ok
15:21:51.0940 7604  [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
15:21:51.0969 7604  wudfsvc - ok
15:21:51.0987 7604  [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc         C:\Windows\System32\wwansvc.dll
15:21:52.0017 7604  WwanSvc - ok
15:21:52.0069 7604  [ 2EE48CFCE7CA8E0DB4C44C7476C0943B ] xusb21          C:\Windows\system32\DRIVERS\xusb21.sys
15:21:52.0091 7604  xusb21 - ok
15:21:52.0107 7604  ================ Scan global ===============================
15:21:52.0128 7604  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
15:21:52.0151 7604  [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
15:21:52.0158 7604  [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
15:21:52.0180 7604  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
15:21:52.0199 7604  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
15:21:52.0202 7604  [Global] - ok
15:21:52.0202 7604  ================ Scan MBR ==================================
15:21:52.0217 7604  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
15:21:52.0554 7604  \Device\Harddisk0\DR0 - ok
15:21:52.0554 7604  ================ Scan VBR ==================================
15:21:52.0556 7604  [ 6A04F76CB68F5227E246BFDC390B6533 ] \Device\Harddisk0\DR0\Partition1
15:21:52.0557 7604  \Device\Harddisk0\DR0\Partition1 - ok
15:21:52.0594 7604  [ 9268F4807D984E0850A43089F572BF04 ] \Device\Harddisk0\DR0\Partition2
15:21:52.0596 7604  \Device\Harddisk0\DR0\Partition2 - ok
15:21:52.0596 7604  ============================================================
15:21:52.0596 7604  Scan finished
15:21:52.0596 7604  ============================================================
15:21:52.0603 7580  Detected object count: 2
15:21:52.0603 7580  Actual detected object count: 2
15:22:07.0263 7580  IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
15:22:07.0263 7580  IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip 
15:22:07.0264 7580  NILM License Manager ( UnsignedFile.Multi.Generic ) - skipped by user
15:22:07.0264 7580  NILM License Manager ( UnsignedFile.Multi.Generic ) - User select action: Skip
         

Alt 11.09.2012, 20:52   #22
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 11.09.2012, 21:32   #23
ChrisK7
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Fertig. Hier das Log-File von ComboFix:

Code:
ATTFilter
ComboFix 12-09-11.02 - Christian 11.09.2012  22:19:45.1.8 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.43.1031.18.8086.6194 [GMT 2:00]
ausgeführt von:: c:\users\Christian\Desktop\ComboFix.exe
AV: McAfee  Anti-Virus und Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee  Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee  Anti-Virus und Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\nud0repor.pad
c:\programdata\Roaming
c:\users\Christian\AppData\Local\assembly\tmp
c:\users\Christian\GoToAssistDownloadHelper.exe
c:\windows\SysWow64\FlashPlayerInstaller.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-08-11 bis 2012-09-11  ))))))))))))))))))))))))))))))
.
.
2012-09-11 20:26 . 2012-09-11 20:26	--------	d-----w-	c:\users\UpdatusUser.Christian-PC\AppData\Local\temp
2012-09-11 20:26 . 2012-09-11 20:26	--------	d-----w-	c:\users\Default\AppData\Local\temp
2012-09-10 19:41 . 2012-09-10 19:41	--------	d-----w-	C:\_OTL
2012-09-06 08:19 . 2012-09-06 08:19	--------	d-----w-	c:\program files (x86)\ESET
2012-09-05 07:31 . 2012-09-05 07:31	--------	d-----w-	c:\users\Christian\AppData\Roaming\Malwarebytes
2012-09-05 07:30 . 2012-09-05 07:30	--------	d-----w-	c:\programdata\Malwarebytes
2012-09-05 07:30 . 2012-07-03 11:46	24904	----a-w-	c:\windows\system32\drivers\mbam.sys
2012-09-05 07:30 . 2012-09-05 07:31	--------	d-----w-	c:\program files (x86)\Malwarebytes' Anti-Malware
2012-08-16 07:01 . 2012-07-06 20:07	552960	----a-w-	c:\windows\system32\drivers\bthport.sys
2012-08-15 18:20 . 2012-05-05 08:36	503808	----a-w-	c:\windows\system32\srcore.dll
2012-08-15 18:20 . 2012-05-05 07:46	43008	----a-w-	c:\windows\SysWow64\srclient.dll
2012-08-15 18:19 . 2012-02-11 06:43	751104	----a-w-	c:\windows\system32\win32spl.dll
2012-08-15 18:19 . 2012-02-11 06:36	559104	----a-w-	c:\windows\system32\spoolsv.exe
2012-08-15 18:19 . 2012-02-11 06:36	67072	----a-w-	c:\windows\splwow64.exe
2012-08-15 18:19 . 2012-02-11 05:43	492032	----a-w-	c:\windows\SysWow64\win32spl.dll
2012-08-15 18:19 . 2012-07-04 22:16	73216	----a-w-	c:\windows\system32\netapi32.dll
2012-08-15 18:19 . 2012-07-04 22:13	59392	----a-w-	c:\windows\system32\browcli.dll
2012-08-15 18:19 . 2012-07-04 22:13	136704	----a-w-	c:\windows\system32\browser.dll
2012-08-15 18:19 . 2012-07-04 21:14	41984	----a-w-	c:\windows\SysWow64\browcli.dll
2012-08-15 18:18 . 2012-07-18 18:15	3148800	----a-w-	c:\windows\system32\win32k.sys
2012-08-15 18:18 . 2012-05-14 05:26	956928	----a-w-	c:\windows\system32\localspl.dll
2012-08-13 11:35 . 2012-08-13 11:35	5115584	----a-w-	c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-20 09:10 . 2012-04-04 10:51	426184	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-20 09:10 . 2012-02-20 21:27	70344	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-15 22:37 . 2012-02-20 20:54	62134624	----a-w-	c:\windows\system32\MRT.exe
2012-07-12 15:13 . 2012-05-08 20:19	405144	----a-w-	c:\windows\SysWow64\Newtonsoft.Json.Net20.dll
2012-07-05 16:32 . 2012-07-05 16:32	268720	----a-w-	c:\windows\system32\javaws.exe
2012-07-05 16:32 . 2012-07-05 16:32	189360	----a-w-	c:\windows\system32\javaw.exe
2012-07-05 16:32 . 2012-07-05 16:32	188840	----a-w-	c:\windows\system32\java.exe
2012-07-05 16:32 . 2012-04-25 17:20	955840	----a-w-	c:\windows\system32\npdeployJava1.dll
2012-07-05 16:32 . 2012-02-20 18:39	839096	----a-w-	c:\windows\system32\deployJava1.dll
2012-06-29 06:27 . 2012-04-02 19:58	43520	----a-w-	c:\windows\SysWow64\CmdLineExt03.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-12 138096]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2012-08-04 1353080]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-07-13 17418928]
"MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-01-12 283160]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-21 1675160]
"RemoteControl9"="c:\program files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [2010-10-01 87336]
"PDVD9LanguageShortcut"="c:\program files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [2010-09-17 50472]
"BDRegion"="c:\program files (x86)\Cyberlink\Shared Files\brs.exe" [2011-08-11 75048]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942]
"AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-05-30 885760]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-10-01 640376]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280]
"NI Background Service"="c:\program files (x86)\National Instruments\Shared\Update Service\niupdate.exe" [2010-08-10 77824]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-18 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-07 421776]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Windchill ProductPoint Client Manager.lnk - c:\windows\Installer\{371E8B48-2AF1-491B-8F35-BD60D18CB927}\PPS.ico [2012-4-12 7782]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages	REG_MULTI_SZ   	kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 CLKMSVC10_9EC60124;CyberLink Product - 2012/02/20 20:27;c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2011-08-11 248304]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-01 2348352]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-07-24 114560]
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2011-01-28 225216]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-02-22 100912]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2011-08-02 22528]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2012-01-17 188224]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2012-04-02 147248]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-03-17 68440]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2012-02-20 1255736]
R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R4 MSSQLServerADHelper100;SQL Server Hilfsdienst für Active Directory;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-21 61976]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]
R4 SQLAgent$SQLEXPRESS;SQL Server-Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-02-22 289664]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2012-03-01 28992]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 75936]
S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys [2012-03-01 249152]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2012-04-02 224048]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2012-04-02 130864]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-12 13336]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-03-20 210584]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-03-20 162192]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-29 382272]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280]
S2 WTGService;WTGService;c:\program files (x86)\3DataManager\WTGService.exe [2009-10-12 312784]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-11-15 327168]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-02-22 65264]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-01-20 176096]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2011-05-18 47616]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-06-08 283200]
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-12-09 60416]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-02-22 487296]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2010-12-21 8505856]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-11-19 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-11-19 181248]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416]
S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [2010-07-02 29288]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2012-04-02 166192]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [2010-12-01 42392]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 31128341
*Deregistered* - 31128341
*Deregistered* - CLKMDRV10_9EC60124
*Deregistered* - mfeavfk01
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-05 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2205288494-3300817759-3993977911-1000Core.job
- c:\users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-29 07:25]
.
2012-09-11 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2205288494-3300817759-3993977911-1000UA.job
- c:\users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-29 07:25]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-01-18 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-01-18 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-01-18 417304]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-17 1933584]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2010-12-14 6561384]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-12-10 2186856]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2011-01-25 4479648]
"Stage Remote"="c:\program files (x86)\Dell\Stage Remote\StageRemote.exe" [2011-08-08 2034752]
"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-05-30 2055816]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.at/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>;*.local
IE: An OneNote s&enden - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: Free YouTube Download - c:\users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
Trusted Zone: oracle.com\ilearning
TCP: DhcpNameServer = 192.168.1.1
Handler: gmx - {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - 
FF - ProfilePath - c:\users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\bzpwl7d1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.at/
FF - prefs.js: network.proxy.type - 0
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-BattlEye - c:\program files (x86)\Bohemia Interactive\ArmA 2 Operation ArrowheadExpansion\BattlEye\UnInstallBE.exe
AddRemove-BattlEye A2 Free - c:\program files (x86)\Bohemia Interactive\ArmA 2 FreeBattlEye\UnInstallBE.exe
AddRemove-Call of Duty Modern Warfare 2_is1 - c:\program files (x86)\Activision\Modern Warfare 2\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-09-11  22:28:51
ComboFix-quarantined-files.txt  2012-09-11 20:28
.
Vor Suchlauf: 14 Verzeichnis(se), 244.549.480.448 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 244.182.171.648 Bytes frei
.
- - End Of File - - F1820A63C14FFDE75B04740AA0584239
         

