Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Windows Security Center Trojaner eingefangen (https://www.trojaner-board.de/112814-windows-security-center-trojaner-eingefangen.html)

cosinus 04.04.2012 11:23

Wiederhol den Fix im abgesicherten Modus bitte

LaurenLaw 04.04.2012 12:59

Code:

All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_USERS\S-1-5-21-806744476-1919467886-1915298580-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D7562AE-8EF6-416d-A838-AB665251703A}\ not found.
Registry key HKEY_USERS\S-1-5-21-806744476-1919467886-1915298580-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_USERS\S-1-5-21-806744476-1919467886-1915298580-1000\Software\Microsoft\Internet Explorer\SearchScopes\{97779E92-3072-45F4-AA39-2DCAF9E977FB}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97779E92-3072-45F4-AA39-2DCAF9E977FB}\ not found.
Registry key HKEY_USERS\S-1-5-21-806744476-1919467886-1915298580-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin not found.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin not found.
Folder C:\Users\Ms Lauren Law\AppData\Roaming\UAs\ not found.
Folder C:\Users\Ms Lauren Law\AppData\Roaming\xmldm\ not found.
Folder C:\Users\Ms Lauren Law\AppData\Roaming\kock\ not found.
Folder C:\Users\Ms Lauren Law\AppData\Roaming\Babylon\ not found.
Folder C:\Users\Ms Lauren Law\AppData\Roaming\UAs\ not found.
Folder C:\Users\Ms Lauren Law\AppData\Roaming\xmldm\ not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: AppData
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes


cosinus 04.04.2012 13:22

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten, Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

LaurenLaw 04.04.2012 14:18

Code:

15:01:49.0757 4840        TDSS rootkit removing tool 2.7.25.0 Apr  3 2012 13:42:32
15:01:49.0986 4840        ============================================================
15:01:49.0986 4840        Current date / time: 2012/04/04 15:01:49.0986
15:01:49.0986 4840        SystemInfo:
15:01:49.0986 4840       
15:01:49.0986 4840        OS Version: 6.1.7600 ServicePack: 0.0
15:01:49.0986 4840        Product type: Workstation
15:01:49.0987 4840        ComputerName: MSLAURENLAW
15:01:49.0987 4840        UserName: Ms Lauren Law
15:01:49.0987 4840        Windows directory: C:\Windows
15:01:49.0987 4840        System windows directory: C:\Windows
15:01:49.0987 4840        Running under WOW64
15:01:49.0987 4840        Processor architecture: Intel x64
15:01:49.0987 4840        Number of processors: 2
15:01:49.0987 4840        Page size: 0x1000
15:01:49.0987 4840        Boot type: Normal boot
15:01:49.0987 4840        ============================================================
15:01:50.0365 4840        Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:01:50.0370 4840        \Device\Harddisk0\DR0:
15:01:50.0371 4840        MBR used
15:01:50.0371 4840        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0xC8800, BlocksNum 0x12A17000
15:01:50.0371 4840        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x12ADF800, BlocksNum 0x1294F000
15:01:50.0445 4840        Initialize success
15:01:50.0445 4840        ============================================================
15:03:42.0171 3196        ============================================================
15:03:42.0171 3196        Scan started
15:03:42.0171 3196        Mode: Manual; SigCheck; TDLFS;
15:03:42.0171 3196        ============================================================
15:03:42.0532 3196        1394ohci        (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
15:03:42.0664 3196        1394ohci - ok
15:03:42.0789 3196        ACPI            (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
15:03:42.0812 3196        ACPI - ok
15:03:42.0915 3196        AcpiPmi        (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
15:03:43.0003 3196        AcpiPmi - ok
15:03:43.0118 3196        AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
15:03:43.0135 3196        AdobeARMservice - ok
15:03:43.0286 3196        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
15:03:43.0319 3196        adp94xx - ok
15:03:43.0442 3196        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
15:03:43.0471 3196        adpahci - ok
15:03:43.0591 3196        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
15:03:43.0615 3196        adpu320 - ok
15:03:43.0704 3196        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
15:03:43.0858 3196        AeLookupSvc - ok
15:03:43.0984 3196        AFD            (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
15:03:44.0048 3196        AFD - ok
15:03:44.0161 3196        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
15:03:44.0184 3196        agp440 - ok
15:03:44.0271 3196        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
15:03:44.0329 3196        ALG - ok
15:03:44.0442 3196        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
15:03:44.0462 3196        aliide - ok
15:03:44.0579 3196        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
15:03:44.0598 3196        amdide - ok
15:03:44.0710 3196        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
15:03:44.0769 3196        AmdK8 - ok
15:03:44.0877 3196        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
15:03:44.0937 3196        AmdPPM - ok
15:03:45.0061 3196        amdsata        (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
15:03:45.0083 3196        amdsata - ok
15:03:45.0212 3196        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
15:03:45.0236 3196        amdsbs - ok
15:03:45.0364 3196        amdxata        (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
15:03:45.0383 3196        amdxata - ok
15:03:45.0495 3196        AntiVirSchedulerService (c27d46b06d340293670450fce9dfb166) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
15:03:45.0510 3196        AntiVirSchedulerService - ok
15:03:45.0602 3196        AntiVirService  (72d90e56563165984224493069c69ed4) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
15:03:45.0620 3196        AntiVirService - ok
15:03:45.0746 3196        AppID          (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
15:03:45.0830 3196        AppID - ok
15:03:45.0922 3196        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
15:03:45.0983 3196        AppIDSvc - ok
15:03:46.0084 3196        Appinfo        (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
15:03:46.0140 3196        Appinfo - ok
15:03:46.0287 3196        Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
15:03:46.0306 3196        Apple Mobile Device - ok
15:03:46.0419 3196        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
15:03:46.0442 3196        arc - ok
15:03:46.0558 3196        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
15:03:46.0575 3196        arcsas - ok
15:03:46.0675 3196        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
15:03:46.0739 3196        AsyncMac - ok
15:03:46.0868 3196        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
15:03:46.0886 3196        atapi - ok
15:03:47.0027 3196        athr            (e857eee6b92aaa473ebb3465add8f7e7) C:\Windows\system32\DRIVERS\athrx.sys
15:03:47.0105 3196        athr - ok
15:03:47.0227 3196        AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
15:03:47.0286 3196        AudioEndpointBuilder - ok
15:03:47.0340 3196        AudioSrv        (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
15:03:47.0392 3196        AudioSrv - ok
15:03:47.0516 3196        avgntflt        (b1224e6b086cd6548315b04ab575a23e) C:\Windows\system32\DRIVERS\avgntflt.sys
15:03:47.0551 3196        avgntflt - ok
15:03:47.0683 3196        avipbb          (ed45f12cfa62b83765c9c1496758cc87) C:\Windows\system32\DRIVERS\avipbb.sys
15:03:47.0697 3196        avipbb - ok
15:03:47.0802 3196        AxInstSV        (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
15:03:47.0844 3196        AxInstSV - ok
15:03:47.0970 3196        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
15:03:48.0038 3196        b06bdrv - ok
15:03:48.0163 3196        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
15:03:48.0240 3196        b57nd60a - ok
15:03:48.0353 3196        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
15:03:48.0383 3196        BDESVC - ok
15:03:48.0492 3196        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
15:03:48.0573 3196        Beep - ok
15:03:48.0692 3196        BFE            (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
15:03:48.0760 3196        BFE - ok
15:03:48.0871 3196        BITS            (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
15:03:48.0938 3196        BITS - ok
15:03:49.0066 3196        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
15:03:49.0094 3196        blbdrive - ok
15:03:49.0193 3196        Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
15:03:49.0219 3196        Bonjour Service - ok
15:03:49.0338 3196        bowser          (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
15:03:49.0382 3196        bowser - ok
15:03:49.0505 3196        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
15:03:49.0553 3196        BrFiltLo - ok
15:03:49.0658 3196        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
15:03:49.0686 3196        BrFiltUp - ok
15:03:49.0777 3196        Browser        (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
15:03:49.0835 3196        Browser - ok
15:03:49.0956 3196        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\system32\Drivers\Brserid.sys
15:03:50.0015 3196        Brserid - ok
15:03:50.0125 3196        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
15:03:50.0162 3196        BrSerWdm - ok
15:03:50.0280 3196        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
15:03:50.0329 3196        BrUsbMdm - ok
15:03:50.0449 3196        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\Drivers\BrUsbSer.sys
15:03:50.0484 3196        BrUsbSer - ok
15:03:50.0625 3196        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
15:03:50.0654 3196        BTHMODEM - ok
15:03:50.0753 3196        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
15:03:50.0824 3196        bthserv - ok
15:03:50.0930 3196        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
15:03:51.0013 3196        cdfs - ok
15:03:51.0136 3196        cdrom          (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
15:03:51.0172 3196        cdrom - ok
15:03:51.0268 3196        CertPropSvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
15:03:51.0352 3196        CertPropSvc - ok
15:03:51.0482 3196        cfWiMAXService  (837ff2d497880198c918e6954dbd170c) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
15:03:51.0502 3196        cfWiMAXService - ok
15:03:51.0618 3196        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
15:03:51.0647 3196        circlass - ok
15:03:51.0767 3196        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
15:03:51.0796 3196        CLFS - ok
15:03:51.0887 3196        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
15:03:51.0913 3196        clr_optimization_v2.0.50727_32 - ok
15:03:51.0994 3196        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
15:03:52.0013 3196        clr_optimization_v2.0.50727_64 - ok
15:03:52.0150 3196        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
15:03:52.0169 3196        clr_optimization_v4.0.30319_32 - ok
15:03:52.0296 3196        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
15:03:52.0314 3196        clr_optimization_v4.0.30319_64 - ok
15:03:52.0431 3196        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
15:03:52.0473 3196        CmBatt - ok
15:03:52.0576 3196        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
15:03:52.0592 3196        cmdide - ok
15:03:52.0719 3196        CNG            (937beb186a735aca91d717044a49d17e) C:\Windows\system32\Drivers\cng.sys
15:03:52.0765 3196        CNG - ok
15:03:52.0880 3196        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
15:03:52.0899 3196        Compbatt - ok
15:03:53.0007 3196        CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
15:03:53.0044 3196        CompositeBus - ok
15:03:53.0087 3196        COMSysApp - ok
15:03:53.0196 3196        ConfigFree Gadget Service (d252c53bcdfc199bba55eeb10cdb266e) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
15:03:53.0213 3196        ConfigFree Gadget Service - ok
15:03:53.0320 3196        ConfigFree Service (cab0eeaf5295fc96ddd3e19dce27e131) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
15:03:53.0334 3196        ConfigFree Service - ok
15:03:53.0434 3196        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
15:03:53.0453 3196        crcdisk - ok
15:03:53.0551 3196        CryptSvc        (8c57411b66282c01533cb776f98ad384) C:\Windows\system32\cryptsvc.dll
15:03:53.0627 3196        CryptSvc - ok
15:03:53.0737 3196        DcomLaunch      (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
15:03:53.0793 3196        DcomLaunch - ok
15:03:53.0894 3196        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
15:03:53.0971 3196        defragsvc - ok
15:03:54.0087 3196        DfsC            (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
15:03:54.0138 3196        DfsC - ok
15:03:54.0247 3196        Dhcp            (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
15:03:54.0327 3196        Dhcp - ok
15:03:54.0419 3196        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
15:03:54.0492 3196        discache - ok
15:03:54.0603 3196        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
15:03:54.0624 3196        Disk - ok
15:03:54.0727 3196        Dnscache        (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
15:03:54.0767 3196        Dnscache - ok
15:03:54.0851 3196        dot3svc        (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
15:03:54.0912 3196        dot3svc - ok
15:03:55.0006 3196        DPS            (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
15:03:55.0065 3196        DPS - ok
15:03:55.0173 3196        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
15:03:55.0226 3196        drmkaud - ok
15:03:55.0358 3196        DXGKrnl        (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
15:03:55.0389 3196        DXGKrnl - ok
15:03:55.0484 3196        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
15:03:55.0553 3196        EapHost - ok
15:03:55.0735 3196        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
15:03:55.0892 3196        ebdrv - ok
15:03:56.0006 3196        EFS            (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
15:03:56.0040 3196        EFS - ok
15:03:56.0147 3196        ehRecvr        (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
15:03:56.0203 3196        ehRecvr - ok
15:03:56.0265 3196        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
15:03:56.0310 3196        ehSched - ok
15:03:56.0448 3196        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
15:03:56.0481 3196        elxstor - ok
15:03:56.0592 3196        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
15:03:56.0635 3196        ErrDev - ok
15:03:56.0737 3196        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
15:03:56.0820 3196        EventSystem - ok
15:03:56.0940 3196        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
15:03:57.0002 3196        exfat - ok
15:03:57.0107 3196        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
15:03:57.0176 3196        fastfat - ok
15:03:57.0290 3196        Fax            (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
15:03:57.0349 3196        Fax - ok
15:03:57.0453 3196        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
15:03:57.0475 3196        fdc - ok
15:03:57.0561 3196        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
15:03:57.0626 3196        fdPHost - ok
15:03:57.0710 3196        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
15:03:57.0781 3196        FDResPub - ok
15:03:57.0896 3196        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
15:03:57.0916 3196        FileInfo - ok
15:03:58.0027 3196        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
15:03:58.0088 3196        Filetrace - ok
15:03:58.0193 3196        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
15:03:58.0231 3196        flpydisk - ok
15:03:58.0337 3196        FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
15:03:58.0364 3196        FltMgr - ok
15:03:58.0489 3196        FontCache      (cb5e4b9c319e3c6bb363eb7e58a4a051) C:\Windows\system32\FntCache.dll
15:03:58.0543 3196        FontCache - ok
15:03:58.0644 3196        FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
15:03:58.0659 3196        FontCache3.0.0.0 - ok
15:03:58.0756 3196        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
15:03:58.0777 3196        FsDepends - ok
15:03:58.0902 3196        fssfltr        (dc0dce4ec2c5d2cf6472f9fd6aa9a7dc) C:\Windows\system32\DRIVERS\fssfltr.sys
15:03:58.0919 3196        fssfltr - ok
15:03:59.0045 3196        fsssvc          (40cdfad174b3d5e80f95dda003c0b97f) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
15:03:59.0098 3196        fsssvc - ok
15:03:59.0197 3196        Fs_Rec          (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
15:03:59.0215 3196        Fs_Rec - ok
15:03:59.0328 3196        fvevol          (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
15:03:59.0356 3196        fvevol - ok
15:03:59.0466 3196        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
15:03:59.0485 3196        gagp30kx - ok
15:03:59.0622 3196        GameConsoleService (c44d560e441f091ea3b72f778ec60de2) C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
15:03:59.0643 3196        GameConsoleService - ok
15:03:59.0766 3196        GEARAspiWDM    (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
15:03:59.0780 3196        GEARAspiWDM - ok
15:03:59.0885 3196        gpsvc          (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
15:03:59.0926 3196        gpsvc - ok
15:04:00.0014 3196        gupdate        (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:04:00.0028 3196        gupdate - ok
15:04:00.0067 3196        gupdatem        (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:04:00.0076 3196        gupdatem - ok
15:04:00.0155 3196        gusvc          (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
15:04:00.0173 3196        gusvc - ok
15:04:00.0283 3196        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
15:04:00.0343 3196        hcw85cir - ok
15:04:00.0466 3196        HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
15:04:00.0513 3196        HdAudAddService - ok
15:04:00.0624 3196        HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
15:04:00.0669 3196        HDAudBus - ok
15:04:00.0773 3196        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
15:04:00.0813 3196        HidBatt - ok
15:04:00.0927 3196        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
15:04:00.0967 3196        HidBth - ok
15:04:01.0081 3196        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
15:04:01.0124 3196        HidIr - ok
15:04:01.0218 3196        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
15:04:01.0276 3196        hidserv - ok
15:04:01.0402 3196        HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
15:04:01.0440 3196        HidUsb - ok
15:04:01.0529 3196        hkmsvc          (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
15:04:01.0597 3196        hkmsvc - ok
15:04:01.0689 3196        HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
15:04:01.0744 3196        HomeGroupListener - ok
15:04:01.0832 3196        HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
15:04:01.0874 3196        HomeGroupProvider - ok
15:04:02.0006 3196        HpSAMD          (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
15:04:02.0027 3196        HpSAMD - ok
15:04:02.0169 3196        HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
15:04:02.0234 3196        HTTP - ok
15:04:02.0331 3196        hwpolicy        (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
15:04:02.0346 3196        hwpolicy - ok
15:04:02.0456 3196        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
15:04:02.0475 3196        i8042prt - ok
15:04:02.0594 3196        iaStor          (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys
15:04:02.0617 3196        iaStor - ok
15:04:02.0745 3196        iaStorV        (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
15:04:02.0776 3196        iaStorV - ok
15:04:02.0901 3196        idsvc          (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
15:04:02.0937 3196        idsvc - ok
15:04:03.0217 3196        igfx            (3c3f27002abc69c5afe29cbe6cf7addf) C:\Windows\system32\DRIVERS\igdkmd64.sys
15:04:03.0466 3196        igfx - ok
15:04:03.0590 3196        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
15:04:03.0609 3196        iirsp - ok
15:04:03.0723 3196        IKEEXT          (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
15:04:03.0791 3196        IKEEXT - ok
15:04:03.0964 3196        IntcAzAudAddService (0c3cf4b3bae28e121a1689e3538f8712) C:\Windows\system32\drivers\RTKVHD64.sys
15:04:04.0007 3196        IntcAzAudAddService - ok
15:04:04.0131 3196        IntcHdmiAddService (88a20fa54c73ded4e8dac764e9130ae9) C:\Windows\system32\drivers\IntcHdmi.sys
15:04:04.0180 3196        IntcHdmiAddService - ok
15:04:04.0306 3196        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
15:04:04.0325 3196        intelide - ok
15:04:04.0438 3196        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
15:04:04.0470 3196        intelppm - ok
15:04:04.0566 3196        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
15:04:04.0610 3196        IPBusEnum - ok
15:04:04.0717 3196        IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
15:04:04.0781 3196        IpFilterDriver - ok
15:04:04.0887 3196        iphlpsvc        (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
15:04:04.0950 3196        iphlpsvc - ok
15:04:05.0056 3196        IPMIDRV        (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
15:04:05.0090 3196        IPMIDRV - ok
15:04:05.0190 3196        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
15:04:05.0257 3196        IPNAT - ok
15:04:05.0373 3196        iPod Service    (50d6ccc6ff5561f9f56946b3e6164fb8) C:\Program Files\iPod\bin\iPodService.exe
15:04:05.0402 3196        iPod Service - ok
15:04:05.0516 3196        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
15:04:05.0546 3196        IRENUM - ok
15:04:05.0659 3196        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
15:04:05.0678 3196        isapnp - ok
15:04:05.0781 3196        iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
15:04:05.0808 3196        iScsiPrt - ok
15:04:05.0913 3196        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
15:04:05.0933 3196        kbdclass - ok
15:04:06.0038 3196        kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
15:04:06.0073 3196        kbdhid - ok
15:04:06.0184 3196        KeyIso          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
15:04:06.0206 3196        KeyIso - ok
15:04:06.0319 3196        KSecDD          (16c1b906fc5ead84769f90b736b6bf0e) C:\Windows\system32\Drivers\ksecdd.sys
15:04:06.0336 3196        KSecDD - ok
15:04:06.0444 3196        KSecPkg        (0b711550c56444879d71c7daabda6c83) C:\Windows\system32\Drivers\ksecpkg.sys
15:04:06.0466 3196        KSecPkg - ok
15:04:06.0547 3196        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
15:04:06.0610 3196        ksthunk - ok
15:04:06.0708 3196        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
15:04:06.0766 3196        KtmRm - ok
15:04:06.0875 3196        LanmanServer    (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
15:04:06.0940 3196        LanmanServer - ok
15:04:07.0049 3196        LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
15:04:07.0097 3196        LanmanWorkstation - ok
15:04:07.0206 3196        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
15:04:07.0266 3196        lltdio - ok
15:04:07.0353 3196        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
15:04:07.0414 3196        lltdsvc - ok
15:04:07.0501 3196        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
15:04:07.0547 3196        lmhosts - ok
15:04:07.0659 3196        LPCFilter      (41e122f6d1448c94cc05196bc41d6bfb) C:\Windows\system32\DRIVERS\LPCFilter.sys
15:04:07.0673 3196        LPCFilter - ok
15:04:07.0772 3196        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
15:04:07.0789 3196        LSI_FC - ok
15:04:07.0898 3196        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
15:04:07.0920 3196        LSI_SAS - ok
15:04:08.0032 3196        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
15:04:08.0054 3196        LSI_SAS2 - ok
15:04:08.0162 3196        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
15:04:08.0179 3196        LSI_SCSI - ok
15:04:08.0268 3196        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
15:04:08.0320 3196        luafv - ok
15:04:08.0409 3196        Mcx2Svc        (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
15:04:08.0447 3196        Mcx2Svc - ok
15:04:08.0540 3196        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
15:04:08.0561 3196        megasas - ok
15:04:08.0663 3196        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
15:04:08.0690 3196        MegaSR - ok
15:04:08.0795 3196        Microsoft Office Groove Audit Service (123271bd5237ab991dc5c21fdf8835eb) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
15:04:08.0812 3196        Microsoft Office Groove Audit Service - ok
15:04:08.0897 3196        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
15:04:08.0962 3196        MMCSS - ok
15:04:09.0062 3196        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
15:04:09.0120 3196        Modem - ok
15:04:09.0223 3196        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
15:04:09.0257 3196        monitor - ok
15:04:09.0365 3196        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
15:04:09.0384 3196        mouclass - ok
15:04:09.0491 3196        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
15:04:09.0517 3196        mouhid - ok
15:04:09.0628 3196        mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
15:04:09.0641 3196        mountmgr - ok
15:04:09.0739 3196        mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
15:04:09.0760 3196        mpio - ok
15:04:09.0856 3196        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
15:04:09.0939 3196        mpsdrv - ok
15:04:10.0050 3196        MpsSvc          (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
15:04:10.0113 3196        MpsSvc - ok
15:04:10.0207 3196        MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
15:04:10.0253 3196        MRxDAV - ok
15:04:10.0377 3196        mrxsmb          (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
15:04:10.0414 3196        mrxsmb - ok
15:04:10.0539 3196        mrxsmb10        (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
15:04:10.0561 3196        mrxsmb10 - ok
15:04:10.0669 3196        mrxsmb20        (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
15:04:10.0706 3196        mrxsmb20 - ok
15:04:10.0805 3196        msahci          (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
15:04:10.0824 3196        msahci - ok
15:04:10.0916 3196        msdsm          (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
15:04:10.0939 3196        msdsm - ok
15:04:11.0036 3196        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
15:04:11.0066 3196        MSDTC - ok
15:04:11.0162 3196        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
15:04:11.0207 3196        Msfs - ok
15:04:11.0303 3196        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
15:04:11.0356 3196        mshidkmdf - ok
15:04:11.0446 3196        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
15:04:11.0464 3196        msisadrv - ok
15:04:11.0563 3196        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
15:04:11.0625 3196        MSiSCSI - ok
15:04:11.0688 3196        msiserver - ok
15:04:11.0791 3196        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
15:04:11.0859 3196        MSKSSRV - ok
15:04:11.0963 3196        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
15:04:12.0030 3196        MSPCLOCK - ok
15:04:12.0139 3196        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
15:04:12.0211 3196        MSPQM - ok
15:04:12.0311 3196        MsRPC          (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
15:04:12.0340 3196        MsRPC - ok
15:04:12.0437 3196        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
15:04:12.0453 3196        mssmbios - ok
15:04:12.0544 3196        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
15:04:12.0606 3196        MSTEE - ok
15:04:12.0698 3196        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
15:04:12.0730 3196        MTConfig - ok
15:04:12.0833 3196        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
15:04:12.0853 3196        Mup - ok
15:04:12.0949 3196        napagent        (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
15:04:13.0028 3196        napagent - ok
15:04:13.0138 3196        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
15:04:13.0178 3196        NativeWifiP - ok
15:04:13.0301 3196        NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
15:04:13.0345 3196        NDIS - ok
15:04:13.0451 3196        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
15:04:13.0512 3196        NdisCap - ok
15:04:13.0615 3196        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
15:04:13.0669 3196        NdisTapi - ok
15:04:13.0745 3196        Ndisuio        (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
15:04:13.0811 3196        Ndisuio - ok
15:04:13.0909 3196        NdisWan        (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
15:04:13.0962 3196        NdisWan - ok
15:04:14.0049 3196        NDProxy        (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
15:04:14.0114 3196        NDProxy - ok
15:04:14.0215 3196        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
15:04:14.0275 3196        NetBIOS - ok
15:04:14.0375 3196        NetBT          (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
15:04:14.0435 3196        NetBT - ok
15:04:14.0552 3196        Netlogon        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
15:04:14.0575 3196        Netlogon - ok
15:04:14.0674 3196        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
15:04:14.0739 3196        Netman - ok
15:04:14.0839 3196        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
15:04:14.0916 3196        netprofm - ok