Alt 11.09.2012, 23:57   #24
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 12.09.2012, 15:39   #25
ChrisK7
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Hat ein bisschen gedauert aber jetzt habe ich alle drei Logs.

Hier das GMER-Log:

Code:
ATTFilter
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-09-12 16:16:03
Windows 6.1.7601 Service Pack 1 
Running: dz7wfiqe.exe


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4ceb42085989                      
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4ceb42085989@d82a7e4afc86         0x0F 0x2A 0xDF 0xC1 ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4ceb42085989 (not active ControlSet)  
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4ceb42085989@d82a7e4afc86             0x0F 0x2A 0xDF 0xC1 ...

---- EOF - GMER 1.0.15 ----
         
Hier das OSAM-Log:

Code:
ATTFilter
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 16:21:03 on 12.09.2012

OS: Windows 7 Ultimate Edition Service Pack 1 (Build 7601), 64-bit
Default Browser: Microsoft Corporation Internet Explorer 9.00.8112.16421

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"FacebookUpdateTaskUserS-1-5-21-2205288494-3300817759-3993977911-1000Core.job" - "Facebook Inc." - C:\Users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe
"FacebookUpdateTaskUserS-1-5-21-2205288494-3300817759-3993977911-1000UA.job" - "Facebook Inc." - C:\Users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe

[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\MLCFG32.CPL
"QuickTime" - "Apple Inc." - C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"Hamachi Network Interface" (hamachi) - "LogMeIn, Inc." - C:\Windows\System32\DRIVERS\hamachi.sys
"McAfee Inc." (mfeavfk01) - ? - C:\Windows\system32\drivers\mfeavfk01.sys  (File not found)
"Performance Tools Driver 10.0" (VSPerfDrv100) - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys
"VGPU" (VGPU) - ? - C:\Windows\System32\drivers\rdvgkmd.sys  (File not found)

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{3EF5086B-5478-4598-A054-786C45D75692} "McInternetProtocolRoot Class" - "McAfee, Inc." - c:\progra~2\mcafee\msc\mcsniepl.dll
{807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{8FAF0273-9CA8-4efc-9536-1E35E254D5CD} "GMX NewTab Protocol" - ? - C:\Program Files (x86)\GMX Toolbar\IE\uitb.dll  (File not found)
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} "Acrobat Elements Context Menu" - "Adobe Systems Inc." - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat Elements\ContextMenu.dll
{3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D} "Arbeitsbereiche" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
{D66DC78C-4F61-447F-942B-3FB6980118CF} "CInfoTipShellExt Class" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\VISSHE.DLL
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
{506F4668-F13E-4AA1-BB04-B43203AB3CC0} "ImageExtractorShellExt Class" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\VISSHE.DLL
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{0875DCB6-C686-4243-9432-ADCCF0B9F2D7} "Microsoft OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONFILTER.DLL
{00020D75-0000-0000-C000-000000000046} "Microsoft Outlook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\MLSHEXT.DLL
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\OLKFSTUB.DLL
{CB7EB523-76DC-4A1B-81C6-46DAABE5AC31} "PTC Umgebung" - "Parametric Technology Corporation" - C:\Program Files (x86)\PTC\'PTC Places' Namespace Shell Extension\ptcnse.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -   (File not found | COM-object registry key not found)
ITBar7Height64 "ITBar7Height64" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout64" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} "A9Helper.A9" - ? - C:\Windows\Downloaded Program Files\A9.ocx / file:///D:/components/A9.ocx
{C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} "DellSystemLite.Scanner" - ? - C:\Windows\Downloaded Program Files\DellSystemLite.ocx / hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
{22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} "HidInputMonitorX Control" - "TODO: <Company name>" - C:\Windows\DOWNLO~1\HIDINP~1.OCX / file:///D:/components/hidinputmonitorx.ocx
{C3F79A2B-B9B4-4A66-B012-3EE46475B072} "MessengerStatsClient Class" - "Microsoft Corporation" - C:\Windows\Downloaded Program Files\MessengerStatsPAClient.dll / hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
{7530BFB8-7293-4D34-9923-61A11451AFC5} "OnlineScanner Control" - "ESET" - C:\PROGRA~2\ESET\ESETON~1\ONLINE~1.OCX / hxxp://download.eset.com/special/eos/OnlineScanner.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\SysWOW64\Macromed\Flash\Flash32_11_3_300_271.ocx / hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
{E6F480FC-BD44-4CBA-B74A-89AF7842937D} "SysInfo Class" - "Husdawg, LLC" - C:\Program Files (x86)\SystemRequirementsLab\srldetect_cyri_4.5.1.0.dll / hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.5.1.0.cab
{1E54D648-B804-468d-BC78-4AFFED8E262F} "System Requirements Lab Class" - "Husdawg, LLC" - C:\Windows\Downloaded Program Files\sysreqlab_nvd.dll / hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
{7030CC6C-1A88-4591-BB5A-651B9F7F0C30} "WMVHDRatingCtrl Class" - ? - C:\Windows\Downloaded Program Files\wmvhdrating.ocx / file:///D:/components/wmvhdrating.ocx
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
{DDA57003-0068-4ed2-9D32-4D1EC707D94D} "Microsoft-Webtestaufzeichnung 10.0-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
{B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
{7DB2D5A0-7241-4E79-B68D-6309F01C5231} "scriptproxy" - "McAfee, Inc." - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120630181840.dll
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID-Anmelde-Hilfsprogramm" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[LSA Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )-----
"Security Packages" - "Microsoft Corp." - C:\Windows\system32\livessp.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Windchill ProductPoint Client Manager.lnk" - "PTC" - C:\Program Files (x86)\PTC\WindchillSharePointProducts\ClientManager\ProductPointService.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"DAEMON Tools Lite" - "DT Soft Ltd" - "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"Facebook Update" - "Facebook Inc." - "C:\Users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
"MobileDocuments" - "Apple Inc." - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
"Skype" - "Skype Technologies S.A." - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"Steam" - "Valve Corporation" - "C:\Program Files (x86)\Steam\steam.exe" -silent
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"AccuWeatherWidget" - ? - "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup
"Acrobat Assistant 8.0" - "Adobe Systems Inc." - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"BCSSync" - "Microsoft Corporation" - "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
"BDRegion" - "cyberlink" - C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
"Dell Webcam Central" - "Creative Technology Ltd" - "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
"HP Software Update" - "Hewlett-Packard" - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
"IAStorIcon" - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
"iTunesHelper" - "Apple Inc." - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"mcui_exe" - "McAfee, Inc." - "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
"NI Background Service" - "National Instruments" - C:\Program Files (x86)\National Instruments\Shared\Update Service\niupdate.exe
"NUSB3MON" - "Renesas Electronics Corporation" - "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"PDVD9LanguageShortcut" - "CyberLink Corp." - "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
"QuickTime Task" - "Apple Inc." - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
"RemoteControl9" - "CyberLink Corp." - "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Adobe PDF Port Monitor" - "Adobe Systems Inc" - C:\Windows\system32\AdobePDF.dll
"HP Discovery Port Monitor (HP Deskjet 3050 J610 series)" - "Hewlett-Packard Co." - C:\Windows\system32\HPDiscoPM9311.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll  (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe"  (File not found)
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"ASP.NET-Zustandsdienst" (aspnet_state) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
"CyberLink Product - 2012/02/20 20:27:18" (CLKMSVC10_9EC60124) - "CyberLink" - C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
"Intel(R) Management and Security Application Local Management Service" (LMS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
"Intel(R) Management and Security Application User Notification Service" (UNS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
"Intel(R) PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
"Intel(R) PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
"Intel(R) Rapid Storage Technology" (IAStorDataMgrSvc) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
"Intel(R) Turbo Boost Technology Monitor 2.0" (TurboBoost) - "Intel(R) Corporation" - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"Lookout Citadel Server" (LkCitadelServer) - "National Instruments, Inc." - C:\Windows\SysWOW64\lkcitdl.exe
"McAfee Activation Service" (McAWFwk) - "McAfee, Inc." - c:\PROGRA~1\mcafee\msc\mcawfwk.exe
"McAfee Anti-Spam Service" (MSK80Service) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
"McAfee Firewall Core Service" (mfefire) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
"McAfee McShield" (McShield) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
"McAfee Network Agent" (McNASvc) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
"McAfee Personal Firewall Service" (McMPFSvc) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
"McAfee Proxy Service" (McProxy) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
"McAfee Scanner" (McODS) - "McAfee, Inc." - C:\Program Files\McAfee\VirusScan\mcods.exe
"McAfee Services" (mcmscsvc) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
"McAfee Validation Trust Protection Service" (mfevtp) - "McAfee, Inc." - C:\Windows\system32\mfevtps.exe
"McAfee VirusScan Announcer" (McNaiAnn) - "McAfee, Inc." - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft SharePoint Workspace Audit Service" (Microsoft SharePoint Workspace Audit Service) - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE
"National Instruments Domain Service" (NIDomainService) - "National Instruments Corporation" - C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe
"National Instruments PSP Server Locator" (lkClassAds) - "National Instruments Corporation" - C:\Windows\SysWOW64\lkads.exe
"National Instruments Time Synchronization" (lkTimeSync) - "National Instruments Corporation" - C:\Windows\SysWOW64\lktsrv.exe
"NI Service Locator" (niSvcLoc) - "National Instruments Corporation" - C:\Windows\SysWOW64\nisvcloc.exe
"NVIDIA Display Driver Service" (NVSvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe
"NVIDIA Stereoscopic 3D Driver Service" (Stereo Service) - "NVIDIA Corporation" - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
"NVIDIA Update Service Daemon" (nvUpdatusService) - "NVIDIA Corporation" - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
"Office  Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"PnkBstrA" (PnkBstrA) - ? - C:\Windows\system32\PnkBstrA.exe  (File not found)
"Skype C2C Service" (Skype C2C Service) - "Skype Technologies S.A." - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files (x86)\Skype\Updater\Updater.exe
"SQL Server (SQLEXPRESS)" (MSSQL$SQLEXPRESS) - "Microsoft Corporation" - c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
"SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
"Wireless PAN DHCP Server" (MyWiFiDHCPDNS) - ? - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
"WTGService" (WTGService) - ? - C:\Program Files (x86)\3DataManager\WTGService.exe  (File found, but it contains no detailed information)