15:04:15.0060 3196        netr28ux        (ba90f3931815703924bfe4d29d27a06c) C:\Windows\system32\DRIVERS\netr28ux.sys
15:04:15.0113 3196        netr28ux - ok
15:04:15.0218 3196        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
15:04:15.0236 3196        NetTcpPortSharing - ok
15:04:15.0351 3196        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
15:04:15.0371 3196        nfrd960 - ok
15:04:15.0478 3196        NlaSvc          (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
15:04:15.0539 3196        NlaSvc - ok
15:04:15.0644 3196        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
15:04:15.0705 3196        Npfs - ok
15:04:15.0797 3196        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
15:04:15.0871 3196        nsi - ok
15:04:15.0956 3196        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
15:04:16.0001 3196        nsiproxy - ok
15:04:16.0139 3196        Ntfs            (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
15:04:16.0184 3196        Ntfs - ok
15:04:16.0276 3196        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
15:04:16.0328 3196        Null - ok
15:04:16.0449 3196        nvraid          (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
15:04:16.0467 3196        nvraid - ok
15:04:16.0576 3196        nvstor          (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
15:04:16.0597 3196        nvstor - ok
15:04:16.0714 3196        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
15:04:16.0735 3196        nv_agp - ok
15:04:16.0821 3196        odserv          (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
15:04:16.0847 3196        odserv - ok
15:04:16.0949 3196        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
15:04:16.0983 3196        ohci1394 - ok
15:04:17.0061 3196        ose            (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:04:17.0080 3196        ose - ok
15:04:17.0180 3196        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
15:04:17.0228 3196        p2pimsvc - ok
15:04:17.0338 3196        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
15:04:17.0368 3196        p2psvc - ok
15:04:17.0466 3196        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
15:04:17.0491 3196        Parport - ok
15:04:17.0585 3196        partmgr        (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
15:04:17.0605 3196        partmgr - ok
15:04:17.0701 3196        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
15:04:17.0747 3196        PcaSvc - ok
15:04:17.0841 3196        pci            (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
15:04:17.0860 3196        pci - ok
15:04:17.0948 3196        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
15:04:17.0965 3196        pciide - ok
15:04:18.0065 3196        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
15:04:18.0090 3196        pcmcia - ok
15:04:18.0206 3196        PCSUService    (7eb95aa73d657a2da9d8cfc336f4f48f) C:\Program Files (x86)\PC Beschleunigen\PCSUService.exe
15:04:18.0223 3196        PCSUService ( UnsignedFile.Multi.Generic ) - warning
15:04:18.0223 3196        PCSUService - detected UnsignedFile.Multi.Generic (1)
15:04:18.0313 3196        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
15:04:18.0334 3196        pcw - ok
15:04:18.0447 3196        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
15:04:18.0522 3196        PEAUTH - ok
15:04:18.0603 3196        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
15:04:18.0637 3196        PerfHost - ok
15:04:18.0802 3196        PGEffect        (663962900e7fea522126ba287715bb4a) C:\Windows\system32\DRIVERS\pgeffect.sys
15:04:18.0815 3196        PGEffect - ok
15:04:18.0935 3196        pla            (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
15:04:19.0015 3196        pla - ok
15:04:19.0139 3196        PlugPlay        (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
15:04:19.0195 3196        PlugPlay - ok
15:04:19.0293 3196        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
15:04:19.0330 3196        PNRPAutoReg - ok
15:04:19.0436 3196        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
15:04:19.0465 3196        PNRPsvc - ok
15:04:19.0572 3196        PolicyAgent    (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
15:04:19.0637 3196        PolicyAgent - ok
15:04:19.0739 3196        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
15:04:19.0808 3196        Power - ok
15:04:19.0920 3196        PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
15:04:19.0985 3196        PptpMiniport - ok
15:04:20.0086 3196        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
15:04:20.0122 3196        Processor - ok
15:04:20.0212 3196        ProfSvc        (f381975e1f4346de875cb07339ce8d3a) C:\Windows\system32\profsvc.dll
15:04:20.0278 3196        ProfSvc - ok
15:04:20.0385 3196        ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
15:04:20.0408 3196        ProtectedStorage - ok
15:04:20.0519 3196        Psched          (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
15:04:20.0587 3196        Psched - ok
15:04:20.0722 3196        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
15:04:20.0770 3196        ql2300 - ok
15:04:20.0862 3196        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
15:04:20.0885 3196        ql40xx - ok
15:04:20.0978 3196        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
15:04:21.0015 3196        QWAVE - ok
15:04:21.0106 3196        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
15:04:21.0157 3196        QWAVEdrv - ok
15:04:21.0254 3196        RalinkRegistryWriter (432f5b15e21a54b48072593f03570326) C:\Program Files (x86)\Sitecom\Common\RegistryWriter.exe
15:04:21.0281 3196        RalinkRegistryWriter ( UnsignedFile.Multi.Generic ) - warning
15:04:21.0281 3196        RalinkRegistryWriter - detected UnsignedFile.Multi.Generic (1)
15:04:21.0378 3196        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
15:04:21.0454 3196        RasAcd - ok
15:04:21.0562 3196        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
15:04:21.0611 3196        RasAgileVpn - ok
15:04:21.0693 3196        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
15:04:21.0739 3196        RasAuto - ok
15:04:21.0837 3196        Rasl2tp        (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
15:04:21.0898 3196        Rasl2tp - ok
15:04:21.0999 3196        RasMan          (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
15:04:22.0082 3196        RasMan - ok
15:04:22.0201 3196        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
15:04:22.0266 3196        RasPppoe - ok
15:04:22.0369 3196        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
15:04:22.0435 3196        RasSstp - ok
15:04:22.0541 3196        rdbss          (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
15:04:22.0602 3196        rdbss - ok
15:04:22.0695 3196        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
15:04:22.0737 3196        rdpbus - ok
15:04:22.0837 3196        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
15:04:22.0887 3196        RDPCDD - ok
15:04:22.0995 3196        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
15:04:23.0055 3196        RDPENCDD - ok
15:04:23.0165 3196        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
15:04:23.0221 3196        RDPREFMP - ok
15:04:23.0335 3196        RDPWD          (074ac702d8b8b660b0e1371555995386) C:\Windows\system32\drivers\RDPWD.sys
15:04:23.0395 3196        RDPWD - ok
15:04:23.0503 3196        rdyboost        (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
15:04:23.0529 3196        rdyboost - ok
15:04:23.0619 3196        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
15:04:23.0674 3196        RemoteAccess - ok
15:04:23.0763 3196        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
15:04:23.0831 3196        RemoteRegistry - ok
15:04:23.0922 3196        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
15:04:23.0999 3196        RpcEptMapper - ok
15:04:24.0081 3196        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
15:04:24.0114 3196        RpcLocator - ok
15:04:24.0207 3196        RpcSs          (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
15:04:24.0260 3196        RpcSs - ok
15:04:24.0359 3196        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
15:04:24.0406 3196        rspndr - ok
15:04:24.0549 3196        RSUSBSTOR      (8c22f21c924413d4e109995f748e18bb) C:\Windows\system32\Drivers\RtsUStor.sys
15:04:24.0602 3196        RSUSBSTOR - ok
15:04:24.0734 3196        RTL8167        (b49dc435ae3695bac5623dd94b05732d) C:\Windows\system32\DRIVERS\Rt64win7.sys
15:04:24.0786 3196        RTL8167 - ok
15:04:24.0925 3196        rtl8192se      (a9ede191b5478d18f0a1bff3b822f7a5) C:\Windows\system32\DRIVERS\rtl8192se.sys
15:04:24.0983 3196        rtl8192se - ok
15:04:25.0053 3196        RtsUIR - ok
15:04:25.0174 3196        s217bus        (b49951a2c8fd81307707443d01936e37) C:\Windows\system32\DRIVERS\s217bus.sys
15:04:25.0191 3196        s217bus - ok
15:04:25.0311 3196        s217mdfl        (58204ec551d1a94d60cac130440f0feb) C:\Windows\system32\DRIVERS\s217mdfl.sys
15:04:25.0324 3196        s217mdfl - ok
15:04:25.0429 3196        s217mdm        (e2b3de89339a7a807520c6063cd146d3) C:\Windows\system32\DRIVERS\s217mdm.sys
15:04:25.0447 3196        s217mdm - ok
15:04:25.0577 3196        s217nd5        (7bc7d18351b846f4544b54db38fb4208) C:\Windows\system32\DRIVERS\s217nd5.sys
15:04:25.0589 3196        s217nd5 - ok
15:04:25.0707 3196        s217obex        (d498b2082f51858f121d4584a7787cd5) C:\Windows\system32\DRIVERS\s217obex.sys
15:04:25.0723 3196        s217obex - ok
15:04:25.0846 3196        s217unic        (43512d0c3a59eb20fda06ce4265a1549) C:\Windows\system32\DRIVERS\s217unic.sys
15:04:25.0863 3196        s217unic - ok
15:04:25.0974 3196        SamSs          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
15:04:25.0997 3196        SamSs - ok
15:04:26.0100 3196        sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
15:04:26.0121 3196        sbp2port - ok
15:04:26.0214 3196        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
15:04:26.0287 3196        SCardSvr - ok
15:04:26.0381 3196        scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
15:04:26.0430 3196        scfilter - ok
15:04:26.0563 3196        Schedule        (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
15:04:26.0614 3196        Schedule - ok
15:04:26.0704 3196        SCPolicySvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
15:04:26.0745 3196        SCPolicySvc - ok
15:04:26.0836 3196        SDRSVC          (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
15:04:26.0891 3196        SDRSVC - ok
15:04:26.0999 3196        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
15:04:27.0046 3196        secdrv - ok
15:04:27.0129 3196        seclogon        (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
15:04:27.0191 3196        seclogon - ok
15:04:27.0279 3196        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
15:04:27.0341 3196        SENS - ok
15:04:27.0436 3196        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
15:04:27.0484 3196        SensrSvc - ok
15:04:27.0571 3196        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
15:04:27.0594 3196        Serenum - ok
15:04:27.0709 3196        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
15:04:27.0745 3196        Serial - ok
15:04:27.0846 3196        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
15:04:27.0867 3196        sermouse - ok
15:04:27.0969 3196        SessionEnv      (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
15:04:28.0026 3196        SessionEnv - ok
15:04:28.0117 3196        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
15:04:28.0156 3196        sffdisk - ok
15:04:28.0252 3196        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
15:04:28.0288 3196        sffp_mmc - ok
15:04:28.0389 3196        sffp_sd        (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
15:04:28.0430 3196        sffp_sd - ok
15:04:28.0534 3196        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
15:04:28.0564 3196        sfloppy - ok
15:04:28.0682 3196        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
15:04:28.0752 3196        SharedAccess - ok
15:04:28.0841 3196        ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
15:04:28.0885 3196        ShellHWDetection - ok
15:04:28.0995 3196        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
15:04:29.0012 3196        SiSRaid2 - ok
15:04:29.0116 3196        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
15:04:29.0134 3196        SiSRaid4 - ok
15:04:29.0243 3196        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
15:04:29.0309 3196        Smb - ok
15:04:29.0421 3196        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
15:04:29.0457 3196        SNMPTRAP - ok
15:04:29.0553 3196        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
15:04:29.0571 3196        spldr - ok
15:04:29.0680 3196        Spooler        (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
15:04:29.0719 3196        Spooler - ok
15:04:29.0898 3196        sppsvc          (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
15:04:30.0011 3196        sppsvc - ok
15:04:30.0104 3196        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
15:04:30.0163 3196        sppuinotify - ok
15:04:30.0274 3196        srv            (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
15:04:30.0323 3196        srv - ok
15:04:30.0446 3196        srv2            (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
15:04:30.0489 3196        srv2 - ok
15:04:30.0609 3196        srvnet          (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
15:04:30.0646 3196        srvnet - ok
15:04:30.0755 3196        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
15:04:30.0822 3196        SSDPSRV - ok
15:04:30.0918 3196        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
15:04:30.0966 3196        SstpSvc - ok
15:04:31.0064 3196        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
15:04:31.0083 3196        stexstor - ok
15:04:31.0189 3196        stisvc          (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
15:04:31.0229 3196        stisvc - ok
15:04:31.0319 3196        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
15:04:31.0337 3196        swenum - ok
15:04:31.0437 3196        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
15:04:31.0492 3196        swprv - ok
15:04:31.0624 3196        SynTP          (be7311da9d6833fa69ed04b744a1c8f8) C:\Windows\system32\DRIVERS\SynTP.sys
15:04:31.0644 3196        SynTP - ok
15:04:31.0772 3196        SysMain        (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
15:04:31.0833 3196        SysMain - ok
15:04:31.0931 3196        TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
15:04:31.0966 3196        TabletInputService - ok
15:04:32.0063 3196        TapiSrv        (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
15:04:32.0133 3196        TapiSrv - ok
15:04:32.0225 3196        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
15:04:32.0290 3196        TBS - ok
15:04:32.0456 3196        Tcpip          (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\drivers\tcpip.sys
15:04:32.0505 3196        Tcpip - ok
15:04:32.0677 3196        TCPIP6          (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\DRIVERS\tcpip.sys
15:04:32.0724 3196        TCPIP6 - ok
15:04:32.0813 3196        tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
15:04:32.0862 3196        tcpipreg - ok
15:04:32.0973 3196        tdcmdpst        (fd542b661bd22fa69ca789ad0ac58c29) C:\Windows\system32\DRIVERS\tdcmdpst.sys
15:04:32.0986 3196        tdcmdpst - ok
15:04:33.0088 3196        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
15:04:33.0119 3196        TDPIPE - ok
15:04:33.0238 3196        TDTCP          (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
15:04:33.0277 3196        TDTCP - ok
15:04:33.0380 3196        tdx            (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
15:04:33.0447 3196        tdx - ok
15:04:33.0519 3196        TemproMonitoringService (63b4f544664dc5154fda4213e2af09d0) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
15:04:33.0534 3196        TemproMonitoringService - ok
15:04:33.0630 3196        TermDD          (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
15:04:33.0650 3196        TermDD - ok
15:04:33.0748 3196        TermService    (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
15:04:33.0817 3196        TermService - ok
15:04:33.0904 3196        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
15:04:33.0947 3196        Themes - ok
15:04:34.0032 3196        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
15:04:34.0082 3196        THREADORDER - ok
15:04:34.0175 3196        TMachInfo      (32577b987ae5401038451bb392cb8d89) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
15:04:34.0188 3196        TMachInfo - ok
15:04:34.0274 3196        TODDSrv        (ed32035bdfeced1ad66d459fd9cc1140) C:\Windows\system32\TODDSrv.exe
15:04:34.0292 3196        TODDSrv - ok
15:04:34.0384 3196        TosCoSrv        (4db8c79bcea76063b83b13410366a1f7) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
15:04:34.0406 3196        TosCoSrv - ok
15:04:34.0518 3196        TOSHIBA eco Utility Service (707800855afbd7648375efb1519b8d6d) C:\Program Files\TOSHIBA\TECO\TecoService.exe
15:04:34.0535 3196        TOSHIBA eco Utility Service - ok
15:04:34.0609 3196        TOSHIBA HDD SSD Alert Service (dd58e1250f604cbbadda04575e5e2376) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
15:04:34.0624 3196        TOSHIBA HDD SSD Alert Service - ok
15:04:34.0754 3196        tos_sps64      (09ff7b0b1b5c3d225495cb6f5a9b39f8) C:\Windows\system32\DRIVERS\tos_sps64.sys
15:04:34.0781 3196        tos_sps64 - ok
15:04:34.0858 3196        TPCHSrv        (de64c52bd0671165cf2eebf2a728a3e2) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
15:04:34.0888 3196        TPCHSrv - ok
15:04:34.0979 3196        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
15:04:35.0047 3196        TrkWks - ok
15:04:35.0137 3196        TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
15:04:35.0173 3196        TrustedInstaller - ok
15:04:35.0272 3196        tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
15:04:35.0338 3196        tssecsrv - ok
15:04:35.0443 3196        tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
15:04:35.0516 3196        tunnel - ok
15:04:35.0643 3196        TVALZ          (550b567f9364d8f7684c3fb3ea665a72) C:\Windows\system32\DRIVERS\TVALZ_O.SYS
15:04:35.0656 3196        TVALZ - ok
15:04:35.0772 3196        TVALZFL        (9c7191f4b2e49bff47a6c1144b5923fa) C:\Windows\system32\DRIVERS\TVALZFL.sys
15:04:35.0784 3196        TVALZFL - ok
15:04:35.0886 3196        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
15:04:35.0905 3196        uagp35 - ok
15:04:36.0008 3196        udfs            (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
15:04:36.0072 3196        udfs - ok
15:04:36.0168 3196        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
15:04:36.0206 3196        UI0Detect - ok
15:04:36.0310 3196        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
15:04:36.0329 3196        uliagpkx - ok
15:04:36.0436 3196        umbus          (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
15:04:36.0470 3196        umbus - ok
15:04:36.0557 3196        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
15:04:36.0576 3196        UmPass - ok
15:04:36.0676 3196        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
15:04:36.0757 3196        upnphost - ok
15:04:36.0889 3196        USBAAPL64      (fb251567f41bc61988b26731dec19e4b) C:\Windows\system32\Drivers\usbaapl64.sys
15:04:36.0933 3196        USBAAPL64 - ok
15:04:37.0039 3196        usbccgp        (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
15:04:37.0083 3196        usbccgp - ok
15:04:37.0155 3196        USBCCID - ok
15:04:37.0280 3196        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
15:04:37.0327 3196        usbcir - ok
15:04:37.0421 3196        usbehci        (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
15:04:37.0445 3196        usbehci - ok
15:04:37.0571 3196        usbhub          (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
15:04:37.0612 3196        usbhub - ok
15:04:37.0716 3196        usbohci        (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
15:04:37.0754 3196        usbohci - ok
15:04:37.0867 3196        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
15:04:37.0912 3196        usbprint - ok
15:04:38.0016 3196        usbscan        (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
15:04:38.0044 3196        usbscan - ok
15:04:38.0158 3196        USBSTOR        (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
15:04:38.0216 3196        USBSTOR - ok
15:04:38.0320 3196        usbuhci        (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys
15:04:38.0358 3196        usbuhci - ok
15:04:38.0492 3196        usbvideo        (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys
15:04:38.0548 3196        usbvideo - ok
15:04:38.0642 3196        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
15:04:38.0689 3196        UxSms - ok
15:04:38.0797 3196        VaultSvc        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
15:04:38.0815 3196        VaultSvc - ok
15:04:38.0930 3196        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
15:04:38.0946 3196        vdrvroot - ok
15:04:39.0028 3196        vds            (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
15:04:39.0082 3196        vds - ok
15:04:39.0197 3196        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
15:04:39.0225 3196        vga - ok
15:04:39.0323 3196        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
15:04:39.0390 3196        VgaSave - ok
15:04:39.0492 3196        vhdmp          (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
15:04:39.0513 3196        vhdmp - ok
15:04:39.0605 3196        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
15:04:39.0618 3196        viaide - ok
15:04:39.0713 3196        volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
15:04:39.0725 3196        volmgr - ok
15:04:39.0822 3196        volmgrx        (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
15:04:39.0850 3196        volmgrx - ok
15:04:39.0962 3196        volsnap        (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
15:04:39.0986 3196        volsnap - ok
15:04:40.0107 3196        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
15:04:40.0130 3196        vsmraid - ok
15:04:40.0261 3196        VSS            (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
15:04:40.0317 3196        VSS - ok
15:04:40.0406 3196        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
15:04:40.0433 3196        vwifibus - ok
15:04:40.0539 3196        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
15:04:40.0583 3196        vwififlt - ok
15:04:40.0708 3196        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
15:04:40.0736 3196        vwifimp - ok
15:04:40.0859 3196        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
15:04:40.0910 3196        W32Time - ok
15:04:41.0005 3196        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
15:04:41.0041 3196        WacomPen - ok
15:04:41.0154 3196        WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
15:04:41.0222 3196        WANARP - ok
15:04:41.0265 3196        Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
15:04:41.0311 3196        Wanarpv6 - ok
15:04:41.0457 3196        WatAdminSvc    (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
15:04:41.0513 3196        WatAdminSvc - ok
15:04:41.0637 3196        wbengine        (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
15:04:41.0698 3196        wbengine - ok
15:04:41.0793 3196        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
15:04:41.0819 3196        WbioSrvc - ok
15:04:41.0920 3196        wcncsvc        (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
15:04:41.0959 3196        wcncsvc - ok
15:04:42.0050 3196        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
15:04:42.0084 3196        WcsPlugInService - ok
15:04:42.0194 3196        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
15:04:42.0214 3196        Wd - ok
15:04:42.0328 3196        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
15:04:42.0360 3196        Wdf01000 - ok
15:04:42.0451 3196        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
15:04:42.0497 3196        WdiServiceHost - ok
15:04:42.0503 3196        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
15:04:42.0524 3196        WdiSystemHost - ok
15:04:42.0628 3196        WebClient      (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
15:04:42.0685 3196        WebClient - ok
15:04:42.0786 3196        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
15:04:42.0840 3196        Wecsvc - ok
15:04:42.0933 3196        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
15:04:42.0989 3196        wercplsupport - ok
15:04:43.0092 3196        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
15:04:43.0145 3196        WerSvc - ok
15:04:43.0257 3196        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
15:04:43.0296 3196        WfpLwf - ok
15:04:43.0394 3196        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
15:04:43.0407 3196        WIMMount - ok
15:04:43.0445 3196        WinDefend - ok
15:04:43.0455 3196        WinHttpAutoProxySvc - ok
15:04:43.0560 3196        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
15:04:43.0599 3196        Winmgmt - ok
15:04:43.0737 3196        WinRM          (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
15:04:43.0824 3196        WinRM - ok
15:04:43.0957 3196        WinUsb          (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
15:04:43.0998 3196        WinUsb - ok
15:04:44.0111 3196        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
15:04:44.0172 3196        Wlansvc - ok
15:04:44.0294 3196        wlcrasvc        (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
15:04:44.0310 3196        wlcrasvc - ok
15:04:44.0464 3196        wlidsvc        (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
15:04:44.0519 3196        wlidsvc - ok
15:04:44.0623 3196        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
15:04:44.0650 3196        WmiAcpi - ok
15:04:44.0761 3196        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
15:04:44.0801 3196        wmiApSrv - ok
15:04:44.0861 3196        WMPNetworkSvc - ok
15:04:44.0961 3196        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
15:04:45.0000 3196        WPCSvc - ok
15:04:45.0096 3196        WPDBusEnum      (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
15:04:45.0136 3196        WPDBusEnum - ok
15:04:45.0231 3196        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
15:04:45.0298 3196        ws2ifsl - ok
15:04:45.0411 3196        wscsvc          (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
15:04:45.0465 3196        wscsvc - ok
15:04:45.0535 3196        WSearch - ok
15:04:45.0626 3196        wuauserv        (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll
15:04:45.0706 3196        wuauserv - ok
15:04:45.0798 3196        WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
15:04:45.0865 3196        WudfPf - ok
15:04:45.0995 3196        WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
15:04:46.0054 3196        WUDFRd - ok
15:04:46.0151 3196        wudfsvc        (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
15:04:46.0212 3196        wudfsvc - ok
15:04:46.0308 3196        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
15:04:46.0343 3196        WwanSvc - ok
15:04:46.0399 3196        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
15:04:47.0294 3196        \Device\Harddisk0\DR0 - ok
15:04:47.0322 3196        Boot (0x1200)  (ce11b9c7e374e2bedac58b5561339d08) \Device\Harddisk0\DR0\Partition0
15:04:47.0324 3196        \Device\Harddisk0\DR0\Partition0 - ok
15:04:47.0344 3196        Boot (0x1200)  (8a294704b3c981353aabc814361bd7b8) \Device\Harddisk0\DR0\Partition1
15:04:47.0345 3196        \Device\Harddisk0\DR0\Partition1 - ok
15:04:47.0346 3196        ============================================================
15:04:47.0346 3196        Scan finished
15:04:47.0346 3196        ============================================================
15:04:47.0426 2832        Detected object count: 2
15:04:47.0426 2832        Actual detected object count: 2
15:16:05.0779 2832        PCSUService ( UnsignedFile.Multi.Generic ) - skipped by user
15:16:05.0779 2832        PCSUService ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:16:05.0782 2832        RalinkRegistryWriter ( UnsignedFile.Multi.Generic ) - skipped by user
15:16:05.0782 2832        RalinkRegistryWriter ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 04.04.2012 14:56

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

LaurenLaw 04.04.2012 22:40

Nachdem wieder irgendwann nichts mehr passierte und die Meldung wie aus dem Zitat von alleine auftauchte, habe ich den PC neu gestartet.

Das einzige was ich nun unter C:/Combofix finde ist das:

Code:

ComboFix 12-04-04.02 - Ms Lauren Law 04.04.2012  16:32:01.2.2 - x64
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.49.1031.18.3933.2596 [GMT 2:00]
ausgeführt von:: C:\Users\Ms Lauren Law\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))


C:\ProgramData\xp
C:\ProgramData\xp\EBLib.dll
C:\ProgramData\xp\TPwSav.sys
C:\Users\Ms Lauren Law\Documents\~WRD0000.tmp


(((((((((((((((((((((((  Dateien erstellt von 2012-03-04 bis 2012-04-04  ))))))))))))))))))))))))))))))


cosinus 04.04.2012 23:24

Starte Windows neu, lösch die alte combofix.exe, lade CF neu runter und probier es bitte nochmal.

LaurenLaw 05.04.2012 11:49

Super, nun hats geklappt:

Combofix Logfile:
Code:

ComboFix 12-04-05.04 - Ms Lauren Law 05.04.2012  12:02:09.4.2 - x64
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.49.1031.18.3933.2664 [GMT 2:00]
ausgeführt von:: c:\users\Ms Lauren Law\Downloads\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-03-05 bis 2012-04-05  ))))))))))))))))))))))))))))))
.
.
2012-04-05 10:13 . 2012-04-05 10:13        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-04-03 23:15 . 2012-04-03 23:15        --------        d-----w-        c:\program files\iPod
2012-04-03 23:15 . 2012-04-03 23:16        --------        d-----w-        c:\program files\iTunes
2012-04-03 18:56 . 2012-04-03 18:56        --------        d-----w-        C:\_OTL
2012-04-03 17:31 . 2012-04-03 17:31        --------        d-----w-        c:\windows\system32\Macromed
2012-04-03 16:27 . 2012-03-14 03:27        8669240        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{037364A3-09BD-471B-8997-50310039AA89}\mpengine.dll
2012-04-02 14:56 . 2012-04-02 14:56        --------        d-----w-        c:\program files (x86)\ESET
2012-03-31 09:38 . 2012-03-31 09:38        --------        d-----w-        c:\users\Ms Lauren Law\AppData\Roaming\Malwarebytes
2012-03-31 09:38 . 2012-03-31 09:38        --------        d-----w-        c:\programdata\Malwarebytes
2012-03-31 09:38 . 2012-03-31 09:38        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-03-31 09:38 . 2011-12-10 13:24        23152        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-03-15 02:02 . 2011-11-19 18:30        5504880        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-03-15 02:02 . 2011-11-19 14:25        3957616        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2012-03-15 02:02 . 2011-11-19 14:25        3902320        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2012-03-14 17:36 . 2012-02-03 04:16        3143168        ----a-w-        c:\windows\system32\win32k.sys
2012-03-14 17:36 . 2012-02-10 06:18        1541120        ----a-w-        c:\windows\system32\DWrite.dll
2012-03-14 17:36 . 2012-02-10 06:17        1837568        ----a-w-        c:\windows\system32\d3d10warp.dll
2012-03-14 17:36 . 2012-02-10 06:17        320512        ----a-w-        c:\windows\system32\d3d10_1core.dll
2012-03-14 17:36 . 2012-02-10 05:41        1074176        ----a-w-        c:\windows\SysWow64\DWrite.dll
2012-03-14 17:36 . 2012-02-10 05:41        218624        ----a-w-        c:\windows\SysWow64\d3d10_1core.dll
2012-03-14 17:36 . 2012-02-10 06:17        902656        ----a-w-        c:\windows\system32\d2d1.dll
2012-03-14 17:36 . 2012-02-10 06:17        197120        ----a-w-        c:\windows\system32\d3d10_1.dll
2012-03-14 17:36 . 2012-02-10 05:41        161792        ----a-w-        c:\windows\SysWow64\d3d10_1.dll
2012-03-14 17:36 . 2012-02-10 05:41        1170944        ----a-w-        c:\windows\SysWow64\d3d10warp.dll
2012-03-14 17:36 . 2012-02-10 05:41        739840        ----a-w-        c:\windows\SysWow64\d2d1.dll
2012-03-14 15:40 . 2012-01-25 06:20        9216        ----a-w-        c:\windows\system32\rdrmemptylst.exe
2012-03-14 15:40 . 2012-01-25 06:27        76288        ----a-w-        c:\windows\system32\rdpwsx.dll
2012-03-14 15:40 . 2012-01-25 06:27        149504        ----a-w-        c:\windows\system32\rdpcorekmts.dll
2012-03-14 15:40 . 2012-02-15 06:27        1031680        ----a-w-        c:\windows\system32\rdpcore.dll
2012-03-14 15:40 . 2012-02-15 05:44        826368        ----a-w-        c:\windows\SysWow64\rdpcore.dll
2012-03-14 15:40 . 2012-02-15 04:47        204800        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-03-14 15:40 . 2012-02-15 04:46        23552        ----a-w-        c:\windows\system32\drivers\tdtcp.sys
2012-03-10 17:37 . 2012-04-03 23:16        --------        d-----w-        c:\program files (x86)\iTunes
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-23 18:53 . 2012-02-23 18:53        86528        ----a-w-        c:\windows\SysWow64\iesysprep.dll
2012-02-23 18:53 . 2012-02-23 18:53        76800        ----a-w-        c:\windows\SysWow64\SetIEInstalledDate.exe
2012-02-23 18:53 . 2012-02-23 18:53        74752        ----a-w-        c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-02-23 18:53 . 2012-02-23 18:53        48640        ----a-w-        c:\windows\SysWow64\mshtmler.dll
2012-02-23 18:53 . 2012-02-23 18:53        161792        ----a-w-        c:\windows\SysWow64\msls31.dll
2012-02-23 18:53 . 2012-02-23 18:53        110592        ----a-w-        c:\windows\SysWow64\IEAdvpack.dll
2012-02-23 18:53 . 2012-02-23 18:53        91648        ----a-w-        c:\windows\system32\SetIEInstalledDate.exe
2012-02-23 18:53 . 2012-02-23 18:53        89088        ----a-w-        c:\windows\system32\RegisterIEPKEYs.exe
2012-02-23 18:53 . 2012-02-23 18:53        76800        ----a-w-        c:\windows\system32\tdc.ocx
2012-02-23 18:53 . 2012-02-23 18:53        74752        ----a-w-        c:\windows\SysWow64\iesetup.dll
2012-02-23 18:53 . 2012-02-23 18:53        63488        ----a-w-        c:\windows\SysWow64\tdc.ocx
2012-02-23 18:53 . 2012-02-23 18:53        49664        ----a-w-        c:\windows\system32\imgutil.dll
2012-02-23 18:53 . 2012-02-23 18:53        48640        ----a-w-        c:\windows\system32\mshtmler.dll
2012-02-23 18:53 . 2012-02-23 18:53        448512        ----a-w-        c:\windows\system32\html.iec
2012-02-23 18:53 . 2012-02-23 18:53        420864        ----a-w-        c:\windows\SysWow64\vbscript.dll
2012-02-23 18:53 . 2012-02-23 18:53        367104        ----a-w-        c:\windows\SysWow64\html.iec
2012-02-23 18:53 . 2012-02-23 18:53        35840        ----a-w-        c:\windows\SysWow64\imgutil.dll
2012-02-23 18:53 . 2012-02-23 18:53        23552        ----a-w-        c:\windows\SysWow64\licmgr10.dll
2012-02-23 18:53 . 2012-02-23 18:53        222208        ----a-w-        c:\windows\system32\msls31.dll
2012-02-23 18:53 . 2012-02-23 18:53        173056        ----a-w-        c:\windows\system32\ieUnatt.exe
2012-02-23 18:53 . 2012-02-23 18:53        152064        ----a-w-        c:\windows\SysWow64\wextract.exe
2012-02-23 18:53 . 2012-02-23 18:53        150528        ----a-w-        c:\windows\SysWow64\iexpress.exe
2012-02-23 18:53 . 2012-02-23 18:53        142848        ----a-w-        c:\windows\SysWow64\ieUnatt.exe
2012-02-23 18:53 . 2012-02-23 18:53        135168        ----a-w-        c:\windows\system32\IEAdvpack.dll
2012-02-23 18:53 . 2012-02-23 18:53        12288        ----a-w-        c:\windows\system32\mshta.exe
2012-02-23 18:53 . 2012-02-23 18:53        11776        ----a-w-        c:\windows\SysWow64\mshta.exe
2012-02-23 18:53 . 2012-02-23 18:53        114176        ----a-w-        c:\windows\system32\admparse.dll
2012-02-23 18:53 . 2012-02-23 18:53        111616        ----a-w-        c:\windows\system32\iesysprep.dll
2012-02-23 18:53 . 2012-02-23 18:53        101888        ----a-w-        c:\windows\SysWow64\admparse.dll
2012-02-23 18:53 . 2012-02-23 18:53        85504        ----a-w-        c:\windows\system32\iesetup.dll
2012-02-23 18:53 . 2012-02-23 18:53        603648        ----a-w-        c:\windows\system32\vbscript.dll
2012-02-23 18:53 . 2012-02-23 18:53        30720        ----a-w-        c:\windows\system32\licmgr10.dll
2012-02-23 18:53 . 2012-02-23 18:53        165888        ----a-w-        c:\windows\system32\iexpress.exe
2012-02-23 18:53 . 2012-02-23 18:53        160256        ----a-w-        c:\windows\system32\wextract.exe
2012-02-23 08:18 . 2011-02-24 18:12        279656        ------w-        c:\windows\system32\MpSigStub.exe
2012-02-15 10:01 . 2012-02-15 10:01        52736        ----a-w-        c:\windows\system32\drivers\usbaapl64.sys
2012-02-15 10:01 . 2012-02-15 10:01        4547944        ----a-w-        c:\windows\system32\usbaaplrc.dll
2012-01-23 10:43 . 2012-01-30 14:58        56928        ----a-w-        c:\windows\system32\pxc40pm.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-08 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2009-08-12 352256]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 423936]
"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-01-13 34088]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-08-17 1294136]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-11-05 281768]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-09-27 59240]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe" [2009-08-12 6203296]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Sitecom Wireless Utility.lnk - c:\program files (x86)\Sitecom\Common\RaUI.exe [2010-6-12 1773568]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
R3 netr28ux;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28ux.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-27 136360]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2009-08-10 248688]
S2 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2009-07-14 42368]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
S2 PCSUService;PC Speed Up Service;c:\program files (x86)\PC Beschleunigen\PCSUService.exe [2011-07-20 206336]
S2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2009-08-06 116104]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-08-27 251760]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-03 137560]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-04 826224]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2012-04-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 23:26]
.
2012-04-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 23:26]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-03 709976]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2009-08-06 1050000]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-02 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-02 387608]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-02 365592]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-28 7982112]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2009-07-30 134032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEH&bmod=TSEH
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube to iPod Converter - c:\users\Ms Lauren Law\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 213.191.74.18 62.109.123.196
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
AddRemove-Uninstall_is1 - c:\program files (x86)\Common Files\DVDVideoSoft\unins000.exe
AddRemove-3988386017.www.pcspeedup.com - c:\program files (x86)\Microsoft Silverlight\4.0.60531.0\Silverlight.Configuration.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-806744476-1919467886-1915298580-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-806744476-1919467886-1915298580-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Sitecom\Common\RegistryWriter.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-04-05  12:42:20 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-04-05 10:42
.
Vor Suchlauf: 15 Verzeichnis(se), 87.391.416.320 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 87.008.587.776 Bytes frei
.
- - End Of File - - 0352AD34C668AFD0B07EB3AB1702136B