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files (x86)\Bonjour\mdnsNSP.dll
"WindowsLive Local NSP" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
"WindowsLive NSP" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
         
Hier das aswMBR-Log (habe das Programm wie in der Anleitung neu starten müssen weil es abgestürzt ist und ich habe den Scan mit der Einstellung "none" neu gestartet):

Code:
ATTFilter
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-12 16:33:37
-----------------------------
16:33:37.380    OS Version: Windows x64 6.1.7601 Service Pack 1
16:33:37.380    Number of processors: 8 586 0x2A07
16:33:37.381    ComputerName: CHRISTIAN-PC  UserName: Christian
16:33:48.511    Initialize success
16:33:54.201    AVAST engine defs: 12091200
16:33:58.455    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
16:33:58.457    Disk 0 Vendor: ST975042 0002 Size: 715404MB BusType: 3
16:33:58.518    Disk 0 MBR read successfully
16:33:58.521    Disk 0 MBR scan
16:33:58.527    Disk 0 Windows 7 default MBR code
16:33:58.540    Disk 0 Partition 1 00     DE Dell Utility Dell 8.0      101 MB offset 63
16:33:58.550    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        20000 MB offset 212992
16:33:58.565    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       695299 MB offset 41172992
16:33:58.588    Disk 0 scanning C:\Windows\system32\drivers
16:34:18.491    Service scanning
16:34:48.073    Modules scanning
16:34:48.088    Disk 0 trace - called modules:
16:34:48.101    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll 
16:34:48.106    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8009711060]
16:34:48.111    3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa8007761d10]
16:34:48.115    5 ACPI.sys[fffff88000f3b7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007765050]
16:34:48.119    Scan finished successfully
16:36:18.108    Disk 0 MBR has been saved successfully to "C:\Users\Christian\Desktop\MBR.dat"
16:36:18.115    The log file has been saved successfully to "C:\Users\Christian\Desktop\aswMBR.txt"
         

Alt 12.09.2012, 18:50   #26
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 13.09.2012, 09:54   #27
ChrisK7
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Noch eine kurze Frage bevor ich die Scans mache. Seit ich gestern die drei Logs gemacht habe stockt mein Laptop bei Spielen die vorher total flüssig gelaufen sind. Auch die Videoqualität bei meinen Filmen ist jetzt nicht mehr so gut.
Kann das mit den Scans zusammenhängen? Denn zuvor hatte ich keinerlei Probleme.

Alt 13.09.2012, 20:08   #28
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Mach bitte erst die Logs. Wenn wir durch sind kümmern wir uns um die anderen Probleme.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 13.09.2012, 23:53   #29
ChrisK7
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Ok, hier die beiden Logs:

Malwarebytes Anti-Malware :

Code:
ATTFilter
Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.13.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Christian :: CHRISTIAN-PC [Administrator]

13.09.2012 18:11:06
mbam-log-2012-09-13 (18-11-06).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 619648
Laufzeit: 3 Stunde(n), 10 Minute(n), 4 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         

SUPERAntiSpyware Scan Log:

Code:
ATTFilter
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/14/2012 at 00:45 AM

Application Version : 5.5.1016

Core Rules Database Version : 9223
Trace Rules Database Version: 7035

Scan type       : Complete Scan
Total Scan Time : 03:15:58

Operating System Information
Windows 7 Ultimate 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Administrator

Memory items scanned      : 874
Memory threats detected   : 0
Registry items scanned    : 69261
Registry threats detected : 0
File items scanned        : 375487
File threats detected     : 377

Adware.Tracking Cookie
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\PKTK2D0V.txt [ /track.adform.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\MUJ6TNE3.txt [ /accounts.google.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\SM34FID4.txt [ /smartadserver.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\Y98W62WV.txt [ /tradedoubler.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\MAAQ83V7.txt [ /specificclick.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\5YCFISSO.txt [ /questionmarket.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\QPT4F37Y.txt [ /ad2.adfarm1.adition.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\OTNAPD34.txt [ /amazon-adsystem.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\ED55MXLJ.txt [ /ad.zanox.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\I70RFZQW.txt [ /revsci.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\70CG3B0Y.txt [ /ar.atwola.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\LCNWSZJ1.txt [ /msnportal.112.2o7.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\U1V4X8NO.txt [ /ad.adc-serv.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\33JS0SIV.txt [ /casalemedia.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\L3J9JXQO.txt [ /microsoftwllivemkt.112.2o7.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\HJ2DNVL6.txt [ /zanox.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\SOHBTAYQ.txt [ /splash.trackmania.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\LT5WUSHC.txt [ /mediaplex.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\75MTCAJ1.txt [ /advertising.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\A51CO6US.txt [ /ad1.adfarm1.adition.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\0626V712.txt [ /invitemedia.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\0HSPAGQQ.txt [ /eas.apm.emediate.eu ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\TMZSH5LI.txt [ /c.atdmt.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\2RK3JUT2.txt [ /tracker.vinsight.de ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\KO7QF06L.txt [ /tracking.quisma.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\JVSVL6O0.txt [ /maniapub.trackmania.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\QD6W3263.txt [ /apmebf.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\O4X1A6H2.txt [ /estat.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\IB7BZN0I.txt [ /ads.creative-serving.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\PUAAKE99.txt [ /highbeam.122.2o7.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\AWT28XF4.txt [ /tacoda.at.atwola.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\ADSUZ6HJ.txt [ /kontera.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\BY0QWXXJ.txt [ /adbrite.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\GTTWCXI0.txt [ /conrad.122.2o7.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\E2W0THS6.txt [ /adtech.de ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\6BK4W16Q.txt [ /de-fourmedia.videoplaza.tv ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\KG4K84NU.txt [ /webmasterplan.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\GK1P8QKI.txt [ /px.steelhousemedia.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\L7E2ZPUZ.txt [ /ad.yieldmanager.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\T70D1UK7.txt [ /e-2dj6wjmikncpgdq.stats.esomniture.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\E48IYZO1.txt [ /media6degrees.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\7QXG1A4I.txt [ /imrworldwide.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\LK4NCCB4.txt [ /ad4.adfarm1.adition.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\4BA9OZOG.txt [ /ad3.adfarm1.adition.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\L64GFAMH.txt [ /tradetracker.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\BFCNEM8H.txt [ /adfarm1.adition.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\TDQNTMXQ.txt [ /at.atwola.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\XGG12GAP.txt [ /doubleclick.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\TEWF5TN5.txt [ /ad.360yield.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\4L6X5QOU.txt [ /atdmt.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\0L8I96FW.txt [ /bs.serving-sys.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\UUQG7KJS.txt [ /im.banner.t-online.de ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\ZE6SMRE9.txt [ /serving-sys.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\5OSGKT49.txt [ /partners.webmasterplan.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\JD8D55X6.txt [ /2o7.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\6YFE43RP.txt [ /statse.webtrendslive.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\ED6LURD3.txt [ /adform.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\PUJ4Y68E.txt [ /fastclick.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\15UENQ3R.txt [ /collective-media.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\98PWVKBB.txt [ /ww251.smartadserver.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\MXVB93CT.txt [ /www.googleadservices.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\33C3NXDT.txt [ /www.googleadservices.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\C3PO5G5T.txt [ /ad.ad-srv.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\H9M5HZPJ.txt [ /steelhousemedia.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\7QEY8323.txt [ /ad.adnet.de ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\9XX22DWD.txt [ /etargetnet.com ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\IMTFGO1N.txt [ /edsa.122.2o7.net ]
	C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Cookies\2FF49X6Q.txt [ /eaeacom.112.2o7.net ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\5U7BCW4U.txt [ Cookie:christian@clkads.com/adServe ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\BI68553W.txt [ Cookie:christian@clkads.com/adServe/banners ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\15FKWLDM.txt [ Cookie:christian@fastclick.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\KOFUZ4C8.txt [ Cookie:christian@track.adform.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\GEXNXCR0.txt [ Cookie:christian@tradedoubler.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Q01GH0GM.txt [ Cookie:christian@specificclick.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\HFTWN6ZB.txt [ Cookie:christian@liveperson.net/hc/42179880 ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\IH4RZK73.txt [ Cookie:christian@eas4.emediate.eu/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\VRP5PBGN.txt [ Cookie:christian@server.adform.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\P0RB7T4N.txt [ Cookie:christian@ad2.adfarm1.adition.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\X7H2Q5B7.txt [ Cookie:christian@liveperson.net/hc/82753263 ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\XF1JN7PM.txt [ Cookie:christian@collective-media.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\NZRYW2U2.txt [ Cookie:christian@amazon-adsystem.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\FO8BBJLA.txt [ Cookie:christian@ad.zanox.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\6NNFW8ED.txt [ Cookie:christian@clkads.com/adServe ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\SBS6RPXV.txt [ Cookie:christian@zedo.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\OX1DOWDJ.txt [ Cookie:christian@revsci.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\FV7HX27A.txt [ Cookie:christian@fangatemedia.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\7EN5Z5WD.txt [ Cookie:christian@tribalfusion.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\D31EHRFI.txt [ Cookie:christian@ad.dyntracker.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\QZZUKZ9Q.txt [ Cookie:christian@zanox.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\3VKKUMS7.txt [ Cookie:christian@advertising.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\BORCNUVM.txt [ Cookie:christian@yadro.ru/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\1XSUP9YX.txt [ Cookie:christian@invitemedia.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MPUHC13H.txt [ Cookie:christian@c.atdmt.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\4NIB619M.txt [ Cookie:christian@server.lon.liveperson.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\J17K7E29.txt [ Cookie:christian@tracking.quisma.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\SVQDGE57.txt [ Cookie:christian@clkads.com/adServe/banners ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\QS3CI1DR.txt [ Cookie:christian@moviepilot.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Y4IYED06.txt [ Cookie:christian@kontera.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MTUH7HNE.txt [ Cookie:christian@liveperson.net/hc/17387962 ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YP94HWJW.txt [ Cookie:christian@adserver.adreactor.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\5E5SKGI2.txt [ Cookie:christian@tracking.oe24.at// ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZOEKAYK8.txt [ Cookie:christian@lucidmedia.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\94E3B83B.txt [ Cookie:christian@adtech.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\0NSUDCFN.txt [ Cookie:christian@ad.yieldmanager.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\IXT8UT6F.txt [ Cookie:christian@ox-d.sublimemedia.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\LG4P2HL6.txt [ Cookie:christian@clicksor.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\OTMFXQ4C.txt [ Cookie:christian@c1.atdmt.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\PRN2RZM3.txt [ Cookie:christian@media6degrees.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\QZK5CJGP.txt [ Cookie:christian@imrworldwide.com/cgi-bin ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZR1COMNC.txt [ Cookie:christian@myroitracking.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MMGQVVSW.txt [ Cookie:christian@www.etracker.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZKTIQQ2V.txt [ Cookie:christian@ad4.adfarm1.adition.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\PAJG4YE0.txt [ Cookie:christian@adx.chip.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\JX0HPDJJ.txt [ Cookie:christian@ad3.adfarm1.adition.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\1KEQ7V64.txt [ Cookie:christian@at.atwola.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\X9HELXIY.txt [ Cookie:christian@adfarm1.adition.