--- --- ---

cosinus 05.04.2012 13:41

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!
  • Starte die aswMBR.exe Vista und Win7 User aswMBR per Rechtsklick "als Administrator ausführen"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr", dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

LaurenLaw 05.04.2012 15:37

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-04-05 16:31:43
-----------------------------
16:31:43.963    OS Version: Windows x64 6.1.7600
16:31:43.963    Number of processors: 2 586 0x170A
16:31:43.965    ComputerName: MSLAURENLAW  UserName:
16:31:44.592    Initialize success
16:32:10.231    AVAST engine download error: 0
16:32:29.876    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
16:32:29.880    Disk 0 Vendor: TOSHIBA_ GC00 Size: 305245MB BusType: 3
16:32:29.924    Disk 0 MBR read successfully
16:32:29.929    Disk 0 MBR scan
16:32:29.934    Disk 0 Windows 7 default MBR code
16:32:29.949    Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS          400 MB offset 2048
16:32:29.959    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      152622 MB offset 821248
16:32:29.980    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      152222 MB offset 313391104
16:32:30.018    Disk 0 scanning C:\Windows\system32\drivers
16:32:37.123    Service scanning
16:33:14.141    Modules scanning
16:33:14.155    Disk 0 trace - called modules:
16:33:14.163   
16:33:14.504    Scan finished successfully
16:34:14.744    Disk 0 MBR has been saved successfully to "C:\Users\Ms Lauren Law\Desktop\MBR.dat"
16:34:14.750    The log file has been saved successfully to "C:\Users\Ms Lauren Law\Desktop\aswMBR.txt"


cosinus 05.04.2012 16:57

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

LaurenLaw 06.04.2012 19:18

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 04/06/2012 at 08:11 PM

Application Version : 5.0.1146

Core Rules Database Version : 8424
Trace Rules Database Version: 6236

Scan type      : Complete Scan
Total Scan Time : 02:08:48

Operating System Information
Windows 7 Home Premium 64-bit (Build 6.01.7600)
UAC On - Administrator

Memory items scanned      : 707
Memory threats detected  : 0
Registry items scanned    : 66352
Registry threats detected : 0
File items scanned        : 179944
File threats detected    : 642