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\QD2RZ8FZ.txt [ Cookie:christian@doubleclick.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\2JE1NZGE.txt [ Cookie:christian@atdmt.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\AS3Z0HQ9.txt [ Cookie:christian@bs.serving-sys.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\5YOZQOP1.txt [ Cookie:christian@statse.webtrendslive.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\SQ7D2HV1.txt [ Cookie:christian@liveperson.net/hc/13554660 ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\X67V9MOX.txt [ Cookie:christian@adform.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\1ITAVZVG.txt [ Cookie:christian@zanox-affiliate.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZH2NAB6L.txt [ Cookie:christian@quartermedia.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\BUUY7ULT.txt [ Cookie:christian@counter.hitslink.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\GUSPYR41.txt [ Cookie:christian@in.getclicky.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Y2J9RW5V.txt [ Cookie:christian@accounts.google.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\FW3PIFMP.txt [ Cookie:christian@adsonar.com/adserving ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\631HTEYG.txt [ Cookie:christian@questionmarket.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\2QD5G717.txt [ Cookie:christian@ww251.smartadserver.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\6H758SM2.txt [ Cookie:christian@ar.atwola.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\TPTO8S86.txt [ Cookie:christian@rambler.ru/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Z1WZLJA5.txt [ Cookie:christian@ad1.adfarm1.adition.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\QUAP7GJO.txt [ Cookie:christian@traffictrack.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\C9Y3VSW7.txt [ Cookie:christian@ru4.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\TN0U7H3W.txt [ Cookie:christian@www.moviepilot.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MS9OSUED.txt [ Cookie:christian@overture.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\KDH1UL9X.txt [ Cookie:christian@uk.sitestat.com/future/techradar/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\OLB1JVSN.txt [ Cookie:christian@adbrite.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\UCVEVWAU.txt [ Cookie:christian@interclick.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\SRJB2JXX.txt [ Cookie:christian@callofduty.4players.de/board1-callofdutyseries-de-news-fragen-und-fehler/board23-news-von-unseren-redakteuren-f%C3%BCr-user/4490-call-of-duty-modern-warfare-2-neuer-multiplayer-crack-im-umlauf/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\IVAAE4TJ.txt [ Cookie:christian@webresint.122.2o7.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\V84I9RYW.txt [ Cookie:christian@mm.chitika.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\6EZ7NB20.txt [ Cookie:christian@edsa.122.2o7.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\6L4GHKGG.txt [ Cookie:christian@de.sitestat.com/idgcom-de/gamestar/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\3AUTCNLP.txt [ Cookie:christian@livestat.derstandard.at/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\UIJEQVEQ.txt [ Cookie:christian@ero-advertising.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\A0IDZCI8.txt [ Cookie:christian@www.mediamarkt.at/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\86P5Y2BQ.txt [ Cookie:christian@www.tunefind.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\PAHLP23X.txt [ Cookie:christian@www.trafficjmp.com/conversion ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\9HLVNVW6.txt [ Cookie:christian@stat.kk-bits.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Q2KQK3IA.txt [ Cookie:christian@ads.pointroll.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\6E6D0O17.txt [ Cookie:christian@adsby.webtraffic.se/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\PAOAL659.txt [ Cookie:christian@2o7.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\W9GPYOVE.txt [ Cookie:christian@content.yieldmanager.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\G5UAL0AJ.txt [ Cookie:christian@guj.122.2o7.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\GGMZQ2F9.txt [ Cookie:christian@www.gotgayporn.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MVVAWR7B.txt [ Cookie:christian@ox.9livesmediainc.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\5UK7AAI5.txt [ Cookie:christian@server.cpmstar.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\310OF6KO.txt [ Cookie:christian@realmedia.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\FFQ0Y4NX.txt [ Cookie:christian@a.revenuemax.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\K0AOD1HL.txt [ Cookie:christian@premiumtv.122.2o7.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Y80DO0LM.txt [ Cookie:christian@eas.apm.emediate.eu/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\6OJ2D9PX.txt [ Cookie:christian@neckermannde.122.2o7.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\GROKWQQU.txt [ Cookie:christian@adserver.hardtecs.org/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\Q6OZ10ZO.txt [ Cookie:christian@www.learning-languages-online.net/piwik-stats/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\03O59IUX.txt [ Cookie:christian@hitbox.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\CF6TXK3Y.txt [ Cookie:christian@nfm-adserver.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\JD7KMA26.txt [ Cookie:christian@vogelservices.122.2o7.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\JL9JCFW7.txt [ Cookie:christian@unister-adservices.com/campaign/conversion/36 ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\HMGK55JU.txt [ Cookie:christian@www.sexhoundlinks.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YB4YUXYX.txt [ Cookie:christian@www.swoodoo.com/at/ad/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\TIPLIS5S.txt [ Cookie:christian@blogs.mediamarkt.at/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\7PPOC6WO.txt [ Cookie:christian@unister-adservices.com/campaign/conversion/27 ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\S12I47D0.txt [ Cookie:christian@pro-market.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\OP0BCRAC.txt [ Cookie:christian@mtvn.112.2o7.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\JQDFFD8T.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1058785566/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\DO43NAIJ.txt [ Cookie:christian@adxpansion.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\E10DNMZT.txt [ Cookie:christian@adultfriendfinder.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\2GQ4E9Q0.txt [ Cookie:christian@thomascookag.122.2o7.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\JQHCTS24.txt [ Cookie:christian@tracking.surveycheck.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\FIFBV2SZ.txt [ Cookie:christian@cdnw.trafficjmp.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\20CVE3SI.txt [ Cookie:christian@liveperson.net/hc/7074034 ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\ODCGNPGP.txt [ Cookie:christian@de.sitestat.com/idgcom-de/macwelt/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\3U106KP8.txt [ Cookie:christian@media.neodau.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\S56V2RE7.txt [ Cookie:christian@c.gigcount.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\WX7CY6AQ.txt [ Cookie:christian@unister-adservices.com/campaign/conversion/56 ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YR80XT33.txt [ Cookie:christian@de.sitestat.com/idgcom-de/gamepro/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\KVYNOXUS.txt [ Cookie:christian@openstat.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\37TRWOGJ.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1045321740/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\O13DQA0F.txt [ Cookie:christian@toplist.cz/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\W0SB94BW.txt [ Cookie:christian@tracking.eduscho.at/265328718441342/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MR6N4H6P.txt [ Cookie:christian@track.effiliation.com/servlet/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YQPU2WKD.txt [ Cookie:christian@www.mediafire.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\B0I3BI5B.txt [ Cookie:christian@hot-sex-tube.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\OW40M3DO.txt [ Cookie:christian@trafficholder.com/cgi-bin/traffic/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\WHT7EL29.txt [ Cookie:christian@aimfar.solution.weborama.fr/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\7YY7OS78.txt [ Cookie:christian@m1.webstats.motigo.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\34ELTGXZ.txt [ Cookie:christian@games.mediamarkt.at/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\W1Q3G2MG.txt [ Cookie:christian@tunefind.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\BG4NHJ2P.txt [ Cookie:christian@clickbank.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\HDIAY67R.txt [ Cookie:christian@yieldmanager.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YPANZ0CI.txt [ Cookie:christian@server.adformdsp.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\9AJ1NQ9M.txt [ Cookie:christian@7.rotator.wigetmedia.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\LEZMXCZ5.txt [ Cookie:christian@unister-adservices.com/campaign/conversion/8 ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\0RNHV7CA.txt [ Cookie:christian@insightexpressai.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\F33J3OI7.txt [ Cookie:christian@adverts.timesofmalta.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\4LDWMR54.txt [ Cookie:christian@media.funpic.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\DFE1E0BH.txt [ Cookie:christian@linksynergy.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\EOPI1YS8.txt [ Cookie:christian@www.abendblatt.de/ratgeber/multimedia/article2377714/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\79VZP2YL.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1035377488/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\G89EX00N.txt [ Cookie:christian@counters.gigya.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\5EU011JO.txt [ Cookie:christian@e-2dj6wdl4ulczmbp.stats.esomniture.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\1NAOX0J6.txt [ Cookie:christian@adscendmedia.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\L6XTHX5Y.txt [ Cookie:christian@rubitrack.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\DBBZ9TLS.txt [ Cookie:christian@ads.neudesicmediagroup.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\INTSR7YT.txt [ Cookie:christian@liveperson.net/hc/64975841 ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\P6R8GF20.txt [ Cookie:christian@ads2.zeusclicks.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YII4PJER.txt [ Cookie:christian@clickandbuy.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\8UN8HKZX.txt [ Cookie:christian@e-2dj6whkoqkdjwbp.stats.esomniture.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\YWPKKQ74.txt [ Cookie:christian@mediamarkt.at/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\WF3NXHK9.txt [ Cookie:christian@unitymedia.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\NOYQDZT2.txt [ Cookie:christian@track.effiliation.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\DYYBQRZZ.txt [ Cookie:christian@twinkteenboys.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\VTJU3NC3.txt [ Cookie:christian@www.mediashop.tv/DE/waterzoom_1/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\1HMON9TJ.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1070806761/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\W576WQF7.txt [ Cookie:christian@otclick-adv.ru/core ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\XX3HT73U.txt [ Cookie:christian@googleads.g.doubleclick.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\39NT7QAK.txt [ Cookie:christian@legolas-media.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\EK117ZRC.txt [ Cookie:christian@pornhub.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\T0GOS1LD.txt [ Cookie:christian@sub.bubblesmedia.ru/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\VELPP7YI.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1017865890/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\UJAXSZP6.txt [ Cookie:christian@unister-adservices.com/campaign/conversion/22 ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\7D7WE645.txt [ Cookie:christian@histats.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\VED181H4.txt [ Cookie:christian@box1.counter-service.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\U5VRDNMH.txt [ Cookie:christian@track.zalando.at/513072222822788/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\AX2JP301.txt [ Cookie:christian@fl01.ct2.comclick.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\IKKC01R7.txt [ Cookie:christian@exoclick.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\NG2CQGIM.txt [ Cookie:christian@tracker.vinsight.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\E3ZRCAWG.txt [ Cookie:christian@austrianairlines.122.2o7.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\DIV0NF79.txt [ Cookie:christian@spylog.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\VJM63G9J.txt [ Cookie:christian@nikonjp.112.2o7.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\EMB2K6NJ.txt [ Cookie:christian@www.pornhub.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\V17MTVNC.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1071943062/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\E9HCW7TE.txt [ Cookie:christian@www.hxtrack.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\MD00Z29P.txt [ Cookie:christian@officemedia.de/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\J1Z3K8I1.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1072260330/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\8B3U7RLG.txt [ Cookie:christian@eas5.emediate.eu/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\4LQWJ28Y.txt [ Cookie:christian@mediashop.tv/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\OJVAW4C8.txt [ Cookie:christian@sexhoundlinks.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\J5BM21LH.txt [ Cookie:christian@ehg-tfl.hitbox.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\N1N7HHBO.txt [ Cookie:christian@zbox.zanox.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\RD9IWAYJ.txt [ Cookie:christian@liveperson.net/hc/55779702 ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\DN8FXYRT.txt [ Cookie:christian@hearstdigital.122.2o7.net/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\2EBK49L8.txt [ Cookie:christian@adxpose.com/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\TFG6TSZU.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1061703000/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\32BP8A4K.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1023629923/ ]
	C:\USERS\CHRISTIAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\WOR3UK2O.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1067799827/ ]
	C:\USERS\CHRISTIAN\Cookies\PKTK2D0V.txt [ Cookie:christian@track.adform.net/ ]
	C:\USERS\CHRISTIAN\Cookies\MUJ6TNE3.txt [ Cookie:christian@accounts.google.com/ ]
	C:\USERS\CHRISTIAN\Cookies\Y98W62WV.txt [ Cookie:christian@tradedoubler.com/ ]
	C:\USERS\CHRISTIAN\Cookies\MAAQ83V7.txt [ Cookie:christian@specificclick.net/ ]
	C:\USERS\CHRISTIAN\Cookies\5YCFISSO.txt [ Cookie:christian@questionmarket.com/ ]
	C:\USERS\CHRISTIAN\Cookies\QPT4F37Y.txt [ Cookie:christian@ad2.adfarm1.adition.com/ ]
	C:\USERS\CHRISTIAN\Cookies\OTNAPD34.txt [ Cookie:christian@amazon-adsystem.com/ ]
	C:\USERS\CHRISTIAN\Cookies\ED55MXLJ.txt [ Cookie:christian@ad.zanox.com/ ]
	C:\USERS\CHRISTIAN\Cookies\5U7BCW4U.txt [ Cookie:christian@clkads.com/adServe ]
	C:\USERS\CHRISTIAN\Cookies\I70RFZQW.txt [ Cookie:christian@revsci.net/ ]
	C:\USERS\CHRISTIAN\Cookies\70CG3B0Y.txt [ Cookie:christian@ar.atwola.com/ ]
	C:\USERS\CHRISTIAN\Cookies\LCNWSZJ1.txt [ Cookie:christian@msnportal.112.2o7.net/ ]
	C:\USERS\CHRISTIAN\Cookies\HJ2DNVL6.txt [ Cookie:christian@zanox.com/ ]
	C:\USERS\CHRISTIAN\Cookies\SOHBTAYQ.txt [ Cookie:christian@splash.trackmania.com/display/ ]
	C:\USERS\CHRISTIAN\Cookies\75MTCAJ1.txt [ Cookie:christian@advertising.com/ ]
	C:\USERS\CHRISTIAN\Cookies\A51CO6US.txt [ Cookie:christian@ad1.adfarm1.adition.com/ ]
	C:\USERS\CHRISTIAN\Cookies\0626V712.txt [ Cookie:christian@invitemedia.com/ ]
	C:\USERS\CHRISTIAN\Cookies\0HSPAGQQ.txt [ Cookie:christian@eas.apm.emediate.eu/ ]
	C:\USERS\CHRISTIAN\Cookies\TMZSH5LI.txt [ Cookie:christian@c.atdmt.com/ ]
	C:\USERS\CHRISTIAN\Cookies\2RK3JUT2.txt [ Cookie:christian@tracker.vinsight.de/ ]
	C:\USERS\CHRISTIAN\Cookies\KO7QF06L.txt [ Cookie:christian@tracking.quisma.com/ ]
	C:\USERS\CHRISTIAN\Cookies\BI68553W.txt [ Cookie:christian@clkads.com/adServe/banners ]
	C:\USERS\CHRISTIAN\Cookies\JVSVL6O0.txt [ Cookie:christian@maniapub.trackmania.com/banner/ ]
	C:\USERS\CHRISTIAN\Cookies\O4X1A6H2.txt [ Cookie:christian@estat.com/ ]
	C:\USERS\CHRISTIAN\Cookies\PUAAKE99.txt [ Cookie:christian@highbeam.122.2o7.net/ ]
	C:\USERS\CHRISTIAN\Cookies\ADSUZ6HJ.txt [ Cookie:christian@kontera.com/ ]
	C:\USERS\CHRISTIAN\Cookies\BY0QWXXJ.txt [ Cookie:christian@adbrite.com/ ]
	C:\USERS\CHRISTIAN\Cookies\E2W0THS6.txt [ Cookie:christian@adtech.de/ ]
	C:\USERS\CHRISTIAN\Cookies\L7E2ZPUZ.txt [ Cookie:christian@ad.yieldmanager.com/ ]
	C:\USERS\CHRISTIAN\Cookies\E48IYZO1.txt [ Cookie:christian@media6degrees.com/ ]
	C:\USERS\CHRISTIAN\Cookies\7QXG1A4I.txt [ Cookie:christian@imrworldwide.com/cgi-bin ]
	C:\USERS\CHRISTIAN\Cookies\LK4NCCB4.txt [ Cookie:christian@ad4.adfarm1.adition.com/ ]
	C:\USERS\CHRISTIAN\Cookies\4BA9OZOG.txt [ Cookie:christian@ad3.adfarm1.adition.com/ ]
	C:\USERS\CHRISTIAN\Cookies\L64GFAMH.txt [ Cookie:christian@tradetracker.net/ ]
	C:\USERS\CHRISTIAN\Cookies\BFCNEM8H.txt [ Cookie:christian@adfarm1.adition.com/ ]
	C:\USERS\CHRISTIAN\Cookies\TDQNTMXQ.txt [ Cookie:christian@at.atwola.com/ ]
	C:\USERS\CHRISTIAN\Cookies\XGG12GAP.txt [ Cookie:christian@doubleclick.net/ ]
	C:\USERS\CHRISTIAN\Cookies\4L6X5QOU.txt [ Cookie:christian@atdmt.com/ ]
	C:\USERS\CHRISTIAN\Cookies\0L8I96FW.txt [ Cookie:christian@bs.serving-sys.com/ ]
	C:\USERS\CHRISTIAN\Cookies\JD8D55X6.txt [ Cookie:christian@2o7.net/ ]
	C:\USERS\CHRISTIAN\Cookies\6YFE43RP.txt [ Cookie:christian@statse.webtrendslive.com/ ]
	C:\USERS\CHRISTIAN\Cookies\ED6LURD3.txt [ Cookie:christian@adform.net/ ]
	C:\USERS\CHRISTIAN\Cookies\PUJ4Y68E.txt [ Cookie:christian@fastclick.net/ ]
	C:\USERS\CHRISTIAN\Cookies\15UENQ3R.txt [ Cookie:christian@collective-media.net/ ]
	C:\USERS\CHRISTIAN\Cookies\98PWVKBB.txt [ Cookie:christian@ww251.smartadserver.com/ ]
	C:\USERS\CHRISTIAN\Cookies\MXVB93CT.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/1023106454/ ]
	C:\USERS\CHRISTIAN\Cookies\33C3NXDT.txt [ Cookie:christian@www.googleadservices.com/pagead/conversion/978602949/ ]
	C:\USERS\CHRISTIAN\Cookies\IMTFGO1N.txt [ Cookie:christian@edsa.122.2o7.net/ ]
	C:\USERS\CHRISTIAN\Cookies\2FF49X6Q.txt [ Cookie:christian@eaeacom.112.2o7.net/ ]
	delivery.ibanner.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9EXBQXJN ]
	.2o7.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.2o7.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.msnportal.112.2o7.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.amazon-adsystem.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	de.sitestat.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.webmasterplan.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.xiti.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.tradedoubler.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	reztrack.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	adx.chip.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.questionmarket.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	www.netdebit-counter.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	ad2.adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.atdmt.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.c1.atdmt.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.apmebf.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.smartadserver.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.mediaplex.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.adtech.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	ww251.smartadserver.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.revsci.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.serving-sys.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.bs.serving-sys.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.adfarm1.adition.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.fastclick.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	ad.yieldmanager.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.im.banner.t-online.de [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.tracking.quisma.com [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
	.doubleclick.net [ C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BZPWL7D1.DEFAULT\COOKIES.SQLITE ]
         