Adware.Tracking Cookie
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@112.2o7[1].txt [ /112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@2.bfugmedia[1].txt [ /2.bfugmedia ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@247realmedia[2].txt [ /247realmedia ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@a.revenuemax[1].txt [ /a.revenuemax ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@account.live[2].txt [ /account.live ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@aco.solution.weborama[2].txt [ /aco.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.360yield[1].txt [ /ad.360yield ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.adition[1].txt [ /ad.adition ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.adnet[2].txt [ /ad.adnet ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.allvoices[1].txt [ /ad.allvoices ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.beepworld[2].txt [ /ad.beepworld ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.dyntracker[1].txt [ /ad.dyntracker ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.dyntracker[2].txt [ /ad.dyntracker ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.leadbolt[1].txt [ /ad.leadbolt ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.reklamport[2].txt [ /ad.reklamport ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.wsod[2].txt [ /ad.wsod ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad.youporn.videobox[1].txt [ /ad.youporn.videobox ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad1.adfarm.adtelligence[2].txt [ /ad1.adfarm.adtelligence ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad2.adfarm1.adition[1].txt [ /ad2.adfarm1.adition ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad5.adfarm1.adition[2].txt [ /ad5.adfarm1.adition ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ad6media[1].txt [ /ad6media ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adbrite[1].txt [ /adbrite ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adcentriconline[2].txt [ /adcentriconline ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adinterax[2].txt [ /adinterax ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.ad4game[2].txt [ /ads.ad4game ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.adk2[2].txt [ /ads.adk2 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.carpooling[1].txt [ /ads.carpooling ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.cinemaden[1].txt [ /ads.cinemaden ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.clicmanager[1].txt [ /ads.clicmanager ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.cosmotourist[2].txt [ /ads.cosmotourist ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.cpxadroit[2].txt [ /ads.cpxadroit ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.e-planning[1].txt [ /ads.e-planning ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.fling[1].txt [ /ads.fling ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.horyzon-media[2].txt [ /ads.horyzon-media ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.iadmanager[2].txt [ /ads.iadmanager ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.immobilienscout24[1].txt [ /ads.immobilienscout24 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.lzjl[2].txt [ /ads.lzjl ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.medienhaus[1].txt [ /ads.medienhaus ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.mikinimedia[2].txt [ /ads.mikinimedia ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.mitfahrzentrale[1].txt [ /ads.mitfahrzentrale ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.moveco[1].txt [ /ads.moveco ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.moviease[1].txt [ /ads.moviease ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.pointroll[1].txt [ /ads.pointroll ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.quartermedia[2].txt [ /ads.quartermedia ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.sportwerk[1].txt [ /ads.sportwerk ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.startseiten24[1].txt [ /ads.startseiten24 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.traffikings[1].txt [ /ads.traffikings ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.travel-overland[1].txt [ /ads.travel-overland ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.undertone[2].txt [ /ads.undertone ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.us.e-planning[1].txt [ /ads.us.e-planning ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.youporn[2].txt [ /ads.youporn ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads.zeusclicks[1].txt [ /ads.zeusclicks ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads2.zeusclicks[1].txt [ /ads2.zeusclicks ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads20.wwe-media[2].txt [ /ads20.wwe-media ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ads5.netpublisher[2].txt [ /ads5.netpublisher ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserv.quality-channel[2].txt [ /adserv.quality-channel ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.adreactor[1].txt [ /adserver.adreactor ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.adtechus[1].txt [ /adserver.adtechus ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.kino-zeit[1].txt [ /adserver.kino-zeit ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.mitfahrzentrale[2].txt [ /adserver.mitfahrzentrale ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.tattooscout[1].txt [ /adserver.tattooscout ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.webmasterbond[1].txt [ /adserver.webmasterbond ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver.yopi[1].txt [ /adserver.yopi ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver2.clipkit[1].txt [ /adserver2.clipkit ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserver2.traffictrack[2].txt [ /adserver2.traffictrack ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adserving.versaneeds[1].txt [ /adserving.versaneeds ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adsrv.admediate[2].txt [ /adsrv.admediate ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adsrv1.admediate[1].txt [ /adsrv1.admediate ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adtech[1].txt [ /adtech ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@advertising[2].txt [ /advertising ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@advertstream[1].txt [ /advertstream ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adx.chip[2].txt [ /adx.chip ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adxpansion[2].txt [ /adxpansion ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@adxpose[1].txt [ /adxpose ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@aidacruises.122.2o7[1].txt [ /aidacruises.122.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@aimfar.solution.weborama[1].txt [ /aimfar.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@albumprinter.122.2o7[1].txt [ /albumprinter.122.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@apmebf[1].txt [ /apmebf ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@apodiscounter[1].txt [ /apodiscounter ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@atdmt.combing[1].txt [ /atdmt.combing ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@autoscout24.112.2o7[1].txt [ /autoscout24.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@banner.testberichte[1].txt [ /banner.testberichte ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@banquepopulaire2010.solution.weborama[2].txt [ /banquepopulaire2010.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@baseco.solution.weborama[2].txt [ /baseco.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@bizrate[1].txt [ /bizrate ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@bluestreak[2].txt [ /bluestreak ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@bnpparibasnet.solution.weborama[2].txt [ /bnpparibasnet.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@bs.serving-sys[2].txt [ /bs.serving-sys ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@burstnet[2].txt [ /burstnet ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@cdn5.specificclick[1].txt [ /cdn5.specificclick ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@cheaptickets.122.2o7[1].txt [ /cheaptickets.122.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@clickbank[1].txt [ /clickbank ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@clicks.pangora[1].txt [ /clicks.pangora ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@clicksor[1].txt [ /clicksor ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@cngg-stats.condenastdigital[1].txt [ /cngg-stats.condenastdigital ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@cofidis2.solution.weborama[2].txt [ /cofidis2.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@content.yieldmanager[3].txt [ /content.yieldmanager ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@count.rbc[1].txt [ /count.rbc ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@countomat[1].txt [ /countomat ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@cunda.122.2o7[1].txt [ /cunda.122.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@dealtime[1].txt [ /dealtime ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@deutschepostag.112.2o7[1].txt [ /deutschepostag.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@directtrack[1].txt [ /directtrack ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@discounter-in-deutschland[2].txt [ /discounter-in-deutschland ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@dmtracker[1].txt [ /dmtracker ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ds.clickexperts[1].txt [ /ds.clickexperts ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@dztadserver.dx-work[2].txt [ /dztadserver.dx-work ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6aekiogazmko.stats.esomniture[2].txt [ /e-2dj6aekiogazmko.stats.esomniture ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6aekyghcjsep.stats.esomniture[2].txt [ /e-2dj6aekyghcjsep.stats.esomniture ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6aeliakdjsco.stats.esomniture[2].txt [ /e-2dj6aeliakdjsco.stats.esomniture ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6wbliwgd5olo.stats.esomniture[2].txt [ /e-2dj6wbliwgd5olo.stats.esomniture ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6wcliwoc5chp.stats.esomniture[2].txt [ /e-2dj6wcliwoc5chp.stats.esomniture ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6whkowiczmdp.stats.esomniture[1].txt [ /e-2dj6whkowiczmdp.stats.esomniture ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6wjlyahd5glp.stats.esomniture[2].txt [ /e-2dj6wjlyahd5glp.stats.esomniture ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6wmk4omd5iep.stats.esomniture[2].txt [ /e-2dj6wmk4omd5iep.stats.esomniture ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@e-2dj6wnmyeidzgeo.stats.esomniture[2].txt [ /e-2dj6wnmyeidzgeo.stats.esomniture ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@eaeacom.112.2o7[1].txt [ /eaeacom.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@eas4.emediate[1].txt [ /eas4.emediate ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@elitepartner.tt.omtrdc[2].txt [ /elitepartner.tt.omtrdc ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@elitepartner[1].txt [ /elitepartner ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ero-advertising[2].txt [ /ero-advertising ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@eyewonder[2].txt [ /eyewonder ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@fl01.ct2.comclick[2].txt [ /fl01.ct2.comclick ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@frontlinegmbh.122.2o7[1].txt [ /frontlinegmbh.122.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@gemey2011.solution.weborama[2].txt [ /gemey2011.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@germanwings.112.2o7[1].txt [ /germanwings.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@girlsteachsex[2].txt [ /girlsteachsex ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@gostats[1].txt [ /gostats ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@gotacha.rotator.hadj7.adjuggler[1].txt [ /gotacha.rotator.hadj7.adjuggler ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@gotacha.rotator.hadj7.adjuggler[2].txt [ /gotacha.rotator.hadj7.adjuggler ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@guj.122.2o7[1].txt [ /guj.122.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@hansenet.122.2o7[1].txt [ /hansenet.122.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@harrenmedianetwork[1].txt [ /harrenmedianetwork ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@himedia.individuad[1].txt [ /himedia.individuad ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@horyzon-media[1].txt [ /horyzon-media ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ice.112.2o7[1].txt [ /ice.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@idtgv.solution.weborama[2].txt [ /idtgv.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@imrworldwide[2].txt [ /imrworldwide ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@indigio.122.2o7[1].txt [ /indigio.122.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@interclick[1].txt [ /interclick ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@intersportmontagne.solution.weborama[2].txt [ /intersportmontagne.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@jsfp.coremetrics[2].txt [ /jsfp.coremetrics ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@komtrack[1].txt [ /komtrack ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@komtrack[2].txt [ /komtrack ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@kontera[1].txt [ /kontera ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@legolas-media[1].txt [ /legolas-media ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@lfstmedia[1].txt [ /lfstmedia ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@liveperson[1].txt [ /liveperson ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@liveperson[2].txt [ /liveperson ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@liveperson[3].txt [ /liveperson ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@liveperson[5].txt [ /liveperson ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@loralparis2011.solution.weborama[2].txt [ /loralparis2011.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@lstat.youku[1].txt [ /lstat.youku ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@media.photobucket[1].txt [ /media.photobucket ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@media2.legacy[1].txt [ /media2.legacy ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@media6degrees[2].txt [ /media6degrees ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@mediafire[1].txt [ /mediafire ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@mediaforge[1].txt [ /mediaforge ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@mediastay.directtrack[2].txt [ /mediastay.directtrack ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@metroleap.rotator.hadj7.adjuggler[2].txt [ /metroleap.rotator.hadj7.adjuggler ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@microsoftinternetexplorer.112.2o7[1].txt [ /microsoftinternetexplorer.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@microsoftmachinetranslation.112.2o7[1].txt [ /microsoftmachinetranslation.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@microsoftwlsearchcrm.112.2o7[1].txt [ /microsoftwlsearchcrm.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@mm.chitika[1].txt [ /mm.chitika ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@monoprix.solution.weborama[2].txt [ /monoprix.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@msnportal.112.2o7[1].txt [ /msnportal.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@naked[1].txt [ /naked ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@nedstat.hostelbookers[1].txt [ /nedstat.hostelbookers ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@nedstat.hostelbookers[2].txt [ /nedstat.hostelbookers ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@nedstat.hostelbookers[3].txt [ /nedstat.hostelbookers ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@nextag[1].txt [ /nextag ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@nike.112.2o7[1].txt [ /nike.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@overture[1].txt [ /overture ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@parship.122.2o7[1].txt [ /parship.122.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@partypoker[3].txt [ /partypoker ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@paypal.112.2o7[1].txt [ /paypal.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@pluckit.demandmedia[1].txt [ /pluckit.demandmedia ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@pmu3.solution.weborama[2].txt [ /pmu3.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@pointroll[2].txt [ /pointroll ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@pornhub[2].txt [ /pornhub ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@pornme[2].txt [ /pornme ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@realmedia[2].txt [ /realmedia ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@revenue[2].txt [ /revenue ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@revsci[1].txt [ /revsci ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@rgadvert[2].txt [ /rgadvert ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@roitracking[1].txt [ /roitracking ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@rotator.adjuggler[1].txt [ /rotator.adjuggler ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ru4[1].txt [ /ru4 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@secmedia[2].txt [ /secmedia ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@server.cpmstar[2].txt [ /server.cpmstar ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@server.iad.liveperson[1].txt [ /server.iad.liveperson ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@server.lon.liveperson[1].txt [ /server.lon.liveperson ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@sevenoneintermedia.112.2o7[1].txt [ /sevenoneintermedia.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@sfr.solution.weborama[2].txt [ /sfr.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@snapfish.112.2o7[1].txt [ /snapfish.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@specificclick[1].txt [ /specificclick ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@start.elitepartner[2].txt [ /start.elitepartner ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stat.culturebase[1].txt [ /stat.culturebase ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stat.dealtime[1].txt [ /stat.dealtime ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stat.heimat[2].txt [ /stat.heimat ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stat.onestat[2].txt [ /stat.onestat ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stat.youku[1].txt [ /stat.youku ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@statcounter[1].txt [ /statcounter ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stats.d-p-h[1].txt [ /stats.d-p-h ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stats.paypal[2].txt [ /stats.paypal ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@stats.yetanotherblog[1].txt [ /stats.yetanotherblog ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@statsadv.dadapro[1].txt [ /statsadv.dadapro ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@supremeadserver[2].txt [ /supremeadserver ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tacoda.at.atwola[2].txt [ /tacoda.at.atwola ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tele2de.112.2o7[1].txt [ /tele2de.112.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tns-counter[1].txt [ /tns-counter ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@toyota2.solution.weborama[2].txt [ /toyota2.solution.weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@track.effiliation[1].txt [ /track.effiliation ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@track.webtrekk[1].txt [ /track.webtrekk ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@track.webtrekk[2].txt [ /track.webtrekk ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.3gnet[1].txt [ /tracking.3gnet ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.affiliaxe[2].txt [ /tracking.affiliaxe ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.bmbfcluster[1].txt [ /tracking.bmbfcluster ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.dc-storm[1].txt [ /tracking.dc-storm ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.ejoni[1].txt [ /tracking.ejoni ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.hannoversche[1].txt [ /tracking.hannoversche ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.inuvo[2].txt [ /tracking.inuvo ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.publicidees[1].txt [ /tracking.publicidees ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.star-advertising[2].txt [ /tracking.star-advertising ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.tchibo[1].txt [ /tracking.tchibo ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tracking.veille-referencement[2].txt [ /tracking.veille-referencement ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tradedoubler[1].txt [ /tradedoubler ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@trafficmp[1].txt [ /trafficmp ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@traveladvertising[1].txt [ /traveladvertising ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@tto2.traffictrack[2].txt [ /tto2.traffictrack ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@uk.at.atwola[1].txt [ /uk.at.atwola ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@usenext.122.2o7[1].txt [ /usenext.122.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@viacom.adbureau[2].txt [ /viacom.adbureau ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@videoegg.adbureau[1].txt [ /videoegg.adbureau ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@vinvest.122.2o7[1].txt [ /vinvest.122.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@vodafonegroup.122.2o7[1].txt [ /vodafonegroup.122.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@weborama[1].txt [ /weborama ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@wissende.122.2o7[1].txt [ /wissende.122.2o7 ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@ww381.smartadserver[2].txt [ /ww381.smartadserver ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.active-tracking[2].txt [ /www.active-tracking ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.advertonic[2].txt [ /www.advertonic ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.bigtracker[1].txt [ /www.bigtracker ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.burstnet[2].txt [ /www.burstnet ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.elitepartner[2].txt [ /www.elitepartner ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[10].txt [ /www.googleadservices ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[11].txt [ /www.googleadservices ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[1].txt [ /www.googleadservices ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[3].txt [ /www.googleadservices ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[5].txt [ /www.googleadservices ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[6].txt [ /www.googleadservices ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[7].txt [ /www.googleadservices ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[8].txt [ /www.googleadservices ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.googleadservices[9].txt [ /www.googleadservices ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.messengerdusexe[1].txt [ /www.messengerdusexe ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.pornhub[1].txt [ /www.pornhub ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.traffic2drive[1].txt [ /www.traffic2drive ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www.yuoporn[1].txt [ /www.yuoporn ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@www3.smartadserver[2].txt [ /www3.smartadserver ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@xiti[1].txt [ /xiti ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@xm.xtendmedia[2].txt [ /xm.xtendmedia ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@yadro[2].txt [ /yadro ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@yieldmanager[1].txt [ /yieldmanager ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@youporn.videobox[1].txt [ /youporn.videobox ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@youporne[1].txt [ /youporne ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@youporn[2].txt [ /youporn ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ms_lauren_law@zbox.zanox[1].txt [ /zbox.zanox ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\1VL01HFJ.txt [ /tracking.quisma.com ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\Q0H56MWF.txt [ /fastclick.net ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\M7FFZQK4.txt [ /youporn.com ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\T1U0HIZC.txt [ /mediaplex.com ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\JO5SKGAC.txt [ /de.partypoker.com ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\42R09K1H.txt [ /doubleclick.net ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\IV9WQBJM.txt [ /www.youporn.com ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\IBWMCMCU.txt [ /www.usenext.de ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\024Q7JNZ.txt [ /apmebf.com ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\8UC650DI.txt [ /partypoker.com ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\X93X1RIP.txt [ /zanox.com ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\ZVPP3UXE.txt [ /forum.usenext.de ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\DJXPEQR3.txt [ /oracle.112.2o7.net ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\GW63R3PI.txt [ /usenext.de ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\NYRKDB5B.txt [ /smartadserver.com ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\B0YAUVSD.txt [ /ad.adc-serv.net ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\QJOIKU4L.txt [ /counter.hitslink.com ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\SUVW7D4B.txt [ /rts.pgmediaserve.com ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\Q7CFTT4D.txt [ /exoclick.com ]
        C:\Users\Ms Lauren Law\AppData\Roaming\Microsoft\Windows\Cookies\0OHRAM65.txt [ /www.usenext.com ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@imrworldwide[2].txt [ Cookie:ms lauren law@imrworldwide.com/cgi-bin ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\R85HYIYM.txt [ Cookie:ms lauren law@fastclick.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads.quartermedia[2].txt [ Cookie:ms lauren law@ads.quartermedia.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\BQPTFBRZ.txt [ Cookie:ms lauren law@youporn.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@media6degrees[2].txt [ Cookie:ms lauren law@media6degrees.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@snapfish.112.2o7[1].txt [ Cookie:ms lauren law@snapfish.112.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@msnportal.112.2o7[1].txt [ Cookie:ms lauren law@msnportal.112.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\C0GUQR46.txt [ Cookie:ms lauren law@traffictrack.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\KNL64NFX.txt [ Cookie:ms lauren law@track.effiliation.com/servlet/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@bluestreak[2].txt [ Cookie:ms lauren law@bluestreak.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.pornhub[1].txt [ Cookie:ms lauren law@www.pornhub.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\JQLL3UFZ.txt [ Cookie:ms lauren law@eas.apm.emediate.eu/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\NG3PFQER.txt [ Cookie:ms lauren law@atdmt.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@intersportmontagne.solution.weborama[2].txt [ Cookie:ms lauren law@intersportmontagne.solution.weborama.fr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@countomat[1].txt [ Cookie:ms lauren law@countomat.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\BKYV9O33.txt [ Cookie:ms lauren law@doubleclick.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@eyewonder[2].txt [ Cookie:ms lauren law@eyewonder.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@paypal.112.2o7[1].txt [ Cookie:ms lauren law@paypal.112.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@autoscout24.112.2o7[1].txt [ Cookie:ms lauren law@autoscout24.112.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@eaeacom.112.2o7[1].txt [ Cookie:ms lauren law@eaeacom.112.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@guj.122.2o7[1].txt [ Cookie:ms lauren law@guj.122.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@lfstmedia[1].txt [ Cookie:ms lauren law@lfstmedia.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\VDDK7NVB.txt [ Cookie:ms lauren law@adviva.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\A7A27Y33.txt [ Cookie:ms lauren law@tradedoubler.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@track.effiliation[1].txt [ Cookie:ms lauren law@track.effiliation.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@xiti[1].txt [ Cookie:ms lauren law@xiti.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@apmebf[1].txt [ Cookie:ms lauren law@apmebf.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads.youporn[2].txt [ Cookie:ms lauren law@ads.youporn.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\JACEA0WE.txt [ Cookie:ms lauren law@bs.serving-sys.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\A1JT2B8K.txt [ Cookie:ms lauren law@zanox.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\42H9H0PO.txt [ Cookie:ms lauren law@partypoker.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@xm.xtendmedia[2].txt [ Cookie:ms lauren law@xm.xtendmedia.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@youporn[2].txt [ Cookie:ms lauren law@youporn.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\162AKRQ7.txt [ Cookie:ms lauren law@casalemedia.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\DX9DU1RR.txt [ Cookie:ms lauren law@questionmarket.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adserver.adtechus[1].txt [ Cookie:ms lauren law@adserver.adtechus.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\RA6YD216.txt [ Cookie:ms lauren law@www.zanox-affiliate.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[2].txt [ Cookie:ms lauren law@de.sitestat.com/karstadt-de/karstadt/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@statcounter[1].txt [ Cookie:ms lauren law@statcounter.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZCNFOIJT.txt [ Cookie:ms lauren law@www.etracker.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\IYYHY7PA.txt [ Cookie:ms lauren law@tracking.mindshare.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@traveladvertising[1].txt [ Cookie:ms lauren law@traveladvertising.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@247realmedia[2].txt [ Cookie:ms lauren law@247realmedia.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\R1RTLESE.txt [ Cookie:ms lauren law@smartadserver.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\PWICDX3M.txt [ Cookie:ms lauren law@adtech.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@revenue[2].txt [ Cookie:ms lauren law@revenue.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@2.bfugmedia[1].txt [ Cookie:ms lauren law@2.bfugmedia.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\TDKV0JRL.txt [ Cookie:ms lauren law@adultfriendfinder.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@youporn.videobox[1].txt [ Cookie:ms lauren law@youporn.videobox.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\XZOS6U6N.txt [ Cookie:ms lauren law@2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.elitepartner[2].txt [ Cookie:ms lauren law@www.elitepartner.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ru4[1].txt [ Cookie:ms lauren law@ru4.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@hansenet.122.2o7[1].txt [ Cookie:ms lauren law@hansenet.122.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.burstnet[2].txt [ Cookie:ms lauren law@www.burstnet.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@lstat.youku[1].txt [ Cookie:ms lauren law@lstat.youku.