Alt 14.09.2012, 14:35   #30
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Cyber Crime Investigation Department Österreich - Trojaner - Standard

Cyber Crime Investigation Department Österreich - Trojaner



Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu Cyber Crime Investigation Department Österreich - Trojaner
administrator, anti-malware, antiviren-programm, appdata, autostart, crime, cyber crime, dateien, ergebnis, explorer, firefox, internet, keine verbindung, laptop, malwarebytes, mcafee, microsoft, mozilla, neustart, probleme, scan, software, super, system, temp, trojaner, verbindung, virus, wlan




Ähnliche Themen: Cyber Crime Investigation Department Österreich - Trojaner


  1. Cyber Crime Investigation Department trojaner
    Mülltonne - 01.11.2014 (1)
  2. Cyver Crime Investigation Department (Österreich) Trojaner
    Log-Analyse und Auswertung - 22.01.2013 (3)
  3. Cyber crime investigation department - Trojaner
    Log-Analyse und Auswertung - 13.01.2013 (13)
  4. polizei cyber crime investigation department trojaner
    Log-Analyse und Auswertung - 23.12.2012 (14)
  5. Cyber Crime Investigation Department Österreich
    Plagegeister aller Art und deren Bekämpfung - 01.11.2012 (10)
  6. cyber crime investigation department österreich - virus?
    Log-Analyse und Auswertung - 24.10.2012 (2)
  7. Cyber Crime Investigation Department-Trojaner
    Log-Analyse und Auswertung - 24.10.2012 (19)
  8. Cyber Crime Investigation Department Trojaner
    Plagegeister aller Art und deren Bekämpfung - 07.10.2012 (13)
  9. Cyber Crime Investigation Department Österreich
    Log-Analyse und Auswertung - 05.10.2012 (15)
  10. Trojaner - Cyber Crime Investigation Department
    Plagegeister aller Art und deren Bekämpfung - 28.09.2012 (12)
  11. Trojaner: Cyber crime investigation department
    Plagegeister aller Art und deren Bekämpfung - 24.09.2012 (7)
  12. Trojaner: cyber crime investigation department
    Log-Analyse und Auswertung - 19.09.2012 (10)
  13. Trojaner - Cyber Crime Investigation Department Österreich
    Log-Analyse und Auswertung - 17.09.2012 (12)
  14. cyber crime investigation department polizei österreich
    Plagegeister aller Art und deren Bekämpfung - 14.09.2012 (1)
  15. Cyber Crime Investigation Department Trojaner
    Log-Analyse und Auswertung - 06.09.2012 (12)
  16. Cyber Crime Investigation Department Trojaner
    Log-Analyse und Auswertung - 02.09.2012 (11)
  17. Bitte um Hilfe gegen Virus cyber crime investigation department österreich
    Plagegeister aller Art und deren Bekämpfung - 02.09.2012 (11)

Zum Thema Cyber Crime Investigation Department Österreich - Trojaner - Wieso von der falschen Seite? Wir verlinken unsere Tools automatisch immer auf die richtige Seite! Wenn du aus anderen Quellen lädst kannst du dir wieder Dreck, Toolbars oder richtig fiese - Cyber Crime Investigation Department Österreich - Trojaner...
Archiv
Du betrachtest: Cyber Crime Investigation Department Österreich - Trojaner auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.