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@nedstat.hostelbookers[3].txt [ Cookie:ms lauren law@nedstat.hostelbookers.com/hb/de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[1].txt [ Cookie:ms lauren law@de.sitestat.com/is24-mail/is24-mail/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\IQZ4P2O5.txt [ Cookie:ms lauren law@ad3.adfarm1.adition.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tns-counter[1].txt [ Cookie:ms lauren law@tns-counter.ru/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.hannoversche[1].txt [ Cookie:ms lauren law@tracking.hannoversche.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@wissende.122.2o7[1].txt [ Cookie:ms lauren law@wissende.122.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\U55NOPYI.txt [ Cookie:ms lauren law@revsci.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[3].txt [ Cookie:ms lauren law@de.sitestat.com/karstadt-de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@rotator.adjuggler[1].txt [ Cookie:ms lauren law@rotator.adjuggler.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@uk.at.atwola[1].txt [ Cookie:ms lauren law@uk.at.atwola.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@himedia.individuad[1].txt [ Cookie:ms lauren law@himedia.individuad.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ad.adition[1].txt [ Cookie:ms lauren law@ad.adition.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@videoegg.adbureau[1].txt [ Cookie:ms lauren law@videoegg.adbureau.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZZVQ1G1I.txt [ Cookie:ms lauren law@ads.crakmedia.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adserver2.traffictrack[2].txt [ Cookie:ms lauren law@adserver2.traffictrack.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@jsfp.coremetrics[2].txt [ Cookie:ms lauren law@jsfp.coremetrics.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\3AGWQY0F.txt [ Cookie:ms lauren law@collective-media.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ad.adnet[2].txt [ Cookie:ms lauren law@ad.adnet.biz/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ero-advertising[2].txt [ Cookie:ms lauren law@ero-advertising.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\G6OWCP1O.txt [ Cookie:ms lauren law@adx.chip.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.yuoporn[1].txt [ Cookie:ms lauren law@www.yuoporn.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@apodiscounter[1].txt [ Cookie:ms lauren law@apodiscounter.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads20.wwe-media[2].txt [ Cookie:ms lauren law@ads20.wwe-media.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ad5.adfarm1.adition[2].txt [ Cookie:ms lauren law@ad5.adfarm1.adition.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@burstnet[2].txt [ Cookie:ms lauren law@burstnet.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adbrite[1].txt [ Cookie:ms lauren law@adbrite.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@cunda.122.2o7[1].txt [ Cookie:ms lauren law@cunda.122.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@fl01.ct2.comclick[2].txt [ Cookie:ms lauren law@fl01.ct2.comclick.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adserver.kino-zeit[1].txt [ Cookie:ms lauren law@adserver.kino-zeit.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\1I86LBXG.txt [ Cookie:ms lauren law@ad2.adfarm1.adition.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\FGS448NP.txt [ Cookie:ms lauren law@statse.webtrendslive.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@microsoftmachinetranslation.112.2o7[1].txt [ Cookie:ms lauren law@microsoftmachinetranslation.112.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.inuvo[2].txt [ Cookie:ms lauren law@tracking.inuvo.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@mediafire[1].txt [ Cookie:ms lauren law@mediafire.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ice.112.2o7[1].txt [ Cookie:ms lauren law@ice.112.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\Z3OHBIDK.txt [ Cookie:ms lauren law@ad.adnet.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\6X0ZG97B.txt [ Cookie:ms lauren law@tribalfusion.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@komtrack[2].txt [ Cookie:ms lauren law@komtrack.com/tr/869350 ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@track.webtrekk[1].txt [ Cookie:ms lauren law@track.webtrekk.de/562243648792138/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@roitracking[1].txt [ Cookie:ms lauren law@roitracking.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@clicksor[1].txt [ Cookie:ms lauren law@clicksor.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\1451A7YO.txt [ Cookie:ms lauren law@unitymedia.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\7TQZMBV7.txt [ Cookie:ms lauren law@im.banner.t-online.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@overture[1].txt [ Cookie:ms lauren law@overture.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@advertising[2].txt [ Cookie:ms lauren law@advertising.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@aidacruises.122.2o7[1].txt [ Cookie:ms lauren law@aidacruises.122.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\8O676AKJ.txt [ Cookie:ms lauren law@adform.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@nike.112.2o7[1].txt [ Cookie:ms lauren law@nike.112.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@statsadv.dadapro[1].txt [ Cookie:ms lauren law@statsadv.dadapro.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@loralparis2011.solution.weborama[2].txt [ Cookie:ms lauren law@loralparis2011.solution.weborama.fr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adserver.tattooscout[1].txt [ Cookie:ms lauren law@adserver.tattooscout.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@count.rbc[1].txt [ Cookie:ms lauren law@count.rbc.ru/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@stat.onestat[2].txt [ Cookie:ms lauren law@stat.onestat.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@sevenoneintermedia.112.2o7[1].txt [ Cookie:ms lauren law@sevenoneintermedia.112.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\OD5A8HT5.txt [ Cookie:ms lauren law@studivz.adfarm1.adition.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\W3VLYTNE.txt [ Cookie:ms lauren law@de.partypoker.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@in.mydirtyhobby[2].txt [ Cookie:ms lauren law@in.mydirtyhobby.com/track/vZIPADkU,33/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@komtrack[1].txt [ Cookie:ms lauren law@komtrack.com/tr ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\JXEGQGL0.txt [ Cookie:ms lauren law@ad4.adfarm1.adition.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@idtgv.solution.weborama[2].txt [ Cookie:ms lauren law@idtgv.solution.weborama.fr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@e-2dj6wnmyeidzgeo.stats.esomniture[2].txt [ Cookie:ms lauren law@e-2dj6wnmyeidzgeo.stats.esomniture.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\4S9ZZME9.txt [ Cookie:ms lauren law@www.google.com/accounts ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adinterax[2].txt [ Cookie:ms lauren law@adinterax.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@e-2dj6aekiogazmko.stats.esomniture[2].txt [ Cookie:ms lauren law@e-2dj6aekiogazmko.stats.esomniture.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@e-2dj6aeliakdjsco.stats.esomniture[2].txt [ Cookie:ms lauren law@e-2dj6aeliakdjsco.stats.esomniture.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@stat.dealtime[1].txt [ Cookie:ms lauren law@stat.dealtime.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.ejoni[1].txt [ Cookie:ms lauren law@tracking.ejoni.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@secmedia[2].txt [ Cookie:ms lauren law@secmedia.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads.pointroll[1].txt [ Cookie:ms lauren law@ads.pointroll.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.bigtracker[1].txt [ Cookie:ms lauren law@www.bigtracker.de/piwik/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\JP7KJ3IW.txt [ Cookie:ms lauren law@www.youporn.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ds.clickexperts[1].txt [ Cookie:ms lauren law@ds.clickexperts.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@yieldmanager[1].txt [ Cookie:ms lauren law@yieldmanager.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adxpose[1].txt [ Cookie:ms lauren law@adxpose.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@vinvest.122.2o7[1].txt [ Cookie:ms lauren law@vinvest.122.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@baseco.solution.weborama[2].txt [ Cookie:ms lauren law@baseco.solution.weborama.fr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@indigio.122.2o7[1].txt [ Cookie:ms lauren law@indigio.122.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@sfr.solution.weborama[2].txt [ Cookie:ms lauren law@sfr.solution.weborama.fr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@stat.youku[1].txt [ Cookie:ms lauren law@stat.youku.com/player/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@kontera[1].txt [ Cookie:ms lauren law@kontera.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@liveperson[1].txt [ Cookie:ms lauren law@liveperson.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@clicks.pangora[1].txt [ Cookie:ms lauren law@clicks.pangora.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@media2.legacy[1].txt [ Cookie:ms lauren law@media2.legacy.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.advertonic[2].txt [ Cookie:ms lauren law@www.advertonic.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@youporne[1].txt [ Cookie:ms lauren law@youporne.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@discounter-in-deutschland[2].txt [ Cookie:ms lauren law@discounter-in-deutschland.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@yadro[2].txt [ Cookie:ms lauren law@yadro.ru/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\SN0IFLZN.txt [ Cookie:ms lauren law@content.yieldmanager.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\K6L4SH87.txt [ Cookie:ms lauren law@rts.pgmediaserve.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.veille-referencement[2].txt [ Cookie:ms lauren law@tracking.veille-referencement.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@aimfar.solution.weborama[1].txt [ Cookie:ms lauren law@aimfar.solution.weborama.fr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@stats.paypal[2].txt [ Cookie:ms lauren law@stats.paypal.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@partypoker[3].txt [ Cookie:ms lauren law@partypoker.fr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@metroleap.rotator.hadj7.adjuggler[2].txt [ Cookie:ms lauren law@metroleap.rotator.hadj7.adjuggler.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[10].txt [ Cookie:ms lauren law@de.sitestat.com/haba/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@a.revenuemax[1].txt [ Cookie:ms lauren law@a.revenuemax.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@pluckit.demandmedia[1].txt [ Cookie:ms lauren law@pluckit.demandmedia.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\3ZL8GT48.txt [ Cookie:ms lauren law@pornografish.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@supremeadserver[2].txt [ Cookie:ms lauren law@supremeadserver.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@dmtracker[1].txt [ Cookie:ms lauren law@dmtracker.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tacoda.at.atwola[2].txt [ Cookie:ms lauren law@tacoda.at.atwola.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@gemey2011.solution.weborama[2].txt [ Cookie:ms lauren law@gemey2011.solution.weborama.fr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@microsoftinternetexplorer.112.2o7[1].txt [ Cookie:ms lauren law@microsoftinternetexplorer.112.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.active-tracking[2].txt [ Cookie:ms lauren law@www.active-tracking.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@pointroll[2].txt [ Cookie:ms lauren law@pointroll.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@e-2dj6aekyghcjsep.stats.esomniture[2].txt [ Cookie:ms lauren law@e-2dj6aekyghcjsep.stats.esomniture.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adxpansion[2].txt [ Cookie:ms lauren law@adxpansion.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@server.lon.liveperson[1].txt [ Cookie:ms lauren law@server.lon.liveperson.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@bizrate[1].txt [ Cookie:ms lauren law@bizrate.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ww381.smartadserver[2].txt [ Cookie:ms lauren law@ww381.smartadserver.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@dztadserver.dx-work[2].txt [ Cookie:ms lauren law@dztadserver.dx-work.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads2.zeusclicks[1].txt [ Cookie:ms lauren law@ads2.zeusclicks.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\4QU9CD6T.txt [ Cookie:ms lauren law@media.gan-online.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[8].txt [ Cookie:ms lauren law@de.sitestat.com/ndr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\QGQK5DW8.txt [ Cookie:ms lauren law@banners.xxxgaymatch.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@liveperson[3].txt [ Cookie:ms lauren law@liveperson.net/hc/67442175 ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@stats.yetanotherblog[1].txt [ Cookie:ms lauren law@stats.yetanotherblog.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@trafficmp[1].txt [ Cookie:ms lauren law@trafficmp.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@directtrack[1].txt [ Cookie:ms lauren law@directtrack.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@account.live[2].txt [ Cookie:ms lauren law@account.live.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@frontlinegmbh.122.2o7[1].txt [ Cookie:ms lauren law@frontlinegmbh.122.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@rgadvert[2].txt [ Cookie:ms lauren law@rgadvert.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\1WUB3NRI.txt [ Cookie:ms lauren law@www.usenext.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[7].txt [ Cookie:ms lauren law@de.sitestat.com/ndr/ts/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@mediaforge[1].txt [ Cookie:ms lauren law@mediaforge.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@e-2dj6whkowiczmdp.stats.esomniture[1].txt [ Cookie:ms lauren law@e-2dj6whkowiczmdp.stats.esomniture.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.3gnet[1].txt [ Cookie:ms lauren law@tracking.3gnet.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@zbox.zanox[1].txt [ Cookie:ms lauren law@zbox.zanox.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@cngg-stats.condenastdigital[1].txt [ Cookie:ms lauren law@cngg-stats.condenastdigital.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.googleadservices[1].txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1066875729/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.googleadservices[9].txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1021415196/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@server.cpmstar[2].txt [ Cookie:ms lauren law@server.cpmstar.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\XSDIGG8H.txt [ Cookie:ms lauren law@www.youporncocks.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@fr.sitestat[1].txt [ Cookie:ms lauren law@fr.sitestat.com/euronews/euronews/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[4].txt [ Cookie:ms lauren law@de.sitestat.com/sueddeutsche/sueddeutsche/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.traffic2drive[1].txt [ Cookie:ms lauren law@www.traffic2drive.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@mm.chitika[1].txt [ Cookie:ms lauren law@mm.chitika.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.affiliaxe[2].txt [ Cookie:ms lauren law@tracking.affiliaxe.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@server.iad.liveperson[1].txt [ Cookie:ms lauren law@server.iad.liveperson.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@gotacha.rotator.hadj7.adjuggler[1].txt [ Cookie:ms lauren law@gotacha.rotator.hadj7.adjuggler.net/servlet/ajrotator/85029/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\L1XSCPA9.txt [ Cookie:ms lauren law@adserver2.exgfnetwork.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.googleadservices[3].txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1051309330/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\HYWRVY4T.txt [ Cookie:ms lauren law@stats.justhost.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\6QUCDKES.txt [ Cookie:ms lauren law@tracking.mlsat02.de/tmobile/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@aco.solution.weborama[2].txt [ Cookie:ms lauren law@aco.solution.weborama.fr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ad6media[1].txt [ Cookie:ms lauren law@ad6media.fr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@germanwings.112.2o7[1].txt [ Cookie:ms lauren law@germanwings.112.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.googleadservices[5].txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1052039368/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tracking.publicidees[1].txt [ Cookie:ms lauren law@tracking.publicidees.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adsonar[3].txt [ Cookie:ms lauren law@adsonar.com/adserving ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@start.elitepartner[2].txt [ Cookie:ms lauren law@start.elitepartner.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\5RWZ47KR.txt [ Cookie:ms lauren law@youporncocks.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@clkads[4].txt [ Cookie:ms lauren law@clkads.com/adServe/static/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\6SQWSL16.txt [ Cookie:ms lauren law@freewebcamsex.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\GUK2O59F.txt [ Cookie:ms lauren law@edates.traffective-tracking.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@realmedia[2].txt [ Cookie:ms lauren law@realmedia.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@banquepopulaire2010.solution.weborama[2].txt [ Cookie:ms lauren law@banquepopulaire2010.solution.weborama.fr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\HTCLUF2S.txt [ Cookie:ms lauren law@youporngay.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\LZ61W26B.txt [ Cookie:ms lauren law@h.atdmt.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\46YUUEJO.txt [ Cookie:ms lauren law@exoclick.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@usenext.122.2o7[1].txt [ Cookie:ms lauren law@usenext.122.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@mediastay.directtrack[2].txt [ Cookie:ms lauren law@mediastay.directtrack.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adserving.versaneeds[1].txt [ Cookie:ms lauren law@adserving.versaneeds.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@pmu3.solution.weborama[2].txt [ Cookie:ms lauren law@pmu3.solution.weborama.fr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@liveperson[2].txt [ Cookie:ms lauren law@liveperson.net/hc/16903755 ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@bnpparibasnet.solution.weborama[2].txt [ Cookie:ms lauren law@bnpparibasnet.solution.weborama.fr/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www3.smartadserver[2].txt [ Cookie:ms lauren law@www3.smartadserver.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@content.yieldmanager[3].txt [ Cookie:ms lauren law@content.yieldmanager.com/ak/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\E0BDL23X.txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1065944648/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@tto2.traffictrack[2].txt [ Cookie:ms lauren law@tto2.traffictrack.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\E31BK844.txt [ Cookie:ms lauren law@exoclick.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\H69GKR03.txt [ Cookie:ms lauren law@hightraffic.hugoboss.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\6XEWZXSE.txt [ Cookie:ms lauren law@count.asnetworks.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ad.dyntracker[1].txt [ Cookie:ms lauren law@ad.dyntracker.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@www.googleadservices[7].txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1067082950/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@de.sitestat[9].txt [ Cookie:ms lauren law@de.sitestat.com/haba/jako-o-de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@adserver.mitfahrzentrale[2].txt [ Cookie:ms lauren law@adserver.mitfahrzentrale.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\SFWB3Z1A.txt [ Cookie:ms lauren law@affiliates.commissionaccount.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\LILJNSLL.txt [ Cookie:ms lauren law@amazon-adsystem.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\N7IVEH5J.txt [ Cookie:ms lauren law@www.youpporn.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@clkads[2].txt [ Cookie:ms lauren law@clkads.com/adServe/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\U6R6THVD.txt [ Cookie:ms lauren law@openx.sexsearchcom.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@gostats[1].txt [ Cookie:ms lauren law@gostats.de/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads5.netpublisher[2].txt [ Cookie:ms lauren law@ads5.netpublisher.pe/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\XMZDUU71.txt [ Cookie:ms lauren law@google.com/accounts/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\82DW7OGR.txt [ Cookie:ms lauren law@c.atdmt.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@e-2dj6wbliwgd5olo.stats.esomniture[2].txt [ Cookie:ms lauren law@e-2dj6wbliwgd5olo.stats.esomniture.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\ms_lauren_law@ads.zeusclicks[1].txt [ Cookie:ms lauren law@ads.zeusclicks.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\4QHWQXW4.txt [ Cookie:ms lauren law@www.googleadservices.com/pagead/conversion/1042917106/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\SL4ZBBM9.txt [ Cookie:ms lauren law@www.google.de/accounts ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\SNEJQ0S9.txt [ Cookie:ms lauren law@pro-market.net/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\RNIS5VJQ.txt [ Cookie:ms lauren law@xxxgaymatch.com/ ]
        C:\USERS\MS LAUREN LAW\AppData\Roaming\Microsoft\Windows\Cookies\Low\9OFZST0M.txt [ Cookie:ms lauren law@stat.ed.cupidplc.com/ ]
        C:\USERS\MS LAUREN LAW\Cookies\Q0H56MWF.txt [ Cookie:ms lauren law@fastclick.net/ ]
        C:\USERS\MS LAUREN LAW\Cookies\M7FFZQK4.txt [ Cookie:ms lauren law@youporn.com/ ]
        C:\USERS\MS LAUREN LAW\Cookies\JO5SKGAC.txt [ Cookie:ms lauren law@de.partypoker.com/ ]
        C:\USERS\MS LAUREN LAW\Cookies\42R09K1H.txt [ Cookie:ms lauren law@doubleclick.net/ ]
        C:\USERS\MS LAUREN LAW\Cookies\IV9WQBJM.txt [ Cookie:ms lauren law@www.youporn.com/ ]
        C:\USERS\MS LAUREN LAW\Cookies\IBWMCMCU.txt [ Cookie:ms lauren law@www.usenext.de/ ]
        C:\USERS\MS LAUREN LAW\Cookies\024Q7JNZ.txt [ Cookie:ms lauren law@apmebf.com/ ]
        C:\USERS\MS LAUREN LAW\Cookies\8UC650DI.txt [ Cookie:ms lauren law@partypoker.com/ ]
        C:\USERS\MS LAUREN LAW\Cookies\X93X1RIP.txt [ Cookie:ms lauren law@zanox.com/ ]
        C:\USERS\MS LAUREN LAW\Cookies\ZVPP3UXE.txt [ Cookie:ms lauren law@forum.usenext.de/ ]
        C:\USERS\MS LAUREN LAW\Cookies\DJXPEQR3.txt [ Cookie:ms lauren law@oracle.112.2o7.net/ ]
        C:\USERS\MS LAUREN LAW\Cookies\NYRKDB5B.txt [ Cookie:ms lauren law@smartadserver.com/ ]
        C:\USERS\MS LAUREN LAW\Cookies\SUVW7D4B.txt [ Cookie:ms lauren law@rts.pgmediaserve.com/ ]
        C:\USERS\MS LAUREN LAW\Cookies\Q7CFTT4D.txt [ Cookie:ms lauren law@exoclick.com/ ]
        C:\USERS\MS LAUREN LAW\Cookies\0OHRAM65.txt [ Cookie:ms lauren law@www.usenext.com/ ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.360YIELD[1].TXT [ /AD.360YIELD ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.SPORTWERK[1].TXT [ /ADS.SPORTWERK ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.MOVECO[1].TXT [ /ADS.MOVECO ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.E-PLANNING[1].TXT [ /ADS.E-PLANNING ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TELE2DE.112.2O7[1].TXT [ /TELE2DE.112.2O7 ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@WEBORAMA[1].TXT [ /WEBORAMA ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.MIKINIMEDIA[2].TXT [ /ADS.MIKINIMEDIA ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSERVER.ADREACTOR[1].TXT [ /ADSERVER.ADREACTOR ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.DYNTRACKER[2].TXT [ /AD.DYNTRACKER ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@STAT.HEIMAT[2].TXT [ /STAT.HEIMAT ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSERVER2.CLIPKIT[1].TXT [ /ADSERVER2.CLIPKIT ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@E-2DJ6WCLIWOC5CHP.STATS.ESOMNITURE[2].TXT [ /E-2DJ6WCLIWOC5CHP.STATS.ESOMNITURE ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@STATS.D-P-H[1].TXT [ /STATS.D-P-H ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@VIACOM.ADBUREAU[2].TXT [ /VIACOM.ADBUREAU ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.TRAFFIKINGS[1].TXT [ /ADS.TRAFFIKINGS ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@GOTACHA.ROTATOR.HADJ7.ADJUGGLER[2].TXT [ /GOTACHA.ROTATOR.HADJ7.ADJUGGLER ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.CLICMANAGER[1].TXT [ /ADS.CLICMANAGER ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.COSMOTOURIST[2].TXT [ /ADS.COSMOTOURIST ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.AD4GAME[2].TXT [ /ADS.AD4GAME ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@NAKED[1].TXT [ /NAKED ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.LEADBOLT[1].TXT [ /AD.LEADBOLT ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.REKLAMPORT[2].TXT [ /AD.REKLAMPORT ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@E-2DJ6WMK4OMD5IEP.STATS.ESOMNITURE[2].TXT [ /E-2DJ6WMK4OMD5IEP.STATS.ESOMNITURE ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@WWW.GOOGLEADSERVICES[6].TXT [ /WWW.GOOGLEADSERVICES ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@VODAFONEGROUP.122.2O7[1].TXT [ /VODAFONEGROUP.122.2O7 ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.CARPOOLING[1].TXT [ /ADS.CARPOOLING ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@DEUTSCHEPOSTAG.112.2O7[1].TXT [ /DEUTSCHEPOSTAG.112.2O7 ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@HARRENMEDIANETWORK[1].TXT [ /HARRENMEDIANETWORK ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ELITEPARTNER.TT.OMTRDC[2].TXT [ /ELITEPARTNER.TT.OMTRDC ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@PARSHIP.122.2O7[1].TXT [ /PARSHIP.122.2O7 ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@MICROSOFTWLSEARCHCRM.112.2O7[1].TXT [ /MICROSOFTWLSEARCHCRM.112.2O7 ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ELITEPARTNER[1].TXT [ /ELITEPARTNER ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.US.E-PLANNING[1].TXT [ /ADS.US.E-PLANNING ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ALBUMPRINTER.122.2O7[1].TXT [ /ALBUMPRINTER.122.2O7 ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.WSOD[2].TXT [ /AD.WSOD ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.MEDIENHAUS[1].TXT [ /ADS.MEDIENHAUS ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.YOUPORN.VIDEOBOX[1].TXT [ /AD.YOUPORN.VIDEOBOX ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@CHEAPTICKETS.122.2O7[1].TXT [ /CHEAPTICKETS.122.2O7 ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TRACKING.DC-STORM[1].TXT [ /TRACKING.DC-STORM ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@NEDSTAT.HOSTELBOOKERS[2].TXT [ /NEDSTAT.HOSTELBOOKERS ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.FLING[1].TXT [ /ADS.FLING ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@STAT.CULTUREBASE[1].TXT [ /STAT.CULTUREBASE ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@NEDSTAT.HOSTELBOOKERS[1].TXT [ /NEDSTAT.HOSTELBOOKERS ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TRACKING.BMBFCLUSTER[1].TXT [ /TRACKING.BMBFCLUSTER ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.IMMOBILIENSCOUT24[1].TXT [ /ADS.IMMOBILIENSCOUT24 ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.MITFAHRZENTRALE[1].TXT [ /ADS.MITFAHRZENTRALE ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@LIVEPERSON[5].TXT [ /LIVEPERSON ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@COFIDIS2.SOLUTION.WEBORAMA[2].TXT [ /COFIDIS2.SOLUTION.WEBORAMA ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.ALLVOICES[1].TXT [ /AD.ALLVOICES ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@LEGOLAS-MEDIA[1].TXT [ /LEGOLAS-MEDIA ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.IADMANAGER[2].TXT [ /ADS.IADMANAGER ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.HORYZON-MEDIA[2].TXT [ /ADS.HORYZON-MEDIA ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@INTERCLICK[1].TXT [ /INTERCLICK ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@MONOPRIX.SOLUTION.WEBORAMA[2].TXT [ /MONOPRIX.SOLUTION.WEBORAMA ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.TRAVEL-OVERLAND[1].TXT [ /ADS.TRAVEL-OVERLAND ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.ADK2[2].TXT [ /ADS.ADK2 ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@MEDIA.PHOTOBUCKET[1].TXT [ /MEDIA.PHOTOBUCKET ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSRV.ADMEDIATE[2].TXT [ /ADSRV.ADMEDIATE ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TOYOTA2.SOLUTION.WEBORAMA[2].TXT [ /TOYOTA2.SOLUTION.WEBORAMA ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@CLICKBANK[1].TXT [ /CLICKBANK ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSERVER.YOPI[1].TXT [ /ADSERVER.YOPI ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@WWW.GOOGLEADSERVICES[10].TXT [ /WWW.GOOGLEADSERVICES ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@WWW.GOOGLEADSERVICES[8].TXT [ /WWW.GOOGLEADSERVICES ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.CPXADROIT[2].TXT [ /ADS.CPXADROIT ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@PORNME[2].TXT [ /PORNME ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TRACK.WEBTREKK[2].TXT [ /TRACK.WEBTREKK ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.UNDERTONE[2].TXT [ /ADS.UNDERTONE ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@DEALTIME[1].TXT [ /DEALTIME ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.STARTSEITEN24[1].TXT [ /ADS.STARTSEITEN24 ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@WWW.MESSENGERDUSEXE[1].TXT [ /WWW.MESSENGERDUSEXE ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@NEXTAG[1].TXT [ /NEXTAG ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.LZJL[2].TXT [ /ADS.LZJL ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@PORNHUB[2].TXT [ /PORNHUB ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@CDN5.SPECIFICCLICK[1].TXT [ /CDN5.SPECIFICCLICK ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSERVER.WEBMASTERBOND[1].TXT [ /ADSERVER.WEBMASTERBOND ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD1.ADFARM.ADTELLIGENCE[2].TXT [ /AD1.ADFARM.ADTELLIGENCE ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@AD.BEEPWORLD[2].TXT [ /AD.BEEPWORLD ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TRACKING.STAR-ADVERTISING[2].TXT [ /TRACKING.STAR-ADVERTISING ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ATDMT.COMBING[1].TXT [ /ATDMT.COMBING ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@HORYZON-MEDIA[1].TXT [ /HORYZON-MEDIA ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSRV1.ADMEDIATE[1].TXT [ /ADSRV1.ADMEDIATE ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@EAS4.EMEDIATE[1].TXT [ /EAS4.EMEDIATE ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@SPECIFICCLICK[1].TXT [ /SPECIFICCLICK ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@E-2DJ6WJLYAHD5GLP.STATS.ESOMNITURE[2].TXT [ /E-2DJ6WJLYAHD5GLP.STATS.ESOMNITURE ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.MOVIEASE[1].TXT [ /ADS.MOVIEASE ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@112.2O7[1].TXT [ /112.2O7 ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@WWW.GOOGLEADSERVICES[11].TXT [ /WWW.GOOGLEADSERVICES ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADS.CINEMADEN[1].TXT [ /ADS.CINEMADEN ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@BANNER.TESTBERICHTE[1].TXT [ /BANNER.TESTBERICHTE ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADVERTSTREAM[1].TXT [ /ADVERTSTREAM ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@GIRLSTEACHSEX[2].TXT [ /GIRLSTEACHSEX ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@TRACKING.TCHIBO[1].TXT [ /TRACKING.TCHIBO ]
        C:\USERS\MS LAUREN LAW\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\MS_LAUREN_LAW@ADSERV.QUALITY-CHANNEL[2].TXT [ /ADSERV.QUALITY-CHANNEL ]

Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.04.05.10

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Ms Lauren Law :: MSLAURENLAW [Administrator]

05.04.2012 23:19:22
mbam-log-2012-04-05 (23-19-22).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 384234
Laufzeit: 1 Stunde(n), 24 Minute(n), 45 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 06.04.2012 20:05

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

LaurenLaw 06.04.2012 20:15

Nein, Probleme gibt es nicht.
Die Cookies die nun in Quarantäne verschoben wurden kann ich löschen oder?
Gut, ich guck mir das mal an was du vorgeschlagen hast.

Und ich danke dir GANZ HERZLICH für deine Zeit und Hilfe!! Ich finds echt toll, dass es diese Seite gibt und ihr/ du sowas mach(s)t.

Und soll ich all die runtergeladenen Sachen aufm PC lassen, für den Fall, dass nochmal was passiert?

Bei dem Cookie Culler steht nicht, dass es für Windows 7 ist. Kann ich das trotzdem runterladen?

cosinus 06.04.2012 20:52

Ja die Cookies können weg.
Dre CookieCuller ist für den Firefox, das ist betriebssystemunabhängig. Nimm die neuere Version falls chip da noch was altes hat => http://filepony.de/download-cookie_culler/

Wichtig ist halt, dass du die Cookies die bleiben sollen über den CookieCuller schützen lässt (Protection On einzustellen bei Extras => CookieCuller), das kannst du zB bei FaceBook, Trojaner-Board oder allen anderen Seiten machen lassen wo es Cookies für das automatische Login erfordert. Ist nur etwas umständlich, denn bisher weiß ich nur, dass man jedes Cookies einzeln manuell schützen muss, ist anfangs etwas viel Klickarbeit je nachdem wie viele Cookies man schützen lassen muss/will
Anschließend muss der CookieCuller so konfiguriert werden, dass er jedes Mal beim FF-Start alle nicht geschützten Cookies löscht (Extras, Addons, CookiesCuller Einstellungen, Haken seiten bei "Delete unprotected Cookies on Startup")

Das im Zusammenspiel mit MVPS Hosts-Datei, die du alle paar Wochen mal aktuell hälst ist schon eine gute Grundkonfig. Viele TrackingCookies kommen duch die Hosts nicht mehr rein und alle ungeschützen Cookies werden beim nächsten FF-Start gelöscht


Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 01:52 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55